close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Connecticut Privacy Law

CT

Connecticut (CTDPA)

Last updated

CTDPA Enacted, in effect

Who this affects: This page tracks Connecticut’s CTDPA, which governs controllers, processors, and third parties.

Who it applies to: Persons that do business in Connecticut or target its residents, and meet: 35,000+ consumers, or other thresholds (see below); some provisions apply under a separate test (see below).

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
July 1, 2023
Effective ↗
Attorney General
Enforced by ↗
$5,000
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

CTDPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Respond to rights requests within forty-five days, and if you decline to act, explain why and how to appeal. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CT-42-518 “A controller shall respond to the consumer without undue delay, but not later than forty-five days after receipt of the request” Read the statute CT-42-518 “the controller shall inform the consumer without undue delay, but not later than forty-five days after receipt of the request, of the justification for declining to take action and instructions for how to appeal the decision” Read the statute
  • Honor opt-out preference signals, such as GPC, and post a clear website link to opt out of targeted ads and sales. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CT-42-520 “Allowing a consumer to opt out of any processing of the consumer's personal data for the purposes of targeted advertising, or any sale of such personal data, through an opt-out preference signal sent, with such consumer's consent, by a platform, technology or mechanism to the controller indicating such consumer's intent to opt out of any such processing or sale.” Read the statute CT-42-520 “the controller shall comply with such consumer's opt-out preference signal but may notify such consumer of such conflict and provide to such consumer the choice to confirm such controller-specific privacy setting or participation in such program” Read the statute CT-42-520 “Providing a clear and conspicuous hyperlink on the controller's Internet web site to an Internet web page that enables the consumer, or an agent of the consumer, to opt out of the processing of the consumer's personal data for purposes of targeted advertising, or any sale of the consumer's personal data” Read the statute
  • Offer appeals, answer each in writing within sixty days, and if denied, show how to complain to the Attorney General. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CT-42-518 “A controller shall establish a process for a consumer to appeal the controller's refusal to take action on a request within a reasonable period of time after the consumer's receipt of the decision” Read the statute CT-42-518 “Not later than sixty days after receipt of an appeal, a controller shall inform the consumer in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions” Read the statute CT-42-518 “If the appeal is denied, the controller shall also provide the consumer with an online mechanism, if available, or other method through which the consumer may contact the Attorney General to submit a complaint.” Read the statute

Can't

  • Process sensitive data unless reasonably necessary and with consent (per COPPA for a child), or sell it without consent. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CT-42-520 “not process sensitive data concerning a consumer unless such processing is reasonably necessary in relation to the purposes for which such sensitive data are processed and without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a consumer who the controller has actual knowledge, or wilfully disregards, is a child, without processing such data in accordance with COPPA” Read the statute CT-42-520 “not sell the sensitive data of a consumer without the consumer's consent” Read the statute
  • Process for targeted ads, or sell, data of anyone you know or wilfully disregard is at least thirteen but younger than eighteen. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CT-42-520 “not process the personal data of a consumer for purposes of targeted advertising, or sell the consumer's personal data, under circumstances where a controller has actual knowledge, or wilfully disregards, that the consumer is at least thirteen years of age but younger than eighteen years of age” Read the statute
  • Discriminate against anyone for exercising rights (bona fide loyalty programs aside) or require a new account to exercise them. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CT-42-520 “A controller shall not discriminate against a consumer for exercising any of the consumer rights contained in sections 42-515 to 42-525, inclusive, including denying goods or services, charging different prices or rates for goods or services or providing a different level of quality of goods or services to the consumer. (2) Nothing in subdivision (1) of this subsection shall be construed to require a controller to provide a product or service that requires the personal data of a consumer which the controller does not collect or maintain, or prohibit a controller from offering a different price, rate, level, quality or selection of goods or services to a consumer, including offering goods or services for no fee, if the offering is in connection with a consumer's voluntary participation in a bona fide loyalty, rewards, premium features, discounts or club card program” Read the statute CT-42-520 “A controller shall not require a consumer to create a new account in order to exercise consumer rights, but may require a consumer to use an existing account” Read the statute

Should

  • Give each processor a binding contract with instructions, purpose, duration, data type, and both parties' rights and obligations. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CT-42-521 “A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller. The contract shall be binding and clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing and the rights and obligations of both parties.” Read the statute
  • Run assessments for heightened-risk processing and significant-decision profiling; keep them ready for the Attorney General. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CT-42-522 “A controller shall conduct and document a data protection assessment for each of the controller's processing activities that presents a heightened risk of harm to a consumer” Read the statute CT-42-522 “Each controller that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer shall conduct an impact assessment for such profiling” Read the statute CT-42-522 “the controller shall make the data protection assessment or impact assessment available to the Attorney General” Read the statute
  • Add to your privacy notice whether you collect, use or sell data to train large language models, plus month and year updated. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CT-42-520 “a statement disclosing whether the controller collects, uses or sells personal data for the purpose of training large language models” Read the statute CT-42-520 “the most recent month and year during which the controller updated such privacy notice” Read the statute

These are the highlights we judge most important, not everything CTDPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Connecticut Data Privacy Act

CTDPA (PA 22-15) is Connecticut’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read …liate of the processor or the controller. (42) “Trade secret” has the same meaning as provided in section 35-51.” (P.A. 22-15, S. 1; P.A. 23-56, S. 1; 23-110, S. 1; 23-204, S. 207; P.A. 25-168, S. 286; 25-113, S. 5.) History: P.A. 22-15 effective July 1, 2023; P.A. 23-56 added reference to Sec. 42-526 in introductory language, added new Subdiv. (1) defining “abortion”, redesignated existing Subdivs. (1) to (7) as Subdivs. (2) to (8), added new Subdivs. (9) and (10) defining … Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
Effective
July 1, 2023
Archived excerpt — the text we read …liate of the processor or the controller. (42) “Trade secret” has the same meaning as provided in section 35-51.” (P.A. 22-15, S. 1; P.A. 23-56, S. 1; 23-110, S. 1; 23-204, S. 207; P.A. 25-168, S. 286; 25-113, S. 5.) History: P.A. 22-15 effective July 1, 2023; P.A. 23-56 added reference to Sec. 42-526 in introductory language, added new Subdiv. (1) defining “abortion”, redesignated existing Subdivs. (1) to (7) as Subdivs. (2) to (8), added new Subdivs. (9) and (10) defining … Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
Signed
May 10, 2022
Archived excerpt — the text we read …matters relating to general law, in accordance with the provisions of section 11-4a of the general statutes. The task force shall terminate on the date that it submits such report or January 1, 2023, whichever is later. Approved May 10, 2022 27 of 27 Archived from source — captured 2026-08-14 · snapshot 8d7c185b Verify at the source

Corroborated by Legislative record

Enforced by
Attorney General
Archived excerpt — the text we read Sec. 42-525. Enforcement by Attorney General. Notice of violation. Cure period. Report. Penalty. (a) The Attorney General shall have exclusive authority to enforce violations of sections 42-515 to 42-524, inclusive, and section 42-526. (b) (1) During the period beginning on July 1, 2023, and ending on December 31, 2024, the Attorney General shall, prior to initiating any action for a violation of any provision of sections 42-515 to 42-524, inclusive,… Archived from source — captured 2026-07-20 · snapshot ff6266b5 Verify at the source
Maximum penalty per violation
$5,000
Per wilful violation, under the Unfair Trade Practices Act (42-110o); enforced only by the AG. Source for each figure$5,000 · CT-42-110o $25,000 · CT-42-110o “the Attorney General, upon petition to the court, may recover, on behalf of the state, a civil penalty of not more than five thousand dollars for each violation” View the statute
Right to cure
Mandatory cure lapsed Dec 31, 2024; now discretionary
The mandatory cure ended Dec 31, 2024; since then the AG may grant a cure at its discretion. Archived excerpt — the text we read …issued; (B) the nature of each violation; (C) the number of violations that were cured during the sixty-day cure period; and (D) any other matter the Attorney General deems relevant for the purposes of such report. (c) Beginning on January 1, 2025, the Attorney General may, in determining whether to grant a controller, processor or consumer health data controller the opportunity to cure an alleged violation described in subsection (b) of this section, consider: (1) The number of violations; (2) the size and complexity of the controller, processor or consumer health data controller; (3) the nature and extent of the controller's, processor's or consumer health data co… Archived from source — captured 2026-07-20 · snapshot ff6266b5 Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read … (4) the substantial likelihood of injury to the public; (5) the safety of persons or property; (6) whether such alleged violation was likely caused by human or technical error; and (7) the sensitivity of the data. (d) Nothing in sections 42-515 to 42-524, inclusive, or section 42-526, shall be construed as providing the basis for, or be subject to, a private right of action for violations of said sections or any other law. (e) A violation of the requirements of sections 42-515 to 42-524, inclusive, or section 42-526, shall constitute an unfair trade practice for purposes of section 42-110b and shall be enforced solely by the Attorney Gen… Archived from source — captured 2026-07-20 · snapshot ff6266b5 Verify at the source

Corroborated by Privacy-law tracker Regulator guidance

Universal opt-out signal
Required
Archived excerpt — the text we read … web page that enables the consumer, or an agent of the consumer, to opt out of the processing of the consumer's personal data for purposes of targeted advertising, or any sale of the consumer's personal data; and (ii) Allowing a consumer to opt out of any processing of the consumer's personal data for the purposes of targeted advertising, or any sale of such personal data, through an opt-out preference signal sent, with such consumer's consent, by a platform, technology or mechanism to the controller indicating such consumer's intent to opt out of any such processing or sale. Such platform, technology or mechanism shall: (I) Not unfairly disadvantage another controller; (II) Not make use of a default setting, but, rather, require the consumer to make an affirmative, freely given and unambi… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source

Who it applies to

Persons that do business in Connecticut or target its residents, and meet: 35,000+ consumers, or other thresholds (see full text); some provisions apply under a separate test (see full text)

What the law gives consumers

  • Right to access Archived excerpt — the text we read …nd after July 1, 2026, this section, as amended by section 8 of public act 25-113, is to read as follows: “Sec. 42-518. Consumers' rights. Compliance by Controllers. Appeals. (a) A consumer shall have the right to: (1) Confirm whether or not a controller is processing the consumer's personal data and access such personal data, including, but not limited to, any inferences about the consumer derived from such personal data and whether a controller or processor is processing a consumer's personal data for the purposes of profiling to make a decision that produces any legal or similarly significant effect concerning a consumer, unless such confirmation or access would require the controller to reveal a trade secret or the controller is prohibited from disclosing such personal data under subsection (e) of this section; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by, or… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Right to correct Archived excerpt — the text we read …oncerning a consumer, unless such confirmation or access would require the controller to reveal a trade secret or the controller is prohibited from disclosing such personal data under subsection (e) of this section; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by, or obtained about, the consumer; (4) obtain a copy of the consumer's personal data processed by the controller, in a portable and, to the extent technically feasible, readily usabl… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Right to delete Archived excerpt — the text we read …under subsection (e) of this section; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by, or obtained about, the consumer; (4) obtain a copy of the consumer's personal data processed by the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another contr… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Right to data portability Archived excerpt — the text we read …onsumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by, or obtained about, the consumer; (4) obtain a copy of the consumer's personal data processed by the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means, provided such controller shall not be required to reveal any trade secret; (… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …at allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means, provided such controller shall not be required to reveal any trade secret; (5) opt out of the processing of the personal data for purposes of (A) targeted advertising, (B) the sale of personal data, except as provided in subdivision (2) of subsection (a) of section 42-520, or (C) profiling in furtherance of any automated decision that produces any legal or similarly significant effect concerning the consumer; (6) … Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read …at allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means, provided such controller shall not be required to reveal any trade secret; (5) opt out of the processing of the personal data for purposes of (A) targeted advertising, (B) the sale of personal data, except as provided in subdivision (2) of subsection (a) of section 42-520, or (C) profiling in furtherance of any automated decision that produces any legal or similarly significant effec… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Right to opt out of profiling for significant decisions Archived excerpt — the text we read …trade secret; (5) opt out of the processing of the personal data for purposes of (A) targeted advertising, (B) the sale of personal data, except as provided in subdivision (2) of subsection (a) of section 42-520, or (C) profiling in furtherance of any automated decision that produces any legal or similarly significant effect concerning the consumer; (6) if the consumer's personal data were processed for the purposes of profiling in furtherance of any automated decision that produced any legal or similarly significant effect concerning the consumer, and if feasible… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Sensitive data: opt-in consent required Archived excerpt — the text we read …sonable administrative, technical and physical data security practices to protect the confidentiality, integrity and accessibility of personal data appropriate to the volume and nature of the personal data at issue; (D) not process sensitive data concerning a consumer unless such processing is reasonably necessary in relation to the purposes for which such sensitive data are processed and without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a consumer who the controller has actual knowledge, or wilfully disregards, is a child, without processing such data in accordance with COPPA; (E) not proc… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Right to a list of the third parties data was sold to Archived excerpt — the text we read … were processed, allow the consumer to correct any incorrect personal data that were processed for the purposes of such profiling and have the profiling decision reevaluated based on the corrected personal data; and (7) obtain from the controller a list of the third parties to which such controller has sold the consumer's personal data or, if such controller does not maintain a list of the third parties to which such controller has sold the consumer's personal data, a list of all third parties to which such controller has sold personal data, provided the controller shall not be required to reveal any trade secret. (b) A consumer may exercise rights under this section by a secure and reliable means established by the controller and described to the consumer in the controller's privacy notice. A consumer may designate an authoriz… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Right to appeal Archived excerpt — the text we read …ions 42-515 to 42-525, inclusive, or (B) opting the consumer out of the processing of such personal data for any purpose except for those exempted pursuant to the provisions of sections 42-515 to 42-525, inclusive. (d) A controller shall establish a process for a consumer to appeal the controller's refusal to take action on a request within a reasonable period of time after the consumer's receipt of the decision. The appeal process shall be conspicuously available and similar to the process for submitting requests to initiate action pursuant to this section. Not later than sixty days after receipt of an appeal, a controller shal… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Right against discrimination Archived excerpt — the text we read …ing, or sell the consumer's personal data, under circumstances where a controller has actual knowledge, or wilfully disregards, that the consumer is at least thirteen years of age but younger than eighteen years of age. A controller shall not discriminate against a consumer for exercising any of the consumer rights contained in sections 42-515 to 42-525, inclusive, including denying goods or services, charging different prices or rates for goods or services or providing a different level of quality of goods or services to the consumer. (2) Nothing in subdivision (1) of this subs… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Right to question a profiling decision Archived excerpt — the text we read …, except as provided in subdivision (2) of subsection (a) of section 42-520, or (C) profiling in furtherance of any automated decision that produces any legal or similarly significant effect concerning the consumer; (6) if the consumer's personal data were processed for the purposes of profiling in furtherance of any automated decision that produced any legal or similarly significant effect concerning the consumer, and if feasible, (A) question the result of such profiling, (B) be informed of the reason that such profiling resulted in such decision, (C) review the consumer's personal data that were processed for the purposes of such profiling, and (D) if the profiling decision concerned housing, taking into account the nature of the personal data and the purposes for which such personal data were processed, allow the consumer to correct any incorrect personal data that were processed for the purposes of such profiling and have the profiling decision reevaluated based on the corrected personal data; and (7) obtain from the controller a list of the third parties to which such controller has sold the consumer's personal data or, if such controller does not maintain a list of the… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read … (4) the substantial likelihood of injury to the public; (5) the safety of persons or property; (6) whether such alleged violation was likely caused by human or technical error; and (7) the sensitivity of the data. (d) Nothing in sections 42-515 to 42-524, inclusive, or section 42-526, shall be construed as providing the basis for, or be subject to, a private right of action for violations of said sections or any other law. (e) A violation of the requirements of sections 42-515 to 42-524, inclusive, or section 42-526, shall constitute an unfair trade practice for purposes of section 42-110b and shall be enforced solely by the Attorney Gen… Archived from source — captured 2026-07-20 · snapshot ff6266b5 Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read …th data and reproductive or sexual health data. (10) “Consumer health data controller” means any controller that, alone or jointly with others, determines the purpose and means of processing consumer health data. (11) “Controller” means a person who, alone or jointly with others, determines the purpose and means of processing personal data. (12) “COPPA” means the Children's Online Privacy Protection Act of 1998, 15 USC 6501 et seq., and the regulations, rules, guidance and exemptions adopted pursuant to said act, as said act and such regulations, rules, g… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Processors Archived excerpt — the text we read …t of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion or modification of personal data. (30) “Processor” means a person who processes personal data on behalf of a controller. (31) “Profiling” means any form of automated processing performed on personal data to evaluate, analyze or predict personal aspects related to an identified or identifiable individual's economic situation, health, pers… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Third parties Archived excerpt — the text we read …(C) advertisements directed to a consumer in response to the consumer's request for information or feedback, or (D) processing personal data solely to measure or report advertising frequency, performance or reach. (41) “Third party” means a person, such as a public authority, agency or body, other than the consumer, controller or processor or an affiliate of the processor or the controller. (42) “Trade secret” has the same meaning as provided in section 35-51.” (P.A. 22-15, S. 1; P.A. 23-56, S. 1; 23-110, S. 1; 23-204, S. 207; P.A. 25-168, S. 286; 25-113, S. 5.) History: P.A. 22-15 effective July 1, 202… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source

Exemptions

  • State and local government agencies Exempt from 42-515 to 42-525 under 42-517(a), and from the 42-526(a) consumer health data restrictions under 42-526(b). Archived excerpt — the text we read …d after July 1, 2026, subsections (a) and (b) of this section, as amended by section 7 of public act 25-113, are to read as follows: “(a) The provisions of sections 42-515 to 42-525, inclusive, do not apply to any: (1) Body, authority, board, bureau, commission, district or agency of this state or of any political subdivision of this state; (2) person who has entered into a contract with any body, authority, board, bureau, commission, district or agency described in subdivision (1) of this subsection while such person is processing consumer health data on… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Contractors processing consumer health data on behalf of government agencies Exempt from 42-515 to 42-525 under 42-517(a), and from the 42-526(a) consumer health data restrictions under 42-526(b). Archived excerpt — the text we read …ows: “(a) The provisions of sections 42-515 to 42-525, inclusive, do not apply to any: (1) Body, authority, board, bureau, commission, district or agency of this state or of any political subdivision of this state; (2) person who has entered into a contract with any body, authority, board, bureau, commission, district or agency described in subdivision (1) of this subsection while such person is processing consumer health data on behalf of such body, authority, board, bureau, commission, district or agency pursuant to such contract; (3) nonprofit organization; (4) candidate committee, national committee, party committee or political committee… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Nonprofit organizations (partial) Exempt from 42-515 to 42-525 only; the 42-526 consumer health data duties still apply. Archived excerpt — the text we read …agency described in subdivision (1) of this subsection while such person is processing consumer health data on behalf of such body, authority, board, bureau, commission, district or agency pursuant to such contract; (3) nonprofit organization; (4) candidate committee, national committee, party committee or political committee, as such terms are defined in section 9-601; (5) institution of higher education; (6) national securities association that is register… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Candidate, national, party and political committees (partial) Exempt from 42-515 to 42-525 only; the 42-526 consumer health data duties still apply. Archived excerpt — the text we read …ion (1) of this subsection while such person is processing consumer health data on behalf of such body, authority, board, bureau, commission, district or agency pursuant to such contract; (3) nonprofit organization; (4) candidate committee, national committee, party committee or political committee, as such terms are defined in section 9-601; (5) institution of higher education; (6) national securities association that is registered under 15 USC 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; (7) covered entity or business associ… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Institutions of higher education Exempt from 42-515 to 42-525 under 42-517(a), and from the 42-526(a) consumer health data restrictions under 42-526(b). Archived excerpt — the text we read … commission, district or agency pursuant to such contract; (3) nonprofit organization; (4) candidate committee, national committee, party committee or political committee, as such terms are defined in section 9-601; (5) institution of higher education; (6) national securities association that is registered under 15 USC 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; (7) covered entity or business associate, as defined in 45 CFR 160.103; (8… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • National securities associations Exempt from 42-515 to 42-525 under 42-517(a), and from the 42-526(a) consumer health data restrictions under 42-526(b). Archived excerpt — the text we read …ant to such contract; (3) nonprofit organization; (4) candidate committee, national committee, party committee or political committee, as such terms are defined in section 9-601; (5) institution of higher education; (6) national securities association that is registered under 15 USC 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; (7) covered entity or business associate, as defined in 45 CFR 160.103; (8) tribal nation government organization; (9) air carrier, as defined in 49 USC 40102, as amended from time to time, and regulated under the Fede… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • GLBA-regulated data Data-level; the entity-level GLBA exemption was removed from 42-517(a) eff. 2026-07-01 but remains in 42-526(b)(5) for the consumer health data restrictions. Archived excerpt — the text we read …n to price, route or service, as such terms are used in the Federal Aviation Act of 1958, 49 USC 40101 et seq., and the Airline Deregulation Act of 1978, 49 USC 41713, as said acts may be amended from time to time; (17) data subject to Title V of the Gramm-Leach-Bliley Act, 15 USC 6801 et seq., as amended from time to time; and (18) information included in a limited data set, as described in 45 CFR 164.514(e), as amended from time to time, to the extent such information is used, disclosed and maintained in the manner specified in 45 CFR 1… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Banks and credit unions (and affiliates/subsidiaries) only and directly engaged in financial activities Regulated and examined by the Department of Banking or a federal bank regulator, with a personal-data compliance program. Exempt from 42-515 to 42-525 under 42-517(a); a GLBA-covered financial institution is also exempt from the 42-526(a) consumer health data restrictions under 42-526(b)(5). Archived excerpt — the text we read …ction 38a-595, health carrier, as defined in section 38a-591a, insurance-support organization, as defined in section 38a-976, or insurance agent or insurance producer, as such terms are defined in section 38a-702a; (11) bank, Connecticut credit union, federal credit union, out-of-state bank or out-of-state credit union, or any affiliate or subsidiary thereof, as such terms are defined in section 36a-2, that (A) is only and directly engaged in financial activities as described in 12 USC 1843(k), (B) is regulated and examined by the Department of Banking or an applicable federal bank regulatory agency, and (C) has established a program to comply with all applicable requirements established by the Banking Commissioner or the applicable federal bank regulatory agency concerning personal data; or (12) agent, broker-dealer, investment adviser or investment adviser agent, as such terms are defined in section 36b-3, who is regulated by the Department of Banking or the Securities and Exchange Commission. (b) Th… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • HIPAA covered entities and business associates Exempt from 42-515 to 42-525 under 42-517(a), and from the 42-526(a) consumer health data restrictions under 42-526(b). Archived excerpt — the text we read …erms are defined in section 9-601; (5) institution of higher education; (6) national securities association that is registered under 15 USC 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; (7) covered entity or business associate, as defined in 45 CFR 160.103; (8) tribal nation government organization; (9) air carrier, as defined in 49 USC 40102, as amended from time to time, and regulated under the Federal Aviation Act of 1958, 49 USC 40101 et seq., and the Airline Deregula… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Tribal nation government organizations Exempt from 42-515 to 42-525 under 42-517(a), and from the 42-526(a) consumer health data restrictions under 42-526(b). Archived excerpt — the text we read …(6) national securities association that is registered under 15 USC 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; (7) covered entity or business associate, as defined in 45 CFR 160.103; (8) tribal nation government organization; (9) air carrier, as defined in 49 USC 40102, as amended from time to time, and regulated under the Federal Aviation Act of 1958, 49 USC 40101 et seq., and the Airline Deregulation Act of 1978, 49 USC 41713, as said act… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Air carriers Exempt from 42-515 to 42-525 under 42-517(a), and from the 42-526(a) consumer health data restrictions under 42-526(b). Archived excerpt — the text we read … registered under 15 USC 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; (7) covered entity or business associate, as defined in 45 CFR 160.103; (8) tribal nation government organization; (9) air carrier, as defined in 49 USC 40102, as amended from time to time, and regulated under the Federal Aviation Act of 1958, 49 USC 40101 et seq., and the Airline Deregulation Act of 1978, 49 USC 41713, as said acts may be amended from time to time; (10) insurer, as defined in section 38a-1, or its affiliate, fraternal benefit society, within the meaning of section 38a-595, health carrier, as defined in section 38a-59… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Insurers and affiliates, fraternal benefit societies, health carriers, and others Insurers and affiliates, fraternal benefit societies, health carriers, insurance-support organizations, insurance agents and producers. Exempt from 42-515 to 42-525 under 42-517(a); a GLBA-covered financial institution is also exempt from the 42-526(a) consumer health data restrictions under 42-526(b)(5). Archived excerpt — the text we read …0102, as amended from time to time, and regulated under the Federal Aviation Act of 1958, 49 USC 40101 et seq., and the Airline Deregulation Act of 1978, 49 USC 41713, as said acts may be amended from time to time; (10) insurer, as defined in section 38a-1, or its affiliate, fraternal benefit society, within the meaning of section 38a-595, health carrier, as defined in section 38a-591a, insurance-support organization, as defined in section 38a-976, or insurance agent or insurance producer, as such terms are defined in section 38a-702a; (11) bank, Connecticut credit union, federal credit union, out-of-state bank or out-of-state credit union, or any affiliate or subsidiary thereof, as such terms are defined in section 36a-2, that (A) is only and direct… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Broker-dealers, agents, and others Broker-dealers, agents, investment advisers and investment adviser agents regulated by the Department of Banking or the SEC. Exempt from 42-515 to 42-525 under 42-517(a); a GLBA-covered financial institution is also exempt from the 42-526(a) consumer health data restrictions under 42-526(b)(5). Archived excerpt — the text we read … regulatory agency, and (C) has established a program to comply with all applicable requirements established by the Banking Commissioner or the applicable federal bank regulatory agency concerning personal data; or (12) agent, broker-dealer, investment adviser or investment adviser agent, as such terms are defined in section 36b-3, who is regulated by the Department of Banking or the Securities and Exchange Commission. (b) The following information and data are exempt from the provisions of sections 42-515 to 42-526, inclusive: (1) Protected health information under HIPAA; (2) patient-identifying information for purposes of 42 USC 2… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Protected health information under HIPAA Archived excerpt — the text we read …section 36b-3, who is regulated by the Department of Banking or the Securities and Exchange Commission. (b) The following information and data are exempt from the provisions of sections 42-515 to 42-526, inclusive: (1) Protected health information under HIPAA; (2) patient-identifying information for purposes of 42 USC 290dd-2; (3) identifiable private information for purposes of the federal policy for the protection of human subjects under 45 CFR 46; (4) identifiable private… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Patient-identifying information under 42 USC 290dd-2 Archived excerpt — the text we read …ent of Banking or the Securities and Exchange Commission. (b) The following information and data are exempt from the provisions of sections 42-515 to 42-526, inclusive: (1) Protected health information under HIPAA; (2) patient-identifying information for purposes of 42 USC 290dd-2; (3) identifiable private information for purposes of the federal policy for the protection of human subjects under 45 CFR 46; (4) identifiable private information that is otherwise information collected as part of huma… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Human subjects research information under 45 CFR 46 Archived excerpt — the text we read …ollowing information and data are exempt from the provisions of sections 42-515 to 42-526, inclusive: (1) Protected health information under HIPAA; (2) patient-identifying information for purposes of 42 USC 290dd-2; (3) identifiable private information for purposes of the federal policy for the protection of human subjects under 45 CFR 46; (4) identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonization of… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Human subjects research under good clinical practice guidelines Archived excerpt — the text we read …ormation under HIPAA; (2) patient-identifying information for purposes of 42 USC 290dd-2; (3) identifiable private information for purposes of the federal policy for the protection of human subjects under 45 CFR 46; (4) identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonization of Technical Requirements for Pharmaceuticals for Human Use; (5) personal data for purposes of the protection of human subjects under 21 CFR Parts 6, 50 and 56, or personal data used or shared in research, as defined in 45 CFR 164.501, that is conducted in accordance with the st… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Human subjects and other lawful research data Personal data for human subjects protection under 21 CFR Parts 6, 50 and 56, or research (45 CFR 164.501) conducted under those standards, or other research conducted in accordance with applicable law. Archived excerpt — the text we read …an subjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonization of Technical Requirements for Pharmaceuticals for Human Use; (5) personal data for purposes of the protection of human subjects under 21 CFR Parts 6, 50 and 56, or personal data used or shared in research, as defined in 45 CFR 164.501, that is conducted in accordance with the standards set forth in this subdivision and subdivisions (3) and (4) of this subsection, or other research conducted in accordance with applicable law; (6) information and docum… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Health Care Quality Improvement Act information Archived excerpt — the text we read …ned in 45 CFR 164.501, that is conducted in accordance with the standards set forth in this subdivision and subdivisions (3) and (4) of this subsection, or other research conducted in accordance with applicable law; (6) information and documents created for purposes of the Health Care Quality Improvement Act of 1986, 42 USC 11101 et seq.; (7) patient safety work product for purposes of section 19a-127o and the Patient Safety and Quality Improvement Act, 42 USC 299b-21 et seq., as amended from time to time; (8) information derived from any of the health … Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Patient safety work product Archived excerpt — the text we read …and (4) of this subsection, or other research conducted in accordance with applicable law; (6) information and documents created for purposes of the Health Care Quality Improvement Act of 1986, 42 USC 11101 et seq.; (7) patient safety work product for purposes of section 19a-127o and the Patient Safety and Quality Improvement Act, 42 USC 299b-21 et seq., as amended from time to time; (8) information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant t… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • De-identified health-care-related information Archived excerpt — the text we read …provement Act of 1986, 42 USC 11101 et seq.; (7) patient safety work product for purposes of section 19a-127o and the Patient Safety and Quality Improvement Act, 42 USC 299b-21 et seq., as amended from time to time; (8) information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA; (9) information originating from and intermingled to be indistinguishable with, or information treated in the same manner as, information exempt under this subsection that is maintained by a covered entity or business … Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Information intermingled with exempt HIPAA/substance-use records Archived excerpt — the text we read …from time to time; (8) information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA; (9) information originating from and intermingled to be indistinguishable with, or information treated in the same manner as, information exempt under this subsection that is maintained by a covered entity or business associate, program or qualified service organization, as specified in 42 USC 290dd-2, as amended from time to time; (10) information used for public health activities and purposes as authorized by HIPAA, community health activities and population health activities; (11) the collection, maintenance, disc… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Public health activities information Archived excerpt — the text we read …er as, information exempt under this subsection that is maintained by a covered entity or business associate, program or qualified service organization, as specified in 42 USC 290dd-2, as amended from time to time; (10) information used for public health activities and purposes as authorized by HIPAA, community health activities and population health activities; (11) the collection, maintenance, disclosure, sale, communication or use of any personal information bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal … Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • FCRA-regulated data Archived excerpt — the text we read …ty, character, general reputation, personal characteristics or mode of living by a consumer reporting agency, furnisher or user that provides information for use in a consumer report, and by a user of a consumer report, but only to the extent that such activity is regulated by and authorized under the Fair Credit Reporting Act, 15 USC 1681 et seq., as amended from time to time; (12) personal data collected, processed, sold or disclosed in compliance with the Driver's Privacy Protection Act of 1994, 18 USC 2721 et seq., as amended from time to time; (13) personal data regulated by the Family E… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read … consumer report, and by a user of a consumer report, but only to the extent that such activity is regulated by and authorized under the Fair Credit Reporting Act, 15 USC 1681 et seq., as amended from time to time; (12) personal data collected, processed, sold or disclosed in compliance with the Driver's Privacy Protection Act of 1994, 18 USC 2721 et seq., as amended from time to time; (13) personal data regulated by the Family Educational Rights and Privacy Act, 20 USC 1232g et seq., as amended from time to time; (14) personal data collected, processed, sold or disclosed in compliance with the Farm … Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read …1 et seq., as amended from time to time; (12) personal data collected, processed, sold or disclosed in compliance with the Driver's Privacy Protection Act of 1994, 18 USC 2721 et seq., as amended from time to time; (13) personal data regulated by the Family Educational Rights and Privacy Act, 20 USC 1232g et seq., as amended from time to time; (14) personal data collected, processed, sold or disclosed in compliance with the Farm Credit Act, 12 USC 2001 et seq., as amended from time to time; (15) data processed or maintained (A) in the course of an individual… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read … Privacy Protection Act of 1994, 18 USC 2721 et seq., as amended from time to time; (13) personal data regulated by the Family Educational Rights and Privacy Act, 20 USC 1232g et seq., as amended from time to time; (14) personal data collected, processed, sold or disclosed in compliance with the Farm Credit Act, 12 USC 2001 et seq., as amended from time to time; (15) data processed or maintained (A) in the course of an individual applying to, employed by or acting as an agent or independent contractor of a controller, processor, consumer health data controller or third party, … Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Employment-context data Archived excerpt — the text we read …, as amended from time to time; (14) personal data collected, processed, sold or disclosed in compliance with the Farm Credit Act, 12 USC 2001 et seq., as amended from time to time; (15) data processed or maintained (A) in the course of an individual applying to, employed by or acting as an agent or independent contractor of a controller, processor, consumer health data controller or third party, to the extent that the data are collected and used within the context of that role, (B) as the emergency contact information of an individual under sections 42-515 to 42-526, inclusive, used for emergency contact purposes, or (C) that are necessary to retain to administer benefits for another individu… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Emergency contact information Archived excerpt — the text we read …oyed by or acting as an agent or independent contractor of a controller, processor, consumer health data controller or third party, to the extent that the data are collected and used within the context of that role, (B) as the emergency contact information of an individual under sections 42-515 to 42-526, inclusive, used for emergency contact purposes, or (C) that are necessary to retain to administer benefits for another individual relating to the individual who is the subject of the information under subdivision (1) of this subsection and used for the purposes of a… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Benefits administration data Archived excerpt — the text we read …ent that the data are collected and used within the context of that role, (B) as the emergency contact information of an individual under sections 42-515 to 42-526, inclusive, used for emergency contact purposes, or (C) that are necessary to retain to administer benefits for another individual relating to the individual who is the subject of the information under subdivision (1) of this subsection and used for the purposes of administering such benefits; (16) personal data collected, processed, sold or disclosed in relation to price, route or service, as such terms are used in the Federal Aviation Act of 1958, 49 USC 40101 et seq., and the Airline Deregulation Act of 1… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Airline price, route, or service data Archived excerpt — the text we read …tain to administer benefits for another individual relating to the individual who is the subject of the information under subdivision (1) of this subsection and used for the purposes of administering such benefits; (16) personal data collected, processed, sold or disclosed in relation to price, route or service, as such terms are used in the Federal Aviation Act of 1958, 49 USC 40101 et seq., and the Airline Deregulation Act of 1978, 49 USC 41713, as said acts may be amended from time to time; (17) data subject to Title V of the Gramm-Leach-Bliley Act, 15 USC 6801 et seq., as amended from time to time; and (18) information included in a limited data set, as desc… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • HIPAA limited data sets (used, disclosed and maintained as 45 CFR 164.514(e) specifies) Archived excerpt — the text we read … the Airline Deregulation Act of 1978, 49 USC 41713, as said acts may be amended from time to time; (17) data subject to Title V of the Gramm-Leach-Bliley Act, 15 USC 6801 et seq., as amended from time to time; and (18) information included in a limited data set, as described in 45 CFR 164.514(e), as amended from time to time, to the extent such information is used, disclosed and maintained in the manner specified in 45 CFR 164.514(e), as amended from time to time.” (P.A. 22-15, S. 3; P.A. 23-56, S. 3; 23-204, S. 207; P.A. 25-113, S. 7.) History: P.A. 22-15 effective July 1, 2023; P.A. 23-56 amended Subsec. (a) by adding new Subdiv. (2) re contract… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …tions 42-515 to 42-526, inclusive, shall not apply where compliance by the controller, processor or consumer health data controller with said sections would violate an evidentiary privilege under the laws of this state. Nothing in sections 42-515 to 42-526, inclusive, shall be construed to prevent a controller, processor or consumer health data controller from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of the state as part of a privileged communication. (d) A controller, processor or consumer health data controller that discloses personal data to a processor or third-party controller in accordance with sections 42-515 to 42-526, inclusive, shall not be deemed to have … Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Evidentiary privilege (compliance would violate a Connecticut evidentiary privilege) Archived excerpt — the text we read …rm internal operations in accordance with the internal operations exception established in COPPA if the controller, processor or consumer health data controller is processing data in accordance with such exception. (c) The obligations imposed on controllers, processors or consumer health data controllers under sections 42-515 to 42-526, inclusive, shall not apply where compliance by the controller, processor or consumer health data controller with said sections would violate an evidentiary privilege under the laws of this state. Nothing in sections 42-515 to 42-526, inclusive, shall be construed to prevent a controller, processor or consumer health data controller from providing personal data concerning a consumer to a person covered by an evi… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Purely personal or household activity Archived excerpt — the text we read … person, including, but not limited to, the rights of any person (A) to freedom of speech or freedom of the press guaranteed in the First Amendment to the United States Constitution, or (B) under section 52-146t; or (2) apply to any person's processing of personal data in the course of such person's purely personal or household activities. (f) Personal data processed by a controller or consumer health data controller pursuant to this section may be processed to the extent that such processing is: (1) Reasonably necessary and proportionate to the purpose… Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source
  • Rights and freedoms of others, including free speech and press Archived excerpt — the text we read … controller, processor or consumer health data controller from which such third-party controller or processor receives such personal data. (e) Nothing in sections 42-515 to 42-526, inclusive, shall be construed to: (1) Impose any obligation on a controller, processor or consumer health data controller that adversely affects the rights or freedoms of any person, including, but not limited to, the rights of any person (A) to freedom of speech or freedom of the press guaranteed in the First Amendment to the United States Constitution, or (B) under section 52-146t; or (2) apply to any person's processing of personal data in the course of such person's purely personal or household activities. (f) Personal data processed by a controller or consumer health data controller pursuant … Archived from source — captured 2026-09-28 · snapshot a6e146b8 Verify at the source

Published Sep 30, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

CTDPA milestones

This state currently has one dated milestone on the books.

Enforcement July 1, 2023

CTDPA took effect

Enforcement began — obligations have been live since this date.

Source: primary citation

Enforcement so far

The fines are already landing

Real regulatory actions and settlements under the Connecticut privacy laws we track. Every entry is a DataGrail summary linking to the primary source.

$275,000 Total penalties
1 Actions on record
View all

DataGrail’s wording, not statutory text. The figures are computed from the linked sources.

Published Sep 30, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 30, 2026