Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Conn. Gen. Stat. § 36a-701b
stage IMMINENT commencement not set
source official Connecticut statute text, Chapter 669, Connecticut General Statutes
A person who owns, licenses, or maintains computerized data including personal information must notify each affected Connecticut resident of a breach without unreasonable delay, and no later than 60 days after discovery unless federal law requires a shorter time. 'Personal information' excludes publicly available information lawfully made available to the general public from government records or widely distributed media.
Unlike CTDPA, which bars a private right of action outright, this breach-notification section deems a violation an unfair trade practice under section 42-110b, and CUTPA's own private-action provision, section 42-110g, lets any person who suffers an ascertainable loss from a practice prohibited by section 42-110b sue for damages, so a breach-notice violation carries indirect private-plaintiff exposure that the comprehensive act does not.
This provision is in force under the current codified text; the underlying research did not establish a dated original commencement, so no effective_date is recorded here.
What it asks of an app →
Comprehensive regime
CTDPA governs private-sector processing of Connecticut residents' personal data. Enacted as Public Act 22-15 (S.B. 6, 2022), effective July 1, 2023. Controller and processor duties are allocated at sections 42-515 to 42-524. S.B. 1295, enacted as Public Act 25-113 (signed June 25, 2025), substantially amended the Act, with amendments effective July 1, 2026, including a lower applicability threshold and an expanded profiling opt-out.
The base chapter as published at cga.ct.gov's 'current' text had not yet folded this Public Act in as of this review, since that page directs readers to a separate 2026 Supplement; the July 1, 2026 effective date and the amendment's substance are confirmed against the enrolled Public Act 25-113 text itself, read during review.
What it asks of an app →
Data subject rights
cite Conn. Gen. Stat. § 42-518
stage IN FORCE in force since 2023-07-01
source official Connecticut statute text, Chapter 743jj, Connecticut General Statutes
CTDPA gives a Connecticut consumer the right to confirm processing, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and qualifying profiling. A controller must respond without undue delay and no later than 45 days after receipt, with one 45-day extension available.
Public Act 25-113 (S.B. 1295, 2025 session, effective July 1, 2026) removed the 'solely automated' qualifier so the profiling opt-out and a new right to contest automated-decision outcomes reach decisions with human involvement, and its Sec. 11 (amending section 42-522) adds a new impact-assessment requirement for such profiling applying to processing activities created or generated on or after August 1, 2026, confirmed against the enrolled act's own text during review.
What it asks of an app →
Enforcement supervision
cite Conn. Gen. Stat. § 42-525
stage IN FORCE in force since 2023-07-01
source official Connecticut statute text, Chapter 743jj, Connecticut General Statutes
The Connecticut Attorney General has exclusive authority to enforce CTDPA as an unfair trade practice under section 42-110b. A cure period was mandatory (60 days) from July 1, 2023 through December 31, 2024; from January 1, 2025 it became discretionary, weighed against factors including violation count, controller size, likelihood of public injury, and data sensitivity. The chapter creates no private right of action.
What it asks of an app →
Sensitive categories
CTDPA classifies data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, consumer health data, the processing of genetic or biometric data to uniquely identify an individual, a known child's data, victim-of-crime status, and precise geolocation data as sensitive data.
'Biometric data' means data from automatic measurement of biological characteristics used to identify a person, such as a fingerprint or voiceprint, and the raw photograph or recording is excluded, but data generated from it (a faceprint, a voiceprint) is brought back inside 'biometric data' the moment it is generated to identify a specific individual.
This clawback is the material finding for Connecticut: a voiceprint or faceprint manufactured from a public-facing recording for identification purposes is covered biometric and sensitive data here.
What it asks of an app →
Social media and minors
Amends the Connecticut Data Privacy Act so social media platforms must honor a minor's request to unpublish or delete their account (effective July 1, 2024), and requires controllers offering services to known minors under 18 to use reasonable care against heightened risk of harm, including limits on targeted advertising, certain profiling, and precise geolocation collection (effective October 1, 2024).
Note and primary source →
Part of a 39 section omnibus online safety and artificial intelligence act signed June 2, 2026.
Section 39 bars covered platforms from showing a user personalized algorithmic recommendations unless the operator uses commercially reasonable and technically feasible methods to determine the user is not a minor under 18, or obtains verifiable parental consent for a minor; bars notifications to minors between 9:00 p.m. and 8:00 a.m. absent parental consent; requires protective defaults for minor accounts including a one hour per day limit on algorithmic feeds; requires deletion of age determination data; and requires annual public disclosures.
Note and primary source →