Law / United States / Connecticut
Adoption of cybersecurity controls by businesses, exemption from punitive damages
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 October 2021.
A security baseline statutes rule binding private bodies.
As of 12 September 2026.
What it requires
- This is a safe harbor from punitive damages, not a duty: it is available to a 'covered entity', any business that accesses, maintains, communicates or processes personal or restricted information through a system, network or service located in or outside Connecticut, sued in tort for a failure to implement reasonable cybersecurity controls that resulted in a data breach.
- To claim it, have created, maintained and complied with a written cybersecurity program with administrative, technical and physical safeguards for personal and restricted information, at the time of the breach, designed to protect the information's security, confidentiality and integrity and scaled to the entity's size, complexity, activities, the sensitivity of the information, and the cost and availability of security tools.
- The program must conform to the current version of a named framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, or the ISO/IEC 27000-series), or, for an entity already regulated under HIPAA, Gramm-Leach-Bliley Title V, FISMA or HITECH, conform to that regime, or comply with the PCI Data Security Standard together with another listed framework; conform to a revised version within six months of its publication.
- The safe harbor is unavailable where the failure to implement reasonable cybersecurity controls was the result of gross negligence or wilful or wanton conduct. It creates no duty to adopt a program of its own, does not limit the Attorney General's or the Commissioner of Consumer Protection's authority to seek other relief, and leaves undisturbed the class-action certification process and the state's breach-notification statute.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Public Act 21-119 (2021) shields a 'covered entity', any business that accesses, maintains, communicates or processes personal or restricted information through a system, network or service located in or outside Connecticut, from punitive damages in a tort action alleging that a failure to implement reasonable cybersecurity controls caused a data breach, where the entity created, maintained and complied with a written cybersecurity program with administrative, technical and physical safeguards that conforms to a named industry framework.
The shield does not apply where the failure was the result of gross negligence or wilful or wanton conduct. The section creates no duty to adopt a program of its own and does not limit the Attorney General's or the Commissioner of Consumer Protection's authority to seek other relief. It leaves undisturbed the process for certifying a class action founded in tort. It also leaves undisturbed the requirements of the state's breach-notification statute at Section 36a-701b.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product