Connecticut SB 4 (2026) Privacy Amendments

Amends the CTDPA: defines facial recognition data, bars controllers and third parties from selling precise geolocation data, and extends deletion rights to collated public data and inferences.

JurisdictionConnecticut
CategoryPrivacy & Data Protection
StatusUpcoming
Effective date
Latest development

Analysis

Connecticut SB 4 (2026) is a broad privacy update that amends the Connecticut Data Privacy Act (CTDPA) and adds new rules on facial recognition technology, precise geolocation data, publicly available information, and consumer deletion rights. The most commonly cited effective date for the CTDPA amendments is October 1, 2026. Connecticut Senate Democrats Wilson Sonsini Inside Privacy

Key Requirements

  • Ban on selling precise geolocation data: SB 4 prohibits controllers and third parties from selling a consumer’s precise geolocation data. This is one of the clearest operational changes for adtech, mobile apps, location analytics, and data brokerage workflows. Wilson Sonsini CBIA Inside Privacy
  • Expanded consumer deletion rights: SB 4 broadens deletion rights so consumers can seek deletion of certain publicly available information that is collated and combined into a consumer profile, and also deletion of inferences generated from that information. Inside Privacy Benesch Wilson Sonsini
  • Revised treatment of publicly available information: SB 4 narrows what counts as publicly available information by excluding certain categories, including data combined with personal data, certain intimate or nonconsensual images, and other specified data categories. Inside Privacy Benesch Regulayer summary
  • Purpose limitation expansion: SB 4 removes the “material” qualifier from the CTDPA’s purpose-limitation concept, so controllers need consent for processing for any new purpose that is not reasonably necessary or compatible with the original purpose. Wilson Sonsini Benesch Inside Privacy
  • Other privacy-program changes: SB 4 is part of a larger Connecticut privacy package that also added data broker registration, a deletion mechanism, surveillance-pricing rules, and genetic-data protections. Inside Privacy Wilson Sonsini CBIA

Compliance Challenges

  • Identifying precise geolocation data across systems: Organizations often store location data in ad SDKs, analytics logs, CRM enrichments, and vendor datasets, making it difficult to determine where precise geolocation is collected, shared, or sold. The Connecticut ban raises cross-functional compliance issues across product, marketing, and vendor-management teams. Wilson Sonsini CBIA Inside Privacy
  • Rebuilding deletion workflows for collated public data: Expanding deletion rights to profiles built from public data means companies may need to trace derived datasets, downstream recipients, and inference layers rather than deleting only source records. This is especially difficult for brokers and data-enrichment vendors. Inside Privacy Benesch Wilson Sonsini
  • Inventorying facial-recognition use cases: Many organizations deploy biometric or computer-vision tools through third parties without treating them as regulated facial-recognition processing. SB 4 makes it necessary to identify where facial recognition is used for security, access control, monitoring, or identity verification. Wilson Sonsini FastDemocracy bill tracking AI Docket bill page
  • Vendor contract remediation: Controllers must ensure processors and third parties are not engaged in prohibited sales or incompatible secondary uses, which usually requires updating DPAs, ad-tech contracts, and data-sharing terms. Inside Privacy Wilson Sonsini CBIA
  • Governance complexity around derived data: Inferences and compiled public profiles are often stored in scoring engines and risk models, so compliance teams must map not only raw data but also downstream model outputs and segmentation logic. Inside Privacy Benesch
  • Example industry concern: adtech and data brokerage: Connecticut business groups and privacy commentators have highlighted that the law materially affects businesses that sell or license consumer data and use location-based advertising or enrichment products. CBIA CBIA Inside Privacy

Implementation Best Practices

  • Create a data map focused on location, biometric, and derived data: Inventory where precise geolocation, facial-recognition outputs, public-source enrichment, and inferences are collected, stored, transferred, sold, or shared. Mapping should include vendors and downstream recipients. NIST Privacy Framework NIST AI Risk Management Framework Inside Privacy
  • Implement a location-data prohibition control: Block sale pathways for precise geolocation data at the source, in data pipelines, and in third-party sharing agreements. Add automated checks in tagging, consent, and vendor-routing logic. Inside Privacy Wilson Sonsini CBIA
  • Update deletion and DSAR workflows: Expand deletion procedures to cover collated public data, derived profiles, and inferences. Ensure requests propagate to vendors and data brokers with documented acknowledgment and completion SLAs. NIST Privacy Framework Inside Privacy Benesch
  • Run a facial-recognition impact review: For any physical-security or identity-related use, document purpose, necessity, data retention, vendor roles, accuracy considerations, and signage/notice obligations. A DPIA-style review aligns well with privacy engineering practice. NIST AI RMF Playbook NIST Privacy Framework Wilson Sonsini
  • Revise contracts and procurement controls: Add representations that vendors will not sell precise geolocation data, will support deletion of derived public profiles, and will notify you of any facial-recognition or secondary-use issues. NIST Privacy Framework Inside Privacy CBIA

Recent Updates

  • SB 4 was signed in 2026 and is widely reported as amending the CTDPA in a package that also includes related privacy and data-broker provisions. Inside Privacy Wilson Sonsini CBIA
  • CTDPA amendment effective date: October 1, 2026. This is the principal compliance date reported for the CTDPA amendments, including the geolocation and facial-recognition changes. Inside Privacy Wilson Sonsini Benesch
  • Data broker registration takes effect January 1, 2027 in the broader Connecticut privacy package. That creates a later operational deadline for broker-facing compliance work. Inside Privacy Wilson Sonsini
  • Reported scope of updates includes precise geolocation sales, publicly available information definitions, deletion rights, facial-recognition requirements, and purpose-limitation changes. Inside Privacy Benesch Wilson Sonsini

Related Regulations

  • Virginia Consumer Data Protection Act (VCDPA) and other state privacy laws: Connecticut’s changes track broader U.S. state-privacy themes such as sensitive data handling, profiling, opt-outs, and purpose limitation. Businesses operating nationally should harmonize controls across states rather than build Connecticut-only workflows. NCSL privacy overview FTC privacy guidance NIST Privacy Framework
  • General Data Protection Regulation (GDPR): If Connecticut-covered organizations also handle EU data, the same data inventories, deletion workflows, and purpose limitation controls can support GDPR compliance, though the legal tests differ. EU GDPR text ICO DPIA guidance NIST Privacy Framework

Industry Impact

  • Adtech and location-based advertising: The precise-geolocation sale ban is likely to reduce monetization options for mobile ad networks, SDK providers, and location-data marketplaces serving Connecticut residents. CBIA Inside Privacy Wilson Sonsini
  • Data brokers and enrichment vendors: Expanded deletion rights for coll

Recent developments

  • — Connecticut Governor Ned Lamont signed SB 4 into law on May 27, 2026, establishing a **data broker registration program** and amending the Connecticut Data Privacy Act (CTDPA) to **prohibit the sale of precise geolocation data**, with key amendments taking effect on October 1, 2026.[4] (source)
  • — SB 4, effective October 1, 2026, adds a **geolocation sales ban**, **data broker registration**, **surveillance pricing restrictions**, **facial recognition rules**, and **genetic data protections**, marking a substantial expansion of Connecticut’s privacy framework and tightening consent requirements for new processing purposes.[1] (source)
  • — A July 2026 analysis highlights that SB 4 amends the CTDPA to **ban sale of precise geolocation data**, add **facial recognition requirements**, **redefine “publicly available information”**, expand **deletion rights**, and **remove the materiality threshold** from purpose limitation, with amendments effective October 1, 2026.[5] (source)
  • — Coverage of Connecticut’s omnibus privacy law explains that SB 4 updates CTDPA definitions of **publicly available information**, broadens **consumer deletion rights**, removes the “material” qualifier from purpose limitation, and introduces rules for **data brokers**, **surveillance pricing**, and **genetic testing companies**, with staggered effective dates starting October 1, 2026.[2] (source)
  • — A detailed commentary notes that SB 4 was passed by wide margins in both chambers and simultaneously **requires registration for businesses selling or licensing personal data**, builds a **single deletion mechanism**, **bans surveillance pricing**, and **rewrites rules on facial recognition, geolocation, and genetic data**, with most provisions operative October 1, 2026 and phased rollout for broker/deletion infrastructure.[6] (source)
  • — The bill-tracking page for Connecticut SB 4 (2026 session) lists the core statutory purposes: creating a **data broker registry**, a **state-run accessible deletion mechanism**, algorithmic **pricing disclosures**, CTDPA amendments including **facial recognition technology definition and requirements**, and a **ban on sale, sharing, transfer or allowing access to precise geolocation data**, along with restrictions on automated license plate reader data.[9] (source)
  • — An industry-focused privacy blog describes SB 4 (now **Public Act 26-64**) as a major CTDPA expansion, adding a **state-administered data broker registry**, a **Department of Consumer Protection deletion mechanism**, **surveillance-pricing disclosure and retail restrictions**, **facial recognition signage and policy duties**, **direct-to-consumer genetic-testing protections**, and an **outright prohibition on selling precise geolocation data**, with most amendments effective October 1, 2026 and broker duties from January 1, 2027.[7] (source)
  • — The Connecticut Business & Industry Association (CBIA) warns that SB 4’s privacy law expansion has **major business implications**, significantly increasing oversight of **data brokers**, enabling **data delete mechanisms** for consumers, restricting **surveillance and automated pricing**, and tightening CTDPA rules on consent, access, correction, deletion, and opt-out rights.[10] (source)
  • — Consumer Reports issued a statement applauding SB 4 as a **consumer-protective package bill** that **prohibits sale of precise geolocation data**, allows residents to **delete their information from registered data brokers via a single mechanism**, and **limits personalized pricing**, positioning Connecticut as a leader in privacy and surveillance-pricing protections.[11] (source)
  • — A CBIA article on the Senate’s advancement of the data privacy bill describes SB 4 as **far-reaching**, imposing new regulatory obligations on **data brokers**, restricting **surveillance-based pricing**, and establishing additional statutory requirements for **biometric, genetic, and location data**, including a **centralized deletion mechanism** for consumers’ data held by registered brokers.[3] (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates