Connecticut Privacy Law
Connecticut Data Privacy Act
Overview
The Connecticut Data Privacy Act (CTDPA) — Public Act 22-15, codified at Conn. Gen. Stat. §§ 42-515 through 42-525 — was signed into law by Governor Ned Lamont on May 10, 2022, and became effective on July 1, 2023. Connecticut was the fifth US state (after California, Virginia, Colorado, and Utah) to enact a comprehensive consumer privacy law, but Attorney General William Tong has positioned it as one of the most consumer-protective: Connecticut was the first state where the cure period sunset on schedule (January 1, 2025), the first to actively enforce universal opt-out signal (GPC) recognition obligations, and — under SB 1295 — will be the first US state with an explicit AI/LLM training disclosure requirement and an enumerated profiling-contest right.
The CTDPA grants Connecticut residents seven core rights: access, correction, deletion, portability, opt-out of the sale of personal data, opt-out of targeted advertising, and opt-out of profiling that produces legal or similarly significant effects. Controllers must respond to verified consumer requests within 45 days (extendable once by an additional 45 days for complex requests), and must provide a clear appeals mechanism for denied requests with a final response within 60 days. Connecticut was among the first states to require businesses to honor universal opt-out mechanisms, with the GPC requirement taking effect January 1, 2025 — and the Connecticut AG's Privacy and Data Security Section has publicly identified GPC compliance, dark patterns in cookie banners, and minors' data processing as its top three early enforcement priorities. The CTDPA does not include a private right of action; enforcement is exclusively through the Attorney General under the Connecticut Unfair Trade Practices Act (CUTPA), with penalties of up to $5,000 per willful violation plus restitution and injunctive relief.
The Connecticut AG's "right to cure" expired by statute on December 31, 2024, making Connecticut the first state where comprehensive privacy law violations can be prosecuted without any mandatory cure window. AG Tong's office has confirmed that, while the office may still extend informal cure opportunities at its discretion, controllers receiving a notice of violation should assume the AG is prepared to file suit if remediation is not completed promptly. As of early 2026, the office has issued multiple non-public notices of violation in cookie-banner dark-pattern and adtech-pixel cases, with the largest publicly disclosed CTDPA-cited matter to date being the TicketNetwork resolution announced in 2025.
The law was significantly overhauled by Senate Bill 1295 (Public Act 25-153), signed by Governor Lamont on June 24, 2025 and substantially effective July 1, 2026. SB 1295 makes Connecticut's law one of the most expansive in scope of any state privacy law: it lowers the base applicability threshold from 100,000 to 35,000 consumers (excluding payment-only transactions) — matching Maryland MODPA and Delaware's thresholds and pulling thousands of mid-market businesses into scope; it removes processing thresholds entirely for sensitive data and for any sale of personal data, meaning controllers handling any amount of sensitive data or selling any consumer data fall within scope regardless of company size; it eliminates the broad entity-level GLBA exemption that previously exempted virtually all financial institutions, replacing it with a narrower data-level exemption applicable only to data processed pursuant to GLBA; it requires controllers to disclose in privacy notices whether personal data is collected, used, or sold for training large language models — the first such state-law obligation in the US; it adds a consumer right to contest profiling results, request the reasoning and input data behind a profiling decision, and (for housing decisions) correct data and request human re-evaluation; it expands the sensitive data definition to include neural data, transgender or nonbinary status, financial account credentials, and government-issued identification numbers; it requires impact assessments for profiling that produces legal or similarly significant effects; and it strengthens minor protections by banning targeted advertising and data sale for minors aged 13-17 with no consent exception, requiring strict-necessity justification for collecting minors' precise geolocation, and prohibiting system-design features intended to significantly increase, sustain, or extend a minor's use of services.
Connecticut followed SB 1295 with Senate Bill 4, now Public Act 26-64, signed into law by Governor Ned Lamont on May 27, 2026. Public Act 26-64 adds a Department of Consumer Protection data broker registry and accessible deletion mechanism, a prohibition on selling consumers' precise geolocation data, surveillance-pricing disclosure and retail-sale restrictions, facial-recognition signage and policy duties for certain on-premises security uses, and direct-to-consumer genetic-testing protections. Most privacy amendments and the data broker framework take effect October 1, 2026; data brokers may not sell or license brokered personal data in Connecticut on or after January 1, 2027 unless registered.
Applicability Thresholds
Conditions are joined by OR — meeting ANY one triggers applicability.
Consumer Rights
Key Changes in 2025-2026
- SB 1295 (Public Act 25-153) major amendments take effect July 1, 2026 — the most significant state privacy law overhaul since the CCPA
- SB 4 is now Public Act 26-64 (signed May 27, 2026). It layers on top of SB 1295 with a Department of Consumer Protection data broker registry, a state-run accessible deletion mechanism, surveillance-pricing disclosure and retail restrictions, facial-recognition signage and policy duties, direct-to-consumer genetic-testing protections, and a prohibition on selling consumers' precise geolocation data. Most privacy amendments and the data broker framework take effect October 1, 2026; data broker registration gates sales/licensing starting January 1, 2027.
- Base applicability threshold lowered from 100,000 to 35,000 consumers (excluding payment-only transactions) — matching Maryland MODPA, Delaware, and New Hampshire
- Processing thresholds for sensitive data and data sales removed — any controller handling any amount of sensitive data or selling any consumer data falls within scope, regardless of company size or revenue
- Entity-level GLBA exemption eliminated — replaced with a narrower data-level exemption that covers only data processed pursuant to GLBA; the entity itself must comply with the CTDPA for all non-GLBA data
- New AI/LLM transparency requirement: controllers must disclose in privacy notices whether personal data is collected, used, or sold for training large language models — the first such state-law obligation in the US
- New consumer right to contest profiling results, request the reasoning and input data behind a profiling decision, and (for housing decisions) correct data and request human re-evaluation
- Sensitive data definition expanded: neural data, transgender or nonbinary status, financial account credentials, and government-issued identification numbers added — Connecticut becomes the first US state to explicitly classify neural data as sensitive
- New impact assessment requirements for profiling that produces legal or similarly significant effects — controllers must document purpose, risks, input/output data, performance metrics, and safeguards
- Strengthened minor protections: complete ban on targeted advertising and data sale for minors aged 13-17 with no consent exception, strict-necessity standard for geolocation collection from minors, and prohibition on dark-pattern design features intended to extend minors' usage
- Cure period sunsetted December 31, 2024 — Connecticut became the first US state to enforce comprehensive privacy law violations without any statutory cure window; AG Tong's office has full enforcement discretion in 2026
- AG Privacy and Data Security Section publicly identified GPC compliance, dark patterns in cookie banners, and minors' data processing as top early enforcement priorities for 2026
- No standalone revenue threshold under SB 1295 — a small Connecticut-targeting business hitting the 35,000-consumer trigger or processing any sensitive data is covered regardless of annual revenue
Enforcement Details
Notable Enforcement Actions
Source check: date_retrieved 2026-07-19. This table is generated from the canonical penalties tracker, so new AG and CalPrivacy actions appear here without duplicating state-page copy. Public monetary penalties shown below total $85,000.
TicketNetwork, Inc.
CTDPA · Privacy Notice Deficiencies / Inoperable Opt-Out
Connecticut Attorney General William Tong announced the state's first enforcement action under the Connecticut Data Privacy Act (CTDPA) — an $85,000 settlement with TicketNetwork, Inc., a Connecticut-based online ticket marketplace. The AG found that TicketNetwork's privacy notice was "largely unreadable," lacked required consumer data rights disclosures, and had misconfigured or inoperable opt-out mechanisms. The company had been given multiple notices to cure since November 2023 but failed to fully remediate.
Sensitive Data Categories
Consent model: opt-in
Universal Opt-Out / GPC Requirements
Businesses must recognize and honor universal opt-out mechanisms such as Global Privacy Control (GPC) starting January 1, 2025. This applies to opt-out requests for data sales and targeted advertising.
Effective: January 1, 2025
Minor / Child Protections
The CTDPA requires opt-in consent for processing personal data of known children under 13, consistent with COPPA. For consumers aged 13-15, businesses must obtain consent before processing data for targeted advertising or data sales. SB 1295 (effective July 1, 2026) further prohibits processing minors' data for targeted advertising or sale with no consent exception, limits data processing to what is reasonably necessary for service delivery, requires that precise geolocation collection be strictly necessary with active collection signaling, and prohibits system design features intended to significantly increase, sustain, or extend a minor's use of services.
Compliance Checklist
- 1Reassess applicability now (not on July 1) — SB 1295 lowers the threshold to 35,000 consumers and removes thresholds entirely for sensitive data processing and any data sale, meaning small B2C businesses, niche e-commerce stores, and any controller selling Connecticut consumer data are pulled into scope regardless of revenue. Build a Connecticut-resident counting methodology and document the count quarterly.
- 2Re-evaluate GLBA exemption status before July 1, 2026 — the entity-level exemption is eliminated and replaced with a narrower data-level exemption. Map every data flow against GLBA scope: customer financial data processed pursuant to GLBA remains exempt, but marketing data, website analytics, employment data, and any consumer data outside the GLBA scope must comply with the full CTDPA. Specific entity-level exemptions remain only for insurers, certain banks, and investment agents under federal or state law.
- 3Implement mechanisms to honor Global Privacy Control (GPC) signals and other universal opt-out preferences with server-side detection, downstream vendor propagation, cross-browser testing (Firefox, Brave, DuckDuckGo, Chrome), and a GPC hit log retained for AG audit defense. AG Privacy and Data Security Section has identified GPC compliance as a top 2026 enforcement priority — non-recognition is the single highest litigation risk.
- 4Update privacy notices to include all CTDPA-required disclosures: categories of data processed, purposes, third parties, consumer rights, opt-out mechanisms, contact info, appeal process — and the new SB 1295 disclosure of whether personal data is collected, used, or sold for training large language models. The LLM disclosure must be explicit and specific (a generic "we use AI" statement does not suffice).
- 5Build a consumer request intake and response process meeting the 45-day initial response window (extendable once by 45 days for complex requests), with documented identity verification proportionate to request sensitivity, a 60-day appeal window, and the new SB 1295 profiling-contest mechanism that allows consumers to challenge automated decisions and request reasoning and input data.
- 6Obtain freely-given, specific, informed, and unambiguous opt-in consent before processing any sensitive data category, including the four newly added under SB 1295: neural data (brain-computer interfaces, EEG-based apps, neurotechnology), transgender or nonbinary status, financial account credentials, and government-issued identification numbers. Dark-pattern consent flows are prohibited.
- 7Cease processing of any sensitive data without consent immediately on July 1, 2026 — there is no cure period and no transition window. Sensitive data sale requires opt-in even after consent for processing.
- 8Conduct and document Data Protection Assessments (DPAs) for high-risk processing — including targeted advertising, sale of personal data, processing of sensitive data, and profiling presenting reasonably foreseeable risk of unfair, deceptive, financial, physical, or reputational injury. Retain assessments for at least three years.
- 9Perform separate Impact Assessments for profiling that produces legal or similarly significant effects on consumers — credit, housing, insurance, employment, healthcare, education, or essential goods/services decisions. Document purpose, automated logic categories, input data, performance and accuracy metrics, false-positive analysis, demographic disparities, mitigation safeguards, and human-review pathway.
- 10Audit system design features for minor protection compliance — ensure zero targeted advertising or data sale for users aged 13-17 (no consent exception), apply strict-necessity test for any minor geolocation collection with active signaling, and remove any dark-pattern features intended to extend minors' session length, increase repeat usage, or encourage compulsive engagement (autoplay, infinite scroll, gamified streaks for minors).
- 11Update processor/sub-processor contracts to include CTDPA flow-down obligations, audit rights, deletion-on-termination, processing-limitation language, sub-processor approval, and breach notification — particularly the new SB 1295 LLM training disclosure and profiling impact assessment requirements. Existing 2023 CTDPA addenda are not sufficient for SB 1295.
- 12Prepare for a zero-cure-period enforcement environment — Connecticut's statutory right to cure expired December 31, 2024. Build an AG-inquiry response playbook: preserve relevant logs from notice receipt, designate counsel, conduct internal compliance audit, prepare remediation plan with timeline, and respond within the deadline stated in the AG's notice. Document everything for potential CUTPA defense.
- 13Establish an ongoing CTDPA compliance monitoring program — monthly GPC honoring tests across browsers, quarterly privacy notice review, annual DPA and impact assessment refresh, employee privacy training, complaint intake log with response tracking, and a designated CTDPA compliance owner. AG Tong's office has signaled it will review compliance program documentation in any enforcement matter.
- 14If you sell or license brokered personal data, prepare for the Public Act 26-64 data broker registry: register with the Department of Consumer Protection before selling or licensing brokered personal data in Connecticut on or after January 1, 2027, budget for the $2,500 registration/renewal fee, publish the required consumer-rights page, and plan for 45-day accessible deletion mechanism checks beginning October 1, 2028.
- 15For location, biometric, pricing, and genetic-data programs, map Public Act 26-64 duties before October 1, 2026: cease sales of Connecticut consumers' precise geolocation data, add the required surveillance-pricing disclosure where a price-setting device increases an online price using personal data, post signage and a facial-recognition policy where covered on-premises facial recognition is used for security or fraud prevention, and update direct-to-consumer genetic testing consent flows.
- 16Map applicability against Maryland MODPA (effective April 1, 2026), New Hampshire (effective January 1, 2025), and Delaware (effective January 1, 2025) — Connecticut joins these states with a 35,000-consumer threshold under SB 1295, and a multistate compliance program designed for the strictest of these laws (typically Maryland MODPA on data minimization or Connecticut on AI/LLM disclosures) provides defensible coverage for the others.
Termly builds and maintains a Connecticut-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests CTDPA grants.
Connecticut Privacy Law FAQ
Official Resources
- Connecticut Attorney General Privacy and Data Security Section
- CTDPA (Public Act 22-15) Full Text
- SB 1295 / Public Act 25-153 (2025 Amendments) Full Text
- SB 4 / Public Act 26-64 (2026 Amendments) Full Text
- Connecticut Unfair Trade Practices Act (CUTPA) — Conn. Gen. Stat. § 42-110a
- File a Consumer Privacy Complaint with the Connecticut AG
- Attorney General William Tong — Office Homepage