AN ACT ESTABLISHING VARIOUS DATA SECURITY REQUIREMENTS APPLICABLE TO CERTAIN FINANCIAL INSTITUTIONS.
What changed between versions
New definitions were added for 'data security incident' and 'personal information' to clarify exactly what events trigger reporting requirements.
The requirement to adopt data security safeguards and file incident reports was removed for federal credit unions and out-of-state credit unions.
The threshold for reporting data security incidents was lowered; previously, an incident had to affect the institution's ability to do business, but now any unauthorized access to personal information must be reported.
The list of regulated entities was updated to explicitly include out-of-state trust companies and to remove references to federal credit unions and out-of-state credit unions.
The list of entities required to file incident reports was narrowed to include only licensees, Connecticut banks, and Connecticut credit unions, excluding federal credit unions and out-of-state credit unions.