Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Banking Department Bills topic

No spam. Unsubscribe anytime.

Banking Department seeks to codify civil‑penalty authority for rental deposits, tighten data‑breach reporting

Connecticut General Assembly, Joint Committee on Banking · February 24, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Connecticut Department of Banking told the Banking Committee that SB 219 clarifies existing civil‑penalty authority in the rental security‑deposit statute and that HB 5210 would align state law with federal safeguard rules to require data‑security programs and regulator notice of breaches.

Matt Smith, director of government relations for the Connecticut Department of Banking, told the Joint Committee on Banking on Feb. 24 that SB 219 and HB 5210 are primarily transparency and conformity measures.

SB 219 inserts an explicit civil‑penalty reference into the rental security‑deposit statute to make clear landlords may be subject to enforcement under the banking code. "When the commissioner is investigating a complaint ... the language makes it clear within the rental security deposit statute," Smith said, citing Conn. Gen. Stat. §36a‑17, §36a‑50 and §36a‑52 as the underpinning enforcement provisions. He and committee members emphasized that the maximum statutory civil penalty is already set at $100,000, but Smith said such penalties have been rarely imposed in practice and that the Department typically seeks twice the security deposit and restitution for tenants in adjudications.

HB 5210 would bring state statute into alignment with a federal safeguard rule by requiring covered entities under the commissioner’s jurisdiction to maintain written data‑security programs and adopt incident‑response procedures. Smith said the draft contains a regulator‑notice obligation that refers to a three‑business‑day reporting timeframe and asked the committee to consider how the reporting clock should be tied to the point when an entity ‘‘knows or has reason to know’’ about unauthorized access. Bank representatives present urged harmonizing state reporting with federal guidance to avoid unrealistic deadlines when third‑party forensics are required.

Committee members pressed department staff on enforcement history and the intended transparency benefits. No vote was taken; the hearing record remains open for written comments.

The bills: SB 219 — clarifying codification of civil‑penalty authority in rental security‑deposit statute; HB 5210 — state conformity with federal safeguard requirements and regulator notice of data breaches.