Connecticut Privacy Law
Correction, September 21, 2026. This page originally said Connecticut's cure period expired on December 31, 2024. Under Conn. Gen. Stat. § 42-525(c), the mandatory 60-day cure ended on that date, and from January 1, 2025 the Attorney General may offer a cure at its discretion, weighing seven factors. The page also said the Attorney General's recommended amendments had not been obtained; Public Act 26-64 has since been enacted.
Connecticut is the only state in this group that publishes an annual account of what it has actually enforced, and the record is specific. The Office of the Attorney General — the first in the country to create a standalone Privacy Section — reports 1,830 breach notifications received in 2025, 63 warning letters about notice delays, five privacy-notice sweeps, and named settlements including the first ever brought under the CTDPA. The statute it enforces has been amended repeatedly and now reaches further than the thresholds suggest: consumer health data controllers are covered regardless of size and regardless of nonprofit status, neural data counts as sensitive data, and processing sensitive data requires opt-in consent that cannot be buried in general terms of use.
The Connecticut Data Privacy Act (CTDPA)
Signed May 10, 2022 as Senate Bill 6 and in force since July 1, 2023, the CTDPA has been amended more often than any other statute in this group — by Public Act 23-56, which expanded minors’ protections effective October 1, 2024, and by the 2025 amendments that broadened its scope. The Attorney General’s office states the applicability test in three alternative branches rather than the two-branch consumer-count-and-revenue formula common elsewhere: controlling or processing the personal data of at least 35,000 consumers; controlling or processing consumers’ sensitive data at all; or offering consumers’ personal data for sale in trade or commerce. Consumer health data controllers are covered whatever their size and whatever their activities, and the nonprofit exemption does not reach them. Sensitive data includes neural data — information generated by measuring the activity of an individual’s central nervous system — consumer health data including gender-affirming and reproductive health data, status as nonbinary or transgender, and the personal data of a child under 13. Controllers have been required to honour universal opt-out preference signals since January 1, 2025, and opt-in consent is required before selling the personal data of a consumer under 16 or processing it for targeted advertising.
| Effective date | July 1, 2023 |
|---|---|
| Citation | Conn. Gen. Stat. § 42-515 et seq. |
| Enforced by | Connecticut Attorney General, Privacy Section |
| Maximum penalty | Up to $5,000 per violation under the Connecticut Unfair Trade Practices Act |
| Private right of action | No, enforcement by the state only |
| Right to cure | 60 days, mandatory through December 31, 2024; discretionary from January 1, 2025 against seven factors under § 42-525(c) |
Who Must Comply
The CTDPA reaches a business that conducts business in Connecticut or produces products or services targeted to Connecticut residents, and controlled or processed the personal data of at least 35,000 consumers, excluding data processed solely to complete payment transactions, or controlled or processed consumers’ sensitive data, excluding data processed solely to complete payment transactions, or offered consumers’ personal data for sale in trade or commerce — with all consumer health data controllers covered regardless of size.
Consumer health data controllers are covered whatever their size and whether or not they are nonprofits, neural data is sensitive data, and the office publishes an annual enforcement report naming the matters it has resolved.
Consumer Rights Under the CTDPA
Residents of Connecticut can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Connecticut
Consumer health data under the CTDPA
The consumer health data provisions operate as a sectoral regime inside the comprehensive statute, on their own applicability rule. The Attorney General’s office states that they apply to all consumer health data controllers conducting business in Connecticut or producing products or services targeted to Connecticut residents, with no revenue or processing threshold, and that the nonprofit exemption does not apply to them. “Consumer health data” means data used to identify a consumer’s physical or mental health condition, diagnosis or status, and expressly includes gender-affirming health data and reproductive health data. It is sensitive data, so processing requires opt-in consent. The office lists four prohibitions: providing employees or contractors with access to consumer health data unless they are required to keep it confidential; providing any processor with consumer health data without a written contract requiring the processor to comply with the CTDPA including confidentiality; using a geofence to establish a virtual boundary around a mental health, reproductive or sexual health facility for the purpose of processing consumer health data; and selling or offering to sell consumer health data without first obtaining consent. The office reports opening an investigation into a hormonal fertility tracker application whose privacy notice failed to recognise these heightened protections, testing the application on both iOS and Android to review data flows, and sending a notice of violation and inquiry letter to a large data broker over its sensitive-data disclosures and consent processes.
Student data privacy and the Safeguards Law (Conn. Gen. Stat. §§ 42-471, 10-234aa et seq.)
The Privacy Section enforces Connecticut’s Safeguards Law at § 42-471 alongside the breach statute, and in 2025 brought the office’s first settlement under the state’s Student Data Privacy law. The office reports that the resolution was reached with California and New York, with Connecticut receiving $150,000 where 28,610 students were impacted, New York $1.7 million where 1.7 million students were impacted, and California $3.25 million where 3 million students were impacted. The office describes the matter as its first settlement involving the Student Data Privacy law and as emphasising the importance of protecting student data.
Connecticut Unfair Trade Practices Act (Conn. Gen. Stat. § 42-110a et seq.)
CUTPA supplies the remedial machinery behind the CTDPA and the breach statute alike, and the Attorney General’s Privacy Section names it among the laws it advises on together with the breach notification statute at § 36a-701b, the Safeguards Law at § 42-471, HIPAA and COPPA. The office reads CUTPA against federal practice: its 2025 report cites the federal courts’ construction of section 5 of the Federal Trade Commission Act, and applies the FTC’s Guides Concerning the Use of Endorsements and Testimonials and its Dot Com Disclosures to give content to the CTDPA’s requirement at §§ 42-520(d) and (e) that a controller engaged in targeted advertising or sale “clearly and conspicuously disclose such processing” and provide a clear and conspicuous opt-out link. On that basis the office states that it questions whether opt-out links embedded in a website footer are “obvious and on the front page”, “difficult to miss”, “easily noticeable” or “unavoidable” when a consumer must scroll to the bottom of a lengthy page to find them.
Data Breach Notification in Connecticut
Section 36a-701b(b)(1) requires notice both to the Office of the Attorney General and to Connecticut residents without unreasonable delay and not later than sixty days after discovery of the breach. The Attorney General’s Privacy Section reviews every notification received: its 2025 enforcement report records over 1,830 breach notifications that year, against 1,900 in 2024, 1,800 in 2023, over 1,500 in each of 2021 and 2022, 1,200 in 2020 and over 800 in 2019. The office states its own reading of when the clock starts, and it is the earlier of the two candidates: in the 63 warning letters it issued in 2025 about notice delays, it stressed that it views the statutory notice period as running “from the date that a company becomes aware of suspicious activity, not the date it determines the full impact to personal information”. The report also sets out what the office expects a notice letter to say — making clear why the company holds the recipient’s data and what specific personal information was compromised, and, where the notifying entity has no direct relationship with the consumer, clearly identifying how it relates to the entity that does. The Privacy Section advises on the breach statute alongside Connecticut’s Safeguards Law at § 42-471 and the Connecticut Unfair Trade Practices Act.
Residents must be notified without unreasonable delay and not later than 60 days after discovery of the breach. Notice goes to the Attorney General and to affected residents on the same 60-day clock. Complaints are taken by the Connecticut Attorney General, which enforces the statute.
How the CTDPA Is Enforced
What a CTDPA violation costs. The Attorney General's office states the figure directly: “Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation, pursuant to the Connecticut Unfair Trade Practices Act.” The same guidance states that in addition to civil penalties the Attorney General can seek injunctive relief and restitution. The route runs through CUTPA rather than through a penalty provision in the privacy statute itself, which is why the office describes its privacy work as spanning the CTDPA, the breach notification statute at Conn. Gen. Stat. § 36a-701b, the Safeguards Law at § 42-471 and CUTPA together, alongside the federal HIPAA and COPPA regimes.
Recent Enforcement in Connecticut
TicketNetwork, Inc. — $85,000, the first CTDPA settlement. The Attorney General’s 2025 enforcement report describes the office’s first settlement under the CTDPA. The office issued a cure notice to TicketNetwork in November 2023 flagging that its privacy notice was “inordinately unreadable, missing key data rights, and contained inoperable rights mechanisms”. The company had sixty days to cure under the statute but did not resolve the deficiencies until December 2024, well beyond the statutory cure period. Under the assurance of voluntary compliance, TicketNetwork must review its privacy notice for CTDPA compliance at least annually and on any material change to its privacy practices, and must document data rights requests from Connecticut consumers and report on them to the office. TicketNetwork paid $85,000 to the State.
Fresenius Medical Care Holdings — $116,085.30, August 2025. The office reports finalising an assurance of voluntary compliance in August 2025 with the dialysis provider Fresenius Medical Care Holdings, Inc. resolving concerns over a September 2023 data breach. Approximately 348,000 individuals were affected, including 9,483 Connecticut residents whose Social Security numbers and health information were exposed. The assurance requires a stringent information security program with new training and reporting obligations, and Fresenius made a $116,085.30 payment to the State. The office states the matter was a priority given the company’s presence in the dialysis field and the sensitivity of the data it maintains for a vulnerable population.
Omni Healthcare, Nextiva and Horne LLP — notice-delay settlements. The office has resolved a series of matters through assurances of voluntary compliance aimed specifically at delayed breach notice. In November 2025 it finalised an assurance with Omni Healthcare over a January 19, 2024 ransomware attack that Omni did not report to the office until April 9, 2025, more than fourteen months later; the breach involved exfiltration of 330 Connecticut residents’ personal information including Social Security and driver’s license numbers, and Omni paid $105,000 in addition to injunctive relief. In April 2024 it finalised an assurance with the voice-over-internet-protocol provider Nextiva Servicing LLC over a January 2020 breach not notified until September 2023, almost four years later, with a $15,000 payment. In November 2024 it finalised an assurance with the professional services firm Horne LLP over a December 2021 breach not notified until January 2024, more than two years later, also with a $15,000 payment.
Universal opt-out sweep with California and Colorado, August 2025. The office reports announcing in August 2025 a joint investigative sweep with California and Colorado flagging potential non-compliance with the CTDPA’s universal opt-out preference signal provisions, in force since January 1, 2025. It issued letters to businesses that did not appear to be processing opt-out requests for targeted advertising and the sale of personal data submitted via the Global Privacy Control, requesting immediate compliance. While stating that those matters remain ongoing, the office set out two positions: a GPC signal should trigger an opt-out across all personal data, not only data collected and shared through tracking technologies such as cookies or software development kits, and the opt-out must apply to all devices a consumer uses to log into an account the controller maintains, including mobile applications.
Pending Privacy Legislation
The CTDPA has been amended in successive sessions rather than left to settle. Public Act 23-56 expanded the protections for minors, with those provisions taking effect October 1, 2024 and carrying their own reporting mandate: the office was required to report by February 1, 2026 on the number of notices of violation issued relating to minors’ privacy and the number cured. The 2025 amendments broadened the statute’s reach, and the Attorney General’s current published applicability test states three alternative branches — 35,000 consumers, any processing of sensitive data, or offering personal data for sale — rather than the consumer-count-plus-revenue formula the Act originally carried. The legislature has since acted again: Public Act 26-64, S.B. 4 of 2026, “An Act Concerning Consumer Privacy and Protection”, was signed May 27, 2026, and its bill record lists among its purposes the registration of data brokers and a deletion mechanism to be established by the Commissioner of Consumer Protection. In its 2025 report the office had recommended two further changes: narrowing what it calls the “too-broad definition of ‘publicly available information’” so that people-search sites and data brokers are fully covered, and omitting the entity-level exemptions that do not appear in other states’ laws, including for HIPAA-covered entities and nonprofits. It also recommends that the legislature follow California in requiring browser vendors to support opt-out preference signals.
Federal Privacy Laws That Apply in Connecticut
Federal privacy law applies in Connecticut by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The CTDPA sits alongside those rules rather than displacing them: the Connecticut Attorney General, Privacy Section enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Connecticut Unfair Trade Practices Act (Conn. Gen. Stat. § 42-110a et seq.), which the Connecticut Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Connecticut Privacy Law FAQ
Does the CTDPA apply to a small business that handles health data?
Is neural data regulated in Connecticut?
When does Connecticut’s 60-day breach clock start running?
Does Connecticut publish what it has enforced?
What does Connecticut expect of an opt-out link?
What counts as consent to process sensitive data in Connecticut?
How many breaches are reported to Connecticut each year?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Connecticut Attorney General — The Connecticut Data Privacy Act (FAQs and universal opt-out resources) agency guidance
- Connecticut Attorney General — CTDPA Enforcement Report, calendar year 2025 agency
- Conn. Gen. Stat. chapter 743jj, including § 42-525 (enforcement and cure period) statute
- Connecticut S.B. 4 (2026), Public Act 26-64: bill status legislation
- Connecticut Attorney General — CTDPA Enforcement Report, calendar year 2024 agency
- Connecticut Attorney General — CTDPA Enforcement Report, July 1 to December 1, 2023 agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.