{"id":375,"date":"2022-12-16T07:42:15","date_gmt":"2022-12-16T06:42:15","guid":{"rendered":"https:\/\/stage.usercentrics.com\/?post_type=knowledge&#038;p=28421"},"modified":"2025-06-26T13:20:49","modified_gmt":"2025-06-26T11:20:49","slug":"connecticut-data-privacy-act-ctdpa","status":"publish","type":"knowledge","link":"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/","title":{"rendered":"Connecticut Data Privacy Act (CTDPA): An Overview"},"content":{"rendered":"\n\n<h2 class=\"wp-block-heading\">Introduction to the Connecticut Data Privacy Act<\/h2>\n<p>Connecticut was the fifth US state to pass a consumer privacy law, which has an effective date of July 1st, 2023. It is technically the \u201cPersonal Data Privacy and Online Monitoring Act\u201d, but more broadly known as the Connecticut Data Privacy Act or CTDPA. The law shares the most similarities with <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/colorado-privacy-act\/\">Colorado\u2019s CPA<\/a> and <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/virginia-consumer-data-protection-act-vcdpa\/\">Virginia&#8217;s CDPA<\/a>, having a bit more of a \u201cconsumer-friendly\u201d focus, as opposed to Utah\u2019s more business-friendly law.<\/p>\n\n\n<h2 class=\"wp-block-heading\">What is the Connecticut Data Privacy Act?<\/h2>\n<p>The Connecticut Data Privacy Act (<a href=\"https:\/\/www.cga.ct.gov\/2022\/act\/Pa\/pdf\/2022PA-00015-R00SB-00006-PA.PDF\" target=\"_blank\" rel=\"noopener\">CTDPA<\/a>) was signed into law on May 10th, 2022, giving companies doing business in the state less than two years to prepare for compliance by mid-2023. The law protects the privacy rights of residents of Connecticut and establishes data privacy responsibilities for companies doing business in the state (i.e. processing the data of Connecticut residents).<\/p>\n<p>The CTDPA applies to the sale of personal data, and defines a sale as: <em>\u201cthe exchange of personal data for monetary or other valuable consideration by the controller to a third party.\u201d<\/em><\/p>\n<p>Like the CCPA and CPA, but unlike Utah, the Connecticut privacy law includes language that a sale can also occur <em>\u201cin exchange for other valuable consideration\u201d<\/em>, i.e. not strictly direct monetary exchange.<\/p>\n<p>Additionally, unlike California\u2019s Privacy Rights Act (<a href=\"\/knowledge-hub\/california-privacy-rights-act-cpra-enforcement-begins\/\">CPRA<\/a>), Connecticut\u2019s law does not apply to the sharing of data.<\/p>\n<p>Like the other US state laws, the CTDPA uses an opt-out model, which means that personal data can be collected without requiring consumers\u2019 consent, but consent must be obtained before the data can be sold (with some exceptions).<\/p>\n<h4>Definitions in the Connecticut Data Privacy Act<\/h4>\n<p>The CTDPA applies to \u201ccontrollers\u201d and \u201cprocessors\u201d of data, which is fairly standard language in consumer privacy laws. A controller is <em>\u201can individual who, or legal entity that, alone or jointly with others determines the purposes and means of processing personal data\u201d<\/em>.<\/p>\n<p>A processor is <em>\u201can individual who, or legal entity that, processes personal data on behalf of a controller.\u201d<\/em> Personal data is: <em>\u201cany information that is linked or reasonably linkable to an identified or identifiable individual.\u201d<\/em><\/p>\n<p>While the law\u2019s language refers to \u201ca person\u201d, for the most part compliance responsibilities will fall to companies and other organizations looking to sell personal data.<\/p>\n<p>A consumer, as defined by the law, refers to an individual who is a Connecticut resident acting as a private person. So individuals <em>\u201cacting in a commercial or employment context\u201d<\/em> are explicitly excluded, and any personal data collected in an employment or business to business relationship is not covered by the CTDPA.<\/p>\n<p><strong>Exclusions to the definition of personal data<\/strong><\/p>\n<p>Under the Connecticut privacy law, the data that has been <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/data-anonymization\/\">de-identified\/anonymized<\/a> and cannot reasonably be used to identify a person or infer identity, and the data that is publicly available are not classified as personal data.<\/p>\n<p><strong>Definition of sensitive personal data<\/strong><\/p>\n<p>There is also a more granularly specified and more regulated category of personal data, classified as \u201csensitive\u201d. It includes personal data that could reveal the following, or be used to cause harm based on these revelations:<\/p>\n<ul>\n<li>racial or ethnic origin<\/li>\n<li>religious beliefs<\/li>\n<li>mental or physical health condition or diagnosis<\/li>\n<li>sex life or sexual orientation<\/li>\n<li>citizenship or immigration status<\/li>\n<li>genetic or biometric data for the purpose of uniquely identifying an individual<\/li>\n<li>personal data collected from a known child<\/li>\n<li>precise geolocation data<\/li>\n<\/ul>\n<p><strong>Personal data of children<\/strong><\/p>\n<p>The CTDPA takes its definition of \u201cchild\u201d from the Children\u2019s Online Privacy Protection Act (<a href=\"\/knowledge-hub\/childrens-online-privacy-protection-act-coppa\/\">COPPA<\/a>), referring to individuals under the age of 13. To comply with the CTDPA, controllers and processors must also comply with parental consent requirements outlined by COPPA.<\/p>\n<p>However, under Connecticut\u2019s privacy law, if a controller has \u201cactual knowledge\u201d that a consumer is between 13 and 15 years of age, they may not \u201cwillfully disregard\u201d this information and process the consumer\u2019s personal data for targeted advertising or sell it without first obtaining consent. This is in line with CPRA requirements as well.<\/p>\n<p>The CDTPA requires opt-in consent for collection and processing of sensitive data, so consent must be obtained before or at the time of collection. A consent management platform can enable controllers to obtain valid consent for the collection and processing of sensitive personal data.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Who does the Connecticut Data Privacy Act apply to?<\/h2>\n<p>Like Virginia and Colorado, the CTDPA does not have a revenue threshold. For example, by comparison, in California and Utah it\u2019s US $25 million annual gross revenue.<\/p>\n<p>For Connecticut\u2019s privacy law to apply, an organization has to:<\/p>\n<ul>\n<li>control or process the personal data of 100,000 or more consumers annually\n<ul>\n<li>unless the personal data is controlled or processed solely for the purpose of completing a payment transaction<\/li>\n<\/ul>\n<p>or<\/li>\n<li>derive over 25 percent of their gross revenue from the sale of personal data, and\n<ul>\n<li>control or process the personal data of 25,000 or more consumers<\/li>\n<\/ul>\n<p>&nbsp;<\/li>\n<\/ul>\n<p>The 25 percent threshold of gross revenue obtained from data sales is significantly lower than the 50 percent threshold in Virginia and Utah\u2019s laws, and thus will likely apply to more and smaller organizations.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Exemptions to Connecticut Data Privacy Act compliance<\/h2>\n<p><strong>Organizational exemptions<\/strong><\/p>\n<p>The Connecticut data privacy law also exempts the following entities from compliance requirements:<\/p>\n<ul>\n<li>state and local government entities<\/li>\n<li>nonprofits<\/li>\n<li>institutions of higher education<\/li>\n<li>certain national security associations<\/li>\n<li>financial institutions covered by the Gramm-Leach-Bliley Act (GLBA)<\/li>\n<li>\u201ccovered entities\u201d and \u201cbusiness associates\u201d as defined under the Health Insurance Portability and Accountability Act (HIPAA)<\/li>\n<\/ul>\n<p>In addition to HIPAA-related exceptions, organizations processing relevant kinds of data should ensure that they familiarize themselves with additional health and life sciences-related exemptions outlined in the CTDPA.<\/p>\n<p><strong>Data Exemptions<\/strong><\/p>\n<p>In addition to the data exemptions for de-identified and publicly available data, or data collected and processed in the course of an employment or business relationship, data exemptions under the CTDPA also include data regulated under the following regulations:<\/p>\n<ul>\n<li>Fair Credit Reporting Act (FCRA)<\/li>\n<li>Driver\u2019s Privacy Protection Act (DPPA)<\/li>\n<li>Family Educational Rights and Privacy Act (FERPA)<\/li>\n<li>Farm Credit Act (FCA)<\/li>\n<li>Airline Deregulation Act (ADA)<\/li>\n<\/ul>\n<p><strong>Employment exemptions<\/strong><\/p>\n<p>Like Virginia and Utah, Connecticut exempts personal data processed or maintained:<\/p>\n<ul>\n<li>in the course of an individual applying to, or acting as an employee, agent, or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role<\/li>\n<\/ul>\n<p>or<\/p>\n<ul>\n<li>as emergency contact information for an individual and used for emergency contact purposes<\/li>\n<\/ul>\n<p>or<\/p>\n<ul>\n<li>to administer benefits for another individual and used to administer those benefits<\/li>\n<\/ul>\n\n\n<h2 class=\"wp-block-heading\">What are the consumer rights under the Connecticut Data Privacy Act?<\/h2>\n<p>As noted, the CTDPA is more \u201cuser-friendly\u201d than Utah\u2019s law, for example, and consumers residing there have more rights. There are some restrictions on these rights, however, for example relating to preventing the revelation of trade secrets.<\/p>\n<p>The primary rights are:<\/p>\n<ul>\n<li><strong>Access<\/strong> &#8211; the right to confirm whether a controller is processing their personal data and to have access to such data, with some exceptions<\/li>\n<li><strong>Correction<\/strong> &#8211; the right to have inaccuracies in their collected personal data corrected, with some limitations<\/li>\n<li><strong>Deletion<\/strong> &#8211; the right to have personal data that was provided by or about them deleted by the controller or processor<\/li>\n<li><strong>Portability<\/strong> &#8211; the right to obtain a portable copy of their personal data, to a technically feasible extent and with some restrictions<\/li>\n<li><strong>Opt-out<\/strong> &#8211; the right to opt out of the processing of their personal data for the purposes of:\n<ul>\n<li>targeted advertising<\/li>\n<li>sale<\/li>\n<li>profiling in connection with automated decision-making that could have legal or comparably significant effects<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n<h2 class=\"wp-block-heading\">Consumer requests, appeals, and litigation<\/h2>\n<p>Under the CTDPA, controllers must respond to consumer requests within 45 days. This period can be extended by an additional 45-day period if \u201creasonably necessary\u201d, for example if the controller has a high volume of requests or the consumer\u2019s request is particularly complex.<\/p>\n<p>Consumers also have the right to appeal controllers\u2019 denials of their requests, which isn\u2019t the case under all US privacy laws. They also have the ability to designate another person as an authorized agent who can exercise their right to opt out on the consumer\u2019s behalf.<\/p>\n<p>Connecticut\u2019s data privacy law does not provide consumers with private right of action (suing controllers in the case of a violation that affects them). To date, among the US privacy laws, only California provides that right.<\/p>\n\n\n<h2 class=\"wp-block-heading\">What are companies\u2019 obligations under the Connecticut Data Privacy Act?<\/h2>\n<h4>The Connecticut Data Privacy Act and consent<\/h4>\n<p><strong>Requirements for valid consent<\/strong><\/p>\n<p>Like the European Union\u2019s General Data Protection Regulation (<a href=\"https:\/\/usercentrics.com\/knowledge-hub\/the-eu-general-data-protection-regulation\/\">GDPR<\/a>), the CTDPA requires consent to be \u201cfreely given, specific, informed and unambiguous\u201d.<\/p>\n<p>Consent must be obtained before processing sensitive personal data or the data of children. Where children\u2019s data is concerned, consent must be obtained from a verifiable parent or legal guardian.<\/p>\n<h4>Consent for additional or alternative data processing purposes<\/h4>\n<p>Consumer consent must first be obtained, if a controller wants to process personal data for a purpose other than that communicated to consumers, or for a period of time longer than that communicated to consumers.<\/p>\n<p><strong>Dark patterns and consent<\/strong><\/p>\n<p>The CTDPA also explicitly excludes <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/dark-patterns-and-how-they-affect-consent\/\">dark patterns<\/a> in the definition of consent, i.e. if they are used, consent is not valid because it violates one or more of the requirements that consent needs to be freely given, specific, informed and unambiguous.<\/p>\n<p><strong>Revocable consent<\/strong><\/p>\n<p>Controllers must provide consumers with a method to revoke their consent that is as accessible and easy to use as the method used to provide consent. If consent is revoked, the controller must cease processing the consumer\u2019s personal data <em>\u201cas soon as practicable but no later than 15 days after receipt of the request.\u201d<\/em><\/p>\n<h4>Transparency and purpose specification<\/h4>\n<p>Consumers must be provided with a \u201creasonably clear and meaningful\u201d privacy notice that includes:<\/p>\n<ul>\n<li>categories of personal data processed<\/li>\n<li>purpose(s) of processing the data<\/li>\n<li>instructions to exercise consumers\u2019 rights, including:\n<ul>\n<li>how to submit a rights-related request<\/li>\n<li>how to appeal a rejection of a request<\/li>\n<\/ul>\n<\/li>\n<li>categories of personal data shared with third parties<\/li>\n<li>online means of contact for the controller, e.g. email address<\/li>\n<\/ul>\n<h4><\/h4>\n<h4>Data minimization<\/h4>\n<p>Controllers must limit collection of personal data to what is <em>\u201cadequate, relevant and reasonably necessary\u201d<\/em> for the disclosed processing purposes.<\/p>\n<h4>Avoid secondary use<\/h4>\n<p>Controllers may not process personal data for purposes that are <em>\u201cneither reasonably necessary to, nor compatible with, the disclosed purposes for which such personal data is processed\u201d<\/em>, unless consumers\u2019 consent has been obtained prior to collection and processing.<\/p>\n<h4>Security<\/h4>\n<p>Controllers must <em>\u201cestablish, implement and maintain reasonable administrative, technical and physical data security practices to protect the confidentiality, integrity and accessibility of personal data.\u201d<\/em> These practices have to take the volume and nature of the personal data collected and processed into account. (Greater amounts of data or data of greater sensitivity should be subject to more stringent processes and protections.)<\/p>\n<h4>Nondiscrimination<\/h4>\n<p>Controllers are prohibited from discriminating against consumers for exercising their rights under Connecticut\u2019s privacy law, or from violating other state or federal laws that prohibit unlawful discrimination against consumers.<\/p>\n<p>The law does note that if a consumer opts out of processing, but that decision conflicts with their privacy settings or voluntary participation in a loyalty or rewards program, the controller may notify the consumer of the conflict and ask them to reconfirm their privacy setting or program participation.<\/p>\n<h4>Data protection assessment<\/h4>\n<p>Controllers must conduct a data protection assessment (DPA) for personal data processing activities that present \u201cheightened risk of harm to a consumer.\u201d These DPAs must identify and weigh risks and benefits of the processing to consumers, the controller, other stakeholders and the public at large. Activities of heightened risk include:<\/p>\n<ul>\n<li>processing personal data for targeted advertising<\/li>\n<li>selling personal data<\/li>\n<li>processing sensitive data<\/li>\n<li>processing personal data for profiling where it involves a foreseeable risk of:\n<ul>\n<li>unfair or deceptive treatment or unlawful disparate impact on consumers<\/li>\n<li>financial, physical or reputational injury to consumers<\/li>\n<li>intrusion upon the solitude or seclusion or private affairs of consumers<\/li>\n<li>other substantial injury to consumers<\/li>\n<\/ul>\n<p>&nbsp;<\/li>\n<\/ul>\n<p>If an investigation into an alleged violation is launched by the Connecticut Attorney General, the controller must provide the DPAs for compliance evaluation.<\/p>\n<p>DPAs are not retroactive under the CTDPA, so will need to be created and maintained from July 1st, 2023 onward. However, similar to Virginia and Colorado, if the controller already creates DPAs to satisfy the requirements of another law, and the assessments are \u201creasonably similar,\u201d then those pre-existing DPAs can be used to satisfy CTDPA requirements.<\/p>\n<h4>Notification link requirements for consumer data processing opt-out<\/h4>\n<p>Similar to the requirements of the <a href=\"\/knowledge-hub\/california-privacy-rights-act-cpra-enforcement-begins\/\">CCPA\/CPRA<\/a>, if a controller sells personal data to third parties or processes it for targeted advertising, the controller must provide a \u201cclear and conspicuous link\u201d on their website that enables consumers to opt out of either of those activities. Exact text requirements for the link are not specified, but it would likely be similar to the CCPA\/CPRA\u2019s required \u201cDo Not Sell or Share My Personal Information\u201d.<\/p>\n<p>As of January 1st, 2025, controllers must allow consumers to opt out of personal data collection to be used for targeted advertising, or the sale of their personal data, via an \u201copt-out preference signal\u201d. Consumers would send this signal, which would include consent preference, via a platform, technology or mechanism like a consent management platform. The <a href=\"https:\/\/usercentrics.com\/ccpa\/\">Global Privacy Control<\/a> (GPC) is a prominent variant of this browser-based signal, and it is respected by the Usercentrics Consent Management Platform (CMP).<\/p>\n<p>Similar to the requirements for valid consent, the CTDPA requires that this opt out signal must:<\/p>\n<ul>\n<li style=\"list-style-type: none\">\n<ul>\n<li>rely on consumers\u2019 affirmative unambiguous choice rather than a default setting<\/li>\n<li>not unfairly disadvantage another controller<\/li>\n<li>be consumer-friendly and easy to use<\/li>\n<li>be as consistent as possible with other similar mechanisms required by other laws<\/li>\n<li>enable the controller to accurately determine if a consumer is a resident of the state and thus making a legitimate opt out request<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n<h2 class=\"wp-block-heading\">What are the penalties for noncompliance under the Connecticut Data Privacy Act?<\/h2>\n<h4>Enforcement authority<\/h4>\n<p>Under the CTDPA, the Attorney General has exclusive enforcement authority (as noted, there is no private right of action). Violations of the law are considered unfair trade practices under the Connecticut Unfair Trade Practices Act (<a href=\"https:\/\/portal.ct.gov\/DCP\/Trade-Practices-Division\/About-the-Connecticut-Unfair-Trade-Practices-Act-CUTPA\" target=\"_blank\" rel=\"noopener\">CUTPA<\/a>). As such, the Connecticut data privacy law does not outline specific penalties itself, financial or otherwise.<\/p>\n<h4>Penalties<\/h4>\n<p>Under the CUTPA, courts can impose civil penalties of up to US $5,000 for willful violations and award actual and punitive damages, costs, and attorneys\u2019 fees. Courts can also issue restraining orders, which could lead to a cease of data collection. Violation of a restraining order could result in a US $25,000 penalty.<\/p>\n<h4>Cure period and sun-setting<\/h4>\n<p>From when the CTDPA comes into effect on July 1st, 2023, companies that are provided with a notice of alleged violation(s) will receive a 60-day cure period, if it is determined that a cure is possible, to enable them to stop and repair the violation. This cure period is twice as long as that under some other laws, like Utah\u2019s. However, the provision of this cure period will only last from July 1st, 2023 to December 31st, 2024.<\/p>\n<p>The CTDPA has a sunset provision, so as of January 1st, 2025, there will no longer be a right to cure. The Attorney General will no longer have to issue notice and provide 60 days to cure, though they will still have that option, with the decision based on:<\/p>\n<ul>\n<li>the number of violations<\/li>\n<li>the size and complexity of the controller or processor<\/li>\n<li>the nature and extent of the controller&#8217;s or processor&#8217;s processing activities<\/li>\n<li>the substantial likelihood of injury to the public<\/li>\n<li>the safety of persons or property<\/li>\n<li>whether the alleged violation was likely caused by human or technical error<\/li>\n<\/ul>\n<p>If the Attorney General decides not to provide notice and a cure period (e.g. for a particularly large or damaging violation), they can pursue penalties for the violation right away.<\/p>\n<h4>Violation reporting<\/h4>\n<p>The Connecticut Attorney General has to submit a report to the Connecticut General Assembly (government) by February 1st, 2024, reporting on:<\/p>\n<ul>\n<li>how many notices of violations were given<\/li>\n<li>the nature of each violation<\/li>\n<li>the amount cured<\/li>\n<li>any other matter the Attorney General deems relevant<\/li>\n<\/ul>\n\n\n<h2 class=\"wp-block-heading\">The future of the Connecticut Data Privacy Act<\/h2>\n<p>Starting September 1st, 2022, the Connecticut General Assembly convened a task force to study data privacy topics, including:<\/p>\n<ul>\n<li>information sharing among health care and social care providers to make recommendations aimed at eliminating health disparities and inequities across sectors<\/li>\n<li>algorithmic decision-making and recommendations to reduce related bias<\/li>\n<li>the possibility of legislation on complying with parent deletion requests under COPPA<\/li>\n<li>age verification of children on social media<\/li>\n<li>data colocation issues<\/li>\n<li>possible expansion of CTDPA<\/li>\n<\/ul>\n<p>The task force will have until January 1st, 2023 to submit findings and recommendations. This information will, no doubt, be influential on future amendments and expansions of the CTDPA.<\/p>\n\n\n<h2 class=\"wp-block-heading\">The Connecticut Data Privacy Act and consent management<\/h2>\n<p>The CTDPA requires obtaining consumers\u2019 consent under more circumstances than some of the other state-level data privacy laws passed before it, particularly Utah\u2019s.<\/p>\n<p>Controllers must also notify consumers about data collection and processing under all circumstances on their websites, using a privacy notice\/page. This enables the requirement that when consent is required, it be \u201cfreely given, specific, informed and unambiguous\u201d.<\/p>\n<p>Consent must be obtained before collection and processing of children&#8217;s data, sensitive data, if the controller wants to collect and process additional data beyond what they have provided notification about, or if the purpose for the data processing changes from what is stated.<\/p>\n<p>Changing or revoking consent must also be as accessible and easily done as giving consent, and consumers can opt out of the processing of their data at any time for the purposes of targeted advertising, sale, or use of automated decision-making technologies.<\/p>\n<p>A consent management platform like the Usercentrics CMP can enable compliance with the CTDPA for all of these requirements. It can help automatically populate a privacy policy and keep it up to date to ensure consumer notification is always accurate. It can collect consent for the circumstances when it\u2019s needed, and enable consumers to opt out of data processing. It can also work with preference signals like the GPC.<\/p>\n<p>With geolocation services, different configurations of the CMP can be displayed to users in different places, enabling compliance with any or all of the US state-level laws, and\/or those abroad (like the GDPR).<\/p>\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n<p>As individual states continue to draft and pass privacy laws, it shows the evolution of thought around data privacy, and the influence of changing consumer attitudes. Inclusions like \u201copt out preference signal\u201d show that technologies that are still relatively new are gaining traction among consumers, tech companies, and governments.<\/p>\n<p>The Connecticut Data Privacy Act shows a \u201cuser-centric\u201d aspect on many fronts, and provides residents of Connecticut with a variety of ways to control their privacy and the use of their data.<\/p>\n<p>The Connecticut General Assembly is clearly looking to the future with the law, with plans and mandates for reporting and recommendations already set out. By 2025 there should be plenty of information to influence beneficial amendments to the law. Because of a lack of inclusion of privacy right of action, unlike in California, consumer class-action lawsuits will not be a potential influence on future amendments to the CTDPA.<\/p>\n<p>The Connecticut data privacy law provides a number of consumer rights, as well as requirements for notification and circumstances under which consent must be obtained before collecting and processing data. Consulting qualified legal counsel is recommended to determine your organization\u2019s potential responsibilities, actions needed to ensure privacy compliance when the law comes into effect, and at the close of sunset periods. Proactive efforts to protect user privacy are also always a good idea to help build user trust and secure high-quality data for marketing operations.<\/p>\n<p>If you have questions or interest in implementing a consent management platform to help achieve compliance with privacy laws in the United States and around the world, <a href=\"https:\/\/usercentrics.com\/book-a-consultation\/\">talk to one of our experts<\/a>.<\/p>\n\n\n","protected":false},"excerpt":{"rendered":"<p>The Connecticut Data Privacy Act is the fifth state-level privacy law passed in the United States and is the most consumer-friendly one to date.<\/p>\n","protected":false},"featured_media":11919,"template":"","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"tags":[],"magazine_issue":[],"magazine_tag":[],"resource_tag":[14,13],"class_list":["post-375","knowledge","type-knowledge","status-publish","has-post-thumbnail","hentry","resource_tag-privacy","resource_tag-regulations"],"acf":[],"yoast_head":"<title>CTDPA - An overview of the Connecticut Data Privacy Act<\/title>\n<meta name=\"description\" content=\"We explain what the Connecticut Data Privacy Act (CTDPA), the Connecticut privacy law, means for consumers and companies.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CTDPA - An overview of the Connecticut Data Privacy Act\" \/>\n<meta property=\"og:description\" content=\"We explain what the Connecticut Data Privacy Act (CTDPA), the Connecticut privacy law, means for consumers and companies.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/\" \/>\n<meta property=\"og:site_name\" content=\"Usercentrics - US\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/usercentrics\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-26T11:20:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/usercentrics.com\/wp-content\/uploads\/2022\/12\/Connecticut-Data-Privacy-Act-an-overview.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"CTDPA - An overview of the Connecticut Data Privacy Act\" \/>\n<meta name=\"twitter:description\" content=\"We explain what the Connecticut Data Privacy Act (CTDPA), the Connecticut privacy law, means for consumers and companies.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/usercentrics.com\/wp-content\/uploads\/2022\/12\/Connecticut-Data-Privacy-Act-an-overview.jpg\" \/>\n<meta name=\"twitter:site\" content=\"@usercentrics\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/connecticut-data-privacy-act-ctdpa\\\/\",\"url\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/connecticut-data-privacy-act-ctdpa\\\/\",\"name\":\"CTDPA - An overview of the Connecticut Data Privacy Act\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/connecticut-data-privacy-act-ctdpa\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/connecticut-data-privacy-act-ctdpa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/wp-content\\\/uploads\\\/sites\\\/7\\\/2022\\\/12\\\/Connecticut-Data-Privacy-Act-CTDPA.jpg\",\"datePublished\":\"2022-12-16T06:42:15+00:00\",\"dateModified\":\"2025-06-26T11:20:49+00:00\",\"description\":\"We explain what the Connecticut Data Privacy Act (CTDPA), the Connecticut privacy law, means for consumers and companies.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/connecticut-data-privacy-act-ctdpa\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/connecticut-data-privacy-act-ctdpa\\\/\"}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/connecticut-data-privacy-act-ctdpa\\\/#primaryimage\",\"url\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/wp-content\\\/uploads\\\/sites\\\/7\\\/2022\\\/12\\\/Connecticut-Data-Privacy-Act-CTDPA.jpg\",\"contentUrl\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/wp-content\\\/uploads\\\/sites\\\/7\\\/2022\\\/12\\\/Connecticut-Data-Privacy-Act-CTDPA.jpg\",\"width\":1000,\"height\":1000,\"caption\":\"Connecticut landscape with CTDPA badge\",\"copyrightNotice\":\"\u00a9 Copyright 2026 Usercentrics GmbH\",\"creator\":{\"@type\":\"Organization\",\"name\":\"Usercentrics GmbH\"},\"creditText\":\"Image: Usercentrics GmbH\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/connecticut-data-privacy-act-ctdpa\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Resources\",\"item\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/resources\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Connecticut Data Privacy Act (CTDPA): An Overview\",\"item\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/connecticut-data-privacy-act-ctdpa\\\/\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/#website\",\"url\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/\",\"name\":\"Usercentrics - US\",\"description\":\"Consent Management Platform (CMP) Usercentrics\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/?s={search_term_string}\"}}],\"inLanguage\":\"en-US\"}]}<\/script>","yoast_head_json":{"title":"CTDPA - An overview of the Connecticut Data Privacy Act","description":"We explain what the Connecticut Data Privacy Act (CTDPA), the Connecticut privacy law, means for consumers and companies.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"CTDPA - An overview of the Connecticut Data Privacy Act","og_description":"We explain what the Connecticut Data Privacy Act (CTDPA), the Connecticut privacy law, means for consumers and companies.","og_url":"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/","og_site_name":"Usercentrics - US","article_publisher":"https:\/\/www.facebook.com\/usercentrics","article_modified_time":"2025-06-26T11:20:49+00:00","og_image":[{"url":"https:\/\/usercentrics.com\/wp-content\/uploads\/2022\/12\/Connecticut-Data-Privacy-Act-an-overview.jpg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_title":"CTDPA - An overview of the Connecticut Data Privacy Act","twitter_description":"We explain what the Connecticut Data Privacy Act (CTDPA), the Connecticut privacy law, means for consumers and companies.","twitter_image":"https:\/\/usercentrics.com\/wp-content\/uploads\/2022\/12\/Connecticut-Data-Privacy-Act-an-overview.jpg","twitter_site":"@usercentrics","twitter_misc":{"Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/","url":"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/","name":"CTDPA - An overview of the Connecticut Data Privacy Act","isPartOf":{"@id":"https:\/\/usercentrics.com\/us\/#website"},"primaryImageOfPage":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/#primaryimage"},"image":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/#primaryimage"},"thumbnailUrl":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2022\/12\/Connecticut-Data-Privacy-Act-CTDPA.jpg","datePublished":"2022-12-16T06:42:15+00:00","dateModified":"2025-06-26T11:20:49+00:00","description":"We explain what the Connecticut Data Privacy Act (CTDPA), the Connecticut privacy law, means for consumers and companies.","breadcrumb":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/"}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/#primaryimage","url":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2022\/12\/Connecticut-Data-Privacy-Act-CTDPA.jpg","contentUrl":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2022\/12\/Connecticut-Data-Privacy-Act-CTDPA.jpg","width":1000,"height":1000,"caption":"Connecticut landscape with CTDPA badge","copyrightNotice":"\u00a9 Copyright 2026 Usercentrics GmbH","creator":{"@type":"Organization","name":"Usercentrics GmbH"},"creditText":"Image: Usercentrics GmbH"},{"@type":"BreadcrumbList","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https:\/\/usercentrics.com\/us\/resources\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/usercentrics.com\/us\/knowledge-hub\/"},{"@type":"ListItem","position":3,"name":"Connecticut Data Privacy Act (CTDPA): An Overview","item":"https:\/\/usercentrics.com\/us\/knowledge-hub\/connecticut-data-privacy-act-ctdpa\/"}]},{"@type":"WebSite","@id":"https:\/\/usercentrics.com\/us\/#website","url":"https:\/\/usercentrics.com\/us\/","name":"Usercentrics - US","description":"Consent Management Platform (CMP) Usercentrics","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/usercentrics.com\/us\/?s={search_term_string}"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge\/375","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge"}],"about":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/types\/knowledge"}],"version-history":[{"count":0,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge\/375\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/media\/11919"}],"wp:attachment":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/media?parent=375"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/tags?post=375"},{"taxonomy":"magazine_issue","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/magazine_issue?post=375"},{"taxonomy":"magazine_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/magazine_tag?post=375"},{"taxonomy":"resource_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/resource_tag?post=375"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}