Connecticut Tightens Rules On Personal Data
Coverage from Foley & Lardner, TechTimes, and others

Connecticut is expanding its privacy framework to regulate data brokers, restrict the sale and use of precise geolocation data, limit surveillance pricing, and give consumers greater control over genetic information and publicly available data used in profiles.
Public Act No. 26-64 creates a data broker registry and a centralized deletion mechanism, while related amendments broaden sensitive-data, profiling, and transparency obligations. The phased implementation will create new operational requirements for companies that collect, sell, analyze, or use personal data in Connecticut.
The update mainly formalizes and operationalizes Connecticut’s previously reported reforms, identifying Public Act No. 26-64 and clarifying phased compliance deadlines. The narrative also shifts from a multi-state overview toward Connecticut-specific implementation and oversight.
The story has broadened from a Connecticut-led privacy-law cluster into a wider state policy shift, with New Jersey enacting major restrictions and Massachusetts advancing a consequential proposal. Enforcement and AI-related compliance requirements are also becoming more operational and specific.
- New Jersey enacted A5328 requiring annual registration for data brokers and data collectors.
- New Jersey broadly prohibited selling or licensing sensitive personal data.
- Massachusetts advanced a privacy bill with a private right of action, but enactment remains unresolved.
- Connecticut now requires disclosures about personal-data use in large-language-model training.
- Privacy regulators are reviewing rights requests, opt-out signals, cookie interfaces, breach notices, and sensitive-data practices.
The main update is greater specificity about Delaware’s privacy expansion: its amendments now clearly cover neural data, sensitive inferences, and safeguards for certain automated decisions. Connecticut’s previously described framework is largely confirmed rather than materially changed.
The story now extends beyond Connecticut, adding Delaware privacy and breach-notification changes as a second state-level development. Connecticut’s provisions are further specified, particularly protections for genetic samples and narrower treatment of publicly available information.
The story has shifted from general state privacy enforcement toward a concrete, enacted Connecticut framework with detailed controls and a long implementation timeline. Public Act 26-64 and related amendments create new operational obligations for data brokers and companies using sensitive data.
- Public Act 26-64 establishes Connecticut’s data-broker registry, with registration beginning January 1, 2027.
- Connecticut must create a centralized data-broker deletion mechanism by July 1, 2028.
- The law restricts commercial use of precise geolocation data and surveillance pricing based on personal information.
- Senate Bill 1295 expands Connecticut Data Privacy Act coverage and adds profiling impact-assessment requirements.
- Later implementation phases require deletion-request reporting and independent data-broker audits through 2031.
The story now broadens beyond Connecticut and New Jersey to show a wider multi-state privacy enforcement push, with the emphasis shifting toward fragmented but converging rules across several states. Connecticut’s enforcement focus is also more specific on deceptive cookie banners and universal opt-out failures, while New Jersey’s framework is framed more clearly as an operational registration-and-penalty regime.
The update is more concrete: Connecticut’s story now centers on documented enforcement activity, while New Jersey’s framework has moved from prospective legislation to enacted registration and sensitive-data restrictions. The framing also broadens from general privacy-law adoption to more active oversight of ads, opt-out mechanics, minors, and data-broker conduct.
- Connecticut reported more than 1,830 breach notifications in 2025.
- Connecticut issued 63 warning letters over delayed breach notice.
- New Jersey enacted annual registration requirements for data brokers and data collectors.
- New Jersey added civil penalties for sensitive-data sale or licensing violations.
- Children’s privacy reviews now include chatbots, messaging apps, and gaming platforms.
The story broadens from Connecticut-centric privacy tightening to a wider multi-state enforcement and legislation trend, with New Jersey joining Connecticut as a major driver. The emphasis also shifts from mainly statutory expansion to more operational enforcement and implementation across data brokers, sensitive data sales, and deletion/opt-out rights.
- New Jersey is now a leading privacy-law actor.
- Sensitive-data sales limits now include biometric, health, and minors' data.
- Regulators are issuing warning letters and targeted investigations.
- Privacy developments now span six states, not just Connecticut.
- The story now centers on phased implementation through 2027-2028.
The story shifts from broad state privacy-law activity toward Connecticut’s concrete implementation and enforcement, including a centralized data-broker deletion system, staged compliance deadlines, and warnings over delayed breach notices.
The story has shifted from a general tightening of state privacy rules to a more concrete Connecticut-led regime now backed by enacted amendments and implementation details. Massachusetts is still part of the picture, but Delaware and enforcement themes around opt-outs, dark patterns, and AI-related governance are newly explicit.
- Connecticut enacted Public Act No. 26-64 privacy amendments.
- Connecticut rules now phase in through 2031.
- Delaware is advancing the Delaware Personal Data Privacy Act.
- Enforcement reporting now highlights chatbot or AI-related governance.
- Public data broker registries are emerging in multiple states.
The story now centers more clearly on enacted and advancing state privacy frameworks, with Connecticut described as having moved into a new statutory phase rather than just active enforcement. Massachusetts is also framed as a broader bill with a larger rights package and stronger enforcement tools.
Connecticut’s privacy story has moved from legislation-in-progress to enacted law, while enforcement has broadened into more operational compliance areas. Massachusetts now meaningfully extends the narrative by adding a parallel state bill with a private right of action and cellphone location-data ban.
- Connecticut signed SB 4 into law.
- Massachusetts advanced a consumer privacy bill.
- The Massachusetts bill bans cellphone location data sales.
- It would allow injured consumers to sue for violations.
- Connecticut enforcement now emphasizes chatbots and universal opt-out signals.
The cluster is centered on Connecticut's privacy regime tightening through both enforcement reporting and active legislation. The dominant current signal is a move from baseline CTDPA implementation toward more specific compliance pressure on breach notifications, data-rights handling, opt-out enforcement, data broker practices, and sensitive-data restrictions. The strongest recent development is SB 4, which expands consumer control over broker-held data and limits geolocation, facial recognition, and surveillance pricing uses. The broader pattern is a state-level privacy escalation with recurring emphasis on operational compliance, consumer deletion rights, and protections for minors and genetic data.
