Does Connecticut CTDPA Amendments (SB 1295 / Public Act 25-113) require Record-Keeping & Documentation?

Connecticut • enforcing

Yes — 1 provision

Requirements at a glance

This regulation imposes 7 specific requirements for Record-Keeping & Documentation across 1 provision:

Attorney General Access to Assessments #

Obligation:
Record Keeping
enforcing
Effective:
Jul 1, 2026
Risk tier:
all
Scope:
Controllers that conduct data protection assessments under § 42-522(b) or profiling impact assessments under § 42-522(c)
cross-domain
This is the provision that converts the § 42-522(c) impact assessment from a paperwork exercise into a retained, producible record. Three design choices matter together: the Attorney General may compel any assessment relevant to an investigation and evaluate it for compliance across §§ 42-515 to 42-525; the assessments are confidential and exempt from the Freedom of Information Act, so a competitor cannot obtain them by request; and disclosure to the Attorney General waives neither attorney-client privilege nor work product protection. The privilege carve-out is the load-bearing piece — without it, counsel would advise against writing anything candid in an assessment, which is precisely how comparable assessment regimes hollow out.

Requirements

RequirementDetails
Production on demandThe Attorney General may require a controller to disclose any data protection assessment or impact assessment relevant to an investigation, and the controller must make it available (§ 42-522(d))
Evaluation for complianceThe Attorney General may evaluate a produced assessment for compliance with the responsibilities set out in §§ 42-515 to 42-525 (§ 42-522(d))
FOIA exemptionData protection assessments and impact assessments are confidential and exempt from disclosure under the Freedom of Information Act as defined in Conn. Gen. Stat. § 1-200 (§ 42-522(d))
No privilege waiverWhere a produced assessment contains information subject to attorney-client privilege or work product protection, disclosure to the Attorney General does not constitute a waiver (§ 42-522(d))
Processor assistanceA processor must provide any information necessary to enable the controller to conduct and document the assessments, so the record must be assemblable across the vendor chain (§ 42-529c(a)(2))
Minors' harm mitigation planWhere a minors' assessment finds a heightened risk of harm to minors, the controller must establish and implement a mitigation or elimination plan, and must disclose it to the Attorney General on request not later than ninety days after being notified (§ 42-529b(f))
Minors' assessments confidentialMinors' data protection assessments, impact assessments and harm mitigation plans carry the same FOIA exemption and the same no-waiver rule (§ 42-529b(g))

Penalties

ViolationFine
Failure to produceThe act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action
Cure period**No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525
View full regulation View obligation Obligation matrix