Does Connecticut CTDPA Amendments (SB 1295 / Public Act 25-113) require Risk Assessment?
Connecticut • enforcing
Yes — 2 provisions
Requirements at a glance
This regulation imposes 19 specific requirements for Risk Assessment across 2 provisions:
- Assessment trigger — Each controller that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer must conduct an impact assessment for that profiling (§ 42-522(c))
- Purpose and deployment context — A statement disclosing the purpose, intended use cases and deployment context of, and benefits afforded by, the profiling (§ 42-522(c)(1))
- Heightened-risk analysis — An analysis of whether the profiling poses any known or reasonably foreseeable heightened risk of harm to a consumer and, if so, the nature of that risk and the steps taken to mitigate it (§ 42-522(c)(2))
- Inputs and outputs — A description of the main categories of personal data processed as inputs for the profiling and of the outputs the profiling produces (§ 42-522(c)(3))
- Customization data — An overview of the main categories of personal data used to customize the profiling, where the controller used data to customize it (§ 42-522(c)(4))
- Performance metrics and limitations — Any metrics used to evaluate the performance and known limitations of the profiling (§ 42-522(c)(5))
- Transparency measures — A description of any transparency measures taken concerning the profiling, including measures disclosing to consumers that the controller is engaged in the profiling while it is engaged in it (§ 42-522(c)(6))
- Post-deployment monitoring — A description of the post-deployment monitoring and user safeguards, including the oversight, use and learning processes established to address issues arising from the profiling (§ 42-522(c)(7))
- Not retroactive — The impact assessment requirement applies only to processing activities created or generated on or after 2026-08-01 (§ 42-522(g)(2))
- Batching permitted — A single data protection assessment or impact assessment may address a comparable set of processing operations that include similar activities (§ 42-522(e))
- Other-law equivalence — An assessment conducted to comply with another applicable law or regulation satisfies this section if it is reasonably similar in scope and effect (§ 42-522(f))
- Consent before minors' profiling — No controller offering an online service, product or feature to known minors may process a minor's personal data for profiling in furtherance of any automated decision producing a legal or similarly significant effect concerning the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunity, health care services, or access to essential goods or services, unless reasonably necessary to provide the service, and unless the controller obtains the minor's consent (§ 42-529a(b)(3)(A) and (B))
- Parental consent under thirteen — Where the minor is younger than thirteen, the consent of a parent or legal guardian is required; compliance with the verifiable parental consent requirements of COPPA, 15 USC 6501 et seq., satisfies that requirement (§ 42-529a(b)(3)(B))
- No dark-pattern consent — The consent mechanism may not be designed to, or manipulated with the effect of, substantially subverting or impairing user autonomy, decision-making or choice (§ 42-529a(c)(1)(A))
- Impact assessment on any profiling — A controller offering an online service, product or feature to known minors that engages in any profiling based on those consumers' personal data must conduct an impact assessment for that service (§ 42-529b(b))
- Six assessment elements — Purpose, intended use cases, deployment context and benefits where the service profiles for legal-effect decisions; heightened-risk analysis for minors and mitigation steps; input categories and outputs; customization data categories; transparency measures, including in-use disclosure that the service is being used for profiling; and post-deployment monitoring and user safeguards, including oversight, use and learning processes (§ 42-529b(b)(1)-(6))
- Review on material change — The controller must review the data protection assessment or impact assessment as necessary to account for any material change to the processing or profiling operations of the service (§ 42-529b(c)(1))
- Three-year retention — Documentation must be maintained for the longer of the three-year period beginning when the processing or profiling operations cease, or as long as the controller offers the service (§ 42-529b(c)(2))
- Reasonable-care presumption — A controller that complied with § 42-529b enjoys a rebuttable presumption of reasonable care under § 42-529a(a) in an Attorney General enforcement action brought under § 42-529e
Profiling Impact Assessment #
This is a second, separate assessment sitting alongside the CTDPA data protection assessment in § 42-522(b) — a controller doing legal-effect profiling now owes both, and the two have different content. The seven elements read as an AI model card written into privacy law: inputs, outputs, customization data, performance metrics, known limitations, transparency measures, and post-deployment monitoring. § 42-522(g)(2) is the date that matters operationally: the impact assessment duty applies only to processing activities created or generated **on or after 2026-08-01** and is expressly not retroactive, one month later than the section's own 2026-07-01 effective date, and a separate clock from the 2023-07-01 line that governs data protection assessments under § 42-522(g)(1).
Requirements
| Requirement | Details |
|---|---|
| Assessment trigger | Each controller that engages in any profiling for the purposes of making a decision that produces any legal or similarly significant effect concerning a consumer must conduct an impact assessment for that profiling (§ 42-522(c)) |
| Purpose and deployment context | A statement disclosing the purpose, intended use cases and deployment context of, and benefits afforded by, the profiling (§ 42-522(c)(1)) |
| Heightened-risk analysis | An analysis of whether the profiling poses any known or reasonably foreseeable heightened risk of harm to a consumer and, if so, the nature of that risk and the steps taken to mitigate it (§ 42-522(c)(2)) |
| Inputs and outputs | A description of the main categories of personal data processed as inputs for the profiling and of the outputs the profiling produces (§ 42-522(c)(3)) |
| Customization data | An overview of the main categories of personal data used to customize the profiling, where the controller used data to customize it (§ 42-522(c)(4)) |
| Performance metrics and limitations | Any metrics used to evaluate the performance and known limitations of the profiling (§ 42-522(c)(5)) |
| Transparency measures | A description of any transparency measures taken concerning the profiling, including measures disclosing to consumers that the controller is engaged in the profiling while it is engaged in it (§ 42-522(c)(6)) |
| Post-deployment monitoring | A description of the post-deployment monitoring and user safeguards, including the oversight, use and learning processes established to address issues arising from the profiling (§ 42-522(c)(7)) |
| Not retroactive | The impact assessment requirement applies only to processing activities created or generated on or after 2026-08-01 (§ 42-522(g)(2)) |
| Batching permitted | A single data protection assessment or impact assessment may address a comparable set of processing operations that include similar activities (§ 42-522(e)) |
| Other-law equivalence | An assessment conducted to comply with another applicable law or regulation satisfies this section if it is reasonably similar in scope and effect (§ 42-522(f)) |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | The act sets no penalty amount. A violation of §§ 42-515 to 42-524 is an unfair trade practice under Conn. Gen. Stat. § 42-110b, enforced **solely** by the Attorney General under § 42-525(a) and (e); § 42-110g, the CUTPA private action, is expressly inapplicable and § 42-525(d) bars any private right of action |
| Cure period | **No longer guaranteed.** The mandatory 60-day cure in § 42-525(b) ran 2023-07-01 to 2024-12-31 and has sunset. Since 2025-01-01, § 42-525(c) makes cure discretionary: the Attorney General may weigh the number of violations, the size and complexity of the controller, the nature and extent of its processing, substantial likelihood of public injury, safety of persons or property, whether the violation was likely human or technical error, and the sensitivity of the data. P.A. 25-113 does not amend § 42-525 |
Sources: Public Act 25-113 (enacted text)
Minors' Profiling Consent and Assessment #
Filed under `risk-assessment` rather than `data-governance` because the ongoing compliance process the section creates is the § 42-529b(b) impact assessment — six enumerated elements, review on any material change to the profiling operations, and documentation kept for the longer of three years after the operations cease or as long as the service is offered. The consent gate in § 42-529a(b)(3)(B) is a condition on a single processing activity rather than a sustained process, and § 42-529a(a) ties the two together by giving a controller that complies with § 42-529b a rebuttable presumption of reasonable care in any Attorney General enforcement action — the assessment is the safe harbor, so it is where the compliance weight sits. Two scope moves are easy to miss. The consent gate was broadened from profiling in furtherance of any **fully** automated decision to **any** automated decision, so a human reviewer in the loop no longer takes a minor's profiling outside it — the same widening the act made to the adult opt-out in § 42-518. And the assessment trigger in § 42-529b(b) is any profiling at all by a service offered to minors, not only legal-effect profiling; only the first of the six elements is qualified by legal or similarly significant effects. Separately, § 42-529d(d)(4) permits processing a minor's personal data for legal-effect profiling solely to detect or correct bias, on five conditions including deletion once the processing is complete, pseudonymization and other industry-standard security measures, strict documented access controls, and no third-party transmission or access — a construction rule creating a safe harbor rather than an obligation, so it is recorded here rather than as its own provision.
Requirements
| Requirement | Details |
|---|---|
| Consent before minors' profiling | No controller offering an online service, product or feature to known minors may process a minor's personal data for profiling in furtherance of any automated decision producing a legal or similarly significant effect concerning the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunity, health care services, or access to essential goods or services, unless reasonably necessary to provide the service, and unless the controller obtains the minor's consent (§ 42-529a(b)(3)(A) and (B)) |
| Parental consent under thirteen | Where the minor is younger than thirteen, the consent of a parent or legal guardian is required; compliance with the verifiable parental consent requirements of COPPA, 15 USC 6501 et seq., satisfies that requirement (§ 42-529a(b)(3)(B)) |
| No dark-pattern consent | The consent mechanism may not be designed to, or manipulated with the effect of, substantially subverting or impairing user autonomy, decision-making or choice (§ 42-529a(c)(1)(A)) |
| Impact assessment on any profiling | A controller offering an online service, product or feature to known minors that engages in any profiling based on those consumers' personal data must conduct an impact assessment for that service (§ 42-529b(b)) |
| Six assessment elements | Purpose, intended use cases, deployment context and benefits where the service profiles for legal-effect decisions; heightened-risk analysis for minors and mitigation steps; input categories and outputs; customization data categories; transparency measures, including in-use disclosure that the service is being used for profiling; and post-deployment monitoring and user safeguards, including oversight, use and learning processes (§ 42-529b(b)(1)-(6)) |
| Review on material change | The controller must review the data protection assessment or impact assessment as necessary to account for any material change to the processing or profiling operations of the service (§ 42-529b(c)(1)) |
| Three-year retention | Documentation must be maintained for the longer of the three-year period beginning when the processing or profiling operations cease, or as long as the controller offers the service (§ 42-529b(c)(2)) |
| Reasonable-care presumption | A controller that complied with § 42-529b enjoys a rebuttable presumption of reasonable care under § 42-529a(a) in an Attorney General enforcement action brought under § 42-529e |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | The act sets no penalty amount. A violation of §§ 42-529 to 42-529d is an unfair trade practice under Conn. Gen. Stat. § 42-110b(a), enforced **solely** by the Attorney General under § 42-529e(a), which also bars any private right of action and any action under § 42-110g |
| Cure period | **A separate regime from the general CTDPA, and it sunset later.** The mandatory notice window in § 42-529e(b) ran 2024-10-01 to 2025-12-31. Its mechanic also differs: the controller had 30 days to notify the Attorney General either that no violation occurred or that it had cured and taken preventive measures, and acceptance removed civil liability. Since 2026-01-01, § 42-529e(c) makes that opportunity discretionary on the same seven factors as § 42-525(c). P.A. 25-113 does not amend § 42-529e |
Sources: Public Act 25-113 (enacted text)