Connecticut Tightens Rules On Personal…Connecticut Tightens Rules On Personal DataCoverage from Foley & Lardner, TechTimes, and others
00/00/0000
DailyWeekly
Connecticut is expanding its privacy framework to regulate data brokers, restrict the sale and use of precise geolocation data, limit surveillance pricing, and give consumers greater control over genetic information and publicly available data used in profiles.
Public Act No. 26-64 creates a data broker registry and a centralized deletion mechanism, while related amendments broaden sensitive-data, profiling, and transparency obligations. The phased implementation will create new operational requirements for companies that collect, sell, analyze, or use personal data in Connecticut.
It explains how the Connecticut law combines data-broker accountability with targeted restrictions on geolocation, surveillance pricing, facial recognition, and genetic data.
It captures the latest material shift by showing how Delaware broadens privacy protections and extends the topic’s multistate trajectory.
Delaware Public Media / Bente Bouthier
Key Issues
01
Data-broker accountability and deletion infrastructure
Connecticut and New Jersey are converting data-broker oversight into operational requirements, including registration, disclosures, fees, penalties, and centralized or simplified deletion processes. Connecticut registration begins in 2027, with a single-request deletion mechanism due by 2028, while New Jersey is building a fee-based registry with enforcement penalties.
Stable
Drawn from 5 articles
02
Broader coverage and stronger consumer rights
Connecticut is extending privacy obligations to more entities and data practices by narrowing exemptions, expanding sensitive-data definitions, and strengthening access and challenge rights for profiling and automated decisions. Delaware’s enacted amendments reinforce the same direction through broader coverage, sensitive-data consent duties, and profiling-related protections.
Stable
Drawn from 5 articles
03
Targeted limits on high-risk data uses
The strongest controls are aimed at specific high-risk practices rather than data processing generally. Connecticut restricts precise-geolocation sales and access, limits surveillance pricing, and adds specialized requirements for facial recognition and direct-to-consumer genetic data.
Stable
Drawn from 4 articles
04
Multistate expansion with divergent implementation
State-level privacy regulation is now extending beyond Connecticut through enacted Delaware and New Jersey measures and advancing Massachusetts proposals. The regimes differ in coverage thresholds, registration timing, definitions, consent rules, and enforcement mechanisms, increasing compliance fragmentation even as the overall regulatory direction converges.
Stable
Drawn from 5 articles
Looking Back
230 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
Jan 30
Mar 6
Apr 17
May 22
Jun 26
Aug 7
Sep 11
The Story So Far
Broadening
Delaware broadens the state-level privacy expansion
Delaware has enacted privacy amendments that widen coverage, strengthen sensitive-data and automated-decision protections, expand employment-data oversight, and clarify breach-notification duties, extending the topic beyond Connecticut’s reforms.
Previously
Connecticut is expanding its consumer privacy framework through new rules governing data brokers, precise geolocation, surveillance pricing, profiling, facial recognition, and genetic data. Public Act 26-64 creates a data broker registry and centralized deletion mechanism, while related amendments broaden the Connecticut Data Privacy Act’s coverage and sensitive-data protections. The changes are designed to give consumers greater control over personal information and constrain commercial uses of data, with major obligations taking effect in stages through 2031.
History
09/15/2026
The update mainly formalizes and operationalizes Connecticut’s previously reported reforms, identifying Public Act No. 26-64 and clarifying phased compliance deadlines. The narrative also shifts from a multi-state overview toward Connecticut-specific implementation and oversight.
09/15/2026
The story has broadened from a Connecticut-led privacy-law cluster into a wider state policy shift, with New Jersey enacting major restrictions and Massachusetts advancing a consequential proposal. Enforcement and AI-related compliance requirements are also becoming more operational and specific.
Connecticut expanded the CTDPA through Public Act 25-113, adding profiling impact assessments and broader sensitive data and sale triggers effective in July and August 2026.
7/8/2026 • Regulation, Law & Enforcement • General
Connecticut privacy law amendments under Public Act 25-113 signed June 24, 2025 require affirmative opt-in consent for sensitive data sales and LLM training disclosures starting July 1, 2026.
6/26/2026 • Regulation, Law & Enforcement • General
Connecticut passed a data broker registry requiring public listing of phone, address, and shopping data sellers, with implementation planned for 2027 amid federal proposals.
6/25/2026 • Regulation, Law & Enforcement • General
Connecticut adopted Public Act No. 26-64 on May 27, 2026, expanding data broker duties and restricting precise geolocation sales and surveillance pricing for covered organizations.
6/18/2026 • Regulation, Law & Enforcement • General
Massachusetts House passed consumer data privacy legislation in 2024, expanding rights and banning sale of precise geolocation data while creating AG rulemaking and private lawsuits.
6/11/2026 • Regulation, Law & Enforcement • General
Connecticut Governor Ned Lamont signed May 27, 2026 Senate Bill 4 to expand the Connecticut Data Privacy Act with a data broker registry, deletion mechanism, and new limits on precise geolocation, surveillance pricing, facial recognition, profiling, and genetic testing.
6/10/2026 • Regulation, Law & Enforcement • General
Massachusetts House passes the Consumer Data Privacy Act, banning cellphone location data sales and adding a private right of action for privacy violations.
6/5/2026 • Regulation, Law & Enforcement • General
Massachusetts House passed consumer privacy legislation granting residents access, deletion, opt-out, and portability rights while restricting sensitive data sales and precise geolocation sales.
6/5/2026 • Regulation, Law & Enforcement • General
Privacy notice supplement for Colorado, Connecticut, Maryland, Nebraska, New Jersey, Nevada, Texas, and Washington describes rights to access, delete, and opt out of sale and targeted advertising, with state-specific health-data authorization rules.
5/12/2026 • Regulation, Law & Enforcement • General
Delaware Governor signed House Bills 380 and 381 on September 2, 2026, expanding privacy obligations and revising breach-notification requirements statewide.
9/13/2026 • Regulation, Law & Enforcement • General
Delaware Governor Matt Meyer signed HB 380 on September 2, 2026, expanding the Delaware Personal Data Privacy Act statewide before its January 1, 2027 effective date.
9/11/2026 • Regulation, Law & Enforcement • General
New Jersey enacted A5328 on June 30, 2026, banning sensitive data sales and requiring data broker and data collector registry registration with disclosures and penalties.
7/13/2026 • Regulation, Law & Enforcement • General
Delaware passed HB 380 on June 16, 2026 to amend the DPDPA, expanding sensitive data and increasing controller and third-party duties effective January 1, 2027.
6/26/2026 • Regulation, Law & Enforcement • General
On Sept. 2, Delaware Governor Matt Meyer signed House Bill 381, requiring organizations to provide earlier Attorney General notice for certain Delaware data breaches.
9/16/2026 • Regulation, Law & Enforcement • General
Delaware Governor Matt Meyer signed House Bill 380 on September 2, 2026, expanding state privacy-law obligations for businesses, controllers, and personal-data recipients statewide.
9/16/2026 • Regulation, Law & Enforcement • General
Mondaq / Aaron Burstein, Alexander Schneider, and Meaghan M. Donahue70
Delaware Gov. Matt Meyer signed H.B. 380 on September 2, requiring stronger third-party data controls and expanding consumer privacy rights statewide from January 1, 2027.
9/15/2026 • Regulation, Law & Enforcement • General
New Jersey Division of Consumer Affairs will launch a 2027 public registry for data brokers and data collectors and restrict sensitive data sales under P.L.2026, c.25.
7/13/2026 • Regulation, Law & Enforcement • General
Alex Schneider, Aaron Burstein, and Celine Guillou discussed expanding New Jersey and California data broker obligations for businesses operating across state data flows.
8/3/2026 • Regulation, Law & Enforcement • General
New Jersey enacted A5328 on June 30, requiring annual registration for data brokers and data collectors and banning sensitive data sales with uncapped penalties.
7/10/2026 • Regulation, Law & Enforcement • General
Connecticut signed SB 4 on May 27, 2026, creating data broker registration and deletion mechanisms while restricting precise geolocation resale and surveillance pricing.
7/6/2026 • Regulation, Law & Enforcement • General
Connecticut signed SB 4 on May 27, expanding CTDPA deletion rights, creating a data broker registry, restricting surveillance pricing, and adding direct-to-consumer genetic testing protections.
5/27/2026 • Regulation, Law & Enforcement • General
Connecticut House passed Senate Bill 4 in 2020s, regulating data brokers and adding consumer data deletion and restrictions on geolocation and facial recognition for Gov. Ned Lamont review.
5/4/2026 • Regulation, Law & Enforcement • General
Connecticut lawmakers passed a data broker registry law in May, while Washington considers federal rules requiring similar registration and public directories.
6/25/2026 • Regulation, Law & Enforcement • General
Massachusetts lawmakers advance H.5472 establishing consumer data privacy rights, including consent limits for sensitive data and a precise geolocation sale ban.
6/11/2026 • Regulation, Law & Enforcement • General
CBIA opposed several Connecticut committee bills in 2026 that would expand employer privacy and cybersecurity duties, including data broker controls, geolocation limits, and massive-breach forensic reporting.
3/27/2026 • Regulation, Law & Enforcement • General
Connecticut, Florida, South Carolina and Minnesota advanced enforcement and new privacy rules in 2025, focusing on deletion rights, children's privacy, foreign-adversary risks, and AI retention.
1/1/1900 • Regulation, Law & Enforcement • General
Delaware Governor Matt Meyer, Attorney General Kathy Jennings, and state lawmakers signed House Bills 380 and 381, expanding consumer privacy protections statewide before the laws take effect January 1, 2027.
9/10/2026 • Regulation, Law & Enforcement • General
Delaware Gov. Matt Meyer signed privacy legislation expanding consumer protections and clarifying breach notification duties in Delaware, with major changes taking effect in 2027.
9/3/2026 • Regulation, Law & Enforcement • General
Delaware enacted expanded privacy protections in 2025, broadening company coverage and requiring faster potential-breach notifications to the state Department of Justice.
9/3/2026 • Regulation, Law & Enforcement • General
Delaware Governor Matt Meyer signed two privacy bills in Wilmington on September 2, 2026, expanding sensitive-data rights and regulating automated decisions.
9/2/2026 • Regulation, Law & Enforcement • General
In the United States, data broker practices that collect and resell personal dossiers are linked to opt-out difficulties and large consumer harms from exposure and misuse.
7/8/2026 • Corporate Data Practices & Accountability • General
Connecticut Attorney General William Tong released the 2025 Connecticut Data Privacy Act enforcement report, outlining privacy enforcement activity and business compliance expectations in Connecticut.
3/8/2026 • Regulation, Law & Enforcement • General