Privacy Law Library

Connecticut Data Privacy Act (Act Concerning Personal Data Privacy and Online Monitoring)

CTDPA

Comprehensive privacy · Children · Biometric · Location · Data security · Artificial intelligence

Connecticut's comprehensive consumer privacy law gives residents rights to access, correct, delete and port their data and to opt out of targeted advertising, sale and consequential profiling, and requires consent for sensitive data, privacy notices, recognition of opt-out preference signals, and data protection assessments. P.A. 25-113 (effective July 1, 2026) sharply broadened coverage (35,000-consumer threshold, any processor of sensitive data, any seller of data), added neural and financial-account data as sensitive data, added profiling rights and impact assessments, extended the teen targeted-advertising and sale ban to under-18s, and required disclosure of LLM training. P.A. 26-64 (effective October 1, 2026) bans the sale of precise geolocation data, restricts facial recognition used for security, and expands deletion rights over people-search profiles built from public information.

Where
Connecticut
Citation
Conn. Gen. Stat. 42-515 to 42-525 (ch. 743jj, part I); enacted by P.A. 22-15; amended by P.A. 23-56, 25-113 and 26-64
Status
In force
In force since
2023-07-01
Last amended
2026-10-01
Enforced by
Connecticut Attorney General (exclusive; Conn. Gen. Stat. 42-525(a))
People can sue
No
Penalties
A violation is an unfair trade practice under CUTPA enforced solely by the Attorney General (42-525(e)); CUTPA civil penalties are up to $5,000 per wilful violation and up to $25,000 per violation of an injunction (42-110o), plus injunctive relief. The mandatory 60-day cure period ended December 31, 2024; since January 1, 2025 a cure opportunity is at the Attorney General's discretion (42-525(b)-(c)). No private right of action (42-525(d)).
Applies to
  • Through 2026-06-30: persons doing business in Connecticut or targeting its residents that in the prior calendar year controlled or processed personal data of 100,000+ consumers (excluding payment-only data), or 25,000+ consumers while deriving over 25% of gross revenue from selling personal data (42-516, 2025 rev.)
  • From 2026-07-01 (P.A. 25-113, s. 6): persons that (1) do business in or target Connecticut and processed personal data of 35,000+ consumers, (2) control or process any consumer's sensitive data, or (3) offer consumers' personal data for sale, regardless of volume (42-516)
  • Exempt entities include state and municipal bodies, nonprofits, institutions of higher education, HIPAA covered entities and business associates, tribal governments, air carriers and national securities associations; from 2026-07-01 the entity-level GLBA exemption is replaced by exemptions for insurers, certain banks and credit unions, broker-dealers and investment advisers, and political committees, with GLBA-covered data exempt at the data level (42-517(a), (b) as amended by P.A. 25-113, s. 7)
  • 'Consumer' means a Connecticut resident; individuals acting in a commercial or employment context are excluded (42-515)

What a privacy notice must say

  • Provide a clear privacy notice listing categories of data processed, purposes, how to exercise and appeal rights, data sold and categories of buyers, targeted-advertising disclosures and a contact method; from 2026-07-01 also whether data are used to train large language models and the date last updated, posted via a 'privacy' link.Conn. Gen. Stat. 42-520(b) as amended by P.A. 25-113, s. 9

Rights it gives people

  • Deletion right extends to publicly available information collated into a consumer profile offered on a public website or offered for sale, and to inferences generated from it.Conn. Gen. Stat. 42-518(a)(3) as amended by P.A. 26-64, s. 13 · From 2026-10-01
  • Consumers subject to a consequential automated profiling decision may question the result, learn the reason, review the data used and, for housing decisions, correct data and obtain reevaluation; consumers may also obtain a list of third parties to which their data were sold.Conn. Gen. Stat. 42-518(a)(6)-(7) (P.A. 25-113, s. 8) · From 2026-07-01
  • Consumers may confirm and access their personal data (from 2026-07-01 including inferences and whether data are used for consequential profiling), correct it, delete it, obtain a portable copy, and opt out of targeted advertising, sale, and profiling in furtherance of automated decisions with legal or similarly significant effects.Conn. Gen. Stat. 42-518(a)(1)-(5)

Practices it requires

  • Do not process data for targeted advertising or sell it without consent where the controller knows or wilfully disregards that the consumer is 13 to 15 years old; from 2026-07-01 the ban is absolute for ages 13 to 17.Conn. Gen. Stat. 42-520(a)(7) (2025 rev.); 42-520(a)(1)(I) as amended by P.A. 25-113, s. 9
  • Honor opt-outs sent through a clear website link and through opt-out preference signals such as browser or device settings; do not require account creation to exercise rights.Conn. Gen. Stat. 42-520(c)
  • Respond to consumer requests within 45 days (one 45-day extension), free once per 12 months, and provide an appeal process with a written decision within 60 days that points the consumer to the Attorney General if denied.Conn. Gen. Stat. 42-518(c)-(d)
  • Obtain consent before processing sensitive data (race or ethnicity, religion, health, sex life or sexual orientation, citizenship, consumer health data, genetic or biometric data, children's data, crime-victim status, precise geolocation; from 2026-07-01 also neural data and financial account credentials), and from 2026-07-01 process it only where reasonably necessary and never sell it without consent.Conn. Gen. Stat. 42-515 (sensitive data), 42-520(a)(1)(D), (H)
  • No controller may sell any consumer's precise geolocation data (location within 1,750 feet), other than utility smart-meter data and communications content.Conn. Gen. Stat. 42-520(a)(3) as amended by P.A. 26-64, s. 14 · From 2026-10-01
  • A controller that uses facial recognition on its premises for security or fraud prevention must match only against a database it maintains itself, post legible signage at entrances with a link or QR code to its facial recognition policy, and include Attorney General contact information in that policy.Conn. Gen. Stat. 42-524(a)(2) as amended by P.A. 26-64, s. 16 · From 2026-10-01

Security duties

  • Maintain reasonable administrative, technical and physical data security practices appropriate to the volume and nature of the data.Conn. Gen. Stat. 42-520(a)(1)(C)

Other duties

  • Conduct and document data protection assessments for targeted advertising, sale, risky profiling and sensitive-data processing; from 2026-07-01 also impact assessments for consequential profiling; produce them to the Attorney General on request.Conn. Gen. Stat. 42-522
  • Processors must follow controller instructions under a binding contract, impose confidentiality on staff, delete or return data at the end of services, and assist with assessments and breach obligations.Conn. Gen. Stat. 42-521

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Whether the General Assembly passed any further 2026 CTDPA amendment beyond P.A. 26-64 was not checked against the full 2026 public act list.

Research reference, not legal advice.