Connecticut passed a Virginia-model statute and then refused to leave it alone. Health-data protections with a geofencing ban, escalating minors’ duties, universal opt-out recognition, threshold cuts, each session tightens the CTDPA, making it the bellwether for where the Virginia lineage is heading. The AG’s early sweep letters, documented in a public enforcement report, targeted exactly the visible failures: broken policies, missing opt-outs, unconsented sensitive data.
| Law | CTDPA, Conn. Gen. Stat. 42-515 et seq. |
|---|---|
| Effective | July 1, 2023 (UOOM Jan 1, 2025; discretionary cure from 2025) |
| Max penalty | $5,000 per willful violation (CUTPA) |
| Regulator | Connecticut AG |
Where Connecticut differs from the pack
Health data has teeth. Opt-in consent for consumer health data, no selling without consent, and the 1,750-foot geofencing prohibition around health facilities, directly relevant to location SDKs, ad geotargeting, and retail apps. If your stack buys or builds location audiences, screen them against Connecticut’s ban the way you screen SPI in California.
Minors are a program, not a checkbox. 13-15 consent gates, account-deletion rights, duty-of-care provisions, and engagement-feature limits arriving in phases. Coordinate with COPPA below 13 and the state children’s law matrix for the rest.
Amendment velocity. The 2025 changes broaden applicability and sensitive-data categories again. Annual re-scoping is part of the compliance obligation in practice; static Virginia-built programs drift out of compliance here first.
Standard machinery, Connecticut clock. 45-day DSAR responses with appeal processes, processor contracts, data protection assessments for heightened-risk processing, and GPC recognition, all shareable with your Colorado and Virginia builds.
For planning across all the states at once, see the comparison matrix and multi-state strategy. And test the sweep-letter surface, policies, opt-outs, trackers, with a free scan.