Connecticut Data Broker Law 2026: What CT's New Privacy Rules Mean for Your Data
Published: October 7, 2026 Category: Data Brokers, Privacy, Privacy Laws, Guide Reading time: ~11 minutes Meta description: Connecticut's data broker law took effect October 1, 2026. Here's what Public Act 26-64 requires, who must register by 2027, and how CT residents can use it to delete their data.
The Connecticut data broker law is now in force. As of October 1, 2026, Public Act 26-64 — signed by Governor Ned Lamont on May 27, 2026 — rewrote the rules for companies that buy, package, and sell personal information in the state, and layered a new set of consumer rights on top of them. If you have ever wondered how a marketing list you never signed up for knows your old address, or how a people-search site assembled a profile of you from scattered public records, this law is aimed squarely at that industry.
Connecticut is now the fifth state to require data brokers to register with the government, after Vermont, Texas, Oregon, and California. It is also the first state to copy California's single-request deletion model — the "one form, every broker" idea behind California's Delete Act. That combination makes Connecticut the clearest signal yet that the era of unregulated data brokerage is ending state by state.
This guide explains what Public Act 26-64 actually does, the dates that matter, how Connecticut's law compares to California's, and — most importantly — what you can do right now to get your own data out of the broker economy.
What Is Connecticut's Data Broker Law?
Public Act 26-64, originally Senate Bill 4 — "An Act Concerning Consumer Privacy and Protection" — is a broad consumer-privacy statute, but its most significant new machinery is a data broker regulatory framework. It amends Connecticut's existing Connecticut Data Privacy Act (CTDPA) and adds a dedicated set of rules for the businesses that trade in personal data.
The law's core definition matters, because it decides who is covered:
- A "data broker" is any business, or any portion of a business, that sells or licenses "brokered personal data" to another person. Unlike some earlier laws, the Connecticut definition does not hinge on whether the company has a direct relationship with you.
- "Brokered personal data" includes name, address, date of birth, place of birth, mother's maiden name, unique biometric data, the name or address of a family or household member, Social Security or other government ID numbers, and any other information that, alone or combined, would let a reasonable person identify you with reasonable certainty — if that data is categorized or organized for sale or license to a third party.
In plain terms: if a company's business model involves packaging information about people who are not its customers, and selling or licensing it onward, Connecticut now treats it as a data broker.
> Why this matters: the definition is written around the *product being sold* — organized personal-data sets — rather than around the consumer relationship. That is what lets it reach people-search sites, marketing-data aggregators, and lead-generation operations that never interact with you directly.
Connecticut Data Broker Registration: Who Must Register, and When
The centerpiece of the law is a state registry of data brokers, run by the Connecticut Department of Consumer Protection (DCP).
From January 1, 2027, no data broker may sell or license brokered personal data in Connecticut unless it is actively registered with the DCP. Registration is annual, and the fee is $2,500 per year — the same amount for the initial registration and each renewal. The DCP is required to publish a public web page listing the information each registered broker filed.
Registration is not just a fee. Every applicant must disclose:
- Its name, mailing address, and a monitored email and phone number;
- The address of its primary website;
- A publicly accessible, dark-pattern-free page on that site explaining how consumers can exercise their CTDPA rights;
- Whether it collects minors' personal data, or consumers' precise geolocation or reproductive or sexual health data;
- The measures it takes to avoid selling or licensing data unlawfully; and
- Whether it is regulated under the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, Connecticut insurance law, or HIPAA.
That last point is the escape hatch: entities regulated under FCRA, GLBA, or HIPAA, among other carve-outs, are exempt from the data broker provisions. So are businesses that collect information about people who are already in a contractual, investor, or donor relationship with them.
> Read more: for the full picture of how state privacy rules are converging, see our 2026 data privacy laws guide and the deep dive on California's Delete Act.
Key Dates for Connecticut's Data Broker Law
The law's obligations phase in over several years. Here is the timeline that matters:
| Date | What happens |
|---|---|
| May 27, 2026 | Governor Lamont signs Public Act 26-64. |
| October 1, 2026 | Core provisions take effect: geolocation-sale ban, surveillance-pricing rules, genetic-data rights, and the registry framework. |
| January 1, 2027 | Data brokers must be registered with the CT DCP to sell or license brokered personal data in Connecticut. |
| July 1, 2028 | The DCP must stand up the state's single-request deletion mechanism. |
| October 1, 2028 | Registered brokers must begin checking the deletion mechanism at least once every 45 days and honoring verified deletions. |
| July 1, 2029 | Registered brokers must post an annual transparency statement on their websites (deletion requests received; how many were deleted vs. retained). |
| July 1, 2031 | Independent third-party audits begin, then every three years. |
The Precise Geolocation Ban and Other October 1, 2026 Changes
The data broker registry is only part of what kicked in on October 1, 2026. Connecticut also:
- Bans the sale of precise geolocation data by controllers and third parties — a categorical ban, not an opt-out. This is stricter than California's approach, which relies on consumer opt-outs.
- Narrows the definition of "publicly available information," and expands the right to delete to cover consumer profiles generated from information that was technically public.
- Restricts "surveillance pricing" — setting individualized prices based on personal data — for retail sellers and third-party delivery services. Businesses using a "price setting device" must disclose: "THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA."
- Imposes new obligations on direct-to-consumer genetic testing companies, including express consent before collecting or transferring genetic data, limits on sharing results with employers and insurers, and a consumer property right over biological samples and test results.
- Adds facial-recognition requirements, including clear signage where the technology is in use.
Enforcement is real but structured: the DCP can impose civil penalties of up to $200 per day for each violation of the data broker provisions, after notice and a hearing. There is no private right of action, so consumers cannot sue directly — the state enforces. Surveillance-pricing and genetic-testing violations are handled by the Attorney General as unfair trade practices.
How Connecticut's Data Broker Law Handles Deletion: The 2028 Portal
The single most consequential piece is the accessible deletion mechanism, modeled on California's Delete Request and Opt-out Platform (DROP).
By July 1, 2028, the DCP must build a portal where a consumer can submit one verified deletion request that reaches all registered data brokers — free of charge, and in any language spoken by a consumer whose data a broker holds. Consumers will also be able to exclude specific brokers from a request.
A few design details are worth noting:
- Identity is verified using the consumer's motor vehicle operator's licence number, and the DCP is explicitly barred from storing or retaining it. Verification exists to prevent fraudulent deletion requests, not to build another database.
- Deletion requests are confidential and are not public records under Connecticut's Freedom of Information Act.
- The mechanism itself cannot be used by a broker to access any personal data beyond confirming whether it has been excluded.
- Consumers can update a request at most once every 45 days.
From October 1, 2028, registered brokers must access the mechanism at least once every 45 days, examine each request, and delete the data (and direct their service providers to delete it) for any verified request that does not exclude them. After a broker deletes your data, it must repeat the check every 45 days and cannot maintain, use, or disclose personal data it later acquires about you — closing the loophole where a broker deletes your record, then re-buys it.
Connecticut vs California: How the Two Data Broker Laws Compare
Connecticut borrowed California's architecture but changed several dials. Here is the head-to-head:
| Feature | Connecticut (PA 26-64) | California (Delete Act) |
|---|---|---|
| Definition of "data broker" | Sells or licenses organized "brokered personal data" | Collects and sells data on consumers with no direct relationship |
| Registration deadline | January 1, 2027 | January 31 each year |
| Annual fee | $2,500 | $6,000 |
| Deletion mechanism | Portal by July 1, 2028; brokers act from Oct 1, 2028 | DROP live since January 1, 2026 |
| Check frequency | Every 45 days | Every 45 days |
| Audit cycle | From July 1, 2031, every 3 years | From January 1, 2028, every 3 years |
| Penalty | Up to $200/day per violation | $200/day to register; $200 per deletion request per day |
| Sale of precise geolocation | Categorically banned | Opt-out based |
What Connecticut Residents Can Do Right Now
Connecticut's new rules strengthen your position, but the statewide deletion portal does not open until 2028. Until then, the work still falls to you — or to a service that automates it.
1. Inventory your exposure. Before you can remove data, you need to know where it lives. Start with the big people-search sites — Spokeo, BeenVerified, Radaris and others — and understand what a data broker actually is. 2. Exercise your CTDPA rights directly. Connecticut's amended law gives you the right to access, correct, and delete personal data, and to obtain a list of the specific third parties to which your data was sold. Send written requests to the companies you know hold your information. 3. Use the manual opt-out list. Our 2026 opt-out list walks through the highest-traffic brokers step by step, with the exact forms and links. 4. Expect removal to be recurring, not one-and-done. Brokers re-acquire and re-list data constantly. Any serious strategy assumes a re-check cadence — see how long broker removal actually takes. 5. Automate the repetitive part. Manual opt-outs are free and effective but slow across dozens of sites. CyberForget scans 237+ databases in 60 seconds and runs the opt-outs for you, then re-checks. You can run a free scan here to see what is exposed.
> Bottom line for Connecticut residents: the law expands your rights the moment it took effect, but the automated statewide tool is still two years out. The companies that profit from your data will not wait — so neither should you. Start with a free scan and work the opt-out list while the state builds its portal.
Why This Matters Beyond Connecticut
Connecticut is the fifth state to demand data-broker registration and the first to replicate California's one-request deletion design. That matters because it establishes a template: registration plus a state-run deletion portal plus a recurring 45-day compliance cycle. If the pattern holds, more states will follow, and the operational burden on brokers will compound — different registries, different fees, potentially different matching systems.
For consumers, the direction of travel is clear and favorable: fewer places where your data can be traded in the dark, more ways to force a deletion, and real financial penalties when brokers ignore the rules. For brokers, the cost of doing business without compliance is climbing fast — $200 a day adds up, and a public registry of the industry is not something most firms want their name on.
Frequently Asked Questions
Is Connecticut's data broker law in effect right now? Yes. Public Act 26-64's core provisions took effect October 1, 2026. The registration requirement for data brokers begins January 1, 2027, and the statewide deletion mechanism arrives in 2028.
Do I have a new right to delete my data in Connecticut? Yes. The law expands your deletion rights under the CTDPA, including for profiles built from information that was technically publicly available. Until the state's portal launches in 2028, you exercise those rights by contacting companies directly.
Can I sue a data broker under the new law? No. There is no private right of action. Enforcement runs through the Department of Consumer Protection (data broker provisions) and the Attorney General (surveillance pricing and genetic testing).
How much does it cost a data broker to register? $2,500 per year with the Connecticut Department of Consumer Protection, payable on initial registration and on each annual renewal.
Which companies are exempt? Entities regulated under the FCRA, the Gramm-Leach-Bliley Act, HIPAA, and certain other frameworks, plus businesses dealing only with people who already have a contractual, investor, or donor relationship with them.
Sources
- Connecticut General Assembly — Public Act No. 26-64, Substitute Senate Bill No. 4
- Office of the Connecticut Attorney General — Rights and Requirements Related to New and Updated Privacy Laws
- Hunton Andrews Kurth — Connecticut Privacy Law Updates: Data Broker Rules, Geolocation Sale Ban, Surveillance Pricing
- Davis+Gilbert — Connecticut's Newly Enacted Data Broker Law: How It Stacks Up Against California's Delete Act
- Superset — Connecticut Data Privacy Act: What You Need to Know
- Paul Weiss — California Privacy Protection Agency's First Enforcement Action Against a Data Broker
- California Privacy Protection Agency — Delete Request and Opt-out Platform (DROP)
*This article is for informational purposes and does not constitute legal advice. Connecticut's law and its implementing regulations continue to develop; check the Department of Consumer Protection and the Attorney General's office for the latest guidance.*
🔒 Take Control of Your Data
Ready to remove your personal information from data broker sites? CyberForget automates the entire process. Scan 190+ sites in seconds.
Start Free Scan →