HB 5210 Connecticut House · 2026 Regular Session

AN ACT ESTABLISHING VARIOUS DATA SECURITY REQUIREMENTS APPLICABLE TO CERTAIN FINANCIAL INSTITUTIONS.

HB 5210 establishes new data security requirements for financial institutions operating in Connecticut, including banks, credit unions, and out-of-state institutions with a presence in the state. It mandates that these institutions create written security programs to protect customer data and comply with federal data security standards under the Gramm-Leach-Bliley Act. The bill also requires institutions to report any data security incidents involving consumer information within three business days of discovery. These requirements take effect October 1, 2026, and apply to all covered financial institutions handling Connecticut consumer data.
Bill status in committee 1 of 4 stages cleared
Introduction
Feb 2026
Committee Review
Floor Vote
Governor
Introduced Feb 18, 2026 Last action Mar 24, 2026
Maddy AI version diff · 1 comparison

What changed between versions

Raised Bill BA Joint Favorable Substitute · 5 edits
MODERATE
The bill was amended to replace the original version with a joint favorable substitute, which significantly rewrites the data security requirements. The most critical change is the addition of specific definitions for 'data security incident' and 'personal information,' ensuring clarity on what triggers reporting obligations. Additionally, the scope of entities required to report incidents was narrowed to exclude federal credit unions and out-of-state credit unions, while the criteria for reporting were expanded to include any unauthorized access to personal information, regardless of whether the institution's ability to do business was impacted.
Scope change
The bill's scope was narrowed by removing federal credit unions and out-of-state credit unions from the list of entities required to adopt data security programs and file incident reports.
DEFINITION

New definitions were added for 'data security incident' and 'personal information' to clarify exactly what events trigger reporting requirements.

ELIGIBILITY

The requirement to adopt data security safeguards and file incident reports was removed for federal credit unions and out-of-state credit unions.

REQUIREMENT

The threshold for reporting data security incidents was lowered; previously, an incident had to affect the institution's ability to do business, but now any unauthorized access to personal information must be reported.

The list of regulated entities was updated to explicitly include out-of-state trust companies and to remove references to federal credit unions and out-of-state credit unions.

The list of entities required to file incident reports was narrowed to include only licensees, Connecticut banks, and Connecticut credit unions, excluding federal credit unions and out-of-state credit unions.

Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
9
Key actions
1
Committee
2
Mar 10, 2026
Lower · Passed
Joint Favorable Substitute
lower
Feb 18, 2026
Committee
REF. TO JOINT COMM. ON Banking
lower
4 primary · 0 co-sponsors

Sponsors