EnglishEspañol
Connecticut flag

Connecticut

CTDPA Consumer Rights: Exercise Your Connecticut Privacy Rights

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

CTDPA Consumer Rights: Exercise Your Connecticut Privacy Rights

Frequently Asked Questions

What are my seven rights under the Connecticut Data Privacy Act?

Under Conn. Gen. Stat. § 42-518(a), you have seven rights: (1) access: confirm whether a company processes your data and get a copy; (2) correction: fix inaccuracies in data the company holds; (3) deletion: require removal of personal data the company collected from you or obtained about you; (4) portability: receive your data in a usable format you can transfer to another service; (5) opt-out: opt out of the sale of your personal data, processing for targeted advertising, and profiling that produces legal or similarly significant effects on you; (6) since July 1, 2026, contest certain automated-profiling decisions and, for housing decisions, correct the data used and have the decision reevaluated; and (7) since July 1, 2026, obtain a list of third parties a controller has sold your personal data to. These rights apply to covered controllers meeting the thresholds in § 42-516.

How long does a company have to respond to my CTDPA request?

Companies must respond within 45 days of receiving your authenticated request under Conn. Gen. Stat. § 42-518(c)(1). If the request is complex or the volume of requests is high, the company may extend this deadline once by an additional 45 days, giving a maximum window of 90 days total. The company must notify you of the extension and its reason within the initial 45-day period. Failing to respond at all within 45 days without notifying you of an extension is a violation.

Is there a fee for submitting a CTDPA data rights request?

No fee may be charged for your first request during any 12-month period. Conn. Gen. Stat. § 42-518(c)(3) requires responses to be provided free of charge once per consumer during any twelve-month period. Note: this is once per 12-month period, not twice. If your requests become manifestly unfounded, excessive, or repetitive beyond that initial free request, the company may charge a reasonable administrative fee or decline to act.

What is the Global Privacy Control and how do I use it in Connecticut?

Global Privacy Control (GPC) is a browser-level signal that automatically broadcasts your opt-out preference to every website you visit. Since January 1, 2025, every CTDPA-covered controller in Connecticut must honor a GPC signal as a request to opt out of data sales and targeted advertising under Conn. Gen. Stat. § 42-520(c)(1)(A)(ii). To use it, install a compatible browser extension or switch to a privacy-focused browser with GPC built in. Resources and a list of compatible tools are available at globalprivacycontrol.org, cited in AG Tong's December 30, 2024 advisory. Once active, covered companies must comply with your GPC preference even if it conflicts with a prior opt-in you gave.

What happens if a company denies my CTDPA rights request?

If a controller denies your request, it must provide a conspicuous appeal mechanism under Conn. Gen. Stat. § 42-518(d). You submit your appeal through that channel, and the company has 60 days to respond in writing with the action taken and the reasons. If your appeal is also denied, the company must give you information on how to contact the Connecticut Attorney General. You then file a complaint with the AG at portal.ct.gov/ag/common/complaint-form-landing-page, selecting Consumer Data Privacy from the subject dropdown.

How do I file a complaint with the Connecticut Attorney General about a data privacy violation?

File your CTDPA complaint using the AG's e-complaint form at portal.ct.gov/ag/common/complaint-form-landing-page and select Consumer Data Privacy from the subject dropdown. Include the company's name, dates of your request and denial, dates of your appeal and appeal denial, and copies of all written correspondence. The Connecticut AG has exclusive enforcement authority. There is no private right of action; only the AG can bring enforcement. Note: the original 60-day right-to-cure period sunsetted December 31, 2024, so the AG may now bring a civil action without first offering a cure window.

What is sensitive data under the CTDPA, and what rights do I have over it?

Sensitive data is defined in Conn. Gen. Stat. § 42-515(39), as amended by Public Act 25-113 effective July 1, 2026, and includes: racial or ethnic origin; religious beliefs; a mental or physical health condition, diagnosis, disability, or treatment; sex life, sexual orientation, or status as nonbinary or transgender; citizenship or immigration status; consumer health data; genetic or biometric data regardless of the purpose it is processed for; status as a victim of crime; precise geolocation; neural data; a financial account or card number combined with the access credential needed to use it; a government-issued identification number not required to be public; and personal data of a consumer the controller knows, or willfully disregards, is a child under 13. For these categories, the default flips from opt-out to opt-in: under Conn. Gen. Stat. § 42-520(a)(1)(D) a company may not process this data at all without first obtaining your affirmative consent. If you did not consent and a company is processing your sensitive data, that is a violation you can report to the AG.

Can a company sell data about a teenager in Connecticut?

No, not for teens 13 to 17. Since July 1, 2026, Conn. Gen. Stat. § 42-520(a)(1)(I), as amended by Public Act 25-113, bars a controller from selling the personal data of, or using it for targeted advertising toward, any consumer it knows or willfully disregards is at least 13 but younger than 18 years old. There is no consent exception, so the teen cannot opt in and a parent cannot consent on the teen's behalf to unlock it. For children under 13, federal COPPA applies and requires verifiable parental consent for any processing.

Can a company charge me more or refuse service because I opted out of data sales?

No. Under Conn. Gen. Stat. § 42-520(a), a controller may not deny you goods or services, charge different prices, or provide a lower quality of goods or services solely because you exercised a CTDPA right. Opting out of data sales, deleting your data, or sending a Global Privacy Control signal cannot be used as grounds to penalize you. A limited exception applies to voluntary loyalty programs where differential treatment is clearly disclosed and proportionate, but declining to participate in such a program cannot result in a penalty.

Updates

Corrected three Connecticut statutory citations and clarified that the minors’ design-feature and unsolicited-messaging safeguards date to 2024 rather than being added by Public Act 25-113.

Updated this page for Public Act 25-113, which took effect July 1, 2026: Connecticut now recognizes seven CTDPA consumer rights, not five (adding a right to contest certain automated-profiling decisions and a right to a list of third parties your data was sold to); the law now applies once a business hits 35,000 Connecticut consumers, processes any amount of sensitive data, or offers data for sale, replacing the old 100,000-consumer or 25,000-consumer-plus-revenue test; the sensitive-data list now also covers neural data, government ID numbers, financial account numbers, crime-victim status, and nonbinary/transgender status, and covers all genetic/biometric data regardless of purpose; the under-18 targeted-advertising and data-sale ban for teens is now in force, not upcoming; and we removed an unsupported claim that the TicketNetwork settlement was the state's first CTDPA enforcement action.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected eight CTDPA subsection citations that pointed to the wrong part of the statute: the 45-day response deadline and free-first-request rule are actually in § 42-518(c), the appeal process is § 42-518(d), the mandatory Global Privacy Control opt-out signal requirement is § 42-520(e)(1)(A)(ii), the teen (13-15) opt-in rule is § 42-520(a)(7), and the non-discrimination rule is § 42-520(a). Removed a citation to § 42-524 for AG enforcement authority since that section actually covers exemptions, not enforcement.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. CT AG. The Connecticut Data Privacy Act — Consumer Rights Overview(portal.ct.gov).gov
  2. Conn. Gen. Stat. § 42-518. Consumer rights; controller responsibilities(portal.ct.gov).gov
  3. Conn. Gen. Stat. § 42-519. Opt-out; authorized agents; universal opt-out signals(portal.ct.gov).gov
  4. Conn. Gen. Stat. § 42-520. Controller duties; data minimization; sensitive data(portal.ct.gov).gov
  5. CT AG Press Release, Dec. 30, 2024: Tong Advises CT Consumers and Businesses of Opt-Out Rights and GPC Requirements(portal.ct.gov).gov
  6. CT AG Press Release, July 8, 2025: Attorney General Tong Announces Settlement with TicketNetwork(portal.ct.gov).gov
  7. CT AG E-Complaint Form — Consumer Data Privacy(portal.ct.gov).gov
  8. Public Act 25-113 (SB 1295, 2025 Reg. Sess.) — Expanded Minors Privacy Protections, eff. July 1, 2026(cga.ct.gov).gov
Share: