Showing 11–12 of 12
bills
All technology bills
SB 117 requires companies holding Connecticut residents' electronic personal information to notify affected individuals within 60 days of discovering a security breach involving unencrypted data. It defines "personal information" broadly to include Social Security numbers, financial data, health records, and biometric details, and sets a "massive breach" threshold of 100,000 affected residents. Companies must also report breaches to the Attorney General and provide free identity theft prevention services (including credit freezes) for two years to affected residents. The law takes effect October 1, 2026, with limited exceptions for ongoing criminal investigations.
SB 384 redefines key terms related to state data management for executive branch agencies, effective July 1, 2026. It clarifies definitions including "executive branch agency" (excluding certain higher education and state offices), "high value data," "open data," and "protected data" based on specific criteria like public demand, operational necessity, and legal requirements. The bill does not create new data-sharing mandates but establishes a framework for how agencies categorize and manage data under existing standards. It directly affects state agencies that collect or maintain public data, ensuring consistent terminology for future data governance policies. This is a procedural definitional update, not a substantive policy change.