CTDPA
Connecticut Data Privacy Act
Virginia-style law, amended to broaden coverage and strengthen rules on sensitive data and minors.
The law in brief
The Connecticut Data Privacy Act (CTDPA) is Connecticut's comprehensive consumer privacy law. It has been in effect since 1 July 2023. Like the other state laws built on the same model, it gives Connecticut residents rights over their personal data and puts duties on the businesses that decide how that data is used (controllers) and on the vendors that handle it for them (processors).
Virginia-style law, amended to broaden coverage and strengthen rules on sensitive data and minors.
Connecticut amended its law in 2025, broadening who it covers and what counts as sensitive data; the changes took effect on 1 July 2026.
Who it applies to
- Businesses that process personal data of the state's residents above the law's thresholds. Thresholds, exemptions and sensitive-data rules differ by state.
- The thresholds usually turn on how many Connecticut residents' personal data a business handles in a year, and whether it earns revenue from selling personal data. Check the statute for the exact figures.
- Like most state privacy laws, it exempts some organizations and data, commonly including data already covered by HIPAA or the Gramm-Leach-Bliley Act, and data about people acting in an employment or commercial capacity.
What it requires
A clear privacy notice
Publish a privacy notice describing the categories of personal data you process, why, what you share and with whom, how consumers can use their rights, and how to appeal.
Collect only what you need
Limit collection to what is adequate, relevant and reasonably necessary for the purposes you disclosed, and secure it with reasonable safeguards.
Sensitive data
Get the consumer's opt-in consent before processing sensitive data, such as health information, biometric or genetic data, precise geolocation, and data about a known child (for whom parental consent is needed).
Contracts with processors
Bind each processor by contract to your instructions, confidentiality, deletion or return at the end of the service, and help with audits and assessments.
Honor opt-outs
Stop targeted advertising, sales and, where covered, qualifying profiling for consumers who opt out, and check whether the law requires you to honor universal opt-out signals such as Global Privacy Control.
Data protection assessments
Document an assessment before processing that presents a heightened risk, such as targeted advertising, selling personal data, processing sensitive data, and certain profiling.
People's rights
Connecticut residents can generally ask a business to confirm and access their personal data, correct it, delete it and get a copy in a portable format, and can opt out of targeted advertising, the sale of their data, and profiling that produces legal or similarly significant effects. Businesses generally have 45 days to respond, extendable once. Residents can usually appeal a refusal.
Enforcement and penalties
Enforced by the Connecticut Attorney General. Violations carry civil penalties set by the statute. Amendments enacted in 2025 took effect 1 July 2026.
What to do first
- Check the thresholds against your Connecticut consumer numbers and any data sales.
- Map the personal and sensitive data you hold about Connecticut residents.
- Update your privacy notice and add the opt-out routes the law requires.
- Set up requests and appeals within the response deadlines.
- Put CTDPA-ready terms in processor contracts.
- Build one program for all state laws, then add Connecticut's departures.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
-
New Jersey enacts Age-Appropriate Design Code (A4015) signed by Governor Sherrill
The NJAADC introduces comprehensive safety‑by‑design rules for minors online, setting a new national benchmark for age‑appropriate design. On August 11, Governor Sherrill signed A4015, the New Jersey Age-Appropriate Design Code (NJAADC). The law, effective September 1, 2027, imposes safety defaults, bans dark patterns, and creates a private right of action. It applies to online services meeting revenue or data‑processing thresholds and includes enforcement under the Consumer Fraud Act.
Effective: 1 September 2027. Penalty: $5k per violation or treble damages (whichever is greater). A4015.
Source: Future of Privacy Forum. CTDPA in the regulations library.
Sources
- All of the comprehensive privacy laws that take effect in 2026 MultiState · Law firm or analyst
- US state privacy laws comparison (24 enacted laws, effective dates) Recording Law · Law firm or analyst