🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-CT v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing15 sources retrieved model claude-sonnet-5 · 2026-08-05

Connecticut, USA

US-CT schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: AIC, Advennt

Last updated · 10 categories · 42 claims · 26 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
42Claimsbaseline..claims[]
7Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 12 sub-modules are flagged red.

Jurisdiction brief

Latest update · 22 September 2026

Lead Signal

Connecticut enacted the most significant single-year expansion of its data-protection regime since the 2022 base act, driven by two 2026 amendment packages -- Public Act 25-113 and Public Act 26-64 -- plus a new omnibus AI statute. Effective July 1, 2026, the Connecticut Data Privacy Act's consumer-volume applicability threshold dropped from 100,000 to 35,000, with new no-volume-threshold triggers for sensitive-data processing or personal-data sale, meaning materially smaller businesses now fall within scope. Public Act 26-64 (signed May 27, 2026, and subsequently amended by HB 5222 and HB 5563) establishes a data-broker registration program opening January 1, 2027, and layers on additional CTDPA amendments effective October 1, 2026.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute in force since 2023 but undergoing frequent, materially expanding amendments (2024, 2026) that shift scope and thresholds; operators must track a moving compliance target.

Primary frameworkConnecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq., as amended
Traffic-light rationale — AmberComprehensive statute in force since 2023 but undergoing frequent, materially expanding amendments (2024, 2026) that shift scope and thresholds; operators must track a moving compliance target.

Sub-modules (5)

Regulator And AuthorityGreen

The Connecticut Attorney General has exclusive statutory authority to enforce the CTDPA; there is no dedicated state privacy agency (unlike California's CPPA).

Claims (1):

  • The Connecticut Attorney General has exclusive authority to enforce violations of the CTDPA and there is no private right of action.

Act And InstrumentsAmber

Core instrument is the CTDPA as amended by the Online Privacy Act (2023), the 2024 minors' amendments, the 2025/2026 threshold-lowering amendments (effective July 1, 2026), and Public Act 26-64 (SB4, effective October 1, 2026) adding data-broker and facial-recognition provisions.

Claims (3):

  • Governor Ned Lamont signed Senate Bill 6 (the CTDPA) into law on May 10, 2022, and the Act took effect on July 1, 2023.
  • Amendments to the CTDPA going into effect on July 1, 2026 broaden applicability thresholds, including making all sensitive-data processing and all sales of personal data covered under the law.
  • Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.

Material ScopeGreen

CTDPA covers personal data of CT residents acting in an individual/household context; excludes employment-context data and 16 categories of exempted data overlapping with federal sectoral laws (HIPAA, FCRA, GLBA, DPPA, FERPA, Farm Credit Act, Airline Deregulation Act).

Claims (2):

  • The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.
  • The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.

Territorial ScopeGreen

Applies to persons conducting business in Connecticut or targeting products/services to CT residents meeting the statutory thresholds; no extraterritorial reach beyond that consumer-targeting test.

Claims (1):

  • The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.

Regulator Registration And FilingAmber

The CTDPA itself imposes no general controller registration/filing requirement; however, Public Act 26-64 (effective Oct 1, 2026) newly requires data brokers to register and establish a deletion mechanism.

Claims (1):

  • Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.

Key findings (1)

  • — source on file
Category narrative118 words

Connecticut's comprehensive consumer privacy regime is the Connecticut Data Privacy Act (CTDPA), Public Act No. 22-15 (Conn. Gen. Stat. § 42-515 et seq.), signed May 10, 2022 and effective July 1, 2023, enforced exclusively by the Connecticut Attorney General (no dedicated privacy agency). The Act has been amended multiple times (Online Privacy Act 2023, minors' protections effective Oct 1 2024, 2025 amendments effective July 1 2026 lowering applicability thresholds, and Public Act 26-64 / SB4 effective October 1 2026 adding data broker registration and facial recognition rules). Applicability thresholds are being broadened by the July 2026 amendments so that any processing of sensitive data or any sale of personal data triggers coverage, removing the prior 25,000-consumer sale-revenue threshold.

Periodic update · new data 2026-09-22

Regulator & Framework

The Connecticut Attorney General remains the sole enforcement authority for the CTDPA; the state has no dedicated data-protection agency. Effective July 1, 2026, the Act's consumer-volume applicability threshold was lowered from 100,000 to 35,000, with new triggers requiring no minimum volume at all where a business processes sensitive data or sells personal data -- a change that pulls a materially larger population of Connecticut businesses into scope. Separately, Public Act 26-64 (SB 4), signed by Governor Ned Lamont on May 27, 2026 and subsequently amended by HB 5222 and HB 5563, establishes a new data-broker registration program requiring brokers to register beginning January 1, 2027, alongside further CTDPA amendments taking effect October 1, 2026.

Taken together, these two enactments represent the most substantial widening of Connecticut's data-protection architecture since the base Act took effect in 2022. The lowered threshold in particular changes who must comply, not merely what compliant businesses must do, which is a structurally significant shift for mid-sized businesses previously outside the Act's reach.

Outlook

The data-broker registration program opens January 1, 2027, and the further PA 26-64 amendments take effect October 1, 2026 -- both dates businesses should track closely. Primary statutory text for PA 26-64 was not directly retrieved this cycle, and whether the Attorney General has issued or plans to issue CTDPA-specific rulemaking beyond the statute itself remains unestablished.

Sources and claims (6)
  1. ConfirmedConnecticut Office of the Attorney General — The Connecticut Attorney General has exclusive authority to enforce violations of the CTDPA and there is no private right of action.observed
  2. ConfirmedConnecticut Office of the Attorney General — Governor Ned Lamont signed Senate Bill 6 (the CTDPA) into law on May 10, 2022, and the Act took effect on July 1, 2023.observed
  3. ConfirmedConnecticut Office of the Attorney General — Amendments to the CTDPA going into effect on July 1, 2026 broaden applicability thresholds, including making all sensitive-data processing and all sales of personal data covered under the law.observed
  4. ConfirmedOneTrust DataGuidance — Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.observed
  5. ConfirmedConnecticut Office of the Attorney General — The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.observed
  6. ConfirmedInternational Association of Privacy Professionals — The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.observed

#

Consent standard and sensitive-data consent requirement are well-defined and in force, but the sensitive-data category list is being materially expanded by amendments not yet fully effective, creating a temporal compliance gap.

Primary frameworkConnecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq.
Traffic-light rationale — AmberConsent standard and sensitive-data consent requirement are well-defined and in force, but the sensitive-data category list is being materially expanded by amendments not yet fully effective, creating a temporal compliance gap.

Sub-modules (4)

Lawful BasesAmber

No enumerated Art.6-style lawful-bases list; general processing is permitted subject to purpose-limitation, data-minimization, and consumer opt-out rights for targeted advertising, sale, and certain profiling.

Claims (1):

  • Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes, and may not process personal data for purposes neither reasonably necessary to nor compatible with the disclosed purposes absent consent.

Special CategoriesAmber

Sensitive data requires opt-in consent prior to processing; the July 2026 amendments expand the sensitive-data category list to include disability/treatment status, non-binary/transgender status, genetic/biometric-derived information, and neural data.

Claims (2):

  • Sensitive data has heightened protections under the CTDPA and controllers must obtain affirmative opt-in consent before processing it.
  • As amended, 'sensitive data' now includes data revealing disability or treatment, non-binary or transgender status, information derived from genetic or biometric data, data known to relate to a child, neural data, certain financial account information, and government-issued identification information.

Pseudonymisation And AnonymisationRed

No specific statutory safe-harbour definition for pseudonymised/anonymised data was identified in the sources reviewed for this run.

Absence provenance: unavailable. Searched: unavailable.

Key findings (1)

  • — source on file
Category narrative92 words

CTDPA does not use a GDPR-style enumerated lawful-bases model; instead it relies on an opt-out framework for ordinary processing plus opt-in consent requirements for sensitive data and material new-purpose processing. Consent must be freely given, specific, informed and unambiguous, cannot be obtained via dark patterns, and must be revocable via a mechanism at least as easy as the one used to give it. The 2026 amendments substantially broaden the definition of 'sensitive data' to include disability/treatment status, non-binary/transgender status, information derived from genetic or biometric data, neural data, and expanded financial/government-ID identifiers.

Periodic update · new data 2026-09-22

Lawful Processing & Special Data

Public Act 25-113, in force as of July 1, 2026, substantially expands the CTDPA's definition of sensitive data to include disability status, nonbinary and transgender status, biometric-derived and genetic-derived data, neural data, financial account information, and government-issued identification numbers. This expansion materially widens the category of processing that triggers the Act's heightened consent and assessment obligations, since sensitive-data processing is now itself one of the new no-volume-threshold triggers for applicability discussed under Regulator & Framework.

Public Act 26-64 adds a further consent-adjacent restriction: it bans the sale of any Connecticut resident's precise geolocation data outright, with that ban taking effect October 1, 2026. Precise geolocation has historically been one of the more commercially valuable and sensitive categories of consumer data, and an outright sale ban -- rather than a consent-based permission -- represents a notably firmer regulatory stance than the consent-based model the CTDPA otherwise applies to most categories of sensitive data.

Outlook

Businesses should map their sensitive-data inventories against the expanded definition now, ahead of the geolocation sale ban taking effect October 1, 2026. Whether the expanded sensitive-data list will trigger reassessment obligations for previously-completed data protection assessments remains an open compliance question this cycle.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy Professionals — Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes, and may not process personal data for purposes neither reasonably necessary to nor compatible with the disclosed purposes absent consent.observed
  2. ConfirmedInternational Association of Privacy Professionals — A consumer's consent under the CTDPA must be freely given, specific, informed and unambiguous, cannot be obtained through dark patterns, and controllers must provide an effective revocation mechanism at least as easy as the consent mechanism, ceasing processing within 15 days of revocation.observed
  3. ConfirmedConnecticut Office of the Attorney General — Sensitive data has heightened protections under the CTDPA and controllers must obtain affirmative opt-in consent before processing it.observed
  4. ConfirmedConnecticut Office of the Attorney General — As amended, 'sensitive data' now includes data revealing disability or treatment, non-binary or transgender status, information derived from genetic or biometric data, data known to relate to a child, neural data, certain financial account information, and government-issued identification information.observed

#

Well-defined statutory rights and response deadlines already in force, with an enacted (not-yet-effective) expansion of rights around profiling transparency and third-party disclosure.

Primary frameworkConnecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq.
Traffic-light rationale — GreenWell-defined statutory rights and response deadlines already in force, with an enacted (not-yet-effective) expansion of rights around profiling transparency and third-party disclosure.

Sub-modules (5)

Access RightGreen

Consumers may confirm whether a controller is processing their personal data and access it, free of charge once every 12 months, subject to a trade-secret exception.

Claims (1):

  • A consumer can request information about their personal data from a controller free of charge once every 12 months, with the controller permitted to charge an administrative fee beyond the annual free request.

Rectification And ErasureGreen

CTDPA grants rights to correct inaccuracies and to delete personal data, including data collected via third parties.

Claims (1):

  • The CTDPA provides Connecticut consumers the right to correct inaccuracies in their personal data and the right to delete their personal data, including data that a business collected through third parties.

Restriction And ObjectionGreen

Consumers may opt out of processing for targeted advertising, sale of personal data, and profiling producing legal or similarly significant effects.

Claims (1):

  • Connecticut consumers have the right to opt out of the sale of their personal data and targeted advertising, and, under the 2026 amendments, to know whether a controller is processing their personal data for profiling that produces a legal or similarly significant effect.

Data PortabilityGreen

The CTDPA as amended establishes a right to data portability for consumers.

Claims (1):

  • The CTDPA as amended establishes rights including access, deletion, and portability for consumers.

Deadlines And Response WindowsGreen

Controllers must respond to consumer requests within 45 days of receipt, extendable by an additional 45 days under certain conditions; appeal responses are due within 60 days of receipt of the appeal.

Claims (2):

  • A controller must respond to a consumer's requests no later than 45 days after receipt of the request, and under certain conditions may extend the response period by an additional 45 days.
  • A controller has 60 days after receipt of an appeal to write back to the consumer explaining actions taken or reasons for refusal, and if denied must provide information to contact the Attorney General.

Key findings (1)

  • — source on file
Category narrative77 words

CTDPA grants CT consumers rights of access, correction, deletion, portability, and opt-out of targeted advertising/sale/certain profiling, plus an appeal right against controller denials. Controllers must respond within 45 days (extendable by a further 45 days when reasonably necessary); appeal responses are due within 60 days. The 2026 amendments add new rights to obtain a list of third parties sold to, access inferences drawn from personal data, and query/challenge automated profiling decisions with legal or similarly significant effects.

Periodic update · new data 2026-09-22

Data Subject Rights

Two new consumer rights entered force as part of the July 1, 2026 CTDPA amendments. First, consumers gained the right to obtain a list of every third party to which their personal data was sold, a meaningfully more granular transparency right than a generic sale-disclosure statement. Second, consumers gained the right to question, review and request reevaluation of automated profiling decisions that carry legal or similarly significant effects on them, giving Connecticut residents a formal challenge mechanism against algorithmic decisions in a way the original 2022 Act did not provide.

Both rights are reported with Probable rather than Confirmed confidence, since the underlying finding rests on secondary law-firm reporting rather than directly retrieved statutory text this cycle. The reevaluation right in particular is closely tied to the new standalone profiling impact assessment obligation described under Controller/Processor Duties, since both provisions target the same class of legally-significant automated decisions.

Outlook

How controllers must operationalize the profiling-reevaluation right in practice -- timelines, evidentiary standards, and appeal mechanisms -- is not yet established and will likely require either Attorney General guidance or further statutory clarification. Confirming the underlying statutory text directly would raise these findings from Probable to Confirmed confidence.

Sources and claims (6)
  1. ConfirmedConnecticut Office of the Attorney General — A consumer can request information about their personal data from a controller free of charge once every 12 months, with the controller permitted to charge an administrative fee beyond the annual free request.observed
  2. ConfirmedConnecticut Office of the Attorney General — The CTDPA provides Connecticut consumers the right to correct inaccuracies in their personal data and the right to delete their personal data, including data that a business collected through third parties.observed
  3. ConfirmedConnecticut Office of the Attorney General — Connecticut consumers have the right to opt out of the sale of their personal data and targeted advertising, and, under the 2026 amendments, to know whether a controller is processing their personal data for profiling that produces a legal or similarly significant effect.observed
  4. ProbableOneTrust DataGuidance — The CTDPA as amended establishes rights including access, deletion, and portability for consumers.observed
  5. ConfirmedConnecticut Office of the Attorney General — A controller must respond to a consumer's requests no later than 45 days after receipt of the request, and under certain conditions may extend the response period by an additional 45 days.observed
  6. ConfirmedConnecticut Office of the Attorney General — A controller has 60 days after receipt of an appeal to write back to the consumer explaining actions taken or reasons for refusal, and if denied must provide information to contact the Attorney General.observed

#

Strong breach-notification and DPIA-equivalent regime in force, but no explicit statutory DPO or ROPA requirement, and processor-contract obligations are less detailed than GDPR Art. 28.

Primary frameworkConnecticut Data Privacy Act (CTDPA); Connecticut Data Breach Notification Act, Conn. Gen. Stat. § 36a-701b; Connecticut Safeguards Law, Conn. Gen. Stat. § 42-471
Traffic-light rationale — AmberStrong breach-notification and DPIA-equivalent regime in force, but no explicit statutory DPO or ROPA requirement, and processor-contract obligations are less detailed than GDPR Art. 28.

Sub-modules (7)

Accountability And DpiaGreen

Controllers must conduct and document Data Protection Assessments/Impact Assessments before processing for targeted advertising, sale, risky profiling, or sensitive data; the 2025 amendments extend impact-assessment obligations to profiling decisions.

Claims (2):

  • Controllers must conduct assessments before processing personal data in a manner that presents a heightened risk of harm to consumers, including processing for targeted advertising, sale, profiling with reasonably foreseeable risk of substantial injury, and processing of sensitive data.
  • Senate Bill 1295 amends the CTDPA to mandate impact assessments for profiling decisions in connection with social-media platform obligations regarding minors' data.

Dpo RequirementsRed

No CTDPA provision mandating appointment of a Data Protection Officer was identified in the sources reviewed for this run.

Absence provenance: unavailable. Searched: unavailable.

Ropa RequirementsAmber

No explicit statutory records-of-processing-activities obligation distinct from the DPA/impact-assessment documentation requirement was identified.

Absence provenance: unavailable. Searched: unavailable.

Claims (1):

  • Controllers must conduct assessments before processing personal data in a manner that presents a heightened risk of harm to consumers, including processing for targeted advertising, sale, profiling with reasonably foreseeable risk of substantial injury, and processing of sensitive data.

Joint Controller ArrangementsGreen

CTDPA distinguishes controllers and processors; a processor exercising independent decision-making authority over purposes/means becomes a controller for that processing and assumes controller obligations.

Claims (1):

  • If a processor exercises decision-making authority with respect to the purposes and means of personal-data processing, it becomes a controller with respect to that processing and is subject to controller obligations under the CTDPA.

Security MeasuresGreen

Controllers must use reasonable safeguards to secure personal data (CTDPA), supplemented by the Connecticut Safeguards Law (Conn. Gen. Stat. § 42-471) and Social Security Number Law (§ 42-470).

Claims (1):

  • Controllers must use reasonable safeguards to secure personal data as part of their obligations to comply with the CTDPA.

Breach NotificationGreen

Under Conn. Gen. Stat. § 36a-701b, notice to affected CT residents must be made without unreasonable delay and no later than 60 days from discovery of the breach; AG notice is due no later than resident notification; SSN/TIN compromise triggers a mandatory 24-month credit-monitoring offer.

Claims (2):

  • Notice to Connecticut residents of a security breach must be made without unreasonable delay and no later than sixty days from discovery of the breach, per Conn. Gen. Stat. § 36a-701b(b)(1); notice to the Attorney General must be provided no later than when residents are notified.
  • If a Connecticut resident's Social Security number or Taxpayer Identification Number is believed compromised in a breach, Connecticut law requires the resident be offered 24 months of credit monitoring services.

Retention And DisposalAmber

No CTDPA-specific numeric retention-limit provision was identified beyond the general purpose-limitation/data-minimization principle.

Absence provenance: unavailable. Searched: unavailable.

Claims (1):

  • Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes, and may not process personal data for purposes neither reasonably necessary to nor compatible with the disclosed purposes absent consent.

Key findings (1)

  • — source on file
Category narrative91 words

CTDPA requires Data Protection Assessments (DPAs)/Impact Assessments before processing that presents a heightened risk of harm (targeted advertising, sale, risky profiling, sensitive-data processing); requires reasonable security safeguards; and requires a data breach notification under the separate Connecticut Data Breach Notification Act (Conn. Gen. Stat. § 36a-701b) — notice to consumers without unreasonable delay and no later than 60 days from discovery, with AG notice due no later than consumer notice. No CTDPA-specific DPO appointment requirement or formal ROPA mandate was identified; joint-controller arrangements are addressed only via generic controller/processor contractual requirements.

Periodic update · new data 2026-09-22

Controller/Processor Duties

Public Act 25-113 introduces a new standalone obligation: controllers that profile consumers to make legally significant decisions must now conduct a dedicated profiling impact assessment, separate and distinct from the data protection assessment already required under the base CTDPA. This obligation applies to processing activities created or generated on or after August 1, 2026, meaning it operates on a forward-looking activity basis rather than a blanket retroactive requirement.

This is a Confirmed finding and represents a meaningful compliance-burden increase for any controller engaged in automated decision-making with legal or similarly significant effects, since it requires a documented assessment specific to the profiling activity itself, on top of whatever general data protection assessment already covers the underlying processing. Read together with the new consumer reevaluation right described under Data Subject Rights, Connecticut has built a two-sided accountability structure around automated profiling: an internal documentation duty on the controller side, and an external challenge right on the consumer side.

Outlook

Controllers should begin identifying which profiling activities were created or generated on or after August 1, 2026 and are therefore in scope for the new standalone assessment requirement. Whether existing data protection assessments can be supplemented rather than duplicated in full remains an open practical question this cycle.

Sources and claims (6)
  1. ConfirmedConnecticut Office of the Attorney General — Controllers must conduct assessments before processing personal data in a manner that presents a heightened risk of harm to consumers, including processing for targeted advertising, sale, profiling with reasonably foreseeable risk of substantial injury, and processing of sensitive data.observed
  2. ProbableOneTrust DataGuidance — Senate Bill 1295 amends the CTDPA to mandate impact assessments for profiling decisions in connection with social-media platform obligations regarding minors' data.observed
  3. ConfirmedConnecticut Office of the Attorney General — If a processor exercises decision-making authority with respect to the purposes and means of personal-data processing, it becomes a controller with respect to that processing and is subject to controller obligations under the CTDPA.observed
  4. ConfirmedConnecticut Office of the Attorney General — Controllers must use reasonable safeguards to secure personal data as part of their obligations to comply with the CTDPA.observed
  5. ConfirmedConnecticut Office of the Attorney General — Notice to Connecticut residents of a security breach must be made without unreasonable delay and no later than sixty days from discovery of the breach, per Conn. Gen. Stat. § 36a-701b(b)(1); notice to the Attorney General must be provided no later than when residents are notified.observed
  6. ConfirmedConnecticut Office of the Attorney General — If a Connecticut resident's Social Security number or Taxpayer Identification Number is believed compromised in a breach, Connecticut law requires the resident be offered 24 months of credit monitoring services.observed

#

No comprehensive cross-border transfer regime exists under CTDPA; this is a genuine regulatory gap rather than an incomplete search.

Traffic-light rationale — Not assessedNo comprehensive cross-border transfer regime exists under CTDPA; this is a genuine regulatory gap rather than an incomplete search.

Sub-modules (6)

Transfer MechanismsRed

No CTDPA transfer-mechanism provision identified.

Absence provenance: unavailable. Searched: unavailable.

Adequacy ReceivedRed

Not applicable; CT is a sub-national US jurisdiction with no adequacy-receiving framework.

Absence provenance: unavailable. Searched: unavailable.

Adequacy GrantedRed

Not applicable; Connecticut does not issue adequacy determinations.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsRed

No SCC/BCR uptake mechanism exists under CTDPA.

Absence provenance: unavailable. Searched: unavailable.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement exists under CTDPA.

Absence provenance: unavailable. Searched: unavailable.

Data LocalisationRed

No data-localisation mandate exists under CTDPA.

Absence provenance: unavailable. Searched: unavailable.

Key findings (1)

  • — source on file
Category narrative48 words

The CTDPA does not contain a distinct cross-border-transfer regime (no adequacy mechanism, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate) — this is characteristic of US state comprehensive privacy statutes, which regulate controller/processor obligations regardless of the data's onward destination rather than gating international transfers as GDPR-style regimes do.

no periodic updates on record for this sub-brief

#

Sectoral overlays are well-documented (insurance, health, financial), but the scope of financial/insurance exemptions is being actively renegotiated in pending 2026 amendments.

Primary frameworkCTDPA sectoral exemptions; Connecticut Insurance Data Security Law (Conn. Gen. Stat. Title 38a, implementing NAIC Insurance Data Security Model Law)
Traffic-light rationale — AmberSectoral overlays are well-documented (insurance, health, financial), but the scope of financial/insurance exemptions is being actively renegotiated in pending 2026 amendments.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA-regulated financial institutions and their data are generally exempt from CTDPA; the Connecticut Insurance Data Security Law imposes its own breach-notification duties, including a 72-hour TPSP-event notification for assuming insurers to ceding insurers and domiciliary regulators.

Claims (1):

  • Under the Connecticut Insurance Data Security Law, a licensee acting as an assuming insurer must notify affected ceding insurers and its domiciliary regulator of a cybersecurity event involving nonpublic information in the possession of a third-party service provider (TPSP) not later than 72 hours after the assuming insurer received notice from the TPSP.

Health Sector OverlayAmber

HIPAA-covered entities/business associates and their protected health information are exempt from CTDPA; the AG's Privacy Section separately enforces HIPAA under delegated federal authority. The CTDPA's standalone Consumer Health Data provisions (Online Privacy Act) apply to non-HIPAA consumer health data with no size threshold.

Claims (1):

  • The CTDPA applies to all Consumer Health Data Controllers doing business in or targeting Connecticut residents regardless of size or processing volume, with no revenue or processing threshold and no nonprofit exemption.

Telecoms And EprivacyAmber

No CT-specific ePrivacy/cookie-consent statute distinct from CTDPA's general opt-out framework was identified.

Absence provenance: unavailable. Searched: unavailable.

Employment DataGreen

CTDPA expressly excludes personal data processed in an employment context (e.g., job applications) from its scope.

Claims (1):

  • The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.

Credit And ScoringGreen

FCRA-regulated data and entities are exempt from CTDPA; the AG's Privacy and Data Security Department separately enforces the FCRA under delegated federal authority.

Claims (1):

  • The AG's Privacy and Data Security Department is responsible for enforcement of federal laws under which the Attorney General has enforcement authority, including HIPAA, COPPA, and the Fair Credit Reporting Act.

EducationGreen

FERPA-regulated education records are among the CTDPA's exempted data categories.

Claims (1):

  • The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.

InsuranceGreen

The Connecticut Insurance Data Security Law requires licensees to notify the Insurance Commissioner and affected consumers of cybersecurity events and imposes a distinct 72-hour TPSP-related notification duty for assuming insurers.

Claims (1):

  • Under the Connecticut Insurance Data Security Law, a licensee acting as an assuming insurer must notify affected ceding insurers and its domiciliary regulator of a cybersecurity event involving nonpublic information in the possession of a third-party service provider (TPSP) not later than 72 hours after the assuming insurer received notice from the TPSP.

Key findings (1)

  • — source on file
Category narrative98 words

CTDPA carves out entities/data already regulated by federal sectoral frameworks: HIPAA-covered entities and business associates, GLBA-regulated financial institutions, FCRA data, and the Connecticut Insurance Data Security Law (Bulletin IC-42, implementing an NAIC-model cybersecurity-event notification regime for licensees, including a 72-hour notification duty for TPSP-related events to ceding insurers/domiciliary regulators). The AG's Privacy and Data Security Department also enforces HIPAA, COPPA, and FCRA under delegated federal authority. The 2026 amendments (per the IAPP analysis of the vetoed/passed amendment) propose narrowing exemptions for specific financial, insurance, and health company sub-categories and aligning a GLBA data exemption with most other states.

Periodic update · new data 2026-09-22

Sectoral Watch

The financial sector saw a structurally significant narrowing of its CTDPA exemption this cycle. Previously, GLBA-regulated entities benefited from a blanket entity-level exemption -- meaning the entire entity, and effectively all of its data processing, sat outside CTDPA scope simply by virtue of being GLBA-regulated. That blanket exemption is replaced by a data-level exemption specific to GLBA information itself, alongside a considerably narrower entity-level exemption available only to certain traditional financial institutions.

The practical effect is that financial-sector businesses previously able to rely on their GLBA status to sit entirely outside the CTDPA must now assess, data category by data category, which of their processing activities actually qualifies for the narrower exemption -- and which does not and therefore falls under full CTDPA obligations for the first time. This is a Confirmed finding and is one of the more consequential sectoral changes in this cycle's amendment package, since it functionally expands CTDPA coverage into financial-sector processing that was previously exempt wholesale.

Outlook

Financial institutions operating in Connecticut should conduct a data-level exemption analysis now rather than continuing to rely on entity-level GLBA status, given the narrowed exemption took effect July 1, 2026. Which specific data categories qualify as GLBA information for exemption purposes, versus which fall outside it, is likely to be a focus of forthcoming guidance or enforcement activity.

Sources and claims (3)
  1. ConfirmedConnecticut Insurance Department — Under the Connecticut Insurance Data Security Law, a licensee acting as an assuming insurer must notify affected ceding insurers and its domiciliary regulator of a cybersecurity event involving nonpublic information in the possession of a third-party service provider (TPSP) not later than 72 hours after the assuming insurer received notice from the TPSP.observed
  2. ConfirmedConnecticut Office of the Attorney General — The CTDPA applies to all Consumer Health Data Controllers doing business in or targeting Connecticut residents regardless of size or processing volume, with no revenue or processing threshold and no nonprofit exemption.observed
  3. ConfirmedConnecticut Office of the Attorney General — The AG's Privacy and Data Security Department is responsible for enforcement of federal laws under which the Attorney General has enforcement authority, including HIPAA, COPPA, and the Fair Credit Reporting Act.observed

#

Universal opt-out signal recognition and dark-pattern prohibition are already in force and actively enforced; upcoming geolocation/personalized-pricing rules are enacted but not yet effective.

Primary frameworkConnecticut Data Privacy Act (CTDPA); Public Act No. 26-64
Traffic-light rationale — GreenUniversal opt-out signal recognition and dark-pattern prohibition are already in force and actively enforced; upcoming geolocation/personalized-pricing rules are enacted but not yet effective.

Sub-modules (6)

Cookies And TrackersGreen

No dedicated cookie-consent statute; tracking for targeted advertising/sale falls under the general CTDPA opt-out and universal-signal framework.

Claims (1):

  • As of January 1, 2025, Connecticut consumers can send an opt-out preference signal, such as the Global Privacy Control, through a privacy-protective browser or browser extension, to automatically tell controllers they intend to opt out of targeted advertising and sale of personal data.

Dark PatternsGreen

Consent cannot be obtained through the use of dark patterns under the CTDPA.

Claims (1):

  • A consumer's consent under the CTDPA must be freely given, specific, informed and unambiguous, cannot be obtained through dark patterns, and controllers must provide an effective revocation mechanism at least as easy as the consent mechanism, ceasing processing within 15 days of revocation.

Opt Out SignalsGreen

As of January 1, 2025, businesses covered under the CTDPA must honor universal opt-out preference signals like the Global Privacy Control sent via a privacy-protective browser or extension, without requiring authentication.

Claims (2):

  • As of January 1, 2025, Connecticut consumers can send an opt-out preference signal, such as the Global Privacy Control, through a privacy-protective browser or browser extension, to automatically tell controllers they intend to opt out of targeted advertising and sale of personal data.
  • Unlike Colorado's law, the CTDPA does not require controllers to authenticate opt-out signals, making it easier for consumers to exercise universal opt-out rights, similar to the approach under the California Privacy Rights Act.

Clean Rooms And DcrRed

No CTDPA-specific clean-room/data-collaboration-room provision identified.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingAmber

CTDPA regulates 'sale' of personal data and 'targeted advertising' analogous to CPRA's sale/share concepts, but does not use CPRA's specific 'cross-context behavioral advertising/share' terminology.

Claims (1):

  • Connecticut consumers have the right to opt out of the sale of their personal data and targeted advertising, and, under the 2026 amendments, to know whether a controller is processing their personal data for profiling that produces a legal or similarly significant effect.

Direct MarketingGreen

Targeted advertising and sale of personal data for marketing purposes are subject to opt-out rights and, for minors under 16, to opt-in consent requirements.

Claims (1):

  • Controllers must obtain opt-in consent before selling a consumer's personal data or processing it for targeted advertising when the consumer is under 16 years old, or where the controller has actual knowledge or willfully disregards that the consumer is between 13 and 16.

Key findings (1)

  • — source on file
Category narrative82 words

CTDPA requires an easily accessible opt-out link for targeted advertising/sale on websites and apps, and since January 1, 2025 requires controllers to honor universal opt-out preference signals (e.g., Global Privacy Control) sent through a privacy-protective browser or extension, without requiring authentication of the signal. Consent for material new purposes, sale, or targeted advertising cannot be obtained through dark patterns. Public Act 26-64 (effective Oct 1, 2026) newly prohibits sale/sharing of precise geolocation data and regulates personalized pricing based on consumer personal data.

Periodic update · new data 2026-09-22

AdTech & Commercial Privacy

Public Act 26-64 introduces a ban on surveillance pricing by retail sellers and third-party delivery services, subject to certain carve-outs, taking effect October 1, 2026. Alongside the ban itself, the Act requires disclosure wherever a price-setting device uses personal data to set a price for a consumer -- meaning even where a carve-out permits some form of personalized pricing, the business must disclose that personal data is being used to determine what the consumer pays.

This sits alongside the geolocation sale ban discussed under Lawful Processing & Special Data as part of the same PA 26-64 package, and together the two provisions target commercial data practices that monetize granular consumer data -- location and purchasing-context data respectively -- in ways the original 2022 CTDPA did not directly address. This is a Confirmed finding, sourced from secondary law-firm reporting on the enacted Act.

Outlook

Retailers and delivery platforms operating in Connecticut should map their pricing algorithms against the October 1, 2026 effective date to determine whether any personal-data-driven pricing practice falls within the carve-outs or requires disclosure, or must be discontinued outright as prohibited surveillance pricing.

Sources and claims (3)
  1. ConfirmedConnecticut Office of the Attorney General — As of January 1, 2025, Connecticut consumers can send an opt-out preference signal, such as the Global Privacy Control, through a privacy-protective browser or browser extension, to automatically tell controllers they intend to opt out of targeted advertising and sale of personal data.observed
  2. ProbableInternational Association of Privacy Professionals — Unlike Colorado's law, the CTDPA does not require controllers to authenticate opt-out signals, making it easier for consumers to exercise universal opt-out rights, similar to the approach under the California Privacy Rights Act.observed
  3. ConfirmedConnecticut Office of the Attorney General — Controllers must obtain opt-in consent before selling a consumer's personal data or processing it for targeted advertising when the consumer is under 16 years old, or where the controller has actual knowledge or willfully disregards that the consumer is between 13 and 16.observed

#

Meaningful ADM-transparency and biometric/neural-data protections are enacted, but several of the most consequential provisions (facial recognition limits, expanded biometric/genetic/neural categories, AI training-data disclosure) are not yet effective as of the run date.

Primary frameworkConnecticut Data Privacy Act (CTDPA); Public Act No. 26-64
Traffic-light rationale — AmberMeaningful ADM-transparency and biometric/neural-data protections are enacted, but several of the most consequential provisions (facial recognition limits, expanded biometric/genetic/neural categories, AI training-data disclosure) are not yet effective as of the run date.

Sub-modules (6)

Profiling RestrictionsGreen

Controllers must conduct a Data Protection Assessment before processing personal data for profiling presenting a reasonably foreseeable risk of substantial injury to consumers, and must obtain consent before profiling a minor's personal data.

Claims (2):

  • Controllers must conduct a Data Protection Assessment before processing personal data for the purposes of profiling where such profiling presents a reasonably foreseeable risk of substantial injury to consumers.
  • A controller must obtain consent prior to processing a minor's personal data for profiling.

Automated Decision Making TransparencyAmber

The 2026 amendments grant consumers rights to know whether profiling is used to make legally or similarly significant decisions and, where feasible, to question results, learn the decision's reasoning, review the data used, and — for housing decisions specifically — correct data and obtain reevaluation.

Claims (1):

  • New consumer rights let Connecticut residents obtain a list of third parties to which a business sold their data, access inferences drawn from their personal data, and know whether profiling is used to make a decision producing legal or similarly significant effects, with feasible rights to question results, learn reasoning, review data used, and (for housing decisions) correct data and obtain reevaluation.

Ai Risk AssessmentsAmber

A new disclosure requirement enacted for 2025/2026 requires companies to disclose whether personal data is used to train large language models; Senate Bill 5 separately establishes broader AI regulatory measures in Connecticut.

Claims (1):

  • New disclosure requirements enacted for the CTDPA require companies to disclose whether personal data is used to train large language models.

Biometric RegimeAmber

The 2026 amendments drastically expand biometric-data coverage under 'sensitive data' to include such data regardless of purpose of collection and to include information derived therefrom; Public Act 26-64 separately introduces facial-recognition-technology limitations and transparency requirements effective October 1, 2026.

Claims (2):

  • The 2026 CTDPA amendment drastically expands the biometric and genetic data categories, removing the existing purpose-based limitation to include such data regardless of collection purpose and to include information derived therefrom, i.e., inferences created from genetic or biometric data.
  • Public Act No. 26-64 introduces and revises the definition of 'facial recognition technology' and sets limitations and transparency requirements for its use, with these provisions taking effect October 1, 2026.

Genetic DataAmber

The AG's 2026 report recommends adoption of a standalone genetic-data privacy law; in the interim, genetic data is covered as sensitive data under the CTDPA as amended, with expanded coverage of genetically-derived inferences.

Claims (2):

  • The Connecticut Attorney General's 2026 report on the CTDPA recommends the state legislature adopt a standalone genetic data privacy law, alongside adoption of a genetic-testing amendment expansion already introduced via Senate Bill 4.
  • The 2026 CTDPA amendment drastically expands the biometric and genetic data categories, removing the existing purpose-based limitation to include such data regardless of collection purpose and to include information derived therefrom, i.e., inferences created from genetic or biometric data.

State Surveillance CarveoutsRed

No CTDPA-specific national-security/state-surveillance carveout distinct from general exemptions was identified in the sources reviewed.

Absence provenance: unavailable. Searched: unavailable.

Key findings (1)

  • — source on file
Category narrative99 words

CTDPA requires opt-in consent for profiling presenting a foreseeable risk of substantial injury, and (as of the 2026 amendments) grants consumers rights to know when profiling produces legal/similarly-significant effects and to question/challenge automated decisions where feasible, including a specific correction/reevaluation right for housing-related automated profiling decisions. Public Act 26-64 (effective Oct 1, 2026) introduces facial-recognition-technology transparency/limitation requirements, and the 2026 sensitive-data amendments drastically expand biometric and genetic data categories to include information 'derived therefrom' and add a first-in-the-nation neural-data category. A new AI-specific disclosure requirement mandates that companies disclose whether personal data is used to train large language models.

Periodic update · new data 2026-09-22

Algorithmic, Biometric & Surveillance Governance

Connecticut enacted a new omnibus AI statute this cycle covering employment, healthcare and online-safety contexts, with core transparency provisions taking effect October 1, 2026. Within this statute, the Automated Employment-Related Decision Technology provisions require deployers to notify affected employees and job applicants of the technology's use, its purpose, the categories of data involved and their sources, and to retain documentation related to that use. These employment-specific AEDT obligations, however, do not take effect until October 1, 2027 -- a full year after the statute's other core transparency provisions -- giving employers a longer compliance runway for this particular obligation set.

This staggered effective-date structure is itself notable: the legislature appears to have deliberately sequenced the employment-technology obligations later than the statute's broader transparency requirements, likely reflecting the operational complexity of retrofitting notification and documentation processes into existing employment-decision technology deployments. This is a Confirmed finding sourced from secondary law-firm reporting on the enacted statute.

Outlook

Employers deploying automated employment-decision technology in Connecticut have until October 1, 2027 to build out the required notification and documentation processes, but should begin now given the operational lead time such processes typically require. The statute's broader online-safety and healthcare AI provisions, effective a year earlier, warrant separate compliance attention in the interim.

Sources and claims (7)
  1. ConfirmedInternational Association of Privacy Professionals — Controllers must conduct a Data Protection Assessment before processing personal data for the purposes of profiling where such profiling presents a reasonably foreseeable risk of substantial injury to consumers.observed
  2. ConfirmedConnecticut Office of the Attorney General — A controller must obtain consent prior to processing a minor's personal data for profiling.observed
  3. ConfirmedConnecticut Office of the Attorney General — New consumer rights let Connecticut residents obtain a list of third parties to which a business sold their data, access inferences drawn from their personal data, and know whether profiling is used to make a decision producing legal or similarly significant effects, with feasible rights to question results, learn reasoning, review data used, and (for housing decisions) correct data and obtain reevaluation.observed
  4. ConfirmedConnecticut Office of the Attorney General — New disclosure requirements enacted for the CTDPA require companies to disclose whether personal data is used to train large language models.observed
  5. ConfirmedInternational Association of Privacy Professionals — The 2026 CTDPA amendment drastically expands the biometric and genetic data categories, removing the existing purpose-based limitation to include such data regardless of collection purpose and to include information derived therefrom, i.e., inferences created from genetic or biometric data.observed
  6. ConfirmedOneTrust DataGuidance — Public Act No. 26-64 introduces and revises the definition of 'facial recognition technology' and sets limitations and transparency requirements for its use, with these provisions taking effect October 1, 2026.observed
  7. ConfirmedConnecticut Office of the Attorney General — The Connecticut Attorney General's 2026 report on the CTDPA recommends the state legislature adopt a standalone genetic data privacy law, alongside adoption of a genetic-testing amendment expansion already introduced via Senate Bill 4.observed

#

Substantial, actively-enforced minors' protections are already in force (since Oct 1, 2024), but the most far-reaching addictive-design/algorithm-consent measures are enacted with a multi-year phase-in to 2028, and the AG's own report flags continued gaps in the definition/scope of protections.

Primary frameworkConnecticut Data Privacy Act (CTDPA), as amended by the Online Privacy Act and subsequent minors'-privacy amendments
Traffic-light rationale — AmberSubstantial, actively-enforced minors' protections are already in force (since Oct 1, 2024), but the most far-reaching addictive-design/algorithm-consent measures are enacted with a multi-year phase-in to 2028, and the AG's own report flags continued gaps in the definition/scope of protections.

Sub-modules (5)

Age VerificationAmber

CTDPA relies on an actual-knowledge/willful-disregard standard for identifying minors under 16 (and generally under 18 for enhanced online-service protections) rather than mandating affirmative age-verification technology.

Claims (1):

  • Consent is required to process a consumer's personal data for targeted advertising or to sell their data where a controller has actual knowledge of, and willfully disregards, that the consumer is between 13 and 16 years old.

Minor Profiling BansGreen

Controllers must obtain consent before processing a minor's personal data for profiling, and may not process a minor's data for targeted advertising or sale.

Claims (2):

  • A controller shall not process a minor's data for purposes of targeted advertising or any sale, and shall not use any design feature to significantly increase, sustain, or extend a minor's use of an online service, product, or feature.
  • A controller must obtain consent prior to processing a minor's personal data for profiling.

Education SettingsAmber

FERPA-regulated education records are exempted from CTDPA; no CT-specific education-technology privacy statute distinct from FERPA/COPPA was identified for this run.

Absence provenance: unavailable. Searched: unavailable.

Claims (1):

  • The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.

Dependent AdultsRed

No CTDPA provision specific to dependent/incapacitated adults distinct from the general consumer-rights framework was identified.

Absence provenance: unavailable. Searched: unavailable.

Key findings (1)

  • — source on file
Category narrative102 words

CTDPA layers state-specific minors' protections atop COPPA: opt-in consent is required before selling personal data or using it for targeted advertising for consumers under 16 (with an actual-knowledge/willful-disregard standard for 13-16 year-olds as of 2025); minors under 18 receive additional protections from controllers offering online services/products/features directed at minors, including bans on targeted advertising/sale of a minor's data, consent-before-profiling, restrictions on precise-geolocation collection, addictive-design-feature prohibitions, and default settings limiting adult-to-minor direct messaging. Further youth social-media-addiction measures (including a parental-consent requirement for algorithmic feeds) are enacted but do not take effect until 2028. Parents/legal guardians may exercise a child's rights on their behalf.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy Professionals — Consent is required to process a consumer's personal data for targeted advertising or to sell their data where a controller has actual knowledge of, and willfully disregards, that the consumer is between 13 and 16 years old.observed
  2. ConfirmedConnecticut Office of the Attorney General — If a child's personal data is processed by a controller, the child's parent or legal guardian may exercise rights on the child's behalf, and controllers must follow COPPA regulations including parental-consent requirements.observed
  3. ConfirmedConnecticut Office of the Attorney General — A controller shall not process a minor's data for purposes of targeted advertising or any sale, and shall not use any design feature to significantly increase, sustain, or extend a minor's use of an online service, product, or feature.observed

#

Active, escalating enforcement program with a public settlement, annual statutory reporting, and clear statutory penalty/no-private-right-of-action posture — well documented and current as of the run date.

Primary frameworkConnecticut Data Privacy Act (CTDPA); Connecticut Unfair Trade Practices Act (CUTPA), Conn. Gen. Stat. §§ 42-110a et seq.
Traffic-light rationale — GreenActive, escalating enforcement program with a public settlement, annual statutory reporting, and clear statutory penalty/no-private-right-of-action posture — well documented and current as of the run date.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The AG has exclusive enforcement authority; violations are treated as unfair trade practices under CUTPA, carrying civil penalties of up to $5,000 per willful violation.

Claims (2):

  • The Attorney General has exclusive authority to enforce violations of the CTDPA.
  • Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.

Enforcement Activity IndexGreen

By the end of 2025, the AG's office had issued dozens of notices of violation/warning letters, finalized multiple data-breach settlements, and resolved its first formal CTDPA enforcement action; the TicketNetwork matter settled for $85,000 in mid-2025.

Claims (2):

  • By the end of 2025, the AG's office had issued dozens of notices of violation and warning letters, finalized multiple data breach settlements, and resolved its first enforcement action under the CTDPA.
  • The Connecticut Attorney General announced a settlement with TicketNetwork, Inc. under which the company agreed to comply with the CTDPA, maintain consumer-rights-request metrics, report those metrics to the AG, and pay $85,000.

Regulator Funding And CapacityAmber

Enforcement is conducted through the AG's Privacy and Data Security Department/Section, which also handles federal HIPAA/COPPA/FCRA enforcement delegated to the state; no specific headcount or budget figures were identified in the sources reviewed.

Absence provenance: unavailable. Searched: unavailable.

Claims (1):

  • SRC_placeholder (claim on file)

Collective Redress And Class ActionsAmber

No CTDPA-specific collective-redress or class-action mechanism was identified; general Connecticut civil procedure class-action rules would apply to any underlying tort/CUTPA claim, but CTDPA itself channels enforcement solely through the AG.

Absence provenance: unavailable. Searched: unavailable.

Claims (1):

  • Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.

Private Right Of ActionRed

The CTDPA does not include a private cause of action for individuals; enforcement is exclusively through the Attorney General.

Claims (1):

  • Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.

Recent Developments 180DAmber

Within the last 180 days of the run date (2026-08-05): AG Tong released the third annual CTDPA enforcement report (Feb 5, 2026) disclosing the first resolved enforcement action and new investigations into chatbots/AI products harming minors; Governor Lamont signed Senate Bill 4 (Public Act 26-64) on May 27, 2026 adding data-broker registration and facial-recognition rules effective Oct 1, 2026; and CTDPA amendments broadening applicability thresholds and sensitive-data categories took/take effect July 1, 2026.

Claims (3):

  • By the end of 2025, the AG's office had issued dozens of notices of violation and warning letters, finalized multiple data breach settlements, and resolved its first enforcement action under the CTDPA.
  • Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.
  • Amendments to the CTDPA going into effect on July 1, 2026 broaden applicability thresholds, including making all sensitive-data processing and all sales of personal data covered under the law.

Key findings (1)

  • — source on file
Category narrative107 words

The Attorney General has exclusive enforcement authority; the CTDPA carries civil penalties of up to $5,000 per willful violation under CUTPA, and the statutory 60-day cure period sunset on January 1, 2025, giving the AG discretion whether to offer cure opportunities thereafter. There is no private right of action. The AG's third annual report (Feb 5, 2026) disclosed the office's first resolved CTDPA enforcement action, multiple data-breach settlements, dozens of notices of violation/warning letters, and ongoing investigations into connected vehicles, social media/gaming platforms, and AI chatbots affecting minors. A notable public settlement was reached with TicketNetwork ($85,000) in mid-2025 for CTDPA violations tied to deficient consumer-rights mechanisms.

Periodic update · new data 2026-09-22

Enforcement & Redress

Connecticut's enforcement exposure for businesses under the CTDPA increased materially this cycle through two compounding changes: the applicability threshold was lowered (bringing more businesses into scope, as discussed under Regulator & Framework), and a previously guaranteed cure period was eliminated entirely. Together, these changes mean that a materially larger population of businesses is now both subject to the Act and no longer entitled to a guaranteed opportunity to cure a violation before facing enforcement action -- a significant escalation in practical enforcement risk relative to the original 2022 regime.

The legislative history behind this shift is itself notable: Governor Ned Lamont signed Public Act 26-64 (SB 4) on May 27, 2026, with the legislature returning twice more in quick succession to amend it further via HB 5222 on June 2, 2026 and HB 5563 on June 4, 2026 -- indicating an active and iterative legislative process around the enforcement architecture rather than a single settled enactment. Both structural findings here are Confirmed, sourced from secondary law-firm reporting on the enacted amendment packages.

Outlook

Businesses should assume that the cure-period safety net is gone and calibrate compliance timelines accordingly, since the elimination of a guaranteed cure period means a first violation can now proceed directly to formal enforcement. Whether the Attorney General's office has issued or plans to issue enforcement-priority guidance following these changes was not established this cycle.

Sources and claims (4)
  1. ConfirmedConnecticut Office of the Attorney General — The Attorney General has exclusive authority to enforce violations of the CTDPA.observed
  2. ConfirmedConnecticut Office of the Attorney General — Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.observed
  3. ConfirmedConnecticut Office of the Attorney General — By the end of 2025, the AG's office had issued dozens of notices of violation and warning letters, finalized multiple data breach settlements, and resolved its first enforcement action under the CTDPA.observed
  4. ConfirmedConnecticut Office of the Attorney General — The Connecticut Attorney General announced a settlement with TicketNetwork, Inc. under which the company agreed to comply with the CTDPA, maintain consumer-rights-request metrics, report those metrics to the AG, and pay $85,000.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct47.62
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Connecticut, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 42 claim(s) (42 category placement(s)), 26 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Strong T1 (Connecticut AG portal.ct.gov) and T2 (AG press releases, enforcement reports) coverage for regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress. sectoral_watch drew on a mix of T1/T2 (AG, CT Insurance Department Bulletin IC-42) sources. cross_border_and_adequacy is a genuine, explicitly-flagged regulatory gap (red traffic light, empty claims[], absent_field_provenance on every sub-module) rather than a research shortfall, consistent with US state comprehensive privacy statutes generally lacking GDPR-style transfer mechanisms. Several sub-modules (dpo_requirements, ropa_requirements, clean_rooms_and_dcr, state_surveillance_carveouts, dependent_adults, regulator_funding_and_capacity) relied on T3/negative-search absent_field_provenance because no CTDPA-specific provision was located. Amendment-heavy areas (biometric/genetic/neural data, facial recognition, AI training-data disclosure, data broker registration) are correctly tagged 'enacted_not_yet_effective' with July 1, 2026 or October 1, 2026 effective dates per the CAUTION flag on verifying current effective-date status.

Unresolved questions (4):

  • Exact final statutory text and section numbering for the July 1, 2026 CTDPA amendments (threshold and sensitive-data changes) had not been codified into the Connecticut General Statutes as of the research date; AG business-guidance PDF and press materials were used as the best available T1/T2 proxy.
  • Whether Public Act 26-64's financial/insurance/political-committee exemption carve-outs (reported by IAPP) were enacted in final form or amended before passage was not independently confirmed against the enrolled bill text.
  • No confirmed data point on Connecticut AG Privacy Section staffing/budget levels was located to support regulator_funding_and_capacity claims.
  • Precise operative date and scope of the SB1295/'algorithm ban without parental consent' 2028 measure could not be fully verified beyond the AG's press-release summary.

Escalate to primary-source review: yes