Connecticut
Code/Regulations
- Connecticut Data Privacy Act (CTDPA)
- Code: Conn. Gen. Stat. §§ 42-515 to –525 (2022)
Effective Date: July 1, 2023
Details
Threshold
For-profit entities that conduct business in Connecticut or produce products and services that are intentionally targeted to Connecticut residents ("consumers") and that during the preceding calendar year fall into one of the following two categories:
(1) Processed the personal data of at least 100,000 consumers (excluding personal data processed solely to complete transactions); OR
(2) Processed the personal data of at least 25,000 consumers and derived more than 25 percent of gross revenue from the sale of personal data
Definition of "Personal Data"
Any information that is linked or reasonably linkable to an identified or identifiable individual. Does not include de-identified data or publicly available information. Personal data does not include data from people acting in an employment or commercial context.
Definition of "Sale"
Exchange of personal data for monetary or other valuable consideration by the controller to a third party
Data-Protection Assessments
Required for processing activities with a heightened risk of harm, including targeted advertising, sale of personal data, processing of sensitive data, and certain profiling
Opt-In Consent Required for Processing Sensitive Data
Consumer Rights to Confirm Processing, Request Access, Correction, Deletion & Portability
Yes
Consumer Right to Opt Out of Sale
Yes
Consumer Right to Opt Out of Targeted Ads
Yes
Consumer Right to Opt Out of Profiling
Yes
Pseudonymous Data Exempt from Consumer Requests
Yes
Appeal Rights
Yes
Universal Opt-Out Mechanism Required Recognition/Date
Yes (January 1, 2025)
Data of Minors
Process sensitive data of a known child in accordance with COPPA
Consent to sell personal data of minors 13 to 16 or process their personal data for targeted advertising
GLBA Exemption
Yes (both entity-level and data-level)
HIPAA Exemption
Yes (entity-level)
Applies/Does Not Apply to Personal Information in a Commercial or Employment Context
Nonprofit Exemption
Yes
Private Right of Action
No
Cure Period
60 Days
Cure Period Expiration
December 31, 2025
Enforcement Authority/Damages
Attorney General/up to $5,000 per violation