Law note · Connecticut
Connecticut Data Privacy Act (CTDPA), publicly available information exemption
What it asks of an app
- Personal data that is lawfully made available through a government record or that a consumer has themselves lawfully made available to the public, including through widely distributed media, falls outside the CTDPA's definition of personal data entirely, so scraping it does not by itself trigger the Act's duties.
- If you meet the CTDPA's 100,000-consumer or 25,000-consumer-plus-25%-revenue thresholds, personal data you collect that is not publicly available in the Act's own sense still triggers the Act's business obligations, including when it feeds AI training.
- Do not assume a court will read the reasonable-basis-to-believe standard broadly; no Connecticut case has tested it.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometrics
What we found
Section 42-515(26) defines personal data to exclude de-identified data or publicly available information outright, and section 42-515(33) defines publicly available information as information that is lawfully made available through federal, state or municipal government records or widely distributed media, and that a controller has a reasonable basis to believe a consumer has lawfully made available to the general public.
Because the exclusion operates on the definition of personal data itself, most scraped public-record or publicly posted personal data falls outside the CTDPA's scope entirely, not merely outside a narrower carve-out from an otherwise-applicable duty.
The Act applies to a business conducting business in Connecticut that, in the preceding calendar year, controlled or processed the personal data of 100,000 or more consumers (excluding payment-transaction data), or 25,000 or more consumers while deriving more than 25% of gross revenue from the sale of personal data.
Separate 2026 amendments (S.B. 1295) added a right to contest automated-decision outcomes and a universal opt-out preference signal requirement, effective July 1, 2026, and a data-protection impact assessment duty for qualifying profiling activities created or generated on or after August 1, 2026; neither amendment changes the publicly-available exemption itself. How a Connecticut court would apply the reasonable-basis-to-believe standard is unlitigated. CTDPA was enacted as Public Act 22-15 and, per its own effective-date history note, took effect July 1, 2023.