EnglishEspañol
Connecticut flag

Connecticut

CTDPA Compliance Checklist for Businesses (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. How we verify our legal content

CTDPA Compliance Checklist for Businesses (2026)

Frequently Asked Questions

Does the CTDPA apply to nonprofits?

Nonprofit organizations are generally exempt from the CTDPA under Conn. Gen. Stat. section 42-517(a). However, the nonprofit exemption does not extend to Consumer Health Data Controllers. A nonprofit that handles consumer health data, such as a wellness program, disease registry, or health-focused charity, must still comply with the CTDPA's health-data provisions regardless of its nonprofit status.

What makes Connecticut's 25% revenue threshold different from other state privacy laws?

Before July 1, 2026, Connecticut's original second applicability trigger covered businesses processing data of 25,000 or more consumers that derived more than 25 percent of gross revenue from selling personal data, a stricter bar than Virginia's 50 percent equivalent. That revenue-percentage trigger disappeared on July 1, 2026, when Public Act 25-113 replaced it with a simpler rule: any sale of personal data, regardless of revenue share or consumer volume, independently triggers coverage under current law.

When was the universal opt-out requirement effective, and what signals must I honor?

The universal opt-out obligation has been in effect since January 1, 2025. All covered businesses must treat opt-out preference signals, including the Global Privacy Control (GPC), as requests to opt out of the sale of personal data and targeted advertising. The signal must come from a platform that enables you to verify Connecticut residency. The Connecticut AG issued implementation guidance on December 19, 2024, advising businesses on technical compliance steps.

What is the difference between a data protection assessment and a profiling impact assessment?

A data protection assessment under Conn. Gen. Stat. section 42-522 is required for four categories of processing: targeted advertising, data sales, risky profiling, and sensitive data processing. It weighs benefits against consumer risks. A profiling impact assessment, newly required effective August 1, 2026 under Public Act 25-113, is a separate, more detailed document required specifically when profiling produces any legal or similarly significant decision effect on consumers. It must document purposes, data categories, risks, mitigation measures, transparency approach, and post-deployment safeguards.

Is there a private right of action under the CTDPA?

No. Enforcement rests exclusively with the Connecticut Attorney General under CUTPA. Individual consumers cannot bring a lawsuit for CTDPA violations, and there is no class action mechanism under the statute. This is a meaningful structural difference from the Illinois Biometric Information Privacy Act, which allows individuals to sue directly and has generated hundreds of millions of dollars in class action settlements.

Can the Connecticut AG still grant a cure opportunity after December 31, 2024?

The AG retains informal discretion to allow remediation time in appropriate cases, but businesses are no longer entitled to a cure opportunity by statute. The mandatory 60-day cure period expired December 31, 2024. The AG's updated enforcement posture indicates that covered entities receiving notice of a violation should assume the AG is prepared to file suit if remediation is not completed promptly. Relying on a discretionary cure opportunity is not a compliance strategy.

Do the July 1, 2026 threshold changes affect my existing compliance program?

Yes, potentially significantly. If your business previously fell below the 100,000-consumer threshold, you should now assess whether you process data of 35,000 or more Connecticut consumers, process any sensitive data, or sell any personal data. All three are independent triggers under Public Act 25-113. Businesses newly covered by the 2026 amendments need to complete a gap analysis covering: privacy notice updates including the new LLM disclosure, sensitive data inventory expansion to include SSNs, financial account information, and disability/treatment data, the minors' data advertising prohibition, and processor contract reviews.

What are the LLM training disclosure requirements and when do they take effect?

Since July 1, 2026, Connecticut has required all covered controllers to include a clear and conspicuous statement in their privacy notice disclosing whether they collect, use, or sell personal data for the purpose of training large language models. The obligation applies whether the training occurs internally or through a third-party vendor. This disclosure requirement is one of the first of its kind in state privacy law. Controllers using vendor AI services that train on customer data, or that feed their own datasets into LLM training pipelines must already have updated their privacy notices to include this disclosure.

Updates

Corrected the statutory citations in the enforcement, controller-duties and data-protection-assessment sections to the correct sections and subsections of the Connecticut General Statutes as amended by Public Act 25-113.

Corrected this checklist's applicability self-test, revenue-threshold FAQ, and LLM-disclosure FAQ, which still described the July 1, 2026 Public Act 25-113 changes as upcoming even though that date has passed and the current three-threshold test is already in force.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Conn. Gen. Stat. sections 42-515 through 42-525 (CTDPA, Chapter 743jj)(cga.ct.gov)
  2. Public Act 22-15 (Original CTDPA, enacted May 10, 2022, effective July 1, 2023)(cga.ct.gov)
  3. Public Act 23-56 (2023 CTDPA Amendments, consumer health data and child safety)(cga.ct.gov)
  4. Public Act 25-113 (SB 1295, signed June 25, 2025; expanded thresholds, LLM disclosure, minors' prohibition, sensitive data expansion, profiling assessments; most provisions effective July 1, 2026)(cga.ct.gov)
  5. Connecticut Attorney General, The Connecticut Data Privacy Act (official guidance)(portal.ct.gov)
  6. Connecticut AG, 'Tong Advises Connecticut Consumers and Businesses of Opt Out Rights and Requirements' (Dec. 19, 2024)(portal.ct.gov)
  7. Connecticut AG, 'Attorney General Tong Announces Settlement with TicketNetwork' (July 8, 2025)(portal.ct.gov)
  8. Connecticut AG, 'Attorney General Tong Releases Updated Report on Connecticut Data Privacy Act' (2026)(portal.ct.gov)
Share: