Connecticut SB 4 (2026) Privacy Amendments
Amends the CTDPA: defines facial recognition data, bars controllers and third parties from selling precise geolocation data, and extends deletion rights to collated public data and inferences.
| Jurisdiction | Connecticut |
|---|---|
| Category | Privacy & Data Protection |
| Status | Upcoming |
| Effective date | |
| Latest development |
Analysis
Connecticut SB 4 (2026) is a broad privacy update that amends the Connecticut Data Privacy Act (CTDPA) and adds new rules on facial recognition technology, precise geolocation data, publicly available information, and consumer deletion rights. The most commonly cited effective date for the CTDPA amendments is October 1, 2026. Connecticut Senate Democrats Wilson Sonsini Inside Privacy
Key Requirements
- Ban on selling precise geolocation data: SB 4 prohibits controllers and third parties from selling a consumer’s precise geolocation data. This is one of the clearest operational changes for adtech, mobile apps, location analytics, and data brokerage workflows. Wilson Sonsini CBIA Inside Privacy
- Facial recognition data and technology restrictions: SB 4 adds new CTDPA rules defining facial recognition technology and imposing compliance obligations where such technology is used, including for physical security contexts. Wilson Sonsini FastDemocracy bill tracking AI Docket bill page
- Expanded consumer deletion rights: SB 4 broadens deletion rights so consumers can seek deletion of certain publicly available information that is collated and combined into a consumer profile, and also deletion of inferences generated from that information. Inside Privacy Benesch Wilson Sonsini
- Revised treatment of publicly available information: SB 4 narrows what counts as publicly available information by excluding certain categories, including data combined with personal data, certain intimate or nonconsensual images, and other specified data categories. Inside Privacy Benesch Regulayer summary
- Purpose limitation expansion: SB 4 removes the “material” qualifier from the CTDPA’s purpose-limitation concept, so controllers need consent for processing for any new purpose that is not reasonably necessary or compatible with the original purpose. Wilson Sonsini Benesch Inside Privacy
- Other privacy-program changes: SB 4 is part of a larger Connecticut privacy package that also added data broker registration, a deletion mechanism, surveillance-pricing rules, and genetic-data protections. Inside Privacy Wilson Sonsini CBIA
Compliance Challenges
- Identifying precise geolocation data across systems: Organizations often store location data in ad SDKs, analytics logs, CRM enrichments, and vendor datasets, making it difficult to determine where precise geolocation is collected, shared, or sold. The Connecticut ban raises cross-functional compliance issues across product, marketing, and vendor-management teams. Wilson Sonsini CBIA Inside Privacy
- Rebuilding deletion workflows for collated public data: Expanding deletion rights to profiles built from public data means companies may need to trace derived datasets, downstream recipients, and inference layers rather than deleting only source records. This is especially difficult for brokers and data-enrichment vendors. Inside Privacy Benesch Wilson Sonsini
- Inventorying facial-recognition use cases: Many organizations deploy biometric or computer-vision tools through third parties without treating them as regulated facial-recognition processing. SB 4 makes it necessary to identify where facial recognition is used for security, access control, monitoring, or identity verification. Wilson Sonsini FastDemocracy bill tracking AI Docket bill page
- Vendor contract remediation: Controllers must ensure processors and third parties are not engaged in prohibited sales or incompatible secondary uses, which usually requires updating DPAs, ad-tech contracts, and data-sharing terms. Inside Privacy Wilson Sonsini CBIA
- Governance complexity around derived data: Inferences and compiled public profiles are often stored in scoring engines and risk models, so compliance teams must map not only raw data but also downstream model outputs and segmentation logic. Inside Privacy Benesch
- Example industry concern: adtech and data brokerage: Connecticut business groups and privacy commentators have highlighted that the law materially affects businesses that sell or license consumer data and use location-based advertising or enrichment products. CBIA CBIA Inside Privacy
Implementation Best Practices
- Create a data map focused on location, biometric, and derived data: Inventory where precise geolocation, facial-recognition outputs, public-source enrichment, and inferences are collected, stored, transferred, sold, or shared. Mapping should include vendors and downstream recipients. NIST Privacy Framework NIST AI Risk Management Framework Inside Privacy
- Implement a location-data prohibition control: Block sale pathways for precise geolocation data at the source, in data pipelines, and in third-party sharing agreements. Add automated checks in tagging, consent, and vendor-routing logic. Inside Privacy Wilson Sonsini CBIA
- Update deletion and DSAR workflows: Expand deletion procedures to cover collated public data, derived profiles, and inferences. Ensure requests propagate to vendors and data brokers with documented acknowledgment and completion SLAs. NIST Privacy Framework Inside Privacy Benesch
- Run a facial-recognition impact review: For any physical-security or identity-related use, document purpose, necessity, data retention, vendor roles, accuracy considerations, and signage/notice obligations. A DPIA-style review aligns well with privacy engineering practice. NIST AI RMF Playbook NIST Privacy Framework Wilson Sonsini
- Revise contracts and procurement controls: Add representations that vendors will not sell precise geolocation data, will support deletion of derived public profiles, and will notify you of any facial-recognition or secondary-use issues. NIST Privacy Framework Inside Privacy CBIA
- Use privacy-by-design templates and registers: Maintain RoPA-style records, high-risk processing reviews, and a change-management log for new purposes and new data uses. ICO Data Protection Impact Assessments guidance NIST Privacy Framework NIST AI RMF
- Tools and resources:
- NIST Privacy Framework for governance, risk mapping, and control selection.
- NIST AI Risk Management Framework for facial-recognition and other AI-related risk management.
- NIST AI RMF Playbooks for implementation guidance.
- FTC Privacy guidance for U.S. privacy program alignment.
- IAPP Connecticut privacy law coverage for implementation commentary and tracking.
Recent Updates
- SB 4 was signed in 2026 and is widely reported as amending the CTDPA in a package that also includes related privacy and data-broker provisions. Inside Privacy Wilson Sonsini CBIA
- CTDPA amendment effective date: October 1, 2026. This is the principal compliance date reported for the CTDPA amendments, including the geolocation and facial-recognition changes. Inside Privacy Wilson Sonsini Benesch
- Data broker registration takes effect January 1, 2027 in the broader Connecticut privacy package. That creates a later operational deadline for broker-facing compliance work. Inside Privacy Wilson Sonsini
- Reported scope of updates includes precise geolocation sales, publicly available information definitions, deletion rights, facial-recognition requirements, and purpose-limitation changes. Inside Privacy Benesch Wilson Sonsini
Related Regulations
- Connecticut Data Privacy Act (CTDPA): SB 4 directly amends the existing state privacy law, so all CTDPA concepts remain relevant, including controller/processor duties, consumer rights, and enforcement structure. Connecticut General Assembly Attorney General of Connecticut Inside Privacy
- Virginia Consumer Data Protection Act (VCDPA) and other state privacy laws: Connecticut’s changes track broader U.S. state-privacy themes such as sensitive data handling, profiling, opt-outs, and purpose limitation. Businesses operating nationally should harmonize controls across states rather than build Connecticut-only workflows. NCSL privacy overview FTC privacy guidance NIST Privacy Framework
- Illinois Biometric Information Privacy Act (BIPA): Facial-recognition and biometric controls in Connecticut may overlap with BIPA obligations if an organization processes Illinois residents’ biometric data. Illinois General Assembly BIPA text FTC privacy guidance NIST AI RMF
- General Data Protection Regulation (GDPR): If Connecticut-covered organizations also handle EU data, the same data inventories, deletion workflows, and purpose limitation controls can support GDPR compliance, though the legal tests differ. EU GDPR text ICO DPIA guidance NIST Privacy Framework
- FTC Act / privacy enforcement: Even where Connecticut is the governing statute, unfair or deceptive data practices may also trigger FTC scrutiny, especially around inaccurate disclosures about data sales, location tracking, or biometric use. FTC privacy guidance FTC section on deceptive practices NIST Privacy Framework
Industry Impact
- Adtech and location-based advertising: The precise-geolocation sale ban is likely to reduce monetization options for mobile ad networks, SDK providers, and location-data marketplaces serving Connecticut residents. CBIA Inside Privacy Wilson Sonsini
- Data brokers and enrichment vendors: Expanded deletion rights for coll
Recent developments
- — Connecticut Governor Ned Lamont signed SB 4 into law on May 27, 2026, establishing a **data broker registration program** and amending the Connecticut Data Privacy Act (CTDPA) to **prohibit the sale of precise geolocation data**, with key amendments taking effect on October 1, 2026.[4] (source)
- — SB 4, effective October 1, 2026, adds a **geolocation sales ban**, **data broker registration**, **surveillance pricing restrictions**, **facial recognition rules**, and **genetic data protections**, marking a substantial expansion of Connecticut’s privacy framework and tightening consent requirements for new processing purposes.[1] (source)
- — A July 2026 analysis highlights that SB 4 amends the CTDPA to **ban sale of precise geolocation data**, add **facial recognition requirements**, **redefine “publicly available information”**, expand **deletion rights**, and **remove the materiality threshold** from purpose limitation, with amendments effective October 1, 2026.[5] (source)
- — Coverage of Connecticut’s omnibus privacy law explains that SB 4 updates CTDPA definitions of **publicly available information**, broadens **consumer deletion rights**, removes the “material” qualifier from purpose limitation, and introduces rules for **data brokers**, **surveillance pricing**, and **genetic testing companies**, with staggered effective dates starting October 1, 2026.[2] (source)
- — A detailed commentary notes that SB 4 was passed by wide margins in both chambers and simultaneously **requires registration for businesses selling or licensing personal data**, builds a **single deletion mechanism**, **bans surveillance pricing**, and **rewrites rules on facial recognition, geolocation, and genetic data**, with most provisions operative October 1, 2026 and phased rollout for broker/deletion infrastructure.[6] (source)
- — The bill-tracking page for Connecticut SB 4 (2026 session) lists the core statutory purposes: creating a **data broker registry**, a **state-run accessible deletion mechanism**, algorithmic **pricing disclosures**, CTDPA amendments including **facial recognition technology definition and requirements**, and a **ban on sale, sharing, transfer or allowing access to precise geolocation data**, along with restrictions on automated license plate reader data.[9] (source)
- — An industry-focused privacy blog describes SB 4 (now **Public Act 26-64**) as a major CTDPA expansion, adding a **state-administered data broker registry**, a **Department of Consumer Protection deletion mechanism**, **surveillance-pricing disclosure and retail restrictions**, **facial recognition signage and policy duties**, **direct-to-consumer genetic-testing protections**, and an **outright prohibition on selling precise geolocation data**, with most amendments effective October 1, 2026 and broker duties from January 1, 2027.[7] (source)
- — The Connecticut Business & Industry Association (CBIA) warns that SB 4’s privacy law expansion has **major business implications**, significantly increasing oversight of **data brokers**, enabling **data delete mechanisms** for consumers, restricting **surveillance and automated pricing**, and tightening CTDPA rules on consent, access, correction, deletion, and opt-out rights.[10] (source)
- — Consumer Reports issued a statement applauding SB 4 as a **consumer-protective package bill** that **prohibits sale of precise geolocation data**, allows residents to **delete their information from registered data brokers via a single mechanism**, and **limits personalized pricing**, positioning Connecticut as a leader in privacy and surveillance-pricing protections.[11] (source)
- — A CBIA article on the Senate’s advancement of the data privacy bill describes SB 4 as **far-reaching**, imposing new regulatory obligations on **data brokers**, restricting **surveillance-based pricing**, and establishing additional statutory requirements for **biometric, genetic, and location data**, including a **centralized deletion mechanism** for consumers’ data held by registered brokers.[3] (source)
Related regulations
- UK Data Protection Act 2018 — United Kingdom, Active
- Texas Data Privacy and Security Act (TDPSA) — Texas, Active, effective 2024-07-01
- General Data Protection Law (LGPD) — Brazil, Active, effective 2020-09-18
- COPPA (Children's Online Privacy Protection Act) — United States, Active
- Oregon Consumer Privacy Act (OCPA) — Oregon, Active, effective 2024-07-01
- Montana Consumer Data Privacy Act (MCDPA) — Montana, Active, effective 2024-10-01
- New Hampshire Privacy Act (NHPA) — New Hampshire, Active, effective 2025-01-01
- Nebraska Data Privacy Act (NDPA) — Nebraska, Active, effective 2025-01-01
Put it into practice
- Generate the policy: Connecticut CTDPA policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates