{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/connecticut",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/connecticut.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/connecticut",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/connecticut/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/connecticut/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "connecticut",
    "frontmatter": {
      "title": "Connecticut Consumer Privacy Law (CTDPA)",
      "description": "The Connecticut Data Privacy Act gives Connecticut consumers rights over their personal data and imposes notice, universal-opt-out, contracting, and consent duties on controllers above defined thresholds — it is enforced exclusively by the Attorney General, its cure period sunset at the end of 2024, and it provides no private right of action.",
      "state": "Connecticut",
      "lastReviewed": "2026-06-04",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Conn. Gen. Stat. §§ 42-515 et seq. (Connecticut Data Privacy Act)",
        "appliesTo": "Persons doing business in Connecticut (or targeting residents) that control or process the data of 100,000+ consumers a year, or 25,000+ while deriving 25%+ of gross revenue from selling data — no revenue floor; nonprofits exempt",
        "privacyPolicyRequired": "Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents",
        "privateRightOfAction": "No — the statute bars any private right of action",
        "regulator": "Connecticut Attorney General (exclusive)",
        "bottomLine": "If you meet the 100,000-consumer (or 25,000 plus data-sale) threshold in Connecticut, the CTDPA requires a privacy notice, recognition of universal opt-out signals, processor contracts, and consent for sensitive data — enforced by the Attorney General, with no consumer lawsuits and a cure period that expired at the end of 2024.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "no",
        "sensitiveDataConsent": "optIn",
        "universalOptOutSignal": "required"
      },
      "about": [
        "Connecticut Data Privacy Act CTDPA",
        "Connecticut privacy policy requirements",
        "Connecticut privacy notice contents",
        "CTDPA applicability thresholds",
        "Connecticut universal opt-out preference signal",
        "CTDPA processor contract requirements",
        "Connecticut Attorney General privacy enforcement",
        "CTDPA no private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-ctdpa-apply",
        "label": "Does the Connecticut Data Privacy Act apply to your business?",
        "heading": "Does the Connecticut Data Privacy Act apply to your business?",
        "answerText": "It depends on consumer volume, not revenue. The CTDPA applies to persons that do business in Connecticut or target its residents and, in the preceding year, controlled or processed the personal data of 100,000 or more consumers, or 25,000 or more while deriving more than 25% of gross revenue from selling personal data.",
        "sources": [
          {
            "id": "stat-516-apply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Conn. Gen. Stat. § 42-516",
            "citation": "Conn. Gen. Stat. § 42-516.",
            "url": "https://www.cga.ct.gov/current/pub/chap_743jj.htm#sec_42-516",
            "proposition": "The CTDPA applies to persons doing business in Connecticut or targeting its residents that controlled or processed the data of 100,000+ consumers, or 25,000+ while deriving over 25% of gross revenue from selling personal data.",
            "verbatimQuote": "apply to persons that conduct business in this state or persons that produce products or services that are targeted to residents of this state and that during the preceding calendar year: (1) Controlled or processed the personal data of not less than one hundred thousand consumers",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/connecticut#src-stat-516-apply"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Connecticut privacy policy contain?",
        "heading": "What must your Connecticut privacy policy contain?",
        "answerText": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed, the purpose for processing, how consumers exercise their rights, the categories of personal data shared with third parties, and the categories of those third parties.",
        "sources": [
          {
            "id": "stat-520-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Conn. Gen. Stat. § 42-520",
            "citation": "Conn. Gen. Stat. § 42-520(c).",
            "url": "https://www.cga.ct.gov/current/pub/chap_743jj.htm#sec_42-520",
            "proposition": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed, the purpose for processing, how consumers may exercise and appeal their rights, the categories of personal data shared with third parties, and the categories of those third parties.",
            "verbatimQuote": "reasonably accessible, clear and meaningful privacy notice that includes: (1) The categories of personal data processed by the controller; (2) the purpose for processing personal data; (3) how consumers may exercise their consumer rights, including how a consumer may appeal a controller's decision with regard to the consumer's request; (4) the categories of personal data that the controller shares with third parties, if any; (5) the categories of third parties, if any, with which the controller shares personal data;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/connecticut#src-stat-520-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with processors say?",
        "heading": "What must your contracts with processors say?",
        "answerText": "A contract between a controller and a processor must govern the processor's data processing on the controller's behalf — making a data processing agreement a statutory requirement, not a best practice.",
        "sources": [
          {
            "id": "stat-521-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Conn. Gen. Stat. § 42-521",
            "citation": "Conn. Gen. Stat. § 42-521(c).",
            "url": "https://www.cga.ct.gov/current/pub/chap_743jj.htm#sec_42-521",
            "proposition": "The controller-processor contract must be binding and set forth processing instructions, the nature and purpose of processing, the type of data and duration, and the parties' rights and obligations, and must require the processor to maintain confidentiality, delete or return data at the controller's direction, make available information needed to demonstrate compliance, bind subcontractors by written contract to the same obligations, and cooperate with reasonable assessments (or arrange an independent assessment).",
            "verbatimQuote": "A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller. The contract shall be binding and clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing and the rights and obligations of both parties. The contract shall also require that the processor: (1) Ensure that each person processing personal data is subject to a duty of confidentiality with respect to the data; (2) at the controller's direction, delete or return all personal data to the controller as requested at the end of the provision of services, unless retention of the personal data is required by law; (3) upon the reasonable request of the controller, make available to the controller all information in its possession necessary to demonstrate the processor's compliance with the obligations in sections 42-515 to 42-525 , inclusive; (4) after providing the controller an opportunity to object, engage any subcontractor pursuant to a written contract that requires the subcontractor to meet the obligations of the processor with respect to the personal data; and (5) allow, and cooperate with, reasonable assessments by the controller or the controller's designated assessor, or the processor may arrange for a qualified and independent assessor to conduct an assessment of the processor's policies and technical and organizational measures in support of the obligations under sections 42-515 to 42-525 , inclusive, using an appropriate and accepted control standard or framework and assessment procedure for such assessments. The processor shall provide a report of such assessment to the controller upon request.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/connecticut#src-stat-521-contract"
          }
        ]
      },
      {
        "slug": "universal-opt-out",
        "label": "Must you honor a universal opt-out signal?",
        "heading": "Must you honor a universal opt-out signal?",
        "answerText": "Yes. Since January 1, 2025, a controller must let consumers opt out of targeted advertising and the sale of their personal data through an opt-out preference signal — a browser- or device-level mechanism such as the Global Privacy Control — not just a website link.",
        "sources": [
          {
            "id": "stat-520-uoom",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Conn. Gen. Stat. § 42-520",
            "citation": "Conn. Gen. Stat. § 42-520(e).",
            "url": "https://www.cga.ct.gov/current/pub/chap_743jj.htm#sec_42-520",
            "proposition": "By January 1, 2025, a controller must allow consumers to opt out of targeted advertising and the sale of personal data through an opt-out preference signal sent by a platform, technology, or mechanism.",
            "verbatimQuote": "Not later than January 1, 2025, allowing a consumer to opt out of any processing of the consumer's personal data for the purposes of targeted advertising, or any sale of such personal data, through an opt-out preference signal sent, with such consumer's consent, by a platform, technology or mechanism to the controller indicating such consumer's intent to opt out of any such processing or sale.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/connecticut#src-stat-520-uoom"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business under the CTDPA?",
        "heading": "Can a consumer sue your business under the CTDPA?",
        "answerText": "No. The CTDPA states that nothing in it provides a basis for a private right of action, so consumers cannot sue under it. Enforcement belongs to the Connecticut Attorney General, who treats violations as unfair trade practices.",
        "sources": [
          {
            "id": "stat-525-nopra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Conn. Gen. Stat. § 42-525",
            "citation": "Conn. Gen. Stat. § 42-525(d).",
            "url": "https://www.cga.ct.gov/current/pub/chap_743jj.htm#sec_42-525",
            "proposition": "The CTDPA bars any private right of action for its violation.",
            "verbatimQuote": "Nothing in sections 42-515 to 42-524 , inclusive, or section 42-526 , shall be construed as providing the basis for, or be subject to, a private right of action for violations of said sections or any other law.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/connecticut#src-stat-525-nopra"
          },
          {
            "id": "stat-525-cure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Conn. Gen. Stat. § 42-525",
            "citation": "Conn. Gen. Stat. § 42-525(b).",
            "url": "https://www.cga.ct.gov/current/pub/chap_743jj.htm#sec_42-525",
            "proposition": "The CTDPA's mandatory notice-and-cure period ran only from July 1, 2023 through December 31, 2024.",
            "verbatimQuote": "During the period beginning on July 1, 2023, and ending on December 31, 2024, the Attorney General shall, prior to initiating any action for a violation of any provision of sections 42-515 to 42-524 , inclusive, issue a notice of violation to the controller if the Attorney General determines that a cure is possible.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/connecticut#src-stat-525-cure"
          }
        ]
      }
    ]
  }
}
