Law note · Connecticut
Breach of security re computerized data containing personal information
A person who owns, licenses, or maintains computerized data including personal information must notify each affected Connecticut resident of a breach without unreasonable delay, and no later than 60 days after discovery unless federal law requires a shorter time. 'Personal information' excludes publicly available information lawfully made available to the general public from government records or widely distributed media.
Unlike CTDPA, which bars a private right of action outright, this breach-notification section deems a violation an unfair trade practice under section 42-110b, and CUTPA's own private-action provision, section 42-110g, lets any person who suffers an ascertainable loss from a practice prohibited by section 42-110b sue for damages, so a breach-notice violation carries indirect private-plaintiff exposure that the comprehensive act does not.
This provision is in force under the current codified text; the underlying research did not establish a dated original commencement, so no effective_date is recorded here.
What it asks of an app
- Notify each affected Connecticut resident of a breach of security involving personal information without unreasonable delay and no later than 60 days after discovery, unless federal law requires a shorter time.
- Expect a breach-notice violation to expose you to a private suit for damages under CUTPA, section 42-110g, even though CTDPA itself bars a private right of action.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official Connecticut statute text, Chapter 669, Connecticut General Statutes