Showing 4 of 4
bills
All technology bills
HB 5222 clarifies and strengthens the Department of Consumer Protection's authority to investigate and enforce consumer protection laws. It specifically amends statutes to explicitly grant the Department and its board the power to issue subpoenas, administer oaths, compel testimony, and request documents during investigations. The bill also establishes immunity for staff acting in good faith and requires the state to cover legal costs for such actions. Additionally, it details enforcement mechanisms, including the ability to issue orders to stop violations and impose civil penalties up to $50,000 for violations of consumer protection statutes. The bill does not affect professional licensing fees or architecture regulations, which appear to be misplaced in the text.
SB 4 establishes a data broker registration system in Connecticut, requiring businesses that sell or license personal data to register with the Department of Consumer Protection by October 1, 2026. It directly affects data brokers (businesses collecting and selling personal data) and Connecticut consumers, who gain new rights to request data deletion. Key provisions include mandatory $600 annual registration fees, a requirement for data brokers to provide an "accessible deletion mechanism" for consumer requests, and definitions clarifying terms like "brokered personal data." The law aims to increase transparency and control over personal data handling while imposing specific compliance obligations on data brokers.
SB 5 (AN ACT CONCERNING ONLINE SAFETY) requires subscription-based AI providers (e.g., companies offering AI tools via paid plans) to give consumers clear, written disclosures about subscription terms before signing or renewing. This includes detailing any usage limits, such as restrictions based on user behavior or changes to prior terms. The bill also establishes new safety rules for "frontier developers" of advanced AI systems ("foundation models"), defining "catastrophic risk" as scenarios where AI could cause mass harm (e.g., aiding weapon creation or severe physical injury) and mandating risk assessments by covered employees. It does not ban specific AI uses but sets transparency and safety protocols for high-risk systems. The law takes effect October 1, 2026.
SB 117 requires companies holding Connecticut residents' electronic personal information to notify affected individuals within 60 days of discovering a security breach involving unencrypted data. It defines "personal information" broadly to include Social Security numbers, financial data, health records, and biometric details, and sets a "massive breach" threshold of 100,000 affected residents. Companies must also report breaches to the Attorney General and provide free identity theft prevention services (including credit freezes) for two years to affected residents. The law takes effect October 1, 2026, with limited exceptions for ongoing criminal investigations.