Last updated
Who this affects: This page tracks Connecticut’s CTDPA, which governs controllers, processors, and third parties.
Who it applies to: Persons that do business in Connecticut or target its residents, and meet: 35,000+ consumers, or other thresholds (see below); some provisions apply under a separate test (see below).
Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.The law, in plain English
CTDPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.
These are the highlights we judge most important, not everything CTDPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.
The comprehensive law
CTDPA (PA 22-15) is Connecticut’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.
Corroborated by Legislative record
Corroborated by Privacy-law tracker Regulator guidance
What the law gives consumers
Who the law governs
Exemptions
Published Sep 30, 2026 from the DataGrail regulation engine; each fact links to its primary source.
Timeline
This state currently has one dated milestone on the books.
Source: primary citation
Enforcement so far
Real regulatory actions and settlements under the Connecticut privacy laws we track. Every entry is a DataGrail summary linking to the primary source.
DataGrail’s wording, not statutory text. The figures are computed from the linked sources.
Published Sep 30, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.