Connecticut CTDPA
Connecticut CTDPA
Connecticut Data Privacy Act
The CTDPA gives residents the right to access, correct, delete, and port their personal data, and to opt out of its sale and use for targeted advertising and profiling. It mandates recognition of universal opt-out signals, and non-compliance can bring enforcement and reputational damage. Security teams need to verify that every script, tracker, and cookie respects user preferences, especially opt-out and consent signals for sensitive data.
How Reflectiz Meets Every CTDPA Requirement
Requirement → Reflectiz SolutionUniversal Opt-Out Recognition
Reflectiz confirms that every script, tracker, and cookie respects universal opt-out signals, and alerts teams to components that ignore them or continue after rejection.
Sensitive Data Consent
User-journey simulation reveals which components collect sensitive data and whether consent preceded collection.
Third-Party Vendor Oversight
Continuous discovery of all third- and fourth-party vendors and a clear map of the personal data each one touches.
Audit & Reporting
Audit-ready reporting and behavioral logs give compliance teams defensible evidence of how consumer data is handled.
Reduces Regulatory Risk & Saves Time
Connecticut CTDPA at a Glance
Key Facts| Full name | Connecticut Data Privacy Act, Conn. Gen. Stat. § 42-515 et seq. Signed May 10, 2022, and in effect since July 1, 2023. Official guidance: Connecticut Attorney General. |
|---|---|
| Who it applies to | Since July 1, 2026, businesses that operate in Connecticut or target its residents and process personal data of at least 35,000 consumers, process any sensitive data, or sell personal data. Consumer health data controllers are covered at any size. |
| Financial institutions | The blanket exemption for entities regulated under the Gramm-Leach-Bliley Act ended July 1, 2026. Data covered by that law, and certain specified financial entities, remain exempt. |
| Consumer rights | Access personal data and inferences, correct, delete, and get a portable copy. Opt out of targeted advertising, sale, and profiling behind significant automated decisions. Since July 1, 2026, consumers can also get a list of the third parties that bought their data. |
| Universal opt-out | Required since January 1, 2025. Businesses must treat signals such as Global Privacy Control as a valid opt-out of targeted advertising and sale. |
| Sensitive data | Consent comes first, and selling sensitive data without consent is prohibited. Covers racial or ethnic origin, religious beliefs, mental or physical health or disability, sex life, sexual orientation, nonbinary or transgender status, citizenship or immigration status, consumer health data, genetic, biometric, and neural data, financial account and government ID numbers, crime victim status, a known child’s data, and precise geolocation. |
| Precise geolocation | Sensitive data today. Starting October 1, 2026, selling it is banned, with narrow exceptions (SB 4, Public Act 26-64). |
| Minors | Since July 1, 2026, no targeted advertising or sale of a minor’s data (under 18), even with consent, when the business knows or willfully disregards the user’s age. Design features built to extend a minor’s use are banned too. |
| Privacy notice | Must disclose targeted advertising, profiling, and whether personal data is used to train large language models, reachable from a homepage link that includes the word “privacy.” |
| Response deadlines | 45 days to answer a consumer request, with one 45-day extension. Appeals get a written answer within 60 days. One request per 12 months is free. |
| Enforcement | The Connecticut Attorney General only, with no private right of action. The mandatory 60-day cure period ended December 31, 2024, and a chance to cure is now at the Attorney General’s discretion. |
| Penalties | Up to $5,000 per willful violation under the Connecticut Unfair Trade Practices Act, plus injunctions and restitution. The first CTDPA settlement, with TicketNetwork in July 2025, cost $85,000. |
Connecticut CTDPA FAQ
Common QuestionsWhat is the Connecticut Data Privacy Act (CTDPA)?
The Connecticut Data Privacy Act (CTDPA) is Connecticut’s comprehensive consumer privacy law, codified at Conn. Gen. Stat. § 42-515 et seq. Signed on May 10, 2022, and in effect since July 1, 2023, it gives Connecticut residents rights over their personal data, requires consent for sensitive data, and requires businesses to honor universal opt-out signals such as Global Privacy Control.
Who must comply with the CTDPA after the 2026 changes?
Since July 1, 2026, the CTDPA covers businesses that operate in Connecticut or target its residents and process personal data of at least 35,000 consumers, process any sensitive data, or sell personal data. The old 100,000-consumer threshold is gone, and consumer health data controllers are covered regardless of size.
Does the CTDPA require honoring Global Privacy Control?
Yes. Since January 1, 2025, businesses must honor opt-out preference signals such as Global Privacy Control as a valid request to opt out of targeted advertising and sale. In September 2025, Connecticut joined California and Colorado in a joint sweep of businesses that ignore the signal.
What counts as sensitive data under the CTDPA?
Sensitive data includes racial or ethnic origin, religious beliefs, mental or physical health or disability, sex life, sexual orientation, nonbinary or transgender status, citizenship or immigration status, consumer health data, genetic, biometric, and neural data, financial account and government ID numbers, crime victim status, a known child’s data, and precise geolocation. Businesses need consent before processing or selling it.
What are the penalties for violating the CTDPA?
The Connecticut Attorney General enforces the law exclusively, with civil penalties of up to $5,000 per willful violation under the Connecticut Unfair Trade Practices Act, plus injunctions and restitution. There is no private right of action. The mandatory 60-day cure period ended on December 31, 2024. In July 2025, TicketNetwork paid $85,000 in the first CTDPA settlement, over a deficient privacy notice.
What changed in the CTDPA in 2025 and 2026?
SB 1295, effective July 1, 2026, lowered the threshold to 35,000 consumers, expanded sensitive data, banned targeted advertising and sale of minors’ data, and added a disclosure on training large language models. SB 4 (Public Act 26-64), effective October 1, 2026, bans selling precise geolocation data and creates a data broker registry starting January 1, 2027.
How does Reflectiz support CTDPA compliance?
Reflectiz monitors your website remotely, with no code changes, and confirms whether every script, tracker, and cookie respects Global Privacy Control and other opt-out signals. It simulates user journeys to catch sensitive data collected before consent, maps every third- and fourth-party vendor that touches personal data, and keeps audit-ready logs for regulators. Your privacy notice states the policy. Reflectiz shows what your site actually does.
Last reviewed September 2026. This page summarizes the Connecticut Data Privacy Act for general information and is not legal advice. Related: CCPA, Texas TDPSA, Colorado CPA, Virginia VCDPA, Illinois BIPA, and the Reflectiz Privacy Hub.
Ready for CTDPA? Know Your Web Exposure.
See every script, tag, and tracker on your site, and whether it honors opt-out signals and consent, in one continuous, agentless view.