Preskočiť na hlavný obsah

Connecticut's Data Privacy Act Now Reaches You at 35,000 Consumers: A Small-Business Compliance Guide

Publikované 10 minút čítaniaMike ThriftMike Thrift
Connecticut's Data Privacy Act Now Reaches You at 35,000 Consumers: A Small-Business Compliance Guide

If your website had 35,000 visitors from Connecticut last year, you may have woken up on July 1, 2026 as a regulated business under one of the toughest state privacy laws in the country — without changing a single thing about how you operate.

That is the practical effect of Connecticut's 2026 overhaul of its Data Privacy Act. The state cut its applicability threshold by nearly two-thirds, added two triggers that have no numerical threshold at all, expanded the definition of sensitive data, eliminated the guaranteed grace period for first-time violations, and stacked a second wave of requirements taking effect October 1. If you sell online, run targeted ads, share customer data with analytics or ad-tech vendors, or collect anything that counts as sensitive data, this guide walks through exactly what changed and the concrete steps to get compliant.

What Actually Changed on July 1, 2026

Connecticut's original privacy law, in effect since 2023, applied mainly to larger organizations: those processing the personal data of at least 100,000 Connecticut residents, or at least 25,000 residents if more than a quarter of gross revenue came from selling personal data. Most small and mid-sized businesses could reasonably conclude the law was not about them.

The amendments, enacted through SB 1295, replace that framework with three alternative triggers. Meet any one of them during the preceding calendar year and you are in scope:

  1. You controlled or processed the personal data of at least 35,000 Connecticut consumers. Data processed solely to complete a payment transaction does not count toward this number, but nearly everything else does — website analytics, email lists, order histories, support tickets, loyalty programs.
  2. You controlled or processed any Connecticut consumer's sensitive data. There is no minimum volume. One record can be enough.
  3. You offered any Connecticut consumer's personal data for sale. Again, no minimum. And "sale" here means exchanging personal data for monetary or other valuable consideration — which can include sharing data with ad networks, data brokers, or analytics providers in ways many businesses do not think of as selling.

The old 25-percent-of-revenue trigger is gone entirely. The direction of travel is unmistakable: where the original law asked "are you big enough to regulate," the amended law asks "did you touch the wrong kind of data, or share data at all."

Why 35,000 Is Easier to Hit Than It Sounds

Thirty-five thousand Connecticut residents is roughly 1 percent of the state's population. A regional e-commerce store, a SaaS product with a few thousand paying accounts, a content site with modest traffic, or a service business with a large email list can cross that line without ever targeting Connecticut specifically — the law covers any business that operates in the state or targets products or services to its residents. If your site is accessible to Connecticut shoppers and your analytics show five-figure annual uniques from the state, assume you need to count carefully rather than assume you are out.

The Sensitive-Data Trap: No Threshold, Broader Definition

The most consequential change for small businesses is not the lower headcount — it is the combination of a zero-threshold sensitive-data trigger with a significantly expanded definition of what counts as sensitive.

Under the amended law, the sensitive category now includes data revealing mental or physical disability or treatment, nonbinary or transgender status, information derived from biometric and genetic data, neural data, financial account information, and government-issued identification numbers, alongside the previously covered categories such as precise geolocation, racial or ethnic origin, religious beliefs, sex life or sexual orientation, citizenship status, and children's data.

Processing any of that — even for a single Connecticut resident — pulls you into the law's scope. And once you are in scope, two further obligations attach to sensitive data specifically:

  • Limit processing to what is reasonably necessary for the purposes you disclosed, and
  • Obtain consumer consent before processing it — including, explicitly, before selling it.

For ordinary small businesses, sensitive data shows up in surprising places: a wellness intake form noting a medical condition, a job application collecting a driver's license number, a loyalty program storing payment credentials alongside purchase history, a fitness or accessibility feature generating biometric-adjacent measurements. None of these require malicious intent to create exposure. Map where such data enters your systems before assuming you hold none.

New Consumer Rights You Must Be Ready to Honor

The amendments give Connecticut residents several new rights that translate directly into operational work for your business:

  • A list of the specific third parties to whom their personal data was sold. A generic "we share data with partners" disclosure no longer suffices — you need to know, buyer by buyer, where data went.
  • Explanations for profiling decisions with legal or similarly significant effects, including the reasoning behind the decision and the data used. In housing-related decisions specifically, consumers can correct inaccurate data and have the decision re-evaluated.
  • Broader access rights that expressly include inferences and profiling information. Note the guardrail running the other way: for higher-risk categories such as Social Security numbers, certain financial data, and biometric elements, you must confirm you hold the data rather than handing the actual values over in response to a request.
  • Stronger opt-out mechanics for targeted advertising, data sales, and consequential profiling, including through authorized agents.

Separately, your privacy notice must now disclose whether you collect, use, or sell personal data to train large language models — a requirement Connecticut shares with Vermont and one that matters to any business using customer content or support conversations as model-training fodder.

There are also new protections for minors: controllers may not sell, or process for targeted advertising, the personal data of consumers aged 13 to 17.

Enforcement Now Has Real Teeth

Under the original law, businesses enjoyed a guaranteed 60-day cure period — a right to fix a violation before penalties could attach. That safety net is gone. The Attorney General retains discretion to offer a cure, but nothing guarantees one.

Penalties run under the state's unfair trade practices framework: up to $5,000 per willful violation and up to $2,500 per non-willful violation. Multiplied across an email list or customer database, those per-violation figures escalate fast. The Attorney General's office has already published business guidance on the expanded scope and filed an annual enforcement report describing active enforcement — the waiting period for taking this seriously ended with the effective date.

One more scope change with quiet bite: the old entity-level exemption for financial institutions under the Gramm-Leach-Bliley Act has been replaced with a narrower data-level exemption. If you are a small lender, broker, insurer, or fintech-adjacent business that assumed blanket exemption, re-examine which specific data and activities are actually excluded rather than relying on your industry label.

Wave Two Arrives October 1: Geolocation, Data Brokers, and More

A companion package, SB 4 as amended by HB 5222, takes effect October 1, 2026, and adds restrictions worth preparing for now:

  • Precise geolocation sales are outright prohibited. Not consent-gated — banned.
  • New-purpose consent gets stricter. Previously you needed consent before processing for a materially different new purpose; the materiality qualifier is removed, so any new purpose that is not reasonably necessary or compatible with the originally disclosed purpose requires fresh consent.
  • Data broker registration begins January 1, 2027, phasing in through 2031. Businesses that knowingly sell or license personal data of consumers with whom they have no direct relationship must register with the state and provide a single deletion-request mechanism covering all registered brokers.
  • Surveillance pricing — using personal data to set individualized prices — faces new restrictions, alongside new disclosure and consent requirements for on-premises facial recognition and new rules for direct-to-consumer genetic testing companies.

If your pricing, personalization, or location-data practices touch any of these areas, the July compliance project and the October one are really a single program with two deadlines.

Your 6-Step Compliance Checklist

You do not need a law-firm budget to make meaningful progress. Work through these in order:

1. Determine whether you are in scope

Pull 2025 full-year numbers and 2026 year-to-date figures: Connecticut-resident uniques and customers, any sensitive-data holdings, and any data sharing that could qualify as a sale — including ad-tech pixels, audience-list uploads, and analytics arrangements. Because two of the three triggers have no volume floor, default to assuming coverage until your inventory proves otherwise.

2. Map your data flows

Build a simple inventory: what personal and sensitive data you collect, where it enters (forms, checkouts, pixels, imports), what you use it for, where it is stored, and every third party that receives it. Pay special attention to tracking pixels, list exchanges, and "free" analytics tools paid for with data access. This map is the foundation for everything downstream — notices, consent, rights fulfillment, and vendor contracts.

Update your privacy notice to cover the newly required disclosures — profiling, targeted advertising, LLM training use, data sales with buyer-level detail — and make sure notices are conspicuous and accessible. Gate sensitive-data collection and any sale of sensitive data behind clear opt-in consent, and confirm your flows capture and timestamp that consent.

4. Build rights-fulfillment workflows

Stand up a repeatable process for access, correction, deletion, opt-out, buyer-list, and profiling-explanation requests: an intake channel, identity verification proportionate to the sensitivity of the data, a 45-day response clock with extension handling, and an appeal path. Test it with a dry run before a real request arrives.

5. Review vendors and profiling systems

Renegotiate vendor agreements to reflect the amended obligations — processing instructions, sale restrictions, sub-processor transparency, and cooperation on consumer requests. For any profiling that drives consequential decisions, prepare the newly required impact assessment covering purpose, risk analysis, data categories, performance metrics, transparency measures, and post-deployment monitoring. The assessment duty applies to activities created or generated on or after August 1, 2026, and the Attorney General can request to see it.

6. Lock down minors' data and geolocation

Suppress targeted advertising and data sales for 13-to-17-year-olds, strip engagement-maximizing design features aimed at minors, and halt any sale or sharing of precise geolocation data before the October 1 ban.

Where Bookkeeping Meets Privacy Compliance

Privacy compliance is a bookkeeping problem as much as a legal one. Your data map, consent timestamps, buyer lists, vendor contracts, and impact assessments are records — and records need the same discipline as your financials: complete, timestamped, reconcilable, and retrievable on demand.

That is also where the costs land. Consent-tooling subscriptions, notice rewrites, vendor renegotiations, and staff time for rights fulfillment are real compliance expenditures. Track them in a dedicated compliance cost category rather than letting them dissolve into general software or legal spend. When renewal season arrives — or if the Attorney General ever asks what you did and when — a clean ledger showing what you spent, which vendors you pay for data handling, and when each control went live is worth far more than a folder of screenshots. Separating compliance costs also keeps them visible at tax time instead of buried in overhead.

Simplify Your Financial Management

As you work through privacy compliance alongside everything else competing for your attention, maintaining clear financial records keeps the whole effort auditable. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — no black boxes, no vendor lock-in. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Zdieľať tento článok

Zdroj: https://beancount.io/sk/blog/2026/09/11/connecticut-data-privacy-act-threshold-35000-small-business-compliance-guide

Publikované: 11. septembra 2026