Connecticut Data Privacy Act (Conn. Gen. Stat. 42-515 et seq., as amended by P.A. 25-113)
Below is what the official text of Connecticut Data Privacy Act (Conn. Gen. Stat. 42-515 et seq., as amended by P.A. 25-113) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Connecticut and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in Connecticut: Not triggered by these answers.
- A US business with no users in Connecticut: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Protects the personal data of Connecticut consumers and binds controllers that conduct business in Connecticut or target its residents and meet the applicability tests.Official wordingSec. 42-516. Applicability. The provisions of sections 42-515 to 42-525, inclusive, apply to persons that: | www.cga.ct.gov read 2026-10-06 |
| When it applies to a business | From July 1, 2026 the act applies to persons that (1) conduct business in Connecticut or produce products or services targeted to Connecticut residents and, in the preceding calendar year, controlled or processed personal data of not fewer than 35,000 consumers (excluding data processed solely to complete a payment transaction); (2) control or process consumers' sensitive data (same payment exclusion); or (3) offer consumers' personal data for sale in trade or commerce. Conditions to check: Not tested here: test (3), persons who 'offer consumers' personal data for sale in trade or commerce' (applies with no volume minimum; our question on selling or sharing data also covers sharing-only, so it is left out), so a seller of personal data can be covered even if the condition above is false. Tests (2) and (3) do not repeat 'conduct business in this state'; we test whether you have users there, which is only a proxy. Exemptions (42-517(a), as amended): government bodies, nonprofit organizations, political committees, institutions of higher education, HIPAA covered entities and business associates, tribal nation governments, air carriers, insurers and related entities, certain banks and credit unions engaged in financial activities and regulated by the Banking Department or a federal banking regulator, and certain securities agents and advisers; exempt data in 42-517(b) includes data subject to Title V of GLBA. Before July 1, 2026 the threshold was 100,000 consumers, or 25,000 consumers with more than 25 percent of gross revenue from sale of personal data. Official wordingConduct business in this state, or produce products or services that are targeted to residents of this state, and during the preceding calendar year controlled or processed the personal data of not fewer than thirty-five thousand consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; (2) control or process consumers' sensitive data | www.cga.ct.gov read 2026-10-06 |
| In force from | 2023-07-01 P.A. 22-15 effective July 1, 2023. P.A. 25-113 substantially amended the act (lower threshold, new duties) effective July 1, 2026, which is now in force. Official wordingHistory: P.A. 22-15 effective July 1, 2023; P.A. 25-113 substantially amended provisions including by reducing threshold in Subdiv. (1) from not fewer than 100,000 consumers to not fewer than 35,000 consumers | www.cga.ct.gov read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text read does not say whether a data protection officer or privacy officer must be appointed | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here