GroundRules
← Search the law
Connecticut · Through Revised to January 1, 2026 (2026 Supplement to the General Statutes of Connecticut, applied over the base revision of January 1, 2025)

Conn. Gen. Stat. § 42-529b: *(See end of section for amended version and effective date.) Controllers' data protections assessments. Review, record keeping, confidentiality and disclosure. Risk mitigation plan.

Read at publisher ↗
Where this section sits in the code
  1. TITLE 42. BUSINESS, SELLING, TRADING AND COLLECTION PRACTICES
  2. CHAPTER 743jj. DATA PRIVACY AND SECURITY
  3. (B). ONLINE SERVICES, PRODUCTS OR FEATURES AND MINORS

(a) Each controller that, on or after October 1, 2024, offers any online service, product or feature to consumers whom such controller has actual knowledge, or wilfully disregards, are minors shall conduct a data protection assessment for such online service, product or feature: (1) In a manner that is consistent with the requirements established in section 42-522; and (2) that addresses (A) the purpose of such online service, product or feature, (B) the categories of minors' personal data that such online service, product or feature processes, (C) the purposes for which such controller processes minors' personal data with respect to such online service, product or feature, and (D) any heightened risk of harm to minors that is a reasonably foreseeable result of offering such online service, product or feature to minors.

(b) Each controller that conducts a data protection assessment pursuant to subsection (a) of this section shall: (1) Review such data protection assessment as necessary to account for any material change to the processing operations of the online service, product or feature that is the subject of such data protection assessment; and (2) maintain documentation concerning such data protection assessment for the longer of (A) the three-year period beginning on the date on which such processing operations cease, or (B) as long as such controller offers such online service, product or feature.

(c) A single data protection assessment may address a comparable set of processing operations that include similar activities.

(d) If a controller conducts a data protection assessment for the purpose of complying with another applicable law or regulation, the data protection assessment shall be deemed to satisfy the requirements established in this section if such data protection assessment is reasonably similar in scope and effect to the data protection assessment that would otherwise be conducted pursuant to this section.

(e) If any controller conducts a data protection assessment pursuant to subsection (a) of this section and determines that the online service, product or feature that is the subject of such assessment poses a heightened risk of harm to minors, such controller shall establish and implement a plan to mitigate or eliminate such risk.

(f) Data protection assessments shall be confidential and shall be exempt from disclosure under the Freedom of Information Act, as defined in section 1-200. To the extent any information contained in a data protection assessment disclosed to the Attorney General includes information subject to the attorney-client privilege or work product protection, such disclosure shall not constitute a waiver of such privilege or protection.

*Note: On and after July 1, 2026, this section, as amended by section 16 of public act 25-113, is to read as follows:

“Sec. 42-529b. Controllers' data protection and impact assessments. Review, record keeping, confidentiality and disclosure. Plans. (a) Each controller that offers any online service, product or feature to consumers whom such controller has actual knowledge, or wilfully disregards, are minors shall conduct a data protection assessment for such online service, product or feature: (1) In a manner that is consistent with the requirements established in section 42-522; and (2) that addresses (A) the purpose of such online service, product or feature, (B) the categories of minors' personal data that such online service, product or feature processes, (C) the purposes for which such controller processes minors' personal data with respect to such online service, product or feature, and (D) any heightened risk of harm to minors that is a reasonably foreseeable result of offering such online service, product or feature to minors.

(b) Each controller that offers any online service, product or feature to consumers whom such controller has actual knowledge, or wilfully disregards, are minors shall, if such online service, product or feature engages in any profiling based on such consumers' personal data, conduct an impact assessment for such online service, product or feature. Such impact assessment shall include, to the extent reasonably known by or available to the controller, as applicable: (1) A statement by the controller disclosing the purpose, intended use cases and deployment context of, and benefits afforded by, such online service, product or feature, if such online service, product or feature engages in any profiling for the purpose of making decisions that produce legal or similarly significant effects concerning such consumers; (2) an analysis of whether such profiling poses any reasonably foreseeable heightened risk of harm to minors and, if so, (A) the nature of such heightened risk of harm to minors, and (B) the steps that have been taken to mitigate such heightened risk of harm to minors; (3) a description of (A) the categories of personal data such online service, product or feature processes as inputs for the purposes of such profiling, and (B) the outputs such online service, product or feature produces for the purposes of such profiling; (4) an overview of the categories of personal data the controller used to customize such online service, product or feature for the purposes of such profiling, if the controller used data to customize such online service, product or feature for the purposes of such profiling; (5) a description of any transparency measures taken concerning such online service, product or feature with respect to such profiling, including, but not limited to, any measures taken to disclose to consumers that such online service, product or feature is being used for such profiling while such online service, product or feature is being used for such profiling; and (6) a description of the post-deployment monitoring and user safeguards provided concerning such online service, product or feature for the purposes of such profiling, including, but not limited to, the oversight, use and learning processes established by the controller to address issues arising from deployment of such online service, product or feature for the purposes of such profiling.

(c) Each controller that conducts a data protection assessment pursuant to subsection (a) of this section, or an impact assessment pursuant to subsection (b) of this section, shall: (1) Review such data protection assessment or impact assessment as necessary to account for any material change to the processing or profiling operations of the online service, product or feature that is the subject of such data protection assessment or impact assessment; and (2) maintain documentation concerning such data protection assessment or impact assessment for the longer of (A) the three-year period beginning on the date on which such processing or profiling operations cease, or (B) as long as such controller offers such online service, product or feature.

(d) A single data protection assessment or impact assessment may address a comparable set of processing or profiling operations that include similar activities.

(e) If a controller conducts a data protection assessment or impact assessment for the purpose of complying with another applicable law or regulation, the data protection assessment or impact assessment shall be deemed to satisfy the requirements established in this section if such data protection assessment or impact assessment is reasonably similar in scope and effect to the data protection assessment or impact assessment that would otherwise be conducted pursuant to this section.

(f) If any controller conducts a data protection assessment pursuant to subsection (a) of this section, or an impact assessment pursuant to subsection (b) of this section, and determines that the online service, product or feature that is the subject of such assessment poses a heightened risk of harm to minors, such controller shall establish and implement a plan to mitigate or eliminate such risk. The Attorney General may require a controller to disclose to the Attorney General a plan established pursuant to this subsection if the plan is relevant to an investigation conducted by the Attorney General. The controller shall disclose such plan to the Attorney General not later than ninety days after the Attorney General notifies the controller, in a form and manner prescribed by the Attorney General, that the Attorney General requires the controller to disclose such plan to the Attorney General.

(g) Data protection assessments, impact assessments and harm mitigation or elimination plans shall be confidential and shall be exempt from disclosure under the Freedom of Information Act, as defined in section 1-200. To the extent any information contained in a data protection assessment, impact assessment or harm mitigation or elimination plan disclosed to the Attorney General includes information subject to the attorney-client privilege or work product protection, such disclosure shall not constitute a waiver of such privilege or protection.”

Collected 2026-09-06T19:07:27Z. Source file · JSON

Browse this collection