Connecticut Data Privacy Act (CTDPA) Compliance: Handle Data Subject Requests on the 45-Day Deadline
The Connecticut Data Privacy Act gives Connecticut residents the right to access, correct, delete, and port their personal data, opt out of its sale and targeted advertising, and appeal a denial. As of July 1, 2026 the thresholds dropped, pulling far more companies into scope. A verified request starts a 45-day clock. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks the deadline so it does not slip.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The Connecticut Data Privacy Act (CTDPA) took effect on July 1, 2023, and a significant round of amendments took effect on July 1, 2026 that broadened who must comply. Under the amended thresholds, the CTDPA applies to a controller that conducts business in Connecticut or targets Connecticut residents and, in the prior year, controlled or processed the personal data of at least 35,000 consumers (down from 100,000), or sold personal data or processed the sensitive data of any number of residents. That lower bar brings many mid-market and smaller companies into scope for the first time. Connecticut consumers can access, correct, delete, and obtain a portable copy of their personal data, opt out of the sale of their data, targeted advertising, and certain profiling, and appeal if you deny a request. You generally must respond within 45 days, extendable once by another 45 days with notice. Since January 1, 2025, controllers must honor a universal opt-out preference signal such as Global Privacy Control, treating it as a binding opt-out of sale and targeted advertising for any browser that identifies a Connecticut resident. Enforcement rests with the Connecticut Attorney General under the Connecticut Unfair Trade Practices Act, with civil penalties of up to $5,000 per willful violation; the original 60-day cure period sunset at the end of 2024, so the Attorney General now enforces at its discretion without a guaranteed chance to cure. There is no private right of action. Obtainer handles the operational side of a CTDPA request: it intakes the request, discovers where the person's data lives across your systems, compiles a source-system manifest, drafts a deadline-safe response, and tracks the 45-day clock. Nothing is disclosed automatically; a human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so scope and exemption calls stay with your team. Self-serve from $49/mo.
Why it fits
Connecticut businesses, plus out-of-state SaaS, ecommerce, adtech, and B2B firms that target Connecticut residents and now meet the lowered CTDPA thresholds, that want discovery, drafting, appeal handling, and 45-day deadline tracking for a data subject request in one place.
Lower thresholds since July 2026
The July 1, 2026 amendments cut the trigger from 100,000 to 35,000 Connecticut consumers, and any business that sells personal data or processes sensitive data is covered regardless of volume. If you were just under the old bar, check again: many companies that were exempt in 2025 are in scope now, and the guaranteed cure period is gone.
45 days to respond, plus an appeal path
Connecticut residents can access, correct, delete, and port their data, and opt out of sale, targeted advertising, and profiling. If you deny a request they can appeal, and you must run a process for it. You have 45 days from a verified request, extendable once by 45 days. Obtainer starts the countdown, finds the data, and drafts the reply so the response and any appeal stay on schedule.
Honor GPC in the intake, not by hand
Since January 1, 2025 the CTDPA requires you to treat a Global Privacy Control signal as a binding opt-out of sale and targeted advertising. Obtainer captures universal opt-out signals in the intake so honoring them is part of the workflow rather than a manual step someone has to remember. Self-serve from $49/mo, with no five-figure floor before your first request.
More use cases
Related features
Questions
Common questions about this
Who must comply with the Connecticut Data Privacy Act in 2026?
After the July 1, 2026 amendments, a controller that conducts business in Connecticut or targets its residents and, in the prior year, processed the personal data of at least 35,000 consumers, or sold personal data or processed sensitive data of any number of residents. The old 100,000 threshold is gone, so many smaller companies are now covered. HIPAA and GLBA regulated data and certain nonprofit and government entities remain exempt.
What changed in the Connecticut Data Privacy Act on July 1, 2026?
The amendments lowered the applicability threshold from 100,000 to 35,000 Connecticut consumers, brought any business that sells data or processes sensitive data into scope regardless of volume, and expanded requirements around sensitive data, consumer health data, minors, and profiling disclosures. The practical effect is that more companies must be ready to answer data subject requests on the 45-day clock than were covered before.
What are the penalties for violating the CTDPA?
Violations are enforced by the Connecticut Attorney General as unfair trade practices under the Connecticut Unfair Trade Practices Act, with civil penalties of up to $5,000 per willful violation, plus injunctive relief and restitution. The original 60-day cure period sunset on December 31, 2024, so the Attorney General now has discretion to pursue penalties without first offering a chance to fix the issue. There is no private right of action.
Does the Connecticut Data Privacy Act require honoring Global Privacy Control?
Yes. Since January 1, 2025, every covered business must honor an opt-out preference signal such as Global Privacy Control transmitted by a consumer's browser or extension when it can reasonably identify a Connecticut resident. The signal counts as a binding opt-out of both the sale of personal data and targeted advertising, and you cannot require the consumer to create an account or provide extra information before honoring it.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.