Connecticut CTDPA
Connecticut Data Privacy Act (Conn. Gen. Stat. § 42-515 et seq., effective 1 Jul 2023) plus PA 23-56 consumer health data amendments.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (18)
AI Governance
| Code | Title |
|---|---|
| CTDPA-AI-PROFILING | Profiling and Automated Decision-Making Governance |
Accountability
| Code | Title |
|---|---|
| CTDPA-RECORDKEEPING | Recordkeeping and Audit Trail |
Children's Data
| Code | Title |
|---|---|
| CTDPA-42-520-CHILDREN | Children's Data: Under 13 and Under 16 |
Consent
| Code | Title |
|---|---|
| CTDPA-42-520-CONSENTREVOKE | Consent Revocation |
Consumer Health Data
| Code | Title |
|---|---|
| CTDPA-42-525-CHD | Consumer Health Data (PA 23-56 Amendment) |
| CTDPA-42-525-GEOFENCE | Geofencing Prohibition Around Healthcare Facilities |
Consumer Rights
| Code | Title |
|---|---|
| CTDPA-42-517 | Consumer Rights Overview |
| CTDPA-42-518-ACCESS | Right to Access and Confirm Processing |
| CTDPA-42-518-AUTHAGENT | Authorized Agents |
| CTDPA-42-518-CORRECT | Right to Correct |
| CTDPA-42-518-DELETE | Right to Delete |
| CTDPA-42-518-OPTOUT | Right to Opt Out of Sale, Targeted Advertising, Profiling |
| CTDPA-42-518-PORT | Right to Data Portability |
| CTDPA-42-518-RESPONSE | Response Timeline and Appeal Process |
| CTDPA-42-518-UOOM | Universal Opt-Out Mechanism (UOOM) Requirement |
Controller Duties
| Code | Title |
|---|---|
| CTDPA-42-520-NONDISCRIM | Non-Discrimination |
| CTDPA-42-520-PURPLIMIT | Purpose Specification and Data Minimization |
Data Treatment
| Code | Title |
|---|---|
| CTDPA-42-521-DEIDENT | Deidentified and Pseudonymous Data |
Enforcement
| Code | Title |
|---|---|
| CTDPA-42-524-AGENFORCE | Exclusive AG Enforcement |
| CTDPA-42-524-CURE | 60-Day Cure Period (Sunset 31 Dec 2024) |
| CTDPA-AG-REPORT-2024 | CT AG First Enforcement Report Lessons |
Incident Response
| Code | Title |
|---|---|
| CTDPA-BREACH-INTERPLAY | Interplay with CT Breach Notification Law |
Multistate Compliance
| Code | Title |
|---|---|
| CTDPA-CROSS-CCPA | Interoperability with CCPA/VCDPA/CPA |
Processor Governance
| Code | Title |
|---|---|
| CTDPA-42-521-PROCESSOR | Processor Obligations and Contracts |
Program Governance
| Code | Title |
|---|---|
| CTDPA-TRAINING | Workforce Training and Awareness |
Risk Assessment
| Code | Title |
|---|---|
| CTDPA-42-520-DPA | Data Protection Assessments (DPAs) |
Scope
| Code | Title |
|---|---|
| CTDPA-42-515 | Definitions and Scope |
| CTDPA-42-516 | Applicability Thresholds |
| CTDPA-42-516-EXEMPT | Entity and Data Exemptions |
Security
| Code | Title |
|---|---|
| CTDPA-42-520-SECURITY | Reasonable Security Practices |
Sensitive Data
| Code | Title |
|---|---|
| CTDPA-42-520-SENSITIVE | Sensitive Data Opt-In Consent |
Transparency
| Code | Title |
|---|---|
| CTDPA-42-520-PRIVNOTICE | Privacy Notice Requirements |
| CTDPA-42-520-SALEDISC | Sale and Targeted Ad Disclosure |
Frequently Asked Questions
What is Connecticut CTDPA?
Connecticut CTDPA is a compliance framework from United States with 18 domains and 33 controls. Connecticut Data Privacy Act (Conn. Gen. Stat. § 42-515 et seq., effective 1 Jul 2023) plus PA 23-56 consumer health data amendments. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Connecticut CTDPA have?
Connecticut CTDPA has 33 controls organised across 18 domains. The largest domains are Consumer Rights (9 controls), Enforcement (3 controls), Scope (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Connecticut CTDPA map to?
Connecticut CTDPA does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with Connecticut CTDPA compliance?
Start your Connecticut CTDPA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Connecticut CTDPA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required