US Privacy Law Connecticut, USA

Connecticut CTDPA: Data Privacy Act Requirements

Connecticut's CTDPA explained: thresholds, consumer rights, consent for sensitive data, minors' amendments, health-data expansion, and AG enforcement.

Regulation

Connecticut Data Privacy Act (P.A. 22-15), Conn. Gen. Stat. 42-515 et seq., effective July 1, 2023

Max Penalty

Up to $5,000 per willful violation under CUTPA, plus restitution and injunctive relief

Enforcing Authority

Connecticut Attorney General

Official Source

portal.ct.gov

Executive Summary

  • The CTDPA (effective July 1, 2023) covers businesses processing personal data of 100,000+ Connecticut consumers annually (excluding payment-only data), or 25,000+ with over 25% of gross revenue from selling personal data.
  • It follows the Virginia model, rights to access, correct, delete, portability, and opt out of targeted advertising, sale, and profiling, but tightens it: opt-in consent for sensitive data, mandatory universal opt-out signal recognition since January 1, 2025, and a cure period that became discretionary after December 31, 2024.
  • Connecticut amended aggressively: 2023's SB 3 added consumer health data protections (geofencing bans around health facilities) and minors' social-media duties, and 2025 amendments (SB 1295) broaden scope, expand sensitive-data categories, and strengthen minors' protections.
  • The AG enforces through CUTPA with per-violation penalties, and its early enforcement report highlighted deficient privacy policies, missing opt-outs, and sensitive-data consent failures found in sweep letters.
  • Its trajectory matters: Connecticut keeps ratcheting requirements, so programs built to the strictest current text (with Colorado) absorb amendments cheaply.

Connecticut passed a Virginia-model statute and then refused to leave it alone. Health-data protections with a geofencing ban, escalating minors’ duties, universal opt-out recognition, threshold cuts, each session tightens the CTDPA, making it the bellwether for where the Virginia lineage is heading. The AG’s early sweep letters, documented in a public enforcement report, targeted exactly the visible failures: broken policies, missing opt-outs, unconsented sensitive data.

LawCTDPA, Conn. Gen. Stat. 42-515 et seq.
EffectiveJuly 1, 2023 (UOOM Jan 1, 2025; discretionary cure from 2025)
Max penalty$5,000 per willful violation (CUTPA)
RegulatorConnecticut AG

Where Connecticut differs from the pack

Health data has teeth. Opt-in consent for consumer health data, no selling without consent, and the 1,750-foot geofencing prohibition around health facilities, directly relevant to location SDKs, ad geotargeting, and retail apps. If your stack buys or builds location audiences, screen them against Connecticut’s ban the way you screen SPI in California.

Minors are a program, not a checkbox. 13-15 consent gates, account-deletion rights, duty-of-care provisions, and engagement-feature limits arriving in phases. Coordinate with COPPA below 13 and the state children’s law matrix for the rest.

Amendment velocity. The 2025 changes broaden applicability and sensitive-data categories again. Annual re-scoping is part of the compliance obligation in practice; static Virginia-built programs drift out of compliance here first.

Standard machinery, Connecticut clock. 45-day DSAR responses with appeal processes, processor contracts, data protection assessments for heightened-risk processing, and GPC recognition, all shareable with your Colorado and Virginia builds.

For planning across all the states at once, see the comparison matrix and multi-state strategy. And test the sweep-letter surface, policies, opt-outs, trackers, with a free scan.

Frequently Asked Questions

Who does the CTDPA cover?

Businesses conducting business in Connecticut or targeting its residents that, in the preceding calendar year, controlled or processed personal data of at least 100,000 consumers (excluding data processed solely for payment transactions), or 25,000+ consumers while deriving more than 25% of gross revenue from selling personal data. The 2025 amendments lower and broaden these thresholds and trim exemptions, so re-run your applicability analysis annually; Connecticut's is no longer static Virginia boilerplate.

What did Connecticut add on consumer health data?

SB 3 (2023) created 'consumer health data' protections inside the CTDPA: opt-in consent for processing, restrictions on selling, and a ban on geofencing within 1,750 feet of mental health, reproductive, or sexual health facilities to identify, track, or target consumers. This is the Washington My Health My Data concept executed as an amendment, without the private right of action, but with the AG's full attention on reproductive-health data flows.

What are the minors' data rules?

Layered and expanding: the CTDPA requires consent for targeted advertising and sales involving consumers aged 13-15 (known), SB 3 added social-media account deletion rights for minors, and later amendments impose duties of care for online services likely to be accessed by minors, default protections, and restrictions on features that increase engagement of minor users. Connecticut is among the most active states here; check current text before launching minor-facing features.

What does universal opt-out compliance require in Connecticut?

Since January 1, 2025, controllers must recognize universal opt-out preference signals (GPC in practice) as valid requests to opt out of targeted advertising and sale. The mechanics mirror Colorado's: automatic processing, no consumer confirmation demanded, authenticated consent may override with logging. If you built the Colorado/California signal pipeline, Connecticut is configuration.

How does enforcement work?

Exclusively through the Attorney General, as CUTPA violations, up to $5,000 per willful violation plus restitution, disgorgement, and injunctions. The mandatory 60-day cure window expired December 31, 2024; cure is now at the AG's discretion, weighing violation history and size. The AG's published enforcement report describes sweeps on privacy-policy deficiencies, sensitive-data consent, and teen-data practices, with cure letters converting into investigations where responses lag.

Regulatory Crosswalk

Colorado CPAVirginia VCDPACCPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.