State WISP guide

WISP requirements in Connecticut

Connecticut’s 60-day outer deadline is paired with a hard Attorney General reporting workflow and a special remedy for Social Security or Taxpayer Identification Number exposure. A Connecticut incident file should preserve discovery date, resident-notice date, AG confirmation and PR case number, any federal shorter-deadline analysis, and the 24-month credit-monitoring offer decision.

Key facts

  • Connecticut firms should keep a written security program tied to the FTC Safeguards Rule and IRS taxpayer-data guidance.
  • Resident notice without unreasonable delay and no later than 60 days after discovery of the breach, unless a shorter federal deadline applies; Attorney General notice no later than resident notice, with law-enforcement delay available.
  • Notify the Connecticut Office of the Attorney General no later than the time affected residents are notified; initial reports should use the online submission form, while updates or supplemental reports should be sent to ag.breach@ct.gov with the case number when available.

Key takeaways

  • Connecticut firms should keep a written security program tied to the FTC Safeguards Rule and IRS taxpayer-data guidance.
  • Resident notice without unreasonable delay and no later than 60 days after discovery of the breach, unless a shorter federal deadline applies; Attorney General notice no later than resident notice, with law-enforcement delay available.
  • Notify the Connecticut Office of the Attorney General no later than the time affected residents are notified; initial reports should use the online submission form, while updates or supplemental reports should be sent to ag.breach@ct.gov with the case number when available.
  • The WISP should preserve evidence, remediation steps, and annual review records.

Do Connecticut tax preparers need a WISP?

Yes, if they are covered by the FTC Safeguards Rule or IRS tax-data security expectations, they should maintain a written plan. Connecticut state breach-notice duties make incident planning especially important.

The WISP should start with federal obligations because the Safeguards Rule supplies the security-program structure.

Connecticut requires notice to the Office of the Attorney General no later than when residents are notified, and the Attorney General prefers initial reports through its online data-breach submission form.

What is specific to Connecticut?

Resident notice without unreasonable delay and no later than 60 days after discovery of the breach, unless a shorter federal deadline applies; Attorney General notice no later than resident notice, with law-enforcement delay available. The plan should identify who evaluates state notice, who contacts counsel, and where the decision record is kept.

State breach-notification law does not replace the Safeguards Rule. It adds a state-specific response layer when an incident affects Connecticut residents.

Connecticut residents whose personal information is believed to have been compromised in a breach of security involving computerized data containing personal information.

Notify the Connecticut Office of the Attorney General no later than the time affected residents are notified; initial reports should use the online submission form, while updates or supplemental reports should be sent to ag.breach@ct.gov with the case number when available.

What should the WISP say?

It should describe real safeguards, assign responsibility, map vendors and systems, and include an incident-response path that reaches state-law review quickly.

For a small firm, the strongest plan is plain and evidence-backed: MFA records, backup tests, access reviews, training, vendor lists, and remediation dates.

The plan should never promise a control that is not actually in place.

Connecticut state-aware WISP checklist
TopicConnecticut planning noteEvidence
Federal WISPUse 16 CFR Part 314 as the program backboneWISP and annual review
IRS tax dataAccount for taxpayer records, PTIN practice, portals, and e-file workflowsSystem inventory and access list
Breach noticeResident notice without unreasonable delay and no later than 60 days after discovery of the breach, unless a shorter federal deadline applies; Attorney General notice no later than resident notice, with law-enforcement delay available.Incident clock and counsel review record
Regulator pathNotify the Connecticut Office of the Attorney General no later than the time affected residents are notified; initial reports should use the online submission form, while updates or supplemental reports should be sent to ag.breach@ct.gov with the case number when available.Notification decision log
State statuteConn. Gen. Stat. § 36a-701bSource URL retained in page sources

FAQ

Is this legal advice?

No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.

Does a small firm still need a written plan?

Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.

What if a control is not in place yet?

A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.

Does Connecticut have its own WISP law?

This page does not claim a standalone Connecticut WISP statute for every firm. It explains how federal WISP duties should be paired with Connecticut breach-notification planning.

Who reviews Connecticut breach notice?

The incident plan should route state-law decisions through qualified counsel and preserve any Connecticut Office of the Attorney General regulator-notice analysis.

Sources

Build a Connecticut-aware WISP packet.

Policywright generates a source-cited WISP and incident response plan you can review with counsel.

Start the questionnaire
Policywright is a configurable template product, not a law firm and not legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.