Connecticut's Privacy Law Changes Again Today: What Website Owners Should Do

If your site has a Connecticut visitor, a second wave of changes to the state's privacy law starts today. Most of it lands on companies that handle location data, profile people from public records, or run cameras on their premises, but one change reaches any site that has an ad SDK or a data partner it has never looked at closely.

What Changed

Connecticut amended its Data Privacy Act twice this year. Public Act 25-113 took effect on July 1, 2026. Public Act 26-64 (Senate Bill 4, signed May 27) and Public Act 26-100 (House Bill 5222, signed June 2) take effect today, October 1. The statute lives in chapter 743jj of the General Statutes.

The July changes narrowed what you can collect to what's reasonably necessary, barred the sale of sensitive data without consent, and required privacy notices to say whether personal data trains large language models. They also added a right to see which third parties bought a consumer's data.

The October changes go further in a few places. Controllers and third parties can no longer sell precise geolocation data at all, meaning anything locating a person within 1,750 feet. The purpose-limitation rule in section 42-520 loses its "material" qualifier, so consent is needed for any new purpose that isn't reasonably necessary to, or compatible with, the one you disclosed. The right to delete now reaches publicly available information that's compiled into a consumer profile or offered for sale. Businesses using facial recognition for on-site security must post signage. And data brokers have to register with the Department of Consumer Protection, with no unregistered sales allowed from January 1, 2027.

One correction to early coverage: summaries written in the spring listed surveillance pricing disclosures for October 1. A later act repealed that section, and the rules that replaced it start July 1, 2027.

What Website Owners Should Do

Start with geolocation. If an SDK, pixel, or data partner receives precise location from your visitors in exchange for money or other value, that arrangement is now unlawful for Connecticut residents. Ask each vendor what location data it receives, and get the answer in writing.

Next, read your privacy notice against the purposes you list. If marketing started using data you collected for account management, you now need consent no matter how small the shift felt. Connecticut has also required you to honor opt-out signals such as Global Privacy Control since January 2025, and that duty didn't change today, though it matters more as the sale rules tighten. Have counsel confirm whether the broker and facial recognition rules apply to your business.

Where Privisy Fits

A Privisy scan observes the third-party requests your pages make and checks whether your site stops them when a browser sends GPC. That gives you an independent list of which vendors your site talks to, so the vendor review has a starting point. It doesn't see data that leaves your servers, and it can't tell you whether a payload contained precise location, so treat it as one input to that review rather than the whole answer.

See Which Third Parties Your Site Calls

Privisy audits your trackers, opt-out handling, and GPC response, so you know what to ask each vendor.

Get Your Audit