CTDPA § 42-520

Duties of Controllers

Reference only. The Privisy audit does not test this section.

Source
Statute
In force from
October 1, 2026
Last reviewed
October 2026
Framework
CTDPA

What it requires

Requires data minimization, security safeguards, detailed privacy notices, and explicit consent for processing sensitive data. Also includes requirements for revoking consent, and carries the duty to honor opt-out preference signals (such as GPC), in force since January 1, 2025 (subsection (e)(1)(A)(ii) before July 1, 2026; (c)(1)(A)(ii) since). Since July 1, 2026, Public Act No. 25-113 has, among other changes, limited collection to what is reasonably necessary and proportionate, required the privacy notice to state whether the controller collects, uses or sells personal data to train large language models (LLMs), and barred controllers from selling a consumer's sensitive data without the consumer's consent. From October 1, 2026, Public Act No. 26-64 (S.B. 4) removes the 'material' qualifier from the purpose-limitation duty (so consent is required to process personal data for any new purpose that is neither reasonably necessary to nor compatible with the disclosed purposes) and bars controllers from selling a consumer's precise geolocation data; its § 15 adds a parallel ban on third parties to § 42-521. The facial-recognition signage and policy duties are not in this section: from October 1, 2026, Public Act No. 26-100 § 45 places them in § 42-524(a)(2), for on-premises use for security, fraud-prevention and similar purposes, with an exception where the consumer consented in the course of a commercial transaction. On the linked 2026 Supplement page, the July 1, 2026 version follows the superseded text in the section's entry; the PA 26-64 changes in force since October 1, 2026 are not yet printed there.

Statute text

(a)(1) A controller shall: (A) Limit the collection of personal data to what is reasonably necessary and proportionate in relation to the purposes for which such data are processed, as disclosed to the consumer; [...] (D) not process sensitive data concerning a consumer unless such processing is reasonably necessary in relation to the purposes for which such sensitive data are processed and without obtaining the consumer's consent [...] (H) not sell the sensitive data of a consumer without the consumer's consent [...] (c) (1) A controller shall establish one or more secure and reliable means for consumers to submit a request to exercise their consumer rights [...] Any such means shall include: (A) [...] (ii) Allowing a consumer to opt out of any processing of the consumer's personal data for the purposes of targeted advertising, or any sale of such personal data, through an opt-out preference signal sent, with such consumer's consent, by a platform, technology or mechanism to the controller indicating such consumer's intent to opt out of any such processing or sale.

Connecticut Data Privacy Act, § 42-520Read the full section from Connecticut Office of the Attorney General

This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit