What marketers need to know about Connecticut privacy laws (CTDPA)
Connecticut significantly expanded its privacy law in 2026. Here's what the current version of the CTDPA means for your ad targeting and measurement strategy.
Linnea Zielinski · 12 min read
Software terms of service have a funny habit of changing after you've already agreed to them. You clicked "accept" once, and now you're bound by whatever version is currently live, whether or not anyone told you it changed. Connecticut's privacy law works a lot like that for marketers. If the last time you looked at it was 2023, you're not looking at the current version anymore.
Marketing teams absolutely need to be up-to-date on how they handle consumers' personal data. Connecticut passed a sweeping set of amendments to its data privacy laws that took effect this year, and they touch everything from who the law even applies to, to brand-new rules around AI and minors. A compliance approach built for the original privacy laws is already behind, and Connecticut isn't the only state whose privacy laws keep moving.
Key takeaways
- The Connecticut Data Privacy Act (CTDPA) now applies to businesses that process the personal data of at least 35,000 Connecticut residents a year, or that sell any amount of personal data, or that process any amount of sensitive data, regardless of consumer volume.
- Sensitive data now includes neural data, government ID numbers, financial account credentials, disability status, and transgender or nonbinary status, on top of the more familiar health, biometric, racial, religious, and sexual orientation categories.
- Businesses now have to disclose in their privacy notice whether they use or sell personal data to train large language models, a first-of-its-kind requirement among comprehensive state privacy laws.
- Targeted advertising and the sale of personal data are now flatly prohibited for consumers ages 13 to 17 when a business has actual knowledge of their age, with no consent workaround.
- Connecticut eliminated its cure period at the end of 2024, so the Attorney General can bring enforcement action without giving businesses a chance to fix a violation first.
- Additional restrictions on surveillance pricing, geolocation data sales, and data broker registration are already signed into law and will phase in through 2027.
What is the Connecticut Data Privacy Act?
The Connecticut Data Privacy Act first took effect on July 1, 2023, but the version in force today looks quite different after amendments signed in 2025 took effect on July 1, 2026. Connecticut's data privacy laws have changed more since 2023 than most other states' comprehensive consumer privacy laws have. As of now, the law applies to any business that conducts business in Connecticut, or that offers products or services targeted to Connecticut residents, and meets any one of three thresholds during the preceding calendar year:
- Processed the personal data of at least 35,000 consumers, excluding personal data processed solely for a payment transaction
- Processed any amount of consumers' sensitive data, excluding data processed solely for a payment transaction
- Offered consumers' personal data for sale in trade or commerce, in any amount
That last threshold change, tied to personal data sold rather than personal data processed overall, deserves your attention. The law used to require a business to process at least 25,000 consumers' data and derive at least 25% of gross revenue from selling personal data before this prong kicked in. Now there's no revenue percentage and no consumer minimum at all. If a business sells any amount of personal data or processes any amount of sensitive data, it's covered, full stop. The entity-level exemption that used to apply to businesses regulated under the Gramm-Leach-Bliley Act was removed too, so financial institutions that assumed they were exempt from processing personal data under the Connecticut Data Privacy Act should double check.
Consumer rights under the CTDPA
Connecticut residents get a fairly standard set of consumer rights, with a couple of Connecticut-specific wrinkles. Here's what the law grants:
- Access and correction: Consumers can confirm whether a business is processing their personal data, submit an access request, and correct inaccurate personal data.
- Deletion: Consumers can request deletion of personal data maintained about them.
- Portability: Consumers can obtain a portable copy of their personal data in a format they can use elsewhere.
- Opt-out: Consumers can opt out of the sale of personal data, targeted advertising, and profiling that produces a legal or similarly significant effect. Businesses have to recognize opt-out preference signals, like Global Privacy Control, rather than requiring a manual opt-out on every site.
The access right recently picked up an important addition: consumers now have the right to know the inferences a business has drawn about them, not just the raw personal data a business processed about them. At the same time, businesses are barred from directly disclosing certain higher-risk identifiers, like Social Security numbers or biometric data, in response to an access request. Instead, they have to notify the consumer that the data exists without handing it over directly.
What the CTDPA requires of businesses
Beyond consumer rights, businesses have a handful of standing obligations under Connecticut's data privacy laws. Data minimization means only collecting personal data that's reasonably necessary for the purpose disclosed to the consumer, and businesses need reasonable security practices to protect whatever personal data they hold. Businesses also need to honor a consumer's consent choices consistently across every channel a consumer's personal data touches, not just the one where the consumer originally gave or withheld consent.
For higher-risk processing activities, like targeted advertising, selling personal data, or profiling that carries a heightened risk of harm, businesses have to conduct data protection assessments before they start, weighing the benefit of the processing against the risk to the consumer. A newer requirement adds a separate impact assessment specifically for automated decision-making systems used to profile consumers in ways that produce a legal or similarly significant effect on the consumer, and it applies to processing activities created or generated on or after August 1, 2026. This profiling impact assessment covers the purpose of the profiling, a risk analysis, the categories of personal data used, and how the system's performance gets monitored after deployment, so it's a more involved document than a standard data protection assessment. The Connecticut Attorney General can request to review both the data protection assessments and the newer impact assessment as part of an investigation, so each needs to be documented.
Sensitive data now covers a lot more ground
Getting a consumer's opt-in consent before processing sensitive data isn't new, but what counts as sensitive data expanded significantly. The current list includes:
- Racial or ethnic origin, religious beliefs, and sexual orientation
- Consumer health data, including physical or mental health condition, diagnosis, or status
- Genetic or biometric data, or information derived from it
- Neural data, meaning information generated by measuring the activity of a consumer's central nervous system, like output from EEG devices or brain-computer interfaces
- Government-issued identification numbers and financial account credentials
- Disability or treatment status, and status as transgender or nonbinary
- Precise geolocation and personal data collected from a known child
Processing sensitive data at all, and selling any sensitive data specifically, now strictly requires prior opt-in consent, regardless of how much data is involved. For marketers, the practical takeaway is that categories like financial account details or government ID numbers, things a business might not have previously flagged as "sensitive" in the privacy sense, now carry the same consent bar as health or biometric data. (You should also be aware that pixel tracking is sometimes considered to be selling personal data.)
Marketing to minors just got a lot more restrictive
This is one of the more consequential changes for brands with a teen or young-adult audience. Connecticut used to allow targeted advertising and data sales for consumers ages 13 to 16 with opt-in consent. That's gone. The protected age range is now 13 to 17, and targeted advertising and the sale of personal data are flatly prohibited for that age group whenever a business has actual knowledge, or willfully disregards, that a consumer falls in that range. There's no consent exception. Getting a parent or the teen to say yes doesn't fix it.
Businesses are also barred from using system-design features intended to significantly increase, sustain, or extend a minor's use of an online service, and heightened data protection assessment obligations apply to any processing of a minor's personal data more broadly. If your business collects birthdate fields, runs school or campus partnerships, or otherwise ends up with actual knowledge that part of its audience is a teenager, this isn't a rule you can consent your way around.
New: disclosing AI and large language model use
Connecticut is the first comprehensive state privacy law to require this specific disclosure. Businesses now have to state in their privacy notice whether they use or sell personal data to train large language models (LLMs). This sits alongside existing disclosure requirements around profiling and targeted advertising, but it's a new category most privacy notices weren't written to address.
If your marketing or product team is feeding customer personal data into an AI tool, whether that's for training a custom model or through a vendor relationship where the vendor uses submitted data for its own model training, this disclosure requirement applies. It's worth an explicit conversation with vendors about whether personal data submitted to their platforms gets used this way, since that answer now has to show up in your own privacy notice.
Consumer health data gets its own set of rules
Connecticut added specific protections for consumer health data back in 2023, ahead of the broader 2026 amendments. A business can't sell or offer to sell consumer health data without first getting the consumer's consent, and a business can't give an employee, contractor, or processor access to consumer health data without the confidentiality protections the law requires. A business also can't use a geofence to draw a virtual boundary within 1,750 feet of a mental health facility or a reproductive or sexual health facility for the purpose of identifying, tracking, collecting data from, or sending a notification to a consumer about their consumer health data. That geofencing rule is a flat prohibition, (there's no consent workaround) and it applies specifically to consumer health data rather than personal data generally.
For marketers running location-based campaigns, that geofencing restriction should be built into your standard checklist any time a campaign involves proximity targeting near healthcare locations, since Connecticut treats it as an outright ban rather than a consent-based restriction like most of the rest of the law. Any business that qualifies as a consumer health data controller under the statute also faces this restriction regardless of whether it otherwise meets the CTDPA's general thresholds.
What's coming next, but isn't in effect yet
A second bill, signed in May 2026, adds more requirements on top of everything above, with a mix of near-term and later effective dates marketers should have on their radar:
- A ban on selling precise geolocation data takes effect October 1, 2026, joining Maryland, Virginia, and Oregon in prohibiting this specific kind of sale.
- New rules for direct-to-consumer genetic testing companies, including consent and disclosure requirements, also take effect October 1, 2026.
- Data broker registration requirements begin January 1, 2027.
- Surveillance pricing restrictions, meaning using personal data to set individualized prices, take effect later still, on July 1, 2027, and apply to retail sellers and third-party delivery services.
- New facial recognition transparency requirements are part of the same set of amendments.
None of this is optional to plan for, but the geolocation and genetic data rules land soon, while data broker registration and surveillance pricing have more runway.
What counts as a "sale" or "targeted advertising" under the CTDPA
A sale of personal data means a controller sold personal data to a third party for monetary or other valuable consideration. Targeted advertising covers ads displayed to a consumer based on personal data obtained from that consumer's activities over time and across non-affiliated services, used to predict personal aspects related to their preferences. Ads based only on a consumer's current activity on the business's own service, rather than data gathered across other sites or apps, generally fall outside that definition.
How the CTDPA affects your ad targeting and audience building
Here are a few practical shifts that follow from these restrictions, which should be reviewed alongside whatever process already handles consumer requests for your other state privacy law obligations:
- Reassess whether you're even covered. With the volume-free triggers for selling personal data or processing sensitive data, businesses that were exempt under the old thresholds may not be anymore.
- Audit your teen-facing campaigns specifically. If there's any chance your business has actual knowledge that part of an audience is 13 to 17, targeted advertising and data sales to that segment need to stop, not just switch to a consent flow.
- Check your AI and data vendor relationships. Confirm whether any vendor uses personal data you share with it to train its own models, since that now needs to be disclosed, and confirm your data processing agreement with that vendor actually says so.
- Expect gradual audience shrinkage. As Connecticut residents opt out through preference signals like Global Privacy Control, prospecting and retargeting pools built on individual-level personal data will shrink over time.
What the CTDPA means for your marketing measurement
Connecticut's amendments add more categories of personal data that require consent before they can be used for targeted advertising, which narrows what's available for individual-level ad targeting further than it already was. Measurement approaches that rely on aggregated, statistical data rather than tracking specific consumers don't carry this same exposure, since they aren't built on the personal data these laws regulate in the first place. That's part of why marketing mix modeling keeps coming up in these conversations as more states, and now more categories of data within each state, fall under consent requirements.
Connecticut isn't the only state you need to track
Compared to Colorado and Virginia, Connecticut's current thresholds cast a noticeably wider net. Colorado and Virginia both use a 100,000-consumer baseline threshold, with a lower secondary threshold tied to selling personal data. Connecticut dropped its consumer minimum to 35,000, and removed the minimum entirely for businesses that sell any personal data or process any sensitive data. A business that's exempt in Colorado or Virginia based on consumer volume alone may still be squarely covered in Connecticut.
Connecticut also removed its cure period at the end of 2024, meaning the Attorney General doesn't have to give a business a chance to fix a violation before pursuing enforcement. Virginia still offers a 30-day cure period, and Colorado's cure period expired the same way Connecticut's did. Rules like this vary enough state by state that a single compliance playbook doesn't hold up nationally.
Where Prescient comes in
As states like Connecticut keep expanding what counts as sensitive data and narrowing what marketers can do with it, the personal data available for individual-level targeting and measurement keeps shrinking. Prescient's marketing mix modeling doesn't depend on the kind of individually identifiable personal data these laws regulate. Instead, it works with your aggregated spend and performance data to show you what's actually driving revenue across your marketing mix.
That means your measurement doesn't need an overhaul every time a state passes a new amendment or adds another category to its sensitive data list. Book a demo and we'll walk you through the platform and how our model uncovers valuable insights without using any tracking data.
FAQs
Does the CTDPA apply to businesses outside Connecticut?
Yes. The CTDPA applies based on whether a business conducts business in Connecticut, or offers products or services targeted to Connecticut residents, not where the business itself is headquartered. A company based anywhere can fall under the law if it meets one of the current thresholds and reaches Connecticut residents.
What's the difference between the CTDPA and other state privacy laws, like Colorado's or Virginia's?
All three give consumers similar rights, like access, deletion, correction, and opt-out of targeted advertising and the sale of personal data, but Connecticut's Data Privacy Act now has notably broader thresholds than Colorado's or Virginia's comprehensive consumer privacy laws. Selling any amount of personal data or processing any amount of sensitive data now triggers coverage in Connecticut regardless of consumer volume, while Colorado and Virginia both still tie their lower thresholds to a 25,000-consumer minimum.
What happens if a business doesn't comply with the CTDPA?
The Connecticut Attorney General's office can investigate and bring enforcement action, and since the cure period expired at the end of 2024, businesses no longer get a chance to fix a violation before facing penalties. The Connecticut Attorney General has already issued dozens of violation notices since the law took effect, and privacy notice and opt-out preference signal compliance have both been publicly named as enforcement priorities. This isn't legal advice, and specific penalty exposure depends on the facts of a given case, so businesses with real compliance questions should talk to counsel directly.
Do small businesses have to comply with the CTDPA?
It depends far more on what kind of personal data a business processes than its size or revenue now. A small business that sells any amount of personal data, or processes any amount of sensitive data, is covered regardless of how few consumers it reaches or how much revenue it generates.
The Halo
Exclusive insights, every week.
Subscribe to The Halo for sharper marketing thinking.
You're subscribed to The Halo!
Quick question (optional): How familiar are you with MMM?
Thanks for sharing! Enjoy The Halo.
Keep reading
View allIs pixel tracking considered selling personal data? Sometimes.
Read article
Virginia privacy laws: What marketers need to know about the VCDPA
Read article
Understanding how Colorado privacy laws change your marketing measurement
Read article
What marketers need to know about California data privacy law vs GDPR and measurement
Read article
What California's data privacy law means for your marketing data
Read article
What is privacy-preserving ad measurement?
Read article