Connecticut Data Privacy Act Amendments Explained
TL;DR
Connecticut Data Privacy Act Amendments are the July 1, 2026 rewrite of Connecticut's consumer privacy statute: the main coverage floor drops to 35,000 residents, and businesses that process sensitive data or offer personal data for sale can be in with no volume floor.
People in Connecticut can question certain automated decisions, see the reasoning and the data used, and in some cases demand a correction and a human redo when the outcome has a legal or similarly significant effect.
Controllers must run a written impact assessment for profiling that produces those effects, but only for processing created or generated on or after August 1, 2026.
Licensed insurance entities sit on the Attorney General's exemption list; independent agencies, insurtechs, marketing vendors, clinics, and shops that handle licenses or sell lists still need a scope check.
Key Takeaways
Connecticut Data Privacy Act Amendments close the old "we only process, we do not sell" loophole by adding no-threshold triggers for sensitive data and for offering personal data for sale.
Privacy notices must say whether personal data is used or sold to train large language models, and the profiling opt-out is no longer limited to purely automated decisions.
Youth rules expand: targeted advertising and sale of personal data are banned for ages 13 through 17 when the controller has actual knowledge or willfully disregards the age.
Federal overlays still matter: GLBA, HIPAA, FCRA, and COPPA did not disappear, and the Connecticut Insurance Department still regulates carriers on a separate track.
The operational job is logging, appeal routing, and assessment files, not a slogan on a website.
Connecticut Data Privacy Act Amendments are the July 1, 2026 package of changes to the Connecticut Data Privacy Act that lower the main coverage floor from 100,000 consumers to 35,000, add no-volume triggers for sensitive data and for offering personal data for sale, and give residents the right to question, inspect, and in some cases get a person to redo automated decisions that produce a legal or similarly significant effect.
If you run a two-truck HVAC shop, a ten-person marketing agency, or a solo clinic, this is not a Hartford-only lawyer memo. The HVAC shop that copies a driver's license at the job, the agency that uploads a client CRM into an ad platform or a model-training job, and the clinic that stores visit notes now ask a different first question: what kind of data do we touch, and do we sell any of it. A regional insurance agency that never underwrites a policy still keeps marketing lists, quote logs, appointment texts, and vendor feeds; those files can pull the shop into scope even when the carrier itself is listed as exempt. The constraint that broke is the old 100,000-person wall plus the idea that processors who never sold data could sit out. As of June 2026, counsel alerts and vendor write-ups were already telling teams to re-run applicability before July 1.
What actually changed on July 1
According to the Connecticut Attorney General's CTDPA page, the original Act took effect on July 1, 2023 after Governor Ned Lamont signed Senate Bill 6 on May 10, 2022.
According to OneTrust's June 30, 2026 summary, the CTDPA has been in effect since July 2023, and the amendment package takes effect on July 1, 2026.
The consumer floor fell from 100,000 to 35,000. According to Wiley's April 27, 2026 alert, the amendments apply to entities that conduct business in Connecticut or target products or services to Connecticut residents and, during the preceding calendar year, controlled or processed personal data of at least 35,000 consumers (excluding data used solely to complete a payment), controlled or processed consumers' sensitive data, or offered consumers' personal data for sale.
OneTrust's same briefing states that the primary threshold drops from 100,000 consumers to 35,000 and that the sensitive-data and sale tests have no minimum volume. The Attorney General's current FAQ already lists those three tests on the CTDPA explainer. Payment-transaction-only data stays out of the volume and sensitive-data counts in the Wiley and Attorney General write-ups.
| Applicability test | Numeric floor | Effective date |
|---|---|---|
| Connecticut consumer personal data | 35,000 | July 1, 2026 |
| Sensitive data of consumers | 0 | July 1, 2026 |
| Personal data offered for sale | 0 | July 1, 2026 |
| Sources: Wiley; OneTrust; Connecticut Attorney General. |
That table is the whole "why now." A shop that never sold data and sat under 100,000 Connecticut records can still be in if it stores a license image, an SSN, a bank account, health notes, or neural data.
Consumer rights that now hit the quoting desk
Wiley describes new rights tied to covered automated profiling decisions: question the outcome, be informed of the reasoning, review data used, and in certain contexts correct and request reevaluation, plus a new right to a list of third parties to whom the controller sold the consumer's personal data.
OneTrust walks the same list and names lending and insurance eligibility as the kind of outcomes that now need an explainable trail. The Attorney General's FAQ already enumerates access (including inferences and whether data is used for profiling), correction, deletion, portability, the third-party sale list, and opt-outs of sale, targeted advertising, and profiling that may have a legal or other significant impact, on the CTDPA page.
Wiley also records two operational catches. Controllers may not hand back certain sensitive elements such as Social Security numbers, certain financial data, and biometric elements in response to a rights request; they confirm that the data was collected. The right to opt out of profiling now covers any covered automated profiling decision, not only decisions that are solely automated. That last change matters for a hybrid desk where a model scores a file and a person clicks approve.
This is not a blank check over hiring software. The Attorney General states that the Act does not protect an individual acting in an employment context, such as applying for a job, on the CTDPA FAQ. Treat job-applicant screening as a different statute problem unless counsel says otherwise.
A European comparison is useful for the appeal idea, not as Connecticut law. Article 22 of the GDPR gives a person the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them, with a human-intervention path in the contract and consent exceptions.
California remains the other U.S. benchmark shops already know. The California Attorney General's CCPA page still ties coverage to over $25 million in gross annual revenue, buying, selling, or sharing personal information of 100,000 or more California residents or households, or deriving 50% or more of annual revenue from selling California residents' personal information. The California Privacy Protection Agency and privacy.ca.gov are the consumer-facing counterparts. Connecticut's volume floor is now much lower than that 100,000-person CCPA leg, and Connecticut added the no-threshold sensitive-data and sale tests.
Colorado is the other 2023-era statute in the same binder. The Colorado Attorney General's CPA page dates Governor Polis's signature to July 7, 2021 and the in-force date to July 1, 2023, and it names access, deletion, correction, and opt-outs of sale, targeted advertising, and certain profiling, plus data-protection assessments and consent for sensitive data. Colorado's statute text, in Senate Bill 21-190, defines decisions that produce legal or similarly significant effects as decisions that result in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services. That list is Colorado's definition. Do not paste it into a Connecticut file as if Hartford wrote it.
| Milestone | Calendar date | Numeric rule attached |
|---|---|---|
| Original CTDPA in force | July 1, 2023 | First comprehensive CT privacy statute |
| Universal opt-out preference signals required | January 1, 2025 | Statewide honor duty |
| Connecticut Data Privacy Act Amendments in force | July 1, 2026 | 35,000-consumer floor |
| Profiling impact assessments for new processing | August 1, 2026 | Not retroactive |
| Sources: Connecticut Attorney General; Wiley; OneTrust. |
Controllers had to honor opt-out preference signals as of January 1, 2025. According to the Connecticut Attorney General's CTDPA FAQ, covered businesses must honor universal opt-out preference signals as of January 1, 2025, including through the Global Privacy Control.
GPC's own site says the signal is intended to communicate a Do Not Sell or Share request under the CCPA and similar state laws, that it is now a W3C Privacy Working Group work item, and that it reports 150 million users and honor on over 66,000 websites on globalprivacycontrol.org. Connecticut's 2025 honor duty is why a banner that ignores the header is already a live operations bug, before anyone writes the new appeal letter.
Impact assessments, LLM notices, and the August 1 line
Profiling assessments attach to processing created on or after August 1, 2026. According to Wiley, the amendments add an impact assessment requirement where controllers engage in any profiling for the purposes of making a decision that produces any legal or similarly significant effect, and that requirement applies to processing activities created or generated on or after August 1, 2026.
OneTrust repeats the same August 1 line and states that the assessment duty is not retroactive, in its 2026 amendments post. That is the honest limit: a model that has been scoring files since 2024 is not automatically pulled into the new assessment template unless the processing is created or generated on or after that date. Changing the model, the features, or the decision path after August 1 is the event that starts the clock.
Notices get more prescriptive at the same time. Wiley and OneTrust both say privacy notices must disclose whether the entity uses or sells personal data to train large language models, and Wiley adds display rules for the notice link and procedures for retroactive material changes. If your agency already dumps claim notes, call transcripts, or email threads into a model, the notice is no longer optional color. Shops that already run document extraction on applications and loss-run PDFs can attach an LLM-use flag to the same inventory instead of starting a second spreadsheet.
Voluntary federal tools sit next to the new state duty. NIST released the AI Risk Management Framework on January 26, 2023 for voluntary use, published a generative-AI profile on July 26, 2024, and on April 7, 2026 issued a concept note for an AI RMF profile on trustworthy AI in critical infrastructure. The NIST AI Resource Center is the companion library. Those documents do not satisfy Connecticut's assessment rule by themselves.
The IAPP US State AI Governance Legislation Tracker, last updated 28 April 2026 on the page we opened, exists because states are writing AI rules next to privacy rules. The IAPP US State Privacy Legislation Tracker, last updated 29 June 2026 on the page we opened, is the parallel chart for comprehensive privacy bills.
Europe's AI Act is a different animal: four risk levels, prohibitions that began in February 2025, GPAI rules that became effective in August 2025, an in-force date of 1 August 2024, and application on 2 August 2026, with high-risk system duties described as starting on 2 December 2027 on the Commission page. A Connecticut agency that never sells in the EU still does not get to ignore Hartford because Brussels has a bigger statute.
Sensitive data, youth, and the files sitting in the AMS
Sensitive data is the sleeper trigger. Wiley lists added categories including certain government identifiers such as a driver's license or passport, financial account-related elements, and Social Security numbers, a consent requirement before processing, a new "reasonably necessary" limit, and a ban on selling sensitive data without consent. OneTrust adds consumer health data and neural data to the expanded list. The Attorney General's FAQ already describes sensitive data as including racial or ethnic origin, religious beliefs, health conditions, disability, sexual orientation, citizenship or immigration status, certain financial account credentials, government-issued identification numbers, neural data, consumer health data, genetic or biometric data, personal data of a child under 13, and precise geolocation, on the CTDPA page.
That list is why a two-truck HVAC shop that photographs a license, a clinic that stores reproductive or mental-health notes, and an agency that keeps bank-draft information are in a different bucket than a shop that only stores a name and a service address. The same FAQ states that Consumer Health Data Controllers who do business in Connecticut or target Connecticut residents are covered with no size threshold, and that the nonprofit exemption does not apply to them.
Youth rules moved from opt-in to a ban. Wiley states that the protected age range expands from 13-16 to 13-17, and that targeted advertising and the sale of personal data are prohibited for that group where the controller has actual knowledge, or willfully disregards, that the consumer is at least 13 but younger than 18. OneTrust matches that description. The Attorney General's FAQ still tells readers that controllers must follow COPPA for children and that the CTDPA required opt-in consent before selling personal data or processing it for targeted advertising when the consumer is under 16, while also noting additional protections for minors under 18. Use Wiley and OneTrust for the July 2026 youth ban; treat the older opt-in sentence on the FAQ as a page that still mixes the pre-amendment rule.
COPPA itself, as summarized by the FTC children's privacy page and the COPPA Rule, applies to operators of sites or services directed to children under 13, and to operators with actual knowledge they are collecting personal information online from a child under 13. Connecticut's 13-17 advertising and sale ban sits on top of that federal under-13 rule, not in place of it.
Insurance shops: the exemption is real, the desk is not empty
The assigned reader here is insurance, so the exemption has to be on the first operational page, not a footnote. The Attorney General lists exempt entities that include financial institutions subject to the Gramm-Leach-Bliley Act, entities subject to HIPAA, insurance entities including health carriers and insurance-support organizations, banks and credit unions, and several others, on the CTDPA FAQ. The FAQ also says the Act does not apply to certain types of personal data maintained in compliance with other laws, such as data subject to Title V of GLBA, HIPAA, the Fair Credit Reporting Act, and FERPA.
That is not a hall pass for every agency website. "Insurance entity" and "insurance-support organization" are defined terms. An independent agency's marketing list, a comparative-ratal tool, a chat bot on a quote form, or a vendor that sells household lists may not be the exempt carrier. Map the legal entity before you retire the project. The Connecticut Insurance Department still licenses producers, reviews form and rate filings, and takes consumer complaints on a separate track.
Federal privacy and security rules continue even when CTDPA does not. The FTC's Gramm-Leach-Bliley page states that GLBA requires financial institutions — companies that offer consumers financial products or services like loans, financial or investment advice, or insurance — to explain their information-sharing practices and to safeguard sensitive data. The FTC Safeguards Rule guide says the Rule took effect in 2003, was amended in 2021, gained breach-notification duties in a 2023 amendment that took effect in May 2024, lists 13 example financial institutions including mortgage brokers, and notes that the FTC has exempted from certain provisions financial institutions that maintain customer information concerning fewer than 5,000 consumers.
HIPAA remains the health-plan overlay. The HHS HIPAA Privacy Rule page states that the Rule applies to health plans, health care clearinghouses, and providers who conduct certain electronic transactions, and that it gives individuals rights to examine and obtain a copy of their health records and to request corrections. A health carrier that is CTDPA-exempt is not HIPAA-exempt.
FCRA remains the adverse-action overlay. The FTC Fair Credit Reporting Act page states that users of consumer-report information for credit, insurance, or employment purposes must notify the consumer when an adverse action is taken on the basis of such reports, and it points to a revised March 2026 text of the Act. If an agency or carrier uses a consumer report to price or decline, FCRA notice duties exist whether or not CTDPA applies.
For the agency stack itself, the live comparisons on this site still matter as workflow context: Applied Epic versus Salesforce Financial Services Cloud is where intake and policy data already live, and the state of insurance automation is the map of which desks are already scripted. Retention campaigns that look like targeted advertising should be read against Agency Revolution versus Better for retention marketing. Adjacent mortgage desks that share the same CRM should look at appointment reminders, invoicing, and helpdesk the same way: each of those queues can become a rights-request or opt-out inbox.
The Privacy and Data Security Department at the Attorney General's office is the enforcement shop for CTDPA, breach notification, Social Security number rules, and the state safeguards law, and it also lists HIPAA, COPPA, and FCRA among the federal statutes it helps enforce. The Attorney General homepage is where that office publishes current actions; it is not a substitute for the CTDPA FAQ.
What a small shop actually has to wire
Start with a three-bin inventory: Connecticut consumer records that are not payment-only, any sensitive category, and any sale or offer to sell. If any bin is non-empty, assume you need a lawyer to confirm exemptions, then keep going on operations.
Second, stand up a request path that can do more than delete. The new work is "why did the model say no," "show me the inputs," and "have a person look again." That is a ticket type, a hold on the downstream letter, and a log. Teams already routing documents through US Tech Automations workflows will plug this in as a model swap and a new request type, not a rebuild of the whole agency system.
Third, freeze a copy of any profiling path you will create or generate on or after August 1, 2026, and write the impact assessment before it scores a live file. If you change a rate-assist model, a lead-score, or an eligibility screen after that date, that is new processing.
Fourth, rewrite the privacy notice. Say whether you use or sell personal data to train an LLM. Say how a person questions a decision. Honor GPC. If you run sales or customer-service agents on the same site, those agents have to read the same opt-out state the website does.
Fifth, kill youth-targeted ads and any sale of 13-17 data if you have actual knowledge or you are looking away. COPPA still owns under-13 collection.
Sixth, if you are a midsized agency with multiple producers, assign one person who owns the assessment file and the appeal queue. The FTC's small-business cybersecurity page is not a CTDPA manual, but it is the hygiene list the same shops need: a strong password of at least 12 characters, multi-factor authentication, encryption, and an incident-response plan. The NIST Cybersecurity Framework page is the voluntary CSF 2.0 companion the FTC points to. The broader FTC privacy and security hub remains the federal index for COPPA, health privacy, GLBA, FCRA, and data security.
US Tech Automations shows up here only as the place those tickets already sit: an appeal packet is another document in the same agentic workflow that already moves applications, loss runs, and producer mail.
USTA analysis
This is derivation from figures already cited, not a new survey.
| Input or derived metric | Value | Trace |
|---|---|---|
| Old consumer floor | 100,000 | Wiley; OneTrust |
| New consumer floor | 35,000 | Wiley; OneTrust; CT AG |
| Absolute drop | 65,000 | 100,000 − 35,000 |
| New floor as share of old | 35% | 35,000 / 100,000 |
| Relative reduction | 65% | 65,000 / 100,000 |
| Days from amendment date to assessment date | 31 | July 1, 2026 to August 1, 2026 |
| CCPA resident/household trigger | 100,000 | California AG |
| CT volume floor vs that CCPA leg | 35% | 35,000 / 100,000 |
| Sources for inputs: Wiley; OneTrust; Connecticut Attorney General; California Attorney General. Absolute drop, shares, day count, and the CT-vs-CCPA volume ratio are USTA arithmetic on those inputs. |
Read the 65% reduction as coverage expansion on the volume leg, not as a 65% jump in enforcement. The no-threshold sensitive-data and sale tests can bring in a shop that never gets near 35,000 Connecticut records. The 31-day gap between July 1 and August 1 is a calendar fact: rights, notices, and youth rules are live a month before the new assessment template attaches to newly created profiling. The 35% comparison to CCPA is only the volume legs; California still has the $25 million and 50% revenue tests that Connecticut did not copy.
Signal vs Speculation
Demonstrated fact, as of the pages opened for this hub: the amendments take effect July 1, 2026; the consumer floor is 35,000; sensitive-data processing and offering personal data for sale are no-threshold triggers; profiling rights include question, reason, data review, and in some cases correction and reevaluation; impact assessments apply to qualifying profiling created or generated on or after August 1, 2026 and are described as not retroactive; notices must disclose LLM training use or sale; youth advertising and sale bans cover 13-17 with an actual-knowledge or willful-disregard standard; the Attorney General lists insurance entities, GLBA institutions, and HIPAA entities among exemptions; original CTDPA go-live was July 1, 2023; universal opt-out signals were required January 1, 2025.
Our read: if those rules hold, then over the next 12 to 36 months small and mid-size shops will feel this as inbox work, not as a new regulator in the lobby. Independent agencies and insurtechs that assumed "we are insurance, so we are out" will spend 2026 and 2027 mapping whether they are actually an exempt insurance entity or just a controller with a producer license. Marketing vendors who sell household lists into Connecticut will be in on the sale trigger even at tiny volume. Clinics and any shop storing health-adjacent notes will be in on the sensitive-data trigger even at tiny volume. The August 1 assessment line will push teams to freeze old models and treat every post-August change as a new processing event, which is a change-control habit, not a science project. We do not forecast a private right of action, a dollar penalty schedule, or an Attorney General sweep against two-truck shops, because none of those figures were on the sources we opened. We do expect the appeal letter to show up first at shops that already send automated declines or price flags by email, because that is the only place a consumer can see that a machine was in the loop.
Glossary
Connecticut Data Privacy Act Amendments. The July 1, 2026 changes to Connecticut's consumer privacy statute described in this hub.
Controller. The party that decides why and how personal data is processed and that must answer consumer requests.
Processor. A vendor that handles personal data only on a controller's instructions.
Profiling. Automated processing of personal data to evaluate a person, which Connecticut now ties to extra rights and, after August 1, 2026, to impact assessments when the decision has a legal or similarly significant effect.
Sensitive data. A tighter subset of personal data, now including items such as government identifiers, SSNs, certain financial account data, health data, and neural data, that can pull a business into the law with no volume floor.
Legal or similarly significant effect. The outcome threshold for the new profiling rights and assessments; OneTrust illustrates it with lending and insurance eligibility.
Universal opt-out preference signal. A browser-level "do not sell / do not use for targeted ads" flag, including Global Privacy Control, that Connecticut controllers have had to honor since January 1, 2025.
Consumer Health Data Controller. A controller of consumer health data that, in Connecticut, can be in scope with no size threshold.
FAQs
Who is in scope after the Connecticut Data Privacy Act Amendments?
Businesses that conduct business in Connecticut or target Connecticut residents and that, in the prior calendar year, processed personal data of at least 35,000 consumers, processed sensitive data, or offered personal data for sale, subject to listed exemptions. Payment-only data is excluded from the volume and sensitive-data counts in the Wiley and Attorney General write-ups.
Do licensed insurance carriers have to run the new appeal desk?
Not automatically under CTDPA. The Attorney General lists insurance entities, including health carriers and insurance-support organizations, among exempt entities, while GLBA, HIPAA, FCRA, and the Connecticut Insurance Department continue on their own tracks. Independent agencies and vendors should confirm their own status instead of borrowing the carrier's exemption.
When do profiling impact assessments start?
They attach to qualifying profiling created or generated on or after August 1, 2026, and OneTrust states that the duty is not retroactive. Rights to question decisions, notices, youth rules, and the 35,000-consumer floor are already live on July 1, 2026.
Does this replace COPPA, HIPAA, or FCRA?
No. COPPA still governs under-13 collection, HIPAA still governs protected health information for covered entities, and FCRA still requires adverse-action notices when a consumer report is used for insurance, credit, or employment. CTDPA sits beside those statutes and carves out some of the same data.
What does a 10-person marketing agency have to change first?
Re-run scope against the 35,000, sensitive-data, and sale tests, stop selling or targeting ads to 13-17-year-olds if you know or are ignoring age, disclose any LLM training use in the notice, honor GPC, and build a path to explain and, where required, redo automated decisions that have a legal or similarly significant effect.
Can a consumer see the data a model used to decline them?
Yes, for covered automated profiling decisions, Wiley and OneTrust both describe a right to review data used and to be informed of the reasoning, with limits on returning certain sensitive elements. Build a redacted packet, not a raw database dump.
Where should we put the work if we already automate intake?
On the same canvas as the rest of the file. US Tech Automations is the workflow layer for the appeal ticket, the assessment checklist, and the notice-update task, next to the existing platform route for agentic workflows. Start at ustechautomations.com if you need the public index of those tools.
Connecticut Data Privacy Act Amendments are live law, not a draft. The shops that will feel them first are the ones that already let a model touch a quote, a lead, or a renewal, and the ones that store a license or a health note without ever selling a list. Wire the request path, the August 1 assessment gate, and the LLM line in the notice, then keep the rest of the file moving.
About the Author

Helping businesses leverage automation for operational efficiency.
Related Articles
See how AI agents fit your team
US Tech Automations builds and runs the AI agents that handle this work end to end, so your team doesn't have to.
View pricing & plans