Connecticut 2021 Regular Session Status: Enacted Bipartisan · 3 R · 2 D cosponsors

HB 5310 — AN ACT CONCERNING DATA PRIVACY BREACHES.

Last action — SIGNED BY GOVERNOR

  1. ✓
    Introduced
  2. ✓
    In Committee
  3. ✓
    Passed House
  4. ✓
    Passed Senate
  5. ✓
    To Executive
  6. 6
    Enacted

This bill has been enacted into law. Introduced January 22, 2021. Enacted.

Odds of enactment

High chance

Based on the sponsor, cosponsors, and committee posture, this bill has a high chance of becoming law.

Upgrade to see the exact probability and what's driving it.

A statistical estimate from our own model of past outcomes — an insight, not a guarantee. Policymaking is volatile.

Prognosis

Likely to advance 78% · moderate confidence
  • Enacted

    Current position in the legislative process.

  • 6 sponsors

    6 primary, 0 co-sponsors signed on.

  • Bipartisan support

    Sponsored across 2 parties (3 R · 2 D) — cross-party backing.

Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.

Bill Text

What changed in the latest version

182 added · 193 removed

182 line(s) added, 193 removed.

→
Previous
Latest
General Assembly Substitute Bill No.
Substitute House Bill No.
5310 January Session, 2021 AN ACT CONCERNING DATA PRIVACY BREACHES.
5310 Public Act No.
21-59 AN ACT CONCERNING DATA PRIVACY BREACHES.
(iv) driver's license number, [or] state identification card number, passport number, military identification number or other identification number issued by the government that is commonly used to verify identity;
(iv) driver's license number, [or] state identification card number, [;
[(C)] (v) credit or debit card number;
(C)] passport number, military identification number or other identification number issued by the government that is commonly used to verify identity;
[or (D)] (vi) financial account number in LCO \\PRDFS1\HCOUSERS\BARRYJN\WS\2021HB-05310-R021 of 6 HB.docx Substitute Bill No.
(v) credit or debit card number;
[or (D)] (vi) financial account number in Substitute House Bill No.
Such notification shall not be required if, after an appropriate investigation [and consultation with relevant federal, state and local agencies responsible for law enforcement,] the person LCO {\\PRDFS1\HCOUSERS\BARRYJN\WS\2021HB-05310-2 of 6 R02-HB.docx } Substitute Bill No.
Such notification shall not be required if, after Public Act No.
5310 reasonably determines that the breach will not likely result in harm to the individuals whose personal information has been acquired [and] or accessed.
21-59 2 of 6 Substitute House Bill No.
5310 an appropriate investigation [and consultation with relevant federal, state and local agencies responsible for law enforcement,] the person reasonably determines that the breach will not likely result in harm to the individuals whose personal information has been acquired [and] or accessed.
and (B) The person who [conducts business in this state, and who, in the ordinary course of such person's business,] owns or licenses computerized data that includes personal information, shall offer to each resident whose [nonpublic] personal information under [subparagraph (B)(i) of subdivision (9) of subsection (b) of section 38a- 38 or personal information as defined in] clause (i) or (ii) of subparagraph (A) of subdivision (2) of subsection (a) of this section was breached or is reasonably believed to have been breached, appropriate identity theft prevention services and, if applicable, identity theft mitigation services.
and (B) The person who [conducts business in this state, and who, in the ordinary course of such person's business,] owns or licenses computerized data that includes personal information, shall offer to each resident whose [nonpublic] personal information under [subparagraph (B)(i) of subdivision (9) of subsection (b) of section 38a- or personal information as defined in] clause (i) or (ii) of subparagraph (A) of subdivision (2) of subsection (a) of this section was breached or is reasonably believed to have been breached, appropriate identity theft prevention services and, if applicable, identity theft mitigation services.
(c) Any person that maintains computerized data that includes personal information that the person does not own shall notify the owner or licensee of the information of any breach of the security of the data immediately following its discovery, if the personal information of a resident of this state was breached or is reasonably believed to have been breached.
(c) Any person that maintains computerized data that includes personal information that the person does not own shall notify the owner or licensee of the information of any breach of the security of the data immediately following its discovery, if the personal information of Public Act No.
(d) Any notification required by this section shall be delayed for a LCO {\\PRDFS1\HCOUSERS\BARRYJN\WS\2021HB-053103 of 6 R02-HB.docx } Substitute Bill No.
21-59 3 of 6 Substitute House Bill No.
5310 reasonable period of time if a law enforcement agency determines that the notification will impede a criminal investigation and such law enforcement agency has made a request that the notification be delayed.
5310 a resident of this state was breached or is reasonably believed to have been breached.
(d) Any notification required by this section shall be delayed for a reasonable period of time if a law enforcement agency determines that the notification will impede a criminal investigation and such law enforcement agency has made a request that the notification be delayed.
(f) (1) In the event of a breach of login credentials under subparagraph (B) of subdivision (2) of subsection (a) of this section, notice to a resident may be provided in electronic or other form that directs the resident whose personal information was breached or is reasonably believed to have been breached to promptly change any password or security question and answer, as applicable, or to take other appropriate steps to protect the affected online account and all other online accounts for which the resident uses the same user name or electronic mail address and password or security question and answer.
(f) (1) In the event of a breach of login credentials under subparagraph (B) of subdivision (2) of subsection (a) of this section, notice to a resident may be provided in electronic or other form that directs the resident whose personal information was breached or is reasonably believed to have been breached to promptly change any password or security question and answer, as applicable, or to take Public Act No.
(2) Any person that furnishes an electronic mail account shall not comply with this section by providing notification to the electronic mail LCO {\\PRDFS1\HCOUSERS\BARRYJN\WS\2021HB-053104 of 6 R02-HB.docx } Substitute Bill No.
21-59 4 of 6 Substitute House Bill No.
5310 account that was breached or reasonably believed to have been breached if the person cannot reasonably verify the affected resident's receipt of such notification.
5310 other appropriate steps to protect the affected online account and all other online accounts for which the resident uses the same user name or electronic mail address and password or security question and answer.
(2) Any person that furnishes an electronic mail account shall not comply with this section by providing notification to the electronic mail account that was breached or reasonably believed to have been breached if the person cannot reasonably verify the affected resident's receipt of such notification.
Any person that maintains such a security breach procedure pursuant to the rules, regulations, procedures or guidelinesestablishedbytheprimaryor functionalregulator,asdefined in 15 USC 6809(2), shall be deemed to be in compliance with the security breach notification requirements of this section, provided (1) such person notifies, as applicable, such residents of this state, owners, and licensees required to be notified under and in accordance with the policies or the rules, regulations, procedures or guidelines established by the primary or functional regulator in the event of a breach of security, and (2) if notice is given to a resident of this state in accordance with subdivision (1) of this subsection regarding a breach of security, such person also notifies the Attorney General not later than the time when notice is provided to the resident.
Any person that maintains such a security breach procedure pursuant to the rules, regulations, procedures or guidelinesestablishedbytheprimaryorfunctionalregulator,asdefined in 15 USC 6809(2), shall be deemed to be in compliance with the security breach notification requirements of this section, provided (1) such person notifies, as applicable, such residents of this state, owners, and licensees required to be notified under and in accordance with the policies or the rules, regulations, procedures or guidelines established by the primary or functional regulator in the event of a breach of Public Act No.
(h) Any person that is subject to and in compliance with the privacy and security standards under the Health Insurance Portability and Accountability Act of 1996 and the Health Information Technology for LCO {\\PRDFS1\HCOUSERS\BARRYJN\WS\2021HB-053105 of 6 R02-HB.docx } Substitute Bill No.
21-59 5 of 6 Substitute House Bill No.
5310 Economic and Clinical Health Act ("HITECH") shall be deemed to be in compliance with this section, provided that (1) any person required to provide notification to Connecticut residents pursuant to HITECH shall also provide notice to the Attorney General not later than the time when notice is provided to such residents if notification to the Attorney General would otherwise be required under subparagraph (A) of subdivision (2) of subsection (b) of this section, and (2) the person otherwise complies with the requirements of subparagraph (B) of subdivision (2) of subsection (b) of this section.
5310 security, and (2) if notice is given to a resident of this state in accordance with subdivision (1) of this subsection regarding a breach of security, such person also notifies the Attorney General not later than the time when notice is provided to the resident.
(h) Any person that is subject to and in compliance with the privacy and security standards under the Health Insurance Portability and Accountability Act of 1996 and the Health Information Technology for Economic and Clinical Health Act ("HITECH") shall be deemed to be in compliance with this section, provided that (1) any person required to provide notification to Connecticut residents pursuant to HITECH shall also provide notice to the Attorney General not later than the time when notice is provided to such residents if notification to the Attorney General would otherwise be required under subparagraph (A) of subdivision (2) of subsection (b) of this section, and (2) the person otherwise complies with the requirements of subparagraph (B) of subdivision (2) of subsection (b) of this section.
This act shall take effect as follows and shall amend the following sections:
Approved June 16, 2021 Public Act No.
Section 1 October 1, 2021 36a-701b GL Joint Favorable Subst.
21-59 6 of 6
GAE Joint Favorable LCO {\\PRDFS1\HCOUSERS\BARRYJN\WS\2021HB-05310- 6 of 6 R02-HB.docx }
View plain text versions (5)

Action History

  1. SIGNED BY GOVERNOR

  2. TRANSMITTED BY SECRETARY OF THE STATE TO GOVERNOR

  3. TRANSMITTED TO SECRETARY OF THE STATE

  4. PUBLIC ACT 21-59

  5. ON CONSENT CALENDAR /IN CONCURRENCE

  6. SENATE PASSED

  7. SENATE CALENDAR NUMBER 529

  8. FAV. RPT., TAB. FOR CAL., SEN.

  9. HOUSE PASSED

  10. TABLED FOR HOUSE CALENDAR

  11. NO NEW FILE BY COMM. ON Government Administration and Elections

  12. RPTD. OUT OF LCO

  13. FILED WITH LCO

  14. Joint Favorable

  15. REF. BY HOUSE TO COMMITTEE ON Government Administration and Elections

  16. FILE NO. 9

  17. HOUSE CALENDAR NUMBER 46

  18. FAV. RPT., TABLED FOR HOUSE CALENDAR

  19. RPTD. OUT OF LCO

  20. REFERRED TO Office of Legislative Research AND Office of Fiscal Analysis 03/03/21

  21. FILED WITH LCO

  22. Joint Favorable Substitute

  23. PUBLIC HEARING 0128

  24. REF. TO JOINT COMM. ON General Law

Sponsors

Sponsorship breakdown

Export CSV (upgrade) →

6 sponsors · 0 co-sponsors · 181 not signed on

Sponsors (6)

Co-sponsors (0)

None.

Not signed on (181)

181 members have not signed on to this bill.

Show all 181 →

"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.

Whip count is in markup. Polling the chamber and every recorded vote this session. Only the first open is slow. It’s instant for you after this. Calling the roll · Tallying · Engrossing

Subjects

Cross-referencing the record. Reading this bill against every other bill in the corpus by meaning, not keywords. Only the first open is slow. It’s instant for you after this. Matching · Ranking · Engrossing

Frequently asked questions

Who sponsors HB 5310?
HB 5310 is sponsored by Hilda E. Santiago (Democratic), Craig C. Fishbein (Republican), Petit, William A., Bill Buckbee (Republican), Tami Zawistowski (Republican), and Derell Wilson (Democratic).
What is the current status of HB 5310?
This bill has been enacted into law. Introduced January 22, 2021. Enacted.
Where can I track HB 5310?
Track HB 5310 free on One Click Politics — get push/email alerts when it moves.

Make your voice heard on HB 5310

Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.

Stay ahead of HB 5310

Last checked for changes 2 months ago · updated continuously

One Click Politics tracks every bill in Congress and all 50 states.

Track this bill →