🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-CT · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 15 sources retrieved model claude-sonnet-5 ·

United States – Connecticut

US-CT schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: AIC, Advennt

Last updated · 10 categories · 42 claims · 15 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
42Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute in force since 2023 but undergoing frequent, materially expanding amendments (2024, 2026) that shift scope and thresholds; operators must track a moving compliance target.

Primary frameworkConnecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq., as amended
Traffic-light rationale — AmberComprehensive statute in force since 2023 but undergoing frequent, materially expanding amendments (2024, 2026) that shift scope and thresholds; operators must track a moving compliance target.

Sub-modules (5)

Regulator And AuthorityGreen

The Connecticut Attorney General has exclusive statutory authority to enforce the CTDPA; there is no dedicated state privacy agency (unlike California's CPPA).

Claims (1):

  • The Connecticut Attorney General has exclusive authority to enforce violations of the CTDPA and there is no private right of action.

Act And InstrumentsAmber

Core instrument is the CTDPA as amended by the Online Privacy Act (2023), the 2024 minors' amendments, the 2025/2026 threshold-lowering amendments (effective July 1, 2026), and Public Act 26-64 (SB4, effective October 1, 2026) adding data-broker and facial-recognition provisions.

Claims (3):

  • Governor Ned Lamont signed Senate Bill 6 (the CTDPA) into law on May 10, 2022, and the Act took effect on July 1, 2023.
  • Amendments to the CTDPA going into effect on July 1, 2026 broaden applicability thresholds, including making all sensitive-data processing and all sales of personal data covered under the law.
  • Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.

Material ScopeGreen

CTDPA covers personal data of CT residents acting in an individual/household context; excludes employment-context data and 16 categories of exempted data overlapping with federal sectoral laws (HIPAA, FCRA, GLBA, DPPA, FERPA, Farm Credit Act, Airline Deregulation Act).

Claims (2):

  • The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.
  • The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.

Territorial ScopeGreen

Applies to persons conducting business in Connecticut or targeting products/services to CT residents meeting the statutory thresholds; no extraterritorial reach beyond that consumer-targeting test.

Claims (1):

  • The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.

Regulator Registration And FilingAmber

The CTDPA itself imposes no general controller registration/filing requirement; however, Public Act 26-64 (effective Oct 1, 2026) newly requires data brokers to register and establish a deletion mechanism.

Claims (1):

  • Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative118 words

Connecticut's comprehensive consumer privacy regime is the Connecticut Data Privacy Act (CTDPA), Public Act No. 22-15 (Conn. Gen. Stat. § 42-515 et seq.), signed May 10, 2022 and effective July 1, 2023, enforced exclusively by the Connecticut Attorney General (no dedicated privacy agency). The Act has been amended multiple times (Online Privacy Act 2023, minors' protections effective Oct 1 2024, 2025 amendments effective July 1 2026 lowering applicability thresholds, and Public Act 26-64 / SB4 effective October 1 2026 adding data broker registration and facial recognition rules). Applicability thresholds are being broadened by the July 2026 amendments so that any processing of sensitive data or any sale of personal data triggers coverage, removing the prior 25,000-consumer sale-revenue threshold.

Sources and claims (6)
  1. ConfirmedConnecticut Office of the Attorney GeneralThe Connecticut Attorney General has exclusive authority to enforce violations of the CTDPA and there is no private right of action.observed
  2. ConfirmedConnecticut Office of the Attorney GeneralGovernor Ned Lamont signed Senate Bill 6 (the CTDPA) into law on May 10, 2022, and the Act took effect on July 1, 2023.observed
  3. ConfirmedConnecticut Office of the Attorney GeneralAmendments to the CTDPA going into effect on July 1, 2026 broaden applicability thresholds, including making all sensitive-data processing and all sales of personal data covered under the law.observed
  4. ConfirmedOneTrust DataGuidancePublic Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.observed
  5. ConfirmedConnecticut Office of the Attorney GeneralThe CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.observed
  6. ConfirmedInternational Association of Privacy ProfessionalsThe CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.observed

#

Consent standard and sensitive-data consent requirement are well-defined and in force, but the sensitive-data category list is being materially expanded by amendments not yet fully effective, creating a temporal compliance gap.

Primary frameworkConnecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq.
Traffic-light rationale — AmberConsent standard and sensitive-data consent requirement are well-defined and in force, but the sensitive-data category list is being materially expanded by amendments not yet fully effective, creating a temporal compliance gap.

Sub-modules (4)

Lawful BasesAmber

No enumerated Art.6-style lawful-bases list; general processing is permitted subject to purpose-limitation, data-minimization, and consumer opt-out rights for targeted advertising, sale, and certain profiling.

Claims (1):

  • Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes, and may not process personal data for purposes neither reasonably necessary to nor compatible with the disclosed purposes absent consent.

Special CategoriesAmber

Sensitive data requires opt-in consent prior to processing; the July 2026 amendments expand the sensitive-data category list to include disability/treatment status, non-binary/transgender status, genetic/biometric-derived information, and neural data.

Claims (2):

  • Sensitive data has heightened protections under the CTDPA and controllers must obtain affirmative opt-in consent before processing it.
  • As amended, 'sensitive data' now includes data revealing disability or treatment, non-binary or transgender status, information derived from genetic or biometric data, data known to relate to a child, neural data, certain financial account information, and government-issued identification information.

Pseudonymisation And AnonymisationRed

No specific statutory safe-harbour definition for pseudonymised/anonymised data was identified in the sources reviewed for this run.

Absence provenance: not recorded. Searched: not recorded.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative92 words

CTDPA does not use a GDPR-style enumerated lawful-bases model; instead it relies on an opt-out framework for ordinary processing plus opt-in consent requirements for sensitive data and material new-purpose processing. Consent must be freely given, specific, informed and unambiguous, cannot be obtained via dark patterns, and must be revocable via a mechanism at least as easy as the one used to give it. The 2026 amendments substantially broaden the definition of 'sensitive data' to include disability/treatment status, non-binary/transgender status, information derived from genetic or biometric data, neural data, and expanded financial/government-ID identifiers.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsControllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes, and may not process personal data for purposes neither reasonably necessary to nor compatible with the disclosed purposes absent consent.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsA consumer's consent under the CTDPA must be freely given, specific, informed and unambiguous, cannot be obtained through dark patterns, and controllers must provide an effective revocation mechanism at least as easy as the consent mechanism, ceasing processing within 15 days of revocation.observed
  3. ConfirmedConnecticut Office of the Attorney GeneralSensitive data has heightened protections under the CTDPA and controllers must obtain affirmative opt-in consent before processing it.observed
  4. ConfirmedConnecticut Office of the Attorney GeneralAs amended, 'sensitive data' now includes data revealing disability or treatment, non-binary or transgender status, information derived from genetic or biometric data, data known to relate to a child, neural data, certain financial account information, and government-issued identification information.observed

#

Well-defined statutory rights and response deadlines already in force, with an enacted (not-yet-effective) expansion of rights around profiling transparency and third-party disclosure.

Primary frameworkConnecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq.
Traffic-light rationale — GreenWell-defined statutory rights and response deadlines already in force, with an enacted (not-yet-effective) expansion of rights around profiling transparency and third-party disclosure.

Sub-modules (5)

Access RightGreen

Consumers may confirm whether a controller is processing their personal data and access it, free of charge once every 12 months, subject to a trade-secret exception.

Claims (1):

  • A consumer can request information about their personal data from a controller free of charge once every 12 months, with the controller permitted to charge an administrative fee beyond the annual free request.

Rectification And ErasureGreen

CTDPA grants rights to correct inaccuracies and to delete personal data, including data collected via third parties.

Claims (1):

  • The CTDPA provides Connecticut consumers the right to correct inaccuracies in their personal data and the right to delete their personal data, including data that a business collected through third parties.

Restriction And ObjectionGreen

Consumers may opt out of processing for targeted advertising, sale of personal data, and profiling producing legal or similarly significant effects.

Claims (1):

  • Connecticut consumers have the right to opt out of the sale of their personal data and targeted advertising, and, under the 2026 amendments, to know whether a controller is processing their personal data for profiling that produces a legal or similarly significant effect.

Data PortabilityGreen

The CTDPA as amended establishes a right to data portability for consumers.

Claims (1):

  • The CTDPA as amended establishes rights including access, deletion, and portability for consumers.

Deadlines And Response WindowsGreen

Controllers must respond to consumer requests within 45 days of receipt, extendable by an additional 45 days under certain conditions; appeal responses are due within 60 days of receipt of the appeal.

Claims (2):

  • A controller must respond to a consumer's requests no later than 45 days after receipt of the request, and under certain conditions may extend the response period by an additional 45 days.
  • A controller has 60 days after receipt of an appeal to write back to the consumer explaining actions taken or reasons for refusal, and if denied must provide information to contact the Attorney General.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative77 words

CTDPA grants CT consumers rights of access, correction, deletion, portability, and opt-out of targeted advertising/sale/certain profiling, plus an appeal right against controller denials. Controllers must respond within 45 days (extendable by a further 45 days when reasonably necessary); appeal responses are due within 60 days. The 2026 amendments add new rights to obtain a list of third parties sold to, access inferences drawn from personal data, and query/challenge automated profiling decisions with legal or similarly significant effects.

Sources and claims (6)
  1. ConfirmedConnecticut Office of the Attorney GeneralA consumer can request information about their personal data from a controller free of charge once every 12 months, with the controller permitted to charge an administrative fee beyond the annual free request.observed
  2. ConfirmedConnecticut Office of the Attorney GeneralThe CTDPA provides Connecticut consumers the right to correct inaccuracies in their personal data and the right to delete their personal data, including data that a business collected through third parties.observed
  3. ConfirmedConnecticut Office of the Attorney GeneralConnecticut consumers have the right to opt out of the sale of their personal data and targeted advertising, and, under the 2026 amendments, to know whether a controller is processing their personal data for profiling that produces a legal or similarly significant effect.observed
  4. ProbableOneTrust DataGuidanceThe CTDPA as amended establishes rights including access, deletion, and portability for consumers.observed
  5. ConfirmedConnecticut Office of the Attorney GeneralA controller must respond to a consumer's requests no later than 45 days after receipt of the request, and under certain conditions may extend the response period by an additional 45 days.observed
  6. ConfirmedConnecticut Office of the Attorney GeneralA controller has 60 days after receipt of an appeal to write back to the consumer explaining actions taken or reasons for refusal, and if denied must provide information to contact the Attorney General.observed

#

Strong breach-notification and DPIA-equivalent regime in force, but no explicit statutory DPO or ROPA requirement, and processor-contract obligations are less detailed than GDPR Art. 28.

Primary frameworkConnecticut Data Privacy Act (CTDPA); Connecticut Data Breach Notification Act, Conn. Gen. Stat. § 36a-701b; Connecticut Safeguards Law, Conn. Gen. Stat. § 42-471
Traffic-light rationale — AmberStrong breach-notification and DPIA-equivalent regime in force, but no explicit statutory DPO or ROPA requirement, and processor-contract obligations are less detailed than GDPR Art. 28.

Sub-modules (7)

Accountability And DpiaGreen

Controllers must conduct and document Data Protection Assessments/Impact Assessments before processing for targeted advertising, sale, risky profiling, or sensitive data; the 2025 amendments extend impact-assessment obligations to profiling decisions.

Claims (2):

  • Controllers must conduct assessments before processing personal data in a manner that presents a heightened risk of harm to consumers, including processing for targeted advertising, sale, profiling with reasonably foreseeable risk of substantial injury, and processing of sensitive data.
  • Senate Bill 1295 amends the CTDPA to mandate impact assessments for profiling decisions in connection with social-media platform obligations regarding minors' data.

Dpo RequirementsRed

No CTDPA provision mandating appointment of a Data Protection Officer was identified in the sources reviewed for this run.

Absence provenance: not recorded. Searched: not recorded.

Ropa RequirementsAmber

No explicit statutory records-of-processing-activities obligation distinct from the DPA/impact-assessment documentation requirement was identified.

Absence provenance: not recorded. Searched: not recorded.

Claims (1):

  • Controllers must conduct assessments before processing personal data in a manner that presents a heightened risk of harm to consumers, including processing for targeted advertising, sale, profiling with reasonably foreseeable risk of substantial injury, and processing of sensitive data.

Joint Controller ArrangementsGreen

CTDPA distinguishes controllers and processors; a processor exercising independent decision-making authority over purposes/means becomes a controller for that processing and assumes controller obligations.

Claims (1):

  • If a processor exercises decision-making authority with respect to the purposes and means of personal-data processing, it becomes a controller with respect to that processing and is subject to controller obligations under the CTDPA.

Security MeasuresGreen

Controllers must use reasonable safeguards to secure personal data (CTDPA), supplemented by the Connecticut Safeguards Law (Conn. Gen. Stat. § 42-471) and Social Security Number Law (§ 42-470).

Claims (1):

  • Controllers must use reasonable safeguards to secure personal data as part of their obligations to comply with the CTDPA.

Breach NotificationGreen

Under Conn. Gen. Stat. § 36a-701b, notice to affected CT residents must be made without unreasonable delay and no later than 60 days from discovery of the breach; AG notice is due no later than resident notification; SSN/TIN compromise triggers a mandatory 24-month credit-monitoring offer.

Claims (2):

  • Notice to Connecticut residents of a security breach must be made without unreasonable delay and no later than sixty days from discovery of the breach, per Conn. Gen. Stat. § 36a-701b(b)(1); notice to the Attorney General must be provided no later than when residents are notified.
  • If a Connecticut resident's Social Security number or Taxpayer Identification Number is believed compromised in a breach, Connecticut law requires the resident be offered 24 months of credit monitoring services.

Retention And DisposalAmber

No CTDPA-specific numeric retention-limit provision was identified beyond the general purpose-limitation/data-minimization principle.

Absence provenance: not recorded. Searched: not recorded.

Claims (1):

  • Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the disclosed purposes, and may not process personal data for purposes neither reasonably necessary to nor compatible with the disclosed purposes absent consent.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative91 words

CTDPA requires Data Protection Assessments (DPAs)/Impact Assessments before processing that presents a heightened risk of harm (targeted advertising, sale, risky profiling, sensitive-data processing); requires reasonable security safeguards; and requires a data breach notification under the separate Connecticut Data Breach Notification Act (Conn. Gen. Stat. § 36a-701b) — notice to consumers without unreasonable delay and no later than 60 days from discovery, with AG notice due no later than consumer notice. No CTDPA-specific DPO appointment requirement or formal ROPA mandate was identified; joint-controller arrangements are addressed only via generic controller/processor contractual requirements.

Sources and claims (6)
  1. ConfirmedConnecticut Office of the Attorney GeneralControllers must conduct assessments before processing personal data in a manner that presents a heightened risk of harm to consumers, including processing for targeted advertising, sale, profiling with reasonably foreseeable risk of substantial injury, and processing of sensitive data.observed
  2. ProbableOneTrust DataGuidanceSenate Bill 1295 amends the CTDPA to mandate impact assessments for profiling decisions in connection with social-media platform obligations regarding minors' data.observed
  3. ConfirmedConnecticut Office of the Attorney GeneralIf a processor exercises decision-making authority with respect to the purposes and means of personal-data processing, it becomes a controller with respect to that processing and is subject to controller obligations under the CTDPA.observed
  4. ConfirmedConnecticut Office of the Attorney GeneralControllers must use reasonable safeguards to secure personal data as part of their obligations to comply with the CTDPA.observed
  5. ConfirmedConnecticut Office of the Attorney GeneralNotice to Connecticut residents of a security breach must be made without unreasonable delay and no later than sixty days from discovery of the breach, per Conn. Gen. Stat. § 36a-701b(b)(1); notice to the Attorney General must be provided no later than when residents are notified.observed
  6. ConfirmedConnecticut Office of the Attorney GeneralIf a Connecticut resident's Social Security number or Taxpayer Identification Number is believed compromised in a breach, Connecticut law requires the resident be offered 24 months of credit monitoring services.observed

#

No comprehensive cross-border transfer regime exists under CTDPA; this is a genuine regulatory gap rather than an incomplete search.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists under CTDPA; this is a genuine regulatory gap rather than an incomplete search.

Sub-modules (6)

Transfer MechanismsRed

No CTDPA transfer-mechanism provision identified.

Absence provenance: not recorded. Searched: not recorded.

Adequacy ReceivedRed

Not applicable; CT is a sub-national US jurisdiction with no adequacy-receiving framework.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedRed

Not applicable; Connecticut does not issue adequacy determinations.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsRed

No SCC/BCR uptake mechanism exists under CTDPA.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement exists under CTDPA.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationRed

No data-localisation mandate exists under CTDPA.

Absence provenance: not recorded. Searched: not recorded.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative48 words

The CTDPA does not contain a distinct cross-border-transfer regime (no adequacy mechanism, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate) — this is characteristic of US state comprehensive privacy statutes, which regulate controller/processor obligations regardless of the data's onward destination rather than gating international transfers as GDPR-style regimes do.

#

Sectoral overlays are well-documented (insurance, health, financial), but the scope of financial/insurance exemptions is being actively renegotiated in pending 2026 amendments.

Primary frameworkCTDPA sectoral exemptions; Connecticut Insurance Data Security Law (Conn. Gen. Stat. Title 38a, implementing NAIC Insurance Data Security Model Law)
Traffic-light rationale — AmberSectoral overlays are well-documented (insurance, health, financial), but the scope of financial/insurance exemptions is being actively renegotiated in pending 2026 amendments.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA-regulated financial institutions and their data are generally exempt from CTDPA; the Connecticut Insurance Data Security Law imposes its own breach-notification duties, including a 72-hour TPSP-event notification for assuming insurers to ceding insurers and domiciliary regulators.

Claims (1):

  • Under the Connecticut Insurance Data Security Law, a licensee acting as an assuming insurer must notify affected ceding insurers and its domiciliary regulator of a cybersecurity event involving nonpublic information in the possession of a third-party service provider (TPSP) not later than 72 hours after the assuming insurer received notice from the TPSP.

Health Sector OverlayAmber

HIPAA-covered entities/business associates and their protected health information are exempt from CTDPA; the AG's Privacy Section separately enforces HIPAA under delegated federal authority. The CTDPA's standalone Consumer Health Data provisions (Online Privacy Act) apply to non-HIPAA consumer health data with no size threshold.

Claims (1):

  • The CTDPA applies to all Consumer Health Data Controllers doing business in or targeting Connecticut residents regardless of size or processing volume, with no revenue or processing threshold and no nonprofit exemption.

Telecoms And EprivacyAmber

No CT-specific ePrivacy/cookie-consent statute distinct from CTDPA's general opt-out framework was identified.

Absence provenance: not recorded. Searched: not recorded.

Employment DataGreen

CTDPA expressly excludes personal data processed in an employment context (e.g., job applications) from its scope.

Claims (1):

  • The CTDPA protects a Connecticut resident acting in an individual or household context but does not protect an individual acting in an employment context.

Credit And ScoringGreen

FCRA-regulated data and entities are exempt from CTDPA; the AG's Privacy and Data Security Department separately enforces the FCRA under delegated federal authority.

Claims (1):

  • The AG's Privacy and Data Security Department is responsible for enforcement of federal laws under which the Attorney General has enforcement authority, including HIPAA, COPPA, and the Fair Credit Reporting Act.

EducationGreen

FERPA-regulated education records are among the CTDPA's exempted data categories.

Claims (1):

  • The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.

InsuranceGreen

The Connecticut Insurance Data Security Law requires licensees to notify the Insurance Commissioner and affected consumers of cybersecurity events and imposes a distinct 72-hour TPSP-related notification duty for assuming insurers.

Claims (1):

  • Under the Connecticut Insurance Data Security Law, a licensee acting as an assuming insurer must notify affected ceding insurers and its domiciliary regulator of a cybersecurity event involving nonpublic information in the possession of a third-party service provider (TPSP) not later than 72 hours after the assuming insurer received notice from the TPSP.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative98 words

CTDPA carves out entities/data already regulated by federal sectoral frameworks: HIPAA-covered entities and business associates, GLBA-regulated financial institutions, FCRA data, and the Connecticut Insurance Data Security Law (Bulletin IC-42, implementing an NAIC-model cybersecurity-event notification regime for licensees, including a 72-hour notification duty for TPSP-related events to ceding insurers/domiciliary regulators). The AG's Privacy and Data Security Department also enforces HIPAA, COPPA, and FCRA under delegated federal authority. The 2026 amendments (per the IAPP analysis of the vetoed/passed amendment) propose narrowing exemptions for specific financial, insurance, and health company sub-categories and aligning a GLBA data exemption with most other states.

Sources and claims (3)
  1. ConfirmedConnecticut Insurance DepartmentUnder the Connecticut Insurance Data Security Law, a licensee acting as an assuming insurer must notify affected ceding insurers and its domiciliary regulator of a cybersecurity event involving nonpublic information in the possession of a third-party service provider (TPSP) not later than 72 hours after the assuming insurer received notice from the TPSP.observed
  2. ConfirmedConnecticut Office of the Attorney GeneralThe CTDPA applies to all Consumer Health Data Controllers doing business in or targeting Connecticut residents regardless of size or processing volume, with no revenue or processing threshold and no nonprofit exemption.observed
  3. ConfirmedConnecticut Office of the Attorney GeneralThe AG's Privacy and Data Security Department is responsible for enforcement of federal laws under which the Attorney General has enforcement authority, including HIPAA, COPPA, and the Fair Credit Reporting Act.observed

#

Universal opt-out signal recognition and dark-pattern prohibition are already in force and actively enforced; upcoming geolocation/personalized-pricing rules are enacted but not yet effective.

Primary frameworkConnecticut Data Privacy Act (CTDPA); Public Act No. 26-64
Traffic-light rationale — GreenUniversal opt-out signal recognition and dark-pattern prohibition are already in force and actively enforced; upcoming geolocation/personalized-pricing rules are enacted but not yet effective.

Sub-modules (6)

Cookies And TrackersGreen

No dedicated cookie-consent statute; tracking for targeted advertising/sale falls under the general CTDPA opt-out and universal-signal framework.

Claims (1):

  • As of January 1, 2025, Connecticut consumers can send an opt-out preference signal, such as the Global Privacy Control, through a privacy-protective browser or browser extension, to automatically tell controllers they intend to opt out of targeted advertising and sale of personal data.

Dark PatternsGreen

Consent cannot be obtained through the use of dark patterns under the CTDPA.

Claims (1):

  • A consumer's consent under the CTDPA must be freely given, specific, informed and unambiguous, cannot be obtained through dark patterns, and controllers must provide an effective revocation mechanism at least as easy as the consent mechanism, ceasing processing within 15 days of revocation.

Opt Out SignalsGreen

As of January 1, 2025, businesses covered under the CTDPA must honor universal opt-out preference signals like the Global Privacy Control sent via a privacy-protective browser or extension, without requiring authentication.

Claims (2):

  • As of January 1, 2025, Connecticut consumers can send an opt-out preference signal, such as the Global Privacy Control, through a privacy-protective browser or browser extension, to automatically tell controllers they intend to opt out of targeted advertising and sale of personal data.
  • Unlike Colorado's law, the CTDPA does not require controllers to authenticate opt-out signals, making it easier for consumers to exercise universal opt-out rights, similar to the approach under the California Privacy Rights Act.

Clean Rooms And DcrRed

No CTDPA-specific clean-room/data-collaboration-room provision identified.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingAmber

CTDPA regulates 'sale' of personal data and 'targeted advertising' analogous to CPRA's sale/share concepts, but does not use CPRA's specific 'cross-context behavioral advertising/share' terminology.

Claims (1):

  • Connecticut consumers have the right to opt out of the sale of their personal data and targeted advertising, and, under the 2026 amendments, to know whether a controller is processing their personal data for profiling that produces a legal or similarly significant effect.

Direct MarketingGreen

Targeted advertising and sale of personal data for marketing purposes are subject to opt-out rights and, for minors under 16, to opt-in consent requirements.

Claims (1):

  • Controllers must obtain opt-in consent before selling a consumer's personal data or processing it for targeted advertising when the consumer is under 16 years old, or where the controller has actual knowledge or willfully disregards that the consumer is between 13 and 16.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative82 words

CTDPA requires an easily accessible opt-out link for targeted advertising/sale on websites and apps, and since January 1, 2025 requires controllers to honor universal opt-out preference signals (e.g., Global Privacy Control) sent through a privacy-protective browser or extension, without requiring authentication of the signal. Consent for material new purposes, sale, or targeted advertising cannot be obtained through dark patterns. Public Act 26-64 (effective Oct 1, 2026) newly prohibits sale/sharing of precise geolocation data and regulates personalized pricing based on consumer personal data.

Sources and claims (3)
  1. ConfirmedConnecticut Office of the Attorney GeneralAs of January 1, 2025, Connecticut consumers can send an opt-out preference signal, such as the Global Privacy Control, through a privacy-protective browser or browser extension, to automatically tell controllers they intend to opt out of targeted advertising and sale of personal data.observed
  2. ProbableInternational Association of Privacy ProfessionalsUnlike Colorado's law, the CTDPA does not require controllers to authenticate opt-out signals, making it easier for consumers to exercise universal opt-out rights, similar to the approach under the California Privacy Rights Act.observed
  3. ConfirmedConnecticut Office of the Attorney GeneralControllers must obtain opt-in consent before selling a consumer's personal data or processing it for targeted advertising when the consumer is under 16 years old, or where the controller has actual knowledge or willfully disregards that the consumer is between 13 and 16.observed

#

Meaningful ADM-transparency and biometric/neural-data protections are enacted, but several of the most consequential provisions (facial recognition limits, expanded biometric/genetic/neural categories, AI training-data disclosure) are not yet effective as of the run date.

Primary frameworkConnecticut Data Privacy Act (CTDPA); Public Act No. 26-64
Traffic-light rationale — AmberMeaningful ADM-transparency and biometric/neural-data protections are enacted, but several of the most consequential provisions (facial recognition limits, expanded biometric/genetic/neural categories, AI training-data disclosure) are not yet effective as of the run date.

Sub-modules (6)

Profiling RestrictionsGreen

Controllers must conduct a Data Protection Assessment before processing personal data for profiling presenting a reasonably foreseeable risk of substantial injury to consumers, and must obtain consent before profiling a minor's personal data.

Claims (2):

  • Controllers must conduct a Data Protection Assessment before processing personal data for the purposes of profiling where such profiling presents a reasonably foreseeable risk of substantial injury to consumers.
  • A controller must obtain consent prior to processing a minor's personal data for profiling.

Automated Decision Making TransparencyAmber

The 2026 amendments grant consumers rights to know whether profiling is used to make legally or similarly significant decisions and, where feasible, to question results, learn the decision's reasoning, review the data used, and — for housing decisions specifically — correct data and obtain reevaluation.

Claims (1):

  • New consumer rights let Connecticut residents obtain a list of third parties to which a business sold their data, access inferences drawn from their personal data, and know whether profiling is used to make a decision producing legal or similarly significant effects, with feasible rights to question results, learn reasoning, review data used, and (for housing decisions) correct data and obtain reevaluation.

Ai Risk AssessmentsAmber

A new disclosure requirement enacted for 2025/2026 requires companies to disclose whether personal data is used to train large language models; Senate Bill 5 separately establishes broader AI regulatory measures in Connecticut.

Claims (1):

  • New disclosure requirements enacted for the CTDPA require companies to disclose whether personal data is used to train large language models.

Biometric RegimeAmber

The 2026 amendments drastically expand biometric-data coverage under 'sensitive data' to include such data regardless of purpose of collection and to include information derived therefrom; Public Act 26-64 separately introduces facial-recognition-technology limitations and transparency requirements effective October 1, 2026.

Claims (2):

  • The 2026 CTDPA amendment drastically expands the biometric and genetic data categories, removing the existing purpose-based limitation to include such data regardless of collection purpose and to include information derived therefrom, i.e., inferences created from genetic or biometric data.
  • Public Act No. 26-64 introduces and revises the definition of 'facial recognition technology' and sets limitations and transparency requirements for its use, with these provisions taking effect October 1, 2026.

Genetic DataAmber

The AG's 2026 report recommends adoption of a standalone genetic-data privacy law; in the interim, genetic data is covered as sensitive data under the CTDPA as amended, with expanded coverage of genetically-derived inferences.

Claims (2):

  • The Connecticut Attorney General's 2026 report on the CTDPA recommends the state legislature adopt a standalone genetic data privacy law, alongside adoption of a genetic-testing amendment expansion already introduced via Senate Bill 4.
  • The 2026 CTDPA amendment drastically expands the biometric and genetic data categories, removing the existing purpose-based limitation to include such data regardless of collection purpose and to include information derived therefrom, i.e., inferences created from genetic or biometric data.

State Surveillance CarveoutsRed

No CTDPA-specific national-security/state-surveillance carveout distinct from general exemptions was identified in the sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative99 words

CTDPA requires opt-in consent for profiling presenting a foreseeable risk of substantial injury, and (as of the 2026 amendments) grants consumers rights to know when profiling produces legal/similarly-significant effects and to question/challenge automated decisions where feasible, including a specific correction/reevaluation right for housing-related automated profiling decisions. Public Act 26-64 (effective Oct 1, 2026) introduces facial-recognition-technology transparency/limitation requirements, and the 2026 sensitive-data amendments drastically expand biometric and genetic data categories to include information 'derived therefrom' and add a first-in-the-nation neural-data category. A new AI-specific disclosure requirement mandates that companies disclose whether personal data is used to train large language models.

Sources and claims (7)
  1. ConfirmedInternational Association of Privacy ProfessionalsControllers must conduct a Data Protection Assessment before processing personal data for the purposes of profiling where such profiling presents a reasonably foreseeable risk of substantial injury to consumers.observed
  2. ConfirmedConnecticut Office of the Attorney GeneralA controller must obtain consent prior to processing a minor's personal data for profiling.observed
  3. ConfirmedConnecticut Office of the Attorney GeneralNew consumer rights let Connecticut residents obtain a list of third parties to which a business sold their data, access inferences drawn from their personal data, and know whether profiling is used to make a decision producing legal or similarly significant effects, with feasible rights to question results, learn reasoning, review data used, and (for housing decisions) correct data and obtain reevaluation.observed
  4. ConfirmedConnecticut Office of the Attorney GeneralNew disclosure requirements enacted for the CTDPA require companies to disclose whether personal data is used to train large language models.observed
  5. ConfirmedInternational Association of Privacy ProfessionalsThe 2026 CTDPA amendment drastically expands the biometric and genetic data categories, removing the existing purpose-based limitation to include such data regardless of collection purpose and to include information derived therefrom, i.e., inferences created from genetic or biometric data.observed
  6. ConfirmedOneTrust DataGuidancePublic Act No. 26-64 introduces and revises the definition of 'facial recognition technology' and sets limitations and transparency requirements for its use, with these provisions taking effect October 1, 2026.observed
  7. ConfirmedConnecticut Office of the Attorney GeneralThe Connecticut Attorney General's 2026 report on the CTDPA recommends the state legislature adopt a standalone genetic data privacy law, alongside adoption of a genetic-testing amendment expansion already introduced via Senate Bill 4.observed

#

Substantial, actively-enforced minors' protections are already in force (since Oct 1, 2024), but the most far-reaching addictive-design/algorithm-consent measures are enacted with a multi-year phase-in to 2028, and the AG's own report flags continued gaps in the definition/scope of protections.

Primary frameworkConnecticut Data Privacy Act (CTDPA), as amended by the Online Privacy Act and subsequent minors'-privacy amendments
Traffic-light rationale — AmberSubstantial, actively-enforced minors' protections are already in force (since Oct 1, 2024), but the most far-reaching addictive-design/algorithm-consent measures are enacted with a multi-year phase-in to 2028, and the AG's own report flags continued gaps in the definition/scope of protections.

Sub-modules (5)

Age VerificationAmber

CTDPA relies on an actual-knowledge/willful-disregard standard for identifying minors under 16 (and generally under 18 for enhanced online-service protections) rather than mandating affirmative age-verification technology.

Claims (1):

  • Consent is required to process a consumer's personal data for targeted advertising or to sell their data where a controller has actual knowledge of, and willfully disregards, that the consumer is between 13 and 16 years old.

Minor Profiling BansGreen

Controllers must obtain consent before processing a minor's personal data for profiling, and may not process a minor's data for targeted advertising or sale.

Claims (2):

  • A controller shall not process a minor's data for purposes of targeted advertising or any sale, and shall not use any design feature to significantly increase, sustain, or extend a minor's use of an online service, product, or feature.
  • A controller must obtain consent prior to processing a minor's personal data for profiling.

Education SettingsAmber

FERPA-regulated education records are exempted from CTDPA; no CT-specific education-technology privacy statute distinct from FERPA/COPPA was identified for this run.

Absence provenance: not recorded. Searched: not recorded.

Claims (1):

  • The CTDPA contains 16 categories of exempted data, including specific information regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and the Airline Deregulation Act, plus exemptions for specific employee and job-applicant data.

Dependent AdultsRed

No CTDPA provision specific to dependent/incapacitated adults distinct from the general consumer-rights framework was identified.

Absence provenance: not recorded. Searched: not recorded.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative102 words

CTDPA layers state-specific minors' protections atop COPPA: opt-in consent is required before selling personal data or using it for targeted advertising for consumers under 16 (with an actual-knowledge/willful-disregard standard for 13-16 year-olds as of 2025); minors under 18 receive additional protections from controllers offering online services/products/features directed at minors, including bans on targeted advertising/sale of a minor's data, consent-before-profiling, restrictions on precise-geolocation collection, addictive-design-feature prohibitions, and default settings limiting adult-to-minor direct messaging. Further youth social-media-addiction measures (including a parental-consent requirement for algorithmic feeds) are enacted but do not take effect until 2028. Parents/legal guardians may exercise a child's rights on their behalf.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsConsent is required to process a consumer's personal data for targeted advertising or to sell their data where a controller has actual knowledge of, and willfully disregards, that the consumer is between 13 and 16 years old.observed
  2. ConfirmedConnecticut Office of the Attorney GeneralIf a child's personal data is processed by a controller, the child's parent or legal guardian may exercise rights on the child's behalf, and controllers must follow COPPA regulations including parental-consent requirements.observed
  3. ConfirmedConnecticut Office of the Attorney GeneralA controller shall not process a minor's data for purposes of targeted advertising or any sale, and shall not use any design feature to significantly increase, sustain, or extend a minor's use of an online service, product, or feature.observed

#

Active, escalating enforcement program with a public settlement, annual statutory reporting, and clear statutory penalty/no-private-right-of-action posture — well documented and current as of the run date.

Primary frameworkConnecticut Data Privacy Act (CTDPA); Connecticut Unfair Trade Practices Act (CUTPA), Conn. Gen. Stat. §§ 42-110a et seq.
Traffic-light rationale — GreenActive, escalating enforcement program with a public settlement, annual statutory reporting, and clear statutory penalty/no-private-right-of-action posture — well documented and current as of the run date.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The AG has exclusive enforcement authority; violations are treated as unfair trade practices under CUTPA, carrying civil penalties of up to $5,000 per willful violation.

Claims (2):

  • The Attorney General has exclusive authority to enforce violations of the CTDPA.
  • Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.

Enforcement Activity IndexGreen

By the end of 2025, the AG's office had issued dozens of notices of violation/warning letters, finalized multiple data-breach settlements, and resolved its first formal CTDPA enforcement action; the TicketNetwork matter settled for $85,000 in mid-2025.

Claims (2):

  • By the end of 2025, the AG's office had issued dozens of notices of violation and warning letters, finalized multiple data breach settlements, and resolved its first enforcement action under the CTDPA.
  • The Connecticut Attorney General announced a settlement with TicketNetwork, Inc. under which the company agreed to comply with the CTDPA, maintain consumer-rights-request metrics, report those metrics to the AG, and pay $85,000.

Regulator Funding And CapacityAmber

Enforcement is conducted through the AG's Privacy and Data Security Department/Section, which also handles federal HIPAA/COPPA/FCRA enforcement delegated to the state; no specific headcount or budget figures were identified in the sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Claims (1):

  • SRC_placeholder (claim on file)

Collective Redress And Class ActionsAmber

No CTDPA-specific collective-redress or class-action mechanism was identified; general Connecticut civil procedure class-action rules would apply to any underlying tort/CUTPA claim, but CTDPA itself channels enforcement solely through the AG.

Absence provenance: not recorded. Searched: not recorded.

Claims (1):

  • Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.

Private Right Of ActionRed

The CTDPA does not include a private cause of action for individuals; enforcement is exclusively through the Attorney General.

Claims (1):

  • Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.

Recent Developments 180DAmber

Within the last 180 days of the run date (2026-08-05): AG Tong released the third annual CTDPA enforcement report (Feb 5, 2026) disclosing the first resolved enforcement action and new investigations into chatbots/AI products harming minors; Governor Lamont signed Senate Bill 4 (Public Act 26-64) on May 27, 2026 adding data-broker registration and facial-recognition rules effective Oct 1, 2026; and CTDPA amendments broadening applicability thresholds and sensitive-data categories took/take effect July 1, 2026.

Claims (3):

  • By the end of 2025, the AG's office had issued dozens of notices of violation and warning letters, finalized multiple data breach settlements, and resolved its first enforcement action under the CTDPA.
  • Public Act No. 26-64 (Senate Bill 4), signed May 27, 2026, amends the CTDPA and establishes a data-broker registration and deletion-request framework, with key provisions (data brokers, facial recognition technology, precise geolocation) taking effect October 1, 2026.
  • Amendments to the CTDPA going into effect on July 1, 2026 broaden applicability thresholds, including making all sensitive-data processing and all sales of personal data covered under the law.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative107 words

The Attorney General has exclusive enforcement authority; the CTDPA carries civil penalties of up to $5,000 per willful violation under CUTPA, and the statutory 60-day cure period sunset on January 1, 2025, giving the AG discretion whether to offer cure opportunities thereafter. There is no private right of action. The AG's third annual report (Feb 5, 2026) disclosed the office's first resolved CTDPA enforcement action, multiple data-breach settlements, dozens of notices of violation/warning letters, and ongoing investigations into connected vehicles, social media/gaming platforms, and AI chatbots affecting minors. A notable public settlement was reached with TicketNetwork ($85,000) in mid-2025 for CTDPA violations tied to deficient consumer-rights mechanisms.

Sources and claims (4)
  1. ConfirmedConnecticut Office of the Attorney GeneralThe Attorney General has exclusive authority to enforce violations of the CTDPA.observed
  2. ConfirmedConnecticut Office of the Attorney GeneralEntities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation pursuant to the Connecticut Unfair Trade Practices Act, and the CTDPA does not include a private cause of action for individuals.observed
  3. ConfirmedConnecticut Office of the Attorney GeneralBy the end of 2025, the AG's office had issued dozens of notices of violation and warning letters, finalized multiple data breach settlements, and resolved its first enforcement action under the CTDPA.observed
  4. ConfirmedConnecticut Office of the Attorney GeneralThe Connecticut Attorney General announced a settlement with TicketNetwork, Inc. under which the company agreed to comply with the CTDPA, maintain consumer-rights-request metrics, report those metrics to the AG, and pay $85,000.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Connecticut
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 42 claim(s), 15 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Strong T1 (Connecticut AG portal.ct.gov) and T2 (AG press releases, enforcement reports) coverage for regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress. sectoral_watch drew on a mix of T1/T2 (AG, CT Insurance Department Bulletin IC-42) sources. cross_border_and_adequacy is a genuine, explicitly-flagged regulatory gap (red traffic light, empty claims[], absent_field_provenance on every sub-module) rather than a research shortfall, consistent with US state comprehensive privacy statutes generally lacking GDPR-style transfer mechanisms. Several sub-modules (dpo_requirements, ropa_requirements, clean_rooms_and_dcr, state_surveillance_carveouts, dependent_adults, regulator_funding_and_capacity) relied on T3/negative-search absent_field_provenance because no CTDPA-specific provision was located. Amendment-heavy areas (biometric/genetic/neural data, facial recognition, AI training-data disclosure, data broker registration) are correctly tagged 'enacted_not_yet_effective' with July 1, 2026 or October 1, 2026 effective dates per the CAUTION flag on verifying current effective-date status.

Unresolved questions (4):

  • Exact final statutory text and section numbering for the July 1, 2026 CTDPA amendments (threshold and sensitive-data changes) had not been codified into the Connecticut General Statutes as of the research date; AG business-guidance PDF and press materials were used as the best available T1/T2 proxy.
  • Whether Public Act 26-64's financial/insurance/political-committee exemption carve-outs (reported by IAPP) were enacted in final form or amended before passage was not independently confirmed against the enrolled bill text.
  • No confirmed data point on Connecticut AG Privacy Section staffing/budget levels was located to support regulator_funding_and_capacity claims.
  • Precise operative date and scope of the SB1295/'algorithm ban without parental consent' 2028 measure could not be fully verified beyond the AG's press-release summary.

Escalate to primary-source review: yes