What CTDPA actually requires
Connecticut's consumer privacy law (CTDPA). Sits between the Virginia and Colorado models — universal opt-out signals, opt-outs for the sale of data, targeted advertising and certain profiling, and stronger protections around sensitive data. Enforced by the Connecticut Attorney General.
Key requirements
- Publish a privacy notice that includes categories of data and purposes
- Offer opt-outs of targeted advertising, sale of data and profiling for legal/significant effects
- Honour universal opt-out mechanisms (e.g. Global Privacy Control)
- Obtain opt-in consent before processing sensitive data
- Conduct data protection assessments for high-risk processing
- Respond to consumer rights requests within 45 days
At a glance
Full name
Connecticut Data Privacy Act
Region
Connecticut, USA
Status
In force since July 2023
Who it affects
Persons who conduct business in Connecticut and either (a) processed personal data of 100,000+ Connecticut residents in the prior year, or (b) processed data of 25,000+ residents and derived more than 25% of revenue from the sale of personal data.
Penalties
Enforced as an unfair trade practice under Connecticut law. Civil penalties up to USD 5,000 per violation, plus injunctive relief, restitution and other equitable remedies.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
