Foley & Lardner·PRIVACY / DATA SECURITY

Connecticut Dramatically Expands State Data Privacy Act

Businesses that collect, process, or sell personal data of Connecticut residents must act, as the expanded law adds new compliance requirements, broadens covered entity scope, and raises noncompliance penalties.

Connecticut has amended its existing Connecticut Data Privacy Act (CTDPA) to dramatically expand its scope and regulatory requirements for covered businesses. Key changes include lowered thresholds for entity coverage, new consumer rights including opt-out rights for targeted advertising and personal data sales, additional data processing and security restrictions, and a quadrupling of maximum civil penalties for noncompliance from $5,000 to $20,000 per violation. In-house counsel for businesses that handle personal data of Connecticut residents, or operate in the state, should immediately review current data practices, update privacy policies and consumer request workflows, and conduct gap analyses to align with the new rules ahead of the effective deadline.

connecticut-data-privacyctdpdaconsumer-data-rightsbusiness-compliancestate-privacy-law

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.