Connecticut CTDPA Amendments (SB 1295 / Public Act 25-113)

Jurisdiction:
Connecticut
enforcing
Effective:
Jul 1, 2026
Authority:
Connecticut Attorney General
Official text

Obligations Covered

Transparency & Disclosure Risk Assessment Record-Keeping & Documentation

Timeline

MilestoneDateNotes
Passed both chambersJun 3, 2025sSB 1295
Signed by the GovernorJun 24, 2025Public Act 25-113
General cure period expiredDec 31, 2024§ 42-525(b): the mandatory 60-day cure for §§ 42-515 to 42-524 ran 2023-07-01 to this date; cure is discretionary on seven factors from 2025-01-01 (§ 42-525(c))
Minors cure window expiredDec 31, 2025§ 42-529e(b): the mandatory notice-and-30-day-response window for §§ 42-529 to 42-529d ran 2024-10-01 to this date; discretionary from 2026-01-01 (§ 42-529e(c))
CTDPA amendments effectiveJul 1, 2026P.A. 25-113 secs. 5-18; consumer opt-out expansion, LLM-training disclosure
Impact assessments applyAug 1, 2026§ 42-522(g)(2): profiling impact assessments apply to processing activities created or generated on or after this date; not retroactive

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Expanded Consumer Opt-Out #

Obligation:
Transparency
enforcing
Effective:
Jul 1, 2026
Risk tier:
all
Scope:
controllers (entities subject to CTDPA)

Requirements

RequirementDetails
Expanded opt-outConsumers may opt out of profiling in furtherance of automated decisions with legal/significant effects — "solely automated" qualifier removed; now covers human-in-the-loop profiling
Right to confirmConsumers may confirm whether their data is being processed for profiling
Right to explanationConsumers may request explanation of profiling outcomes affecting them
Data review and correctionConsumers may review data used in profiling decisions and correct inaccurate data
Re-evaluationConsumers may request re-evaluation after correcting data (especially in housing contexts)

Penalties

ViolationFine
Non-complianceThe act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action
Cure period**No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525
Sources: CT SB 1295

Profiling Impact Assessment #

Obligation:
Risk Assessment
enforcing
Effective:
Jul 1, 2026
Risk tier:
high-risk
Scope:
Every controller subject to the CTDPA that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer (§ 42-522(c)). The applicability threshold in § 42-516 was lowered to 35,000 consumers by the same act
high-impact
This is a second, separate assessment sitting alongside the CTDPA data protection assessment in § 42-522(b) — a controller doing legal-effect profiling now owes both, and the two have different content. The seven elements read as an AI model card written into privacy law: inputs, outputs, customization data, performance metrics, known limitations, transparency measures, and post-deployment monitoring. § 42-522(g)(2) is the date that matters operationally: the impact assessment duty applies only to processing activities created or generated **on or after 2026-08-01** and is expressly not retroactive, one month later than the section's own 2026-07-01 effective date, and a separate clock from the 2023-07-01 line that governs data protection assessments under § 42-522(g)(1).

Requirements

RequirementDetails
Assessment triggerEach controller that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer must conduct an impact assessment for that profiling (§ 42-522(c))
Purpose and deployment contextA statement disclosing the purpose, intended use cases and deployment context of, and benefits afforded by, the profiling (§ 42-522(c)(1))
Heightened-risk analysisAn analysis of whether the profiling poses any known or reasonably foreseeable heightened risk of harm to a consumer and, if so, the nature of that risk and the steps taken to mitigate it (§ 42-522(c)(2))
Inputs and outputsA description of the main categories of personal data processed as inputs for the profiling and of the outputs the profiling produces (§ 42-522(c)(3))
Customization dataAn overview of the main categories of personal data used to customize the profiling, where the controller used data to customize it (§ 42-522(c)(4))
Performance metrics and limitationsAny metrics used to evaluate the performance and known limitations of the profiling (§ 42-522(c)(5))
Transparency measuresA description of any transparency measures taken concerning the profiling, including measures disclosing to consumers that the controller is engaged in the profiling while it is engaged in it (§ 42-522(c)(6))
Post-deployment monitoringA description of the post-deployment monitoring and user safeguards, including the oversight, use and learning processes established to address issues arising from the profiling (§ 42-522(c)(7))
Not retroactiveThe impact assessment requirement applies only to processing activities created or generated on or after 2026-08-01 (§ 42-522(g)(2))
Batching permittedA single data protection assessment or impact assessment may address a comparable set of processing operations that include similar activities (§ 42-522(e))
Other-law equivalenceAn assessment conducted to comply with another applicable law or regulation satisfies this section if it is reasonably similar in scope and effect (§ 42-522(f))

Penalties

ViolationFine
Non-complianceThe act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action
Cure period**No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525

Large Language Model Training Disclosure #

Obligation:
Transparency
enforcing
Effective:
Jul 1, 2026
Risk tier:
all
Scope:
Every controller subject to the CTDPA that is required to publish a privacy notice under § 42-520(b)(1)
high-impactsleeper
Tagged `sleeper` because the duty is AI-specific but lives inside a general consumer privacy act, so it binds by controller status rather than by anything the controller does with models. Every organization over the § 42-516 threshold — retailers, insurers, hospitals, employers — must now take a position in its published privacy notice on whether it collects, uses or sells personal data to train large language models, including the position that it does not. That makes it the first US statutory disclosure aimed squarely at training-data provenance and the cheapest available discovery tool: the notice is a dated public statement the Attorney General can hold a controller to. Note the statute says "large language models" specifically, not "artificial intelligence" or "automated decision systems", so a controller training a non-language model is outside the literal text.

Requirements

RequirementDetails
LLM training statementThe privacy notice must include a statement disclosing whether the controller collects, uses or sells personal data for the purpose of training large language models (§ 42-520(b)(1)(H))
Notice currencyThe same notice must state the most recent month and year during which the controller updated it (§ 42-520(b)(1)(I)), so a stale LLM training statement is visible on its face
PublicationThe notice must be published through a conspicuous hyperlink containing the word "privacy" on the web site home page, on the app store or download page and in the app settings menu where applicable, in every language in which the controller offers the covered product or service, and in a manner reasonably accessible to and usable by individuals with disabilities (§ 42-520(b)(2))
Material change noticeWhere a controller makes a retroactive material change to its privacy notice or practices, it must comply with the change-notification duties in § 42-520(b)(3)

Penalties

ViolationFine
Non-complianceThe act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action
Cure period**No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525

Attorney General Access to Assessments #

Obligation:
Record Keeping
enforcing
Effective:
Jul 1, 2026
Risk tier:
all
Scope:
Controllers that conduct data protection assessments under § 42-522(b) or profiling impact assessments under § 42-522(c)
cross-domain
This is the provision that converts the § 42-522(c) impact assessment from a paperwork exercise into a retained, producible record. Three design choices matter together: the Attorney General may compel any assessment relevant to an investigation and evaluate it for compliance across §§ 42-515 to 42-525; the assessments are confidential and exempt from the Freedom of Information Act, so a competitor cannot obtain them by request; and disclosure to the Attorney General waives neither attorney-client privilege nor work product protection. The privilege carve-out is the load-bearing piece — without it, counsel would advise against writing anything candid in an assessment, which is precisely how comparable assessment regimes hollow out.

Requirements

RequirementDetails
Production on demandThe Attorney General may require a controller to disclose any data protection assessment or impact assessment relevant to an investigation, and the controller must make it available (§ 42-522(d))
Evaluation for complianceThe Attorney General may evaluate a produced assessment for compliance with the responsibilities set out in §§ 42-515 to 42-525 (§ 42-522(d))
FOIA exemptionData protection assessments and impact assessments are confidential and exempt from disclosure under the Freedom of Information Act as defined in Conn. Gen. Stat. § 1-200 (§ 42-522(d))
No privilege waiverWhere a produced assessment contains information subject to attorney-client privilege or work product protection, disclosure to the Attorney General does not constitute a waiver (§ 42-522(d))
Processor assistanceA processor must provide any information necessary to enable the controller to conduct and document the assessments, so the record must be assemblable across the vendor chain (§ 42-529c(a)(2))
Minors' harm mitigation planWhere a minors' assessment finds a heightened risk of harm to minors, the controller must establish and implement a mitigation or elimination plan, and must disclose it to the Attorney General on request not later than ninety days after being notified (§ 42-529b(f))
Minors' assessments confidentialMinors' data protection assessments, impact assessments and harm mitigation plans carry the same FOIA exemption and the same no-waiver rule (§ 42-529b(g))

Penalties

ViolationFine
Failure to produceThe act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action
Cure period**No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525
Cite this regulation

Permalink: https://everyailaw.com/regulation/connecticut-sb1295/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Connecticut CTDPA Amendments (SB 1295 / Public Act 25-113)”, EveryAILaw.com, Aug 3, 2026. https://everyailaw.com/regulation/connecticut-sb1295/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.