The CTDPA compliance checklist is a 16-step plan for meeting the Connecticut Data Privacy Act (CTDPA), Connecticut's consumer privacy law, which took effect July 1, 2023. It is enforced by the Connecticut Attorney General, with civil penalties up to $5,000 per violation and no cure period. Work through every step below, then confirm your specific obligations with the free applicability calculator.
It is a 16-step plan organizations use to meet the Connecticut Data Privacy Act (CTDPA), which took effect July 1, 2023. The steps below cover consumer-rights request handling, privacy-notice disclosures, opt-out mechanisms, data-processing agreements, and security safeguards required under Connecticut law.
Who has to comply with the Connecticut Data Privacy Act?
The CTDPA generally applies to organizations that handle Connecticut residents' personal data above the law's revenue and data-volume thresholds. Whether it applies to you depends on the specifics — check your exact obligations with the free applicability calculator at /calculator rather than assuming.
What is the penalty for CTDPA non-compliance?
The Connecticut Attorney General can impose civil penalties of up to $5,000 per violation and no cure period. There is no private right of action, so enforcement comes from the state, not individual lawsuits. Figures verified July 28, 2026.
Put CTDPA Into Practice on Your SiteSponsored
Termly builds and maintains a Connecticut-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests CTDPA grants.