Connecticut to Expand Consumer Privacy Rights Starting October 1, 2026
Beginning October 1, 2026, Connecticut consumers will gain enhanced legal protections under the state’s expanding data privacy framework, according to an advisory issued by Connecticut Attorney General William Tong. The updated rules arrive alongside tighter corporate compliance thresholds, shifting the digital privacy landscape for residents and businesses operating within the state.
The Evolution of Connecticut Data Privacy Rights
Connecticut enacted the comprehensive Connecticut Data Privacy Act (CTDPA), codified under Conn. Gen. Stat. 42-515 through 42-525, which originally took effect on July 1, 2023. This legislation established foundational consumer rights, including the ability to confirm data processing, access personal records, correct inaccuracies, request data deletion, and obtain data portability.
According to compliance breakdowns from RecordingLaw, the legislative framework expanded further when Connecticut enacted SB 4 as Public Act 26-64 on May 27, 2026, setting an effective date of October 1, 2026. This latest update introduces a dedicated data broker registration program, an outright ban on selling precise geolocation data, and stringent operational rules governing facial recognition technology signage. Additionally, the amendments broaden the legal definition of publicly available information and institute personalized pricing disclosure requirements.
Lowered Thresholds and Expanded Corporate Obligations
Businesses face a significantly lower jurisdictional bar under recent legislative adjustments. Public Act 25-113 lowered the applicability threshold from the former standard of 100,000 consumers down to just 35,000 Connecticut residents. Consequently, any company processing the personal data of at least 35,000 consumers—or handling any volume of consumers while processing sensitive data or engaging in the sale of personal data—must immediately comply with statutory mandates.
Furthermore, covered entities have been required to honor Global Privacy Control (GPC) signals since January 1, 2025. This technical mandate aligns Connecticut with states like California and Colorado, which previously participated in joint enforcement sweeps targeting businesses that fail to process automated opt-out requests.
Enforcement Mechanisms and Penalties
The Office of the Attorney General maintains exclusive enforcement authority over the CTDPA. Crucially, the statutory mandatory cure period expired on January 1, 2025, meaning businesses no longer receive a statutory grace period to fix violations before facing punitive action. While the CTDPA does not contain its own standalone penalty figures, violations are prosecuted as unfair trade practices under the Connecticut Unfair Trade Practices Act (CUTPA). This mechanism permits civil penalties of up to $5,000 for each violation a court finds wilful. State enforcement momentum was underscored in July 2025 when the Attorney General resolved the state’s first data privacy settlement against TicketNetwork LLC for $85,000.

Beyond consumer profiling and tracking regulations, Connecticut data breach notification law under Conn. Gen. Stat. 36a-701b mandates that local residents receive notice within 60 days of a security incident discovery. When Social Security numbers are compromised, affected individuals must also be provided with 24 months of free credit monitoring.
As state regulators ramp up oversight heading into the final quarter of 2026, businesses that collect, monetize, or process digital footprints must continuously evaluate their data governance infrastructure to withstand state scrutiny.