HB 5210 — AN ACT ESTABLISHING VARIOUS DATA SECURITY REQUIREMENTS APPLICABLE TO CERTAIN FINANCIAL INSTITUTIONS.
Last action — FILE NO. 133
-
✓Introduced
-
2In Committee
-
3Passed House
-
4Passed Senate
-
5To Executive
-
6Enacted
This bill is in committee in the House. Introduced February 18, 2026. It must pass committee before a floor vote.
Next likely step: a committee vote, then a floor vote in the House.
Odds of enactment
Low chanceBased on the sponsor, cosponsors, and committee posture, this bill has a low chance of becoming law.
Upgrade to see the exact probability and what's driving it.
A statistical estimate from our own model of past outcomes — an insight, not a guarantee. Policymaking is volatile.
Prognosis
-
In Committee
Current position in the legislative process.
-
4 sponsors
4 primary, 0 co-sponsors signed on.
-
Bipartisan support
Sponsored across 2 parties (2 R · 2 D) — cross-party backing.
Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.
Bill Text
What changed in the latest version
157 added · 44 removedPlain-language change summary
The recent changes to Bill HB 5210 clarify that certain financial institutions must implement data security measures and inform the Department of Banking about specific issues. Additionally, the language about the bill's impact on state and municipal finances was streamlined to indicate that there would be no fiscal impact. This is important because it emphasizes the focus on enhancing security for financial data without requiring additional financial resources from the state or municipalities.
House of Representatives General Assembly RaisedFile Bill No.
5210133 February Session, 2026 LCOSubstitute House Bill No.
15785210 ReferredHouse toof Representatives, March 24, 2026 The Committee on BANKINGBanking Introducedreported by:through REP.
(BA)DOUCETTE ANof ACTthe ESTABLISHING13th VARIOUSDist., DATAChairperson SECURITYof REQUIREMENTSthe APPLICABLECommittee TOon CERTAINthe FINANCIALpart INSTITUTIONS.of the House, that the substitute bill ought to pass.
AN ACT ESTABLISHING VARIOUS DATA SECURITY REQUIREMENTS APPLICABLE TO CERTAIN FINANCIAL INSTITUTIONS.
(a) EachAs financialused institution that is a bank, a Connecticut credit union, a federal credit union, an out-of-state bank that maintains a branch in this state,section: an out-of-state trust company or an out-of-state credit union that maintains an office in this state [,] or a licensee under this title, [or] and any person subject to the jurisdiction of the commissioner under title 36b shall (1) adopt, in writing, a program setting forth standards for developing, implementing and maintaining reasonable data security safeguards to protect the security, confidentiality and integrity of customer information, and (2) comply with all provisions of Subtitle A of Title V of the Gramm-Leach-Bliley Financial Modernization Act of 1999, 15 USC 6801 et seq., and the regulations promulgated thereunder that apply to such financial LCO No.
1578(1) 1"Data security incident" means any unauthorized access to or unauthorized acquisition, destruction or corruption of 2electronic Raisedfiles, Billmedia, No.databases or computerized data containing (A) personal information of an individual, or (B) supervisory, financial, operational or business information of any (i) licensee under this title, (ii) Connecticut bank, or (iii) Connecticut credit union;
5210(2) institution"Financial orinstitution" person,has exceptthe tosame themeaning extentas thatprovided thisin [section]Section subsection509 isinconsistentof withtheprovisionsofsections36a-41tothe 36a-44,inclusive,Gramm-Leach-Bliley inFinancial whichModernization caseAct theof provisions1999, that15 affordUSC 6809, and the customerregulations greaterpromulgated protectionthereunder, shallas control.said sHB5210 / File No.
For133 purposes1 ofsHB5210 thisFile [section]No. subsection, "financial institution" has the meaning given to that term in Section 509 of the Gramm-Leach-Bliley Financial Modernization Act of 1999, 15 USC 6809, and the regulations promulgated thereunder, as said act and such regulations may be amended from time to time.
(b)133 Eachact licenseeand undersuch thisregulations titlemay thatbe maintains customer information for any consumer in this state shall comply with all applicable provisions of 16 CFR Part 314, as amended from time to time.time;
(c) Each licensee under this title, bank, Connecticut credit union and federal(3) credit"Personal unioninformation" shall file a written report with the Department of Banking, in a form and manner prescribed by the Banking Commissioner, not later than three business days after such licensee, bank or credit union knows, or has reason to know, of the occurrencesame ofmeaning anyas dataprovided security incident that (1) affects its ability to do business, or (2) involves, or potentially involves, any unauthorized access to the personal information of any consumer in thissection state.36a-701b.
(b) Each financial institution that is a bank, a Connecticut credit union, a federal credit union, an out-of-state bank that maintains a branch in this state, an out-of-state trust company or out-of-state credit union that maintains an office in this state [,] or a licensee under this title, [or any] and each person subject to the jurisdiction of the commissioner under title 36b, shall (1) adopt, in writing, a program setting forth standards for developing, implementing and maintaining reasonable data security safeguards to protect the security, confidentiality and integrity of customer information, and (2) comply with all provisions of Subtitle A of Title V of the Gramm-Leach-Bliley Financial Modernization Act of 1999, 15 USC 6801 et seq., and the regulations promulgated thereunder that apply to such financial institution [, except to] or person, including, but not limited to, the applicable provisions of 12 CFR Part 364, Appendix B, 12 CFR Part 748, Appendix A and 16 CFR Part 314, as said act and such regulations may be amended from time to time.
To the extent that this [section] subsection is inconsistent with the provisions of sections 36a-41 to 36a- 44, inclusive, [in which case] the provisions that afford the customer greater protection shall control.
[For purposes of this section, "financial institution" has the meaning given to that term in Section 509 of the Gramm-Leach-Bliley Financial Modernization Act of 1999, 15 USC 6809, and the regulations promulgated thereunder.] (c) Each licensee under this title, Connecticut bank and Connecticut credit union shall file a notification with the Department of Banking, in a form and manner prescribed by the Banking Commissioner, not later than three business days after such licensee, Connecticut bank or Connecticut credit union knows, or has reason to know, of the occurrence of any data security incident that may (1) materially impact its ability to operate in a safe and sound manner or comply with applicable laws and regulations, (2) cause significant disruption in sHB5210 / File No.
133 2 sHB5210 File No.
133 customer services, or (3) involve any unauthorized access to the personal information of any individual.
Section 1 October 1, 2026 36a-44a StatementBA ofJoint Purpose:Favorable Subst.
TosHB5210 establish/ variousFile dataNo. security requirements applicable to certain financial institutions.
that133 when3 thesHB5210 entireFile text of a bill or resolution or a section of a bill or resolution is new, it is not underlined.] LCO No.
1578133 2The following Fiscal Impact Statement and Bill Analysis are prepared for the benefit of 2the members of the General Assembly, solely for purposes of information, summarization and explanation and do not represent the intent of the General Assembly or either chamber thereof for any purpose.
In general, fiscal impacts are based upon a variety of informational sources, including the analyst’s professional knowledge.
Whenever applicable, agency data is consulted as part of the analysis, however final products do not necessarily reflect an assessment from any specific department.
OFA Fiscal Note State Impact:
None Municipal Impact:
None Explanation The bill, which requires certain financial institutions to adopt data security safeguards and to notify the Department of Banking of certain data security incidents, results in no fiscal impact to the state as the department has sufficient resources to receive the notifications.
sHB5210 / File No.
133 4 sHB5210 File No.
133 OLR Bill Analysis sHB 5210 AN ACT ESTABLISHING VARIOUS DATA SECURITY REQUIREMENTS APPLICABLE TO CERTAIN FINANCIAL INSTITUTIONS.
SUMMARY This bill requires the following entities and individuals to adopt written programs with standards on developing, implementing, and maintaining reasonable data security safeguards to protect the security, confidentiality, and integrity of customer information:
banks, Connecticut credit unions, federal credit unions, out-of-state banks with a branch in Connecticut, out-of-state trust companies or credit unions with an office in Connecticut, licensees under Connecticut banking law, and those who are subject to the Department of Banking’s (DOB) jurisdiction under Connecticut securities law.
Under the bill, to the extent that this requirement conflicts with existing state law on financial records disclosure, the provisions giving customers the greater protection control.
The bill also requires DOB licensees and Connecticut banks and credit unions to notify the department within three business days after they know, or have reason to know, of certain data security incidents.
The reporting requirement is triggered by any incident that may (1) materially impact the ability to operate safely and soundly or comply with applicable laws and regulations, (2) significantly disrupt customer services, or (3) involve unauthorized access to an individual’s personal information (see BACKGROUND).
Under existing law, the same entities and individuals that the bill requiresto adopt awrittenprogramonprotecting customer information mustcomplywiththefinancialprivacyprovisionsoftheGramm-Leach- Bliley Financial Modernization Act of 1999 and associated regulations sHB5210 / File No.
133 5 sHB5210 File No.
133 (see BACKGROUND).
The bill specifies that this includes required compliance with the applicable provisions of three associated federal regulations on standards for developing, implementing, and maintaining safeguards to protect customer information.
Lastly, the bill makes technical and conforming changes.
EFFECTIVE DATE:
October 1, 2026 DATA SECURITY INCIDENT Under the bill, a “data security incident” is unauthorized access to or unauthorized acquisition, destruction, or corruption of certain electronic files, media, databases, or computerized data.
Show all 66 changed lines (26 more)
The files, media, databases, or data involved must have either (1) an individual’s personal information or (2) a DOB-licensee’s or Connecticut bank’s or credit union’s supervisory, financial, operational, or business information.
BACKGROUND Gramm-Leach-Bliley Financial Modernization Act of 1999 Subtitle A of Title V of the Gramm-Leach-Bliley Financial Modernization Act of 1999 limits the circumstances under which a financial institution can disclose a consumer’s nonpublic personal information to nonaffiliated third parties.
It also requires financial institutions to disclose to their customers the institution’s financial privacy policiesandpracticeswithrespect to affiliatedandnonaffiliated parties (15 U.S.C.
§ 6801 et seq.).
Personal Information By law, “personal information” is a person’s first name or initial and last name, combined with at least one of the following:
1.
driver’s license or state identification card number;
2.
government-issued identification number that is commonly used to verify identity, such as a Social Security, taxpayer identification, passport, or military identification number;
sHB5210 / File No.
133 6 sHB5210 File No.
133 3.
credit or debit card number;
4.
financial account number, with other information that would give account access;
5.
information about the person’s medical history, mental or physical condition, or medical treatment or diagnosis;
6.
health insurance policy number or subscriber identification number, or any unique identifier a health insurer uses to identify the person;
7.
biometric data generated by electronic measurements of the person’s unique physical characteristics used to authenticate or determine identity (for example, fingerprint, voice print, or eye image);
or 8.
precise geolocation data.
It also includes a person’s username or email address, combined with a password or security question and answer that would allow access to an online account (breach of login credentials) (CGS § 36a-701b).
COMMITTEE ACTION Banking Committee Joint Favorable Substitute Yea 13 Nay 0 (03/10/2026) sHB5210 / File No.
133 7
Show all 66 changed rows (26 more)
View plain text versions (3)
- File No. 133 View text pdf
- Raised Bill View text Current pdf
- Substitute BA Joint Favorable Substitute pdf
Action History
-
FILE NO. 133
-
HOUSE CALENDAR NUMBER 113
-
FAV. RPT., TABLED FOR HOUSE CALENDAR
-
RPTD. OUT OF LCO
-
REFERRED TO Office of Legislative Research AND Office of Fiscal Analysis 03/23/26
-
FILED WITH LCO
-
Joint Favorable Substitute
-
PUBLIC HEARING 0224
-
REF. TO JOINT COMM. ON Banking
Sponsors
- Eric C. Berthel · Primary
- Tom Delnicki · Primary
- Antonio Felipe · Primary
- Travis Simms · Primary
Sponsorship breakdown
Export CSV (upgrade) →4 sponsors · 0 co-sponsors · 183 not signed on
Sponsors (4)
- Eric C. Berthel Republican
- Tom Delnicki Republican
- Antonio Felipe Democratic
- Travis Simms Democratic
Co-sponsors (0)
None.
Not signed on (183)
183 members have not signed on to this bill.
Show all 183 →"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.
Subjects
Frequently asked questions
- Who sponsors HB 5210?
- HB 5210 is sponsored by Eric C. Berthel (Republican), Tom Delnicki (Republican), Antonio Felipe (Democratic), and Travis Simms (Democratic).
- What is the current status of HB 5210?
- This bill is in committee in the House. Introduced February 18, 2026. It must pass committee before a floor vote.
- Where can I track HB 5210?
- Track HB 5210 free on One Click Politics — get push/email alerts when it moves.
Make your voice heard on HB 5210
Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.
Stay ahead of HB 5210
Last checked for changes 3 months ago · updated continuously
One Click Politics tracks every bill in Congress and all 50 states.
Track this bill →