CTDPA · Opt-out model

Connecticut Privacy Law (CTDPA): Compliance Guide

The Connecticut Data Privacy Act, effective July 1, 2023, was the fifth comprehensive state privacy law and quietly one of the more demanding ones. It layered a universal opt-out signal requirement — in force since January 1, 2025 — on top of a Virginia-style baseline, and its 25% revenue-from-sales trigger catches mid-size data sellers that most other state laws miss. If your business model involves selling personal data at any meaningful share of revenue, Connecticut deserves a close read.

Effective
July 1, 2023
GPC / universal opt-out
Required since January 1, 2025
Required link text
Your Privacy Choices
Handle CTDPA compliance free

Last reviewed July 19, 2026 · Connecticut Data Privacy Act (CTDPA)

Applicability

Who must comply with the CTDPA

The Connecticut Data Privacy Act applies to businesses that meet the following criteria:

  • Conducts business in Connecticut, and:
  • Controls or processes the personal data of 100,000 or more Connecticut consumers, or
  • Controls or processes the personal data of 25,000 or more Connecticut consumers and derives 25% or more of gross revenue from the sale of personal data

Consumer rights

What Connecticut consumers can demand

  • Right to access personal data
  • Right to correct inaccuracies
  • Right to delete personal data
  • Right to data portability
  • Right to opt out of the sale of personal data, targeted advertising, and profiling

Opt-out mechanics

Connecticut opt-out & GPC requirements

Like every US state privacy law, the CTDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Connecticut is Your Privacy Choices.

Global Privacy Control: Required since January 1, 2025

Connecticut requires covered businesses to honor universal opt-out signals — Global Privacy Control included — similar to Colorado's mandate. The requirement has been in force since January 1, 2025.

Enforcement

CTDPA penalties & enforcement

  • Up to $5,000 per violation

Cure period: 60-day cure period.

State quirks

What makes Connecticut different

Connecticut's distinctives are in the details. The 25% revenue-from-data-sales trigger is the lowest sales-revenue threshold among the early state laws — half the usual 50%. It was among the first states to make universal opt-out signals mandatory, with the requirement live since January 1, 2025. For minors under 16, selling personal data requires opt-in consent, not just an opt-out link. Penalties top out at $5,000 per violation — lower than most — but the 60-day cure period still leaves real exposure once it lapses.

Universal opt-out signals

Businesses must honor universal opt-out signals such as Global Privacy Control, in force since January 1, 2025.

Low sales-revenue trigger

The 25,000-consumer prong applies at just 25% of gross revenue from data sales — half the 50% figure used by most other states.

Minors under 16

The sale of a minor's personal data requires opt-in consent rather than a simple opt-out option.

Data protection assessments

Required for higher-risk processing activities.

Automation

How ConsentKit handles Connecticut

  • ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Connecticut visitors are identified before any consent UI renders — no client-side geo-lookup delay.
  • Connecticut visitors see a persistent Your Privacy Choices link — the exact statutory text — available to new and returning visitors alike.
  • Because Connecticut requires universal opt-out signals, ConsentKit automatically honors Global Privacy Control for Connecticut visitors: when the browser broadcasts GPC, the widget applies the opt-out and denies analytics and marketing categories with no click required.
  • Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
  • Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Connecticut visitor makes a choice.

ConsentKit treats a Connecticut visitor's Global Privacy Control signal exactly like a click on “Your Privacy Choices” — the opt-out is applied and recorded with the same audit metadata.

FAQ

Connecticut CTDPA FAQ

Does the CTDPA apply to my business?

It applies to businesses operating in Connecticut that control or process the personal data of 100,000 or more Connecticut consumers, or 25,000 or more consumers while deriving 25% or more of gross revenue from selling personal data. That 25% trigger is the lowest sales-revenue threshold among the early state laws.

Do I have to honor opt-out preference signals in Connecticut?

Yes. Connecticut requires honoring universal opt-out signals — Global Privacy Control included — and the requirement has been in force since January 1, 2025. A signal-based opt-out must be treated like a consumer who clicked your privacy choices link.

What does Connecticut require for minors' data?

For consumers under 16, selling personal data requires opt-in consent rather than a mere opt-out option. Data protection assessments are also required for higher-risk processing activities.

What are the penalties under the CTDPA?

Violations run up to $5,000 each. Connecticut provides a 60-day cure period, giving businesses a window to fix a noticed violation before penalties are assessed.

This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the CTDPA.

Comply with Connecticut's CTDPA — and the other 19 state laws

ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.