Connecticut
CTDPA Consumer Rights: Exercise Your Connecticut Privacy Rights
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

Under Conn. Gen. Stat. § 42-518, Connecticut residents hold seven enforceable privacy rights against companies that collect their data, including two rights added by Public Act 25-113 that took effect July 1, 2026. This page explains each right, the exact steps to exercise it, how to use Global Privacy Control, and how to escalate if a company ignores or denies your request.
Connecticut's Data Privacy Act applies to any covered controller that processes your personal data. If you want a broader overview of how the law works and who it covers, start with what the CTDPA is and who it covers. For the main Connecticut Data Privacy Act (CTDPA) hub, see the parent page.
Your Seven CTDPA Privacy Rights at a Glance
Connecticut's Data Privacy Act grants residents seven enumerated rights under Conn. Gen. Stat. § 42-518(a), two of which were added by Public Act 25-113 effective July 1, 2026. Every covered controller must honor these rights on request.
1. Right to access and confirm processing. You can ask any covered company to confirm whether it holds personal data about you and, if so, to provide you a copy. This covers both the confirmation (does the company have your data?) and the access right (show me what you have).
2. Right to correction. You can require a company to correct inaccuracies in personal data it holds about you, taking into account the nature of the data and the purposes of processing. This matters most for financial profiles, health-related records, and contact information used for decisions.
3. Right to deletion. You can demand removal of personal data the company collected from you or obtained about you from third parties. This is the broadest erasure right the CTDPA provides. Deletion is not absolute; companies may retain data to complete a transaction, comply with a legal obligation, or carry out certain security or research functions, and they must tell you which exemption applies if they refuse.
4. Right to data portability. You can receive a copy of your personal data in a portable, readily usable format that allows you to transmit it to another service where technically feasible.
5. Right to opt out. You can opt out of three distinct uses of your data: (a) the sale of your personal data to third parties; (b) processing for targeted advertising, meaning ads selected for you based on your activity across unrelated websites, apps, or services; and (c) profiling in furtherance of decisions that produce legal or similarly significant effects on you, such as decisions affecting credit, insurance, employment, housing, or access to essential services.
6. Right to contest automated profiling. Since July 1, 2026, if a company processed your data for profiling that produced a decision with a legal or similarly significant effect, you can question the result, be told why the profiling led to that decision, and review the data used. If the decision concerned housing, you can also correct inaccurate data and have the decision reevaluated based on the correction.
7. Right to a list of third-party data recipients. Since July 1, 2026, you can ask a controller for a list of the third parties it has sold your personal data to. If the controller does not keep a consumer-specific list, it must give you a list of all third parties it has sold personal data to generally. A controller is not required to reveal a trade secret to comply.
These rights apply only against controllers that meet the CTDPA's thresholds under Conn. Gen. Stat. § 42-516. As of July 1, 2026, a company conducting business in or targeting Connecticut residents is covered if, in the preceding calendar year, it (a) controlled or processed the personal data of at least 35,000 Connecticut consumers, excluding data processed solely to complete a payment transaction; (b) controlled or processed consumers' sensitive data, at any volume; or (c) offered consumers' personal data for sale in trade or commerce. Businesses that meet none of these three tests are not subject to the CTDPA's consumer-rights requirements.
How to Submit a CTDPA Rights Request
Every covered controller is required by Conn. Gen. Stat. § 42-520(b)(1) to maintain a privacy notice that clearly describes how consumers may exercise their rights, and by § 42-520(c)(1) to provide at least one secure, reliable submission channel. In practice, most companies offer an online privacy portal, a dedicated email address, or a toll-free number.
Step-by-step process:
- Find the company's privacy policy or look for a link in its website footer labeled "Privacy Rights," "Consumer Request," "Do Not Sell My Data," or "Your Privacy Choices."
- Select the right you want to exercise: access, correction, deletion, portability, or opt-out.
- Provide enough identifying information for the company to authenticate you. This typically means your name, the email address on file with your account, and possibly answers to security questions.
- Submit your request and save confirmation, whether a screenshot or a confirmation email, so you have a record of the submission date.
- The 45-day response window starts from the date the company receives your authenticated request.
Under Conn. Gen. Stat. § 42-518(c)(1), companies must respond without undue delay and in all cases within 45 days of receipt. If the company needs more time, it may extend the deadline once by an additional 45 days, giving a maximum response window of 90 days. When a company extends, it must notify you within the initial 45-day window and explain the reason for the extension.
Your first request in any 12-month period must be fulfilled free of charge. If your requests become manifestly unfounded, excessive, or repetitive, the company may charge a reasonable administrative fee or decline to act on them under § 42-518(c)(3).
If the company cannot authenticate your identity using commercially reasonable efforts, it is not required to comply, but it may request additional information from you necessary to authenticate the request rather than simply refusing outright. You are not required to provide information beyond what is reasonably necessary for authentication.

Using Global Privacy Control (GPC) to Opt Out Automatically
Since January 1, 2025, every CTDPA-covered controller must honor opt-out preference signals sent by Connecticut consumers under Conn. Gen. Stat. § 42-520(c)(1)(A)(ii). The Global Privacy Control is the leading implementation of this requirement.
GPC is a browser-level signal that automatically tells every website you visit that you do not consent to the sale of your personal data or its use for targeted advertising. Instead of clicking through an opt-out form on each company's website, you activate GPC once in your browser and it broadcasts your preference to every covered site you visit going forward.
How to activate GPC:
- Use a privacy-focused browser that has GPC built in, such as Brave or DuckDuckGo Browser.
- Install a GPC-compatible browser extension in Chrome, Firefox, or another browser.
- A list of compatible browsers and extensions is available at globalprivacycontrol.org, referenced directly by Connecticut Attorney General Tong in his December 30, 2024 consumer advisory.
Once activated, covered controllers must treat a valid GPC signal as a request to opt out of both the sale of your personal data and processing for targeted advertising. Critically, companies must honor a GPC signal even if it conflicts with a prior opt-in preference you gave or with participation in a loyalty program. If you previously opted in to data sharing as part of a rewards program, a GPC signal overrides that prior consent.
As of late 2024, more than 40 million users globally were already using GPC. As AG Tong noted in his advisory: "We're all familiar now with the 'ask site not to track' pop-ups. Starting January 1, you can install a simple browser extension to answer that question once and for all, and sites you visit will be responsible for knowing and following your preference."
Under Conn. Gen. Stat. § 42-519, you may also designate an authorized agent to submit opt-out requests on your behalf. The authorization can be made through a browser setting, browser extension, global device setting, or other technology. The controller must comply if it can verify your identity and the agent's authority using commercially reasonable effort.
Appealing a Denial and Filing a Complaint with the Connecticut AG
If a controller refuses to act on your rights request, Connecticut law gives you two escalation steps.
Step 1: Internal appeal. Under Conn. Gen. Stat. § 42-518(d), every covered controller must establish a conspicuous process for consumers to appeal refusals. Submit your appeal through whatever channel the company designates, typically the same privacy portal used for your initial request or a dedicated appeal email. There is no required form; clearly state that you are appealing the denial, identify your original request by type and date, and explain why you believe the refusal was improper.
The company has 60 days after receipt of your appeal to respond to you in writing, stating the action it took or the reasons it declined to act. Note the different timelines: 45 days for initial requests, 60 days for appeals.
Step 2: Connecticut Attorney General complaint. If the company denies your appeal, the law requires it to give you information describing how to contact the Connecticut Attorney General to file a complaint. File your CTDPA complaint at portal.ct.gov/ag/common/complaint-form-landing-page. Select "Consumer Data Privacy" from the subject dropdown on the AG's e-complaint form.
When filing, include the company's name, the date you submitted your original request, the date you received the denial, the date you submitted your appeal, the date you received the appeal denial, and copies of any written correspondence. The more documentation you provide, the stronger your complaint file.
The Connecticut AG has exclusive enforcement authority over the CTDPA. There is no private right of action, meaning you cannot sue a company directly for a CTDPA violation. The original CTDPA included a 60-day right-to-cure period that allowed the AG to give controllers an opportunity to fix violations before filing suit, but that cure period sunsetted on December 31, 2024. For violations occurring after that date, the AG may bring a civil action without first offering a cure window.
The AG's enforcement posture is serious. In one of its highest-profile CTDPA settlements, announced July 8, 2025, TicketNetwork, Inc. paid $85,000 and entered a consent decree after the AG found that its privacy notice was "largely unreadable, missing key data rights, and contained rights mechanisms that were misconfigured or inoperable." By that point the AG's office had already run four privacy-notice sweeps totaling more than two dozen cure notices; TicketNetwork was singled out because it repeatedly claimed to have fixed the deficiencies without actually doing so. The AG had issued its cure notice to TicketNetwork in November 2023; the company failed to cure within the window.

Sensitive Data Opt-In Consent and Protections for Minors
For certain categories of data and certain consumers, the CTDPA's default flips from opt-out to opt-in. The company must obtain your affirmative consent before processing can begin at all.
Sensitive data categories requiring opt-in consent. Under Conn. Gen. Stat. § 42-520(a)(1)(D), a controller may not process sensitive data without first obtaining the consumer's consent. The categories that count as sensitive data are defined separately, in Conn. Gen. Stat. § 42-515(39). As of July 1, 2026, that definition covers:
- Data revealing racial or ethnic origin
- Religious beliefs
- A mental or physical health condition, diagnosis, disability, or treatment
- Sex life, sexual orientation, or status as nonbinary or transgender
- Citizenship or immigration status
- Consumer health data as defined by Connecticut law
- Genetic data, regardless of the purpose it is processed for
- Biometric data, regardless of the purpose it is processed for (for more on this category, see biometric data protections in Connecticut)
- Status as a victim of crime
- Precise geolocation data
- Neural data (information generated by measuring the activity of your central nervous system)
- A financial account, debit card, or credit card number combined with the access code, password, or credential needed to reach the account
- A government-issued identification number not required by law to be publicly displayed, such as a Social Security number, passport number, state ID card number, or driver's license number
- Personal data of a consumer the controller knows, or willfully disregards, is a child under 13
For personal data of a known child under 13, the controller must comply with the Children's Online Privacy Protection Act (COPPA) verifiable parental consent requirement rather than the CTDPA's standard consumer-consent mechanism. Parents may submit rights requests on behalf of their minor children.
Current protection for teens aged 13 to 17. Public Act 25-113 (SB 1295, 2025 Regular Session) took effect July 1, 2026 and rewrote Conn. Gen. Stat. § 42-520(a)(1)(I). Where a controller has actual knowledge, or willfully disregards, that a consumer is at least 13 but younger than 18 years of age, the controller may not process that consumer's personal data for targeted advertising or sell it, period. There is no consent override: the teen cannot opt back in and a parent cannot consent on the teen's behalf to unlock it. This replaced the prior rule, which covered only ages 13 to 15 and allowed opt-in consent as an exception.
Personal data of a known child under 13 is handled separately under COPPA's verifiable-parental-consent standard, not this provision.
Separate minors' online-safety duties sit in Conn. Gen. Stat. § 42-529a, and they predate the 2025 act. Since October 1, 2024, a controller offering an online service to consumers it knows are minors has been barred from using any system design feature to significantly increase, sustain, or extend a minor's use of that service, and has had to provide safeguards limiting the ability of adults to send unsolicited messages to minors they are not connected to. Effective July 1, 2026, Public Act 25-113 moved the design-feature ban to § 42-529a(c)(1)(C) and added a carve-out for services used under the direction of an educational entity, and strengthened the messaging safeguard at § 42-529a(c)(1)(B) by requiring it to block unsolicited adult messages as a default setting.
Non-Discrimination: Exercising Rights Without Penalty
Under Conn. Gen. Stat. § 42-520(a), a controller must not discriminate against you for exercising any right under the CTDPA. The prohibition covers three specific forms of retaliation:
- Denying goods or services because you submitted a privacy request or opted out
- Charging different prices or rates solely because you exercised a right
- Providing a different level or quality of goods or services because you asked for your data, requested deletion, or opted out of data sales
In practical terms: a company cannot refuse to sell you a product, raise your price, or downgrade your subscription because you sent a deletion request or activated Global Privacy Control. The CTDPA's non-discrimination protection mirrors the approach taken in CCPA opt-out rights in California and Virginia's VCDPA consumer rights.
The prohibition does not prevent controllers from offering voluntary loyalty programs or financial incentives tied to data sharing. A retailer may offer discounts in exchange for agreeing to certain data uses, but participation in such programs must be genuinely voluntary, the differential treatment must be proportionate, and it must be clearly disclosed upfront. You cannot be penalized for declining to participate.
If you believe a company has penalized you for exercising a CTDPA right, document the conduct (screenshots of pricing changes, denial of access, downgraded service tier) and include it in your AG complaint.
Related guides
- What Is the CTDPA? Connecticut Data Privacy Act Explained
- CTDPA Compliance Checklist for Businesses (2026)
- Connecticut Data Privacy Laws: CTDPA Consumer Rights Guide (2026)
- Connecticut Biometric Privacy Laws: Collection, Consent & Penalties (2026)
- US State Privacy Laws Comparison Chart (2026)
More Connecticut Laws
Frequently Asked Questions
What are my seven rights under the Connecticut Data Privacy Act?
Under Conn. Gen. Stat. § 42-518(a), you have seven rights: (1) access: confirm whether a company processes your data and get a copy; (2) correction: fix inaccuracies in data the company holds; (3) deletion: require removal of personal data the company collected from you or obtained about you; (4) portability: receive your data in a usable format you can transfer to another service; (5) opt-out: opt out of the sale of your personal data, processing for targeted advertising, and profiling that produces legal or similarly significant effects on you; (6) since July 1, 2026, contest certain automated-profiling decisions and, for housing decisions, correct the data used and have the decision reevaluated; and (7) since July 1, 2026, obtain a list of third parties a controller has sold your personal data to. These rights apply to covered controllers meeting the thresholds in § 42-516.
How long does a company have to respond to my CTDPA request?
Companies must respond within 45 days of receiving your authenticated request under Conn. Gen. Stat. § 42-518(c)(1). If the request is complex or the volume of requests is high, the company may extend this deadline once by an additional 45 days, giving a maximum window of 90 days total. The company must notify you of the extension and its reason within the initial 45-day period. Failing to respond at all within 45 days without notifying you of an extension is a violation.
Is there a fee for submitting a CTDPA data rights request?
No fee may be charged for your first request during any 12-month period. Conn. Gen. Stat. § 42-518(c)(3) requires responses to be provided free of charge once per consumer during any twelve-month period. Note: this is once per 12-month period, not twice. If your requests become manifestly unfounded, excessive, or repetitive beyond that initial free request, the company may charge a reasonable administrative fee or decline to act.
What is the Global Privacy Control and how do I use it in Connecticut?
Global Privacy Control (GPC) is a browser-level signal that automatically broadcasts your opt-out preference to every website you visit. Since January 1, 2025, every CTDPA-covered controller in Connecticut must honor a GPC signal as a request to opt out of data sales and targeted advertising under Conn. Gen. Stat. § 42-520(c)(1)(A)(ii). To use it, install a compatible browser extension or switch to a privacy-focused browser with GPC built in. Resources and a list of compatible tools are available at globalprivacycontrol.org, cited in AG Tong's December 30, 2024 advisory. Once active, covered companies must comply with your GPC preference even if it conflicts with a prior opt-in you gave.
What happens if a company denies my CTDPA rights request?
If a controller denies your request, it must provide a conspicuous appeal mechanism under Conn. Gen. Stat. § 42-518(d). You submit your appeal through that channel, and the company has 60 days to respond in writing with the action taken and the reasons. If your appeal is also denied, the company must give you information on how to contact the Connecticut Attorney General. You then file a complaint with the AG at portal.ct.gov/ag/common/complaint-form-landing-page, selecting Consumer Data Privacy from the subject dropdown.
How do I file a complaint with the Connecticut Attorney General about a data privacy violation?
File your CTDPA complaint using the AG's e-complaint form at portal.ct.gov/ag/common/complaint-form-landing-page and select Consumer Data Privacy from the subject dropdown. Include the company's name, dates of your request and denial, dates of your appeal and appeal denial, and copies of all written correspondence. The Connecticut AG has exclusive enforcement authority. There is no private right of action; only the AG can bring enforcement. Note: the original 60-day right-to-cure period sunsetted December 31, 2024, so the AG may now bring a civil action without first offering a cure window.
What is sensitive data under the CTDPA, and what rights do I have over it?
Sensitive data is defined in Conn. Gen. Stat. § 42-515(39), as amended by Public Act 25-113 effective July 1, 2026, and includes: racial or ethnic origin; religious beliefs; a mental or physical health condition, diagnosis, disability, or treatment; sex life, sexual orientation, or status as nonbinary or transgender; citizenship or immigration status; consumer health data; genetic or biometric data regardless of the purpose it is processed for; status as a victim of crime; precise geolocation; neural data; a financial account or card number combined with the access credential needed to use it; a government-issued identification number not required to be public; and personal data of a consumer the controller knows, or willfully disregards, is a child under 13. For these categories, the default flips from opt-out to opt-in: under Conn. Gen. Stat. § 42-520(a)(1)(D) a company may not process this data at all without first obtaining your affirmative consent. If you did not consent and a company is processing your sensitive data, that is a violation you can report to the AG.
Can a company sell data about a teenager in Connecticut?
No, not for teens 13 to 17. Since July 1, 2026, Conn. Gen. Stat. § 42-520(a)(1)(I), as amended by Public Act 25-113, bars a controller from selling the personal data of, or using it for targeted advertising toward, any consumer it knows or willfully disregards is at least 13 but younger than 18 years old. There is no consent exception, so the teen cannot opt in and a parent cannot consent on the teen's behalf to unlock it. For children under 13, federal COPPA applies and requires verifiable parental consent for any processing.
Can a company charge me more or refuse service because I opted out of data sales?
No. Under Conn. Gen. Stat. § 42-520(a), a controller may not deny you goods or services, charge different prices, or provide a lower quality of goods or services solely because you exercised a CTDPA right. Opting out of data sales, deleting your data, or sending a Global Privacy Control signal cannot be used as grounds to penalize you. A limited exception applies to voluntary loyalty programs where differential treatment is clearly disclosed and proportionate, but declining to participate in such a program cannot result in a penalty.
Updates
Corrected three Connecticut statutory citations and clarified that the minors’ design-feature and unsolicited-messaging safeguards date to 2024 rather than being added by Public Act 25-113.
Updated this page for Public Act 25-113, which took effect July 1, 2026: Connecticut now recognizes seven CTDPA consumer rights, not five (adding a right to contest certain automated-profiling decisions and a right to a list of third parties your data was sold to); the law now applies once a business hits 35,000 Connecticut consumers, processes any amount of sensitive data, or offers data for sale, replacing the old 100,000-consumer or 25,000-consumer-plus-revenue test; the sensitive-data list now also covers neural data, government ID numbers, financial account numbers, crime-victim status, and nonbinary/transgender status, and covers all genetic/biometric data regardless of purpose; the under-18 targeted-advertising and data-sale ban for teens is now in force, not upcoming; and we removed an unsupported claim that the TicketNetwork settlement was the state's first CTDPA enforcement action.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected eight CTDPA subsection citations that pointed to the wrong part of the statute: the 45-day response deadline and free-first-request rule are actually in § 42-518(c), the appeal process is § 42-518(d), the mandatory Global Privacy Control opt-out signal requirement is § 42-520(e)(1)(A)(ii), the teen (13-15) opt-in rule is § 42-520(a)(7), and the non-discrimination rule is § 42-520(a). Removed a citation to § 42-524 for AG enforcement authority since that section actually covers exemptions, not enforcement.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Connecticut General Statutes, Title 42 (Business, Selling, Trading and Collection Practices), Chapter 743jj
§ 42-518Consumers' rights. Compliance by Controllers. Appeals.In forcecited in 3 of our articles
(a) A consumer shall have the right to: (1) Confirm whether or not a controller is processing the consumer's personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by, or obtained about, the consumer; (4) obtain a copy of the consumer's personal data processed by the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means, provided such controller shall not be required to reveal any trade secret; and (5) opt out of the processing of the personal data for purposes of (A) targeted advertising, (B) the sale of personal data, except as provided in subsection (b) of section 42-520, or (C) profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at cga.ct.gov
Also relied on in: What Is the CTDPA? Connecticut Data Privacy Act Explained, Connecticut Data Privacy Laws: CTDPA Consumer Rights Guide (2026)
§ 42-520Controllers' duties. Sale of personal data to third parties. Notice and disclosure to consumers. Consumer opt-out.In forcecited in 3 of our articles
(a) A controller shall: (1) Limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer; (2) except as otherwise provided in sections 42-515 to 42-525, inclusive, not process personal data for purposes that are neither reasonably necessary to, nor compatible with, the disclosed purposes for which such personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer's consent; (3) establish, implement and maintain reasonable administrative, technical and physical data security practices to protect the confidentiality, integrity and accessibility of personal data appropriate to the volume and nature of the personal data at issue; (4) not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with COPPA; (5) not process personal data in violation of the laws of this state and federal laws that prohibit unlawful discrimination against consumers; (6) provide an effective…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at cga.ct.gov
Also relied on in: Connecticut Biometric Privacy Laws: Collection, Consent & Penalties (2026), CTDPA Compliance Checklist for Businesses (2026)
§ 42-519Authorized agents and consumer opt-out.In force
A consumer may designate another person to serve as the consumer's authorized agent, and act on such consumer's behalf, to opt out of the processing of such consumer's personal data for one or more of the purposes specified in subdivision (5) of subsection (a) of section 42-518. The consumer may designate such authorized agent by way of, among other things, a technology, including, but not limited to, an Internet link or a browser setting, browser extension or global device setting, indicating such consumer's intent to opt out of such processing. A controller shall comply with an opt-out request received from an authorized agent if the controller is able to verify, with commercially reasonable effort, the identity of the consumer and the authorized agent's authority to act on such consumer's behalf.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at cga.ct.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- CT AG. The Connecticut Data Privacy Act — Consumer Rights Overview(portal.ct.gov).gov
- Conn. Gen. Stat. § 42-518. Consumer rights; controller responsibilities(portal.ct.gov).gov
- Conn. Gen. Stat. § 42-519. Opt-out; authorized agents; universal opt-out signals(portal.ct.gov).gov
- Conn. Gen. Stat. § 42-520. Controller duties; data minimization; sensitive data(portal.ct.gov).gov
- CT AG Press Release, Dec. 30, 2024: Tong Advises CT Consumers and Businesses of Opt-Out Rights and GPC Requirements(portal.ct.gov).gov
- CT AG Press Release, July 8, 2025: Attorney General Tong Announces Settlement with TicketNetwork(portal.ct.gov).gov
- CT AG E-Complaint Form — Consumer Data Privacy(portal.ct.gov).gov
- Public Act 25-113 (SB 1295, 2025 Reg. Sess.) — Expanded Minors Privacy Protections, eff. July 1, 2026(cga.ct.gov).gov