Connecticut Cybersecurity Bill Prohibiting Punitive Damages for Businesses Advances in State Legislature
Privacy, Cyber & AI Decoded Alert | 2 min read
Jun 16, 2021
On May 24, 2021, the Connecticut House of Representatives passed House Bill 6607, "An Act Incentivizing The Adoption Of Cybersecurity Standards For Businesses," which carves out a data security safe harbor provision for Connecticut businesses. The Bill prohibits the Connecticut Superior Court from assessing punitive damages to covered business entities for data breaches of personal or restricted information under certain circumstances.
The Bill requires covered entities to create, maintain, and comply with a written cybersecurity plan that conforms to industry standards and is risk-based. "Covered Entities" are defined as businesses that access, maintain, communicate, or process personal or restricted information via systems, networks, or services located inside or outside the state.
First, the scale and scope of a covered entity's cybersecurity plan must be based on the entity's size, complexity, and the nature and scope of its activities. The plan must also be based upon the sensitivity of the information to be protected in addition to the cost and availability of tools to improve information security and reduce vulnerabilities.
Second, a qualifying cybersecurity plan must be based on a current version of any of the six listed frameworks in combination with the Payment Card Industry Data Security Standard. For entities regulated by the Health Insurance Portability and Accountability Act of 1996, Title V of the Gramm-Leach-Bliley Act of 1999, the Federal Information Security Modernization Act of 2014, security requirements of the Health Information Technology for Economic and Clinical Health Act, or state or federal government, the cybersecurity framework must incorporate one of the four federal laws and regulations specified in the Bill.
An earlier version of the Bill provided an affirmative defense to a civil action rather than a bar on punitive damages. The Assembly further amended the Bill to disqualify covered entities for certain conduct and implemented a six-month time period by which a covered entity's cybersecurity program must conform with revisions or amendments to certain cybersecurity frameworks, laws, and regulations. In addition to creating specific exemptions to certain statutes, executive powers, and legal processes, the amendment altered the definitions of personal and restricted information.
The Bill would not:
- Limit the authority of the attorney general or the Department of Consumer Protection commissioner to seek administrative, legal, or equitable relief allowed by law;
- Affect or limit the process of granting class certifications in class actions; or
- Affect or limit existing statutory structures for (1) state contractors who receive confidential information and (2) Connecticut businesses that maintain computerized personal information and suffer security breaches.
Passed by the Connecticut Senate on June 7, the Bill is now on a consent calendar as a formality before heading to the Governor. The Bill would be effective on October 1, 2021.
Related Capabilities
Featured Insights

Press Release
Sep 18, 2026
Paris Glazer Named to Chicago Daily Law Bulletin’s 2026 40 Attorneys Under Forty

Consumer Crossroads: Where Financial Services and Litigation Intersect
Sep 17, 2026
Federal and State Regulators Continue Crackdown on Junk Fees

Press Release
Sep 17, 2026
Defense Verdict Reduces $134 Million Demand to $2 Million in Catastrophic Motorcycle Injury Case

Insights for Insurers Alert
Sep 16, 2026
America 250: The Nation’s Unique Contributions to Insurance Coverage Law and Litigation

In The News
Sep 15, 2026
Lucy Wang Discusses the California Insurance Commissioner’s Role in Protecting Consumers

Press Release
Sep 10, 2026
Hinshaw Attorneys Recognized as 2027 Lexology Index Thought Leaders: USA

In The News
Sep 10, 2026
Nicholas Ajello and Gregory Emry Analyze FAA’s Proposed BVLOS Drone Regulations

Consumer Crossroads: Where Financial Services and Litigation Intersect
Sep 9, 2026
“Play Now, Arbitrate Later”—“Not So Fast,” Ninth Circuit Says

In The News
Sep 9, 2026
Jennifer Driscoll Discusses “Patchwork” of Laws Targeting Personalized Pricing

Employment Law Observer
Sep 8, 2026
Five Workplace Issues Every Employer Should Address Before They Become a Costly Lawsuit

Press Release
Sep 8, 2026
Jim Sandy Appointed Chair of ABA Debt Collection and Bankruptcy Subcommittee

