Connecticut CTDPA Amendments (SB 1295 / Public Act 25-113)
Obligations Covered
Timeline
| Milestone | Date | Notes |
|---|---|---|
| Passed both chambers | Jun 3, 2025 | sSB 1295 |
| Signed by the Governor | Jun 24, 2025 | Public Act 25-113 |
| General cure period expired | Dec 31, 2024 | § 42-525(b): the mandatory 60-day cure for §§ 42-515 to 42-524 ran 2023-07-01 to this date; cure is discretionary on seven factors from 2025-01-01 (§ 42-525(c)) |
| Minors cure window expired | Dec 31, 2025 | § 42-529e(b): the mandatory notice-and-30-day-response window for §§ 42-529 to 42-529d ran 2024-10-01 to this date; discretionary from 2026-01-01 (§ 42-529e(c)) |
| CTDPA amendments effective | Jul 1, 2026 | P.A. 25-113 secs. 5-18; consumer opt-out expansion, LLM-training disclosure |
| Impact assessments apply | Aug 1, 2026 | § 42-522(g)(2): profiling impact assessments apply to processing activities created or generated on or after this date; not retroactive |
Related Regulations and Standards
Related instruments are selected from shared compliance obligations and jurisdiction coverage.
Expanded Consumer Opt-Out #
Requirements
| Requirement | Details |
|---|---|
| Expanded opt-out | Consumers may opt out of profiling in furtherance of automated decisions with legal/significant effects — "solely automated" qualifier removed; now covers human-in-the-loop profiling |
| Right to confirm | Consumers may confirm whether their data is being processed for profiling |
| Right to explanation | Consumers may request explanation of profiling outcomes affecting them |
| Data review and correction | Consumers may review data used in profiling decisions and correct inaccurate data |
| Re-evaluation | Consumers may request re-evaluation after correcting data (especially in housing contexts) |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | The act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action |
| Cure period | **No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525 |
Sources: CT SB 1295
Profiling Impact Assessment #
This is a second, separate assessment sitting alongside the CTDPA data protection assessment in § 42-522(b) — a controller doing legal-effect profiling now owes both, and the two have different content. The seven elements read as an AI model card written into privacy law: inputs, outputs, customization data, performance metrics, known limitations, transparency measures, and post-deployment monitoring. § 42-522(g)(2) is the date that matters operationally: the impact assessment duty applies only to processing activities created or generated **on or after 2026-08-01** and is expressly not retroactive, one month later than the section's own 2026-07-01 effective date, and a separate clock from the 2023-07-01 line that governs data protection assessments under § 42-522(g)(1).
Requirements
| Requirement | Details |
|---|---|
| Assessment trigger | Each controller that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer must conduct an impact assessment for that profiling (§ 42-522(c)) |
| Purpose and deployment context | A statement disclosing the purpose, intended use cases and deployment context of, and benefits afforded by, the profiling (§ 42-522(c)(1)) |
| Heightened-risk analysis | An analysis of whether the profiling poses any known or reasonably foreseeable heightened risk of harm to a consumer and, if so, the nature of that risk and the steps taken to mitigate it (§ 42-522(c)(2)) |
| Inputs and outputs | A description of the main categories of personal data processed as inputs for the profiling and of the outputs the profiling produces (§ 42-522(c)(3)) |
| Customization data | An overview of the main categories of personal data used to customize the profiling, where the controller used data to customize it (§ 42-522(c)(4)) |
| Performance metrics and limitations | Any metrics used to evaluate the performance and known limitations of the profiling (§ 42-522(c)(5)) |
| Transparency measures | A description of any transparency measures taken concerning the profiling, including measures disclosing to consumers that the controller is engaged in the profiling while it is engaged in it (§ 42-522(c)(6)) |
| Post-deployment monitoring | A description of the post-deployment monitoring and user safeguards, including the oversight, use and learning processes established to address issues arising from the profiling (§ 42-522(c)(7)) |
| Not retroactive | The impact assessment requirement applies only to processing activities created or generated on or after 2026-08-01 (§ 42-522(g)(2)) |
| Batching permitted | A single data protection assessment or impact assessment may address a comparable set of processing operations that include similar activities (§ 42-522(e)) |
| Other-law equivalence | An assessment conducted to comply with another applicable law or regulation satisfies this section if it is reasonably similar in scope and effect (§ 42-522(f)) |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | The act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action |
| Cure period | **No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525 |
Sources: Public Act 25-113 (enacted text)
Large Language Model Training Disclosure #
Tagged `sleeper` because the duty is AI-specific but lives inside a general consumer privacy act, so it binds by controller status rather than by anything the controller does with models. Every organization over the § 42-516 threshold — retailers, insurers, hospitals, employers — must now take a position in its published privacy notice on whether it collects, uses or sells personal data to train large language models, including the position that it does not. That makes it the first US statutory disclosure aimed squarely at training-data provenance and the cheapest available discovery tool: the notice is a dated public statement the Attorney General can hold a controller to. Note the statute says "large language models" specifically, not "artificial intelligence" or "automated decision systems", so a controller training a non-language model is outside the literal text.
Requirements
| Requirement | Details |
|---|---|
| LLM training statement | The privacy notice must include a statement disclosing whether the controller collects, uses or sells personal data for the purpose of training large language models (§ 42-520(b)(1)(H)) |
| Notice currency | The same notice must state the most recent month and year during which the controller updated it (§ 42-520(b)(1)(I)), so a stale LLM training statement is visible on its face |
| Publication | The notice must be published through a conspicuous hyperlink containing the word "privacy" on the web site home page, on the app store or download page and in the app settings menu where applicable, in every language in which the controller offers the covered product or service, and in a manner reasonably accessible to and usable by individuals with disabilities (§ 42-520(b)(2)) |
| Material change notice | Where a controller makes a retroactive material change to its privacy notice or practices, it must comply with the change-notification duties in § 42-520(b)(3) |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | The act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action |
| Cure period | **No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525 |
Sources: Public Act 25-113 (enacted text)
Attorney General Access to Assessments #
This is the provision that converts the § 42-522(c) impact assessment from a paperwork exercise into a retained, producible record. Three design choices matter together: the Attorney General may compel any assessment relevant to an investigation and evaluate it for compliance across §§ 42-515 to 42-525; the assessments are confidential and exempt from the Freedom of Information Act, so a competitor cannot obtain them by request; and disclosure to the Attorney General waives neither attorney-client privilege nor work product protection. The privilege carve-out is the load-bearing piece — without it, counsel would advise against writing anything candid in an assessment, which is precisely how comparable assessment regimes hollow out.
Requirements
| Requirement | Details |
|---|---|
| Production on demand | The Attorney General may require a controller to disclose any data protection assessment or impact assessment relevant to an investigation, and the controller must make it available (§ 42-522(d)) |
| Evaluation for compliance | The Attorney General may evaluate a produced assessment for compliance with the responsibilities set out in §§ 42-515 to 42-525 (§ 42-522(d)) |
| FOIA exemption | Data protection assessments and impact assessments are confidential and exempt from disclosure under the Freedom of Information Act as defined in Conn. Gen. Stat. § 1-200 (§ 42-522(d)) |
| No privilege waiver | Where a produced assessment contains information subject to attorney-client privilege or work product protection, disclosure to the Attorney General does not constitute a waiver (§ 42-522(d)) |
| Processor assistance | A processor must provide any information necessary to enable the controller to conduct and document the assessments, so the record must be assemblable across the vendor chain (§ 42-529c(a)(2)) |
| Minors' harm mitigation plan | Where a minors' assessment finds a heightened risk of harm to minors, the controller must establish and implement a mitigation or elimination plan, and must disclose it to the Attorney General on request not later than ninety days after being notified (§ 42-529b(f)) |
| Minors' assessments confidential | Minors' data protection assessments, impact assessments and harm mitigation plans carry the same FOIA exemption and the same no-waiver rule (§ 42-529b(g)) |
Penalties
| Violation | Fine |
|---|---|
| Failure to produce | The act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action |
| Cure period | **No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525 |
Sources: Public Act 25-113 (enacted text)
Minors' Profiling Consent and Assessment #
Filed under `risk-assessment` rather than `data-governance` because the ongoing compliance process the section creates is the § 42-529b(b) impact assessment — six enumerated elements, review on any material change to the profiling operations, and documentation kept for the longer of three years after the operations cease or as long as the service is offered. The consent gate in § 42-529a(b)(3)(B) is a condition on a single processing activity rather than a sustained process, and § 42-529a(a) ties the two together by giving a controller that complies with § 42-529b a rebuttable presumption of reasonable care in any Attorney General enforcement action — the assessment is the safe harbor, so it is where the compliance weight sits. Two scope moves are easy to miss. The consent gate was broadened from profiling in furtherance of any **fully** automated decision to **any** automated decision, so a human reviewer in the loop no longer takes a minor's profiling outside it — the same widening the act made to the adult opt-out in § 42-518. And the assessment trigger in § 42-529b(b) is any profiling at all by a service offered to minors, not only legal-effect profiling; only the first of the six elements is qualified by legal or similarly significant effects. Separately, § 42-529d(d)(4) permits processing a minor's personal data for legal-effect profiling solely to detect or correct bias, on five conditions including deletion once the processing is complete, pseudonymization and other industry-standard security measures, strict documented access controls, and no third-party transmission or access — a construction rule creating a safe harbor rather than an obligation, so it is recorded here rather than as its own provision.
Requirements
| Requirement | Details |
|---|---|
| Consent before minors' profiling | No controller offering an online service, product or feature to known minors may process a minor's personal data for profiling in furtherance of any automated decision producing a legal or similarly significant effect concerning the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunity, health care services, or access to essential goods or services, unless reasonably necessary to provide the service, and unless the controller obtains the minor's consent (§ 42-529a(b)(3)(A) and (B)) |
| Parental consent under thirteen | Where the minor is younger than thirteen, the consent of a parent or legal guardian is required; compliance with the verifiable parental consent requirements of COPPA, 15 USC 6501 et seq., satisfies that requirement (§ 42-529a(b)(3)(B)) |
| No dark-pattern consent | The consent mechanism may not be designed to, or manipulated with the effect of, substantially subverting or impairing user autonomy, decision-making or choice (§ 42-529a(c)(1)(A)) |
| Impact assessment on any profiling | A controller offering an online service, product or feature to known minors that engages in any profiling based on those consumers' personal data must conduct an impact assessment for that service (§ 42-529b(b)) |
| Six assessment elements | Purpose, intended use cases, deployment context and benefits where the service profiles for legal-effect decisions; heightened-risk analysis for minors and mitigation steps; input categories and outputs; customization data categories; transparency measures, including in-use disclosure that the service is being used for profiling; and post-deployment monitoring and user safeguards, including oversight, use and learning processes (§ 42-529b(b)(1)-(6)) |
| Review on material change | The controller must review the data protection assessment or impact assessment as necessary to account for any material change to the processing or profiling operations of the service (§ 42-529b(c)(1)) |
| Three-year retention | Documentation must be maintained for the longer of the three-year period beginning when the processing or profiling operations cease, or as long as the controller offers the service (§ 42-529b(c)(2)) |
| Reasonable-care presumption | A controller that complied with § 42-529b enjoys a rebuttable presumption of reasonable care under § 42-529a(a) in an Attorney General enforcement action brought under § 42-529e |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | The act sets no penalty amount. A violation of §§ 42-529 to 42-529d is an unfair trade practice under Conn. Gen. Stat. § 42-110b(a), enforced **solely** by the Attorney General under § 42-529e(a), which also bars any private right of action and any action under § 42-110g |
| Cure period | **A separate regime from the general CTDPA, and it sunset later.** The mandatory notice window in § 42-529e(b) ran 2024-10-01 to 2025-12-31. Its mechanic also differs: the controller had 30 days to notify the Attorney General either that no violation occurred or that it had cured and taken preventive measures, and acceptance removed civil liability. Since 2026-01-01, § 42-529e(c) makes that opportunity discretionary on the same seven factors as § 42-525(c). P.A. 25-113 does not amend § 42-529e |
Sources: Public Act 25-113 (enacted text)
Cite this regulation
Permalink: https://everyailaw.com/regulation/connecticut-sb1295/
JSON: https://everyailaw.com/api/v1/regulations.json
Attribution: EveryAILaw, PAICE.work PBC. “Connecticut CTDPA Amendments (SB 1295 / Public Act 25-113)”, EveryAILaw.com, Aug 3, 2026. https://everyailaw.com/regulation/connecticut-sb1295/
Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.