California vs Connecticut Privacy Law Comparison
Understanding the differences between California's CCPA/CPRA and Connecticut's CTDPA is essential for businesses operating across state lines. California's law became effective January 1, 2020, while Connecticut's law took effect July 1, 2023. Below is a detailed side-by-side comparison covering applicability thresholds, consumer rights, enforcement, and more.
Reviewed by PrivacyLawMap editorial team · Last verified: 2026-08-13
Start with the California data privacy law guide and the Connecticut data privacy law guide for the full state-specific thresholds, rights, source links, and checklist steps behind this comparison.
To weigh the real-world stakes behind these two laws, see documented CCPA/CPRA fines and privacy penalties from actual state enforcement actions in the penalties tracker.
CCPA/CPRA vs CTDPA: the key differences at a glance
The biggest difference between California's CCPA/CPRA and Connecticut's CTDPA (as of 2026) is that California's CCPA/CPRA grants consumers a private right of action (the ability to sue directly in some circumstances), while Connecticut's CTDPA is enforced only by regulators.
- Maximum civil penalty: CCPA/CPRA up to $7,988 per violation vs CTDPA up to $5,000 per violation.
- Right to cure: CCPA/CPRA has no cure period vs CTDPA with no cure period.
- Private right of action: yes under CCPA/CPRA vs no under CTDPA.
- Universal opt-out (GPC) signals: must be honored under CCPA/CPRA vs must be honored under CTDPA.
- Effective date: CCPA/CPRA since January 1, 2020 vs CTDPA since July 1, 2023.
Primary sources: CCPA/CPRA Full Text (California Legislative Information) · CTDPA (Public Act 22-15) Full Text · Verified 2026-08-13.
Swipe the table sideways to see every state column.
| Category | California CCPA/CPRA | Connecticut CTDPA |
|---|---|---|
| Thresholds & Applicability | ||
Effective Date | Jan 1, 2020 | Jul 1, 2023 |
Revenue Threshold | $25M | None |
Consumer Count | 100,000 | 35,000 |
Data Sale % Threshold | 50% | 25% |
| Consumer Rights | ||
Right to Access | ||
Right to Deletion | ||
Right to Correction | ||
Opt-Out of Sale | ||
Opt-Out Targeted Ads | ||
Opt-Out Profiling | ||
Limit Sensitive Data | ||
Right to Appeal | ||
Private Right of Action | ||
| Enforcement & Compliance | ||
Universal Opt-Out Required | ||
Cure Period | None | None |
Penalty / Violation | $7,988 | $5,000 |
Enforcement Body | California Privacy Protection Agency (CPPA) and California Attorney General | Connecticut Attorney General |
Sensitive Data Consent | Opt-In | Opt-In |
Data Broker Provisions | California has a separate Data Broker Registration law (SB 362 — the California Delete Act, effective 2024) requiring data brokers to register with the CPPA, pay annual fees, and comply with the Delete Request and Opt-out Platform (DROP). The DROP system launched January 1, 2026 for consumer registration; starting August 1, 2026, data brokers must access the DROP at least every 45 days to process deletion requests. Non-registration carries fines of $200 per day. Failure to process deletion requests incurs $200 per request per day of non-compliance. The CPPA launched a Data Broker Enforcement Strike Force in January 2026 to actively pursue non-compliant brokers. Separately, the Delete Act requires every registered data broker to undergo an independent third-party audit of its Delete Act compliance beginning January 1, 2028 and once every three years thereafter (Civil Code §1798.99.86); brokers must keep the audit report for at least six years and submit it to CalPrivacy upon written request. This triennial data-broker audit is distinct from the CCPA cybersecurity audit and applies regardless of a broker's revenue. | Connecticut now has a separate data broker registration and deletion-mechanism law under SB 4 / Public Act 26-64. The framework takes effect October 1, 2026; data brokers may not sell or license brokered personal data in Connecticut on or after January 1, 2027 unless registered with the Department of Consumer Protection. Registration and renewal fees are $2,500. DCP must establish the accessible deletion mechanism by July 1, 2028, and registered data brokers must access it at least once every 45 days starting October 1, 2028. |
Highlighted rows indicate differences between the two states
California vs Connecticut: Common Questions
Not sure if California or Connecticut privacy laws apply to you?
Our free calculator analyzes your business details and tells you exactly which state privacy laws you need to comply with.
Turn this comparison into compliance documents
Privacy Policy Generator
Draft policy language that reflects the disclosure, rights, and opt-out duties that differ between California and Connecticut.
Opt-Out Link Generator
Create a state-aware opt-out page template for sale, sharing, targeted advertising, and profiling requests triggered by either law.