Public Act 25-113 Rewrote the Connecticut Data Privacy Act on July 1, 2026, and a 2026 Act Rewrites Part of It Again in October
Key Takeaways
- Every Data Privacy Act section of Public Act 25-113 carries the same effective date, July 1, 2026; the Governor signed the bill on June 24, 2025
- Section 42-516 now reaches anyone processing 35,000 consumers' data, anyone controlling or processing sensitive data, and anyone offering personal data for sale, with no revenue test
- The entity-level Gramm-Leach-Bliley exemption is gone; GLBA-covered data stays exempt, and insurers, qualifying banks and credit unions, and broker-dealers gain their own entity exemptions
- Controllers must now run impact assessments for profiling that feeds significant decisions, for processing activities created on or after August 1, 2026
- Targeted advertising to, and sale of the data of, known 13-to-17-year-olds is prohibited outright; the consent route that existed for 13-to-15-year-olds is deleted
One Omnibus Act, Thirteen Privacy Sections, One Date
The bill status page for S.B. 1295 records the path: the General Law Committee's bill passed in concurrence on June 3, 2025, became Public Act 25-113 on June 11, and was signed by the Governor on June 24, 2025. Its title, "An Act Concerning Broadband Internet, Gaming, Social Media, Online Services and Consumer Contracts," signals that privacy is only part of it.
Read as enacted, Public Act 25-113 runs to 26 sections with several different effective dates, from July 1, 2025 to July 1, 2026, plus provisions effective from passage. The sections that amend the Connecticut Data Privacy Act are 5 through 12, which rewrite §§ 42-515 through 42-524, and 14 through 18, which rewrite the minors' online services provisions at §§ 42-529 through 42-529d. Each is marked "Effective July 1, 2026." The broadband, gaming, social media account and consumer contract sections run on other dates and are outside this account.
A public act prints deleted words in square brackets and new words underlined, and a plain-text copy loses the underline but keeps the brackets. Every change described below was checked against the 2026 Supplement to chapter 743jj, which prints each amended section in full beneath the old text, with a history note saying what Public Act 25-113 did to it.
A Lower Threshold and Two Triggers That Ignore Size
Before July 1, 2026, § 42-516 reached persons that in the preceding calendar year processed the personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving more than 25 per cent of gross revenue from selling personal data. Section 6 of the act replaced both limbs. The applicability section now lists three alternatives:
- Conducting business in Connecticut, or targeting products or services to its residents, and processing the personal data of "not fewer than thirty-five thousand consumers" in the preceding calendar year, excluding data processed solely to complete a payment transaction
- Controlling or processing "consumers' sensitive data," with the same payment-transaction exclusion
- Offering "consumers' personal data for sale in trade or commerce"
The second and third limbs carry no number. The Attorney General's 2025 CTDPA Enforcement Report describes the "expansion of the CTDPA to all processing of sensitive data and all sales of such data" as "unique to Connecticut" among states that have lowered their thresholds, and says the office will "continue to focus on sensitive data especially with the removal of the problematic threshold." The office's CTDPA page now states the three-branch test and adds that consumer health data controllers are covered regardless of size.
Section 7 reworked the entity exemptions in § 42-517(a). The exemption for any "financial institution or data subject to Title V of the Gramm-Leach-Bliley Act" was struck and replaced by a data-level exemption for GLBA-covered data in § 42-517(b)(17). New entity exemptions were added for political committees; for insurers, fraternal benefit societies, health carriers, insurance-support organizations and producers; for banks and credit unions that are engaged only in financial activities, supervised by a banking regulator and running a personal-data compliance program; and for broker-dealers and investment advisers regulated by the Department of Banking or the SEC. Information in a HIPAA limited data set, used and kept as 45 CFR 164.514(e) allows, became exempt data.
What Counts as Sensitive Data Now
Section 5 renumbered the definitions in § 42-515 and rewrote the sensitive-data definition, now subdivision (39). Placed beside the prior text, the list changed in seven places:
| Element | Before July 1, 2026 | From July 1, 2026 |
|---|---|---|
| Health | Mental or physical health condition or diagnosis | Adds disability or treatment |
| Gender identity | Not listed | Status as nonbinary or transgender |
| Genetic and biometric | Processing "for the purpose of uniquely identifying an individual" | Genetic or biometric data "or information derived therefrom," with no purpose limit |
| Children | Data collected from "a known child" | Data from an individual the controller "has actual knowledge, or wilfully disregards, is a child" |
| Neural data | Not listed | Information generated by measuring central nervous system activity |
| Financial access | Not listed | Account or card number that, with any required code or credential, would allow access |
| Government ID | Not listed | Government-issued identification numbers that law does not require to be displayed |
The duties attached to sensitive data changed too. Section 9 restructured § 42-520(a) into lettered subparagraphs. Subparagraph (D) now reads that a controller shall "not process sensitive data concerning a consumer unless such processing is reasonably necessary in relation to the purposes for which such sensitive data are processed and without obtaining the consumer's consent." Subparagraph (H) is new and freestanding: a controller shall "not sell the sensitive data of a consumer without the consumer's consent." Collection is also narrowed, from data that is "adequate, relevant and reasonably necessary" to data that is "reasonably necessary and proportionate" to the disclosed purposes.
Profiling, Consumer Rights and the Privacy Notice
Section 8 rewrote § 42-518. The access right now expressly includes "any inferences about the consumer derived from such personal data" and whether the data is being used for profiling toward a significant decision. The opt-out from profiling no longer requires the decision to be "solely" automated; it reaches "any automated decision that produces any legal or similarly significant effect." Two rights are new. Subdivision (6) lets a consumer whose data fed such a decision, where feasible, question the result, learn the reason for it and review the data used, and, for housing decisions, correct the data and have the decision reevaluated. Subdivision (7) entitles a consumer to a list of the third parties to which the controller sold that consumer's data, or of all third parties to which it sold personal data if it keeps no per-consumer list. A new subsection (e) bars a controller from returning Social Security, government ID, financial account, health insurance or medical ID numbers, passwords, security answers or biometric data in an access response, and requires it instead to say with particularity that it holds them.
The same section narrowed what counts as a significant decision. Section 5 dropped "access to essential goods or services" from the definition in § 42-515(15), leaving financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunity and health care services.
The privacy notice in § 42-520(b) gained content and placement rules. It must now disclose the categories of personal data the controller sells and to whom, any processing for targeted advertising, "whether the controller collects, uses or sells personal data for the purpose of training large language models," and the month and year of its last update. It must be linked through a hyperlink containing the word "privacy" on the home page, in any app store listing and in any app's settings menu, provided in each language the controller does business in, and accessible to people with disabilities. A controller making a retroactive material change must notify affected consumers and give them a reasonable opportunity to withdraw consent.
Impact Assessments Join Data Protection Assessments
Section 11 split § 42-522 so that the heightened-risk list (targeted advertising, sale, risky profiling and sensitive data) sits in its own subsection (a), and added subsection (c): each controller that profiles to make a significant decision "shall conduct an impact assessment for such profiling." The assessment covers, to the extent reasonably known, the purpose, intended uses and deployment context; any foreseeable heightened risk of harm and the mitigating steps taken; the categories of input data and the outputs; any data used to customize the profiling; performance metrics and known limitations; transparency measures; and post-deployment monitoring and safeguards.
Subsection (g)(2) applies the impact assessment requirement to "processing activities created or generated on or after August 1, 2026," and states it is not retroactive. Data protection assessments keep their July 1, 2023 start. The Attorney General can demand either kind of assessment when relevant to an investigation; both stay confidential and exempt from the Freedom of Information Act, and disclosure does not waive privilege. A separate amendment to § 42-520(a)(1)(E) makes "any evidence, or lack of evidence, concerning proactive anti-bias testing" relevant to a claim or defense under Connecticut anti-discrimination law.
Minors' Data
The most direct change for young users sits in the core statute. Old § 42-520(a)(7) barred targeted advertising to, and sale of the data of, a consumer known to be at least 13 and under 16 "without the consumer's consent." New subparagraph (I) raises the upper age to 18 and deletes the consent words, so both practices are prohibited for 13-to-17-year-olds the controller knows or wilfully disregards are in that range.
The minors' online services provisions added by Public Act 23-56 were rewritten on the same date. As amended, § 42-529a(b)(1) prohibits a controller whose service is used by known minors from processing a minor's data for targeted advertising or sale at all, with the consent structure removed. Collecting precise geolocation now requires that it be "strictly necessary" rather than "reasonably necessary." Profiling toward a significant decision is limited to what is reasonably necessary to provide the service and still requires consent, from the minor or, under 13, a parent. Subsection (c) now prohibits, with an exception only for educational services, design features that "significantly increase, sustain or extend" a minor's use, and requires that direct messaging default to blocking unsolicited contact from unconnected adults. The definition of heightened risk of harm to minors in § 42-529 gained physical violence, severe or pervasive harassment, and sexual abuse or exploitation, and § 42-529b now requires impact assessments for services that profile minors, with harm-mitigation plans that a controller must disclose within 90 days of an Attorney General demand.
The Attorney General's 2025 report says the office issued two violation notices under the minors' provisions in their first year and relied more on information requests, and that the legislature's removal of the consent structure followed the office's advocacy.
What the Attorney General's Cure Period Now Looks Like
Public Act 25-113 did not amend § 42-525, the enforcement section. Subsection (b) required the Attorney General, where a cure was possible, to issue a notice of violation and allow 60 days before suing, but only from July 1, 2023 (October 1, 2023 for consumer health data controllers) through December 31, 2024. Since January 1, 2025, subsection (c) has let the Attorney General decide whether to offer a cure at all, weighing seven factors: the number of violations; the size and complexity of the business; the nature and extent of its processing; the likelihood of injury to the public; the safety of persons or property; whether the violation was likely caused by human or technical error; and the sensitivity of the data.
Enforcement remains exclusive to the Attorney General under § 42-525(a), and subsection (e) makes a violation an unfair trade practice under § 42-110b while excluding the private action in § 42-110g. Subsection (d) states that nothing in the Act provides a private right of action. The newly covered businesses therefore meet a statute whose cure opportunity is already discretionary on the day they come within it.
Public Act 26-64 Changes Some of the Same Words on October 1, 2026
The 2025 text is not the last word. The bill record for S.B. 4 of 2026 shows it became Public Act 26-64 and was signed on May 27, 2026. Public Act 26-64 amends §§ 42-515, 42-518, 42-520, 42-521 and 42-524 "as amended by" Public Act 25-113, each effective October 1, 2026. Three of its changes alter the text described above:
- Section 14 strikes "material" from § 42-520(a)(1)(B), so consent is required for processing for "any new purpose" that is neither reasonably necessary to nor compatible with the disclosed purposes
- Section 14 adds § 42-520(a)(3): "No controller shall sell any consumer's precise geolocation data," with no consent exception
- Section 12 rewrites the definition of publicly available information, which now excludes biometric data collected without the consumer's knowledge, genetic data the consumer did not make public, and information posted where the consumer kept a reasonable expectation of privacy
The same act adds a facial recognition signage rule to § 42-524 and creates a data broker registry, genetic testing protections and other provisions outside the Data Privacy Act. Those are separate subjects and are not covered here.
Background
For the underlying law rather than this development: Connecticut privacy law.
Frequently Asked Questions
When did Connecticut's 2025 privacy amendments take effect?
Does the Connecticut Data Privacy Act still exempt banks?
What does the amended CTDPA say about large language models?
Is there still a 60-day cure period under the CTDPA?
Did the 2026 legislative session change the CTDPA again?
Sources
Everything above is reported from these documents. Follow them to verify.
- Connecticut General Assembly, bill status for S.B. 1295 (2025 session) (June 24, 2025) statute
- Public Act No. 25-113, Substitute Senate Bill No. 1295, as enacted (June 24, 2025) statute
- Conn. Gen. Stat. chapter 743jj, 2026 Supplement (amended §§ 42-515 to 42-529d with history notes) (January 1, 2026) statute
- Conn. Gen. Stat. chapter 743jj, 2025 revision (pre-amendment text, including § 42-525) statute
- Connecticut General Assembly, bill status for S.B. 4 (2026 session) (May 27, 2026) statute
- Public Act No. 26-64, Substitute Senate Bill No. 4, An Act Concerning Consumer Privacy and Protection (May 27, 2026) statute
- Connecticut Office of the Attorney General, 2025 CTDPA Enforcement Report agency release
- Connecticut Office of the Attorney General, The Connecticut Data Privacy Act (FAQs) agency guidance
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.