Connecticut Data Privacy Act (CTDPA) 📜
Effective Date: July 1, 2023
Enacted: May 10, 2022 (Senate Bill 6) Reuters+[Link]+12Reddit+12
📌 Who Must Comply
Applies to businesses that either:
Process the personal data of 100,000 or more Connecticut consumers in the previous
year; or
Process data on ≥25,000 consumers and derive over 25% of revenue from selling
that data
– Or any Consumer Health Data Controller, regardless of size or revenue
thresholds Reddit+[Link]+[Link]+15.
Exemptions include:
State/local governments
Nonprofits (except those processing consumer health data)
Financial institutions under GLBA
HIPAA-covered healthcare entities
Higher education institutions [Link]+[Link]+7Cookiebot+7
Consumer Rights
Connecticut residents (in a personal, non-employment context) have the right to:
Access personal data a controller holds about them
Correct inaccurate information
Delete their personal data, including data sourced from third parties
Obtain a portable copy of their personal data in a commonly-used format
Opt out of:
o Sale of personal data
o Processing for targeted advertising
o Profiling that produces legal or similarly significant effects (e.g. affecting
housing, lending, insurance)
Reddit+[Link]+12Reddit+12RedditOsano+[Link]+3Red
dit+3
⚙️Business Obligations
Controllers must publish clear privacy notices explaining data collection, categories,
purposes, rights of consumers, and how to exercise them.
They must conduct Data Protection Assessments for processing activities that pose
heightened risks, including profiling and sensitive data use
[Link]+2Reddit+2CT Insider+[Link]+1Osano+1.
🧬 Sensitive Data & Health Data Rules
Sensitive personal data (requiring opt-in consent) includes:
Race, religion, mental/physical health, sexual orientation, citizenship/immigration
status
Genetic or biometric data
Data about known minors under 13
Precise geolocation data
Consumer Health Data (as defined)
[Link]+1Usercentrics+1CookieYes+[Link]+[Link]+3
Key restrictions:
Controllers must obtain consumer consent before processing sensitive data.
Consumer Health Data Controllers may not use geofencing (e.g. around mental or
reproductive health clinics) and must secure written consent prior to selling CHD
[Link]+[Link]+5Reuters+5.
🌐 Global Opt-Out Support
Starting January 1, 2025, covered businesses must honor universal opt-out preference
signals (e.g. Global Privacy Control browser settings or extensions), so consumers can opt
out across multiple sites at once [Link]+[Link]+3CT Insider+3.
⚖️Enforcement & Penalties
Enforced by the Connecticut Attorney General, violations are treated as violations
of the Connecticut Unfair Trade Practices Act (CUTPA) Reddit+1CT Insider+1.
Businesses receive a “cure notice” and have up to 60 days to become compliant—for
example, TicketNetwork received one and later settled for $85,000 after failing to
comply CT Insider.
✅ At a Glance
Area Summary
Coverage Processing ≥ 100,000 consumers or ≥ 25% revenue from data + ≥25,000
thresholds consumers; plus all health data controllers
Consumer rights Access, correct, delete, portability, opt-out (sale, profiling, targeted ads)
Sensitive & health Opt-in only; no geofencing around health facilities; extra restrictions for
data CHD controllers
Obligations Privacy notices, data protection assessments, risk mitigation
Global opt-out
Effective from Jan 1, 2025
support
Enforcement CT AG enforces under CUTPA; cure period & civil penalties apply
🔍 In short: CTDPA is a robust, consumer-friendly privacy framework. It offers strong rights,
strict requirements for sensitive/health data, and modern opt-out mechanisms—setting
Connecticut among the leading states in U.S. consumer data privacy laws.