Law / United States / Connecticut

Connecticut Data Privacy Act (CTDPA), publicly available information exemption

Conn. Gen. Stat. §§ 42-515 to 42-526 (Public Act 22-15, as amended)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 July 2023.

A personal data rule binding private bodies.

As of 29 August 2026.

What it requires

  • Personal data that is lawfully made available through a government record or that a consumer has themselves lawfully made available to the public, including through widely distributed media, falls outside the CTDPA's definition of personal data entirely, so scraping it does not by itself trigger the Act's duties.
  • If you meet the CTDPA's 100,000-consumer or 25,000-consumer-plus-25%-revenue thresholds, personal data you collect that is not publicly available in the Act's own sense still triggers the Act's business obligations, including when it feeds AI training.
  • Do not assume a court will read the reasonable-basis-to-believe standard broadly; no Connecticut case has tested it.

Who checks it

Audit expectation

on_request

Who audits it

Self

Where the report goes

Kept, Produced on request

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 42-515(26) defines personal data to exclude de-identified data or publicly available information outright, and section 42-515(33) defines publicly available information as information that is lawfully made available through federal, state or municipal government records or widely distributed media, and that a controller has a reasonable basis to believe a consumer has lawfully made available to the general public.

Because the exclusion operates on the definition of personal data itself, most scraped public-record or publicly posted personal data falls outside the CTDPA's scope entirely, not merely outside a narrower carve-out from an otherwise-applicable duty.

The Act applies to a business conducting business in Connecticut that, in the preceding calendar year, controlled or processed the personal data of 100,000 or more consumers (excluding payment-transaction data), or 25,000 or more consumers while deriving more than 25% of gross revenue from the sale of personal data.

Separate 2026 amendments (S.B. 1295) added a right to contest automated-decision outcomes and a universal opt-out preference signal requirement, effective July 1, 2026, and a data-protection impact assessment duty for qualifying profiling activities created or generated on or after August 1, 2026; neither amendment changes the publicly-available exemption itself. How a Connecticut court would apply the reasonable-basis-to-believe standard is unlitigated. CTDPA was enacted as Public Act 22-15 and, per its own effective-date history note, took effect July 1, 2023.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics

Read the law

official text, Connecticut General Assembly (cga.ct.gov)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app