Connecticut Data Privacy Act (CTDPA)
CTDPA: Controller Duties (42-520)

Connecticut Data Privacy Act (CTDPA) CTDPA-42-520-CONSENTREVOKE: Consent and Revocation (No Dark Patterns)

Consent must be a clear affirmative act, freely given, specific, informed and unambiguous (not via dark patterns); controllers must provide a mechanism to revoke consent and cease processing within 15 days of revocation.

Other controls in CTDPA: Controller Duties (42-520)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.