Connecticut's private-sector security law is a two-part reasonable-security regime, a safeguards-and-destruction duty layered with a cybersecurity-program safe harbor, plus a newly effective connected-device security duty; it has no general private-sector vulnerability or incident-reporting statute and no sector cyber-resilience regime the LexLint activity vocabulary can express.
Conn. Gen. Stat. Sec. 42-471, added by Public Act 08-167 and effective October 1, 2008, requires any person in possession of another person's personal information (a Social Security number, driver's license or state identification card number, account number, credit or debit card number, passport number, alien registration number, health insurance identification number, or military identification information, combined with an identifier) to safeguard the data, computer files and documents containing it from misuse by third parties and to destroy, erase or make them unreadable before disposal, and requires any person who collects Social Security numbers in the course of business to create and publish a privacy protection policy; a financial institution whose safeguards comply with the Gramm-Leach-Bliley Act's Section 501(b) standards is deemed compliant, and the section does not reach a state agency or political subdivision.
Public Act 21-119 (2021), codified at Conn. Gen. Stat. Sec. 42-901 and effective October 1, 2021, layers an incentive rather than a mandate on top of that duty: a covered entity, any business that accesses, maintains, communicates or processes personal or restricted information, is shielded from punitive damages in a tort action alleging that a failure to implement reasonable cybersecurity controls caused a data breach, where it created, maintained and complied with a written cybersecurity program conforming to a named framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, the ISO/IEC 27000-series, or, for an entity already regulated under Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Title V, FISMA or HITECH, that regime, or the PCI Data Security Standard paired with another listed framework); the shield does not apply where the failure was gross negligence or wilful or wanton conduct, and the statute creates no duty to adopt a program of its own; it leaves undisturbed the class-action certification process, the Attorney General's and Commissioner's other enforcement authority, and the state's breach-notification statute.
Public Act 25-44 (2025), Section 2, effective July 1, 2026, is Connecticut's first connected-device statute: it defines a connected device as an Internet-connected home appliance, television or toy with a camera or microphone, and its subsection (c) requires a 'provider' (the device's manufacturer, and any person under contract who gets access to the camera or microphone data) to implement and maintain reasonable security measures to protect personally identifying information collected through the device's camera or microphone from unauthorized access, acquisition, destruction, disclosure, modification or use.
The same section's other subsections, mandatory pre-activation disclosure of recording capability, a right to decline activation, and a bar on selling or using a recording for targeted advertising without opt-in consent, are disclosure and consent duties that attach to the data rather than to the device's security posture and belong to the privacy topic; they are not yet researched under either topic as of this visit, so this row is scoped to subsection (c) alone rather than restating a claim nobody has filed.
No enacted Connecticut statute is confirmed in the primary text consulted here to set market-entry security requirements (an authentication-credential mandate, an update or support-period duty) a connected device or software product must meet, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act; that reading rests on the CGA's current codification and the sources read for this visit, not on a further dedicated search of the point.
Connecticut's Insurance Data Security Law, Conn. Gen. Stat. Sec. 38a-38 (Public Act 19-117, delayed to an October 1, 2020 effective date and since amended by Public Act 21-157), requires a person licensed, authorized or required to be licensed under the state's insurance laws to develop, implement and maintain a written information security program and to investigate and report a cybersecurity event to the Insurance Commissioner and affected consumers; because it binds only insurance licensees, a bound-party class no activity in the LexLint vocabulary expresses, it is recorded here rather than flagged on a guess or filed as an instrument.
Section 42-471 is enforced administratively by the Department of Consumer Protection, with a civil penalty of up to $5,000 per violation, or by another state agency where the person is licensed by it, with Attorney General injunctive authority under Section 42-472; it creates no private right of action, and no published enforcement record for it is confirmed in the primary text consulted here.
Public Act 25-44's connected-device security duty, by contrast, is enforced as an unfair or deceptive trade practice under Chapter 735a, and unlike Section 42-471 and several of Public Act 25-44's own other sections, its subsection (g) does not exclude Section 42-110g, so a person who suffers an ascertainable loss appears to retain Connecticut's ordinary private right of action for it.
Connecticut's breach-notification duty, Conn. Gen. Stat. Sec. 36a-701b, and the Connecticut Data Privacy Act's own security-practices clause, Conn. Gen. Stat. Sec. 42-520(a)(3) (one subsection of the comprehensive CTDPA, the same shape as the Texas Data Privacy and Security Act's Section 541.101(a)(2)), are already this jurisdiction's privacy-topic rows rather than repeated here.