Connecticut Data Privacy Act (CTDPA)
· About Connecticut Data Privacy Act (CTDPA)
Key Takeaways
- The Connecticut Data Privacy Act (CTDPA) applies to covered controllers that do business in Connecticut or target Connecticut residents and meet the statute’s applicability thresholds, which were significantly expanded by 2025 and 2026 amendments effective in 2026.[1][2]
- As of 1 July 2026, Connecticut lowered the consumer threshold to 35,000 consumers and removed the separate thresholds that previously turned on processing sensitive data or selling personal data, bringing more organizations into scope.[2][4]
- As of 1 July 2026, the law’s definition of sensitive data expanded to include additional government identifiers, financial-account elements, Social Security numbers, disability and treatment information, and non-binary or transgender status.[2][5]
- As of 1 October 2026, Connecticut’s amendments add restrictions on precise geolocation data, facial recognition, surveillance pricing, and direct-to-consumer genetic testing uses, with separate data-broker registration requirements phasing in later.[3][8]
- The Connecticut Attorney General enforces the CTDPA, and violations can be punished under the Connecticut Unfair Trade Practices Act with civil penalties of up to $5,000 per violation.[9]
- Connecticut gives covered consumers rights to access, correct, delete, obtain a copy of, and obtain portability for personal data, and it imposes privacy notice, consent, data-minimization, assessment, and appeals obligations on covered businesses.[1][9]
What It Is
The CTDPA is Connecticut’s comprehensive consumer privacy law, codified in Chapter 743jj of the Connecticut General Statutes, and it regulates how covered controllers collect, use, disclose, and sell personal data of Connecticut residents.[1][13] The law is enforced by the Connecticut Attorney General.[9]
The original CTDPA was enacted in 2022 and became operative in 2023, while later amendments substantially expanded the law in 2025 and 2026.[7][14] A major amendment enacted in June 2025 took effect on 1 July 2026, and another major amendment signed on 27 May 2026 takes effect on 1 October 2026.[1][3][4]
The law’s current phase-in matters because the 2026 amendments changed both who is covered and what conduct is restricted.[2][3] In practical terms, compliance programs must now be aligned to the pre-October 2026 rules as well as the new requirements that begin on 1 October 2026.[3][8]
Who Must Comply
The CTDPA applies to persons that do business in Connecticut or target products or services to Connecticut residents and, during the preceding calendar year, controlled or processed the personal data of at least 35,000 consumers (excluding data processed solely to complete a payment transaction), or offer consumers’ personal data for sale under the amended framework.[2][4] The 2026 amendments also made the law broader by eliminating prior alternative thresholds tied to sensitive-data processing and sale activity.[2][5]
The law has extraterritorial reach because it applies based on doing business in the state or targeting Connecticut residents, not only on physical presence in Connecticut.[2][14] That makes it relevant to out-of-state and online businesses that market into Connecticut or serve Connecticut residents at scale.[2][14]
The law includes exemptions for certain entity-level and data-level categories, but the 2025 amendments narrowed exemptions and expanded coverage in multiple areas.[6][14] Covered entities still need to analyze whether any specific statutory exemption applies before relying on it, because the amended law is materially broader than the original version.[6][14]
Core Requirements
- Consumer rights handling. Covered controllers must provide a process for consumers to exercise rights to access, correct, delete, and obtain a copy of personal data, and they must respond through a compliant appeals process when a request is denied.[1][9]
- Data minimization and purpose limitation. Controllers may collect only personal data that is adequate, relevant, and reasonably necessary for the disclosed purposes, and they must not process data for purposes that are not reasonably necessary or compatible without proper notice or consent.[14][6]
- Sensitive data protections. Processing sensitive data requires heightened controls, and the 2026 amendments expand what counts as sensitive data to include several additional identifiers and protected characteristics.[2][5]
- Privacy notices and disclosures. Covered businesses must provide a privacy notice that explains categories of data processed, purposes, consumer rights, how to appeal decisions, and, where applicable, whether personal data is used to train large language models.[5][9]
- Risk assessments. Controllers must conduct and document assessments for processing activities that present a heightened risk of harm, including profiling, targeted advertising, sales, and certain sensitive-data uses.[6][14]
- Minors’ data safeguards. The amended law adds stronger protections for minors, including limits on targeted advertising and sale of minors’ personal data.[5][6]
- Special-category restrictions beginning 1 October 2026. Connecticut adds rules for precise geolocation data, facial recognition transparency, surveillance pricing, data brokers, and DTC genetic testing companies, all of which require separate operational review.[3][8]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Original CTDPA effective date | 1 July 2023 | Baseline consumer rights, controller obligations, and enforcement regime begin.[13][14] | | 2025 amendment effective date | 1 July 2026 | Expanded scope, broader sensitive-data definition, stronger minors’ protections, and revised assessments take effect.[1][4][6] | | 2026 amendment effective date | 1 October 2026 | Precise geolocation, facial recognition, surveillance pricing, and genetic-data rules take effect.[3][8] | | Data broker registration phase-in | January 2027 | Registration obligations for the new data broker framework begin to phase in.[3] |
The Connecticut Attorney General states that violations may be punished with civil penalties of up to $5,000 per violation under the Connecticut Unfair Trade Practices Act.[9] The AG can also seek injunctive relief and other remedies available under that enforcement framework.[9]
How to Comply
- Map data flows and classify data. Build a current inventory of personal data, sensitive data, precise geolocation data, and any data used for profiling, targeted advertising, or model training; this is the foundation for CTDPA scoping and assessments.[2][5][6]
- Re-check scope against the amended thresholds. Recalculate applicability using the 35,000-consumer threshold and the broader “business in Connecticut or targets Connecticut residents” test, then document the conclusion.[2][4]
- Update notices and consumer-request workflows. Revise privacy notices, appeal instructions, response templates, and internal SLAs so access, correction, deletion, portability, and denial appeals are handled consistently.[1][9]
- Run risk assessments for high-risk processing. Align privacy impact assessments with ISO 27001 governance, NIST CSF 2.0 risk management, and, where AI systems are involved, ISO 42001 controls for AI governance and lifecycle oversight.[6][14]
- Tighten consent and sensitive-data controls. Separate sensitive-data collection, restrict use to disclosed purposes, and verify that downstream vendors do not broaden use without a lawful basis or required notice.[2][5]
- Implement minors, geolocation, and profiling safeguards. Add age-aware ad and sale restrictions, disable or gate precise geolocation sharing where required, and document profiling decision logic and challenge pathways for consumers.[3][5][6]
- Vendor and contract review. Re-paper processor and controller arrangements to reflect CTDPA duties, allocation of notices, assessment support, deletion/correction flow-downs, and restrictions on secondary use.[6][14]
- Prepare for the October 2026 and 2027 changes. Build a separate implementation track for the October 2026 amendments and the later data-broker registration obligations so the program is not surprised by the next phase-in.[3][8]
Related Regulations
Virginia Consumer Data Protection Act (VCDPA). Connecticut’s law is similar in structure but has expanded more aggressively in 2025–2026 on minors, geolocation, and AI-related disclosures, so multi-state programs cannot assume parity.[6][14]
Colorado Privacy Act (CPA). Colorado and Connecticut both require consumer rights handling and risk assessments, but Connecticut’s amended sensitive-data and special-category rules are more prescriptive in several areas.[6][14]
Utah Consumer Privacy Act (UCPA). Utah is narrower and generally lighter on controller obligations, so CTDPA compliance controls often exceed Utah requirements when deployed enterprise-wide.[14]
Texas Data Privacy and Security Act (TDPSA). Texas has comparable consumer rights and controller duties, but Connecticut’s 2026 amendments create additional topic-specific restrictions that may not exist in Texas.[6][14]
EU GDPR. GDPR remains the broader benchmark for rights and lawful-basis analysis, but CTDPA differs in scope, enforcement, and certain consent and profiling rules, so GDPR alignment is helpful but not sufficient.[6][14]
Does the CTDPA apply to companies outside Connecticut?
Yes, if the company does business in Connecticut or targets Connecticut residents and meets the applicable threshold or activity trigger under the amended law.[2][4] Physical presence in Connecticut is not required.[2][14] This is why out-of-state SaaS, e-commerce, and ad-tech companies often fall within scope.[2][14]
Does the CTDPA now cover more businesses than it did before 2026?
Yes. The 2026 amendments lowered the consumer threshold to 35,000 and removed the prior separate triggers for sensitive-data processing and personal-data sales.[2][5] That substantially broadens the number of organizations that must comply.[1][4]
What counts as sensitive data under the amended law?
The amended law expands sensitive data beyond the earlier categories to include additional government identifiers, financial-account-related elements, Social Security numbers, disability or treatment information, and non-binary or transgender status.[2][5] That broader definition raises the compliance burden for notice, consent, and risk assessment.[2][6]
When do the newest CTDPA changes take effect?
The major 2025 amendment took effect on 1 July 2026, and the 2026 amendment takes effect on 1 October 2026.[1][3][4] Some data-broker registration requirements phase in later, beginning in January 2027.[3]
What are the penalties for violating the CTDPA?
The Connecticut Attorney General says violators may face civil penalties of up to $5,000 per violation under the Connecticut Unfair Trade Practices Act.[9] The AG may also seek injunctive relief and other remedies available under that enforcement framework.[9]
Sources
- Connecticut Data Privacy Act overview — Connecticut Attorney General
- Updated report on the Connecticut Data Privacy Act — Connecticut Attorney General
- Connecticut General Statutes, Chapter 743jj — Data Privacy and Security
- Public Act No. 22-15 / 2022 CT privacy act text
- Snell & Wilmer, Connecticut Data Privacy Act: 2026 Amendments
- Wiley, Major Changes to Connecticut’s Consumer Privacy Law Will Take Effect July 1, 2026
- Proskauer, From Data Brokers to DNA: Connecticut Enacts Sweeping Privacy Amendments
- WilmerHale, Connecticut Amends Its Data Privacy Act to Increase Data Protections
Put it into practice
- Generate the policy: Connecticut CTDPA policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)