Skip to main content
Explainer · Reviewed September 2026

What Is the Connecticut Data Privacy Act?

CTDPA covers qualifying controllers and grants access, deletion, correction, portability, and opt-out rights, subject to its current scope and exceptions. Connecticut requires covered businesses to honor qualifying universal opt-out preference signals, such as GPC, under the current law. Enforcement is exclusively by the AG. The 60-day cure period sunset on January 1, 2025.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 7, 2026

At a glance

Full name
Connecticut Data Privacy Act
Short code
CTDPA
Effective date
July 1, 2023
Response reference
45 days in this snapshot
Cure period
None recorded in this snapshot
Private right of action
No
Enforcement
Connecticut Attorney General
Penalty reference
Up to $5,000 per violation under the Connecticut Unfair Trade Practices Act

Who CTDPA applies to

A business is covered if it meets the applicability thresholds set out in Conn. Gen. Stat. §§ 42-515–42-526, as amended. The thresholds listed below are the research record for this law. Whether one or more applies depends on the current statute, its exceptions, and the business's facts; do not assume a universal threshold structure.

  • Conducts business in Connecticut or targets Connecticut residents, AND controls or processes personal data of at least 35,000 consumers (excluding data processed solely to complete a payment transaction)
  • Conducts business in Connecticut or targets Connecticut residents, AND controls or processes consumers' sensitive data (excluding data processed solely to complete a payment transaction)
  • Conducts business in Connecticut or targets Connecticut residents, AND offers consumers' personal data for sale in trade or commerce
  • Consumer health data controllers that conduct business in Connecticut or target Connecticut residents are covered regardless of the general processing or revenue thresholds

Consumer rights under CTDPA

Right to deletion, access, correction, portability

Right to opt-out via GPC universal opt-out

AG exclusive enforcement

Notable features (vs. CCPA)

As of July 1, 2026, the CTDPA lowered its general processing threshold to 35,000 consumers and also reaches qualifying sensitive-data processing and offers of personal data for sale. Covered businesses must honor qualifying universal opt-out signals such as Global Privacy Control (GPC). Current Connecticut guidance describes rights involving inferences, certain profiling, third-party sale lists, and opt-outs; it also provides additional protections for minors under 18 and opt-in protections for targeted advertising and sale involving consumers under 16. Consumer health data controllers are covered without the general thresholds. Public Acts 26-64 and 26-100 add further provisions scheduled primarily for October 1, 2026; those future provisions are not treated as operative in this snapshot.

Enforcement and penalty reference

Enforcing agency: Connecticut Attorney General

Penalty reference: Up to $5,000 per violation under the Connecticut Unfair Trade Practices Act

Cure period: The general 60-day cure right sunset on January 1, 2025, after December 31, 2024. The current enforcement authority, statutory exceptions, and facts of a matter still govern; this snapshot does not promise a particular enforcement sequence.

Private right of action: CTDPA has no private right of action. Enforcement is exclusive to the Connecticut Attorney General.

Where to file a complaint: Connecticut Attorney General

How to exercise your CTDPA rights

  1. 1

    Identify the business that holds your data. OfflistMe can help you review a provider route across 1,034 US/global workflow profiles in the 1,052-record research universe; it does not decide whether a law applies to a specific request.

  2. 2

    Submit a request to the business's designated contact using the provider's current verification instructions. Include only the information reasonably needed to match your record and check the applicable Connecticut residency, scope, exemption, and verification rules before sending.

  3. 3

    This research snapshot records a 45-day reference window for the modeled request. Confirm the current statute, request type, controller scope, extension rule, and verification date before treating it as a deadline.

  4. 4

    If the provider does not respond or disputes the request, preserve the request and response record, review the applicable exceptions, and consider the Connecticut Attorney General complaint route at https://portal.ct.gov/AG/Complaints/Consumer-Complaints. A complaint route does not itself guarantee deletion or a particular enforcement result.

Generate requests in under 60 seconds

Generate a CTDPA privacy request, $9 one-time

Review the provider route, applicable law, and information you intend to send before dispatch. You remain in control of the request and any evidence kept.

FAQ

Is the CTDPA cure period still active?+

The general cure period expired on January 1, 2025. That does not create a universal investigation or penalty schedule; check the current CTDPA, regulations, and Connecticut AG process for the facts at issue.

Do I need to be a Connecticut resident to use CTDPA?+

Yes. CTDPA covers Connecticut consumers. Non-residents rely on their home state laws or on federal/broker voluntary policies.

Official sources & citations

Compare with sibling state laws

CTDPA is one of 18 comprehensive US state privacy laws. Its closest peers by effective date, useful when tracking how this law influenced or was influenced by neighboring legislation:

Related concepts & guides