Publication
Connecticut Data Privacy Act: 2026 Amendments
Connecticut’s consumer data privacy framework is expanding in 2026 through two separate legislative packages with staggered effective dates that will have significant impacts on many industries. The first, SB 1295,1 was enacted in June 2025 and took effect July 1, 2026. SB 1295 expands the affected class and the requirements for sensitive data, consumer rights, privacy notices, and automated decision-making. The second, SB 4,2 takes effect October 1, 2026, adding a geolocation sales ban, data broker registration requirements, surveillance pricing restrictions, facial recognition rules, and genetic data protections.3 Taken together, the changes mark a substantial expansion of Connecticut’s privacy framework.
JULY 1, 2026: SB 1295 AMENDMENTS
The SB 1295 amendments expand the scope of the law. The original Consumer Data Privacy Act (“CTDPA”)4 applied to organizations that processed the personal data of at least 100,000 Connecticut consumers, or at least 25,000 consumers where the organization derived more than 25 percent of gross revenue from data sales during a calendar year. The amendments lower the general threshold to 35,000 consumers and add two new “no-threshold” triggers: any organization that (a) processes sensitive data, or (b) sells personal data. The prior Gramm-Leach-Bliley Act (“GLBA”) exemption based on entity-type is replaced with a data-level exemption, requiring a more careful review of which data and activities are actually out of scope.
On the consumer rights side, the amendments add an individual right for consumers to obtain a list of specific third parties to which their personal data has been sold. The amendments also add new profiling rights. Under these new rights, when individuals are impacted by decisions with legal or similarly significant effects from profiling, they may request an explanation of the reasoning and review the data used in the decision-making. In housing-related decisions specifically, consumers may correct inaccurate data and have the decision re-evaluated.
Controllers5 must now expressly limit sensitive data processing to what is reasonably necessary in relation to the purposes for which such data is provided for processing and must obtain consumer consent before selling sensitive data. Privacy notices must be updated to disclose whether the controller collects, uses, or sells personal data to train large language models (“LLMs”). This happens to be a requirement Connecticut shares with Vermont. Controllers are also prohibited from selling or processing the personal data of consumers between the ages of 13 and 17 for targeted advertising.6
The amendments add a new impact assessment requirement for profiling systems used to make decisions with legal or similarly significant effects. The assessment must include disclosure of the profiling’s purpose, a risk analysis, the categories of data used, performance metrics, transparency measures, and post-deployment monitoring plans. This requirement applies to processing activities created or generated on or after August 1, 2026, and assessments may be requested by the Connecticut Attorney General.
Enforcement remains with the Connecticut Attorney General, and a business in violation of the Connecticut Personal Data Privacy Act can face civil penalties of up to $5,000 per willful violation and up to $2,500 per non-willful violation. While the Attorney General retains discretion to permit a cure period, the amendments eliminate the guaranteed 60-day cure period that existed under the original law for entities to come into compliance.
OCTOBER 1, 2026: SB 4 AND HB 5222
SB 4, as amended by HB 5222, introduces several additional requirements that take effect October 1, 2026.
The sale of any Connecticut resident’s precise geolocation data is outright prohibited.7 The prior law required consent before processing for a “material” new purpose; SB 4 removes the materiality qualifier, so consent is now required before processing for any new purpose not reasonably necessary or compatible with the original disclosed purpose.
SB 4 also establishes a data broker registration framework. Businesses that knowingly sell or license personal data of consumers with whom they have no direct relationship (“data brokers”) must register with the state and provide consumers with a single mechanism to request deletion of their data across all registered brokers. Registration requirements take effect January 1, 2027, with additional requirements phasing in through 2031.
The law also establishes new restrictions on surveillance pricing – the practice of using personal data to set individualized prices – and imposes new disclosure and consent requirements for businesses that use facial recognition technology on their premises for security, fraud prevention, and related investigative purposes. Direct-to-consumer genetic testing companies face new requirements governing consent, data retention, and third-party data sharing.
WHAT IT MEANS
The lowered applicability threshold is an immediate concern for organizations that have not previously assessed their CTDPA obligations. The shift from serving 100,000 to only 35,000 consumers now qualifies a substantial number of new businesses. The no-threshold triggers for sensitive data processing and data sales expand scope further. Organizations should revisit and compare these thresholds against 2025 data and 2026 projections before assuming they remain outside the law.
The elimination of the guaranteed cure period increases enforcement risk for organizations within scope. Under the original law, businesses had a right to fix violations before facing penalties. That safety net is gone, and organizations that are not in compliance when the Attorney General acts are no longer guaranteed an opportunity to cure before penalties attach.
For organizations already compliant with the original CTDPA, the SB 1295 amendments require targeted updates: revised privacy notices disclosing LLM training use, new consumer rights workflows for profiling decisions and data buyer lists, updated sensitive data consent flows to address the sale prohibition, new impact assessment processes for covered profiling activities, and data governance controls sufficient to enforce the minor data restriction. Existing vendor agreements should also be reviewed to confirm alignment with the amended obligations.
POTENTIAL FUTURE FRAMEWORKS
Connecticut’s 2026 amendments fit within a broader national pattern. Across the country, applicability thresholds for privacy laws are dropping and compliance requirements are expanding. States are increasingly requiring the registration of data brokers. AI-specific obligations – including LLM disclosure requirements and impact assessments – are gaining traction in state legislatures.
The geolocation sales ban and the surveillance pricing restrictions in SB 4 signal a statutory recognition of the value of all data and Connecticut’s direction on data commercialization more broadly. These provisions are not limited to sensitive data categories as traditionally defined. Indeed, they reflect an expanded view that certain uses of personal data are impermissible regardless of consent, and that certain data monetization practices may no longer be viable in Connecticut.
Connecticut’s LLM training disclosure requirement, adopted in parallel with Vermont’s disclosure requirements, is notable for appearing in two states at nearly the same time. Whether other states follow this pattern is a question businesses should be tracking as a precursor to broader adoption.
Footnotes
-
Substitute Senate Bill No. 1295; 2025 Conn. Acts No. 25-113. (Reg. Sess.)
-
Substitute Senate Bill No. 4; 2026 Conn. Acts No. 26-62 (Reg. Sess.).
-
A companion bill, HB 5222, signed June 2, 2026, amends parts of SB 4.
-
Conn. Gen. Stat. §§ 42-515 to 42-525 (2024).
-
Controllers include persons who “determine[] the purpose and means of processing personal data.” Conn. Gen. Stat. § 42-515 (2026).
-
The restriction does not apply where processing is “reasonably necessary to provide such online service, product or feature.” The law also excludes services or applications used by or under the direction of an educational entity.
-
Identifying the location of an individual to within a 1,750-foot radius. See Conn. Gen. Stat. § 42-515 (2026).
About Snell & Wilmer
Founded in 1938, Snell & Wilmer is a full-service business law firm with more than 500 attorneys practicing in 17 locations throughout the United States and in Mexico, including Phoenix and Tucson, Arizona; Los Angeles, Orange County, Palo Alto and San Diego, California; Denver, Colorado; Washington, D.C.; Boise, Idaho; Las Vegas and Reno-Tahoe, Nevada; Albuquerque, New Mexico; Portland, Oregon; Dallas, Texas; Salt Lake City, Utah; Seattle, Washington; and Los Cabos, Mexico. The firm represents clients ranging from large, publicly traded corporations to small businesses, individuals and entrepreneurs. For more information, visit swlaw.com.