Comprehensive statute in force since 2023 but undergoing frequent, materially expanding amendments (2024, 2026) that shift scope and thresholds; operators must track a moving compliance target.
Primary frameworkConnecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq., as amended
Traffic-light rationale — AmberComprehensive statute in force since 2023 but undergoing frequent, materially expanding amendments (2024, 2026) that shift scope and thresholds; operators must track a moving compliance target.
Sub-modules (5)
Regulator And AuthorityGreen
The Connecticut Attorney General has exclusive statutory authority to enforce the CTDPA; there is no dedicated state privacy agency (unlike California's CPPA).
Claims (1):
The Connecticut Attorney General has exclusive authority to enforce violations of the CTDPA and there is no private right of action.
Act And InstrumentsAmber
Core instrument is the CTDPA as amended by the Online Privacy Act (2023), the 2024 minors' amendments, the 2025/2026 threshold-lowering amendments (effective July 1, 2026), and Public Act 26-64 (SB4, effective October 1, 2026) adding data-broker and facial-recognition provisions.
Claims (3):
Governor Ned Lamont signed Senate Bill 6 (the CTDPA) into law on May 10, 2022, and the Act took effect on July 1, 2023.
Amendments to the CTDPA going into effect on July 1, 2026 broaden applicability thresholds, including making all sensitive-data processing and all sales of personal data covered under the law.
Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.
Material ScopeGreen
CTDPA covers personal data of CT residents acting in an individual/household context; excludes employment-context data and 16 categories of exempted data overlapping with federal sectoral laws (HIPAA, FCRA, GLBA, DPPA, FERPA, Farm Credit Act, Airline Deregulation Act).
Claims (2):
The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.
The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.
Territorial ScopeGreen
Applies to persons conducting business in Connecticut or targeting products/services to CT residents meeting the statutory thresholds; no extraterritorial reach beyond that consumer-targeting test.
Claims (1):
The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.
Regulator Registration And FilingAmber
The CTDPA itself imposes no general controller registration/filing requirement; however, Public Act 26-64 (effective Oct 1, 2026) newly requires data brokers to register and establish a deletion mechanism.
Claims (1):
Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.
Key findings (3)
— source on file
— source on file
— source on file
Category narrative118 words
Connecticut's comprehensive consumer privacy regime is the Connecticut Data Privacy Act (CTDPA), Public Act No. 22-15 (Conn. Gen. Stat. § 42-515 et seq.), signed May 10, 2022 and effective July 1, 2023, enforced exclusively by the Connecticut Attorney General (no dedicated privacy agency). The Act has been amended multiple times (Online Privacy Act 2023, minors' protections effective Oct 1 2024, 2025 amendments effective July 1 2026 lowering applicability thresholds, and Public Act 26-64 / SB4 effective October 1 2026 adding data broker registration and facial recognition rules). Applicability thresholds are being broadened by the July 2026 amendments so that any processing of sensitive data or any sale of personal data triggers coverage, removing the prior 25,000-consumer sale-revenue threshold.
Sources and claims (6)
ConfirmedConnecticut Office of the Attorney General — The Connecticut Attorney General has exclusive authority to enforce violations of the CTDPA and there is no private right of action.observed
ConfirmedConnecticut Office of the Attorney General — Governor Ned Lamont signed Senate Bill 6 (the CTDPA) into law on May 10, 2022, and the Act took effect on July 1, 2023.observed
ConfirmedConnecticut Office of the Attorney General — Amendments to the CTDPA going into effect on July 1, 2026 broaden applicability thresholds, including making all sensitive-data processing and all sales of personal data covered under the law.observed
ConfirmedOneTrust DataGuidance — Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.observed
ConfirmedConnecticut Office of the Attorney General — The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.observed
ConfirmedInternational Association of Privacy Professionals — The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.observed
Consent standard and sensitive-data consent requirement are well-defined and in force, but the sensitive-data category list is being materially expanded by amendments not yet fully effective, creating a temporal compliance gap.
Primary frameworkConnecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq.
Traffic-light rationale — AmberConsent standard and sensitive-data consent requirement are well-defined and in force, but the sensitive-data category list is being materially expanded by amendments not yet fully effective, creating a temporal compliance gap.
Sub-modules (4)
Lawful BasesAmber
No enumerated Art.6-style lawful-bases list; general processing is permitted subject to purpose-limitation, data-minimization, and consumer opt-out rights for targeted advertising, sale, and certain profiling.
Claims (1):
Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes, and may not process personal data for purposes neither reasonably necessary to nor compatible with the disclosed purposes absent consent.
Consent ThresholdsGreen
Consent must be freely given, specific, informed and unambiguous and cannot be obtained through dark patterns; controllers must provide a revocation mechanism at least as easy as the consent mechanism, and must cease processing within 15 days of revocation.
Claims (1):
A consumer's consent under the CTDPA must be freely given, specific, informed and unambiguous, cannot be obtained through dark patterns, and controllers must provide an effective revocation mechanism at least as easy as the consent mechanism, ceasing processing within 15 days of revocation.
Special CategoriesAmber
Sensitive data requires opt-in consent prior to processing; the July 2026 amendments expand the sensitive-data category list to include disability/treatment status, non-binary/transgender status, genetic/biometric-derived information, and neural data.
Claims (2):
Sensitive data has heightened protections under the CTDPA and controllers must obtain affirmative opt-in consent before processing it.
As amended, 'sensitive data' now includes data revealing disability or treatment, non-binary or transgender status, information derived from genetic or biometric data, data known to relate to a child, neural data, certain financial account information, and government-issued identification information.
Pseudonymisation And AnonymisationRed
No specific statutory safe-harbour definition for pseudonymised/anonymised data was identified in the sources reviewed for this run.
Absence provenance: not recorded. Searched: not recorded.
Key findings (3)
— source on file
— source on file
— source on file
Category narrative92 words
CTDPA does not use a GDPR-style enumerated lawful-bases model; instead it relies on an opt-out framework for ordinary processing plus opt-in consent requirements for sensitive data and material new-purpose processing. Consent must be freely given, specific, informed and unambiguous, cannot be obtained via dark patterns, and must be revocable via a mechanism at least as easy as the one used to give it. The 2026 amendments substantially broaden the definition of 'sensitive data' to include disability/treatment status, non-binary/transgender status, information derived from genetic or biometric data, neural data, and expanded financial/government-ID identifiers.
Sources and claims (4)
ConfirmedInternational Association of Privacy Professionals — Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes, and may not process personal data for purposes neither reasonably necessary to nor compatible with the disclosed purposes absent consent.observed
ConfirmedInternational Association of Privacy Professionals — A consumer's consent under the CTDPA must be freely given, specific, informed and unambiguous, cannot be obtained through dark patterns, and controllers must provide an effective revocation mechanism at least as easy as the consent mechanism, ceasing processing within 15 days of revocation.observed
ConfirmedConnecticut Office of the Attorney General — Sensitive data has heightened protections under the CTDPA and controllers must obtain affirmative opt-in consent before processing it.observed
ConfirmedConnecticut Office of the Attorney General — As amended, 'sensitive data' now includes data revealing disability or treatment, non-binary or transgender status, information derived from genetic or biometric data, data known to relate to a child, neural data, certain financial account information, and government-issued identification information.observed
Well-defined statutory rights and response deadlines already in force, with an enacted (not-yet-effective) expansion of rights around profiling transparency and third-party disclosure.
Primary frameworkConnecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq.
Traffic-light rationale — GreenWell-defined statutory rights and response deadlines already in force, with an enacted (not-yet-effective) expansion of rights around profiling transparency and third-party disclosure.
Sub-modules (5)
Access RightGreen
Consumers may confirm whether a controller is processing their personal data and access it, free of charge once every 12 months, subject to a trade-secret exception.
Claims (1):
A consumer can request information about their personal data from a controller free of charge once every 12 months, with the controller permitted to charge an administrative fee beyond the annual free request.
Rectification And ErasureGreen
CTDPA grants rights to correct inaccuracies and to delete personal data, including data collected via third parties.
Claims (1):
The CTDPA provides Connecticut consumers the right to correct inaccuracies in their personal data and the right to delete their personal data, including data that a business collected through third parties.
Restriction And ObjectionGreen
Consumers may opt out of processing for targeted advertising, sale of personal data, and profiling producing legal or similarly significant effects.
Claims (1):
Connecticut consumers have the right to opt out of the sale of their personal data and targeted advertising, and, under the 2026 amendments, to know whether a controller is processing their personal data for profiling that produces a legal or similarly significant effect.
Data PortabilityGreen
The CTDPA as amended establishes a right to data portability for consumers.
Claims (1):
The CTDPA as amended establishes rights including access, deletion, and portability for consumers.
Deadlines And Response WindowsGreen
Controllers must respond to consumer requests within 45 days of receipt, extendable by an additional 45 days under certain conditions; appeal responses are due within 60 days of receipt of the appeal.
Claims (2):
A controller must respond to a consumer's requests no later than 45 days after receipt of the request, and under certain conditions may extend the response period by an additional 45 days.
A controller has 60 days after receipt of an appeal to write back to the consumer explaining actions taken or reasons for refusal, and if denied must provide information to contact the Attorney General.
Key findings (3)
— source on file
— source on file
— source on file
Category narrative77 words
CTDPA grants CT consumers rights of access, correction, deletion, portability, and opt-out of targeted advertising/sale/certain profiling, plus an appeal right against controller denials. Controllers must respond within 45 days (extendable by a further 45 days when reasonably necessary); appeal responses are due within 60 days. The 2026 amendments add new rights to obtain a list of third parties sold to, access inferences drawn from personal data, and query/challenge automated profiling decisions with legal or similarly significant effects.
Sources and claims (6)
ConfirmedConnecticut Office of the Attorney General — A consumer can request information about their personal data from a controller free of charge once every 12 months, with the controller permitted to charge an administrative fee beyond the annual free request.observed
ConfirmedConnecticut Office of the Attorney General — The CTDPA provides Connecticut consumers the right to correct inaccuracies in their personal data and the right to delete their personal data, including data that a business collected through third parties.observed
ConfirmedConnecticut Office of the Attorney General — Connecticut consumers have the right to opt out of the sale of their personal data and targeted advertising, and, under the 2026 amendments, to know whether a controller is processing their personal data for profiling that produces a legal or similarly significant effect.observed
ProbableOneTrust DataGuidance — The CTDPA as amended establishes rights including access, deletion, and portability for consumers.observed
ConfirmedConnecticut Office of the Attorney General — A controller must respond to a consumer's requests no later than 45 days after receipt of the request, and under certain conditions may extend the response period by an additional 45 days.observed
ConfirmedConnecticut Office of the Attorney General — A controller has 60 days after receipt of an appeal to write back to the consumer explaining actions taken or reasons for refusal, and if denied must provide information to contact the Attorney General.observed
Strong breach-notification and DPIA-equivalent regime in force, but no explicit statutory DPO or ROPA requirement, and processor-contract obligations are less detailed than GDPR Art. 28.
Primary frameworkConnecticut Data Privacy Act (CTDPA); Connecticut Data Breach Notification Act, Conn. Gen. Stat. § 36a-701b; Connecticut Safeguards Law, Conn. Gen. Stat. § 42-471
Traffic-light rationale — AmberStrong breach-notification and DPIA-equivalent regime in force, but no explicit statutory DPO or ROPA requirement, and processor-contract obligations are less detailed than GDPR Art. 28.
Sub-modules (7)
Accountability And DpiaGreen
Controllers must conduct and document Data Protection Assessments/Impact Assessments before processing for targeted advertising, sale, risky profiling, or sensitive data; the 2025 amendments extend impact-assessment obligations to profiling decisions.
Claims (2):
Controllers must conduct assessments before processing personal data in a manner that presents a heightened risk of harm to consumers, including processing for targeted advertising, sale, profiling with reasonably foreseeable risk of substantial injury, and processing of sensitive data.
Senate Bill 1295 amends the CTDPA to mandate impact assessments for profiling decisions in connection with social-media platform obligations regarding minors' data.
Dpo RequirementsRed
No CTDPA provision mandating appointment of a Data Protection Officer was identified in the sources reviewed for this run.
Absence provenance: not recorded. Searched: not recorded.
Ropa RequirementsAmber
No explicit statutory records-of-processing-activities obligation distinct from the DPA/impact-assessment documentation requirement was identified.
Absence provenance: not recorded. Searched: not recorded.
Claims (1):
Controllers must conduct assessments before processing personal data in a manner that presents a heightened risk of harm to consumers, including processing for targeted advertising, sale, profiling with reasonably foreseeable risk of substantial injury, and processing of sensitive data.
Joint Controller ArrangementsGreen
CTDPA distinguishes controllers and processors; a processor exercising independent decision-making authority over purposes/means becomes a controller for that processing and assumes controller obligations.
Claims (1):
If a processor exercises decision-making authority with respect to the purposes and means of personal-data processing, it becomes a controller with respect to that processing and is subject to controller obligations under the CTDPA.
Security MeasuresGreen
Controllers must use reasonable safeguards to secure personal data (CTDPA), supplemented by the Connecticut Safeguards Law (Conn. Gen. Stat. § 42-471) and Social Security Number Law (§ 42-470).
Claims (1):
Controllers must use reasonable safeguards to secure personal data as part of their obligations to comply with the CTDPA.
Breach NotificationGreen
Under Conn. Gen. Stat. § 36a-701b, notice to affected CT residents must be made without unreasonable delay and no later than 60 days from discovery of the breach; AG notice is due no later than resident notification; SSN/TIN compromise triggers a mandatory 24-month credit-monitoring offer.
Claims (2):
Notice to Connecticut residents of a security breach must be made without unreasonable delay and no later than sixty days from discovery of the breach, per Conn. Gen. Stat. § 36a-701b(b)(1); notice to the Attorney General must be provided no later than when residents are notified.
If a Connecticut resident's Social Security number or Taxpayer Identification Number is believed compromised in a breach, Connecticut law requires the resident be offered 24 months of credit monitoring services.
Retention And DisposalAmber
No CTDPA-specific numeric retention-limit provision was identified beyond the general purpose-limitation/data-minimization principle.
Absence provenance: not recorded. Searched: not recorded.
Claims (1):
Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes, and may not process personal data for purposes neither reasonably necessary to nor compatible with the disclosed purposes absent consent.
Key findings (3)
— source on file
— source on file
— source on file
Category narrative91 words
CTDPA requires Data Protection Assessments (DPAs)/Impact Assessments before processing that presents a heightened risk of harm (targeted advertising, sale, risky profiling, sensitive-data processing); requires reasonable security safeguards; and requires a data breach notification under the separate Connecticut Data Breach Notification Act (Conn. Gen. Stat. § 36a-701b) — notice to consumers without unreasonable delay and no later than 60 days from discovery, with AG notice due no later than consumer notice. No CTDPA-specific DPO appointment requirement or formal ROPA mandate was identified; joint-controller arrangements are addressed only via generic controller/processor contractual requirements.
Sources and claims (6)
ConfirmedConnecticut Office of the Attorney General — Controllers must conduct assessments before processing personal data in a manner that presents a heightened risk of harm to consumers, including processing for targeted advertising, sale, profiling with reasonably foreseeable risk of substantial injury, and processing of sensitive data.observed
ProbableOneTrust DataGuidance — Senate Bill 1295 amends the CTDPA to mandate impact assessments for profiling decisions in connection with social-media platform obligations regarding minors' data.observed
ConfirmedConnecticut Office of the Attorney General — If a processor exercises decision-making authority with respect to the purposes and means of personal-data processing, it becomes a controller with respect to that processing and is subject to controller obligations under the CTDPA.observed
ConfirmedConnecticut Office of the Attorney General — Controllers must use reasonable safeguards to secure personal data as part of their obligations to comply with the CTDPA.observed
ConfirmedConnecticut Office of the Attorney General — Notice to Connecticut residents of a security breach must be made without unreasonable delay and no later than sixty days from discovery of the breach, per Conn. Gen. Stat. § 36a-701b(b)(1); notice to the Attorney General must be provided no later than when residents are notified.observed
ConfirmedConnecticut Office of the Attorney General — If a Connecticut resident's Social Security number or Taxpayer Identification Number is believed compromised in a breach, Connecticut law requires the resident be offered 24 months of credit monitoring services.observed
No comprehensive cross-border transfer regime exists under CTDPA; this is a genuine regulatory gap rather than an incomplete search.
Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists under CTDPA; this is a genuine regulatory gap rather than an incomplete search.
Sub-modules (6)
Transfer MechanismsRed
No CTDPA transfer-mechanism provision identified.
Absence provenance: not recorded. Searched: not recorded.
Adequacy ReceivedRed
Not applicable; CT is a sub-national US jurisdiction with no adequacy-receiving framework.
Absence provenance: not recorded. Searched: not recorded.
Adequacy GrantedRed
Not applicable; Connecticut does not issue adequacy determinations.
Absence provenance: not recorded. Searched: not recorded.
Sccs And BcrsRed
No SCC/BCR uptake mechanism exists under CTDPA.
Absence provenance: not recorded. Searched: not recorded.
Transfer Impact AssessmentRed
No transfer-impact-assessment requirement exists under CTDPA.
Absence provenance: not recorded. Searched: not recorded.
Data LocalisationRed
No data-localisation mandate exists under CTDPA.
Absence provenance: not recorded. Searched: not recorded.
Key findings (3)
— source on file
— source on file
— source on file
Category narrative48 words
The CTDPA does not contain a distinct cross-border-transfer regime (no adequacy mechanism, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate) — this is characteristic of US state comprehensive privacy statutes, which regulate controller/processor obligations regardless of the data's onward destination rather than gating international transfers as GDPR-style regimes do.
Sectoral overlays are well-documented (insurance, health, financial), but the scope of financial/insurance exemptions is being actively renegotiated in pending 2026 amendments.
Primary frameworkCTDPA sectoral exemptions; Connecticut Insurance Data Security Law (Conn. Gen. Stat. Title 38a, implementing NAIC Insurance Data Security Model Law)
Traffic-light rationale — AmberSectoral overlays are well-documented (insurance, health, financial), but the scope of financial/insurance exemptions is being actively renegotiated in pending 2026 amendments.
Sub-modules (7)
Financial Sector OverlayGreen
GLBA-regulated financial institutions and their data are generally exempt from CTDPA; the Connecticut Insurance Data Security Law imposes its own breach-notification duties, including a 72-hour TPSP-event notification for assuming insurers to ceding insurers and domiciliary regulators.
Claims (1):
Under the Connecticut Insurance Data Security Law, a licensee acting as an assuming insurer must notify affected ceding insurers and its domiciliary regulator of a cybersecurity event involving nonpublic information in the possession of a third-party service provider (TPSP) not later than 72 hours after the assuming insurer received notice from the TPSP.
Health Sector OverlayAmber
HIPAA-covered entities/business associates and their protected health information are exempt from CTDPA; the AG's Privacy Section separately enforces HIPAA under delegated federal authority. The CTDPA's standalone Consumer Health Data provisions (Online Privacy Act) apply to non-HIPAA consumer health data with no size threshold.
Claims (1):
The CTDPA applies to all Consumer Health Data Controllers doing business in or targeting Connecticut residents regardless of size or processing volume, with no revenue or processing threshold and no nonprofit exemption.
Telecoms And EprivacyAmber
No CT-specific ePrivacy/cookie-consent statute distinct from CTDPA's general opt-out framework was identified.
Absence provenance: not recorded. Searched: not recorded.
Employment DataGreen
CTDPA expressly excludes personal data processed in an employment context (e.g., job applications) from its scope.
Claims (1):
The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.
Credit And ScoringGreen
FCRA-regulated data and entities are exempt from CTDPA; the AG's Privacy and Data Security Department separately enforces the FCRA under delegated federal authority.
Claims (1):
The AG's Privacy and Data Security Department is responsible for enforcement of federal laws under which the Attorney General has enforcement authority, including HIPAA, COPPA, and the Fair Credit Reporting Act.
EducationGreen
FERPA-regulated education records are among the CTDPA's exempted data categories.
Claims (1):
The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.
InsuranceGreen
The Connecticut Insurance Data Security Law requires licensees to notify the Insurance Commissioner and affected consumers of cybersecurity events and imposes a distinct 72-hour TPSP-related notification duty for assuming insurers.
Claims (1):
Under the Connecticut Insurance Data Security Law, a licensee acting as an assuming insurer must notify affected ceding insurers and its domiciliary regulator of a cybersecurity event involving nonpublic information in the possession of a third-party service provider (TPSP) not later than 72 hours after the assuming insurer received notice from the TPSP.
Key findings (3)
— source on file
— source on file
— source on file
Category narrative98 words
CTDPA carves out entities/data already regulated by federal sectoral frameworks: HIPAA-covered entities and business associates, GLBA-regulated financial institutions, FCRA data, and the Connecticut Insurance Data Security Law (Bulletin IC-42, implementing an NAIC-model cybersecurity-event notification regime for licensees, including a 72-hour notification duty for TPSP-related events to ceding insurers/domiciliary regulators). The AG's Privacy and Data Security Department also enforces HIPAA, COPPA, and FCRA under delegated federal authority. The 2026 amendments (per the IAPP analysis of the vetoed/passed amendment) propose narrowing exemptions for specific financial, insurance, and health company sub-categories and aligning a GLBA data exemption with most other states.
Sources and claims (3)
ConfirmedConnecticut Insurance Department — Under the Connecticut Insurance Data Security Law, a licensee acting as an assuming insurer must notify affected ceding insurers and its domiciliary regulator of a cybersecurity event involving nonpublic information in the possession of a third-party service provider (TPSP) not later than 72 hours after the assuming insurer received notice from the TPSP.observed
ConfirmedConnecticut Office of the Attorney General — The CTDPA applies to all Consumer Health Data Controllers doing business in or targeting Connecticut residents regardless of size or processing volume, with no revenue or processing threshold and no nonprofit exemption.observed
ConfirmedConnecticut Office of the Attorney General — The AG's Privacy and Data Security Department is responsible for enforcement of federal laws under which the Attorney General has enforcement authority, including HIPAA, COPPA, and the Fair Credit Reporting Act.observed
Universal opt-out signal recognition and dark-pattern prohibition are already in force and actively enforced; upcoming geolocation/personalized-pricing rules are enacted but not yet effective.
Primary frameworkConnecticut Data Privacy Act (CTDPA); Public Act No. 26-64
Traffic-light rationale — GreenUniversal opt-out signal recognition and dark-pattern prohibition are already in force and actively enforced; upcoming geolocation/personalized-pricing rules are enacted but not yet effective.
Sub-modules (6)
Cookies And TrackersGreen
No dedicated cookie-consent statute; tracking for targeted advertising/sale falls under the general CTDPA opt-out and universal-signal framework.
Claims (1):
As of January 1, 2025, Connecticut consumers can send an opt-out preference signal, such as the Global Privacy Control, through a privacy-protective browser or browser extension, to automatically tell controllers they intend to opt out of targeted advertising and sale of personal data.
Dark PatternsGreen
Consent cannot be obtained through the use of dark patterns under the CTDPA.
Claims (1):
A consumer's consent under the CTDPA must be freely given, specific, informed and unambiguous, cannot be obtained through dark patterns, and controllers must provide an effective revocation mechanism at least as easy as the consent mechanism, ceasing processing within 15 days of revocation.
Opt Out SignalsGreen
As of January 1, 2025, businesses covered under the CTDPA must honor universal opt-out preference signals like the Global Privacy Control sent via a privacy-protective browser or extension, without requiring authentication.
Claims (2):
As of January 1, 2025, Connecticut consumers can send an opt-out preference signal, such as the Global Privacy Control, through a privacy-protective browser or browser extension, to automatically tell controllers they intend to opt out of targeted advertising and sale of personal data.
Unlike Colorado's law, the CTDPA does not require controllers to authenticate opt-out signals, making it easier for consumers to exercise universal opt-out rights, similar to the approach under the California Privacy Rights Act.
Clean Rooms And DcrRed
No CTDPA-specific clean-room/data-collaboration-room provision identified.
Absence provenance: not recorded. Searched: not recorded.
Cross Context AdvertisingAmber
CTDPA regulates 'sale' of personal data and 'targeted advertising' analogous to CPRA's sale/share concepts, but does not use CPRA's specific 'cross-context behavioral advertising/share' terminology.
Claims (1):
Connecticut consumers have the right to opt out of the sale of their personal data and targeted advertising, and, under the 2026 amendments, to know whether a controller is processing their personal data for profiling that produces a legal or similarly significant effect.
Direct MarketingGreen
Targeted advertising and sale of personal data for marketing purposes are subject to opt-out rights and, for minors under 16, to opt-in consent requirements.
Claims (1):
Controllers must obtain opt-in consent before selling a consumer's personal data or processing it for targeted advertising when the consumer is under 16 years old, or where the controller has actual knowledge or willfully disregards that the consumer is between 13 and 16.
Key findings (3)
— source on file
— source on file
— source on file
Category narrative82 words
CTDPA requires an easily accessible opt-out link for targeted advertising/sale on websites and apps, and since January 1, 2025 requires controllers to honor universal opt-out preference signals (e.g., Global Privacy Control) sent through a privacy-protective browser or extension, without requiring authentication of the signal. Consent for material new purposes, sale, or targeted advertising cannot be obtained through dark patterns. Public Act 26-64 (effective Oct 1, 2026) newly prohibits sale/sharing of precise geolocation data and regulates personalized pricing based on consumer personal data.
Sources and claims (3)
ConfirmedConnecticut Office of the Attorney General — As of January 1, 2025, Connecticut consumers can send an opt-out preference signal, such as the Global Privacy Control, through a privacy-protective browser or browser extension, to automatically tell controllers they intend to opt out of targeted advertising and sale of personal data.observed
ProbableInternational Association of Privacy Professionals — Unlike Colorado's law, the CTDPA does not require controllers to authenticate opt-out signals, making it easier for consumers to exercise universal opt-out rights, similar to the approach under the California Privacy Rights Act.observed
ConfirmedConnecticut Office of the Attorney General — Controllers must obtain opt-in consent before selling a consumer's personal data or processing it for targeted advertising when the consumer is under 16 years old, or where the controller has actual knowledge or willfully disregards that the consumer is between 13 and 16.observed
Meaningful ADM-transparency and biometric/neural-data protections are enacted, but several of the most consequential provisions (facial recognition limits, expanded biometric/genetic/neural categories, AI training-data disclosure) are not yet effective as of the run date.
Primary frameworkConnecticut Data Privacy Act (CTDPA); Public Act No. 26-64
Traffic-light rationale — AmberMeaningful ADM-transparency and biometric/neural-data protections are enacted, but several of the most consequential provisions (facial recognition limits, expanded biometric/genetic/neural categories, AI training-data disclosure) are not yet effective as of the run date.
Sub-modules (6)
Profiling RestrictionsGreen
Controllers must conduct a Data Protection Assessment before processing personal data for profiling presenting a reasonably foreseeable risk of substantial injury to consumers, and must obtain consent before profiling a minor's personal data.
Claims (2):
Controllers must conduct a Data Protection Assessment before processing personal data for the purposes of profiling where such profiling presents a reasonably foreseeable risk of substantial injury to consumers.
A controller must obtain consent prior to processing a minor's personal data for profiling.
Automated Decision Making TransparencyAmber
The 2026 amendments grant consumers rights to know whether profiling is used to make legally or similarly significant decisions and, where feasible, to question results, learn the decision's reasoning, review the data used, and — for housing decisions specifically — correct data and obtain reevaluation.
Claims (1):
New consumer rights let Connecticut residents obtain a list of third parties to which a business sold their data, access inferences drawn from their personal data, and know whether profiling is used to make a decision producing legal or similarly significant effects, with feasible rights to question results, learn reasoning, review data used, and (for housing decisions) correct data and obtain reevaluation.
Ai Risk AssessmentsAmber
A new disclosure requirement enacted for 2025/2026 requires companies to disclose whether personal data is used to train large language models; Senate Bill 5 separately establishes broader AI regulatory measures in Connecticut.
Claims (1):
New disclosure requirements enacted for the CTDPA require companies to disclose whether personal data is used to train large language models.
Biometric RegimeAmber
The 2026 amendments drastically expand biometric-data coverage under 'sensitive data' to include such data regardless of purpose of collection and to include information derived therefrom; Public Act 26-64 separately introduces facial-recognition-technology limitations and transparency requirements effective October 1, 2026.
Claims (2):
The 2026 CTDPA amendment drastically expands the biometric and genetic data categories, removing the existing purpose-based limitation to include such data regardless of collection purpose and to include information derived therefrom, i.e., inferences created from genetic or biometric data.
Public Act No. 26-64 introduces and revises the definition of 'facial recognition technology' and sets limitations and transparency requirements for its use, with these provisions taking effect October 1, 2026.
Genetic DataAmber
The AG's 2026 report recommends adoption of a standalone genetic-data privacy law; in the interim, genetic data is covered as sensitive data under the CTDPA as amended, with expanded coverage of genetically-derived inferences.
Claims (2):
The Connecticut Attorney General's 2026 report on the CTDPA recommends the state legislature adopt a standalone genetic data privacy law, alongside adoption of a genetic-testing amendment expansion already introduced via Senate Bill 4.
The 2026 CTDPA amendment drastically expands the biometric and genetic data categories, removing the existing purpose-based limitation to include such data regardless of collection purpose and to include information derived therefrom, i.e., inferences created from genetic or biometric data.
State Surveillance CarveoutsRed
No CTDPA-specific national-security/state-surveillance carveout distinct from general exemptions was identified in the sources reviewed.
Absence provenance: not recorded. Searched: not recorded.
Key findings (3)
— source on file
— source on file
— source on file
Category narrative99 words
CTDPA requires opt-in consent for profiling presenting a foreseeable risk of substantial injury, and (as of the 2026 amendments) grants consumers rights to know when profiling produces legal/similarly-significant effects and to question/challenge automated decisions where feasible, including a specific correction/reevaluation right for housing-related automated profiling decisions. Public Act 26-64 (effective Oct 1, 2026) introduces facial-recognition-technology transparency/limitation requirements, and the 2026 sensitive-data amendments drastically expand biometric and genetic data categories to include information 'derived therefrom' and add a first-in-the-nation neural-data category. A new AI-specific disclosure requirement mandates that companies disclose whether personal data is used to train large language models.
Sources and claims (7)
ConfirmedInternational Association of Privacy Professionals — Controllers must conduct a Data Protection Assessment before processing personal data for the purposes of profiling where such profiling presents a reasonably foreseeable risk of substantial injury to consumers.observed
ConfirmedConnecticut Office of the Attorney General — New consumer rights let Connecticut residents obtain a list of third parties to which a business sold their data, access inferences drawn from their personal data, and know whether profiling is used to make a decision producing legal or similarly significant effects, with feasible rights to question results, learn reasoning, review data used, and (for housing decisions) correct data and obtain reevaluation.observed
ConfirmedConnecticut Office of the Attorney General — New disclosure requirements enacted for the CTDPA require companies to disclose whether personal data is used to train large language models.observed
ConfirmedInternational Association of Privacy Professionals — The 2026 CTDPA amendment drastically expands the biometric and genetic data categories, removing the existing purpose-based limitation to include such data regardless of collection purpose and to include information derived therefrom, i.e., inferences created from genetic or biometric data.observed
ConfirmedOneTrust DataGuidance — Public Act No. 26-64 introduces and revises the definition of 'facial recognition technology' and sets limitations and transparency requirements for its use, with these provisions taking effect October 1, 2026.observed
ConfirmedConnecticut Office of the Attorney General — The Connecticut Attorney General's 2026 report on the CTDPA recommends the state legislature adopt a standalone genetic data privacy law, alongside adoption of a genetic-testing amendment expansion already introduced via Senate Bill 4.observed
Substantial, actively-enforced minors' protections are already in force (since Oct 1, 2024), but the most far-reaching addictive-design/algorithm-consent measures are enacted with a multi-year phase-in to 2028, and the AG's own report flags continued gaps in the definition/scope of protections.
Primary frameworkConnecticut Data Privacy Act (CTDPA), as amended by the Online Privacy Act and subsequent minors'-privacy amendments
Traffic-light rationale — AmberSubstantial, actively-enforced minors' protections are already in force (since Oct 1, 2024), but the most far-reaching addictive-design/algorithm-consent measures are enacted with a multi-year phase-in to 2028, and the AG's own report flags continued gaps in the definition/scope of protections.
Sub-modules (5)
Age VerificationAmber
CTDPA relies on an actual-knowledge/willful-disregard standard for identifying minors under 16 (and generally under 18 for enhanced online-service protections) rather than mandating affirmative age-verification technology.
Claims (1):
Consent is required to process a consumer's personal data for targeted advertising or to sell their data where a controller has actual knowledge of, and willfully disregards, that the consumer is between 13 and 16 years old.
Parental ConsentGreen
A child's parent or legal guardian may exercise privacy rights on the child's behalf, and controllers must follow COPPA parental-consent requirements for children under 13.
Claims (1):
If a child's personal data is processed by a controller, the child's parent or legal guardian may exercise rights on the child's behalf, and controllers must follow COPPA regulations including parental-consent requirements.
Minor Profiling BansGreen
Controllers must obtain consent before processing a minor's personal data for profiling, and may not process a minor's data for targeted advertising or sale.
Claims (2):
A controller shall not process a minor's data for purposes of targeted advertising or any sale, and shall not use any design feature to significantly increase, sustain, or extend a minor's use of an online service, product, or feature.
A controller must obtain consent prior to processing a minor's personal data for profiling.
Education SettingsAmber
FERPA-regulated education records are exempted from CTDPA; no CT-specific education-technology privacy statute distinct from FERPA/COPPA was identified for this run.
Absence provenance: not recorded. Searched: not recorded.
Claims (1):
The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.
Dependent AdultsRed
No CTDPA provision specific to dependent/incapacitated adults distinct from the general consumer-rights framework was identified.
Absence provenance: not recorded. Searched: not recorded.
Key findings (3)
— source on file
— source on file
— source on file
Category narrative102 words
CTDPA layers state-specific minors' protections atop COPPA: opt-in consent is required before selling personal data or using it for targeted advertising for consumers under 16 (with an actual-knowledge/willful-disregard standard for 13-16 year-olds as of 2025); minors under 18 receive additional protections from controllers offering online services/products/features directed at minors, including bans on targeted advertising/sale of a minor's data, consent-before-profiling, restrictions on precise-geolocation collection, addictive-design-feature prohibitions, and default settings limiting adult-to-minor direct messaging. Further youth social-media-addiction measures (including a parental-consent requirement for algorithmic feeds) are enacted but do not take effect until 2028. Parents/legal guardians may exercise a child's rights on their behalf.
Sources and claims (3)
ConfirmedInternational Association of Privacy Professionals — Consent is required to process a consumer's personal data for targeted advertising or to sell their data where a controller has actual knowledge of, and willfully disregards, that the consumer is between 13 and 16 years old.observed
ConfirmedConnecticut Office of the Attorney General — If a child's personal data is processed by a controller, the child's parent or legal guardian may exercise rights on the child's behalf, and controllers must follow COPPA regulations including parental-consent requirements.observed
ConfirmedConnecticut Office of the Attorney General — A controller shall not process a minor's data for purposes of targeted advertising or any sale, and shall not use any design feature to significantly increase, sustain, or extend a minor's use of an online service, product, or feature.observed
Active, escalating enforcement program with a public settlement, annual statutory reporting, and clear statutory penalty/no-private-right-of-action posture — well documented and current as of the run date.
Primary frameworkConnecticut Data Privacy Act (CTDPA); Connecticut Unfair Trade Practices Act (CUTPA), Conn. Gen. Stat. §§ 42-110a et seq.
Traffic-light rationale — GreenActive, escalating enforcement program with a public settlement, annual statutory reporting, and clear statutory penalty/no-private-right-of-action posture — well documented and current as of the run date.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The AG has exclusive enforcement authority; violations are treated as unfair trade practices under CUTPA, carrying civil penalties of up to $5,000 per willful violation.
Claims (2):
The Attorney General has exclusive authority to enforce violations of the CTDPA.
Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.
Enforcement Activity IndexGreen
By the end of 2025, the AG's office had issued dozens of notices of violation/warning letters, finalized multiple data-breach settlements, and resolved its first formal CTDPA enforcement action; the TicketNetwork matter settled for $85,000 in mid-2025.
Claims (2):
By the end of 2025, the AG's office had issued dozens of notices of violation and warning letters, finalized multiple data breach settlements, and resolved its first enforcement action under the CTDPA.
The Connecticut Attorney General announced a settlement with TicketNetwork, Inc. under which the company agreed to comply with the CTDPA, maintain consumer-rights-request metrics, report those metrics to the AG, and pay $85,000.
Regulator Funding And CapacityAmber
Enforcement is conducted through the AG's Privacy and Data Security Department/Section, which also handles federal HIPAA/COPPA/FCRA enforcement delegated to the state; no specific headcount or budget figures were identified in the sources reviewed.
Absence provenance: not recorded. Searched: not recorded.
Claims (1):
SRC_placeholder (claim on file)
Collective Redress And Class ActionsAmber
No CTDPA-specific collective-redress or class-action mechanism was identified; general Connecticut civil procedure class-action rules would apply to any underlying tort/CUTPA claim, but CTDPA itself channels enforcement solely through the AG.
Absence provenance: not recorded. Searched: not recorded.
Claims (1):
Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.
Private Right Of ActionRed
The CTDPA does not include a private cause of action for individuals; enforcement is exclusively through the Attorney General.
Claims (1):
Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.
Recent Developments 180DAmber
Within the last 180 days of the run date (2026-08-05): AG Tong released the third annual CTDPA enforcement report (Feb 5, 2026) disclosing the first resolved enforcement action and new investigations into chatbots/AI products harming minors; Governor Lamont signed Senate Bill 4 (Public Act 26-64) on May 27, 2026 adding data-broker registration and facial-recognition rules effective Oct 1, 2026; and CTDPA amendments broadening applicability thresholds and sensitive-data categories took/take effect July 1, 2026.
Claims (3):
By the end of 2025, the AG's office had issued dozens of notices of violation and warning letters, finalized multiple data breach settlements, and resolved its first enforcement action under the CTDPA.
Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.
Amendments to the CTDPA going into effect on July 1, 2026 broaden applicability thresholds, including making all sensitive-data processing and all sales of personal data covered under the law.
Key findings (3)
— source on file
— source on file
— source on file
Category narrative107 words
The Attorney General has exclusive enforcement authority; the CTDPA carries civil penalties of up to $5,000 per willful violation under CUTPA, and the statutory 60-day cure period sunset on January 1, 2025, giving the AG discretion whether to offer cure opportunities thereafter. There is no private right of action. The AG's third annual report (Feb 5, 2026) disclosed the office's first resolved CTDPA enforcement action, multiple data-breach settlements, dozens of notices of violation/warning letters, and ongoing investigations into connected vehicles, social media/gaming platforms, and AI chatbots affecting minors. A notable public settlement was reached with TicketNetwork ($85,000) in mid-2025 for CTDPA violations tied to deficient consumer-rights mechanisms.
ConfirmedConnecticut Office of the Attorney General — Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.observed
ConfirmedConnecticut Office of the Attorney General — By the end of 2025, the AG's office had issued dozens of notices of violation and warning letters, finalized multiple data breach settlements, and resolved its first enforcement action under the CTDPA.observed
ConfirmedConnecticut Office of the Attorney General — The Connecticut Attorney General announced a settlement with TicketNetwork, Inc. under which the company agreed to comply with the CTDPA, maintain consumer-rights-request metrics, report those metrics to the AG, and pay $85,000.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Connecticut
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 42 claim(s), 15 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).
Strong T1 (Connecticut AG portal.ct.gov) and T2 (AG press releases, enforcement reports) coverage for regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress. sectoral_watch drew on a mix of T1/T2 (AG, CT Insurance Department Bulletin IC-42) sources. cross_border_and_adequacy is a genuine, explicitly-flagged regulatory gap (red traffic light, empty claims[], absent_field_provenance on every sub-module) rather than a research shortfall, consistent with US state comprehensive privacy statutes generally lacking GDPR-style transfer mechanisms. Several sub-modules (dpo_requirements, ropa_requirements, clean_rooms_and_dcr, state_surveillance_carveouts, dependent_adults, regulator_funding_and_capacity) relied on T3/negative-search absent_field_provenance because no CTDPA-specific provision was located. Amendment-heavy areas (biometric/genetic/neural data, facial recognition, AI training-data disclosure, data broker registration) are correctly tagged 'enacted_not_yet_effective' with July 1, 2026 or October 1, 2026 effective dates per the CAUTION flag on verifying current effective-date status.
Unresolved questions (4):
Exact final statutory text and section numbering for the July 1, 2026 CTDPA amendments (threshold and sensitive-data changes) had not been codified into the Connecticut General Statutes as of the research date; AG business-guidance PDF and press materials were used as the best available T1/T2 proxy.
Whether Public Act 26-64's financial/insurance/political-committee exemption carve-outs (reported by IAPP) were enacted in final form or amended before passage was not independently confirmed against the enrolled bill text.
No confirmed data point on Connecticut AG Privacy Section staffing/budget levels was located to support regulator_funding_and_capacity claims.
Precise operative date and scope of the SB1295/'algorithm ban without parental consent' 2028 measure could not be fully verified beyond the AG's press-release summary.