惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
博客园 - 司徒正美
小众软件
小众软件
H
Help Net Security
博客园 - 聂微东
宝玉的分享
宝玉的分享
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell
阮一峰的网络日志
阮一峰的网络日志
M
MIT News - Artificial intelligence
博客园 - 【当耐特】
U
Unit 42
大猫的无限游戏
大猫的无限游戏
Apple Machine Learning Research
Apple Machine Learning Research
S
SegmentFault 最新的问题
腾讯CDC
MongoDB | Blog
MongoDB | Blog
云风的 BLOG
云风的 BLOG
J
Java Code Geeks
I
InfoQ
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Martin Fowler
Martin Fowler
博客园 - 三生石上(FineUI控件)
Vercel News
Vercel News

Privacy & Cybersecurity Law Blog

FTC Rescinds 2021 Policy Statement on Health App Data Breaches EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays
Connecticut Privacy Law Updates: Data Broker Rules, Geolo...
2026-06-05 · via Privacy & Cybersecurity Law Blog

Connecticut Privacy Law Updates: Data Broker Rules, Geolocation Sale Ban, Surveillance Pricing Restrictions, and Genetic Data Regulations

On May 27, 2026, Connecticut Governor Ned Lamont signed Senate Bill 4 into law, amending the Connecticut Data Privacy Act (“CTDPA”). Two additional bills making minor adjustments and technical fixes to the CTDPA—HB 5222 and HB 5563—are expected to be signed, and together these changes are referred to herein as the “CTDPA Amendments.”

The CTDPA Amendments create data broker registration and compliance requirements, ban the sale of geolocation data, and set limits on surveillance pricing and the processing of genetic data.

  • Data Brokers
    • Effective Date: January 1, 2027 (registration requirements).
    • Scope: “Data broker” is defined as any business, or portion of a business, that sells or licenses brokered personal data to another person. “Brokered personal data” means personal data that is categorized or organized for sale or license to a third party.
    • Registration: Beginning January 1, 2027, data brokers must annually register with the Connecticut Department of Consumer Protection (“DCP”) and pay an annual fee. The DCP will publish the information included in each data broker’s registration application.
    • Deletion Mechanism: By July 1, 2028, the DCP must create an accessible universal deletion mechanism that allows consumers to submit a single data deletion request to all registered data brokers. By October 2028, data brokers will be required to regularly check the mechanism and process deletion requests, including by flowing such requests downstream to service providers.
    • Audits: Beginning 2031, data brokers will be subject to independent third-party audit requirements every three years.
    • Exemptions: Entities regulated under HIPAA, GLB, FCRA, and DPPA, among other laws, are exempt from the data broker requirements.
    • Enforcement: The DCP may impose civil penalties of up to $200 per day, per consumer, for each violation.
  • Privacy Updates.
    • Effective Date: October 1, 2026.
    • Relevant CTDPA Amendments:
      • ban on the sale of precise geolocation;
      • narrowed definition of “publicly available information”;
      • expansion of deletion right to include certain publicly available data and inferences; and
      • new transparency requirements around the use of facial recognition technology for security or fraud prevention purposes.
    • Surveillance Pricing.
      • Effective Date: October 1, 2026.
      • Price Setting Device Mandatory Disclosure: The CTDPA Amendments require any person doing business in Connecticut using a “price setting device” to provide the following disclosure: “THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA,” unless the price setting device is used solely to offer a discounted price in an online transaction.
        • Price setting device” means any automated or programmed process that uses a consumer’s personal data to establish a price for a consumer good or service to be sold, leased, exchanged, or provided to the consumer.
      • Surveillance Pricing Ban: The CTDPA Amendments ban “surveillance pricing” by “retail sellers” and “third-party delivery services,” subject to certain carve-outs.
        • Surveillance pricing” means establishing a customized price for a consumer for a consumer good or service based on personal data collected through any technology and by the person establishing the customized price, directly or indirectly.
        • The prohibition on surveillance pricing applies to “retailer sellers” (e., an entity or business (including a retail food establishment) that sells, leases, or rents consumer goods or services (including digital goods) directly to end-users) and “third-party delivery service providers” (i.e., an entity—outside of the operation of a retail food establishment’s business—that facilitates delivery or online ordering services to customers of a retail food establishment).
        • Exceptions:
          • The following pricing activities are exempted from the ban on surveillance pricing:
            • Customer retention discounts: Businesses may offer discounted prices to retain existing customers.
            • Price differences for legitimate business reasons: Different prices may be offered based on factors such as delivery costs, consumer choices, delivery timing, or supply-and-demand-driven price fluctuations.
            • Broadly available discount programs: Businesses may offer discounts through publicly disclosed promotions, group-based discounts (e.g., for veterans, students, or seniors), or loyalty and rewards programs, provided the terms are clearly posted and available to all eligible consumers.
          • Exempt entities: Entities subject to Connecticut’s insurance laws, the GLBA, and certain banks or holding companies are exempt from the surveillance pricing provisions.
        • Genetic Testing
          • Effective Date: October 1, 2026.
          • Requirements and Restrictions: The CTDPA Amendments require direct-to-consumer genetic testing companies to:
            • disclose certain information to consumers;
            • obtain express consent prior to collecting, using, or disclosing a consumer’s genetic data, including obtaining separate express consent for the disclosure or transfer of genetic data to any person other than a vendor or service provider;
            • limit the disclosure of genetic testing results to the consumer or a person acting pursuant to a court order, warrant, or subpoena;
            • not disclose a consumer’s genetic data to the consumer’s employer, insurers, or third parties whom the company knows, or reasonably should know, intend to use the data for marketing or targeted advertising purposes;
            • implement reasonable security measures to protect consumers’ biological samples and genetic data; and
            • provide consumers with the ability to exercise their rights to access, delete, destroy, and revoke consent for certain genetic data processing activities.

The CTDPA Amendments also provide consumers with a “property right in, and . . . the right to exercise exclusive control over,” their biological samples used by direct-to-consumer genetic testing companies, as well as results of DNA testing by such companies.