Description

Defense against cybersecurity liability adopted by General Assembly

The Act Incentivizing the Adoption of Cybersecurity Standards for Businesses (House Bill 6607) moves into force without signature of the Governor. The grace period ends on 1 October 2021. The bill creates a defense in any action brought under Connecticut law alleging a failure to implement adequate cybersecurity controls that results in a data breach involving personal or restricted information. In detail, Superior Courts shall not assess punitive damages against a covered entity if the entity created, maintained and complied with a written cybersecurity program that conforms to an industry recognized cybersecurity framework. Accepted frameworks can be found in subsection c. Covered entity means a business that accesses, maintains, communicates or processes personal information or restricted information.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
subnational
Government Branch
legislature
Government Body
parliament

Complete timeline of this policy change

Hide details
2021-03-12
under deliberation

The Act Incentivizing the Adoption of Cybersecurity Standards for Businesses (House Bill 6607) was …

2021-05-20
under deliberation

The Act Incentivizing the Adoption of Cybersecurity Standards for Businesses (House Bill 6607) was …

2021-06-07
under deliberation

The Act Incentivizing the Adoption of Cybersecurity Standards for Businesses (House Bill 6607) was …

2021-06-24
in grace period

The Act Incentivizing the Adoption of Cybersecurity Standards for Businesses (House Bill 6607) move…

2021-10-01
in force

The Act Incentivizing the Adoption of Cybersecurity Standards for Businesses (House Bill 6607) goes…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
consumer data (all forms): storage (any form)
personal data (all forms): storage (any form)
corporate data (all forms): storage (any form)

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

consumer data (all forms): storage (any form)

personal data (all forms): storage (any form)

corporate data (all forms): storage (any form)