Duties of Controllers
Reference only: This requirement is not currently tested by the Privisy scanner. It is included for reference. Consult a qualified attorney to assess your compliance posture.
What it requires
Requires data minimization, security safeguards, detailed privacy notices, and explicit consent for processing sensitive data. Also includes requirements for revoking consent. Effective July 1, 2026, Public Act No. 25-113 adds two obligations: the privacy notice must disclose whether the controller uses or sells personal data to train large language models (LLMs), and controllers may not sell a consumer's sensitive data without first obtaining the consumer's consent.
Legal text (excerpt)
A controller shall: (1) Limit the collection of personal data to what is adequate, relevant and reasonably necessary... (3) Not process sensitive data... without obtaining the consumer's consent...
Primary source
Connecticut Office of the Attorney General: § 42-520: Duties of Controllers ↗Legal notice: This page is for informational purposes only and does not constitute legal advice. The legal text excerpt is reproduced from official public sources and is current as of the stated effective date. Laws change: verify against the authoritative source and consult a licensed attorney for compliance guidance.