Connecticut Data Privacy Act (Conn. Gen. Stat. 42-515 et seq., as amended by P.A. 25-113)

Below is what the official text of Connecticut Data Privacy Act (Conn. Gen. Stat. 42-515 et seq., as amended by P.A. 25-113) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".

The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.

Typical situations, run through the same conditions as the check

Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.

What the official text states

QuestionWhat the official text statesSource
What it coversProtects the personal data of Connecticut consumers and binds controllers that conduct business in Connecticut or target its residents and meet the applicability tests.
Official wording
Sec. 42-516. Applicability. The provisions of sections 42-515 to 42-525, inclusive, apply to persons that:
www.cga.ct.gov
read 2026-10-06
When it applies to a businessFrom July 1, 2026 the act applies to persons that (1) conduct business in Connecticut or produce products or services targeted to Connecticut residents and, in the preceding calendar year, controlled or processed personal data of not fewer than 35,000 consumers (excluding data processed solely to complete a payment transaction); (2) control or process consumers' sensitive data (same payment exclusion); or (3) offer consumers' personal data for sale in trade or commerce.
Conditions to check: Not tested here: test (3), persons who 'offer consumers' personal data for sale in trade or commerce' (applies with no volume minimum; our question on selling or sharing data also covers sharing-only, so it is left out), so a seller of personal data can be covered even if the condition above is false. Tests (2) and (3) do not repeat 'conduct business in this state'; we test whether you have users there, which is only a proxy. Exemptions (42-517(a), as amended): government bodies, nonprofit organizations, political committees, institutions of higher education, HIPAA covered entities and business associates, tribal nation governments, air carriers, insurers and related entities, certain banks and credit unions engaged in financial activities and regulated by the Banking Department or a federal banking regulator, and certain securities agents and advisers; exempt data in 42-517(b) includes data subject to Title V of GLBA. Before July 1, 2026 the threshold was 100,000 consumers, or 25,000 consumers with more than 25 percent of gross revenue from sale of personal data.
Official wording
Conduct business in this state, or produce products or services that are targeted to residents of this state, and during the preceding calendar year controlled or processed the personal data of not fewer than thirty-five thousand consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; (2) control or process consumers' sensitive data
www.cga.ct.gov
read 2026-10-06
In force from2023-07-01
P.A. 22-15 effective July 1, 2023. P.A. 25-113 substantially amended the act (lower threshold, new duties) effective July 1, 2026, which is now in force.
Official wording
History: P.A. 22-15 effective July 1, 2023; P.A. 25-113 substantially amended provisions including by reducing threshold in Subdiv. (1) from not fewer than 100,000 consumers to not fewer than 35,000 consumers
www.cga.ct.gov
read 2026-10-06
Privacy noticeIncluded in the paid checklist. See the checklist—
Consent and opt-outIncluded in the paid checklist. See the checklist—
Rights of individualsIncluded in the paid checklist. See the checklist—
Data protection officerNot stated on the official pages we read.
the text read does not say whether a data protection officer or privacy officer must be appointed
—
Breach notificationNot stated on the official pages we read.
separate breach-notification statute not read
—
What the privacy notice must containIncluded in the paid checklist. See the checklist—

What we do not cover

These areas are outside this site, so nothing on this page says anything about them:

Check my business All laws