Connecticut SB 4 Is Now Public Act 26-64: CTDPA Expansion, Data Broker Registry, and Geolocation Ban
Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.
Connecticut SB 4 at a Glance (Public Act 26-64, signed May 27, 2026)
Connecticut Public Act 26-64 (formerly Senate Bill 4) is a 2026 consumer-privacy law that Governor Ned Lamont signed on May 27, 2026, expanding the Connecticut Data Privacy Act (CTDPA) with a state-run data broker registry and deletion mechanism, a surveillance-pricing disclosure rule, facial-recognition signage duties, direct-to-consumer genetic-testing protections, and a ban on selling consumers’ precise geolocation data. Most amendments take effect October 1, 2026; data broker registration is required to sell or license brokered personal data starting January 1, 2027.
- Bill title: “An Act Concerning Consumer Privacy” (Senate Bill 4, 2026 regular session). Sponsored by Sen. James Maroney; reported out of the Joint Committee on General Law as substitute language (sSB 4 / File No. 285).
- Current status: Signed — Public Act No. 26-64. Governor Ned Lamont signed SB 4 into law on May 27, 2026, after the Senate passed it 31-4 on April 23 and the House passed it 141-6 on May 4. (Sources: CGA Public Act 26-64 PDF; LegiScan SB 4 history; Wilson Sonsini analysis; retrieved July 14, 2026.)
- Primary effective date: October 1, 2026 for most privacy amendments, the data broker framework, facial-recognition provisions, direct-to-consumer genetic-testing protections, and the precise-geolocation sale ban. The surveillance-pricing disclosure and retail restrictions phase in on a later timeline (see below).
- Relationship to SB 1295: SB 4 is separate from the CTDPA SB 1295 amendments (Public Act 25-153) Governor Lamont signed June 24, 2025 with a July 1, 2026 effective date. SB 4 layers ON TOP of SB 1295’s threshold reductions, GLBA tightening, and AI/LLM disclosure rules.
- Five major privacy frameworks: (1) data broker registry under the Department of Consumer Protection with $2,500 registration and renewal fees, (2) state-run accessible deletion mechanism, (3) surveillance-pricing disclosure and retail restrictions, (4) facial recognition technology signage and policy rules for certain on-premises security uses, (5) prohibition on selling consumers’ precise geolocation data.
- Data broker rollout: Data brokers may not sell or license brokered personal data in Connecticut on or after January 1, 2027 unless registered; DCP must establish the accessible deletion mechanism by July 1, 2028; registered brokers must check it at least once every 45 days starting October 1, 2028.
Connecticut Is Expanding Its Privacy Law — Again
Connecticut was one of the first states to pass a comprehensive data privacy law when it enacted the Connecticut Data Privacy Act (CTDPA) in 2022. The state has now enacted the most aggressive expansion yet. Senate Bill 4, sponsored by Sen. James Maroney, passed the Connecticut Senate on April 23, 2026 by a bipartisan 31-4 margin, passed the House on Monday, May 4, 2026 by an overwhelming 141-6 vote, and was signed into law by Governor Ned Lamont as Public Act No. 26-64 on May 27, 2026. Public Act 26-64 adds major new regulatory frameworks to the existing CTDPA: a state-administered data broker registry with mandatory registration fees, a Department of Consumer Protection-run accessible deletion mechanism, surveillance-pricing disclosure and retail restrictions, facial recognition technology signage and policy duties, direct-to-consumer genetic-testing protections, and an outright prohibition on selling consumers’ precise geolocation data.
Public Act 26-64 is distinct from SB 1295 (Public Act 25-153), which Governor Lamont signed June 24, 2025 and which takes effect July 1, 2026. SB 1295 lowered the CTDPA applicability threshold to 35,000 consumers, killed the GLBA entity-level exemption, and added the first state AI/LLM training-data disclosure requirement. Public Act 26-64 layers on top — a controller already preparing for SB 1295 now has an October 1, 2026 compliance wave for geolocation, pricing, facial recognition, genetic-testing, and CTDPA-definition changes, plus a January 1, 2027 registration deadline if it sells or licenses brokered personal data.
What Public Act 26-64 Changes
1. Data Broker Registry + State-Run Deletion Mechanism
Public Act 26-64 requires data brokers operating in Connecticut to register with the Department of Consumer Protection (not the Attorney General’s office). The act charges DCP with operating both the registry and a statewide accessible deletion mechanism modeled on California’s Delete Act (SB 362) — see our Vermont H 211 analysis (Vermont’s 2026 bill dropped its own deletion portal in the Senate). Key features:
- Mandatory registration before selling or licensing brokered personal data in Connecticut on or after January 1, 2027
- $2,500 initial and renewal fees deposited into the data broker registration account to fund deletion-mechanism infrastructure
- Public registry disclosing each broker’s website, consumer-rights page, categories of sensitive brokered personal information, and regulated-status disclosures
- Centralized consumer deletion request portal — DCP must build an accessible deletion mechanism by July 1, 2028, enabling Connecticut residents to send deletion requests to every registered broker except brokers the consumer excludes
- 45-day access cadence — starting October 1, 2028, registered brokers must access the deletion mechanism at least once every 45 days and process verified deletion requests
- Independent audits — registered brokers must obtain triennial independent audits beginning by July 1, 2031 and produce audit materials to DCP on request
For businesses, this means that if you buy, sell, license, or aggregate consumer data without a direct relationship with those consumers, you may need to register as a Connecticut data broker — in addition to existing obligations in California, Vermont, Oregon, and Texas. Connecticut is now on track to join California as a state with a working universal-deletion infrastructure.
2. Facial Recognition Technology Restrictions
The final facial recognition provisions are narrower than some earlier bill summaries suggested, but they still create concrete obligations for covered businesses. A controller or consumer health data controller that uses facial recognition technology on its premises for security, fraud, harassment, malicious-activity, system-integrity, or similar protective purposes must:
- Limit matching to still images or video matched against a database maintained exclusively by that controller or consumer health data controller
- Post clearly legible entrance signage where the technology is used, except for entrances to employee-only restricted areas
- Provide a hyperlink or QR code directing consumers to the business’s facial recognition technology policy
- Include Attorney General contact information in the facial recognition technology policy
This does not turn Connecticut into Illinois BIPA. There is still no private right of action under the CTDPA. But businesses using face-matching cameras in stores, venues, clinics, or offices should treat October 1, 2026 as the signage, policy, and database-isolation deadline.
3. Algorithmic / Surveillance Pricing Transparency
Public Act 26-64’s most novel provision is its “surveillance pricing” framework — the practice of using personal data, browsing history, location, biometric signals, device tracking, sensors, or other consumer signals to set individualized prices. The final act does two things:
- Online price-increase disclosure — a person doing business in Connecticut that increases an online price using a consumer’s personal data must display the disclosure: “THIS PRICE WAS INCREASED USING YOUR PERSONAL DATA” or a substantially similar disclosure. (Confirmed against Wilson Sonsini and Proskauer summaries of Public Act 26-64; retrieved July 14, 2026.)
- Retail and delivery-service restriction — retail sellers and third-party delivery services may not engage in surveillance pricing, subject to carveouts for loyalty, rewards, disclosed discounts, justifiable supply/demand differences, delivery-distance differences, and similar bona fide pricing differences.
Effective date for the pricing rules: unlike most Public Act 26-64 provisions (October 1, 2026), the surveillance-pricing disclosure and retail restrictions phase in later — per Proskauer’s analysis (retrieved July 14, 2026), the data-driven pricing obligations take effect July 1, 2027. Businesses should confirm the operative date against the enrolled Public Act text before relying on it.
Algorithmic pricing has become a flashpoint after reports of surge pricing, dynamic pricing, and personalized pricing in industries from e-commerce to insurance. Connecticut is now one of the first states to directly regulate the practice through consumer privacy and unfair-trade-practice law.
4. Precise Geolocation Data Sale Prohibition
Public Act 26-64 also prohibits controllers and third parties from selling any consumer’s precise geolocation data. The act defines precise geolocation data as location information that identifies an individual’s specific location within a radius of 1,750 feet, excluding communications content and certain utility-metering data. This mirrors the dedicated geolocation-sale bans in Maryland MODPA, Oregon HB 2008, and Virginia SB 338 (signed April 13, 2026). Combined with the existing CTDPA opt-in requirement and SB 1295’s broader sensitive-data treatment, Connecticut is now the fourth state with a hard prohibition on monetizing precise location data.
Current Status and Timeline (updated July 14, 2026)
SB 4 has cleared both chambers and is now Public Act 26-64. Key dates:
- February-March 2026 — Public hearings before the Joint Committee on General Law
- Late March 2026 — Voted out of the Joint Committee on General Law as substitute language (sSB 4 / File No. 285)
- April 23, 2026 — Senate passed sSB 4 by a 31-4 bipartisan vote and engrossed the bill the same day. (Sources: LegiScan SB 4 history; CT Mirror, April 23, 2026; retrieved May 5, 2026.)
- April 24, 2026 — OLR Bill Analysis published (2026SB-00004-R01-BA.PDF, retrieved May 5, 2026).
- Monday, May 4, 2026 — House passed SB 4 by a 141-6 bipartisan vote. Senate Democrats Maroney, Duff, and Delany issued a joint statement praising the House’s near-unanimous adoption. CT Mirror reported Governor Lamont had signaled support before enactment. (Sources: CT Mirror, May 4, 2026; Connecticut Senate Democrats statement, May 4, 2026; retrieved May 5, 2026.)
- Wednesday, May 6, 2026 — Sine die: Connecticut General Assembly 2026 session ends. SB 4 already cleared both chambers, so unlike most session-end bills, it is not vulnerable to the adjournment.
- May 27, 2026 — Governor Ned Lamont signs SB 4 into law as Public Act 26-64. The official CGA public-act PDF is published as 2026PA-00064-R00SB-00004-PA.PDF. (Signing date confirmed via Wilson Sonsini and Proskauer; retrieved July 14, 2026.)
- October 1, 2026 — Most privacy amendments and new frameworks take effect (data broker framework, geolocation-sale ban, facial-recognition duties, genetic-testing protections).
- January 1, 2027 — Data brokers may not sell or license brokered personal data in Connecticut unless registered with DCP.
- July 1, 2027 — Surveillance / data-driven pricing disclosure and retail restrictions take effect (per Proskauer analysis; confirm against the enrolled act).
- July 1, 2028 / October 1, 2028 — DCP must establish the accessible deletion mechanism by July 1; registered brokers must begin 45-day checks and deletion processing on October 1.
The 31-4 Senate margin and 141-6 House margin together signal overwhelming bipartisan support — uncommon for a privacy bill of this scope and a strong indicator that Connecticut intends to lead among states that already have a comprehensive privacy law. Businesses with Connecticut consumers should begin gap-assessing now against both SB 1295 (effective July 1, 2026) and Public Act 26-64 (mostly effective October 1, 2026) — a coordinated rollout, not two separate compliance projects.
How This Compares to Other States
| Feature | Connecticut (Public Act 26-64) | California (CCPA/CPRA) | Maryland (MODPA) |
|---|---|---|---|
| Data broker registration | Required starting 2027 | Required (Delete Act) | Not required |
| Facial recognition rules | Signage + policy for covered on-premises security uses | Limited (ADMT regulations pending) | Not specifically addressed |
| Algorithmic pricing transparency | Disclosure + retail restrictions | Not specifically addressed | Not specifically addressed |
| Data minimization | Existing (reasonable) | Existing (reasonable) | Strictest (necessary + proportionate) |
| Universal opt-out (GPC) | Required | Required | Not required |
What Businesses Should Do Now
1. Assess Data Broker Status
Determine whether your business qualifies as a data broker. If you collect and sell consumer data without a direct relationship, you may need to register. Check our data broker registration guide to see where you already have obligations.
2. Audit Biometric Data Practices
If your business uses facial recognition, fingerprint scanning, or other biometric technologies, document your current practices. For on-premises facial recognition used for security or fraud-prevention purposes, prepare signage, QR-code or hyperlink routing, and a facial recognition technology policy before October 1, 2026.
3. Review Pricing Algorithms
If you use personal data to set individualized prices, document how the algorithm works and what data inputs it uses. Consider whether you can offer a "standard price" option for consumers who opt out.
4. Ensure CTDPA Baseline Compliance
Before worrying about SB 4 additions, make sure you're compliant with the existing Connecticut Data Privacy Act. This includes honoring universal opt-out signals, processing consumer data requests, and conducting data protection assessments.
5. Use the Privacy Law Calculator
Check whether Connecticut's privacy laws apply to your business by using our Privacy Law Calculator. If they do, layer Public Act 26-64 into the same 2026 compliance roadmap instead of treating it as a later standalone project.
Frequently Asked Questions
Is Connecticut SB 4 law yet?
Yes. Governor Ned Lamont signed SB 4 into law on May 27, 2026, as Public Act No. 26-64, after the Senate passed the bill 31-4 on April 23 and the House passed it 141-6 on May 4. Most privacy amendments take effect October 1, 2026, with data broker registration required for selling or licensing brokered personal data starting January 1, 2027. (Sources: CGA Public Act 26-64 PDF, LegiScan SB 4 history, Wilson Sonsini; retrieved July 14, 2026.)
What is Connecticut’s surveillance pricing law, and what disclosure does it require?
Public Act 26-64 restricts “surveillance pricing” — using a consumer’s personal data (browsing history, location, device signals, and similar inputs) to set an individualized price. A business that increases an online price using a consumer’s personal data must display the disclosure “THIS PRICE WAS INCREASED USING YOUR PERSONAL DATA” (or substantially similar language). Separately, retail sellers and third-party delivery services may not engage in surveillance pricing at all, subject to carveouts for loyalty programs, disclosed discounts, and bona fide supply/demand or delivery-distance differences. Per Proskauer’s analysis (retrieved July 14, 2026), the pricing provisions take effect July 1, 2027 — later than the October 1, 2026 core amendments.
Does Connecticut ban selling precise geolocation data?
Yes. Public Act 26-64 prohibits controllers and third parties from selling any consumer’s precise geolocation data, defined as location information identifying an individual within a radius of 1,750 feet (excluding communications content and certain utility-metering data). Combined with the existing CTDPA opt-in requirement for sensitive data, this makes Connecticut one of a growing group of states — alongside Maryland, Oregon, and Virginia — with a hard prohibition on monetizing precise location data. The geolocation-sale ban takes effect October 1, 2026.
What is a data broker under Connecticut law?
Public Act 26-64 defines a data broker as a business, or a portion of a business, that sells or licenses brokered personal data to another person. Brokered personal data includes listed identifiers such as name, address, date of birth, government ID numbers, biometric data used for identification or authentication, family or household names/addresses, and other information that would let a reasonable person identify the consumer with reasonable certainty. Check our Data Broker Classification Quiz to assess your status.
Does SB 4 affect small businesses?
Yes, potentially. SB 1295 separately lowers the CTDPA baseline threshold to 35,000 Connecticut consumers effective July 1, 2026, and removes thresholds entirely for sensitive data processing and any data sale. Public Act 26-64's data broker framework is not limited to the old 100,000-consumer CTDPA threshold; if a smaller business sells or licenses brokered personal data in Connecticut, it should assess registration obligations. Use our calculator to check broader CTDPA coverage.
What about the CTDPA's existing requirements — do those change?
Public Act 26-64 adds new provisions on top of the existing CTDPA framework. The existing requirements — consumer rights, data protection assessments, opt-out preference signals, sensitive data protections — remain in effect. The new data broker, facial recognition, surveillance-pricing, geolocation-sale, and genetic-testing provisions are additional obligations.
When does Public Act 26-64 take effect?
Most privacy amendments in Public Act 26-64 take effect October 1, 2026. Data brokers may not sell or license brokered personal data in Connecticut on or after January 1, 2027 unless registered with DCP. DCP must establish the accessible deletion mechanism by July 1, 2028; DCP verification starts August 15, 2028; registered data brokers must access the mechanism at least once every 45 days starting October 1, 2028. Streaming-video ad-volume restrictions in section 20 take effect July 1, 2027.
Published: March 29, 2026. Last verified: July 14, 2026 — enactment date corrected to Governor Lamont’s May 27, 2026 signature, surveillance-pricing disclosure text corrected to the enacted “THIS PRICE WAS INCREASED USING YOUR PERSONAL DATA,” and pricing-provision effective date noted as July 1, 2027, against Wilson Sonsini and Proskauer analyses of Public Act 26-64 (date_retrieved: 2026-07-14).
Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.