Law / Connecticut

Connecticut

age

Connecticut has no adult content age verification, app store, or design code law. Its 2023 privacy law amendments (SB 3, Public Act 23-56) give minors under 18 the right to have social media accounts unpublished or deleted and require reasonable care and data protection assessments for services offered to known minors, in effect since 2024.

In 2026 the state enacted SB 5 (Public Act 26-15), an omnibus online safety and artificial intelligence act whose social media provisions, effective January 1, 2028, require age determination and parental consent before minors may use personalized algorithmic feeds, restrict notification hours, and set protective defaults including a one hour per day feed limit. A narrower 2025 bill with similar provisions (HB 6857) passed the House 121 to 26 but died without a Senate vote.

privacy

The Connecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. sections 42-515 to 42-529e (Chapter 743jj), is Connecticut's comprehensive consumer-privacy regime, correcting an earlier seed citation range that undercounted the chapter's later insertions (consumer health data at section 42-526, social media and minors at section 42-528).

Enacted as Public Act 22-15, effective July 1, 2023, and substantially amended by Public Act 25-113 (S.B. 1295), with amendments effective July 1, 2026 (a profiling impact-assessment duty follows on August 1, 2026), confirmed against the enrolled act's own text during review rather than the base chapter page, which had not yet folded the Public Act in.

Genetic or biometric data collected to identify a person is one of CTDPA's enumerated sensitive-data categories, correcting the carried seed's False value on that question.

Separately, Connecticut's biometric-data definition claws back data generated from a photograph, video, or audio recording the moment that data is generated to identify a specific individual, so a faceprint or voiceprint manufactured from a public recording for identification purposes is covered biometric, and therefore sensitive, data here, unlike Virginia's or Iowa's blanket exclusion.

A separate chapter, Conn. Gen. Stat. section 36a-701b, governs breach notification; that chapter deems a violation an unfair trade practice, which pulls in CUTPA's own private right of action for a person who suffers an ascertainable loss, unlike CTDPA itself, which bars a private right of action. The CTDPA Attorney General has exclusive enforcement authority over the comprehensive act, with a cure period that was mandatory through 2024 and discretionary from 2025 onward.

11 instruments named 7 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Breach of security re computerized data containing personal information

cite Conn. Gen. Stat. § 36a-701b stage IMMINENT commencement not set source official Connecticut statute text, Chapter 669, Connecticut General Statutes

A person who owns, licenses, or maintains computerized data including personal information must notify each affected Connecticut resident of a breach without unreasonable delay, and no later than 60 days after discovery unless federal law requires a shorter time. 'Personal information' excludes publicly available information lawfully made available to the general public from government records or widely distributed media.

Unlike CTDPA, which bars a private right of action outright, this breach-notification section deems a violation an unfair trade practice under section 42-110b, and CUTPA's own private-action provision, section 42-110g, lets any person who suffers an ascertainable loss from a practice prohibited by section 42-110b sue for damages, so a breach-notice violation carries indirect private-plaintiff exposure that the comprehensive act does not.

This provision is in force under the current codified text; the underlying research did not establish a dated original commencement, so no effective_date is recorded here.

What it asks of an app

Comprehensive regime

Connecticut Data Privacy Act (CTDPA), general applicability and controller/processor duties

cite Conn. Gen. Stat. §§ 42-515, 42-524 stage IN FORCE in force since 2023-07-01 source official Connecticut statute text, Chapter 743jj, Connecticut General Statutes

CTDPA governs private-sector processing of Connecticut residents' personal data. Enacted as Public Act 22-15 (S.B. 6, 2022), effective July 1, 2023. Controller and processor duties are allocated at sections 42-515 to 42-524. S.B. 1295, enacted as Public Act 25-113 (signed June 25, 2025), substantially amended the Act, with amendments effective July 1, 2026, including a lower applicability threshold and an expanded profiling opt-out.

The base chapter as published at cga.ct.gov's 'current' text had not yet folded this Public Act in as of this review, since that page directs readers to a separate 2026 Supplement; the July 1, 2026 effective date and the amendment's substance are confirmed against the enrolled Public Act 25-113 text itself, read during review.

What it asks of an app

Data subject rights

Connecticut Data Privacy Act, consumer rights

cite Conn. Gen. Stat. § 42-518 stage IN FORCE in force since 2023-07-01 source official Connecticut statute text, Chapter 743jj, Connecticut General Statutes

CTDPA gives a Connecticut consumer the right to confirm processing, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and qualifying profiling. A controller must respond without undue delay and no later than 45 days after receipt, with one 45-day extension available.

Public Act 25-113 (S.B. 1295, 2025 session, effective July 1, 2026) removed the 'solely automated' qualifier so the profiling opt-out and a new right to contest automated-decision outcomes reach decisions with human involvement, and its Sec. 11 (amending section 42-522) adds a new impact-assessment requirement for such profiling applying to processing activities created or generated on or after August 1, 2026, confirmed against the enrolled act's own text during review.

What it asks of an app

Enforcement supervision

Connecticut Data Privacy Act, Attorney General enforcement

cite Conn. Gen. Stat. § 42-525 stage IN FORCE in force since 2023-07-01 source official Connecticut statute text, Chapter 743jj, Connecticut General Statutes

The Connecticut Attorney General has exclusive authority to enforce CTDPA as an unfair trade practice under section 42-110b. A cure period was mandatory (60 days) from July 1, 2023 through December 31, 2024; from January 1, 2025 it became discretionary, weighed against factors including violation count, controller size, likelihood of public injury, and data sensitivity. The chapter creates no private right of action.

What it asks of an app

Sensitive categories

Connecticut Data Privacy Act, sensitive data and biometric data definitions

cite Conn. Gen. Stat. § 42-515(4), (38) stage IN FORCE in force since 2023-07-01 source official Connecticut statute text, Chapter 743jj, Connecticut General Statutes

CTDPA classifies data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, consumer health data, the processing of genetic or biometric data to uniquely identify an individual, a known child's data, victim-of-crime status, and precise geolocation data as sensitive data.

'Biometric data' means data from automatic measurement of biological characteristics used to identify a person, such as a fingerprint or voiceprint, and the raw photograph or recording is excluded, but data generated from it (a faceprint, a voiceprint) is brought back inside 'biometric data' the moment it is generated to identify a specific individual.

This clawback is the material finding for Connecticut: a voiceprint or faceprint manufactured from a public-facing recording for identification purposes is covered biometric and sensitive data here.

What it asks of an app

Social media and minors

SB 3 (2023), online privacy, data and safety protections for minors

cite Conn. Gen. Stat. ch. 743jj (Public Act 23-56) stage IN FORCE in force since 2024-07-01 source official session public act text

Amends the Connecticut Data Privacy Act so social media platforms must honor a minor's request to unpublish or delete their account (effective July 1, 2024), and requires controllers offering services to known minors under 18 to use reasonable care against heightened risk of harm, including limits on targeted advertising, certain profiling, and precise geolocation collection (effective October 1, 2024).

Note and primary source

SB 5 (2026), An Act Concerning Online Safety, social media protections for minors

cite Public Act No. 26-15, Sec. 39 (2026) stage IMMINENT in force in 490 days effective 2028-01-01 source official session public act text, Connecticut General Assembly

Part of a 39 section omnibus online safety and artificial intelligence act signed June 2, 2026.

Section 39 bars covered platforms from showing a user personalized algorithmic recommendations unless the operator uses commercially reasonable and technically feasible methods to determine the user is not a minor under 18, or obtains verifiable parental consent for a minor; bars notifications to minors between 9:00 p.m. and 8:00 a.m. absent parental consent; requires protective defaults for minor accounts including a one hour per day limit on algorithmic feeds; requires deletion of age determination data; and requires annual public disclosures.

Note and primary source

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.