Skip to main content

Connecticut Data Privacy Act (CTDPA)

Written by: Victoria Xikis

The CTDPA is a Connecticut law that took effect on May 10, 2022, to provide CT residents with control over their personal information and data collection when interacting with businesses that use this collected information. Earlier this year, Connecticut Attorney General William Tong released a report addressing amendments to the CTDPA. The report highlighted increased enforcement efforts, coordination with other state and federal privacy laws, and a continued focus on strengthening consumer protections for minors. These updates took effect on July 1, 2026.

Key Takeaways

  • More businesses are now subject to the CTDPA,
  • Stronger consent requirements are needed for sensitive data,
  • Increased protections are in place for minors,
  • New transparency requirements must be implemented around AI and data collection, and
  • Consumer rights have been expanded.

Amendments to CTDPA

Applicability and Stronger Consent Requirements

  1. Lowered thresholds for applicability, including all sensitive data processing and the sale of personal data.
    • The CTDPA will apply to any organization that processes sensitive data (e.g., health data).
    • Organizations will be required to obtain opt-in consent before collecting or using sensitive data. This consent must be clear, informed, and voluntarily given by the consumer.
      • Consumers must actively agree and not just accept general terms.
      • Consumers must provide “their freely given, specific, informed and unambiguous agreement to process their information with disclosure that identifies which categories of sensitive data are collected, who it is shared with, and for what specific purpose.”
    • Organizations are required to provide users with identifiable categories of the sensitive data that will be collected, who it is shared with, and the specific purpose for the collection while giving them the ability to revoke consent easily.[1]

New Requirements for Selling Personal Data

For organizations that sell personal data, there is now an expectation of transparency and notice to consumers. Businesses must implement a conspicuous notice that directs consumers to a mechanism for revocation of their consent and honor that revocation. Businesses must also……[please reword the rest of this sentence…]as well as provide either a list of third parties that they are affiliated with on their website or a contact department where consumers who request this list are able to be assisted in a timely manner. [1]

Enhanced Protections for Minors

  1. The amendments introduce significantly stronger protections for minors’ data, including:
    • Prohibiting targeted advertising and the sale of minors’ personal data;
    • Avoiding the use of addictive design features outright and banning minors’ data processing for targeted advertising and sale;
    • Banning the collection of a minor’s precise geolocation unless strictly necessary.

Avoiding a heightened risk of harm to minors, including but not limited to physical violence against minors, any material harassment of minors, and any sexual abuse or sexual exploitation of minors.

The amendments may force businesses to implement stronger age verification processes, which could increase compliance costs. Implementing more robust age verification processes would add further burden on businesses, requiring them to bolster their security platforms and enforce stronger security measures to verify, store, and, when necessary, delete sensitive information.

  1. Organizations will now be prohibited from using any system design feature to significantly increase, sustain, or extend any minor’s use of such online service, product, or feature.
  2. Controllers will also be required to conduct privacy impact assessments for minors’ data processing in addition to data protection assessments.[1]
    • Privacy Impact Assessments (PIAs) are used to assess how organizations collect, use, and share consumer personal information in order to ensure compliance with privacy policies.
    • Data Protection Impact Assessments (DPIAs) analyze privacy risks when processing, using, and storing consumer personal information with a focus of any risks to their freedom or rights. [2]

The result of these amendments may force businesses to implement stronger age verification processes, which could increase compliance costs. Implementing more robust age verification processes may add further burden on businesses by requiring them to bolster their security platforms and enforce stronger security measures to verify, store, and, when necessary, delete sensitive information.

Expanded Definition of Sensitive Data

  1. A broader definition of sensitive data, including new classifications such as disability, non-binary, transgender, neural data, certain treatment information, and financial and government identifier information.

New Disclosure Requirements for AI and Data Profiling

  1. New disclosure obligations related to AI, requiring organizations to disclose whether personal data is used to train a large language model (LLM).

Updated Consumer Rights

  1. CT residents’ right to opt out of profiling has also been expanded to include any automated processing as opposed to “solely” automated processing that produces legal or similar significant events, and they will also be afforded the right to contest the result of profiling decisions.
  2. Residents will be granted the right to access a list of specific third parties to whom the organization sells personal data and the explicit right to access inferences about the consumer derived from personal data.[1]

Expanded Reach and Updated Thresholds for Businesses

The CTDPA’s reach has significantly expanded to organizations that meet any of the following thresholds:

  • Control or process the personal data of at least 35,000 CT consumers;
  • Control or process CT consumers’ sensitive data (excluding personal data controlled or processed solely for the purpose of completing a payment transaction); or
  • Sell CT consumer personal data. [3]

Requirements for Privacy Notices

The CTDPA amendments impose the following disclosure requirements on businesses:

  1. Whether the business engages in profiling and whether personal data is used to train LLMs.
  2. Whether the business sells personal data to third parties for targeted advertising.
  3. A hyperlink with the word “privacy” on the business’s homepage so a user can directly access their privacy notice.
    • Notices must also be accessible to individuals with disabilities.2

Conclusion

Overall, these updates significantly expand the scope of the CTDPA and increase compliance requirements for businesses. As restrictions around minors’ online activity become more stringent, businesses will need to develop mechanisms to verify users’ ages and ensure that data belonging to a minor is identified and promptly deleted as applicable. Businesses should review their data practices now if they have not already done so. For Connecticut consumers, these changes provide stronger protections and greater control over their personal data.

 

References:

[1]Att’ys Gen., CTDPA Enf’t Rep, Off. of the Att’y Gen. Conn. (February 5, 2026), https://portal.ct.gov/-/media/ag/press_releases/2026/annual-report-final-2.pdf?rev=0cfe4e24714c4dd6b3562a677b1ecc55&hash=5017E8EEAD0A24C05AFC93D3E8C180C7

 

[2]Osano, PIA vs. DPIA: What’s the Difference?, JDSUPRA (2024), https://www.jdsupra.com/legalnews/pia-vs-dpia-what-s-the-difference-3328598/

 

[3]Pub. Act No. 25-113 (2025) §6, §42-525, https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF

 

Incident Response Consultant, Data Due Diligence Law Firm, Data Security Law Firm, Data Breach Lawyer & Privacy Law Firm in Buffalo, NY

Data Due Diligence Law Firm in Buffalo, NY | Cryptocurrency Law Firm

Cryptocurrency Law FirmData Security Law FirmData Breach LawyerIncident Response ConsultantPrivacy Law Firm ∴ Buffalo, NY

Buffalo, NY