Law / United States / Connecticut

Connecticut

United States law applies in Connecticut Connecticut is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Connecticut, described on this page below, applies here too.

All 21 named instruments researched to a stage, across five of the six areas of law we track: 12 in force and 9 enacted but not yet in force. As of 12 September 2026.

When they take effect20 of 21 carry a date, 1 does not. Earlier is before 2016.
Before 2016: 2 instruments (2 in force) earlier 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 5 instruments (5 in force) 2024: 2 instruments (2 in force) 2025: 1 instrument (1 in force) ’25 2026: 7 instruments (1 in force, 6 enacted but not yet in force) 2027: 1 instrument (1 enacted but not yet in force) 2028: 1 instrument (1 enacted but not yet in force) ’28 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 9
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law 3
  5. Age gating law 2
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law9 instruments, 2 in force, 7 enacted but not yet in force

Research summary (222 words)

Connecticut has no comprehensive AI risk-management statute in force: its flagship proposal, SB 2, died in 2024 and again in 2025 without a House vote. Its place has been taken by a narrower, enacted approach built section by section into a single 2026 omnibus, the Connecticut Artificial Intelligence Responsibility and Transparency Act (2026 Conn. Pub.

Acts 26-15), which layers disclosure and governance duties onto specific activities rather than adopting a Colorado-style conformity regime: AI companion chatbot disclosure and minor-safety rules, an automated employment-decision technology notice regime, a synthetic-content provenance duty for large generative AI providers, frontier-model whistleblower protections, a subscription-AI disclosure duty, and an AI-related mass-layoff disclosure to the Labor Department, all effective October 1, 2026 or January 1, 2027.

Separately, and predating the omnibus, Connecticut's criminal code was amended in 2024 to bring computer-generated child sexual abuse material within its existing CSAM offenses, and in 2025 to create a standalone criminal offense for disseminating a synthetically created intimate image; a 2026 follow-on act adds a private right of action and an Attorney General enforcement and platform-takedown regime for the same conduct.

Connecticut's comprehensive privacy statute, the Connecticut Data Privacy Act, separately gives consumers rights against profiling used for automated decisions; that duty attaches to personal data rather than to an AI system and is catalogued under Connecticut's privacy record, not here.

AI governance

Frontier Developer Catastrophic-Risk Whistleblower Protections

2026 Conn. Pub. Acts 26-15, Sec. 2official session Public Act text, Connecticut General Assembly

In force in 8 days, effective 1 October 2026. Binds private bodies.

What this law does

Takes effect October 1, 2026.

A frontier developer, defined as anyone who trains or intends to train a foundation model using more than ten to the twenty-sixth power of computing operations, may not retaliate against a covered employee for reporting a reasonable belief that the developer's activity poses a specific and substantial danger to public health or safety through a catastrophic risk, defined to include contributing to more than fifty deaths or serious injuries or more than one billion dollars of property damage or loss from a single incident.

A large frontier developer, one with annual gross revenues over five hundred million dollars, must by January 1, 2027 establish an internal process for a covered employee to anonymously report such concerns, share reports with officers and directors at least quarterly, and give employees notice of their rights under the section.

A frontier developer that violates the notice or anti-retaliation provisions is liable to the state for a civil penalty of up to one thousand dollars per violation, recoverable by the Attorney General in Superior Court for the judicial district of Hartford.

What it requires

AI prohibited practices

Civil Action and Platform Takedown Duty for Synthetically Created Intimate Images

2026 Conn. Pub. Acts 26-55 (Sub. H.B. 5312, 2026 Gen. Assemb., Reg. Sess.)official session Public Act text, Connecticut General Assembly

In force in 8 days, effective 1 October 2026. Binds public and private bodies.

What this law does

Signed May 26, 2026 and taking effect October 1, 2026.

An individual harmed by the unlawful dissemination of a synthetically created intimate image, defined the same way as in Conn. Gen. Stat. Sec. 53a-189d, may bring a civil action for an injunction and for economic, emotional-distress, and punitive damages against a person who knowingly disseminated the image intending to cause harm, within two years of discovering the dissemination, with costs and attorneys' fees available to the prevailing party.

Separately, a covered platform under 47 U.S.C. Sec. 223a must set up a notice-and-removal process for a harmed individual or the Attorney General to report such an image, post a clear and conspicuous notice describing that process, and, within forty-eight hours of a valid request, remove the image and make reasonable efforts to remove copies, with good-faith removal shielded from liability.

A platform that violates the removal duty is subject to a civil penalty of up to twenty-five thousand dollars per day, sought by the Attorney General in Superior Court, in addition to the harmed individual's own private right of action.

What it requires

Computer-Generated Child Sexual Abuse Material

Conn. Gen. Stat. Sec. 53a-193(13), as amended by 2024 Conn. Pub. Acts 24-118, Sec. 2official session Public Act text, Connecticut General Assembly

In force since 1 October 2024. Binds public and private bodies.

What this law does

In effect since October 1, 2024. Connecticut's definition of child sexual abuse material, which governs the promoting, importing, and possessing offenses at Conn. Gen. Stat. Secs. 53a-196a to 53a-196f, was amended to cover a computer-generated image or picture, made or produced by electronic, digital, mechanical, or other means, of sexually explicit conduct, where a person under sixteen was used in producing the depiction.

The 2024 amendment also renamed the term from child pornography to child sexual abuse material throughout the definition.

What it requires

Unlawful Dissemination of an Intimate Synthetically Created Image

Conn. Gen. Stat. Sec. 53a-189d, created by 2025 Conn. Pub. Acts 25-168, Sec. 261official session Public Act text, Connecticut General Assembly

In force 12 months, effective 1 October 2025. Binds public and private bodies.

What this law does

In effect since October 1, 2025.

A person commits unlawful dissemination of an intimate synthetically created image by intentionally disseminating, without the depicted person's consent, an image that is not wholly recorded by a camera or is partially or wholly computer-generated, depicts a person's genitals, pubic area, buttocks, breast, or sexual intercourse, and is virtually indistinguishable from what a reasonable person would believe is an actual depiction of an identifiable person, where the depicted person suffers harm from the dissemination.

Dissemination to one person is a class D misdemeanor, or a class A misdemeanor if the person created or acquired the image intending to cause harm; dissemination to more than one person through an interactive computer, information, or telecommunications service is a class C misdemeanor, or a class D felony with that same intent. An interactive computer service, information service, or telecommunications service provider is not liable for content provided by another person.

What it requires

AI sector rules

Automated Employment-Related Decision Technology Act

2026 Conn. Pub. Acts 26-15, Secs. 7 to 13official session Public Act text, Connecticut General Assembly

In force in 8 days, effective 1 October 2026. Binds private bodies.

What this law does

Enacted effective October 1, 2026, binding a deployment of automated employment-related decision technology, technology that processes personal data to produce an output that is a substantial factor in a decision to hire, promote, discipline, discharge, or set the terms of someone's employment, on or after October 1, 2027. A developer must give a deployer the information the deployer needs to meet its own duties.

A deployer must ensure an employee or applicant is told when they are interacting with the technology, unless that would be obvious, and before an employment-related decision is made must give written notice naming the technology, its purpose, the categories and sources of personal data it analyzes, and contact information, subject to a trade-secret withholding notice.

A companion amendment to the state's employment discrimination statute, Conn. Gen. Stat. Sec. 46a-60(b)(1), provides that using such technology is not a defense to a discrimination complaint, though anti-bias testing may be considered as evidence. Violations are enforced solely by the Attorney General as an unfair trade practice, with a sixty-day cure period available for violations occurring on or before December 31, 2027, and create no private right of action.

What it requires

Employer AI-Related Layoff Disclosure to the Labor Department

2026 Conn. Pub. Acts 26-15, Sec. 26official session Public Act text, Connecticut General Assembly

In force in 8 days, effective 1 October 2026. Binds private bodies.

What this law does

Takes effect October 1, 2026. An employer that serves a mass-layoff notice on the Connecticut Labor Department under the federal WARN Act, 29 U.S.C. Sec. 2102(a), must also disclose to the department, in a form the Labor Commissioner prescribes, whether the layoffs relate to the employer's use of artificial intelligence or another technological change.

What it requires

AI transparency

AI Companion Chatbot Disclosure and Minor Safety Duties

2026 Conn. Pub. Acts 26-15, Secs. 4 to 6official session Public Act text, Connecticut General Assembly

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Takes effect January 1, 2027.

An operator of an artificial intelligence companion, an AI system with a natural language interface designed to sustain a relationship across multiple interactions, that would cause a reasonable user to believe they are speaking with a human must give a clear and conspicuous notice that the user is communicating with an artificial intelligence companion, repeated at least hourly for a user under eighteen and at least every three hours for an adult user, and must respond to a direct question about whether it is human by disclosing that it is not.

A violation of the disclosure duty is enforced solely by the Attorney General as an unfair trade practice and creates no private right of action.

Separately, an operator that knows or has reason to believe a user is a minor may not let the companion encourage self-harm, suicide, or violence, offer mental-health services outside narrow exceptions, discourage the user from seeking help from a professional or a trusted adult, engage in romantic or sexually explicit interaction, or use enumerated manipulative engagement techniques, and must give minor users and their parents tools to manage screen time and account settings.

What it requires

Generative AI Content Provenance Duty for Large Providers

2026 Conn. Pub. Acts 26-15, Sec. 15official session Public Act text, Connecticut General Assembly

In force in 8 days, effective 1 October 2026. Binds private bodies.

What this law does

Takes effect October 1, 2026.

A covered provider, defined as anyone who creates a generative artificial intelligence system that has more than one million users a month and is publicly accessible to consumers, must, to the extent commercially and technically reasonable, embed provenance data in audio, image, or video content its system creates or materially alters, letting a consumer assess whether the content came from that system, and must use commercially and technically reasonable methods, including the Coalition for Content Provenance and Authenticity standard, to make that data hard to remove or tamper with.

The duty does not require identifying an individual depicted in the content or disclosing a trade secret.

What it requires

Subscription-Based AI Provider Disclosure Duty

2026 Conn. Pub. Acts 26-15, Sec. 1 (Sub. S.B. 5, 2026 Gen. Assemb., Reg. Sess.)official session Public Act text, Connecticut General Assembly

In force in 8 days, effective 1 October 2026. Binds private bodies.

What this law does

Takes effect October 1, 2026. A subscription-based provider of an artificial intelligence technology may not enter into or renew a consumer subscription, or collect a fee for one, unless the provider first gives the consumer written notice of the key terms and conditions and the consumer accepts them in writing.

The initial-subscription notice must disclose any quantitative or qualitative limitations the provider may impose, including limitations it may impose in response to the consumer's own conduct, and whether the provider has discretion to limit or eliminate the consumer's access to, or reduce the quality of, the technology's functionality. A renewal notice must disclose any such limitation or discretion that is new or has changed since the prior term.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (240 words)

The Connecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. sections 42-515 to 42-529e (Chapter 743jj), is Connecticut's comprehensive consumer-privacy regime, a range that takes in the chapter's later insertions, consumer health data at section 42-526 and social media and minors at section 42-528.

Enacted as Public Act 22-15, effective July 1, 2023, and substantially amended by Public Act 25-113 (S.B. 1295), with amendments effective July 1, 2026 (a profiling impact-assessment duty follows on August 1, 2026), confirmed against the enrolled act's own text rather than the base chapter page, which has not yet folded the Public Act in. Genetic or biometric data collected to identify a person is one of CTDPA's enumerated sensitive-data categories.

Separately, Connecticut's biometric-data definition claws back data generated from a photograph, video, or audio recording the moment that data is generated to identify a specific individual, so a faceprint or voiceprint manufactured from a public recording for identification purposes is covered biometric, and therefore sensitive, data here, unlike Virginia's or Iowa's blanket exclusion.

A separate chapter, Conn. Gen. Stat. section 36a-701b, governs breach notification; that chapter deems a violation an unfair trade practice, which pulls in CUTPA's own private right of action for a person who suffers an ascertainable loss, unlike CTDPA itself, which bars a private right of action. The CTDPA Attorney General has exclusive enforcement authority over the comprehensive act, with a cure period that was mandatory through 2024 and discretionary from 2025 onward.

Breach notification

Breach of security re computerized data containing personal information

Conn. Gen. Stat. § 36a-701bofficial Connecticut statute text, Chapter 669, Connecticut General Statutes

Commencement not set. Binds public and private bodies.

What this law does

A person who owns, licenses, or maintains computerized data including personal information must notify each affected Connecticut resident of a breach without unreasonable delay, and no later than 60 days after discovery unless federal law requires a shorter time. 'Personal information' excludes publicly available information lawfully made available to the general public from government records or widely distributed media.

Unlike CTDPA, which bars a private right of action outright, this breach-notification section deems a violation an unfair trade practice under section 42-110b, and CUTPA's own private-action provision, section 42-110g, lets any person who suffers an ascertainable loss from a practice prohibited by section 42-110b sue for damages, so a breach-notice violation carries indirect private-plaintiff exposure that the comprehensive act does not.

This provision is in force under the current codified text; no dated original commencement is established, so no effective date is recorded here.

What it requires

Comprehensive regime

Connecticut Data Privacy Act (CTDPA), general applicability and controller/processor duties

Conn. Gen. Stat. §§ 42-515, 42-524official Connecticut statute text, Chapter 743jj, Connecticut General Statutes

In force since 1 July 2023. Binds private bodies.

What this law does

CTDPA governs private-sector processing of Connecticut residents' personal data. Enacted as Public Act 22-15 (S.B. 6, 2022), effective July 1, 2023. Controller and processor duties are allocated at sections 42-515 to 42-524. S.B. 1295, enacted as Public Act 25-113 (signed June 25, 2025), substantially amended the Act, with amendments effective July 1, 2026, including a lower applicability threshold and an expanded profiling opt-out.

The base chapter as published at cga.ct.gov's 'current' text has not yet folded this Public Act in, directing readers to a separate 2026 Supplement instead; the July 1, 2026 effective date and the amendment's substance are confirmed against the enrolled Public Act 25-113 text itself.

What it requires

Data subject rights

Connecticut Data Privacy Act, consumer rights

Conn. Gen. Stat. § 42-518official Connecticut statute text, Chapter 743jj, Connecticut General Statutes

In force since 1 July 2023. Binds private bodies.

What this law does

CTDPA gives a Connecticut consumer the right to confirm processing, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and qualifying profiling. A controller must respond without undue delay and no later than 45 days after receipt, with one 45-day extension available.

Public Act 25-113 (S.B. 1295, 2025 session, effective July 1, 2026) removed the 'solely automated' qualifier so the profiling opt-out and a new right to contest automated-decision outcomes reach decisions with human involvement, and its Sec. 11 (amending section 42-522) adds a new impact-assessment requirement for such profiling applying to processing activities created or generated on or after August 1, 2026, confirmed against the enrolled act's own text.

What it requires

Enforcement supervision

Connecticut Data Privacy Act, Attorney General enforcement

Conn. Gen. Stat. § 42-525official Connecticut statute text, Chapter 743jj, Connecticut General Statutes

In force since 1 July 2023. Binds private bodies.

What this law does

The Connecticut Attorney General has exclusive authority to enforce CTDPA as an unfair trade practice under section 42-110b. A cure period was mandatory (60 days) from July 1, 2023 through December 31, 2024; from January 1, 2025 it became discretionary, weighed against factors including violation count, controller size, likelihood of public injury, and data sensitivity. The chapter creates no private right of action.

What it requires

Sensitive categories

Connecticut Data Privacy Act, sensitive data and biometric data definitions

Conn. Gen. Stat. § 42-515(4), (38)official Connecticut statute text, Chapter 743jj, Connecticut General Statutes

In force since 1 July 2023. Binds private bodies.

What this law does

CTDPA classifies data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, consumer health data, the processing of genetic or biometric data to uniquely identify an individual, a known child's data, victim-of-crime status, and precise geolocation data as sensitive data.

'Biometric data' means data from automatic measurement of biological characteristics used to identify a person, such as a fingerprint or voiceprint, and the raw photograph or recording is excluded, but data generated from it (a faceprint, a voiceprint) is brought back inside 'biometric data' the moment it is generated to identify a specific individual.

This clawback is the material finding for Connecticut: a voiceprint or faceprint manufactured from a public-facing recording for identification purposes is covered biometric and sensitive data here.

What it requires

Scraping law2 instruments, 2 in force

Research summary (171 words)

Connecticut diverges from federal scraping law in the computer_misuse and personal_data families. Its computer crime statute carries the same undefined without authorization language the federal Computer Fraud and Abuse Act (CFAA) has always carried, so it resolves no more of the public-page question than federal law already does; no Connecticut appellate decision construes it against a scraper.

The Connecticut Data Privacy Act (CTDPA) genuinely diverges: it excludes publicly available information from the definition of personal data itself, rather than carving out an exemption from an otherwise-applicable duty, so most scraped public-record or publicly posted personal data falls outside its scope entirely.

Copyright, text-and-data-mining, and database rights add nothing beyond the federal position; Connecticut has no state text and data mining (TDM) exception and no sui generis database right, and compilations receive only Feist's thin copyright protection.

ToS enforceability and unfair competition (the Connecticut Unfair Trade Practices Act) rest on general contract and consumer-protection law with no Connecticut case applying either to a scraping fact pattern, so neither earns its own instrument here. robots.txt carries no independent legal weight in Connecticut.

Computer misuse

Connecticut Computer Crime (unauthorized access, undefined authorization test)

Conn. Gen. Stat. § 53a-251official text, Connecticut General Assembly (cga.ct.gov)

In force since 1 October 1984. Binds public and private bodies.

What this law does

Section 53a-251(b)(1) criminalizes unauthorized access to a computer system when a person, knowing that he is not authorized to do so, accesses or causes to be accessed any computer system without authorization. The statute does not itself define without authorization for a system open to the public, so it carries the same textual gap the federal Computer Fraud and Abuse Act (CFAA) has always carried, and no Connecticut appellate decision construes it against a scraper of public pages.

Grading turns on the dollar value of damage or of computer services, and the statute fixes the value of private personal data at $1,500 for grading purposes (section 53a-259(c)), which matters specifically for personal-data scraping.

The Second Circuit's narrow construction of exceeds authorized access in United States v. Valle (807 F.3d 508, 2d Cir. 2015), consistent with the national reading Van Buren v. United States (593 U.S. 374, 2021) later adopted, is the closest regional authority, though it is federal rather than Connecticut law. Section 53a-251 was added by Public Act 84-206 and carries no History note in the official statute text, meaning it has never been amended since.

That Act's own conversion table shows no override of the general default rule for the effective date of a Connecticut public act (Conn. Gen. Stat. § 2-32: the first day of October following the session at which it was passed), so the section commenced October 1, 1984.

What it requires

Personal data

Connecticut Data Privacy Act (CTDPA), publicly available information exemption

Conn. Gen. Stat. §§ 42-515 to 42-526 (Public Act 22-15, as amended)official text, Connecticut General Assembly (cga.ct.gov)

In force since 1 July 2023. Binds private bodies.

What this law does

Section 42-515(26) defines personal data to exclude de-identified data or publicly available information outright, and section 42-515(33) defines publicly available information as information that is lawfully made available through federal, state or municipal government records or widely distributed media, and that a controller has a reasonable basis to believe a consumer has lawfully made available to the general public.

Because the exclusion operates on the definition of personal data itself, most scraped public-record or publicly posted personal data falls outside the CTDPA's scope entirely, not merely outside a narrower carve-out from an otherwise-applicable duty.

The Act applies to a business conducting business in Connecticut that, in the preceding calendar year, controlled or processed the personal data of 100,000 or more consumers (excluding payment-transaction data), or 25,000 or more consumers while deriving more than 25% of gross revenue from the sale of personal data.

Separate 2026 amendments (S.B. 1295) added a right to contest automated-decision outcomes and a universal opt-out preference signal requirement, effective July 1, 2026, and a data-protection impact assessment duty for qualifying profiling activities created or generated on or after August 1, 2026; neither amendment changes the publicly-available exemption itself. How a Connecticut court would apply the reasonable-basis-to-believe standard is unlitigated. CTDPA was enacted as Public Act 22-15 and, per its own effective-date history note, took effect July 1, 2023.

What it requires

Cybersecurity law3 instruments, 3 in force

Research summary (870 words)

Connecticut's private-sector security law is a two-part reasonable-security regime, a safeguards-and-destruction duty layered with a cybersecurity-program safe harbor, plus a newly effective connected-device security duty; it has no general private-sector vulnerability or incident-reporting statute and no sector cyber-resilience regime the LexLint activity vocabulary can express.

Conn. Gen. Stat. Sec. 42-471, added by Public Act 08-167 and effective October 1, 2008, requires any person in possession of another person's personal information (a Social Security number, driver's license or state identification card number, account number, credit or debit card number, passport number, alien registration number, health insurance identification number, or military identification information, combined with an identifier) to safeguard the data, computer files and documents containing it from misuse by third parties and to destroy, erase or make them unreadable before disposal, and requires any person who collects Social Security numbers in the course of business to create and publish a privacy protection policy; a financial institution whose safeguards comply with the Gramm-Leach-Bliley Act's Section 501(b) standards is deemed compliant, and the section does not reach a state agency or political subdivision.

Public Act 21-119 (2021), codified at Conn. Gen. Stat. Sec. 42-901 and effective October 1, 2021, layers an incentive rather than a mandate on top of that duty: a covered entity, any business that accesses, maintains, communicates or processes personal or restricted information, is shielded from punitive damages in a tort action alleging that a failure to implement reasonable cybersecurity controls caused a data breach, where it created, maintained and complied with a written cybersecurity program conforming to a named framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, the ISO/IEC 27000-series, or, for an entity already regulated under Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Title V, FISMA or HITECH, that regime, or the PCI Data Security Standard paired with another listed framework); the shield does not apply where the failure was gross negligence or wilful or wanton conduct, and the statute creates no duty to adopt a program of its own; it leaves undisturbed the class-action certification process, the Attorney General's and Commissioner's other enforcement authority, and the state's breach-notification statute.

Public Act 25-44 (2025), Section 2, effective July 1, 2026, is Connecticut's first connected-device statute: it defines a connected device as an Internet-connected home appliance, television or toy with a camera or microphone, and its subsection (c) requires a 'provider' (the device's manufacturer, and any person under contract who gets access to the camera or microphone data) to implement and maintain reasonable security measures to protect personally identifying information collected through the device's camera or microphone from unauthorized access, acquisition, destruction, disclosure, modification or use.

The same section's other subsections, mandatory pre-activation disclosure of recording capability, a right to decline activation, and a bar on selling or using a recording for targeted advertising without opt-in consent, are disclosure and consent duties that attach to the data rather than to the device's security posture and belong to the privacy topic; they are not yet researched under either topic as of this visit, so this row is scoped to subsection (c) alone rather than restating a claim nobody has filed.

No enacted Connecticut statute is confirmed in the primary text consulted here to set market-entry security requirements (an authentication-credential mandate, an update or support-period duty) a connected device or software product must meet, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act; that reading rests on the CGA's current codification and the sources read for this visit, not on a further dedicated search of the point.

Connecticut's Insurance Data Security Law, Conn. Gen. Stat. Sec. 38a-38 (Public Act 19-117, delayed to an October 1, 2020 effective date and since amended by Public Act 21-157), requires a person licensed, authorized or required to be licensed under the state's insurance laws to develop, implement and maintain a written information security program and to investigate and report a cybersecurity event to the Insurance Commissioner and affected consumers; because it binds only insurance licensees, a bound-party class no activity in the LexLint vocabulary expresses, it is recorded here rather than flagged on a guess or filed as an instrument.

Section 42-471 is enforced administratively by the Department of Consumer Protection, with a civil penalty of up to $5,000 per violation, or by another state agency where the person is licensed by it, with Attorney General injunctive authority under Section 42-472; it creates no private right of action, and no published enforcement record for it is confirmed in the primary text consulted here.

Public Act 25-44's connected-device security duty, by contrast, is enforced as an unfair or deceptive trade practice under Chapter 735a, and unlike Section 42-471 and several of Public Act 25-44's own other sections, its subsection (g) does not exclude Section 42-110g, so a person who suffers an ascertainable loss appears to retain Connecticut's ordinary private right of action for it.

Connecticut's breach-notification duty, Conn. Gen. Stat. Sec. 36a-701b, and the Connecticut Data Privacy Act's own security-practices clause, Conn. Gen. Stat. Sec. 42-520(a)(3) (one subsection of the comprehensive CTDPA, the same shape as the Texas Data Privacy and Security Act's Section 541.101(a)(2)), are already this jurisdiction's privacy-topic rows rather than repeated here.

Security baseline statutes

Adoption of cybersecurity controls by businesses, exemption from punitive damages

Conn. Gen. Stat. sec. 42-901Official statute text, Connecticut General Statutes, Adoption of Cybersecurity Controls by Businesses (Public Act 21-119)

In force since 1 October 2021. Binds private bodies.

What this law does

Public Act 21-119 (2021) shields a 'covered entity', any business that accesses, maintains, communicates or processes personal or restricted information through a system, network or service located in or outside Connecticut, from punitive damages in a tort action alleging that a failure to implement reasonable cybersecurity controls caused a data breach, where the entity created, maintained and complied with a written cybersecurity program with administrative, technical and physical safeguards that conforms to a named industry framework.

The shield does not apply where the failure was the result of gross negligence or wilful or wanton conduct. The section creates no duty to adopt a program of its own and does not limit the Attorney General's or the Commissioner of Consumer Protection's authority to seek other relief. It leaves undisturbed the process for certifying a class action founded in tort. It also leaves undisturbed the requirements of the state's breach-notification statute at Section 36a-701b.

What it requires

Connected device provider's duty to protect recorded personal information with reasonable security measures

Public Act No. 25-44, Sec. 2(c) (2025)Official session law text, Public Act No. 25-44 (Substitute Senate Bill No. 3), Connecticut General Assembly

In force 84 days, effective 1 July 2026. Binds private bodies.

What this law does

Public Act 25-44 defines a connected device as an Internet-connected home appliance, television or toy that includes a camera or microphone. It defines a 'provider' as the device's manufacturer or any person under contract with the manufacturer who gets access to the camera, microphone, or the images, video or sound they collect.

Each provider must implement and maintain reasonable security measures to protect any personally identifying information collected through a connected device's camera or microphone from unauthorized access, acquisition, destruction, disclosure, modification or use.

A violation of this subsection is an unfair or deceptive trade practice under the Connecticut Unfair Trade Practices Act, and unlike several of this same Public Act's other sections, the enforcement clause covering it does not exclude Section 42-110g, so it appears to carry that chapter's ordinary private right of action for a person who suffers an ascertainable loss.

What it requires

Protection of Social Security Numbers and Personal Information Act, safeguarding and destruction duty

Conn. Gen. Stat. sec. 42-471Official statute text, Connecticut General Statutes, Protection of Social Security Numbers and Personal Information

In force since 1 October 2008. Binds private bodies.

What this law does

Any person in possession of another person's personal information must safeguard the data, computer files and documents containing it from misuse by third parties, and destroy, erase or make it unreadable before disposal. Any person who collects Social Security numbers in the course of business must create and publish a privacy protection policy that protects their confidentiality, prohibits unlawful disclosure and limits access.

The section does not apply to a state agency or political subdivision of the state. A financial institution that has adopted safeguards complying with the Gramm-Leach-Bliley Act's Section 501(b) standards is deemed compliant with this section.

What it requires

Age gating law2 instruments, 1 in force, 1 enacted but not yet in force

Research summary (130 words)

Connecticut has no adult content age verification, app store, or design code law. Its 2023 privacy law amendments (SB 3, Public Act 23-56) give minors under 18 the right to have social media accounts unpublished or deleted and require reasonable care and data protection assessments for services offered to known minors, in effect since 2024.

In 2026 the state enacted SB 5 (Public Act 26-15), an omnibus online safety and artificial intelligence act whose social media provisions, effective January 1, 2028, require age determination and parental consent before minors may use personalized algorithmic feeds, restrict notification hours, and set protective defaults including a one hour per day feed limit. A narrower 2025 bill with similar provisions (HB 6857) passed the House 121 to 26 but died without a Senate vote.

Social media and minors

SB 3 (2023), online privacy, data and safety protections for minors

Conn. Gen. Stat. ch. 743jj (Public Act 23-56)official session public act text

In force since 1 July 2024. Binds private bodies.

What this law does

Amends the Connecticut Data Privacy Act so social media platforms must honor a minor's request to unpublish or delete their account (effective July 1, 2024), and requires controllers offering services to known minors under 18 to use reasonable care against heightened risk of harm, including limits on targeted advertising, certain profiling, and precise geolocation collection (effective October 1, 2024).

Note and primary source

SB 5 (2026), An Act Concerning Online Safety, social media protections for minors

Public Act No. 26-15, Sec. 39 (2026)official session public act text, Connecticut General Assembly

In force in 465 days, effective 1 January 2028. Binds private bodies.

What this law does

Part of a 39 section omnibus online safety and artificial intelligence act signed June 2, 2026.

Section 39 bars covered platforms from showing a user personalized algorithmic recommendations unless the operator uses commercially reasonable and technically feasible methods to determine the user is not a minor under 18, or obtains verifiable parental consent for a minor; bars notifications to minors between 9:00 p.m. and 8:00 a.m. absent parental consent; requires protective defaults for minor accounts including a one hour per day limit on algorithmic feeds; requires deletion of age determination data; and requires annual public disclosures.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.