A data visualization dashboard on a computer monitor showing analytical charts, the kind of consumer data practice the Connecticut amendments are designed to constrain
Photo via Unsplash

TL;DR: Connecticut's Data Privacy Act (CTDPA) amendments take effect July 1, 2026, and they meaningfully expand who the law covers and what it lets you do about your data. The applicability threshold drops from 100,000 consumers to 35,000, which pulls tens of thousands of small and mid-sized businesses under state privacy law for the first time. The definition of "sensitive data" expands to cover driver's license numbers, passport numbers, financial account details, and Social Security numbers, and selling that data now requires opt-in consent. Consumers gain a new right to a list of every third party their data was sold to, and new rights to question, review, and request reevaluation of automated decisions. The age-13-to-16 opt-in for targeted advertising and data sales expands to age 17. Connecticut's broader privacy posture keeps getting more aggressive. The state is also standing up a data broker registry and deletion mechanism under SB4, and just passed a 97-page AI bill under SB5. Read on for the practical details, what is changing for whom, and what to do before July 1.

Who Is Now Covered: The 35,000-Consumer Threshold

The single biggest change is the applicability drop. The current Connecticut Data Privacy Act, in force since January 1, 2023, applies to entities that controlled or processed personal data of at least 100,000 consumers in the preceding calendar year (or 25,000 consumers if at least 25% of revenue came from selling personal data). The amendments lower the first threshold to 35,000 consumers, and they add two new no-threshold triggers.[1]

Under the amended law, the CTDPA applies to any entity that conducts business in Connecticut or targets products or services to Connecticut residents and, during the preceding calendar year:

  • Controlled or processed personal data of at least 35,000 consumers (down from 100,000), excluding data processed solely to complete a payment transaction.
  • Controlled or processed consumers' sensitive data (excluding data processed solely to complete a payment transaction). This trigger has no volume floor.
  • Offered consumers' personal data for sale. This trigger also has no volume floor.

Read those last two again. A Connecticut-facing business that processes even one Connecticut consumer's sensitive data, or that sells even a single record of personal data, is now subject to the CTDPA, regardless of total volume. The 100,000-consumer floor was the main reason smaller data brokers and ad-tech firms were able to operate outside Connecticut privacy law. That cover is gone.[1]

The CTDPA's existing exceptions still apply, and the amendments added and clarified several of them. The Wiley alert flags this as a "should review carefully" area, because the small print on employment data, B2B contacts, and protected health information determines which organizations are actually in scope. The general rule: if you sell consumer data, process sensitive data, and reach Connecticut residents, you are now in scope.[1]

Sensitive Data Expands, and Selling It Now Requires Consent

The amendments grow the definition of "sensitive data" in ways that catch categories companies have historically treated as routine. The expanded definition covers government identifiers (driver's license numbers, passport numbers), financial account-related elements, and Social Security numbers (SSNs), in addition to the pre-existing categories (racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data, and children's personal data).[1]

The CTDPA already required controllers to obtain consent before processing sensitive data. The amendments layer a new restriction on top: the sale of sensitive data is now expressly prohibited absent consumer consent. SSNs, financial account credentials, and biometric identifiers cannot be sold to data brokers, ad networks, or downstream customers without an explicit opt-in. The data broker industry has been running on a model where the more sensitive the record, the higher the price. The Connecticut amendment is the first state-level pushback that names the categories most commonly sold.[1]

The amendments also tighten the consumer access mechanism. Controllers may not provide certain categories of sensitive data (SSNs, certain financial data, biometric elements) in response to a consumer's data-access request. They can only confirm whether the data was collected. That change is meant to stop the worst-case scenario: a consumer submits a subject access request, the controller returns a copy of the SSN, and the response email gets breached or intercepted. The new rule is "we confirm we have it; we do not send it back to you." Same protection logic as the IRS not emailing your tax return.[1]

The New Rights: Profiling Challenges, Sale Lists, and Inferences

The consumer rights overhaul is the part of the amendment package that will most directly change the experience of being a Connecticut resident online. The four big changes:

1. New rights over automated profiling decisions. The amendments create rights for consumers to question the outcome of certain covered automated decisions, be informed of the reasoning, review the data used, and (in certain contexts) correct the data and request reevaluation. The opt-out right also expands: consumers can now opt out of any covered automated profiling decision, not just those that are "solely" automated. A human-in-the-loop review that rubber-stamps an algorithm no longer shields the decision from opt-out.[1]

2. New right to a list of third-party buyers. Consumers now have the right to obtain a list of every third party to whom the controller has sold the consumer's personal data. This is a structural change. Today, the typical subject access request returns the data the controller has on you. Under the amended law, you can ask, separately, "who did you sell me to?" The response will name the recipients. That is the lever consumer advocates have been pushing for since 2020, and Connecticut is the first state to make it a statutory right.[1]

3. Inferences are now explicitly covered. The amendments clarify that inferences derived from personal data count as personal data for the purposes of the right to know and the right to access. That closes a long-running loophole where controllers argued that a model's prediction about you (creditworthiness, health risk, "interested in X") was not "your data" and therefore not subject to access requests. The amendment says inferences are data. You can ask for them.[1]

4. Other changes to existing rights. The amendments make targeted updates to the right to correct, the right to delete, and the right to opt out. Most are clarifying, not novel. The big-picture effect: every existing right is slightly harder to refuse and slightly easier for consumers to invoke.[1]

The Under-18 Opt-In: Connecticut Extends the Bracket to 17

The current CTDPA requires opt-in consent before a controller engages in targeted advertising or sells the personal data of consumers between ages 13 and 16. The amendments extend that protected bracket to age 17. Seventeen-year-olds in Connecticut now join 13- to 16-year-olds in needing affirmative opt-in for targeted ads and data sales.[1]

This is a quiet but meaningful tightening. Most state privacy laws cap the youth opt-in at 16 (California's CCPA, Connecticut pre-amendment, others). Pushing the cap to 17 means platforms serving a high-school-graduate-heavy demographic have to rebuild their age-gating logic. It also closes the "17-and-three-quarters" loophole where a teen turns 17, opts out under the old rule, and the platform re-engages them as an adult in the ad system within months. The new rule holds the opt-in until 18.[1]

How Connecticut's Rules Compare to Texas, Oregon, and the Rest

Connecticut is not the only state tightening consumer privacy law in 2026, but the July 1 amendments are the most consequential package of the year. Here is how the new CTDPA stacks up against the other major state laws in force or taking effect this summer:

  • Texas Data Privacy and Security Act (TDPSA): Effective July 1, 2024. No general data broker sale opt-out (a separate Texas law covers broker registration), no profiling rights as granular as Connecticut's new provisions. Connecticut's profiling challenge right and sale-list right go further than Texas.[1][2]
  • Oregon Consumer Privacy Act (OCPA): Effective July 1, 2024, with a universal opt-out mechanism (Global Privacy Control) required. Connecticut's existing CTDPA requires GPC recognition; the amendments do not weaken that.[3]
  • Colorado Privacy Act (CPA): Amended effective July 1, 2024, with profiling rights narrower than Connecticut's new ones. Colorado's universal opt-out mechanism applies.[3]
  • California (CCPA/CPRA): The original state privacy law. California has had a right to a list of data buyers in practice, but the statutory right is narrower. Connecticut's "right to a list of third parties to whom your data was sold" is more specific.[1][4]

The pattern across 2024-2026 is convergence: every active state privacy law now requires sensitive-data consent, profiling opt-outs, and reasonable security. Connecticut's amendments push the leading edge in three places: the lower applicability threshold (35,000 pulls in many more businesses), the explicit sale ban on SSNs and financial credentials (the first sale prohibition of its kind at the state level), and the right to a list of data buyers (the first statutory, actionable right of its kind).

What Connecticut Residents Should Do Before July 1

The amendments add new rights, and most of them require affirmative action on your part to use. Three things to do now:

  • Send a "right to know" request to every company that has your data. Under the amended CTDPA, your request can now explicitly ask for the list of third parties your data was sold to. The request template at the IAPP has a Connecticut-specific form, and most controllers are required to acknowledge within 45 days.[1][3]
  • Send a "right to opt out of profiling" request to any platform that makes decisions about you. Insurance, lending, employment screening, healthcare risk scoring: all of these touch automated decisions. The amended right to opt out covers "any covered automated profiling decision," not just the fully-automated ones. Send the request in writing. Keep the confirmation.[1]
  • For parents of 17-year-olds: revisit the ad and data settings. The age-17 opt-in means platforms that previously treated 17-year-olds as adults for ad targeting now need to default to opt-out. Check Instagram, TikTok, Snapchat, YouTube, and any gaming platform your 17-year-old uses. The default should change, but it may not change automatically.[1]

What Connecticut-Facing Businesses Should Do Before July 1

If you run a business that touches Connecticut residents, the threshold drop is the immediate fire:

  • Recalculate your applicability. If you are between 35,000 and 100,000 Connecticut consumers in a calendar year, you are newly in scope as of July 1. If you process sensitive data or sell personal data, you are in scope regardless of volume. Map your 2025 traffic and 2026 projections against the new triggers.[1]
  • Update your privacy notice. The amended CTDPA adds new disclosures, including the right to a list of data buyers. Most state-privacy-law templates cover the existing rights; the new ones need explicit language.[1]
  • Build a sensitive-data sale opt-in flow. If you sell any sensitive data (SSNs, financial account numbers, biometric identifiers), you need a documented opt-in. The "we have always sold this data" defense does not survive July 1. Pause any planned sales of newly-sensitive data categories until the opt-in is in place.[1]
  • Train the customer service team on the new profiling rights. The "right to question, be informed of reasoning, review data, and request reevaluation" requires a process, not just a checkbox. A consumer invoking the right against a script-reading agent will get a wrong answer.[1]

How This Connects to Connecticut's Other 2026 Privacy Laws

The July 1 CTDPA amendments do not exist in isolation. Connecticut has stacked an unusually aggressive privacy posture across multiple bills in 2026, and the four pieces of the stack now reinforce each other:

  • CTDPA amendments (this article): Lower applicability threshold, expanded sensitive data, new consumer rights. Effective July 1, 2026.
  • SB4 (data broker registry and deletion): State-run registry of data brokers, a single-request deletion mechanism to wipe your data from every registered broker, surveillance pricing ban, and facial recognition restrictions. Passed the House 141-6 and Senate 31-4 in 2026. The registry and deletion mechanism are expected to be operational alongside the CTDPA amendments in 2026.[5]
  • SB5 (AI bill): 97-page AI bill that requires employers to disclose AI in hiring decisions, requires chatbots to detect suicidal users, and regulates frontier AI models. Passed the Senate 32-4 in 2026; the House has not yet voted.[6]
  • Existing sectoral rules: Connecticut's Genetic Information Privacy Act, its data breach notification statute, and its student data privacy law remain in force and apply alongside the new amendments.

Read together, the message is clear. Connecticut is no longer a middling state on privacy. It is closer to California or Colorado than to the 14 states with no comprehensive privacy law. For a business, the practical consequence: if you are in scope of any one of these Connecticut rules, you are probably in scope of two or three. The July 1 amendments are the trigger that pulls the long tail of mid-sized businesses into the system for the first time.

The Bottom Line

Connecticut's July 1, 2026 amendments are the strongest state-level consumer privacy upgrade of 2026. The 35,000-consumer threshold pulls in tens of thousands of small and mid-sized businesses that have never had to think about state privacy law. The sensitive data expansion and sale ban target the categories that data brokers value most. The new rights over automated decisions and the right to a list of data buyers give Connecticut residents the most actionable privacy toolkit of any state.

For consumers: send the right-to-know requests in the next three weeks. The 45-day response window means requests sent on June 15 will land just after July 1, and the new rights will apply to the responses.

For businesses: recalculate applicability, update your privacy notice, and pause any sales of newly-sensitive data until the opt-in is documented. The amended law has no grace period. The first enforcement action will not be friendly to a "we did not know" defense.

References

  1. Wiley Rein: "Major Changes to Connecticut's Consumer Privacy Law Will Take Effect July 1, 2026" (April 27, 2026) - Primary law firm alert with detailed breakdown of the CTDPA amendments, applicability thresholds, sensitive data expansion, consumer rights additions, and youth data opt-in extension.
  2. IAPP - US State Privacy Legislation Tracker - Authoritative tracker of state privacy law applicability thresholds, sensitive data definitions, and effective dates.
  3. Benesch: "Connecticut Broadens Data Privacy Act Requirements Effective July 1, 2026" - Cross-confirming law firm alert on the CTDPA amendments with additional analysis on compliance steps.
  4. Privacy Law Map: Connecticut Data Privacy Act guide - Plain-language summary of the CTDPA framework and 2026 amendments.
  5. State of Surveillance: "Connecticut Just Passed a Data Broker Kill Switch" - Coverage of SB4 creating the state data broker registry and single-request deletion mechanism.
  6. State of Surveillance: "Connecticut Just Passed the Most Ambitious AI Bill in America" - Coverage of SB5, the 97-page AI bill requiring employer disclosure of automated decision systems.