Skip to content

Cyber Liability by state

Connecticut data breach notification law and cyber insurance

Direct answer

What is Connecticut's data breach notification law?

Connecticut's breach notification law (Conn. Gen. Stat. sect. 36a-701b) requires businesses to notify affected residents without unreasonable delay but not later than 60 days after discovery of the breach after a breach of personal information. Connecticut requires businesses to notify affected residents and the Attorney General within 60 days of discovering a breach, and to offer identity theft protection in certain cases.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

Connecticut requires businesses to notify affected residents and the Attorney General within 60 days of discovering a breach, and to offer identity theft protection in certain cases. Cyber liability insurance generally funds the forensics, notification, credit monitoring, and legal review this statute requires.

Consumer notification deadline
Without unreasonable delay but not later than 60 days after discovery of the breach
Regulator notice
Notify the Connecticut Attorney General not later than the time residents are notified.
Safe harbor
Notification is not required if the compromised data was encrypted or otherwise secured and the confidential key was not acquired.
Enforcement
Failure to comply is an unfair trade practice enforceable by the Attorney General under the Connecticut Unfair Trade Practices Act.

Statutes and sources

  • Connecticut Breach of Security Notification Law

    Conn. Gen. Stat. sect. 36a-701b

Regulator: Connecticut Attorney General . Last verified 2026-07-29 from the official source .

Get Connecticut coverage handled

Share a few details and an agent will respond within one business day.