SB 117 requires companies holding Connecticut residents' electronic personal information to notify affected individuals within 60 days of discovering a security breach involving unencrypted data. It defines "personal information" broadly to include Social Security numbers, financial data, health records, and biometric details, and sets a "massive breach" threshold of 100,000 affected residents. Companies must also report breaches to the Attorney General and provide free identity theft prevention services (including credit freezes) for two years to affected residents. The law takes effect October 1, 2026, with limited exceptions for ongoing criminal investigations.
SB 4 establishes a data broker registration system in Connecticut, requiring businesses that sell or license personal data to register with the Department of Consumer Protection by October 1, 2026. It directly affects data brokers (businesses collecting and selling personal data) and Connecticut consumers, who gain new rights to request data deletion. Key provisions include mandatory $600 annual registration fees, a requirement for data brokers to provide an "accessible deletion mechanism" for consumer requests, and definitions clarifying terms like "brokered personal data." The law aims to increase transparency and control over personal data handling while imposing specific compliance obligations on data brokers.
HB 5128 gives Connecticut consumers legal ownership of their genetic test results and biological samples (like saliva or blood) collected by direct-to-consumer genetic testing companies. It requires companies to obtain clear, active consent before collecting, using, or sharing genetic data, and to disclose their data policies prominently online. Companies must get separate consent for sharing data with third parties, using data for new purposes beyond the original test, or retaining samples after testing. The law ensures consumers control how their genetic information is handled, with exceptions only for court orders or subpoenas.
HB 5037 requires social media platforms to verify the age of users under 18 or obtain parental consent before showing them personalized content recommendations (like feeds or suggested posts). It applies to platforms that prioritize media based on user data, excluding shopping sites and purely educational tools. Platforms must delete age verification data after use and cannot charge more or degrade service for compliance. Exceptions include private messages, search results, or content from accounts users follow. The law takes effect January 1, 2028.
HB 5210 establishes new data security requirements for financial institutions operating in Connecticut, including banks, credit unions, and out-of-state institutions with a presence in the state. It mandates that these institutions create written security programs to protect customer data and comply with federal data security standards under the Gramm-Leach-Bliley Act. The bill also requires institutions to report any data security incidents involving consumer information within three business days of discovery. These requirements take effect October 1, 2026, and apply to all covered financial institutions handling Connecticut consumer data.