Connecticut
What Is the CTDPA? Connecticut Data Privacy Act Explained
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. How we verify our legal content

The Connecticut Data Privacy Act (CTDPA), codified at Conn. Gen. Stat. §§ 42-515 through 42-526, took effect July 1, 2023, making Connecticut the fifth state to enact a comprehensive consumer data privacy law. Governor Ned Lamont signed Public Act 22-15 on May 10, 2022, and the law has since been expanded twice to become one of the most protective state privacy frameworks in the country.
As of 2026, the Connecticut Attorney General actively enforces the CTDPA and has resolved its first enforcement action under the law, issuing dozens of notices of violation and warning letters to covered businesses.
What the CTDPA is: statute, enactment, and background
The CTDPA is Connecticut's comprehensive consumer data privacy statute, codified at Conn. Gen. Stat. §§ 42-515 through 42-526 (Chapter 743jj). Governor Ned Lamont signed Senate Bill 6 as Public Act 22-15 on May 10, 2022, with a delayed effective date of July 1, 2023, giving businesses just over a year to prepare. The law's official title is "An Act Concerning Personal Data Privacy and Online Monitoring."
Connecticut was the fifth state to enact a law of this scope, joining California, Virginia, Colorado, and Utah. But the CTDPA moved quickly to distinguish itself from its predecessors. Its original secondary applicability threshold used a 25 percent gross revenue trigger rather than the 50 percent bar set by Virginia; Public Act 25-113 repealed that revenue-percentage prong outright, effective July 1, 2026. It expressly covers Consumer Health Data Controllers regardless of size. And in 2025 it became one of the first states in the country to mandate that businesses honor Global Privacy Control signals sent from consumers' browsers.
The CTDPA uses a controller-processor framework borrowed from the EU's General Data Protection Regulation. Entities that determine the purpose and means of processing personal data are "controllers"; entities that process data on a controller's behalf are "processors." Controllers bear the primary compliance obligations, including privacy notice requirements, data minimization, data protection assessments for high-risk activities, and processor contracts that limit how data can be used downstream.
For the full compliance framework covering controller obligations, processor contracts, and enforcement history, see the Connecticut data privacy laws parent page.
Who the CTDPA covers: applicability thresholds and exemptions
The CTDPA reaches for-profit entities that conduct business in Connecticut or produce products or services targeted to Connecticut residents and meet any of three volume thresholds during the preceding calendar year.
Under Conn. Gen. Stat. § 42-516(a), as amended by Public Act 25-113 effective July 1, 2026, a business is covered if it: (1) controlled or processed the personal data of at least 35,000 consumers (excluding data processed solely to complete a payment transaction and not retained for any other purpose), OR (2) controlled or processed consumers' sensitive data in any amount (same payment-transaction exclusion), OR (3) offered consumers' personal data for sale in trade or commerce, regardless of volume.
This is a significantly lower bar than the CTDPA's original test. Before July 1, 2026, coverage required either 100,000 consumers or 25,000 consumers plus more than 25 percent of gross revenue from data sales. PA 25-113 dropped the consumer-count floor to 35,000 and deleted the revenue-percentage prong entirely, replacing it with two no-floor triggers: any sensitive-data processing, or any sale of personal data at all. The change catches a much wider range of data brokers, lead-generation firms, and ad-tech companies than the prior law did.
One category of business is covered with no volume threshold at all. Consumer Health Data Controllers (those that alone or jointly with others determine the purpose and means of processing Consumer Health Data) are subject to the CTDPA regardless of how many consumers they serve. Consumer Health Data under the CTDPA includes data that controllers use to identify a consumer's physical or mental health condition or diagnosis, including gender-affirming care information and reproductive and sexual health information. A small health-tech startup that processes this type of data for even a handful of Connecticut residents is a covered controller.
The definition of "consumer" is also worth understanding carefully. The CTDPA defines "consumer" as a Connecticut resident acting only in an individual or household capacity. Employees, owners, directors, officers, and contractors are not "consumers" when their interactions with a controller occur solely within the context of their employment or business relationship. This employment exclusion applies to both sides of the relationship: a company's internal HR data about its own staff is not subject to CTDPA consumer rights.
The exemptions in Conn. Gen. Stat. § 42-517(a) and (b), as amended by Public Act 25-113 effective July 1, 2026, are substantial, though several carry significant carve-outs or conditions:
- Nonprofit organizations (but this exemption does NOT apply if the nonprofit qualifies as a Consumer Health Data Controller)
- Institutions of higher education
- Banks, credit unions, and their affiliates, but only if they engage solely in financial activities under (k), are regulated and examined by the Banking Commissioner or a federal bank regulator, and maintain an established compliance program
- Broker-dealers, investment advisers, and their agents regulated by the Banking Commissioner or the Securities and Exchange Commission
- HIPAA-covered entities and their business associates
- Government bodies, tribal nation government organizations, and candidate, party, and political committees
- Insurers, health carriers, fraternal benefit societies, and insurance agents or producers
- Data already regulated by FERPA, the Fair Credit Reporting Act, HIPAA, the Driver's Privacy Protection Act, and other specified federal statutes, including data subject to the Gramm-Leach-Bliley Act
Public Act 25-113 repealed the CTDPA's old blanket entity exemption for financial institutions subject to the Gramm-Leach-Bliley Act. A financial company is no longer automatically exempt from the CTDPA just because it is GLBA-regulated. Only a qualifying bank or credit union that meets the three conditions above, or a regulated broker-dealer or investment adviser, is exempt as an entity. GLBA-regulated data itself remains exempt, but now only as a narrower data-category exemption, not an entity-wide pass.
The nonprofit carve-out from the exemption deserves emphasis. A nonprofit health organization that processes Consumer Health Data cannot claim the general nonprofit exemption and walk away from CTDPA compliance. The Consumer Health Data Controller classification overrides it.
Consumer rights under the CTDPA
Connecticut residents can exercise the following enumerated rights against covered controllers under Conn. Gen. Stat. § 42-518:
- Right to access. A consumer may confirm whether a controller is processing their personal data and request a copy of that data in a format the consumer can use, including any inferences the controller has derived from the data.
- Right to correct. A consumer may require a controller to correct inaccurate personal data, taking into account the nature and purpose of the processing.
- Right to delete. A consumer may request deletion of personal data, including data the controller collected from third-party sources about that consumer, not only data the consumer provided directly.
- Right to portability. A consumer may obtain a copy of their personal data in a portable, readily usable format that allows transfer to another controller or service.
- Right to opt out. A consumer may opt out of processing for three specific purposes: targeted advertising, the sale of personal data, and profiling that produces a legal or similarly significant effect on the consumer.
- Right to challenge automated decisions. Since July 1, 2026, if personal data was processed for profiling that produced a legal or similarly significant effect, a consumer may question the result, be informed of the reason for the decision, and review the data used. If the decision concerned housing, the consumer may also correct the data and have the decision reevaluated.
- Right to a list of data buyers. Since July 1, 2026, a consumer may obtain from a controller a list of the third parties to which the controller sold the consumer's personal data.
Controllers must respond to a rights request within 45 days of receipt. They may extend that period by one additional 45-day window when reasonably necessary, but only if they notify the consumer within the initial 45-day period. The outer limit on response time with a valid extension is therefore 90 days.
Controllers that deny a request must inform the consumer of the denial and provide a way to appeal. After receiving an appeal, the controller has 60 days to respond in writing, explaining what actions it took or declined to take and the reasons. If the appeal is denied, the controller must also provide the consumer with information or a mechanism to contact the Attorney General to file a complaint.
For a detailed breakdown of how Connecticut residents can submit access, correction, deletion, and opt-out requests, see the Connecticut data privacy laws parent page.

Sensitive data and the opt-in consent requirement
One of the CTDPA's most protective features is its affirmative opt-in consent requirement for sensitive personal data. Before a controller may process any category of sensitive data, it must first obtain the consumer's affirmative consent. This is a prior, active agreement, not a default-on setting with an opt-out link that consumers must find and click.
Sensitive data categories under Conn. Gen. Stat. § 42-515 include:
- Personal data revealing racial or ethnic origin, religious beliefs, mental or physical health conditions or diagnoses, sexual orientation, citizenship or immigration status
- Genetic or biometric data processed to uniquely identify an individual
- Precise geolocation data
- Consumer Health Data, including gender-affirming and reproductive health information
- Personal data collected from a known child
- Neural data, financial account numbers with access credentials, government-issued identification numbers, disability or treatment status, and transgender or nonbinary status (added by Public Act 25-113, effective July 1, 2026)
The opt-in standard for sensitive data puts the CTDPA roughly on par with Virginia's VCDPA and meaningfully stricter than California's CCPA and CPRA. California requires businesses to provide a "Limit the Use of My Sensitive Personal Information" link and honor opt-out requests, a model that defaults to processing unless the consumer acts. Connecticut's model defaults to no processing until the consumer actively consents.
For children's and teens' data, the CTDPA layers in additional requirements beyond the general sensitive-data opt-in. Since July 1, 2026, no consent, including a parent's opt-in, can authorize selling a Connecticut consumer's personal data or processing it for targeted advertising if the consumer is under 18. This categorical ban, added by Public Act 25-113, replaced the original PA 22-15 standard, which allowed a parent or guardian to opt in on behalf of a consumer under 16.
Universal opt-out signals: required since January 1, 2025
The CTDPA's universal opt-out mandate stands out as one of its most consumer-forward provisions. Effective January 1, 2025, all businesses covered by the CTDPA must honor opt-out preference signals (OOPS), such as the Global Privacy Control (GPC), transmitted through a consumer's privacy-protective browser or browser extension when those signals can accurately identify a Connecticut resident.
The GPC is an open technical standard supported by browsers including Firefox, Brave, and DuckDuckGo, and by browser extensions. When a Connecticut resident activates GPC in their browser, every covered business must treat the signal as a binding opt-out request for both targeted advertising and the sale of personal data. Controllers cannot require the consumer to create an account or provide additional information before honoring the signal.
The Attorney General's press release on January 29, 2025, stated plainly: "All businesses covered by the CTDPA must respond to a consumer's OOPS." The AG also clarified that controllers cannot override the signal simply because the consumer previously enrolled in a loyalty program or a discount arrangement. If a controller determines that honoring a GPC signal will conflict with an existing loyalty-program benefit, it may notify the consumer of the conflict and ask the consumer to confirm their opt-out choice, but the controller may not treat the loyalty enrollment as a prior waiver that automatically defeats the signal.
This mandate puts Connecticut in a small group of states that have moved beyond passive opt-out mechanisms to require active infrastructure for browser-level signals. Businesses that display opt-out links but have not implemented GPC recognition are not in compliance.
Minors protections: layered through 2024 and 2025 amendments
The CTDPA's protections for minors have been built up in two distinct legislative rounds, each adding meaningful obligations for businesses that serve younger users online.
Public Act 23-56 (effective October 1, 2024). SB 3 was signed in 2023 and took effect October 1, 2024. It represents the first major expansion of the CTDPA's minors-protection layer. Under PA 23-56, a controller that offers any online service, product, or feature to consumers it knows or willfully disregards to be minors must:
- Use reasonable care to avoid any heightened risk of harm to minors from the service
- Conduct data protection assessments for every such service or feature before deployment
- Refrain from using design features intended to sustain or increase a minor's engagement with the platform, unless parental consent has been obtained
- Provide a clearly visible, persistent signal to a minor whenever the controller collects precise geolocation data from them
The "willfully disregards" standard in PA 23-56 is broader than actual knowledge. A controller cannot avoid these obligations simply by claiming it did not know its service attracted minors: if the design or targeting of the service is such that a reasonable operator would know minors are present, the obligations apply.
Public Act 25-113 (signed June 25, 2025; CTDPA amendments effective July 1, 2026). SB 1295 significantly expanded the CTDPA's minors protections and made other sweeping changes to the law, most of which took effect July 1, 2026 and are now in force. The minors-specific additions from PA 25-113 include: a requirement that social media platform owners establish and maintain an online safety center and adopt and enforce a cyberbullying policy; a tightened definition of "heightened risk of harm to minors" to expressly include physical and mental health harms; and a default setting on any online service offered to minors that blocks adults from sending unsolicited direct communications to minors.
PA 23-56 is fully in force as of October 1, 2024. PA 25-113's CTDPA provisions took effect July 1, 2026 and are now in force. For the full scope of PA 25-113's changes, see the section below.

Enforcement: AG-exclusive, CUTPA, cure period sunset, up to $5,000 per wilful violation
The CTDPA is enforced exclusively by the Connecticut Attorney General. Conn. Gen. Stat. § 42-525(e) provides that a violation of the requirements of §§ 42-515 to 42-524 or § 42-526 constitutes an unfair trade practice for purposes of the Connecticut Unfair Trade Practices Act (CUTPA), Conn. Gen. Stat. § 42-110b, and is enforced solely by the Attorney General. There is no private right of action for consumers under the CTDPA: § 42-525(d) states that nothing in the act provides the basis for a private right of action, and § 42-525(e) expressly makes CUTPA's private-action provision, § 42-110g, inapplicable. Individual Connecticut residents cannot bring a lawsuit against a business directly for violating their CTDPA rights.
The CUTPA enforcement mechanism matters for understanding the penalty exposure. CUTPA is Connecticut's general consumer protection statute, and the AG's enforcement toolkit under it is substantial. The $5,000 figure is not flat per-violation exposure, though. Under Conn. Gen. Stat. § 42-110o(b), in an action brought under § 42-110m, the Attorney General may petition for a civil penalty of up to $5,000 for each violation only where the court finds that the person is wilfully using or has wilfully used a practice prohibited by § 42-110b. A violation is wilful when the party knew or should have known that the conduct violated § 42-110b, or when the party broke an assurance of voluntary compliance accepted under § 42-110j. A separate and higher penalty of up to $25,000 per violation applies under § 42-110o(a) to anyone who violates a temporary restraining order or injunction issued under § 42-110d(d) or § 42-110m(a). Beyond penalties, the AG may seek injunctive relief, restitution to affected consumers, and disgorgement of ill-gotten revenues.
The cure period that operated during the law's first 18 months is worth understanding precisely, because it has changed. From July 1, 2023 through December 31, 2024, the CTDPA imposed a mandatory cure requirement: if the AG determined that a violation could be cured, the AG was required to issue a written notice of violation to the controller before commencing any enforcement action. The controller then had 60 days to cure the violation. If the controller cured and delivered a written statement of compliance within that period, no enforcement action could be brought for that specific violation.
That mandatory cure period sunset on December 31, 2024. After that date, the AG has discretion to pursue enforcement directly without first offering a cure opportunity. The AG may choose to issue a warning or cure notice, but is no longer required to do so. This represents a meaningfully tougher enforcement posture: businesses that received warning letters in 2023 and 2024 while the mandatory cure period was in effect should not assume the same procedural protection applies to any future violation.
For a step-by-step guide to what businesses must do to achieve and document compliance, see the Connecticut data privacy laws parent page.
PA 25-113 amendments: current law since July 1, 2026
Governor Lamont signed Public Act 25-113 (SB 1295) on June 25, 2025. The statute's most significant CTDPA amendments took effect July 1, 2026 and are now in force. The changes materially expanded the law's scope.
Lowered applicability threshold. The primary threshold dropped from 100,000 Connecticut consumers to 35,000. In addition, any entity that controls or processes even a single Connecticut resident's sensitive data, or that sells personal data at any volume, is now covered regardless of consumer count. This dramatically expanded the number of businesses subject to the CTDPA. The prior 25,000-consumer/25%-revenue prong was deleted, not replaced with a new percentage.
Under-18 categorical ban replacing the under-16 opt-in. The former rule allowing opt-in consent before selling data or processing it for targeted advertising for consumers under 16 has been replaced with a categorical prohibition. As of July 1, 2026, no consent can authorize those activities for consumers younger than 18. Controllers cannot use a parental opt-in to unlock data sales or targeted advertising for minors in the 16-to-17 age range.
Neural data and expanded sensitive categories. New sensitive data categories added by PA 25-113 include neural data, financial account numbers with access credentials, government-issued identification numbers, disability or treatment status, and transgender or nonbinary status. These now require the same affirmative opt-in consent required for health, biometric, and geolocation data.
LLM training disclosure requirement. Controllers subject to the CTDPA must update their consumer-facing privacy notices to include a clear and conspicuous statement disclosing whether they collect, use, or sell personal data for the purpose of training large language models (LLMs). This obligation applies to all covered controllers regardless of whether they actually engage in LLM training.
Additional consumer rights, including automated-decision review. Consumers now have the right to obtain a list of third parties that purchased their personal data and the right to access inferences a controller has derived from their data. For automated decisions that produce a legal or similarly significant effect, a consumer may also question the result, be informed of the reason for the decision, and review the data used, and, if the decision concerned housing, correct the data and have the decision reevaluated. Profiling impact assessments are required for certain processing activities created on or after August 1, 2026.
All of these provisions took effect July 1, 2026 and are in force today. Businesses subject to the CTDPA should already be in compliance with these amendments.
CTDPA vs. CCPA: key differences at a glance
The CTDPA and California's CCPA are frequently compared because both give consumers similar core rights (access, correction, deletion, portability, and opt-out) and both use an opt-in model for sensitive data. But three CTDPA features are structurally distinctive.
No revenue-percentage threshold. Since July 1, 2026, the CTDPA no longer uses a revenue-percentage trigger at all. Any business that sells Connecticut residents' personal data in trade or commerce is covered regardless of sales volume or revenue share, a materially lower bar than Virginia's VCDPA, which still requires more than 50 percent of gross revenue from data sales before its lower 25,000-consumer threshold applies. A data analytics company that sells even a small amount of Connecticut consumers' personal data is covered under the CTDPA; the same company might not be covered under the VCDPA unless it also clears Virginia's 50 percent revenue bar.
Universal opt-out signal mandate. As of January 1, 2025, the CTDPA requires businesses to honor browser-level opt-out preference signals like the GPC. California also imposes a similar requirement under CPRA, and the two states are among the most aggressive in the country on this front. Many other state privacy laws do not include a comparable mandate, meaning businesses operating in Connecticut must build technical infrastructure for signal recognition rather than relying solely on a website opt-out link.
CUTPA enforcement vehicle. The CTDPA does not set its own penalty dollar figure or create its own enforcement statute. Instead, every CTDPA violation becomes a CUTPA violation, giving the AG access to CUTPA's full toolkit including disgorgement and restitution in addition to per-violation civil penalties. This structure means the AG can pursue CTDPA violations using CUTPA's established procedural framework and can seek remedies that go beyond what a standalone privacy penalty statute might offer. The $5,000 per-violation figure comes from CUTPA's penalty provision, § 42-110o(b), and reaches only wilful violations; it is not a number written into the CTDPA itself, and it is not CUTPA's ceiling, because § 42-110o(a) sets a penalty of up to $25,000 per violation of a court order.
For a broader cross-state comparison that includes Virginia, Colorado, Texas, and other state frameworks, see the state privacy law comparison page and the California's CCPA explainer.
Related guides
- CTDPA Consumer Rights: Exercise Your Connecticut Privacy Rights
- CTDPA Compliance Checklist for Businesses (2026)
- Connecticut Data Privacy Laws: CTDPA Consumer Rights Guide (2026)
- Connecticut Biometric Privacy Laws: Collection, Consent & Penalties (2026)
- US State Privacy Laws Comparison Chart (2026)
More Connecticut Laws
Frequently Asked Questions
What is the CTDPA?
The CTDPA, or Connecticut Data Privacy Act, is Connecticut's comprehensive consumer data privacy law codified at Conn. Gen. Stat. §§ 42-515 through 42-526 (Chapter 743jj). Governor Ned Lamont signed it as Public Act 22-15 on May 10, 2022, and it took effect July 1, 2023. It gives Connecticut residents rights over their personal data, requires covered businesses to be transparent about collection and use, mandates opt-in consent for sensitive data, and requires businesses to honor browser-based opt-out signals.
Who does the CTDPA apply to?
As of July 1, 2026, for-profit businesses that process personal data of 35,000 or more Connecticut consumers per year, OR control or process any amount of consumers' sensitive data, OR sell consumers' personal data in trade or commerce at any volume. Consumer Health Data Controllers are covered regardless of size. Nonprofits are generally exempt, but the nonprofit exemption does not apply to organizations that qualify as Consumer Health Data Controllers. HIPAA-covered entities, government bodies, and institutions of higher education are also exempt, along with a narrow group of banks, credit unions, broker-dealers, and investment advisers that meet specific statutory conditions. A blanket exemption for GLBA-regulated financial institutions was repealed effective July 1, 2026; most financial institutions are no longer automatically exempt as entities, though GLBA-regulated data itself remains separately exempt.
What rights do Connecticut consumers have under the CTDPA?
As of July 1, 2026: the right to access data (including inferences derived from it) and confirm whether it is being processed, the right to correct inaccurate data, the right to delete personal data (including data collected from third parties), the right to a portable copy, the right to opt out of targeted advertising, data sales, and profiling with significant effects, the right to a list of third parties data was sold to, and, for automated decisions with legal or similarly significant effects, the right to question the result, learn the reason, review the data used, and, for housing decisions, correct the data and have it reevaluated. Controllers have 45 days to respond, with one possible 45-day extension with advance notice. Since July 1, 2026, no consent can authorize data sales or targeted advertising for consumers under 18.
What is the universal opt-out requirement under the CTDPA?
Since January 1, 2025, all businesses covered by the CTDPA must honor opt-out preference signals (OOPS) such as the Global Privacy Control sent through a consumer's browser. The signal acts as a binding opt-out request for targeted advertising and data sales. Controllers cannot require account creation or additional steps to process the signal, and a prior loyalty or discount enrollment does not override it.
What is the penalty for violating the CTDPA?
CTDPA violations are CUTPA violations under Conn. Gen. Stat. § 42-525(e). Under CUTPA's penalty provision, § 42-110o(b), the Attorney General may petition for civil penalties of up to $5,000 for each wilful violation, meaning the violator knew or should have known the conduct was unlawful; violating a court injunction carries up to $25,000 per violation under § 42-110o(a). The AG may also seek injunctive relief, restitution, and disgorgement. After December 31, 2024, the AG is no longer required to offer a 60-day cure period before filing an enforcement action; cure is now at the AG's discretion.
Does the CTDPA have a private right of action?
No. Enforcement is exclusive to the Connecticut Attorney General. Individual consumers cannot sue businesses directly for CTDPA violations. If the AG denies a consumer's appeal of a rights request denial, the controller must provide information on how to file a complaint with the AG.
What is the cure period under the CTDPA?
From July 1, 2023 through December 31, 2024, the AG was required to give controllers a 60-day written cure notice before bringing an enforcement action. After December 31, 2024, that mandatory cure period expired. The AG now has discretion to pursue enforcement directly without first offering a cure opportunity.
What counts as sensitive data under the CTDPA?
Sensitive data includes: health conditions or diagnoses, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify a person, precise geolocation data, Consumer Health Data (including gender-affirming and reproductive health information), and personal data collected from a known child. Controllers must obtain affirmative opt-in consent before processing any of these categories.
How does the CTDPA protect minors?
In layers. The original law required opt-in consent for data sales and targeted advertising involving consumers under 16. Public Act 23-56 (effective October 1, 2024) added reasonable-care obligations, required data protection assessments for services offered to known minors, prohibited addictive design features without parental consent, and required visible geolocation signals when tracking minors. Public Act 25-113 (signed June 25, 2025; effective July 1, 2026) added social media safety centers, cyberbullying policies, and default blocks on unsolicited messages from adults to minors, and replaced the under-16 opt-in standard with a categorical under-18 ban on data sales and targeted advertising.
How is the CTDPA different from Virginia's VCDPA?
Two main differences stand out. First, since July 1, 2026 the CTDPA no longer has a revenue-percentage threshold at all: any business that sells Connecticut residents' personal data at any volume is covered, a lower bar than Virginia's VCDPA, which still requires more than 50% of gross revenue from data sales. Second, the CTDPA mandates universal opt-out signal compliance (GPC) as of January 1, 2025, a requirement the VCDPA does not include. Both laws use an AG-exclusive enforcement model and require opt-in consent for sensitive data.
Updates
Corrected the enforcement section: the provision making a CTDPA violation an unfair trade practice is Conn. Gen. Stat. Sec. 42-525(e), not Sec. 42-524, and CUTPA's $5,000 civil penalty applies per wilful violation under Sec. 42-110o(b) rather than as a flat per-violation cap.
Corrected this page's exemption list and matching FAQ answer, which cited the wrong statute section and described a blanket financial-institution exemption that Public Act 25-113 repealed, replacing it with a narrow bank/credit-union rule.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Connecticut General Statutes, Title 42 (Business, Selling, Trading and Collection Practices), Chapter 743jj
§ 42-518Consumers' rights. Compliance by Controllers. Appeals.In forcecited in 3 of our articles
(a) A consumer shall have the right to: (1) Confirm whether or not a controller is processing the consumer's personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by, or obtained about, the consumer; (4) obtain a copy of the consumer's personal data processed by the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means, provided such controller shall not be required to reveal any trade secret; and (5) opt out of the processing of the personal data for purposes of (A) targeted advertising, (B) the sale of personal data, except as provided in subsection (b) of section 42-520, or (C) profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at cga.ct.gov
Also relied on in: CTDPA Consumer Rights: Exercise Your Connecticut Privacy Rights, Connecticut Data Privacy Laws: CTDPA Consumer Rights Guide (2026)
§ 42-515Definitions.In forcecited in 2 of our articles
As used in this section and sections 42-516 to 42-526, inclusive, unless the context otherwise requires: (1) “Abortion” means terminating a pregnancy for any purpose other than producing a live birth. (2) “Affiliate” means a legal entity that shares common branding with another legal entity or controls, is controlled by or is under common control with another legal entity. For the purposes of this subdivision, “control” and “controlled” mean (A) ownership of, or the power to vote, more than fifty per cent of the outstanding shares of any class of voting security of a company, (B) control in any manner over the election of a majority of the directors or of individuals exercising similar functions, or (C) the power to exercise controlling influence over the management of a company. (3) “Authenticate” means to use reasonable means to determine that a request to exercise any of the rights afforded under subdivisions (1) to (4), inclusive, of subsection (a) of section 42-518 is being made by, or on behalf of, the consumer who is entitled to exercise such consumer rights with respect to the personal data at issue.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at cga.ct.gov
Also relied on in: Connecticut Requires Facial-Recognition Signs (PA 26-64)
United States Code Title 12
§ 1843Interests in nonbanking organizationsIn force
Except as otherwise provided in this chapter, no bank holding company shall— after May 9, 1956, acquire direct or indirect ownership or control of any voting shares of any company which is not a bank, or after two years from the date as of which it becomes a bank holding company, or in the case of a company which has been continuously affiliated since May 15, 1955, with a company which was registered under the Investment Company Act of 1940 [15 U.S.C. 80a–1 et seq.], prior to May 15, 1955, in such a manner as to constitute an affiliated company within the meaning of that Act, after December 31, 1978, or, in the case of any company which becomes, as a result of the enactment of the Bank Holding Company Act Amendments of 1970, a bank holding company on December 31, 1970, after December 31, 1980, retain direct or indirect ownership or control of any voting shares of any company which is not a bank or bank holding company or engage in any activities other than (A) those of banking or of managing or controlling banks and other subsidiaries authorized under this chapter or of furnishing services to or performing services for its subsidiaries, and (B) those permitted under paragraph (8)…
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 159 court opinionsMost recently applied by a court: 2026
Leading cases:
- Investment Company Institute v. Board of Governors of the Federal Reserve System (Court of Appeals for the D.C. Circuit 1977, 551 F.2d 1270)“…c)(8) of the Bank Holding Company Act of 1956, as amended, 12 U.S.C. § 1843 (c)(8) (1970). Appellant claims that t…”
- Board of Governors of Federal Reserve System v. Investment Co. Institute (Supreme Court of the United States 1981, 450 U.S. 46)“…the acquisition, in whole or in part, of a going concern.” 12 U. S. C. § 1843 (c)(8). 3 See 36…”
- National Courier Ass'n v. Board of Governors of the Federal Reserve System (Court of Appeals for the D.C. Circuit 1975, 516 F.2d 1229)“…or controlling banks as to be a proper incident thereto.” 12 U.S.C. § 1843 (c)(8) (1970). In the regulation herein…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Public Act 22-15 (2022 Reg. Sess. SB 6): Original CTDPA enactment(cga.ct.gov)
- Public Act 23-56 (2023 Reg. Sess. SB 3): Minors and Consumer Health Data amendments(cga.ct.gov)
- Public Act 25-113 (2025 Reg. Sess. SB 1295): Social media safety and expanded minors protections(cga.ct.gov)
- CT Attorney General: The Connecticut Data Privacy Act (official AG page)(portal.ct.gov)
- CT AG Press Release: AG Tong Advises Connecticut Consumers of Upcoming Rights Under the CTDPA (June 2023)(portal.ct.gov)
- CT AG Press Release: Tong Advises Consumers and Businesses of Opt-Out Rights and Requirements (Jan. 29, 2025)(portal.ct.gov)
- CT AG Press Release: Data Privacy Day 2025 (Jan. 28, 2025)(portal.ct.gov)
- CT AG: Report on Connecticut Data Privacy Act (2024 enforcement report)(portal.ct.gov)
- CT AG: Updated Report on Connecticut Data Privacy Act (2026)(portal.ct.gov)
- Chapter 743jj: Data Privacy and Security (2024 supplement, post-PA 23-56)(cga.ct.gov)
- Conn. Gen. Stat. Sec. 42-525: Enforcement by Attorney General; subsection (e) makes a CTDPA violation an unfair trade practice under Sec. 42-110b(cga.ct.gov)
- Conn. Gen. Stat. Sec. 42-110o: CUTPA civil penalties (up to $5,000 per wilful violation under subsection (b); up to $25,000 per violation of a court order under subsection (a))(cga.ct.gov)