Connecticut Privacy Law (CTDPA): Compliance Guide
The Connecticut Data Privacy Act, effective July 1, 2023, was the fifth comprehensive state privacy law and quietly one of the more demanding ones. It layered a universal opt-out signal requirement — in force since January 1, 2025 — on top of a Virginia-style baseline, and its 25% revenue-from-sales trigger catches mid-size data sellers that most other state laws miss. If your business model involves selling personal data at any meaningful share of revenue, Connecticut deserves a close read.
- Effective
- July 1, 2023
- GPC / universal opt-out
- Required since January 1, 2025
- Required link text
- “Your Privacy Choices”
Last reviewed July 19, 2026 · Connecticut Data Privacy Act (CTDPA)
Applicability
Who must comply with the CTDPA
The Connecticut Data Privacy Act applies to businesses that meet the following criteria:
- Conducts business in Connecticut, and:
- Controls or processes the personal data of 100,000 or more Connecticut consumers, or
- Controls or processes the personal data of 25,000 or more Connecticut consumers and derives 25% or more of gross revenue from the sale of personal data
Consumer rights
What Connecticut consumers can demand
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to data portability
- Right to opt out of the sale of personal data, targeted advertising, and profiling
Opt-out mechanics
Connecticut opt-out & GPC requirements
Like every US state privacy law, the CTDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Connecticut is “Your Privacy Choices”.
Global Privacy Control: Required since January 1, 2025
Connecticut requires covered businesses to honor universal opt-out signals — Global Privacy Control included — similar to Colorado's mandate. The requirement has been in force since January 1, 2025.
Enforcement
CTDPA penalties & enforcement
- Up to $5,000 per violation
Cure period: 60-day cure period.
State quirks
What makes Connecticut different
Connecticut's distinctives are in the details. The 25% revenue-from-data-sales trigger is the lowest sales-revenue threshold among the early state laws — half the usual 50%. It was among the first states to make universal opt-out signals mandatory, with the requirement live since January 1, 2025. For minors under 16, selling personal data requires opt-in consent, not just an opt-out link. Penalties top out at $5,000 per violation — lower than most — but the 60-day cure period still leaves real exposure once it lapses.
Universal opt-out signals
Businesses must honor universal opt-out signals such as Global Privacy Control, in force since January 1, 2025.
Low sales-revenue trigger
The 25,000-consumer prong applies at just 25% of gross revenue from data sales — half the 50% figure used by most other states.
Minors under 16
The sale of a minor's personal data requires opt-in consent rather than a simple opt-out option.
Data protection assessments
Required for higher-risk processing activities.
Automation
How ConsentKit handles Connecticut
- ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Connecticut visitors are identified before any consent UI renders — no client-side geo-lookup delay.
- Connecticut visitors see a persistent “Your Privacy Choices” link — the exact statutory text — available to new and returning visitors alike.
- Because Connecticut requires universal opt-out signals, ConsentKit automatically honors Global Privacy Control for Connecticut visitors: when the browser broadcasts GPC, the widget applies the opt-out and denies analytics and marketing categories with no click required.
- Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
- Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Connecticut visitor makes a choice.
ConsentKit treats a Connecticut visitor's Global Privacy Control signal exactly like a click on “Your Privacy Choices” — the opt-out is applied and recorded with the same audit metadata.
FAQ
Connecticut CTDPA FAQ
Does the CTDPA apply to my business?
It applies to businesses operating in Connecticut that control or process the personal data of 100,000 or more Connecticut consumers, or 25,000 or more consumers while deriving 25% or more of gross revenue from selling personal data. That 25% trigger is the lowest sales-revenue threshold among the early state laws.
Do I have to honor opt-out preference signals in Connecticut?
Yes. Connecticut requires honoring universal opt-out signals — Global Privacy Control included — and the requirement has been in force since January 1, 2025. A signal-based opt-out must be treated like a consumer who clicked your privacy choices link.
What does Connecticut require for minors' data?
For consumers under 16, selling personal data requires opt-in consent rather than a mere opt-out option. Data protection assessments are also required for higher-risk processing activities.
What are the penalties under the CTDPA?
Violations run up to $5,000 each. Connecticut provides a 60-day cure period, giving businesses a window to fix a noticed violation before penalties are assessed.
This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the CTDPA.
Comply with Connecticut's CTDPA — and the other 19 state laws
ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.