CTDPA: The Complete Guide
The Connecticut Data Privacy Act, signed into law in May 2022 and effective July 1, 2023, represents Connecticut's entry into the growing landscape of US state privacy legislation. The CTDPA closely follows the Virginia and Colorado models while incorporating several consumer-protective provisions — including loyalty program transparency requirements and one of the earlier state law mandates for universal opt-out mechanisms. Understanding the CTDPA is increasingly important as the US state privacy law landscape consolidates around the Virginia-Colorado-Connecticut template.
What the CTDPA Is and Who Enforces It
The CTDPA was signed into law by Governor Ned Lamont on May 10, 2022, as Public Act No. 22-15. Enforcement authority rests with the Connecticut Attorney General. There is no private right of action — only the AG may enforce the law.
The initial 60-day cure period applied until December 31, 2024. From January 1, 2025, the AG may pursue enforcement without providing a prior cure notice. Connecticut aligned its cure period sunset with Colorado's, making both states capable of prompt enforcement from 2025 onward.
Civil penalties under the CTDPA are assessed under the Connecticut Unfair Trade Practices Act (CUTPA), which provides for civil penalties of up to $5,000 per willful violation. The CUTPA route also allows private litigation under Connecticut's consumer protection framework in some circumstances, creating broader enforcement exposure than the AG-only model in Virginia and Colorado.
Territorial and Material Scope
The CTDPA applies to persons that conduct business in Connecticut or produce products or services targeted to Connecticut residents and during the prior calendar year either:
- Controlled or processed the personal data of at least 100,000 consumers (excluding personal data processed solely for completing a payment transaction), or
- Controlled or processed the personal data of at least 25,000 consumers while deriving more than 25% of gross revenue from the sale of personal data.
Connecticut's revenue threshold differs from Virginia (50% of gross revenue) and Colorado (revenue from sale of data, without a general revenue percentage): Connecticut uses 25% of gross revenue derived from sale of personal data. This lower percentage may bring more businesses within scope compared to Virginia's 50% threshold.
The payment transaction exclusion for the 100,000 consumer threshold is Connecticut-specific: if a business processes personal data solely to complete a payment (such as processing credit card data for a transaction), that processing does not count toward the 100,000 threshold. This provides meaningful relief for businesses that process large volumes of payment data without engaging in broader consumer profiling.
Significant exemptions apply:
- Personal data regulated by HIPAA, GLBA, FERPA, COPPA, and other specified federal frameworks.
- Nonprofits — exempt, consistent with Virginia and Colorado.
- Institutions of higher education.
- State and local government entities.
Consumer Rights
The CTDPA grants Connecticut consumers five core rights:
- Right to access — Confirm whether personal data is processed and access that data.
- Right to correct — Correct inaccuracies in personal data.
- Right to delete — Delete personal data about the consumer.
- Right to data portability — Obtain a portable copy of personal data in a readily usable format.
- Right to opt out — Opt out of targeted advertising, sale of personal data, and profiling that produces legal or similarly significant effects.
Controllers must respond to consumer requests within 45 days, with a 45-day extension available with notice. Denied requests must include a reason and an appeals process. Controllers must respond to appeals within 60 days and inform consumers of the right to file a complaint with the AG.
Universal Opt-Out Mechanism
Like Colorado, Connecticut requires controllers to recognize and honor universal opt-out mechanisms (UOOMs) — technology-based signals that consumers use to communicate opt-out preferences automatically. The CTDPA's UOOM requirement took effect January 1, 2025.
Controllers must honor signals such as the Global Privacy Control (GPC) as valid opt-out requests from Connecticut consumers. This requires technical implementation — detecting the signal at the server level and applying opt-out status to the consumer's processing record. Policy language alone does not satisfy this requirement.
Connecticut's UOOM requirement is functionally identical to Colorado's. Organizations implementing GPC recognition for CPA compliance can apply the same technical implementation to satisfy Connecticut's requirement, making this one of the clearest efficiency opportunities in multi-state US privacy compliance.
Sensitive Data
Sensitive data under the CTDPA includes: racial or ethnic origin, religious beliefs, mental or physical health conditions or diagnoses, sexual orientation or gender identity, immigration status, financial data beyond publicly available information, genetic or biometric data for unique identification, personal data of children known to be under 13, and precise geolocation.
Processing sensitive data requires opt-in consent before collection. The definition and consent requirement are functionally identical to the CPA and VCDPA.
Loyalty Program Transparency — Connecticut's Distinctive Requirement
The CTDPA includes a provision specific to loyalty, rewards, or club card programs that distinguishes it from Virginia and Colorado. Where a business offers a loyalty or rewards program, the business must clearly disclose how personal data is collected and used in connection with the program. Consumers must be able to understand what personal data is being collected for loyalty purposes, how it is used, and what benefits they receive in exchange.
This provision reflects growing concern about the data economics of loyalty programs — where consumers exchange personal data for discounts or points without fully understanding the extent of data collection and use. Organizations operating loyalty programs targeting Connecticut consumers must review their program disclosures for CTDPA compliance.
Data Protection Assessments
Controllers must conduct and document data protection assessments before engaging in processing that presents heightened risk:
- Targeted advertising.
- Sale of personal data.
- Profiling that presents a foreseeable risk of injury, intrusion upon solitude, discrimination, or other substantial harm.
- Processing of sensitive data.
- Any other processing presenting heightened risk as described by the AG.
Assessments must balance the benefits of processing against privacy risks, considering available safeguards. The AG may request production of data protection assessments in connection with an investigation.
CTDPA vs. GDPR and Sibling State Laws
The CTDPA shares approximately 85% structural overlap with both the VCDPA and the CPA. The three laws together define the dominant US state privacy law model — sometimes called the "Virginia model" or the "controller-processor framework" approach — that has been adopted with variations by approximately 20 states through mid-2026.
Compared to the GDPR (60% overlap), the CTDPA uses an opt-out default rather than a lawful basis requirement. GDPR applies without thresholds; CTDPA applies only above consumer volume or revenue thresholds. GDPR imposes percentage-of-turnover penalties; CTDPA penalties are capped per violation.
Compared to CCPA (65% overlap), the CTDPA has different thresholds (lower revenue percentage but higher consumer volume), requires opt-in for sensitive data rather than CCPA's notice-and-opt-out approach, and adds UOOM and loyalty program requirements that CCPA does not have.
Compliance Steps and Timeline
| Phase | Activities | Typical Duration |
|---|---|---|
| Assessment | Applicability analysis, loyalty program audit, data inventory | 2-3 weeks |
| Design | GPC/UOOM implementation, sensitive data consent, loyalty program disclosures | 2-4 weeks |
| Implementation | Consumer rights workflows, processor contracts, assessment documentation | 3-5 weeks |
| Ongoing | UOOM monitoring, assessment updates, AG guidance tracking | Continuous |
Key compliance steps:
- Applicability assessment — Evaluate processing thresholds against Connecticut consumer data, remembering the payment transaction exclusion.
- Universal opt-out — Implement GPC and similar signal recognition for the January 2025 UOOM requirement if not already done for Colorado.
- Sensitive data consent — Deploy opt-in consent flows for all sensitive personal data categories before collection begins.
- Rights fulfillment — Establish 45-day response processes for consumer requests with appeal procedures.
- Loyalty programs — Audit loyalty and rewards program disclosures for CTDPA compliance and update as needed.
- Data protection assessments — Document assessments for all targeted advertising, sale, profiling, and sensitive data processing.
- Vendor contracts — Update processor agreements to include CTDPA-required provisions and data processing agreement terms.
How Privacy Automation Helps
CTDPA compliance is efficiently managed alongside other US state privacy laws through a unified privacy platform. TruePrivacy covers the CTDPA within its 12-plus framework portfolio alongside VCDPA, CPA, CCPA, and CPRA. AI data discovery across 128-plus sources supports the data inventory needed for accurate processing disclosures. DSR automation handles the 45-day response window and appeal workflows. UOOM detection is a technical integration layer that feeds into TruePrivacy's consent management infrastructure.
At $5,000 per year with 24-hour onboarding and an AuditXYZ score of 88/100, TruePrivacy is a practical choice for organizations managing growing US state privacy law portfolios. See best privacy management tools or the TruePrivacy vs OneTrust comparison.
Frequently Asked Questions
How does the CTDPA's revenue threshold differ from Virginia's? Virginia requires that a business derive over 50% of gross revenue from the sale of personal data to meet the lower consumer-volume threshold (25,000 consumers). Connecticut lowers this to 25% of gross revenue. A business processing data of 30,000 Connecticut consumers that derives 30% of its revenue from data sales would meet Connecticut's threshold but not Virginia's.
What disclosures must a loyalty program make under the CTDPA? The CTDPA requires clear disclosure of the personal data collected in connection with a loyalty program and how it is used. At minimum, privacy notices for loyalty programs should identify what categories of personal data are collected through program participation (purchases, location at redemption, preferences derived from purchase history), the purposes for which that data is used (personalization, marketing, analytics), whether the data is sold or shared with third parties, and what the consumer receives in exchange for participating.
Does UOOM recognition apply to opt-out of targeted advertising as well as sale? Yes. Connecticut's UOOM requirement, like Colorado's, applies to all three opt-out rights: opt-out of targeted advertising, opt-out of sale of personal data, and opt-out of profiling for significant decisions. A single GPC signal should trigger opt-out status for all three categories simultaneously, not just one.
What happens after the cure period ended on December 31, 2024? From January 1, 2025, the Connecticut AG may initiate enforcement actions without providing prior written notice or a cure opportunity. The AG retains discretion to work informally with businesses in some circumstances, but there is no legal obligation to offer a cure. Organizations that have not yet completed CTDPA compliance should treat the lack of a cure period as a reason to prioritize remediation.
Are there any CTDPA-specific guidance documents we should review? The Connecticut AG has published FAQs and informal guidance on CTDPA scope, the UOOM requirement timeline, and loyalty program obligations. Connecticut has not promulgated formal implementing regulations equivalent to Colorado's, but the AG's published guidance functions as the practical compliance standard. The AG's office has also participated in multi-state privacy law working groups, and shared guidance among the Virginia-Colorado-Connecticut cluster is broadly applicable.