Back to Frameworks

Connecticut CTDPA

United States
18 domains
33 controls

Connecticut Data Privacy Act (Conn. Gen. Stat. § 42-515 et seq., effective 1 Jul 2023) plus PA 23-56 consumer health data amendments.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (18)

AI Governance

1 controls
Controls in the AI Governance domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-AI-PROFILINGProfiling and Automated Decision-Making Governance

Accountability

1 controls
Controls in the Accountability domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-RECORDKEEPINGRecordkeeping and Audit Trail

Children's Data

1 controls
Controls in the Children's Data domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-42-520-CHILDRENChildren's Data: Under 13 and Under 16

Consent

1 controls
Controls in the Consent domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-42-520-CONSENTREVOKEConsent Revocation

Consumer Health Data

2 controls
Controls in the Consumer Health Data domain of Connecticut CTDPA2 controls
CodeTitle
CTDPA-42-525-CHDConsumer Health Data (PA 23-56 Amendment)
CTDPA-42-525-GEOFENCEGeofencing Prohibition Around Healthcare Facilities

Consumer Rights

9 controls
Controls in the Consumer Rights domain of Connecticut CTDPA9 controls
CodeTitle
CTDPA-42-517Consumer Rights Overview
CTDPA-42-518-ACCESSRight to Access and Confirm Processing
CTDPA-42-518-AUTHAGENTAuthorized Agents
CTDPA-42-518-CORRECTRight to Correct
CTDPA-42-518-DELETERight to Delete
CTDPA-42-518-OPTOUTRight to Opt Out of Sale, Targeted Advertising, Profiling
CTDPA-42-518-PORTRight to Data Portability
CTDPA-42-518-RESPONSEResponse Timeline and Appeal Process
CTDPA-42-518-UOOMUniversal Opt-Out Mechanism (UOOM) Requirement

Controller Duties

2 controls
Controls in the Controller Duties domain of Connecticut CTDPA2 controls
CodeTitle
CTDPA-42-520-NONDISCRIMNon-Discrimination
CTDPA-42-520-PURPLIMITPurpose Specification and Data Minimization

Data Treatment

1 controls
Controls in the Data Treatment domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-42-521-DEIDENTDeidentified and Pseudonymous Data

Enforcement

3 controls
Controls in the Enforcement domain of Connecticut CTDPA3 controls
CodeTitle
CTDPA-42-524-AGENFORCEExclusive AG Enforcement
CTDPA-42-524-CURE60-Day Cure Period (Sunset 31 Dec 2024)
CTDPA-AG-REPORT-2024CT AG First Enforcement Report Lessons

Incident Response

1 controls
Controls in the Incident Response domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-BREACH-INTERPLAYInterplay with CT Breach Notification Law

Multistate Compliance

1 controls
Controls in the Multistate Compliance domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-CROSS-CCPAInteroperability with CCPA/VCDPA/CPA

Processor Governance

1 controls
Controls in the Processor Governance domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-42-521-PROCESSORProcessor Obligations and Contracts

Program Governance

1 controls
Controls in the Program Governance domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-TRAININGWorkforce Training and Awareness

Risk Assessment

1 controls
Controls in the Risk Assessment domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-42-520-DPAData Protection Assessments (DPAs)

Scope

3 controls
Controls in the Scope domain of Connecticut CTDPA3 controls
CodeTitle
CTDPA-42-515Definitions and Scope
CTDPA-42-516Applicability Thresholds
CTDPA-42-516-EXEMPTEntity and Data Exemptions

Security

1 controls
Controls in the Security domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-42-520-SECURITYReasonable Security Practices

Sensitive Data

1 controls
Controls in the Sensitive Data domain of Connecticut CTDPA1 controls
CodeTitle
CTDPA-42-520-SENSITIVESensitive Data Opt-In Consent

Transparency

2 controls
Controls in the Transparency domain of Connecticut CTDPA2 controls
CodeTitle
CTDPA-42-520-PRIVNOTICEPrivacy Notice Requirements
CTDPA-42-520-SALEDISCSale and Targeted Ad Disclosure

Frequently Asked Questions

What is Connecticut CTDPA?

Connecticut CTDPA is a compliance framework from United States with 18 domains and 33 controls. Connecticut Data Privacy Act (Conn. Gen. Stat. § 42-515 et seq., effective 1 Jul 2023) plus PA 23-56 consumer health data amendments. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Connecticut CTDPA have?

Connecticut CTDPA has 33 controls organised across 18 domains. The largest domains are Consumer Rights (9 controls), Enforcement (3 controls), Scope (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Connecticut CTDPA map to?

Connecticut CTDPA does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with Connecticut CTDPA compliance?

Start your Connecticut CTDPA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Connecticut CTDPA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required