Connecticut Dramatically Expands State Data Privacy Act
Businesses that collect, process, or sell personal data of Connecticut residents must act, as the expanded law adds new compliance requirements, broadens covered entity scope, and raises noncompliance penalties.
Connecticut has amended its existing Connecticut Data Privacy Act (CTDPA) to dramatically expand its scope and regulatory requirements for covered businesses. Key changes include lowered thresholds for entity coverage, new consumer rights including opt-out rights for targeted advertising and personal data sales, additional data processing and security restrictions, and a quadrupling of maximum civil penalties for noncompliance from $5,000 to $20,000 per violation. In-house counsel for businesses that handle personal data of Connecticut residents, or operate in the state, should immediately review current data practices, update privacy policies and consumer request workflows, and conduct gap analyses to align with the new rules ahead of the effective deadline.