State Comprehensive Privacy Laws

Public Act 25-113 Rewrote the Connecticut Data Privacy Act on July 1, 2026, and a 2026 Act Rewrites Part of It Again in October

Key Takeaways

  • Every Data Privacy Act section of Public Act 25-113 carries the same effective date, July 1, 2026; the Governor signed the bill on June 24, 2025
  • Section 42-516 now reaches anyone processing 35,000 consumers' data, anyone controlling or processing sensitive data, and anyone offering personal data for sale, with no revenue test
  • The entity-level Gramm-Leach-Bliley exemption is gone; GLBA-covered data stays exempt, and insurers, qualifying banks and credit unions, and broker-dealers gain their own entity exemptions
  • Controllers must now run impact assessments for profiling that feeds significant decisions, for processing activities created on or after August 1, 2026
  • Targeted advertising to, and sale of the data of, known 13-to-17-year-olds is prohibited outright; the consent route that existed for 13-to-15-year-olds is deleted

One Omnibus Act, Thirteen Privacy Sections, One Date

The bill status page for S.B. 1295 records the path: the General Law Committee's bill passed in concurrence on June 3, 2025, became Public Act 25-113 on June 11, and was signed by the Governor on June 24, 2025. Its title, "An Act Concerning Broadband Internet, Gaming, Social Media, Online Services and Consumer Contracts," signals that privacy is only part of it.

Read as enacted, Public Act 25-113 runs to 26 sections with several different effective dates, from July 1, 2025 to July 1, 2026, plus provisions effective from passage. The sections that amend the Connecticut Data Privacy Act are 5 through 12, which rewrite §§ 42-515 through 42-524, and 14 through 18, which rewrite the minors' online services provisions at §§ 42-529 through 42-529d. Each is marked "Effective July 1, 2026." The broadband, gaming, social media account and consumer contract sections run on other dates and are outside this account.

A public act prints deleted words in square brackets and new words underlined, and a plain-text copy loses the underline but keeps the brackets. Every change described below was checked against the 2026 Supplement to chapter 743jj, which prints each amended section in full beneath the old text, with a history note saying what Public Act 25-113 did to it.

A Lower Threshold and Two Triggers That Ignore Size

Before July 1, 2026, § 42-516 reached persons that in the preceding calendar year processed the personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving more than 25 per cent of gross revenue from selling personal data. Section 6 of the act replaced both limbs. The applicability section now lists three alternatives:

  1. Conducting business in Connecticut, or targeting products or services to its residents, and processing the personal data of "not fewer than thirty-five thousand consumers" in the preceding calendar year, excluding data processed solely to complete a payment transaction
  2. Controlling or processing "consumers' sensitive data," with the same payment-transaction exclusion
  3. Offering "consumers' personal data for sale in trade or commerce"

The second and third limbs carry no number. The Attorney General's 2025 CTDPA Enforcement Report describes the "expansion of the CTDPA to all processing of sensitive data and all sales of such data" as "unique to Connecticut" among states that have lowered their thresholds, and says the office will "continue to focus on sensitive data especially with the removal of the problematic threshold." The office's CTDPA page now states the three-branch test and adds that consumer health data controllers are covered regardless of size.

Section 7 reworked the entity exemptions in § 42-517(a). The exemption for any "financial institution or data subject to Title V of the Gramm-Leach-Bliley Act" was struck and replaced by a data-level exemption for GLBA-covered data in § 42-517(b)(17). New entity exemptions were added for political committees; for insurers, fraternal benefit societies, health carriers, insurance-support organizations and producers; for banks and credit unions that are engaged only in financial activities, supervised by a banking regulator and running a personal-data compliance program; and for broker-dealers and investment advisers regulated by the Department of Banking or the SEC. Information in a HIPAA limited data set, used and kept as 45 CFR 164.514(e) allows, became exempt data.

What Counts as Sensitive Data Now

Section 5 renumbered the definitions in § 42-515 and rewrote the sensitive-data definition, now subdivision (39). Placed beside the prior text, the list changed in seven places:

ElementBefore July 1, 2026From July 1, 2026
HealthMental or physical health condition or diagnosisAdds disability or treatment
Gender identityNot listedStatus as nonbinary or transgender
Genetic and biometricProcessing "for the purpose of uniquely identifying an individual"Genetic or biometric data "or information derived therefrom," with no purpose limit
ChildrenData collected from "a known child"Data from an individual the controller "has actual knowledge, or wilfully disregards, is a child"
Neural dataNot listedInformation generated by measuring central nervous system activity
Financial accessNot listedAccount or card number that, with any required code or credential, would allow access
Government IDNot listedGovernment-issued identification numbers that law does not require to be displayed

The duties attached to sensitive data changed too. Section 9 restructured § 42-520(a) into lettered subparagraphs. Subparagraph (D) now reads that a controller shall "not process sensitive data concerning a consumer unless such processing is reasonably necessary in relation to the purposes for which such sensitive data are processed and without obtaining the consumer's consent." Subparagraph (H) is new and freestanding: a controller shall "not sell the sensitive data of a consumer without the consumer's consent." Collection is also narrowed, from data that is "adequate, relevant and reasonably necessary" to data that is "reasonably necessary and proportionate" to the disclosed purposes.

Profiling, Consumer Rights and the Privacy Notice

Section 8 rewrote § 42-518. The access right now expressly includes "any inferences about the consumer derived from such personal data" and whether the data is being used for profiling toward a significant decision. The opt-out from profiling no longer requires the decision to be "solely" automated; it reaches "any automated decision that produces any legal or similarly significant effect." Two rights are new. Subdivision (6) lets a consumer whose data fed such a decision, where feasible, question the result, learn the reason for it and review the data used, and, for housing decisions, correct the data and have the decision reevaluated. Subdivision (7) entitles a consumer to a list of the third parties to which the controller sold that consumer's data, or of all third parties to which it sold personal data if it keeps no per-consumer list. A new subsection (e) bars a controller from returning Social Security, government ID, financial account, health insurance or medical ID numbers, passwords, security answers or biometric data in an access response, and requires it instead to say with particularity that it holds them.

The same section narrowed what counts as a significant decision. Section 5 dropped "access to essential goods or services" from the definition in § 42-515(15), leaving financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunity and health care services.

The privacy notice in § 42-520(b) gained content and placement rules. It must now disclose the categories of personal data the controller sells and to whom, any processing for targeted advertising, "whether the controller collects, uses or sells personal data for the purpose of training large language models," and the month and year of its last update. It must be linked through a hyperlink containing the word "privacy" on the home page, in any app store listing and in any app's settings menu, provided in each language the controller does business in, and accessible to people with disabilities. A controller making a retroactive material change must notify affected consumers and give them a reasonable opportunity to withdraw consent.

Impact Assessments Join Data Protection Assessments

Section 11 split § 42-522 so that the heightened-risk list (targeted advertising, sale, risky profiling and sensitive data) sits in its own subsection (a), and added subsection (c): each controller that profiles to make a significant decision "shall conduct an impact assessment for such profiling." The assessment covers, to the extent reasonably known, the purpose, intended uses and deployment context; any foreseeable heightened risk of harm and the mitigating steps taken; the categories of input data and the outputs; any data used to customize the profiling; performance metrics and known limitations; transparency measures; and post-deployment monitoring and safeguards.

Subsection (g)(2) applies the impact assessment requirement to "processing activities created or generated on or after August 1, 2026," and states it is not retroactive. Data protection assessments keep their July 1, 2023 start. The Attorney General can demand either kind of assessment when relevant to an investigation; both stay confidential and exempt from the Freedom of Information Act, and disclosure does not waive privilege. A separate amendment to § 42-520(a)(1)(E) makes "any evidence, or lack of evidence, concerning proactive anti-bias testing" relevant to a claim or defense under Connecticut anti-discrimination law.

Minors' Data

The most direct change for young users sits in the core statute. Old § 42-520(a)(7) barred targeted advertising to, and sale of the data of, a consumer known to be at least 13 and under 16 "without the consumer's consent." New subparagraph (I) raises the upper age to 18 and deletes the consent words, so both practices are prohibited for 13-to-17-year-olds the controller knows or wilfully disregards are in that range.

The minors' online services provisions added by Public Act 23-56 were rewritten on the same date. As amended, § 42-529a(b)(1) prohibits a controller whose service is used by known minors from processing a minor's data for targeted advertising or sale at all, with the consent structure removed. Collecting precise geolocation now requires that it be "strictly necessary" rather than "reasonably necessary." Profiling toward a significant decision is limited to what is reasonably necessary to provide the service and still requires consent, from the minor or, under 13, a parent. Subsection (c) now prohibits, with an exception only for educational services, design features that "significantly increase, sustain or extend" a minor's use, and requires that direct messaging default to blocking unsolicited contact from unconnected adults. The definition of heightened risk of harm to minors in § 42-529 gained physical violence, severe or pervasive harassment, and sexual abuse or exploitation, and § 42-529b now requires impact assessments for services that profile minors, with harm-mitigation plans that a controller must disclose within 90 days of an Attorney General demand.

The Attorney General's 2025 report says the office issued two violation notices under the minors' provisions in their first year and relied more on information requests, and that the legislature's removal of the consent structure followed the office's advocacy.

What the Attorney General's Cure Period Now Looks Like

Public Act 25-113 did not amend § 42-525, the enforcement section. Subsection (b) required the Attorney General, where a cure was possible, to issue a notice of violation and allow 60 days before suing, but only from July 1, 2023 (October 1, 2023 for consumer health data controllers) through December 31, 2024. Since January 1, 2025, subsection (c) has let the Attorney General decide whether to offer a cure at all, weighing seven factors: the number of violations; the size and complexity of the business; the nature and extent of its processing; the likelihood of injury to the public; the safety of persons or property; whether the violation was likely caused by human or technical error; and the sensitivity of the data.

Enforcement remains exclusive to the Attorney General under § 42-525(a), and subsection (e) makes a violation an unfair trade practice under § 42-110b while excluding the private action in § 42-110g. Subsection (d) states that nothing in the Act provides a private right of action. The newly covered businesses therefore meet a statute whose cure opportunity is already discretionary on the day they come within it.

Public Act 26-64 Changes Some of the Same Words on October 1, 2026

The 2025 text is not the last word. The bill record for S.B. 4 of 2026 shows it became Public Act 26-64 and was signed on May 27, 2026. Public Act 26-64 amends §§ 42-515, 42-518, 42-520, 42-521 and 42-524 "as amended by" Public Act 25-113, each effective October 1, 2026. Three of its changes alter the text described above:

  • Section 14 strikes "material" from § 42-520(a)(1)(B), so consent is required for processing for "any new purpose" that is neither reasonably necessary to nor compatible with the disclosed purposes
  • Section 14 adds § 42-520(a)(3): "No controller shall sell any consumer's precise geolocation data," with no consent exception
  • Section 12 rewrites the definition of publicly available information, which now excludes biometric data collected without the consumer's knowledge, genetic data the consumer did not make public, and information posted where the consumer kept a reasonable expectation of privacy

The same act adds a facial recognition signage rule to § 42-524 and creates a data broker registry, genetic testing protections and other provisions outside the Data Privacy Act. Those are separate subjects and are not covered here.

Background

For the underlying law rather than this development: Connecticut privacy law.

Frequently Asked Questions

When did Connecticut's 2025 privacy amendments take effect?
Every section of Public Act 25-113 that amends the Connecticut Data Privacy Act, sections 5 to 12 and 14 to 18, is marked effective July 1, 2026. The impact assessment requirement in § 42-522(g)(2) applies only to processing activities created or generated on or after August 1, 2026.
Does the Connecticut Data Privacy Act still exempt banks?
Not by reference to the Gramm-Leach-Bliley Act. The entity-level GLBA exemption was deleted; GLBA-covered data remains exempt under § 42-517(b)(17), and a bank or credit union is exempt as an entity only if it is engaged solely in financial activities, supervised by a banking regulator and running a personal-data compliance program.
What does the amended CTDPA say about large language models?
Section 42-520(b)(1)(H) requires the privacy notice to include a statement disclosing whether the controller collects, uses or sells personal data for the purpose of training large language models. The statute requires the disclosure; it does not regulate the training itself.
Is there still a 60-day cure period under the CTDPA?
Not as of right. The mandatory cure period in § 42-525(b) covered notices through December 31, 2024. Since January 1, 2025 the Attorney General may offer a cure in its discretion, weighing the seven factors in § 42-525(c). Public Act 25-113 left that section unchanged.
Did the 2026 legislative session change the CTDPA again?
Yes. Public Act 26-64, signed May 27, 2026, amends several of the same sections effective October 1, 2026, including a flat ban on selling precise geolocation data and a narrower definition of publicly available information.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.