On July 1, 2026, significant amendments to the Connecticut Data Privacy Act took effect, materially expanding the statute's reach and imposing new substantive obligations onβ¦
On July 1, 2026, significant amendments to the Connecticut Data Privacy Act took effect, materially expanding the statute's reach and imposing new substantive obligations on organizations that handle Connecticut residents' personal information. Businesses that previously considered themselves outside the law's scope should reassess their compliance posture without delay, as the amendments recalibrate both who is covered and how covered entities must handle data.
Most consequentially, the applicability threshold has been lowered from 100,000 to 35,000 Connecticut residents. This reduction sweeps a substantial number of mid-sized businesses into the law's coverage for the first time, including regional retailers, service providers, and online platforms that may not have previously tracked Connecticut-specific data volumes. Organizations approaching or exceeding this new threshold should promptly evaluate their processing activities to determine whether they now qualify as controllers or processors under the amended statute.
The amendments also broaden the definition of sensitive data to expressly include disability and medical information, transgender or nonbinary status, neural data, financial account details, and government-issued identification numbers. Each of these categories triggers heightened obligations, including consent requirements and enhanced handling standards. Businesses that collect information falling within these expanded categories, whether through customer intake, employment processes, health-related services, or account registration, will need to implement additional safeguards and revisit consent workflows to ensure the required authorizations are properly obtained and documented.
Equally important is the new proportionality standard, which requires that data collection be aligned with the purposes disclosed to consumers. This obligation moves beyond traditional notice-and-choice principles and compels organizations to audit their actual data practices against their published representations. Companies should tighten purpose limitations, update privacy notices to reflect current processing activities accurately, and review vendor contracts to ensure downstream data uses remain consistent with the scope disclosed at the point of collection.
Taken together, the amendments demand a coordinated response spanning legal, compliance, information security, and vendor management functions. Prompt gap assessments, updated policies, and refreshed training will be essential to mitigate regulatory and reputational risk.
This article is provided for general informational purposes only and does not constitute legal advice. Clients with specific questions about how the amended Connecticut Data Privacy Act applies to their operations should seek tailored guidance from qualified counsel.