USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

Connecticut Privacy & Data Security Laws

Every statute below can apply to a business handling Connecticut residents' data, depending on your revenue, the number of Connecticut consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Jul 1, 2023 (SB 1295 amendment in effect since Jul 1, 2026; SB 4 amendment effective Oct 1, 2026)
Connecticut Data Privacy Act
CTDPA

A major 2025 amendment took effect July 1, 2026 and dramatically lowered the bar: it now applies at 35,000+ Connecticut residents, OR if you sell personal data of even a single resident, OR process sensitive data (health, biometric, genetic, precise geolocation, children's/teens' data, immigration status, and more) of even a single resident — the old 25%-of-revenue test is effectively gone. The amendment also added neural data, transgender/nonbinary status, and government ID numbers as new sensitive-data categories, plus a new AI-training-use disclosure duty. The same amendment eliminated CTDPA's broad entity-level GLBA exemption — it's now data-level only (GLBA-regulated data specifically, not GLBA-regulated financial institutions generally), so a GLBA-regulated company is no longer automatically exempt for its other personal data. Connecticut then amended the law a third time: SB 4 (Public Act 26-64, signed May 27, 2026, effective Oct 1, 2026) bans selling precise geolocation data, adds transparency and signage duties for on-premises facial recognition (which may only be run against the controller's own database), restricts "surveillance pricing," expands deletion rights, strengthens protections for genetic data and biological samples, and creates a separate data-broker registration regime starting Jan 1, 2027 — see the Data Broker entry for Connecticut.

Conn. Gen. Stat. §§ 42-515 to 42-525, as amended by 2025 Public Act 25-113 (SB 1295) and 2026 Public Act 26-64 (SB 4)Read statute →

Data Security & Breach Notification · 1

Varies by state
Connecticut data breach notification law
CT Breach Notification

Connecticut law separately requires a safeguards program for entities handling Social Security numbers, plus an insurance-sector data security law. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

Conn. Gen. Stat. § 36a-701bRead statute →

Consumer Health Data · 1

Jul 1, 2023 (unusually short compliance window from its Jun 26, 2023 signing)
Connecticut Data Privacy Act — consumer health data amendments
CTDPA Health Amendments

Layers a specific "consumer health data" definition (including reproductive/sexual health and gender-affirming care data) onto CTDPA, restricting its sale/processing regardless of the base law's thresholds.

Conn. Gen. Stat. §§ 42-515–42-526 (Public Act 23-56)Read statute →

Student Data Privacy · 1

Requires contracts with school districts governing student data use, security, and deletion; restricts advertising uses.

Conn. Gen. Stat. § 10-234aa et seq.Read statute →

Data Broker Registration & Duties · 1

Registration required from Jan 1, 2027; deletion mechanism phases in through Oct 1, 2028
Connecticut Data Broker Registration (SB 4 / Public Act 26-64)
CT Data Broker Law

Signed May 27, 2026 as part of Connecticut's third round of privacy amendments. From Jan 1, 2027 a data broker must register annually ($2,500 fee) to sell or license brokered personal data in Connecticut. The state must stand up a California-style centralized consumer deletion mechanism by Jul 1, 2028, with brokers required to run 45-day deletion-request cycles against it beginning Oct 1, 2028.

2026 Public Act 26-64 (SB 4), amending Conn. Gen. Stat. §§ 42-515 et seq.Read statute →