WISP requirements in Connecticut
Connecticut’s 60-day outer deadline is paired with a hard Attorney General reporting workflow and a special remedy for Social Security or Taxpayer Identification Number exposure. A Connecticut incident file should preserve discovery date, resident-notice date, AG confirmation and PR case number, any federal shorter-deadline analysis, and the 24-month credit-monitoring offer decision.
Key facts
- Connecticut firms should keep a written security program tied to the FTC Safeguards Rule and IRS taxpayer-data guidance.
- Resident notice without unreasonable delay and no later than 60 days after discovery of the breach, unless a shorter federal deadline applies; Attorney General notice no later than resident notice, with law-enforcement delay available.
- Notify the Connecticut Office of the Attorney General no later than the time affected residents are notified; initial reports should use the online submission form, while updates or supplemental reports should be sent to ag.breach@ct.gov with the case number when available.
Key takeaways
- Connecticut firms should keep a written security program tied to the FTC Safeguards Rule and IRS taxpayer-data guidance.
- Resident notice without unreasonable delay and no later than 60 days after discovery of the breach, unless a shorter federal deadline applies; Attorney General notice no later than resident notice, with law-enforcement delay available.
- Notify the Connecticut Office of the Attorney General no later than the time affected residents are notified; initial reports should use the online submission form, while updates or supplemental reports should be sent to ag.breach@ct.gov with the case number when available.
- The WISP should preserve evidence, remediation steps, and annual review records.
Do Connecticut tax preparers need a WISP?
Yes, if they are covered by the FTC Safeguards Rule or IRS tax-data security expectations, they should maintain a written plan. Connecticut state breach-notice duties make incident planning especially important.
The WISP should start with federal obligations because the Safeguards Rule supplies the security-program structure.
Connecticut requires notice to the Office of the Attorney General no later than when residents are notified, and the Attorney General prefers initial reports through its online data-breach submission form.
What is specific to Connecticut?
Resident notice without unreasonable delay and no later than 60 days after discovery of the breach, unless a shorter federal deadline applies; Attorney General notice no later than resident notice, with law-enforcement delay available. The plan should identify who evaluates state notice, who contacts counsel, and where the decision record is kept.
State breach-notification law does not replace the Safeguards Rule. It adds a state-specific response layer when an incident affects Connecticut residents.
Connecticut residents whose personal information is believed to have been compromised in a breach of security involving computerized data containing personal information.
Notify the Connecticut Office of the Attorney General no later than the time affected residents are notified; initial reports should use the online submission form, while updates or supplemental reports should be sent to ag.breach@ct.gov with the case number when available.
What should the WISP say?
It should describe real safeguards, assign responsibility, map vendors and systems, and include an incident-response path that reaches state-law review quickly.
For a small firm, the strongest plan is plain and evidence-backed: MFA records, backup tests, access reviews, training, vendor lists, and remediation dates.
The plan should never promise a control that is not actually in place.
| Topic | Connecticut planning note | Evidence |
|---|---|---|
| Federal WISP | Use 16 CFR Part 314 as the program backbone | WISP and annual review |
| IRS tax data | Account for taxpayer records, PTIN practice, portals, and e-file workflows | System inventory and access list |
| Breach notice | Resident notice without unreasonable delay and no later than 60 days after discovery of the breach, unless a shorter federal deadline applies; Attorney General notice no later than resident notice, with law-enforcement delay available. | Incident clock and counsel review record |
| Regulator path | Notify the Connecticut Office of the Attorney General no later than the time affected residents are notified; initial reports should use the online submission form, while updates or supplemental reports should be sent to ag.breach@ct.gov with the case number when available. | Notification decision log |
| State statute | Conn. Gen. Stat. § 36a-701b | Source URL retained in page sources |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
Does Connecticut have its own WISP law?
This page does not claim a standalone Connecticut WISP statute for every firm. It explains how federal WISP duties should be paired with Connecticut breach-notification planning.
Who reviews Connecticut breach notice?
The incident plan should route state-law decisions through qualified counsel and preserve any Connecticut Office of the Attorney General regulator-notice analysis.
Sources
- FTC Safeguards Rule, 16 CFR Part 314 (eCFR)
- FTC, Safeguards Rule: What Your Business Needs to Know
- FTC, Safeguards Rule notification requirement now in effect (16 CFR 314.4(j), eff. May 13, 2024)
- IRS Publication 5708, Creating a Written Information Security Plan
- IRS Publication 4557, Safeguarding Taxpayer Data
- IRS Form W-12, PTIN Application and Renewal
- IRS Publication 1345, Handbook for Authorized IRS e-file Providers
- Connecticut General Statutes § 36a-701b
- Connecticut Attorney General data breach reporting
- Connecticut Attorney General data breach submission form
Build a Connecticut-aware WISP packet.
Policywright generates a source-cited WISP and incident response plan you can review with counsel.
Start the questionnaire