Connecticut — Comprehensive Law

Connecticut Privacy Law

Correction, September 21, 2026. This page originally said Connecticut's cure period expired on December 31, 2024. Under Conn. Gen. Stat. § 42-525(c), the mandatory 60-day cure ended on that date, and from January 1, 2025 the Attorney General may offer a cure at its discretion, weighing seven factors. The page also said the Attorney General's recommended amendments had not been obtained; Public Act 26-64 has since been enacted.

Connecticut is the only state in this group that publishes an annual account of what it has actually enforced, and the record is specific. The Office of the Attorney General — the first in the country to create a standalone Privacy Section — reports 1,830 breach notifications received in 2025, 63 warning letters about notice delays, five privacy-notice sweeps, and named settlements including the first ever brought under the CTDPA. The statute it enforces has been amended repeatedly and now reaches further than the thresholds suggest: consumer health data controllers are covered regardless of size and regardless of nonprofit status, neural data counts as sensitive data, and processing sensitive data requires opt-in consent that cannot be buried in general terms of use.

The Connecticut Data Privacy Act (CTDPA)

Signed May 10, 2022 as Senate Bill 6 and in force since July 1, 2023, the CTDPA has been amended more often than any other statute in this group — by Public Act 23-56, which expanded minors’ protections effective October 1, 2024, and by the 2025 amendments that broadened its scope. The Attorney General’s office states the applicability test in three alternative branches rather than the two-branch consumer-count-and-revenue formula common elsewhere: controlling or processing the personal data of at least 35,000 consumers; controlling or processing consumers’ sensitive data at all; or offering consumers’ personal data for sale in trade or commerce. Consumer health data controllers are covered whatever their size and whatever their activities, and the nonprofit exemption does not reach them. Sensitive data includes neural data — information generated by measuring the activity of an individual’s central nervous system — consumer health data including gender-affirming and reproductive health data, status as nonbinary or transgender, and the personal data of a child under 13. Controllers have been required to honour universal opt-out preference signals since January 1, 2025, and opt-in consent is required before selling the personal data of a consumer under 16 or processing it for targeted advertising.

Effective dateJuly 1, 2023
CitationConn. Gen. Stat. § 42-515 et seq.
Enforced byConnecticut Attorney General, Privacy Section
Maximum penaltyUp to $5,000 per violation under the Connecticut Unfair Trade Practices Act
Private right of actionNo, enforcement by the state only
Right to cure60 days, mandatory through December 31, 2024; discretionary from January 1, 2025 against seven factors under § 42-525(c)

Who Must Comply

The CTDPA reaches a business that conducts business in Connecticut or produces products or services targeted to Connecticut residents, and controlled or processed the personal data of at least 35,000 consumers, excluding data processed solely to complete payment transactions, or controlled or processed consumers’ sensitive data, excluding data processed solely to complete payment transactions, or offered consumers’ personal data for sale in trade or commerce — with all consumer health data controllers covered regardless of size.

Consumer health data controllers are covered whatever their size and whether or not they are nonprofits, neural data is sensitive data, and the office publishes an annual enforcement report naming the matters it has resolved.

Consumer Rights Under the CTDPA

Residents of Connecticut can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Connecticut

Consumer health data under the CTDPA

The consumer health data provisions operate as a sectoral regime inside the comprehensive statute, on their own applicability rule. The Attorney General’s office states that they apply to all consumer health data controllers conducting business in Connecticut or producing products or services targeted to Connecticut residents, with no revenue or processing threshold, and that the nonprofit exemption does not apply to them. “Consumer health data” means data used to identify a consumer’s physical or mental health condition, diagnosis or status, and expressly includes gender-affirming health data and reproductive health data. It is sensitive data, so processing requires opt-in consent. The office lists four prohibitions: providing employees or contractors with access to consumer health data unless they are required to keep it confidential; providing any processor with consumer health data without a written contract requiring the processor to comply with the CTDPA including confidentiality; using a geofence to establish a virtual boundary around a mental health, reproductive or sexual health facility for the purpose of processing consumer health data; and selling or offering to sell consumer health data without first obtaining consent. The office reports opening an investigation into a hormonal fertility tracker application whose privacy notice failed to recognise these heightened protections, testing the application on both iOS and Android to review data flows, and sending a notice of violation and inquiry letter to a large data broker over its sensitive-data disclosures and consent processes.

Student data privacy and the Safeguards Law (Conn. Gen. Stat. §§ 42-471, 10-234aa et seq.)

The Privacy Section enforces Connecticut’s Safeguards Law at § 42-471 alongside the breach statute, and in 2025 brought the office’s first settlement under the state’s Student Data Privacy law. The office reports that the resolution was reached with California and New York, with Connecticut receiving $150,000 where 28,610 students were impacted, New York $1.7 million where 1.7 million students were impacted, and California $3.25 million where 3 million students were impacted. The office describes the matter as its first settlement involving the Student Data Privacy law and as emphasising the importance of protecting student data.

Connecticut Unfair Trade Practices Act (Conn. Gen. Stat. § 42-110a et seq.)

CUTPA supplies the remedial machinery behind the CTDPA and the breach statute alike, and the Attorney General’s Privacy Section names it among the laws it advises on together with the breach notification statute at § 36a-701b, the Safeguards Law at § 42-471, HIPAA and COPPA. The office reads CUTPA against federal practice: its 2025 report cites the federal courts’ construction of section 5 of the Federal Trade Commission Act, and applies the FTC’s Guides Concerning the Use of Endorsements and Testimonials and its Dot Com Disclosures to give content to the CTDPA’s requirement at §§ 42-520(d) and (e) that a controller engaged in targeted advertising or sale “clearly and conspicuously disclose such processing” and provide a clear and conspicuous opt-out link. On that basis the office states that it questions whether opt-out links embedded in a website footer are “obvious and on the front page”, “difficult to miss”, “easily noticeable” or “unavoidable” when a consumer must scroll to the bottom of a lengthy page to find them.

Data Breach Notification in Connecticut

Section 36a-701b(b)(1) requires notice both to the Office of the Attorney General and to Connecticut residents without unreasonable delay and not later than sixty days after discovery of the breach. The Attorney General’s Privacy Section reviews every notification received: its 2025 enforcement report records over 1,830 breach notifications that year, against 1,900 in 2024, 1,800 in 2023, over 1,500 in each of 2021 and 2022, 1,200 in 2020 and over 800 in 2019. The office states its own reading of when the clock starts, and it is the earlier of the two candidates: in the 63 warning letters it issued in 2025 about notice delays, it stressed that it views the statutory notice period as running “from the date that a company becomes aware of suspicious activity, not the date it determines the full impact to personal information”. The report also sets out what the office expects a notice letter to say — making clear why the company holds the recipient’s data and what specific personal information was compromised, and, where the notifying entity has no direct relationship with the consumer, clearly identifying how it relates to the entity that does. The Privacy Section advises on the breach statute alongside Connecticut’s Safeguards Law at § 42-471 and the Connecticut Unfair Trade Practices Act.

Residents must be notified without unreasonable delay and not later than 60 days after discovery of the breach. Notice goes to the Attorney General and to affected residents on the same 60-day clock. Complaints are taken by the Connecticut Attorney General, which enforces the statute.

How the CTDPA Is Enforced

What a CTDPA violation costs. The Attorney General's office states the figure directly: “Entities or individuals that violate the CTDPA may face civil penalties up to $5,000 per violation, pursuant to the Connecticut Unfair Trade Practices Act.” The same guidance states that in addition to civil penalties the Attorney General can seek injunctive relief and restitution. The route runs through CUTPA rather than through a penalty provision in the privacy statute itself, which is why the office describes its privacy work as spanning the CTDPA, the breach notification statute at Conn. Gen. Stat. § 36a-701b, the Safeguards Law at § 42-471 and CUTPA together, alongside the federal HIPAA and COPPA regimes.

Recent Enforcement in Connecticut

TicketNetwork, Inc. — $85,000, the first CTDPA settlement. The Attorney General’s 2025 enforcement report describes the office’s first settlement under the CTDPA. The office issued a cure notice to TicketNetwork in November 2023 flagging that its privacy notice was “inordinately unreadable, missing key data rights, and contained inoperable rights mechanisms”. The company had sixty days to cure under the statute but did not resolve the deficiencies until December 2024, well beyond the statutory cure period. Under the assurance of voluntary compliance, TicketNetwork must review its privacy notice for CTDPA compliance at least annually and on any material change to its privacy practices, and must document data rights requests from Connecticut consumers and report on them to the office. TicketNetwork paid $85,000 to the State.

Fresenius Medical Care Holdings — $116,085.30, August 2025. The office reports finalising an assurance of voluntary compliance in August 2025 with the dialysis provider Fresenius Medical Care Holdings, Inc. resolving concerns over a September 2023 data breach. Approximately 348,000 individuals were affected, including 9,483 Connecticut residents whose Social Security numbers and health information were exposed. The assurance requires a stringent information security program with new training and reporting obligations, and Fresenius made a $116,085.30 payment to the State. The office states the matter was a priority given the company’s presence in the dialysis field and the sensitivity of the data it maintains for a vulnerable population.

Omni Healthcare, Nextiva and Horne LLP — notice-delay settlements. The office has resolved a series of matters through assurances of voluntary compliance aimed specifically at delayed breach notice. In November 2025 it finalised an assurance with Omni Healthcare over a January 19, 2024 ransomware attack that Omni did not report to the office until April 9, 2025, more than fourteen months later; the breach involved exfiltration of 330 Connecticut residents’ personal information including Social Security and driver’s license numbers, and Omni paid $105,000 in addition to injunctive relief. In April 2024 it finalised an assurance with the voice-over-internet-protocol provider Nextiva Servicing LLC over a January 2020 breach not notified until September 2023, almost four years later, with a $15,000 payment. In November 2024 it finalised an assurance with the professional services firm Horne LLP over a December 2021 breach not notified until January 2024, more than two years later, also with a $15,000 payment.

Universal opt-out sweep with California and Colorado, August 2025. The office reports announcing in August 2025 a joint investigative sweep with California and Colorado flagging potential non-compliance with the CTDPA’s universal opt-out preference signal provisions, in force since January 1, 2025. It issued letters to businesses that did not appear to be processing opt-out requests for targeted advertising and the sale of personal data submitted via the Global Privacy Control, requesting immediate compliance. While stating that those matters remain ongoing, the office set out two positions: a GPC signal should trigger an opt-out across all personal data, not only data collected and shared through tracking technologies such as cookies or software development kits, and the opt-out must apply to all devices a consumer uses to log into an account the controller maintains, including mobile applications.

Pending Privacy Legislation

The CTDPA has been amended in successive sessions rather than left to settle. Public Act 23-56 expanded the protections for minors, with those provisions taking effect October 1, 2024 and carrying their own reporting mandate: the office was required to report by February 1, 2026 on the number of notices of violation issued relating to minors’ privacy and the number cured. The 2025 amendments broadened the statute’s reach, and the Attorney General’s current published applicability test states three alternative branches — 35,000 consumers, any processing of sensitive data, or offering personal data for sale — rather than the consumer-count-plus-revenue formula the Act originally carried. The legislature has since acted again: Public Act 26-64, S.B. 4 of 2026, “An Act Concerning Consumer Privacy and Protection”, was signed May 27, 2026, and its bill record lists among its purposes the registration of data brokers and a deletion mechanism to be established by the Commissioner of Consumer Protection. In its 2025 report the office had recommended two further changes: narrowing what it calls the “too-broad definition of ‘publicly available information’” so that people-search sites and data brokers are fully covered, and omitting the entity-level exemptions that do not appear in other states’ laws, including for HIPAA-covered entities and nonprofits. It also recommends that the legislature follow California in requiring browser vendors to support opt-out preference signals.

Federal Privacy Laws That Apply in Connecticut

Federal privacy law applies in Connecticut by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The CTDPA sits alongside those rules rather than displacing them: the Connecticut Attorney General, Privacy Section enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Connecticut Unfair Trade Practices Act (Conn. Gen. Stat. § 42-110a et seq.), which the Connecticut Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Connecticut Privacy Law FAQ

Does the CTDPA apply to a small business that handles health data?
The Attorney General’s office states that it does. Its published guidance provides that the CTDPA applies to all consumer health data controllers conducting business in Connecticut or producing products or services targeted to Connecticut residents, and that “[u]nlike other types of controllers, there are no revenue or processing thresholds that a Consumer Health Data Controller must meet for the law to apply.” The office also states that the nonprofit exemption does not apply to consumer health data controllers.
Is neural data regulated in Connecticut?
Yes, as sensitive data. The Attorney General’s office lists among the categories of sensitive data under the CTDPA “Neural Data – which means any information generated by measuring the activity of an individual’s central nervous system”, alongside consumer health data, genetic or biometric data, the personal data of a child under 13, precise geolocation data, and data revealing racial or ethnic origins, religious beliefs, health conditions or diagnoses, disability or treatment, sexual activity or orientation, status as nonbinary or transgender, citizenship or immigration status, certain financial account credentials and government-issued identification numbers. A controller needs the consumer’s consent to process sensitive data.
When does Connecticut’s 60-day breach clock start running?
Section 36a-701b(b)(1) requires notice to the Office of the Attorney General and to Connecticut residents without unreasonable delay and not later than sixty days after breach discovery. The office states its own position on when discovery occurs: in the 63 warning letters it issued in 2025 regarding notice delays, it stressed that it views the statutory notice period as running “from the date that a company becomes aware of suspicious activity, not the date it determines the full impact to personal information”.
Does Connecticut publish what it has enforced?
The Attorney General’s office has issued a CTDPA enforcement report covering July 1 to December 1, 2023 and annual reports for calendar years 2024 and 2025. Public Act 23-56 additionally required the office to report by February 1, 2026 on the number of notices of violation issued relating to minors’ privacy, the number of violations cured, and any other matter the Attorney General deems relevant. The 2025 report states that the office was the first in the country to create a standalone Privacy Section.
What does Connecticut expect of an opt-out link?
The Attorney General’s 2025 report reads Conn. Gen. Stat. §§ 42-520(d) and (e) — requiring a controller to “clearly and conspicuously disclose” targeted advertising or sale and to provide “a clear and conspicuous link” to an opt-out page — against the FTC’s endorsement guides and Dot Com Disclosures, under which a disclosure should be difficult to miss, easily understandable and, in an interactive electronic medium, unavoidable. On that basis the office states it questions whether opt-out links embedded in a website footer meet the standard when consumers must scroll to the bottom of a lengthy page and no visual cue encourages them to do so.
What counts as consent to process sensitive data in Connecticut?
The Attorney General’s report quotes the statutory definition — “a clear affirmative act signifying a consumer’s freely given, specific, informed and unambiguous agreement to allow the processing of personal data relating to the consumer” — and the exclusion that follows it: consent “does not include … acceptance of general or broad terms of use or a similar document that contains descriptions of personal data processing along with other, unrelated information”. The office states that a consent disclosure must identify what categories of sensitive data are collected, who they are shared with and for what specific purposes, and that a mechanism to revoke consent must be at least as easy as the one by which it was given.
How many breaches are reported to Connecticut each year?
The Attorney General’s 2025 enforcement report records over 1,830 breach notifications received that year, and gives the series for comparison: over 800 in 2019, 1,200 in 2020, over 1,500 in each of 2021 and 2022, 1,800 in 2023 and 1,900 in 2024. The office states that it reviews each notification for compliance with the state’s breach notice and data security laws and follows up on notice timelines, the protections offered to affected residents, the safeguards in place at the time and post-breach remedial measures. It separately received over 60 complaints related to data breaches in 2025 and almost 70 new CTDPA complaints since its prior reports.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.