EnglishEspañol
Connecticut flag

Connecticut

What Is the CTDPA? Connecticut Data Privacy Act Explained

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. How we verify our legal content

What Is the CTDPA? Connecticut Data Privacy Act Explained

Frequently Asked Questions

What is the CTDPA?

The CTDPA, or Connecticut Data Privacy Act, is Connecticut's comprehensive consumer data privacy law codified at Conn. Gen. Stat. §§ 42-515 through 42-526 (Chapter 743jj). Governor Ned Lamont signed it as Public Act 22-15 on May 10, 2022, and it took effect July 1, 2023. It gives Connecticut residents rights over their personal data, requires covered businesses to be transparent about collection and use, mandates opt-in consent for sensitive data, and requires businesses to honor browser-based opt-out signals.

Who does the CTDPA apply to?

As of July 1, 2026, for-profit businesses that process personal data of 35,000 or more Connecticut consumers per year, OR control or process any amount of consumers' sensitive data, OR sell consumers' personal data in trade or commerce at any volume. Consumer Health Data Controllers are covered regardless of size. Nonprofits are generally exempt, but the nonprofit exemption does not apply to organizations that qualify as Consumer Health Data Controllers. HIPAA-covered entities, government bodies, and institutions of higher education are also exempt, along with a narrow group of banks, credit unions, broker-dealers, and investment advisers that meet specific statutory conditions. A blanket exemption for GLBA-regulated financial institutions was repealed effective July 1, 2026; most financial institutions are no longer automatically exempt as entities, though GLBA-regulated data itself remains separately exempt.

What rights do Connecticut consumers have under the CTDPA?

As of July 1, 2026: the right to access data (including inferences derived from it) and confirm whether it is being processed, the right to correct inaccurate data, the right to delete personal data (including data collected from third parties), the right to a portable copy, the right to opt out of targeted advertising, data sales, and profiling with significant effects, the right to a list of third parties data was sold to, and, for automated decisions with legal or similarly significant effects, the right to question the result, learn the reason, review the data used, and, for housing decisions, correct the data and have it reevaluated. Controllers have 45 days to respond, with one possible 45-day extension with advance notice. Since July 1, 2026, no consent can authorize data sales or targeted advertising for consumers under 18.

What is the universal opt-out requirement under the CTDPA?

Since January 1, 2025, all businesses covered by the CTDPA must honor opt-out preference signals (OOPS) such as the Global Privacy Control sent through a consumer's browser. The signal acts as a binding opt-out request for targeted advertising and data sales. Controllers cannot require account creation or additional steps to process the signal, and a prior loyalty or discount enrollment does not override it.

What is the penalty for violating the CTDPA?

CTDPA violations are CUTPA violations under Conn. Gen. Stat. § 42-525(e). Under CUTPA's penalty provision, § 42-110o(b), the Attorney General may petition for civil penalties of up to $5,000 for each wilful violation, meaning the violator knew or should have known the conduct was unlawful; violating a court injunction carries up to $25,000 per violation under § 42-110o(a). The AG may also seek injunctive relief, restitution, and disgorgement. After December 31, 2024, the AG is no longer required to offer a 60-day cure period before filing an enforcement action; cure is now at the AG's discretion.

Does the CTDPA have a private right of action?

No. Enforcement is exclusive to the Connecticut Attorney General. Individual consumers cannot sue businesses directly for CTDPA violations. If the AG denies a consumer's appeal of a rights request denial, the controller must provide information on how to file a complaint with the AG.

What is the cure period under the CTDPA?

From July 1, 2023 through December 31, 2024, the AG was required to give controllers a 60-day written cure notice before bringing an enforcement action. After December 31, 2024, that mandatory cure period expired. The AG now has discretion to pursue enforcement directly without first offering a cure opportunity.

What counts as sensitive data under the CTDPA?

Sensitive data includes: health conditions or diagnoses, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify a person, precise geolocation data, Consumer Health Data (including gender-affirming and reproductive health information), and personal data collected from a known child. Controllers must obtain affirmative opt-in consent before processing any of these categories.

How does the CTDPA protect minors?

In layers. The original law required opt-in consent for data sales and targeted advertising involving consumers under 16. Public Act 23-56 (effective October 1, 2024) added reasonable-care obligations, required data protection assessments for services offered to known minors, prohibited addictive design features without parental consent, and required visible geolocation signals when tracking minors. Public Act 25-113 (signed June 25, 2025; effective July 1, 2026) added social media safety centers, cyberbullying policies, and default blocks on unsolicited messages from adults to minors, and replaced the under-16 opt-in standard with a categorical under-18 ban on data sales and targeted advertising.

How is the CTDPA different from Virginia's VCDPA?

Two main differences stand out. First, since July 1, 2026 the CTDPA no longer has a revenue-percentage threshold at all: any business that sells Connecticut residents' personal data at any volume is covered, a lower bar than Virginia's VCDPA, which still requires more than 50% of gross revenue from data sales. Second, the CTDPA mandates universal opt-out signal compliance (GPC) as of January 1, 2025, a requirement the VCDPA does not include. Both laws use an AG-exclusive enforcement model and require opt-in consent for sensitive data.

Updates

Corrected the enforcement section: the provision making a CTDPA violation an unfair trade practice is Conn. Gen. Stat. Sec. 42-525(e), not Sec. 42-524, and CUTPA's $5,000 civil penalty applies per wilful violation under Sec. 42-110o(b) rather than as a flat per-violation cap.

Corrected this page's exemption list and matching FAQ answer, which cited the wrong statute section and described a blanket financial-institution exemption that Public Act 25-113 repealed, replacing it with a narrow bank/credit-union rule.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Public Act 22-15 (2022 Reg. Sess. SB 6): Original CTDPA enactment(cga.ct.gov)
  2. Public Act 23-56 (2023 Reg. Sess. SB 3): Minors and Consumer Health Data amendments(cga.ct.gov)
  3. Public Act 25-113 (2025 Reg. Sess. SB 1295): Social media safety and expanded minors protections(cga.ct.gov)
  4. CT Attorney General: The Connecticut Data Privacy Act (official AG page)(portal.ct.gov)
  5. CT AG Press Release: AG Tong Advises Connecticut Consumers of Upcoming Rights Under the CTDPA (June 2023)(portal.ct.gov)
  6. CT AG Press Release: Tong Advises Consumers and Businesses of Opt-Out Rights and Requirements (Jan. 29, 2025)(portal.ct.gov)
  7. CT AG Press Release: Data Privacy Day 2025 (Jan. 28, 2025)(portal.ct.gov)
  8. CT AG: Report on Connecticut Data Privacy Act (2024 enforcement report)(portal.ct.gov)
  9. CT AG: Updated Report on Connecticut Data Privacy Act (2026)(portal.ct.gov)
  10. Chapter 743jj: Data Privacy and Security (2024 supplement, post-PA 23-56)(cga.ct.gov)
  11. Conn. Gen. Stat. Sec. 42-525: Enforcement by Attorney General; subsection (e) makes a CTDPA violation an unfair trade practice under Sec. 42-110b(cga.ct.gov)
  12. Conn. Gen. Stat. Sec. 42-110o: CUTPA civil penalties (up to $5,000 per wilful violation under subsection (b); up to $25,000 per violation of a court order under subsection (a))(cga.ct.gov)
Share: