Connecticut Data Privacy Act 2026 Amendments: Lower Thresholds and What Changed
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
On July 1, 2026, a set of amendments to the Connecticut Data Privacy Act took effect that meaningfully widen who has to comply. The headline change is the applicability threshold dropping from 100,000 to 35,000 Connecticut consumers, plus new coverage for any business that sells personal data or processes sensitive data regardless of how many people that involves. If your company was just under the old line, you are very likely in scope now, and the guaranteed cure period that once softened enforcement is gone.
General information, not legal advice. The CTDPA has exemptions and definitions that turn on your specific facts, so confirm how the amended law applies to your business before you rely on this summary.
What changed in the Connecticut Data Privacy Act on July 1, 2026?
The 2026 amendments do several things at once, but three matter most for whether and how you handle data subject requests. The threshold fell, the scope of covered data widened, and the disclosure obligations around profiling and sensitive data grew. Here is the before-and-after at a glance.
| Provision | Before July 1, 2026 | From July 1, 2026 |
|---|---|---|
| Consumer-count threshold | 100,000 Connecticut consumers | 35,000 Connecticut consumers |
| Selling data | 25,000 consumers and revenue from sale | Covered if you sell data of any number of residents |
| Sensitive data | Counted toward thresholds | Processing sensitive data brings you in scope regardless of volume |
| Profiling disclosures | Limited | Expanded rights to information about automated profiling and its logic |
| Cure period | 60-day cure (sunset end of 2024) | No guaranteed cure; enforcement at AG discretion |
The through-line is that Connecticut moved from a law aimed at larger data operations to one that reaches ordinary mid-market and smaller companies. Cutting the threshold by nearly two-thirds, and adding volume-independent triggers for selling data and sensitive-data processing, brings in businesses that never had to think about the CTDPA before.
Who is newly covered by the CTDPA in 2026?
The clearest group is companies that sat between 35,000 and 100,000 Connecticut residents. A regional retailer, a growing SaaS product, a media site with a Connecticut readership, or a healthcare-adjacent service that processes sensitive data can all cross into scope on volume alone. The sensitive-data trigger catches a second group: any business that handles precise geolocation, health data, biometric identifiers, data revealing race or religion, or the personal data of a known child is covered even below 35,000 people. And because selling personal data of any number of residents now triggers the law, small adtech and lead-generation businesses that once flew under the threshold are in.
Remember that "consumers" counts residents whose data you process, not just customers. Website visitors tracked with analytics and advertising pixels count, so a company with only a few thousand paying Connecticut customers can easily clear 35,000 unique residents across a year. If you run paid campaigns, the same data flows that feed your automated media buying are exactly the ones that push your visitor count over the line and expose you to targeted-advertising opt-out obligations.
What rights do Connecticut consumers have?
The core rights are unchanged and match the multi-state template: Connecticut residents can confirm whether you process their personal data and access it, correct inaccuracies, delete it, and obtain a portable copy. They can opt out of the sale of their data, targeted advertising, and certain profiling, and they can appeal if you deny a request. The 2026 amendments add depth around automated decision-making, giving consumers expanded rights to understand profiling that produces significant effects, including the logic involved and, in specific contexts, the ability to have an analysis rerun after correcting inaccurate data.
Two obligations that predate the amendments still bite. Since January 1, 2025, every covered business must honor a universal opt-out signal such as Global Privacy Control, treating it as a binding opt-out of sale and targeted advertising for any browser that identifies a Connecticut resident. And the response deadline is 45 days from a verified request, extendable once by another 45 days with notice, the same clock 18 of the 20 comprehensive state laws use. Iowa runs 90 days plus 45 and Florida allows only a 15-day extension, so Connecticut's timing is the common case rather than a universal one. Our guide to universal opt-out mechanisms and Global Privacy Control covers how to detect and act on those signals.
What are the penalties, and did the cure period really go away?
Yes. Connecticut's original 60-day cure period was temporary and sunset at the end of 2024, so through 2025 and now under the amended law the attorney general enforces at its own discretion without a guaranteed opportunity to fix a violation first. Enforcement runs through the Connecticut Unfair Trade Practices Act, which carries civil penalties of up to $5,000 per willful violation, plus injunctive relief and restitution. There is no private right of action, so individuals cannot sue you directly under the CTDPA, but per-violation penalties across many mishandled requests add up quickly. The removal of a safety net is the practical story: a process that was merely risky in 2024 is now a live liability.
What should a newly covered company do first?
Start with the two things that fail most often under time pressure. First, make sure any inbound request is logged and dated the moment it arrives, because the 45-day clock starts on receipt, not when you notice. Second, make sure you can actually find a person's data when a request lands, since a single consumer's records are spread across your product database, warehouse, billing system, help desk, marketing tools, and exported files. That discovery step is where teams burn three of their four available weeks. The rest, verifying identity, redacting third-party data, drafting the response, and honoring any opt-out, is manageable once you know where the data is.
Handling CTDPA requests without a governance suite
Newly covered companies rarely have a privacy team or a six-figure budget, and they do not need one to answer requests correctly. Connecticut Data Privacy Act compliance with Obtainer works by intaking the request, running personal data discovery to find where the person's data lives across your systems, compiling one reviewable manifest, drafting a deadline-safe response, and tracking the 45-day clock and any appeal. Universal opt-out signals are captured in the intake so honoring them is part of the workflow, not a manual step. Nothing is disclosed or deleted automatically; a human reviews, redacts, and approves at a gate, so you stay in control. Obtainer helps you comply, self-serve from $49 a month, which is the level most companies newly pulled in by the 35,000 threshold actually need.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.