ARE YOU PREPARED FOR THE NEW DATA PRIVACY LAWS BEING ENFORCED IN 2023?
Beginning in July of 2023, the state of Connecticut will begin to enforce the comprehensive data privacy law that was passed in June of 2022. This law applies to certain businesses based in Connecticut and certain businesses that serve or produce products for Connecticut residents.
ARE YOU PREPARED FOR THE NEW DATA PRIVACY LAWS BEING ENFORCED IN 2023?
Beginning in July of 2023, the state of Connecticut will begin to enforce the comprehensive data privacy law that was passed in June of 2022. This law applies to certain businesses based in Connecticut and certain businesses that serve or produce products for Connecticut residents.
LAW REQUIREMENTS
WHO IS AFFECTED:
-Businesses based in Connecticut and/or businesses that serve or produce products for Connecticut residents.
-Businesses that process the data of at least 100,000 consumers annually (minus transactions that are limited to just a payment of some sort) or make at least 25% of their revenue from the sale of personal information and process data for at least 25,000 consumers annually.
Business Owner Obligations
- Limit the collection of data to what is āadequate, relevant and reasonably necessary in relation to the purposeā for which data is processed (as disclosed to customers)
- Establish, implement, and maintain reasonable data security controls, among other requirements
- Provide for consent and consent-revocation when processing āsensitive personal dataā (including information about race or ethnicity, religion, health conditions, sex life or orientation, citizenship or immigration status, genetic or biometric data, childrenās data, and precise geolocation data).
- The law additionally restricts the ability to target advertising for children between the ages of 13 ā 16.
Consumer Rights
- Connecticut consumers have the right to access, correct, delete, and port their data. In addition, businesses must provide consumers an opt-out for targeted advertising, the sale of their data, and automated decision-making profiling. Owners are required to respond to consumer requests no later than 45 days after receipt of the request.
Privacy Notice
- The CTDPA requires business owners to post a āreasonably accessible, clear, and meaningfulā privacy notice. Privacy notices must include the type of data being processed and which are shared with third parties and how consumers can exercise their rights. There must also be an email address or other mechanism visible so consumers can contact the business.
Risk Assessment & Documentation
- Businesses are required to have data protection assessments completed and documented. Proof of these assessments may be specially requested by the state Attorney General at their discretion.
LAW REQUIREMENTS
WHO IS AFFECTED:
-Businesses based in Connecticut and/or businesses that serve or produce products for Connecticut residents.
-Businesses that process the data of at least 100,000 consumers annually (minus transactions that are limited to just a payment of some sort) or make at least 25% of their revenue from the sale of personal information and process data for at least 25,000 consumers annually.
Business Owner Obligations
- Limit the collection of data to what is āadequate, relevant and reasonably necessary in relation to the purposeā for which data is processed (as disclosed to customers)
- Establish, implement, and maintain reasonable data security controls, among other requirements
- Provide for consent and consent-revocation when processing āsensitive personal dataā (including information about race or ethnicity, religion, health conditions, sex life or orientation, citizenship or immigration status, genetic or biometric data, childrenās data, and precise geolocation data).
- The law additionally restricts the ability to target advertising for children between the ages of 13 ā 16.
Consumer Rights
- Connecticut consumers have the right to access, correct, delete, and port their data. In addition, businesses must provide consumers an opt-out for targeted advertising, the sale of their data, and automated decision-making profiling. Owners are required to respond to consumer requests no later than 45 days after receipt of the request.
Privacy Notice
- The CTDPA requires business owners to post a āreasonably accessible, clear, and meaningfulā privacy notice. Privacy notices must include the type of data being processed and which are shared with third parties and how consumers can exercise their rights. There must also be an email address or other mechanism visible so consumers can contact the business.
Risk Assessment & Documentation
- Businesses are required to have data protection assessments completed and documented. Proof of these assessments may be specially requested by the state Attorney General at their discretion.
SOUND LIKE A LOT?ā IT IS.
SOUND LIKE A LOT? IT IS.
Hire a team of experts to do it for you.
The repercussions of noncompliance are too great to risk not getting this done right.
Penalties
At the conclusion of the grace period, penalties and fine amounts will be determined at the discretion of the state’s Attorney General.
If any breach of data happens or is suspected, companies must inform authorities and data subjects within 72 hours of the breachās discovery.
DATES TO REMEMBER
- July 1, 2023 ā The CTPDA becomes effective. The recommended target date for full compliance.
- December 31, 2024 ā The last date of the enforcement grace period.
- January 1, 2025 ā Businesses are required to have controls in place to collect consent and respond to consumer opt-out requests.
Recommended Steps for Compliance
- Create a data map of personal information
- Evaluate data processing activities
- Evaluate data retention policies and schedules
- Create and update privacy policies and terms and conditions and make them visible to consumers
- Develop policies and procedures to facilitate consumer privacy rights
- Review and amend third-party contracts
- Ensure you have a sound cybersecurity framework in place to keep data protected
HOW IMPACT BUSINESS TECHNOLOGY CAN HELP YOU
Ā Businesses and organizations should take heed of this notice as authorities are not just looking into big corporations. Take proactive action and ensure your business is compliant with these standards before they are enforced.Ā Impact Business Technology can help you classify consumer data, assess your business’s data security, and provide the needed documentation of your standing.
Let us tackle this for you. Use the form below to get started.
Let us tackle this for you. Use the form below to get started.
UNSURE OF YOUR BUSINESS NEEDS? GIVE US A CALL.
We will examine your current IT infrastructure and recommend a solution that fits.
UNSURE OF YOUR BUSINESS NEEDS? GIVE US A CALL.
We will examine your current IT infrastructure and recommend a solution that fits.
Our Blog
Protecting National Security: A Closer Look at Consumer Tech Risks
The Discovery of This New Threat Underscores the Importance of Scrutiny in Consumer Technology In an era where cybersecurity is a critical...
The Hidden Dangers of Lifestyle Apps & Wearable Devices: Protecting Your Data and Privacy
In today's tech-savvy world, lifestyle apps and wearable devices have become an integral part of our daily lives. They help us monitor our fitness...
New Social Engineering Tactic: Lead Imposters
The Continuous Fight Against Digital DeceptionĀ In today's digital world, new ways of exploitation are constantly emerging. If you are not vigilant,...
Our Blog
Protecting National Security: A Closer Look at Consumer Tech Risks
The Discovery of This New Threat Underscores the Importance of Scrutiny in Consumer Technology In an era where cybersecurity is a critical concern, the technology we rely on daily must be secure. TP-Link Technologies Co., Ltd. (TP-Link), a major player in the...
The Hidden Dangers of Lifestyle Apps & Wearable Devices: Protecting Your Data and Privacy
In today's tech-savvy world, lifestyle apps and wearable devices have become an integral part of our daily lives. They help us monitor our fitness levels, track our sleep patterns, manage our diets, and even keep tabs on our mental health. However, as convenient as...
New Social Engineering Tactic: Lead Imposters
The Continuous Fight Against Digital DeceptionĀ In today's digital world, new ways of exploitation are constantly emerging. If you are not vigilant, a bad actor might just slip in right under your nose. We have seen a recent increase in a method of social engineering...