Clym Logo

2026 Connecticut Data Privacy Act (CTDPA) Checklist: 10 Steps for Your Business

Published
AS
AuthorAdam Safar
6 min read

Connecticut CTDPA checklist 10 steps

A 10-step action checklist for CTDPA compliance efforts after PA 25-113: scope, sensitive data, AI disclosure, minors, opt-outs, and DPAs.

Summarize full article with:

Use this checklist to review your business against the Connecticut Data Privacy Act (CTDPA), including the Public Act 25-113 amendments that took effect July 1, 2026. Each step focuses on a specific action you can work through with your team or legal counsel.

For a deeper explanation of what changed and why, read Clym’s Connecticut Data Privacy Act guide first, then come back to this checklist to put those requirements into practice.

Work through the 10 items below in order. Each one explains what to check and what action to take, without repeating the full legal background.

Key takeaways
  • Start with your triggers, not just your consumer count. From July 1, 2026, any sensitive data processing or any data sale puts you in scope, regardless of volume.

  • The consumer threshold dropped to 35,000, and the old revenue-linked path (25,000-plus-50%-revenue) is gone, replaced by the two no-threshold triggers.

  • AI and LLM training disclosure is new and easy to miss if your last privacy notice review predates mid-2025.

  • The minors’ consent age for targeted ads and data sales rose from 16 to under 18.

  • The mandatory cure period ended January 1, 2025. The attorney general may still choose to offer one, but it is no longer guaranteed.

Quick CTDPA applicability check

From July 1, 2026, you’re in scope if you meet any one of these three triggers, with no revenue threshold attached to any of them:

  1. You control or process the personal data of 35,000 or more Connecticut consumers annually, excluding payment-only data

  2. You process any amount of sensitive data from a Connecticut consumer

  3. You sell any amount of personal data from a Connecticut consumer, in any trade or commerce

If you’re unsure whether the CTDPA applies to your business, use Clym Compass to check applicability before continuing with the rest of the checklist.

Step 1: Confirm scope under the 2026 triggers

  • Recalculate your scope using the 35,000-consumer threshold, not the original 100,000 figure

  • Separately confirm whether you process any sensitive data or sell any personal data. Either one puts you in scope with no volume threshold at all

  • Record the date and basis for your determination

  • Confirm whether a sector-level exemption applies: government entities, nonprofits, higher education, or data governed by HIPAA, GLBA, or COPPA

Step 2: Map your data against the expanded sensitive categories

Check your data inventory against the categories below. Several are new under PA 25-113:

  • Neural data (new)

  • Government-issued IDs, including driver’s licenses, Social Security numbers, and passports (new)

  • Financial account login credentials, not just account data generally (new)

  • Gender identity data (new)

  • Consumer health data and disability status

  • Biometric and genetic data

  • Racial or ethnic origin, religious beliefs, sexual orientation, and immigration status

  • Precise geolocation

Step 3: Update your privacy notice

  • Add the categories of personal data you process, the purposes, and any third-party sharing

  • Add a clear explanation of consumer rights

  • Add a disclosure stating whether you use personal data to train AI models or LLMs, including internal tools and third-party AI vendors

  • Display the month and year the notice was last updated, prominently and visibly

A privacy and cookie policy solution can help manage the new AI disclosure and update timestamp alongside your existing notice content.

Step 4: Require opt-in consent for sensitive data

  • Confirm you get explicit opt-in consent before processing any sensitive data category

  • Confirm you never sell sensitive data without a specific, separate consent for that sale

  • Confirm your consent flow doesn’t rely on pre-checked boxes or bundled agreement

Step 5: Update your minors’ consent age to under 18

  • Confirm your opt-in consent process for targeted advertising and data sales now covers anyone under 18, not just under 16

  • Review your age verification flow for any digital property with mixed-age users

  • Confirm your ad and audience-targeting tools respect the updated age cutoff

Clym’s age gating workflows can help apply the correct consent flow based on a visitor’s age.

Step 6: Set up opt-out for sale, targeted advertising, and profiling

  • Build a clear opt-out method for data sales, targeted advertising, and automated-decision profiling

  • Confirm your site detects and honors Global Privacy Control (GPC) and other opt-out signals automatically, required since January 1, 2025

  • Test this on your live site rather than assuming your platform or vendor already handles it

A consent management platform can detect these signals and apply the correct preference automatically.

Step 7: Build a data subject rights process

  • Set up intake, identity verification, and tracking for access, correction, deletion, portability, and opt-out requests

  • Confirm you can respond within 45 days, with a documented process for the one-time 45-day extension

  • Test every consumer rights link and request channel live. A broken opt-out link is independently enforceable

A data subject request workflow helps track intake, deadlines, and documentation without manual spreadsheets.

Step 8: Complete data protection assessments for high-risk processing

  • Complete an assessment before using data for targeted advertising

  • Complete an assessment before selling personal data

  • Complete an assessment before processing sensitive personal data

  • Complete an assessment before profiling with legal or similarly significant effects

  • Store assessments somewhere your team can produce quickly if the attorney general issues a civil investigative demand

Step 9: Review contracts with data processors

  • Confirm each processor contract states clear processing instructions, nature, and purpose

  • Confirm each contract requires appropriate technical and organizational security measures

  • Confirm subprocessors are bound by the same obligations

  • Confirm each contract requires the processor to delete or return data at the end of the engagement

Step 10: Prepare for the current enforcement landscape

  • Confirm your team knows the mandatory 60-day cure period ended January 1, 2025, and isn’t guaranteed anymore

  • Confirm your team understands penalties can reach $5,000 per willful violation

  • Confirm you know there is no private right of action. The Connecticut attorney general is the sole enforcement authority

Common CTDPA checklist mistakes

  • Still screening for the old 100,000-consumer or 25,000-plus-revenue thresholds instead of the new 35,000 figure and the two no-threshold triggers

  • Missing the AI and LLM training disclosure because it wasn’t required when the notice was last reviewed

  • Leaving minors’ consent set to the old under-16 standard instead of under 18

  • Assuming a 60-day cure period is guaranteed before any enforcement action

  • Never testing opt-out and DSR links live, so a broken mechanism goes unnoticed

How to stay on top of CTDPA changes

  • Review your privacy notice and data practices at least once a year and whenever your processing activities change materially

  • Monitor the Connecticut attorney general’s CTDPA page for enforcement reports and guidance

  • Update your data map whenever you add new vendors, AI tools, or data collection methods

  • If you operate across multiple states, Clym’s U.S. state privacy law comparison guide covers thresholds, cure periods, and enforcement side by side

How Clym can support your CTDPA privacy program

  • Apply updated applicability logic automatically through ReadyCompliance® as the 2026 thresholds take effect

  • Update your privacy notice with required AI disclosures and maintain dated policy versions through the Clym Control Center.

  • Recognize and act on GPC and other opt-out signals through Clym’s consent management platform

  • Support the expanded range of consumer rights requests, including corrections, in a structured DSAR workflow

Clym does not guarantee compliance. Your obligations depend on your specific data practices, legal advice, and internal processes. The platform provides tools to support your privacy operations and help you work toward the CTDPA’s requirements.

Conclusion

Work through these 10 steps in order, starting with the new no-threshold triggers. With the cure period no longer guaranteed, treat anything you find as a priority rather than something to revisit later.

For the full explanation behind any of these requirements and how the CTDPA compares to other state privacy laws, go back to Clym’s Connecticut Data Privacy Act guide.

Frequently asked questions

It’s an action checklist for working through Connecticut Data Privacy Act requirements, including the Public Act 25-113 amendments effective July 1, 2026. Each step tells you what to check and do. For background on what changed and why, see Clym’s Connecticut Data Privacy Act guide.

Any business that processes 35,000 or more Connecticut consumers’ data annually, or processes any amount of sensitive data, or sells any amount of personal data. The last two triggers have no volume threshold at all.

Start with Step 1, then go straight to Step 3. Most gaps trace back to missing the two new no-threshold triggers and the AI/LLM disclosure requirement, which didn’t exist under the original law.

Yes. If personal data flows to a third-party AI vendor for training or fine-tuning, that counts. Disclose it in your privacy notice the same way you would disclose an internal AI use case.

45 days, with one additional 45-day extension available when reasonably necessary.

Not automatically guaranteed, but not eliminated either. Since January 1, 2025, the attorney general decides case by case whether to offer a cure period, based on factors like violation count and business size. Don’t assume you’ll get one.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam