Connecticut Amends Privacy Law for a Third Time and Introduces New Requirements for Data Brokering, Personalized Pricing, Using Facial Recognition, Selling Geolocation Data, and Moreby Tatum Andres A new package of Connecticut privacy laws significantly expands the state’s privacy framework. Through SB 4, HB 5222, and HB 5563, Connecticut has amended the Connecticut Data Privacy Act (CTDPA), created a new data broker registration and deletion regime, imposed restrictions on certain forms of data-driven pricing, and established a direct-to-consumer genetic testing privacy law.
Key changes include a prohibition on the sale of precise geolocation data, expanded consumer deletion rights, new transparency obligations for facial recognition technology used for security and fraud prevention, annual registration requirements for data brokers, a state-administered deletion mechanism similar to California’s Delete Act, restrictions on “surveillance pricing,” and enhanced protections for consumers’ genetic data and biological samples. Many of the requirements take effect beginning October 1, 2026, with additional obligations rolling out through 2028 and beyond.
The bottom line: Organizations that collect, use, sell, or share consumer data in Connecticut should assess whether these changes affect their privacy programs and products. The new requirements are particularly relevant for any company that collects or shares geolocation data, operates as or works with data brokers, uses facial recognition technology, personalizes pricing, or offers direct-to-consumer genetic testing services.
What you need to do:
×
|
