Does Connecticut CTDPA Amendments (SB 1295 / Public Act 25-113) require Risk Assessment?

Connecticut • enforcing

Yes — 2 provisions

Requirements at a glance

This regulation imposes 19 specific requirements for Risk Assessment across 2 provisions:

Profiling Impact Assessment #

Obligation:
Risk Assessment
enforcing
Effective:
Jul 1, 2026
Risk tier:
high-risk
Scope:
Every controller subject to the CTDPA that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer (§ 42-522(c)). The applicability threshold in § 42-516 was lowered to 35,000 consumers by the same act
high-impact
This is a second, separate assessment sitting alongside the CTDPA data protection assessment in § 42-522(b) — a controller doing legal-effect profiling now owes both, and the two have different content. The seven elements read as an AI model card written into privacy law: inputs, outputs, customization data, performance metrics, known limitations, transparency measures, and post-deployment monitoring. § 42-522(g)(2) is the date that matters operationally: the impact assessment duty applies only to processing activities created or generated **on or after 2026-08-01** and is expressly not retroactive, one month later than the section's own 2026-07-01 effective date, and a separate clock from the 2023-07-01 line that governs data protection assessments under § 42-522(g)(1).

Requirements

RequirementDetails
Assessment triggerEach controller that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer must conduct an impact assessment for that profiling (§ 42-522(c))
Purpose and deployment contextA statement disclosing the purpose, intended use cases and deployment context of, and benefits afforded by, the profiling (§ 42-522(c)(1))
Heightened-risk analysisAn analysis of whether the profiling poses any known or reasonably foreseeable heightened risk of harm to a consumer and, if so, the nature of that risk and the steps taken to mitigate it (§ 42-522(c)(2))
Inputs and outputsA description of the main categories of personal data processed as inputs for the profiling and of the outputs the profiling produces (§ 42-522(c)(3))
Customization dataAn overview of the main categories of personal data used to customize the profiling, where the controller used data to customize it (§ 42-522(c)(4))
Performance metrics and limitationsAny metrics used to evaluate the performance and known limitations of the profiling (§ 42-522(c)(5))
Transparency measuresA description of any transparency measures taken concerning the profiling, including measures disclosing to consumers that the controller is engaged in the profiling while it is engaged in it (§ 42-522(c)(6))
Post-deployment monitoringA description of the post-deployment monitoring and user safeguards, including the oversight, use and learning processes established to address issues arising from the profiling (§ 42-522(c)(7))
Not retroactiveThe impact assessment requirement applies only to processing activities created or generated on or after 2026-08-01 (§ 42-522(g)(2))
Batching permittedA single data protection assessment or impact assessment may address a comparable set of processing operations that include similar activities (§ 42-522(e))
Other-law equivalenceAn assessment conducted to comply with another applicable law or regulation satisfies this section if it is reasonably similar in scope and effect (§ 42-522(f))

Penalties

ViolationFine
Non-complianceThe act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action
Cure period**No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525
View full regulation View obligation Obligation matrix