SB00117
CT
engrossed
An Act Concerning Breaches Of Security Involving Electronic Personal Information.
privacy
Plain-English summary
1. **ONE-SENTENCE SUMMARY:** This bill requires businesses to report certain information to the Attorney General after a significant data breach and mandates a third-party forensic examination for massive breaches.
2. **KEY REQUIREMENTS:**
- Report specific materials to the Attorney General after a breach, following their prescribed format.
- Conduct a third-party forensic examination and analysis if a "massive breach of security" occurs.
- Submit a forensic report to the Attorney General after a massive breach.
3. **DEADLINES:**
- The bill is effective immediately upon passage, so businesses should prepare to comply right away.
4. **PENALTIES:**
- Failing to submit the required third-party forensic report can result in additional penalties, though specific fines are not detailed in the bill.
5. **SMB IMPACT:** Small businesses must be vigilant about data security and have a plan in place for reporting breaches, as the costs and complexities of forensic examinations could be significant. Compliance is essential to avoid penalties and protect customer trust.
Source description
To (1) provide that certain materials provided to the Attorney General following a breach of security involving electronic personal information shall be provided to the Attorney General in a form and manner prescribed by the Attorney General, (2) define "massive breach of security", (3) require a third-party forensic examination, analysis and report following a massive breach of security, and (4) impose an additional penalty for any person who fails to submit a third-party forensic report to the Attorney General following a massive breach of security.
Not legal advice. Summaries are generated by AI from publicly available bill text and may contain errors or omissions. Always consult counsel before making compliance decisions.