Connecticut Data Privacy Act (CTDPA)
CTDPA: Controller Duties (42-520)

Connecticut Data Privacy Act (CTDPA) CTDPA-42-520-SECONDARY: No Secondary Use Without Consent

Controllers may not process personal data for purposes not reasonably necessary to or compatible with the disclosed purposes without the consumer's consent.

Other controls in CTDPA: Controller Duties (42-520)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.