Does the Connecticut Data Privacy Act apply to your business?
From July 1, 2026, under Public Act 25-113, the Connecticut Data Privacy Act applies to businesses targeting Connecticut residents that, in the prior year, processed the personal data of 35,000 or more consumers, processed any sensitive data regardless of volume, or offered any personal data for sale. There is no revenue threshold.
Applies to: Persons that conduct business in Connecticut or target its residents and meet any one of the three current triggers under the amended Section 42-516.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
Connecticut passed one of the early comprehensive privacy laws in 2022, and then it kept amending it. The version that matters now is the one reshaped by Public Act 25-113, which took effect on July 1, 2026. That amendment lowered the entry point sharply and added two triggers that ignore volume entirely, so a business that was comfortably outside the old law may be inside the new one.
Who the Connecticut Data Privacy Act covers
Under Conn. Gen. Stat. Section 42-516, as amended, the law applies to a person that conducts business in Connecticut, or produces products or services targeted to Connecticut residents, and that meets any one of three tests: it controlled or processed the personal data of at least 35,000 consumers in the prior year, excluding data used solely to complete a payment; or it controls or processes any consumers' sensitive data; or it offers consumers' personal data for sale in trade or commerce. There is no revenue threshold, and the second and third tests have no volume floor.
What Public Act 25-113 changed
The original test was 100,000 consumers, or 25,000 consumers plus more than 25 percent of gross revenue from selling data. Public Act 25-113 cut the main threshold to 35,000, deleted the revenue prong, and replaced it with two standalone triggers: processing any sensitive data, and offering any personal data for sale. It also widened the definition of sensitive data to include neural data, financial account numbers, and government identification numbers, and it added new exemptions for insurers, banks, and political committees.
Why the sensitive-data trigger is easy to hit
Because processing any sensitive data now brings you in, the practical bar is low. Sensitive data in Connecticut includes health data, precise geolocation, biometric data used to identify someone, data revealing race, religion, or immigration status, and data about a known child. A business that collects even a small amount of this data about Connecticut residents can be covered regardless of how many people it reaches.
Who is carved out
Section 42-517 keeps entity-level exemptions for state bodies, nonprofit organizations, institutions of higher education, national securities associations, GLBA financial institutions, HIPAA covered entities, and, from July 1, 2026, insurers and banks. The 35,000 threshold now matches Delaware's DPDPA, Maryland's MODPA, New Hampshire's Data Privacy Act, and Rhode Island's DTPPA, while the duties resemble the Colorado Privacy Act. Our comparison of privacy law thresholds by state shows how the 35,000 tier lines up against the rest, and the US state privacy laws hub ties them together.
Next step
Connecticut's any-sale and any-sensitive-data triggers mean the old habit of checking a consumer count is no longer enough. The free 2-minute Obligation Scan runs the current Section 42-516 triggers against your business and flags the notice, consent, and assessment duties that follow, so you spend your time on the obligations rather than the arithmetic.
Compliance checklist
- Determine whether you meet any of the three current triggers: 35,000 consumers, any sale of data, or any sensitive-data processing.
- Provide and maintain a clear privacy notice.
- Obtain opt-in consent before processing sensitive data, which now includes neural data and government-ID and financial-account numbers.
- Honor opt-outs, including a universal opt-out mechanism.
- Conduct data protection assessments for high-risk processing and enter data processing agreements with processors.
Sources
- Conn. Gen. Stat. § 42-516 as amended by P.A. 25-113 § 6 (effective July 1, 2026), CT General Statutes 2026 Supplement, ch. 743jj
- Connecticut Public Act No. 25-113 (Substitute Senate Bill 1295), amending the CTDPA effective July 1, 2026
Last verified: 2026-07-22
Informational, not legal advice.