CTDPA: Connecticut Data Privacy Act

Connecticut Office of the Attorney General

Connecticut privacy law granting consumer rights, requiring data protection assessments, and honoring opt-out signals, as amended by Public Act No. 25-113 (operative July 1, 2026) and by Public Acts No. 26-64 and No. 26-100 (operative October 1, 2026).

6Citations
0Audited
6Reference only
Jun 2026Last amended
Official source ↗Effective July 1, 2023

CTDPA citations (6)

§ 42-515Reference

Definitions

Establishes key definitions under the Connecticut Data Privacy Act, including controller, processor, consumer, personal data, and consent, as amended by Public Act No. 25-113. Effective July 1, 2026, PA 25-113 broadens the definition of 'sensitive data' to add government-issued identifiers (such as driver's license, passport, and Social Security numbers), financial account information, and neural data. Effective October 1, 2026, Public Act No. 26-64 (S.B. 4) rewrites the 'publicly available information' definition in both directions. It widens the base: information made available through government records or to the general public from widely distributed media no longer has to have been made available lawfully, and a processor's or an affiliate's reasonable basis to believe the consumer lawfully made the information public now counts alongside a controller's. It also adds exclusions for personal data created by combining personal data with publicly available information, genetic data the consumer has not made public, information posted where the consumer kept a reasonable expectation of privacy, obscene visual depictions, and intimate or synthetically created intimate images known to be nonconsensual, and the biometric-data exclusion now turns on collection without the consumer's knowledge rather than without consent. PA 26-64 also adds a definition of 'facial recognition technology'. On the linked 2026 Supplement page, the July 1, 2026 version follows the superseded text in the section's entry; the PA 26-64 changes in force since October 1, 2026 are not yet printed there.

ScopeSensitive PI
§ 42-516Reference

Applicability

Applies to any person that meets one of three independent triggers. Under Public Act No. 25-113 (signed June 24, 2025, effective July 1, 2026), the prior 100,000/25,000-consumer thresholds are replaced by: (1) conducting business in Connecticut, or producing products or services targeted to Connecticut residents, and processing the personal data of at least 35,000 consumers in the preceding calendar year; (2) controlling or processing consumers' sensitive data in any amount, with no consumer-count floor; or (3) offering consumers' personal data for sale in trade or commerce, also with no consumer-count floor. A business can therefore fall in scope solely by touching sensitive data or selling personal data, regardless of how many consumers' records it processes. On the linked 2026 Supplement page, the version in force from July 1, 2026 follows the superseded text in the section's entry.

Scope
§ 42-518Reference

Consumer Rights

Grants consumers rights to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of automated decisions that produce legal or similarly significant effects. The companion duty to honor opt-out preference signals (such as GPC), in force since January 1, 2025, sits in § 42-520, not here (subsection (c)(1)(A)(ii) since July 1, 2026). Since July 1, 2026, Public Act No. 25-113 has extended the profiling opt-out from 'solely automated' decisions to any automated decision that produces a legal or similarly significant effect. Where feasible, a consumer whose personal data were profiled for such a decision may also question the result, be told why the profiling led to the decision, and review the personal data used; for a housing decision, the consumer may also correct incorrect personal data and have the decision reevaluated. PA 25-113 also added rights to access inferences drawn about the consumer and to obtain a list of the third parties to which the controller has sold personal data. From October 1, 2026, Public Act No. 26-64 (S.B. 4) extends the right to delete to publicly available information that is (i) collated and combined into a consumer profile made available to users of a publicly accessible website, for compensation or free of charge, or (ii) made available for sale, along with any inference generated from that information. On the linked 2026 Supplement page, the July 1, 2026 version follows the superseded text in the section's entry; the PA 26-64 changes in force since October 1, 2026 are not yet printed there.

Consumer RightsOpt-OutGPC
§ 42-520Reference

Duties of Controllers

Requires data minimization, security safeguards, detailed privacy notices, and explicit consent for processing sensitive data. Also includes requirements for revoking consent, and carries the duty to honor opt-out preference signals (such as GPC), in force since January 1, 2025 (subsection (e)(1)(A)(ii) before July 1, 2026; (c)(1)(A)(ii) since). Since July 1, 2026, Public Act No. 25-113 has, among other changes, limited collection to what is reasonably necessary and proportionate, required the privacy notice to state whether the controller collects, uses or sells personal data to train large language models (LLMs), and barred controllers from selling a consumer's sensitive data without the consumer's consent. From October 1, 2026, Public Act No. 26-64 (S.B. 4) removes the 'material' qualifier from the purpose-limitation duty (so consent is required to process personal data for any new purpose that is neither reasonably necessary to nor compatible with the disclosed purposes) and bars controllers from selling a consumer's precise geolocation data; its § 15 adds a parallel ban on third parties to § 42-521. The facial-recognition signage and policy duties are not in this section: from October 1, 2026, Public Act No. 26-100 § 45 places them in § 42-524(a)(2), for on-premises use for security, fraud-prevention and similar purposes, with an exception where the consumer consented in the course of a commercial transaction. On the linked 2026 Supplement page, the July 1, 2026 version follows the superseded text in the section's entry; the PA 26-64 changes in force since October 1, 2026 are not yet printed there.

Privacy PolicyData CollectionConsentSensitive PI
§ 42-522Reference

Data Protection and Impact Assessments; Disclosure to Attorney General

Requires controllers to conduct and document a data protection assessment for each processing activity that presents a heightened risk of harm to a consumer, which the statute says includes targeted advertising, the sale of personal data, the processing of sensitive data, and profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact, financial, physical or reputational injury, an intrusion on seclusion or private affairs that a reasonable person would find offensive, or other substantial injury. Since July 1, 2026, Public Act No. 25-113 also requires a separate impact assessment for any profiling used to make a decision that produces a legal or similarly significant effect. To the extent reasonably known or available, it must cover the profiling's purpose, intended use cases, deployment context and benefits; any heightened risk of harm and the steps taken to mitigate it; input data categories and outputs; data used to customize the profiling; performance metrics and known limitations; transparency measures; and post-deployment monitoring and user safeguards. Impact assessments apply to processing activities created or generated on or after August 1, 2026, data protection assessments to those created or generated after July 1, 2023, and neither is retroactive. The Attorney General may require a controller to disclose either kind of assessment when relevant to an investigation, and both are confidential and exempt from the Freedom of Information Act. On the linked 2026 Supplement page, the version in force from July 1, 2026 follows the superseded text in the section's entry.

Data Protection AssessmentOpt-Out
§ 42-525Reference

Enforcement and Penalties

Vests enforcement authority exclusively in the Connecticut Attorney General; there is no private right of action. Each violation of sections 42-515 to 42-524, inclusive, or section 42-526 (consumer health data privacy) constitutes an unfair trade practice under the Connecticut Unfair Trade Practices Act (CUTPA), carrying civil penalties of up to $5,000 per willful violation, in addition to injunctive relief and restitution. The mandatory 60-day right to cure sunset on December 31, 2024, so the Attorney General may now bring an enforcement action at its discretion without first affording an opportunity to cure.

Enforcement

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit