Regulations › US states › Connecticut

CTDPA

Connecticut Data Privacy Act

In force privacy consumer rights
WhenIn effect since 1 July 2023
Who enforces itState Attorney General
Who it applies toBusinesses that process personal data of the state's residents above the law's thresholds. Thresholds, exemptions and sensitive-data rules differ by state.

Virginia-style law, amended to broaden coverage and strengthen rules on sensitive data and minors.

The law in brief

The Connecticut Data Privacy Act (CTDPA) is Connecticut's comprehensive consumer privacy law. It has been in effect since 1 July 2023. Like the other state laws built on the same model, it gives Connecticut residents rights over their personal data and puts duties on the businesses that decide how that data is used (controllers) and on the vendors that handle it for them (processors).

Virginia-style law, amended to broaden coverage and strengthen rules on sensitive data and minors.

Connecticut amended its law in 2025, broadening who it covers and what counts as sensitive data; the changes took effect on 1 July 2026.

Who it applies to

  • Businesses that process personal data of the state's residents above the law's thresholds. Thresholds, exemptions and sensitive-data rules differ by state.
  • The thresholds usually turn on how many Connecticut residents' personal data a business handles in a year, and whether it earns revenue from selling personal data. Check the statute for the exact figures.
  • Like most state privacy laws, it exempts some organizations and data, commonly including data already covered by HIPAA or the Gramm-Leach-Bliley Act, and data about people acting in an employment or commercial capacity.

What it requires

A clear privacy notice

Publish a privacy notice describing the categories of personal data you process, why, what you share and with whom, how consumers can use their rights, and how to appeal.

Collect only what you need

Limit collection to what is adequate, relevant and reasonably necessary for the purposes you disclosed, and secure it with reasonable safeguards.

Sensitive data

Get the consumer's opt-in consent before processing sensitive data, such as health information, biometric or genetic data, precise geolocation, and data about a known child (for whom parental consent is needed).

Contracts with processors

Bind each processor by contract to your instructions, confidentiality, deletion or return at the end of the service, and help with audits and assessments.

Honor opt-outs

Stop targeted advertising, sales and, where covered, qualifying profiling for consumers who opt out, and check whether the law requires you to honor universal opt-out signals such as Global Privacy Control.

Data protection assessments

Document an assessment before processing that presents a heightened risk, such as targeted advertising, selling personal data, processing sensitive data, and certain profiling.

People's rights

Connecticut residents can generally ask a business to confirm and access their personal data, correct it, delete it and get a copy in a portable format, and can opt out of targeted advertising, the sale of their data, and profiling that produces legal or similarly significant effects. Businesses generally have 45 days to respond, extendable once. Residents can usually appeal a refusal.

Enforcement and penalties

Enforced by the Connecticut Attorney General. Violations carry civil penalties set by the statute. Amendments enacted in 2025 took effect 1 July 2026.

What to do first

  1. Check the thresholds against your Connecticut consumer numbers and any data sales.
  2. Map the personal and sensitive data you hold about Connecticut residents.
  3. Update your privacy notice and add the opt-out routes the law requires.
  4. Set up requests and appeals within the response deadlines.
  5. Put CTDPA-ready terms in processor contracts.
  6. Build one program for all state laws, then add Connecticut's departures.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

  • 12 Aug 2026 New Law signed High 68 US-NJ New Jersey Attorney General

    New Jersey enacts Age-Appropriate Design Code (A4015) signed by Governor Sherrill

    The NJAADC introduces comprehensive safety‑by‑design rules for minors online, setting a new national benchmark for age‑appropriate design. On August 11, Governor Sherrill signed A4015, the New Jersey Age-Appropriate Design Code (NJAADC). The law, effective September 1, 2027, imposes safety defaults, bans dark patterns, and creates a private right of action. It applies to online services meeting revenue or data‑processing thresholds and includes enforcement under the Consumer Fraud Act.

    Effective: 1 September 2027. Penalty: $5k per violation or treble damages (whichever is greater). A4015.

    Source: Future of Privacy Forum. CTDPA in the regulations library.

Sources