Conn. Gen. Stat. § 10-234dd
This is the official text of Conn. Gen. Stat. § 10-234dd, part of Connecticut’s Gen. Stat — part of the compiled statutory law of Connecticut, published by the state as "Gen. Stat." Browse the sections below, each linked to its official government source.
Not legal advice. This page reproduces the official text of a government statute for reference only. Laws change, and how a statute applies depends on your specific facts. For advice about your situation, consult a licensed attorney in your state.
Sec. 10-234dd. Duties re unauthorized release, disclosure or acquisition of student data.
Official statutory text
(2) Upon the discovery of a breach of security that results in the unauthorized release, disclosure or acquisition of directory information, student records or student-generated content, a contractor shall notify, without unreasonable delay, but not more than sixty days after such discovery, the local or regional board of education of such breach of security. During such sixty-day period, the contractor may (A) conduct an investigation to determine the nature and scope of such unauthorized release, disclosure or acquisition, and the identity of the students whose directory information, student records or student-generated content is involved in such unauthorized release, disclosure or acquisition, or (B) restore the reasonable integrity of the contractor's data system.
(3) Upon receipt of notice of a breach of security under subdivision (1) or (2) of this subsection, a local or regional board of education shall electronically notify, not later than two business days after receipt of such notice, the student and the parents or guardians of the student whose student information, student records or student-generated content is involved in such breach of security. The local or regional board of education shall post such notice on the board's Internet web site.
(b) Upon the discovery of a breach of security that results in the unauthorized release, disclosure or acquisition of student information, student records or student-generated content, an operator that is in possession of or maintains student information, student records or student-generated content as a result of a student's use of such operator's Internet web site, online service or mobile application, shall (1) notify, without unreasonable delay, but not more than thirty days after such discovery, the student or the parents or guardians of such student of any breach of security that results in the unauthorized release, disclosure or acquisition of student information, excluding any directory information contained in such student information, of such student, and (2) notify, without unreasonable delay, but not more than sixty days after such discovery, the student or the parents or guardians of such student of any breach of security that results in the unauthorized release, disclosure or acquisition of directory information, student records or student-generated content of such student. During such thirty-day or sixty-day period, the operator may (A) conduct an investigation to determine the nature and scope of such unauthorized release, disclosure or acquisition, and the identity of the students whose student information, student records or student-generated content are involved in such unauthorized release, disclosure or acquisition, or (B) restore the reasonable integrity of the operator's data system.
(3) Upon receipt of notice of a breach of security under subdivision (1) or (2) of this subsection, a local or regional board of education shall electronically notify, not later than two business days after receipt of such notice, the student and the parents or guardians of the student whose student information, student records or student-generated content is involved in such breach of security. The local or regional board of education shall post such notice on the board's Internet web site.
(b) Upon the discovery of a breach of security that results in the unauthorized release, disclosure or acquisition of student information, student records or student-generated content, an operator that is in possession of or maintains student information, student records or student-generated content as a result of a student's use of such operator's Internet web site, online service or mobile application, shall (1) notify, without unreasonable delay, but not more than thirty days after such discovery, the student or the parents or guardians of such student of any breach of security that results in the unauthorized release, disclosure or acquisition of student information, excluding any directory information contained in such student information, of such student, and (2) notify, without unreasonable delay, but not more than sixty days after such discovery, the student or the parents or guardians of such student of any breach of security that results in the unauthorized release, disclosure or acquisition of directory information, student records or student-generated content of such student. During such thirty-day or sixty-day period, the operator may (A) conduct an investigation to determine the nature and scope of such unauthorized release, disclosure or acquisition, and the identity of the students whose student information, student records or student-generated content are involved in such unauthorized release, disclosure or acquisition, or (B) restore the reasonable integrity of the operator's data system.
Status: in_force · Read it on the official government site
Need a lawyer in Connecticut?
Find a Connecticut lawyer
About this page: Statute text is reproduced from official government publishers via the
Open US Law dataset
(Vaquill AI, snapshot v2026.08, CC BY 4.0). Primary legislative text like this is public domain under the government-edicts doctrine
(Georgia v. Public.Resource.Org, 2020). We link every section back to its official source so you can verify it independently.