Skip to content

Connecticut Data Privacy Act (CTDPA): An Overview

Connecticut landscape with CTDPA badge
Resources / Blog / Connecticut Data Privacy Act (CTDPA): An Overview
Summary
  • The CTDPA took effect January 1, 2023; Public Act 25-113 (effective July 1, 2026) lowered the applicability threshold from 100,000 to 35,000 consumers and added no-threshold triggers for processing sensitive data or offering data for sale.
  • The definition of sensitive data now includes neural data, transgender or nonbinary status, disability-related data, government ID numbers, and certain financial account credentials.
  • Consumers ages 13–17 are now covered by an outright ban on targeted advertising and data sale for that age group, replacing the earlier consent-based approach for 13–15-year-olds.
  • New consumer rights cover automated profiling decisions, including the ability to question outcomes, review underlying data, and request a list of third parties personal data was sold to.
  • A second bill, SB 4, signed May 27, 2026, separately bans the sale of precise geolocation data and adds facial recognition disclosure, surveillance pricing, genetic testing, and data broker registration requirements, with effective dates staggered between October 1, 2026, and July 1, 2027.
  • Privacy notices must now disclose LLM-training use of personal data, and a new impact assessment requirement applies to certain profiling activities starting August 1, 2026.

Connecticut was the fifth U.S. state to pass a consumer privacy law, which has an effective date of July 1st, 2023. It is technically the “Personal Data Privacy and Online Monitoring Act”, but more broadly known as the Connecticut Data Privacy Act or CTDPA. The law shares the most similarities with Colorado’s CPA and Virginia’s CDPA, having a bit more of a “consumer-friendly” focus, as opposed to Utah’s more business-friendly law.

What Is the Connecticut Data Privacy Act?

The Connecticut Data Privacy Act (CTDPA) was signed into law on May 10th, 2022, giving companies doing business in the state less than two years to prepare for compliance by mid-2023. Legislators have remained active since, with multiple updates to the regulation having been passed since.

The law protects the privacy rights of residents of Connecticut and establishes data privacy responsibilities for companies doing business in the state (i.e. processing the data of Connecticut residents). The CTDPA applies to the sale of personal data, and defines a sale as: “the exchange of personal data for monetary or other valuable consideration by the controller to a third party.”

Like the laws in California and Colorado, the Connecticut privacy law includes language that a sale can also occur “in exchange for other valuable consideration”, i.e. not strictly direct monetary exchange.

Like the other U.S. state laws, the CTDPA uses an opt-out consent model in most circumstances, which means that personal data can be collected without requiring consumers’ consent, but individuals must be notified about data use and their rights and given the option to opt out of certain uses of their data. Additionally, consent must be obtained before the data can be sold (with some exceptions).

Definitions in the Connecticut Data Privacy Act

Before getting into obligations and consent mechanics, it’s worth pausing on terminology. The CTDPA, like most of its state counterparts, gives several ordinary words, such as “consumer,” “controller,” “sale,” a more precise legal meaning than one might assume, and getting these wrong tends to unravel compliance efforts further down the line.

Controllers and Processors

The CTDPA applies to “controllers” and “processors” of data, which is fairly standard language in consumer privacy laws. A controller is “an individual who, or legal entity that, alone or jointly with others determines the purposes and means of processing personal data”.

A processor is “an individual who, or legal entity that, processes personal data on behalf of a controller.” Personal data is: “any information that is linked or reasonably linkable to an identified or identifiable individual.”

While the law’s language refers to “a person”, for the most part compliance responsibilities will fall to companies and other organizations looking to sell personal data.

Consumer

A consumer, as defined by the law, refers to an individual who is a Connecticut resident acting as a private person. So individuals “acting in a commercial or employment context” are explicitly excluded, and any personal data collected in an employment or business to business relationship is not covered by the CTDPA.

Exclusions to the Definition of Personal Data

Under the Connecticut privacy law, the data that has been de-identified/anonymized and cannot reasonably be used to identify a person or infer identity, and the data that is publicly available are not classified as personal data.

Definition of Sensitive Personal Data

There is also a more granularly specified and more regulated category of personal data, classified as “sensitive”. It includes personal data that could reveal the following, or be used to cause harm based on these revelations:

  • Racial or ethnic origin
  • Religious beliefs
  • Mental or physical health condition or diagnosis
  • Sex life or sexual orientation
  • Citizenship or immigration status
  • Genetic or biometric data for the purpose of uniquely identifying an individual
  • Personal data collected from a known child
  • Precise geolocation data
  • Neural data generated by a consumer’s brain activity
  • Status as transgender or nonbinary
  • Data reflecting a disability or treatment for a disability
  • Government-issued identification numbers (e.g., driver’s license, passport, Social Security number)
  • Financial account numbers or credentials paired with a required access code or password

The requirements regarding neural data, transgender or nonbinary status, disabilities, government-issued IDs, and financial accounts were added as of July 1, 2026.

Personal Data of Children

The CTDPA takes its definition of “child” from the Children’s Online Privacy Protection Act (COPPA), referring to individuals under the age of 13. To comply with the CTDPA, controllers and processors must also comply with parental consent requirements outlined by COPPA.

However, under Connecticut’s privacy law, as of July 1, 2026, the protected age range expands to 13–17 from 13–15, and controllers face an outright prohibition — not merely a consent requirement — on targeted advertising and sale of personal data for consumers the controller has actual knowledge of, or willfully disregards, being at least 13 but under 18.

The CDTPA requires opt-in consent for collection and processing of sensitive data, so consent must be obtained before or at the time of collection. A consent management platform can enable controllers to obtain valid consent for the collection and processing of sensitive personal data. As of July 1, 2026, controllers must also obtain consumer consent before selling sensitive data, and processing sensitive data now carries an additional ‘reasonably necessary’ standard alongside the consent requirement.

Who Does the Connecticut Data Privacy Act Apply To?

Like Virginia and Colorado, the CTDPA does not have a revenue threshold. For example, by comparison, in California and Utah it’s USD 25 million annual gross revenue.

For Connecticut’s privacy law to apply, an organization has to:

  • Control or process the personal data of at least 35,000 consumers, excluding data processed solely to complete a payment transaction, or
  • Control or process consumers’ sensitive data (no volume threshold applies), or
  • Offer consumers’ personal data for sale (no volume threshold applies)

The number of consumers changed as of July 1, 2026, from 100,000 to 35, 000, and added the sensitive data and sale provisions, which have no volume threshold, replacing previous provisions.

Exemptions to Connecticut Data Privacy Act Compliance

Not every organization handling Connecticut residents’ data falls under the CTDPA’s purview, and the exemptions are worth knowing before assuming the statute applies in full. Some are entity-level, with entire sectors carved out, while others apply only to specific categories of data, which is a distinction well worth keeping straight.

Organizational Exemptions

The Connecticut data privacy law also exempts the following entities from compliance requirements:

  • state and local government entities
  • nonprofits
  • institutions of higher education
  • certain national security associations
  • financial institutions covered by the Gramm-Leach-Bliley Act (GLBA)
  • “covered entities” and “business associates” as defined under the Health Insurance Portability and Accountability Act (HIPAA)

In addition to HIPAA-related exceptions, organizations processing relevant kinds of data should familiarize themselves with additional health and life sciences-related exemptions outlined in the CTDPA.

Data Exemptions

In addition to the data exemptions for de-identified and publicly available data, or data collected and processed in the course of an employment or business relationship, data exemptions under the CTDPA also include data regulated under the following regulations:

  • Fair Credit Reporting Act (FCRA)
  • Driver’s Privacy Protection Act (DPPA)
  • Family Educational Rights and Privacy Act (FERPA)
  • Farm Credit Act (FCA)
  • Airline Deregulation Act (ADA)

Employment exemptions

Like Virginia and Utah, Connecticut exempts personal data processed or maintained:

  • In the course of an individual applying to, or acting as an employee, agent, or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role, or
  • As emergency contact information for an individual and used for emergency contact purposes, or
  • To administer benefits for another individual and used to administer those benefits

What Are the Consumer Rights Under the Connecticut Data Privacy Act?

As noted, the CTDPA is more “user-friendly” than Utah’s law, for example, and consumers residing there have more rights. There are some restrictions on these rights, however, for example relating to preventing the revelation of trade secrets.

  • Right of Access: Consumers can confirm whether a controller is processing their personal data and to have access to such data, with some exceptions
  • Right of Correction: Consumers can have inaccuracies in their collected personal data corrected, with some limitations
  • Right of Deletion: Consumers can have personal data that was provided by or about them deleted by the controller or processor
  • Right of Data Portability: Consumers can obtain a portable copy of their personal data, to a technically feasible extent and with some restrictions
  • Right of Opt-out: Consumers can opt out of the processing of their personal data for the purposes of:
    • Targeted advertising
    • Sale
    • Profiling in connection with automated decision-making that could have legal or comparably significant effects

As of July 1, 2026, consumers also have rights tied to covered automated profiling decisions with legal or similarly significant effect, including:

  • Right to question the outcome, be informed of the reasoning, review the data used, and in certain contexts correct that data and request reevaluation
  • Right to obtain a list of third parties to whom the controller has sold their personal data

The right to know and right to access now expressly extend to inferences drawn from personal data, and the opt-out right now covers covered profiling generally, not only solely automated decisions.

Controllers may no longer provide certain sensitive data categories (e.g., Social Security numbers, some financial data, biometric elements) in response to a consumer’s access request. They may only confirm that such data was collected.

Consumer Requests, Appeals, and Litigation

Under the CTDPA, controllers must respond to consumer requests within 45 days. This period can be extended by an additional 45-day period if “reasonably necessary”, for example if the controller has a high volume of requests or the consumer’s request is particularly complex.

Consumers also have the right to appeal controllers’ denials of their requests, which isn’t the case under all U.S. privacy laws. They also have the ability to designate another person as an authorized agent who can exercise their right to opt out on the consumer’s behalf.

Connecticut’s data privacy law does not provide consumers with private right of action (suing controllers in the case of a violation that affects them). To date, among the U.S. privacy laws, only California provides that right.

What Are Companies’ Obligations Under the Connecticut Data Privacy Act?

The CTDPA imposes a range of duties on data controllers, from transparency in privacy notices to the honoring of consumer rights requests. Consent, however, warrants particular attention, since the statute is notably precise about what will and will not count.

Connecticut does not leave “consent” to interpretation. The statute sets out specific conditions that must be met before it can be considered valid. The requirements below outline what businesses must get right.

Like the European Union’s General Data Protection Regulation (GDPR), the CTDPA requires consent to be “freely given, specific, informed and unambiguous”.

Consent must be obtained before processing sensitive personal data or the data of children. Where children’s data is concerned, consent must be obtained from a verifiable parent or legal guardian.

Consumer consent must first be obtained if a controller wants to process personal data for a purpose other than that communicated to consumers, or for a period of time longer than that communicated to consumers. As of October 1, 2026, this requirement no longer turns on whether the new purpose is ‘material.’ Consent is required before processing for any new purpose that is not reasonably necessary to, or compatible with, the originally disclosed purpose.

The CTDPA also explicitly excludes dark patterns in the definition of consent, i.e. if they are used, consent is not valid because it violates one or more of the requirements that consent needs to be freely given, specific, informed and unambiguous.

Controllers must provide consumers with a method to revoke their consent that is as accessible and easy to use as the method used to provide consent. If consent is revoked, the controller must cease processing the consumer’s personal data “as soon as practicable but no later than 15 days after receipt of the request.”

Transparency and Purpose Specification

Consumers must be provided with a “reasonably clear and meaningful” privacy notice that includes:

  • Categories of personal data processed
  • Purpose(s) of processing the data
  • Instructions to exercise consumers’ rights, including:
    • How to submit a rights-related request
    • How to appeal a rejection of a request
  • Categories of personal data shared with third parties
  • Online means of contact for the controller, e.g. email address

As of July 1, 2026, privacy notices must also disclose whether the controller uses or sells personal data to train large language models (LLMs) — the first state to introduce this requirement, with Vermont’s new law being the second — and are subject to new presentation requirements governing how the notice link is displayed and how retroactive material changes must be communicated.

Data Minimization

Controllers must limit collection of personal data to what is “adequate, relevant and reasonably necessary” for the disclosed processing purposes.

Avoid Secondary Use

Controllers may not process personal data for purposes that are “neither reasonably necessary to, nor compatible with, the disclosed purposes for which such personal data is processed”, unless consumers’ consent has been obtained prior to collection and processing.

Precise Geolocation Data

As of October 1, 2026, controllers and third parties are prohibited outright from selling a consumer’s precise geolocation data. This is defined as location data accurate to within a 1,750-foot radius, regardless of consent. Utility metering data is excluded from this prohibition.

Facial Recognition Technology

Controllers (and consumer health data controllers) using facial recognition technology for physical security or fraud-prevention purposes are now subject to new disclosure requirements under SB 4, effective October 1, 2026.

Surveillance Pricing Restrictions

SB 4 also introduces surveillance pricing restrictions, effective July 1, 2027, requiring any business using a ‘price setting device,’ defined as an automated process that uses a consumer’s personal data to set a price, to display the disclosure: ‘THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA,’ unless the device is used solely to offer a discount.

Security

Controllers must “establish, implement and maintain reasonable administrative, technical and physical data security practices to protect the confidentiality, integrity and accessibility of personal data.” These practices have to take the volume and nature of the personal data collected and processed into account. (Greater amounts of data or data of greater sensitivity should be subject to more stringent processes and protections.)

Nondiscrimination

Controllers are prohibited from discriminating against consumers for exercising their rights under Connecticut’s privacy law, or from violating other state or federal laws that prohibit unlawful discrimination against consumers.

The law does note that if a consumer opts out of processing, but that decision conflicts with their privacy settings or voluntary participation in a loyalty or rewards program, the controller may notify the consumer of the conflict and ask them to reconfirm their privacy setting or program participation.

Data Protection Assessment (DPA)

Controllers must conduct a data protection assessment for personal data processing activities that present “heightened risk of harm to a consumer.” These DPAs must identify and weigh risks and benefits of the processing to consumers, the controller, other stakeholders and the public at large. Activities of heightened risk include:

  • Processing personal data for targeted advertising
  • Selling personal data
  • Processing sensitive data
  • Processing personal data for profiling where it involves a foreseeable risk of:
    • Unfair or deceptive treatment or unlawful disparate impact on consumers
    • Financial, physical or reputational injury to consumers
    • Intrusion upon the solitude or seclusion or private affairs of consumers
    • Other substantial injury to consumers

If an investigation into an alleged violation is launched by the Connecticut Attorney General, the controller must provide the DPAs for compliance evaluation.

DPAs are not retroactive under the CTDPA, so will need to be created and maintained from July 1st, 2023 onward. However, similar to Virginia and Colorado, if the controller already creates DPAs to satisfy the requirements of another law, and the assessments are “reasonably similar,” then those pre-existing DPAs can be used to satisfy CTDPA requirements.

Impact Assessment

A separate impact assessment requirement now applies where a controller engages in any profiling used to make a decision producing a legal or similarly significant effect, applicable to processing activities created or generated on or after August 1, 2026.

Similar to the requirements of the CCPA/CPRA, if a controller sells personal data to third parties or processes it for targeted advertising, the controller must provide a “clear and conspicuous link” on their website that enables consumers to opt out of either of those activities. Exact text requirements for the link are not specified, but it would likely be similar to the CCPA/CPRA’s required “Do Not Sell or Share My Personal Information”.

As of January 1st, 2025, controllers must allow consumers to opt out of personal data collection to be used for targeted advertising, or the sale of their personal data, via an “opt-out preference signal”. Consumers would send this signal, which would include consent preference, via a platform, technology or mechanism like a consent management platform. The Global Privacy Control (GPC) is a prominent variant of this browser-based signal, and it is respected by the Usercentrics Consent Management Platform (CMP).

Similar to the requirements for valid consent, the CTDPA requires that this opt out signal must:

  • Rely on consumers’ affirmative unambiguous choice rather than a default setting
  • Not unfairly disadvantage another controller
  • Be consumer-friendly and easy to use
  • Be as consistent as possible with other similar mechanisms required by other laws
  • Enable the controller to accurately determine if a consumer is a resident of the state and thus making a legitimate opt out request

What Are the Penalties for Non-Compliance Under the Connecticut Data Privacy Act?

Enforcement is where the CTDPA’s recent amendments have the most bite, particularly given the expiry of the statutory cure period. Businesses weighing the risk of non-compliance will want a clear picture of who enforces the law, what penalties look like, and how much room (if any) remains to correct a violation before facing action.

Enforcement Authority

Under the CTDPA, the Attorney General has exclusive enforcement authority (as noted, there is no private right of action). Violations of the law are considered unfair trade practices under the Connecticut Unfair Trade Practices Act (CUTPA). As such, the Connecticut data privacy law does not outline specific penalties itself, financial or otherwise.

Penalties

Under the CUTPA, courts can impose civil penalties of up to USD 5,000 for willful violations and award actual and punitive damages, costs, and attorneys’ fees. Courts can also issue restraining orders, which could lead to a cease of data collection. Violation of a restraining order could result in a USD 25,000 penalty.

Cure Period and Sunsetting

From when the CTDPA comes into effect on July 1st, 2023, companies that are provided with a notice of alleged violation(s) will receive a 60-day cure period, if it is determined that a cure is possible, to enable them to stop and repair the violation. This cure period is twice as long as that under some other laws, like Utah’s. However, the provision of this cure period will only last from July 1st, 2023 to December 31st, 2024.

The CTDPA has a sunset provision, so as of January 1st, 2025, there will no longer be a right to cure. The Attorney General will no longer have to issue notice and provide 60 days to cure, though they will still have that option, with the decision based on:

  • Number of violations
  • Size and complexity of the controller or processor
  • Nature and extent of the controller’s or processor’s processing activities
  • Substantial likelihood of injury to the public
  • Safety of persons or property
  • Whether the alleged violation was likely caused by human or technical error

If the Attorney General decides not to provide notice and a cure period (e.g., for a particularly large or damaging violation), they can pursue penalties for the violation right away.

Violation Reporting

The Connecticut Attorney General has to submit a report to the Connecticut General Assembly (government) by February 1st, 2024, reporting on:

  • how many notices of violations were given
  • the nature of each violation
  • the amount cured
  • any other matter the Attorney General deems relevant

How the Connecticut Data Privacy Act Has Evolved

The Connecticut General Assembly convened a task force in September 2022 to study data privacy topics, including:

  • Information sharing among health care and social care providers to make recommendations aimed at eliminating health disparities and inequities across sectors
  • Algorithmic decision-making and recommendations to reduce related bias
  • The possibility of legislation on complying with parent deletion requests under COPPA
  • Age verification of children on social media
  • Data colocation issues
  • Possible expansion of CTDPA

The task force submitted its findings by January 1st, 2023, and several of the questions it raised have since been addressed through statute.

Algorithmic decision-making now carries dedicated profiling rights and impact assessment obligations under the July 2026 amendments (Public Act 25-113). Age verification and expanded protections for minors were likewise taken up in that same amendment package, which extended the CTDPA’s protected age range and converted its youth-data consent requirement into an outright prohibition.

Possible expansion of the CTDPA has, in the meantime, occurred twice over: first through PA 25-113, and second through SB 4, a separate bill signed May 27, 2026. SB 4 establishes a data broker registration and single-request deletion framework, with registration effective January 1, 2027, and certain other data broker requirements phasing in through 2031, and imposes new compliance requirements on direct-to-consumer genetic testing companies, effective October 1, 2026.

Given the pace of amendment since 2023, organizations should treat the CTDPA as a statute under active revision rather than a fixed compliance target, and confirm current requirements before relying on any given effective date.

The CTDPA requires obtaining consumers’ consent under more circumstances than some of the other state-level data privacy laws passed before it, particularly Utah’s.

Controllers must also notify consumers about data collection and processing under all circumstances on their websites, using a privacy notice/page. This enables the requirement that when consent is required, it be “freely given, specific, informed and unambiguous”.

Consent must be obtained before collection and processing of children’s data, sensitive data, if the controller wants to collect and process additional data beyond what they have provided notification about, or if the purpose for the data processing changes from what is stated.

Changing or revoking consent must also be as accessible and easily done as giving consent, and consumers can opt out of the processing of their data at any time for the purposes of targeted advertising, sale, or use of automated decision-making technologies.

A consent management platform like the Usercentrics CMP can enable compliance with the CTDPA for all of these requirements. It can help automatically populate a privacy policy and keep it up to date to help support accurate consumer notification. It can collect consent for the circumstances when it’s needed, and enable consumers to opt out of data processing. It can also work with preference signals like the GPC.

With geolocation services, different configurations of the CMP can be displayed to users in different places, enabling compliance with any or all of the U.S. state laws, and/or global ones like the GDPR.

How Usercentrics Supports Ongoing CTDPA Compliance

Many more states have enacted data privacy laws since Connecticut enacted the CTDPA, and updates to the law show the evolution of thought around data privacy, as well as consideration of rapidly changing technologies, consumer expectations, and global regulation.

The Connecticut General Assembly continues to the future, and has been (and will likely continue to be) among the most active with regards to updating the law to reflect current and future needs. Usercentrics Consent Management Platform (CMP) supports evolving privacy compliance requirements with automated scanning to detect changes in tracking technologies in use on websites, also automatically updating consent banners and privacy notices.

The CMP also updates automatically as regulatory requirements change, which saves time and resources, particularly with frequently updated regulations like the CTDPA, or as your business grows and compliance needs expand.

Is your website handling ongoing CTDPA requirements?

Usercentrics supports opt-in and opt-out consent workflows, opt-out signal detection, consent logs, and geotargeted configurations across U.S. state privacy laws. See it in action today.

William Newmark
Senior Legal Counsel, Usercentrics
Stay in the loop

Join our growing community of data privacy enthusiasts now. Subscribe to the Usercentrics newsletter and get the latest updates right in your inbox.