Skip to content

Connecticut Data Privacy Act (CTDPA): 2026 Compliance Guide

Mate Prgin 8/26/26, 1:00 PM

Table of Contents

The Connecticut Data Privacy Act (CTDPA) is Connecticut's comprehensive privacy law. It gives residents the right to access, correct, delete, and port their personal data, and to opt out of its sale, targeted advertising, and profiling. Businesses that decide how that data is used have to honor those rights and keep the data secure.

The CTDPA applies to any business that targets Connecticut residents and processes data on 35,000 or more consumers, sells personal data, or processes sensitive data. The last two triggers have no size threshold, and selling covers any exchange for value, not just money, so most ad-tech and analytics sharing can qualify.

It requires opt-outs for sale and targeted advertising, opt-in consent for sensitive data, and honoring Global Privacy Control (GPC) signals.

Willful violations cost up to $5,000 each under Connecticut's unfair trade practices law. There is no automatic cure period (it ended December 31, 2024) and no private right of action.

On June 30, 2026, a company with 40,000 Connecticut customers and no data sales was outside the CTDPA. On July 1, that flipped. The amendment that did that also erased volume thresholds: businesses selling or processing personal data, regardless of amount, are now subject to the law. 

The law was amended effective July 1, 2026; the changelog below covers every change.

This guide covers the current law, with the emphasis where you need it: what your website has to do, and how to tell whether you're covered at all.

What is the CTDPA?

The Connecticut Data Privacy Act is Connecticut's comprehensive consumer privacy law, in force since July 1, 2023 and substantially amended effective July 1, 2026 (SB 1295). It grants Connecticut residents rights over personal data and sets duties for controllers, the businesses that decide how data gets used. The statute sits at Conn. Gen. Stat. § 42-515; the attorney general's CTDPA page is the official reference.

For where Connecticut sits among all 20 state laws, see the U.S state law tracker.

Does the CTDPA apply to your business?

Since July 1, 2026, you're covered if you do business in Connecticut or target its residents, and any one of these is true:

  1. You control or process personal data of 35,000 or more Connecticut consumers in a year (down from 100,000 before the amendment), excluding data processed only to complete payments.
  2. You sell personal data. Any amount. Remember the broad definition: anything of value.
  3. You process sensitive data. Any amount, payment-only processing excluded. Consumer health data controllers are covered regardless of size.

Count only Connecticut residents acting for themselves, not your employees or B2B contacts, and count people rather than sessions. Estimate how many individual Connecticut residents show up across your customer records, email lists, and analytics in a year, in good faith; no one matches identities perfectly across systems.

The worked example from the top: a retailer that processed order and account data for 40,000 Connecticut customers in 2025 crossed nothing under the old law. Under the amended thresholds it's covered on prong one, and if its ad pixels share visitor data with an ad network, it was covered on prong two all along.

2-coverage@3x

 

Who's exempt

The CTDPA's exemptions work on two levels: some organizations are exempt as whole entities, and some data is exempt no matter who holds it.

Exempt as entities: state and local government bodies, nonprofits, higher-education institutions, and registered securities associations such as FINRA. Financial institutions used to be fully exempt under the federal Gramm-Leach-Bliley Act, but the 2026 amendment narrowed that to banks and Connecticut or federal credit unions.

Exempt as data: information already governed by federal law, including credit data under the FCRA, driver data under the DPPA, education records under FERPA, and Farm Credit Act data. De-identified data and publicly available information are out too.

The HIPAA exemption

Connecticut's exemption runs at both levels: HIPAA covered entities and business associates are exempt as organizations, and protected health information is exempt as data. The 2026 amendments left this alone. Note the contrast if you operate multi-state: Colorado exempts only the data, so the same hospital system can be exempt in Connecticut and covered in Colorado.

What counts as sensitive data under CTDPA

Sensitive data gets the strictest treatment: opt-in consent before you process it, and its own no-volume coverage trigger. Connecticut's categories are personal data revealing:

  • Racial or ethnic origin
  • Religious beliefs
  • A mental or physical health condition or diagnosis
  • Sex life or sexual orientation
  • Citizenship or immigration status
  • Genetic or biometric data processed to uniquely identify a person
  • Precise geolocation
  • Personal data collected from a known child

The 2026 amendment added more: status as nonbinary or transgender, disability, neural data, government identifiers such as driver's license or passport numbers, specified financial-account information, and Social Security numbers. Selling sensitive data now needs a separate consent, on top of consent to process it.

CTDPA compliance checklist

3-checklist@3x

Complying with the CTDPA comes down to five steps: count your Connecticut consumers, audit what your site shares, stand up sensitive-data consent, honor GPC, and get your records and DSAR intake in order. The list below doubles as a self-audit for whether your site sells data without realizing it.

  1. Count your Connecticut consumers. Customer records, email lists, analytics, previous calendar year, good-faith estimate.
  2. Audit what your site shares. List every third-party tag, pixel, and script. If any exchange visitor data for something of value (ad performance, discounted tooling, audience insights), you are likely selling.
  3. Stand up sensitive-data consent. If you touch health, biometric, precise location, or minors' data, you need opt-in consent before processing, and you may be covered at any size.
  4. Honor GPC. Mandatory in Connecticut since January 1, 2025. Test your banner against a GPC-enabled browser.
  5. Get your records and DSAR intake in order. Timestamped consent logs and a working rights-request workflow, including the new profiling-decision questions. Our DSAR guide covers the setup.

What the CTDPA requires from your website

Your website needs a compliant privacy notice, working opt-out and consent mechanics, and honored GPC signals. This is where enforcement actually starts: the attorney general's office has repeatedly cited cookie banners and privacy notices as its top problem areas.

Is your website selling data?

Under the CTDPA, a sale is any exchange of personal data for monetary or other valuable consideration, and targeted advertising is regulated separately but similarly. In practice that sweeps in a lot: a Meta pixel sharing browsing data to improve ad targeting, an analytics tool that reuses your visitor data across its customer base, an affiliate integration passing identifiable click data.

All of these can qualify as selling or targeted advertising. The question isn't whether money changed hands; it's whether data left your control and something of value came back.

Cookie consent and third-party scripts

Connecticut runs an opt-out model for ordinary personal data: you can load analytics and advertising scripts for a Connecticut visitor, but the moment they opt out (via your banner, a preference center, or a GPC signal), those scripts have to stop. Sensitive data flips the model to opt-in: nothing that touches it runs before consent.

A banner that shows but doesn't actually gate the scripts is decoration, and script behavior is exactly what automated compliance scans check.

Do-not-sell and GPC, implemented

Two mechanisms, one obligation. You need a visible way to opt out of sale and targeted advertising, and since January 1, 2025 you must also treat a Global Privacy Control browser signal as that same opt-out, no click required. GPC arrives with the page request, so your consent tooling has to read it and suppress the relevant tags on the first load, not after.

What your privacy notice must include

Your notice is the document the AG reads first, and it now has a required contents list: the categories of personal data you process and why, the categories you share and with whom, how a consumer exercises each right and how to appeal a denial, and an active online contact method.

The 2026 amendment added two disclosures: whether you profile or run targeted advertising, and whether you use or sell personal data to train large language models.

The amendment also tightened presentation. The notice needs a conspicuous homepage link containing the word privacy, it has to be available in each language you do business in, and it must be accessible to people with disabilities. If you make a material, retroactive change to how you use data you already collected, you have to tell affected consumers and give them a chance to withdraw consent.

5-website-must-do@3x

Service provider or third party?

Data you hand to a processor working under your instructions (your email platform, your hosting) is not a sale. Data that goes to a third party that uses it for its own purposes can be.

The dividing line is the contract and the actual data use. If a vendor uses your visitor data to improve its own products or serve other clients, treat it as a third party and gate it behind the opt-out.

How Enzuzo handles this: Enzuzo's consent management platform detects where a visitor is, applies Connecticut's opt-out and consent rules including GPC signals, blocks trackers until the right consent state exists, and keeps timestamped records. Teams typically go live in one to three days. Book a demo and see it for yourself.

Your duties as a controller

Beyond the website mechanics, the CTDPA puts a set of standing duties on the controller, and this is where most 2023-era compliance is now short.

Data minimization. Collect only what is reasonably necessary for the purposes you disclose. The 2026 amendment tightened this further for sensitive data.

Purpose limitation. Using data for a new purpose that isn't reasonably necessary to, or compatible with, the disclosed purpose needs the consumer's consent first, and your notice has to be updated to match.

Reasonable security. Keep administrative, technical, and physical safeguards appropriate to the volume and sensitivity of the data.

Processor contracts. Every processor must be bound by a contract governing how it handles your data, and you have to hold it to those terms. Data that goes to a vendor acting on its own behalf is a third party, not a processor.

Consent that counts. Where the law requires consent (sensitive data, secondary uses, minors), it must be freely given, specific, informed, and unambiguous. A consumer can withdraw it as easily as they gave it, and you have to stop the processing within 15 days.

No retaliation. You can't penalize a consumer for exercising a right by denying goods, charging more, or degrading service. A bona fide loyalty or rewards program is allowed, as long as it isn't a workaround for the opt-out.

Assessments. Processing with a heightened risk of harm (targeted advertising, selling data, certain profiling, handling sensitive data) requires a documented data protection assessment. A separate, new profiling impact assessment applies to profiling with legal or similar effects, for processing created on or after August 1, 2026.

Minors and the CTDPA

Minors get extra protection, and the 2026 amendment widened it. Data from a child under 13 needs verifiable parental consent, aligned with COPPA.

The protected teen band rose from under 16 to under 18, so for any consumer aged 13 to 17 you cannot serve targeted advertising or sell their personal data at all, with or without consent. You also cannot use engagement-maximizing design features to significantly extend a known minor's time on your service.

Penalties and enforcement: what actually happens

A willful CTDPA violation costs up to $5,000 per violation under the Connecticut Unfair Trade Practices Act. Fines are not the whole exposure: the attorney general can seek a restraining order, and violating one carries a further $25,000 penalty. The AG can also order a business to stop collecting data, pursue restitution, disgorgement (handing back what the violation earned), actual and punitive damages, costs, and attorneys' fees.

Enforcement is exclusive to the AG; consumers can't sue under the CTDPA. And there's no warning built in anymore: the 60-day cure period ended December 31, 2024, so a first violation can draw a demand without a fix-it window.

Connecticut's AG enforces this law more visibly than most. The office publishes annual enforcement reports, and by the end of 2025 it had issued dozens of violation notices and closed its first monetary settlement: TicketNetwork paid $85,000 after a 2023 cure notice about a deficient privacy notice went unfixed.

The pattern in the reports is consistent: privacy notices and consent mechanics draw the letters.

SB 1295 changelog: what changed on July 1, 2026

The 2025 amendment (SB 1295, signed June 24, 2025) is the biggest change to the CTDPA since it passed. Dated reference, one row per change:

SB 1295: what changed on July 1, 2026
Provision What changed What you must do
Thresholds 100K → 35K consumers; NEW no-volume triggers for selling data and processing sensitive data Re-check applicability even if you checked in 2023
Sensitive data Definition expanded (adds government IDs, SSNs, financial account elements, disability, transgender/nonbinary status, neural data); sale without consent expressly prohibited Update data inventory and consent flows
Minors Protected band raised to under 18 (was under 16); targeted ads and sale banned outright regardless of consent Remove reliance on teen consent for ads/sale
Consumer rights Access includes inferences; right to a list of third-party recipients; profiling opt-out no longer limited to solely automated decisions; consumers can question automated decisions Extend DSAR workflows
High-risk identifiers SSNs and similar can't be disclosed in access responses, only confirmed Adjust DSAR response templates
Privacy notices Must disclose LLM-training use of personal data and whether you profile or run targeted advertising; conspicuous homepage privacy link, in each language used, disability-accessible Rework notice content and placement
Data minimization Reasonably necessary standard tightened for sensitive data Review collection scope
Impact assessments Required for profiling with legal or similarly significant effects For processing created on or after Aug 1, 2026
Consent + withdrawal Sale of sensitive data needs a separate consent; withdrawal must be as easy as consent, and processing stops within 15 days Add a distinct sensitive-sale consent and easy withdrawal
Minors' design Engagement-maximizing design aimed at known minors is banned Remove addictive design patterns for minors

SB 4: the other CTDPA amendment, effective October 1

SB 1295 was not the only 2026 change. A second law, SB 4 (signed May 27, 2026, and amended by HB 5222 and HB 5563), takes effect October 1, 2026 and reaches beyond the CTDPA's core. If you handle location data, run a data business, or personalize prices, this one is for you.

  • Precise geolocation. Selling precise geolocation data, defined as accuracy within 1,750 feet, is banned.
  • Data brokers. Brokers must register with the Department of Consumer Protection ($2,500 to start, $2,500 a year) and honor a state deletion mechanism. Enforcement runs up to $200 per day, per consumer.
  • Surveillance pricing. If you raise a price using someone's personal data, you must disclose it with the exact line "THIS PRICE WAS INCREASED USING YOUR PERSONAL DATA," and retail sellers and third-party delivery platforms are barred from the practice outright.
  • Facial recognition. Public-facing use needs clear signage with a QR code or link to a policy that lists an attorney-general contact.
  • Genetic data. Consumers get a property right in the genetic samples and results a direct-to-consumer testing company holds.

6-rights-dsar@3x

Consumer rights under the CTDPA

Connecticut residents have these rights:

  • Access their data, now including inferences drawn about them.
  • Correct inaccuracies.
  • Delete their data.
  • Portability: take a copy in a usable format.
  • Third-party list: get the recipients their data went to.
  • Opt out of sale, targeted advertising, and profiling.
  • Question automated decisions with legal or similar effects.

Each right lands on your DSAR intake, and the mechanics matter as much as the list:

  • Timing. Respond within 45 days, extendable once by another 45 days when reasonably necessary, with notice to the consumer.
  • Cost. The first request in a 12-month period is free; you can charge a reasonable fee or decline a request that is manifestly unfounded, excessive, or repetitive, and you carry the burden of showing it qualifies.
  • Authorized agents. Consumers can name an agent to submit opt-outs on their behalf, including through a browser signal.
  • Appeals. You must offer a way to appeal a refusal, respond to that appeal, and if you still deny it, give the consumer a way to contact the attorney general.

CTDPA vs CCPA

4-ctdpa-vs-ccpa@3x

The CTDPA and California's CCPA cover the same ground but draw the lines differently. Connecticut reaches smaller companies, with a 35,000-consumer threshold and no-volume triggers for selling data or handling sensitive data. California adds a revenue test and covers the employee and B2B data that Connecticut leaves out entirely. Where they overlap most is the website work: both require opt-outs and honor GPC.

CTDPA vs CCPA at a glance
Point Connecticut (CTDPA) California (CCPA/CPRA)
Thresholds 35K consumers, or ANY selling / sensitive-data processing $25M revenue, 100K consumers, or 50% revenue from data
Private lawsuits No Breaches only
Fines $5,000/willful violation + AG remedies $2,500-$7,500/violation
Sensitive data Opt-in consent; sale banned without consent Right to limit
GPC Mandatory since Jan 2025 Mandatory
LLM-training disclosure Required in notices Not required

The practical takeaway: if you already comply with California, you have most of the operational pieces for Connecticut in place already. The key differences are CTDPA's no-volume triggers can pull in small companies California would exempt, and its LLM-training disclosure that California does not cover at the moment. 

FAQs

Who must comply with the CTDPA in 2026?

Any business targeting Connecticut residents that processes personal data of 35,000+ consumers, sells any personal data, or processes any sensitive data (payment-only data excluded). The last two have no volume threshold, so small companies are covered if they sell data or handle sensitive categories. Out-of-state and non-US companies count if they target Connecticut.

What are the penalties for violating the CTDPA, and is there a warning first?

Up to $5,000 per willful violation via Connecticut's unfair trade practices law, plus AG orders, restitution, disgorgement, restraining orders (with a further $25,000 penalty for violating one), and actual and punitive damages, costs, and fees. No warning is required: the cure period expired December 31, 2024. The first CTDPA settlement (TicketNetwork, $85,000) started as an unfixed privacy-notice problem.

What counts as selling data under the CTDPA?

Exchanging personal data for money or anything else of value. Ad pixels that share visitor data for better targeting, analytics tools that reuse your data, and data-for-discount arrangements can all qualify. Handing data to a processor that works only under your instructions is not a sale.

Does the CTDPA have a HIPAA exemption?

Yes, at both levels: HIPAA covered entities and business associates are exempt as organizations, and protected health information is exempt as data. The 2026 amendments didn't change this. Colorado, by contrast, exempts only the data, so multi-state health organizations need separate analyses.

Does Connecticut require honoring Global Privacy Control?

Yes, Connecticut requires honoring Global Privacy Control. Since January 1, 2025, controllers must treat universal opt-out signals like GPC as a valid opt-out from sale and targeted advertising, applied automatically, without the visitor clicking anything. Your consent tooling has to read the signal on page load and suppress the relevant scripts.

What changed in the CTDPA on July 1, 2026?

The threshold dropped from 100,000 to 35,000 consumers, and selling personal data or processing sensitive data now triggers coverage at any volume. Sensitive data expanded, minors' targeted ads and data sales are banned outright, consumer rights grew (inferences, third-party lists, profiling decisions), and privacy notices must disclose LLM-training use of personal data.

What must a CTDPA privacy notice include?

The categories of data you process and why, the categories you share and with whom, how consumers exercise each right and appeal a denial, and an online contact method. Since July 1, 2026 it must also disclose whether you profile, run targeted advertising, or use data to train large language models.

The notice also needs a conspicuous homepage link containing the word privacy, in each language you use and accessible to people with disabilities.

Does the CTDPA protect children's and minors' data?

The CTDPA gives minors extra protection, and the 2026 amendment widened it. Data from a child under 13 needs verifiable parental consent, aligned with COPPA. For minors aged 13 to 17, you cannot serve targeted advertising or sell their personal data at all, with or without consent, and you cannot use engagement-maximizing design to extend a known minor's time on your service.

Check your consent setup against the amended CTDPA, and the other 19 states → Book a demo

Mate Prgin

Mate Prgin

Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.