{
 "jurisdiction_id": "US-CT",
 "jurisdiction": "United States – Connecticut",
 "url": "https://dataprotection.gi/jurisdictions/united-states-connecticut/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 42,
  "sub_modules": 57,
  "source_register": 15
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-connecticut/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive statute in force since 2023 but undergoing frequent, materially expanding amendments (2024, 2026) that shift scope and thresholds; operators must track a moving compliance target.",
   "claims": [
    {
     "statement": "The Connecticut Attorney General has exclusive authority to enforce violations of the CTDPA and there is no private right of action.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Governor Ned Lamont signed Senate Bill 6 (the CTDPA) into law on May 10, 2022, and the Act took effect on July 1, 2023.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Amendments to the CTDPA going into effect on July 1, 2026 broaden applicability thresholds, including making all sensitive-data processing and all sales of personal data covered under the law.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/-/media/ag/press_releases/2026/cdpa-business.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/connecticut-governor-signs-bill-amending-ctdpa-and",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/connecticut-enacts-comprehensive-consumer-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-connecticut/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Consent standard and sensitive-data consent requirement are well-defined and in force, but the sensitive-data category list is being materially expanded by amendments not yet fully effective, creating a temporal compliance gap.",
   "claims": [
    {
     "statement": "Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes, and may not process personal data for purposes neither reasonably necessary to nor compatible with the disclosed purposes absent consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/connecticut-enacts-comprehensive-consumer-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A consumer's consent under the CTDPA must be freely given, specific, informed and unambiguous, cannot be obtained through dark patterns, and controllers must provide an effective revocation mechanism at least as easy as the consent mechanism, ceasing processing within 15 days of revocation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/connecticut-enacts-comprehensive-consumer-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Sensitive data has heightened protections under the CTDPA and controllers must obtain affirmative opt-in consent before processing it.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/press-releases/2026-press-releases/attorney-general-tong-sends-message-to-big-tech-about-hooking-kids-on-addictive-apps",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "As amended, 'sensitive data' now includes data revealing disability or treatment, non-binary or transgender status, information derived from genetic or biometric data, data known to relate to a child, neural data, certain financial account information, and government-issued identification information.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/press-releases/2026-press-releases/attorney-general-tong-sends-message-to-big-tech-about-hooking-kids-on-addictive-apps",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-connecticut/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Well-defined statutory rights and response deadlines already in force, with an enacted (not-yet-effective) expansion of rights around profiling transparency and third-party disclosure.",
   "claims": [
    {
     "statement": "A consumer can request information about their personal data from a controller free of charge once every 12 months, with the controller permitted to charge an administrative fee beyond the annual free request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The CTDPA provides Connecticut consumers the right to correct inaccuracies in their personal data and the right to delete their personal data, including data that a business collected through third parties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/press-releases/2023-press-releases/ag-tong-advises-connecticut-consumers-of-upcoming-rights-under-the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Connecticut consumers have the right to opt out of the sale of their personal data and targeted advertising, and, under the 2026 amendments, to know whether a controller is processing their personal data for profiling that produces a legal or similarly significant effect.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/press-releases/2026-press-releases/attorney-general-tong-sends-message-to-big-tech-about-hooking-kids-on-addictive-apps",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The CTDPA as amended establishes rights including access, deletion, and portability for consumers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/connecticut",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A controller must respond to a consumer's requests no later than 45 days after receipt of the request, and under certain conditions may extend the response period by an additional 45 days.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A controller has 60 days after receipt of an appeal to write back to the consumer explaining actions taken or reasons for refusal, and if denied must provide information to contact the Attorney General.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-connecticut/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Strong breach-notification and DPIA-equivalent regime in force, but no explicit statutory DPO or ROPA requirement, and processor-contract obligations are less detailed than GDPR Art. 28.",
   "claims": [
    {
     "statement": "Controllers must conduct assessments before processing personal data in a manner that presents a heightened risk of harm to consumers, including processing for targeted advertising, sale, profiling with reasonably foreseeable risk of substantial injury, and processing of sensitive data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Senate Bill 1295 amends the CTDPA to mandate impact assessments for profiling decisions in connection with social-media platform obligations regarding minors' data.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/connecticut",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "If a processor exercises decision-making authority with respect to the purposes and means of personal-data processing, it becomes a controller with respect to that processing and is subject to controller obligations under the CTDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Controllers must use reasonable safeguards to secure personal data as part of their obligations to comply with the CTDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Notice to Connecticut residents of a security breach must be made without unreasonable delay and no later than sixty days from discovery of the breach, per Conn. Gen. Stat. § 36a-701b(b)(1); notice to the Attorney General must be provided no later than when residents are notified.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/reporting-a-data-breach",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "If a Connecticut resident's Social Security number or Taxpayer Identification Number is believed compromised in a breach, Connecticut law requires the resident be offered 24 months of credit monitoring services.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/reporting-a-data-breach",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-connecticut/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No comprehensive cross-border transfer regime exists under CTDPA; this is a genuine regulatory gap rather than an incomplete search.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-connecticut/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Sectoral overlays are well-documented (insurance, health, financial), but the scope of financial/insurance exemptions is being actively renegotiated in pending 2026 amendments.",
   "claims": [
    {
     "statement": "Under the Connecticut Insurance Data Security Law, a licensee acting as an assuming insurer must notify affected ceding insurers and its domiciliary regulator of a cybersecurity event involving nonpublic information in the possession of a third-party service provider (TPSP) not later than 72 hours after the assuming insurer received notice from the TPSP.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Insurance Department",
     "source_url": "https://portal.ct.gov/-/media/CID/1_Bulletins/Bulletin-IC-42.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The CTDPA applies to all Consumer Health Data Controllers doing business in or targeting Connecticut residents regardless of size or processing volume, with no revenue or processing threshold and no nonprofit exemption.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The AG's Privacy and Data Security Department is responsible for enforcement of federal laws under which the Attorney General has enforcement authority, including HIPAA, COPPA, and the Fair Credit Reporting Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-privacy-and-data-security-department",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "green",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-connecticut/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Universal opt-out signal recognition and dark-pattern prohibition are already in force and actively enforced; upcoming geolocation/personalized-pricing rules are enacted but not yet effective.",
   "claims": [
    {
     "statement": "As of January 1, 2025, Connecticut consumers can send an opt-out preference signal, such as the Global Privacy Control, through a privacy-protective browser or browser extension, to automatically tell controllers they intend to opt out of targeted advertising and sale of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Unlike Colorado's law, the CTDPA does not require controllers to authenticate opt-out signals, making it easier for consumers to exercise universal opt-out rights, similar to the approach under the California Privacy Rights Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/connecticut-enacts-comprehensive-consumer-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Controllers must obtain opt-in consent before selling a consumer's personal data or processing it for targeted advertising when the consumer is under 16 years old, or where the controller has actual knowledge or willfully disregards that the consumer is between 13 and 16.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/press-releases/2023-press-releases/ag-tong-advises-connecticut-consumers-of-upcoming-rights-under-the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-connecticut/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Meaningful ADM-transparency and biometric/neural-data protections are enacted, but several of the most consequential provisions (facial recognition limits, expanded biometric/genetic/neural categories, AI training-data disclosure) are not yet effective as of the run date.",
   "claims": [
    {
     "statement": "Controllers must conduct a Data Protection Assessment before processing personal data for the purposes of profiling where such profiling presents a reasonably foreseeable risk of substantial injury to consumers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/connecticut-enacts-comprehensive-consumer-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A controller must obtain consent prior to processing a minor's personal data for profiling.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "New consumer rights let Connecticut residents obtain a list of third parties to which a business sold their data, access inferences drawn from their personal data, and know whether profiling is used to make a decision producing legal or similarly significant effects, with feasible rights to question results, learn reasoning, review data used, and (for housing decisions) correct data and obtain reevaluation.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/press-releases/2026-press-releases/attorney-general-tong-sends-message-to-big-tech-about-hooking-kids-on-addictive-apps",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "New disclosure requirements enacted for the CTDPA require companies to disclose whether personal data is used to train large language models.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/press-releases/2026-press-releases/attorney-general-tong-releases-updated-report-on-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The 2026 CTDPA amendment drastically expands the biometric and genetic data categories, removing the existing purpose-based limitation to include such data regardless of collection purpose and to include information derived therefrom, i.e., inferences created from genetic or biometric data.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-double-toil-and-trouble-in-connecticut-s-privacy-amendment",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Public Act No. 26-64 introduces and revises the definition of 'facial recognition technology' and sets limitations and transparency requirements for its use, with these provisions taking effect October 1, 2026.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/connecticut-governor-signs-bill-amending-ctdpa-and",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Connecticut Attorney General's 2026 report on the CTDPA recommends the state legislature adopt a standalone genetic data privacy law, alongside adoption of a genetic-testing amendment expansion already introduced via Senate Bill 4.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/press-releases/2026-press-releases/attorney-general-tong-releases-updated-report-on-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-connecticut/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Substantial, actively-enforced minors' protections are already in force (since Oct 1, 2024), but the most far-reaching addictive-design/algorithm-consent measures are enacted with a multi-year phase-in to 2028, and the AG's own report flags continued gaps in the definition/scope of protections.",
   "claims": [
    {
     "statement": "Consent is required to process a consumer's personal data for targeted advertising or to sell their data where a controller has actual knowledge of, and willfully disregards, that the consumer is between 13 and 16 years old.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/connecticut-enacts-comprehensive-consumer-data-privacy-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "If a child's personal data is processed by a controller, the child's parent or legal guardian may exercise rights on the child's behalf, and controllers must follow COPPA regulations including parental-consent requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A controller shall not process a minor's data for purposes of targeted advertising or any sale, and shall not use any design feature to significantly increase, sustain, or extend a minor's use of an online service, product, or feature.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-connecticut/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Active, escalating enforcement program with a public settlement, annual statutory reporting, and clear statutory penalty/no-private-right-of-action posture — well documented and current as of the run date.",
   "claims": [
    {
     "statement": "The Attorney General has exclusive authority to enforce violations of the CTDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "By the end of 2025, the AG's office had issued dozens of notices of violation and warning letters, finalized multiple data breach settlements, and resolved its first enforcement action under the CTDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/press-releases/2026-press-releases/attorney-general-tong-releases-updated-report-on-connecticut-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Connecticut Attorney General announced a settlement with TicketNetwork, Inc. under which the company agreed to comply with the CTDPA, maintain consumer-rights-request metrics, report those metrics to the AG, and pay $85,000.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Connecticut Office of the Attorney General",
     "source_url": "https://portal.ct.gov/ag/press-releases/2025-press-releases/attorney-general-tong-announces-settlement-with-ticketnetwork",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}