CTDPA § 42-522
Data Protection and Impact Assessments; Disclosure to Attorney General
Reference only. The Privisy audit does not test this section.
- Source
- Statute
- In force from
- July 1, 2026
- Last reviewed
- September 2026
- Framework
- CTDPA
What it requires
Requires controllers to conduct and document a data protection assessment for each processing activity that presents a heightened risk of harm to a consumer, which the statute says includes targeted advertising, the sale of personal data, the processing of sensitive data, and profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact, financial, physical or reputational injury, an intrusion on seclusion or private affairs that a reasonable person would find offensive, or other substantial injury. Since July 1, 2026, Public Act No. 25-113 also requires a separate impact assessment for any profiling used to make a decision that produces a legal or similarly significant effect. To the extent reasonably known or available, it must cover the profiling's purpose, intended use cases, deployment context and benefits; any heightened risk of harm and the steps taken to mitigate it; input data categories and outputs; data used to customize the profiling; performance metrics and known limitations; transparency measures; and post-deployment monitoring and user safeguards. Impact assessments apply to processing activities created or generated on or after August 1, 2026, data protection assessments to those created or generated after July 1, 2023, and neither is retroactive. The Attorney General may require a controller to disclose either kind of assessment when relevant to an investigation, and both are confidential and exempt from the Freedom of Information Act. On the linked 2026 Supplement page, the version in force from July 1, 2026 follows the superseded text in the section's entry.
Statute text
(a) For the purposes of this section, processing that presents a heightened risk of harm to a consumer includes: (1) The processing of personal data for the purposes of targeted advertising; (2) the sale of personal data; (3) the processing of personal data for the purposes of profiling, where such profiling presents a reasonably foreseeable risk of (A) unfair or deceptive treatment of, or unlawful disparate impact on, consumers, (B) financial, physical or reputational injury to consumers, (C) a physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where such intrusion would be offensive to a reasonable person, or (D) other substantial injury to consumers; and (4) the processing of sensitive data. (b) (1) A controller shall conduct and document a data protection assessment for each of the controller's processing activities that presents a heightened risk of harm to a consumer. [...] (c) Each controller that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer shall conduct an impact assessment for such profiling.
Connecticut Data Privacy Act, § 42-522Read the full section from Connecticut Office of the Attorney General
This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.