HB 5222 clarifies and strengthens the Department of Consumer Protection's authority to investigate and enforce consumer protection laws. It specifically amends statutes to explicitly grant the Department and its board the power to issue subpoenas, administer oaths, compel testimony, and request documents during investigations. The bill also establishes immunity for staff acting in good faith and requires the state to cover legal costs for such actions. Additionally, it details enforcement mechanisms, including the ability to issue orders to stop violations and impose civil penalties up to $50,000 for violations of consumer protection statutes. The bill does not affect professional licensing fees or architecture regulations, which appear to be misplaced in the text.
This bill requires employers to notify employees in advance about electronic monitoring activities, such as camera use or computer tracking, and to post clear notices in visible locations. It defines electronic monitoring as data collection through technology like cameras or computers, excluding security cameras in public areas and legally prohibited surveillance. Employers must provide written notice before monitoring begins, except when investigating suspected illegal activity, workplace violations, or hostile environments. The law also establishes civil penalties ranging from $500 to $3,000 for repeated violations of the notification requirements.
This bill requires employers in Connecticut to inform job applicants and employees when automated systems are used to make employment decisions, such as hiring, firing, or performance evaluations. Companies deploying these systems must disclose what personal data is being collected, how long it will be kept, who will access it, and provide options for applicants to opt out of data processing. The law also mandates that employees receive written notice before any employment decision is made, explaining the purpose of the automated system and the nature of the decision being made. Developers of these systems must provide necessary information to employers to ensure compliance, unless they have a contract assuming those responsibilities. The protections apply to various automated processes including resume screening, online interview analysis, and predictive assessments used in workplace decisions.
SB 117 requires companies holding Connecticut residents' electronic personal information to notify affected individuals within 60 days of discovering a security breach involving unencrypted data. It defines "personal information" broadly to include Social Security numbers, financial data, health records, and biometric details, and sets a "massive breach" threshold of 100,000 affected residents. Companies must also report breaches to the Attorney General and provide free identity theft prevention services (including credit freezes) for two years to affected residents. The law takes effect October 1, 2026, with limited exceptions for ongoing criminal investigations.
SB 86 establishes data governance structures for Connecticut's executive branch agencies to improve data management and transparency. It requires each agency to appoint an "agency data officer" and creates a state "Chief Data Officer" to develop a biennial data plan, standardize data practices, and create an online open data repository. The bill mandates agencies to inventory high-value public data and publish open data (after privacy safeguards), with a specific provision (section j) directing the Chief Data Officer to identify data suitable for AI systems by 2028, while ensuring policies prevent discrimination. The law focuses on data infrastructure and access - not regulating AI technology or developers - and takes effect July 1, 2027.
HB 5262 allows property and casualty insurers to provide policies and changes electronically instead of by mail, but only with the insured's agreement and if no personal information is included. Insurers must offer a paper copy option upon request, keep electronic records for five years after policy expiration, and clearly inform customers about their electronic delivery choices and paper copy access. This directly affects insurers and policyholders in Connecticut, shifting notice delivery methods while maintaining consumer choice. The bill takes effect October 1, 2026, and includes specific requirements for online accessibility and record retention. (Other provisions mentioned in the title, like reserve funding and drug reporting, are not detailed in the provided bill text.)
SB 4 establishes a data broker registration system in Connecticut, requiring businesses that sell or license personal data to register with the Department of Consumer Protection by October 1, 2026. It directly affects data brokers (businesses collecting and selling personal data) and Connecticut consumers, who gain new rights to request data deletion. Key provisions include mandatory $600 annual registration fees, a requirement for data brokers to provide an "accessible deletion mechanism" for consumer requests, and definitions clarifying terms like "brokered personal data." The law aims to increase transparency and control over personal data handling while imposing specific compliance obligations on data brokers.
SB 384 redefines key terms related to state data management for executive branch agencies, effective July 1, 2026. It clarifies definitions including "executive branch agency" (excluding certain higher education and state offices), "high value data," "open data," and "protected data" based on specific criteria like public demand, operational necessity, and legal requirements. The bill does not create new data-sharing mandates but establishes a framework for how agencies categorize and manage data under existing standards. It directly affects state agencies that collect or maintain public data, ensuring consistent terminology for future data governance policies. This is a procedural definitional update, not a substantive policy change.