Connecticut Data Privacy Act (CTDPA)
The Connecticut Data Privacy Act (CTDPA), effective July 1, 2023, establishes comprehensive consumer privacy rights, including the right to access, delete, correct, and opt out of the sale of personal data and targeted advertising. It applies to controllers conducting business in Connecticut or producing goods/services targeted to Connecticut residents who control or process personal data of 100,000 or more consumers, or of 25,000 or more consumers and derive over 25% of their gross revenue from the sale of personal data.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (18)
Consumer Rights
| Code | Title |
|---|---|
| CPA-CR-1 | Right to Access |
| CPA-CR-2 | Right to Correction |
| CPA-CR-3 | Right to Deletion |
| CPA-CR-4 | Right to Data Portability |
| CPA-CR-5 | Right to Opt Out |
| CT-DP-V2-2 | Right to Confirm and Access |
| CT-DP-V2-3 | Right to Correct |
| CT-DP-V2-4 | Right to Delete |
| CT-DP-V2-5 | Right to Portability |
| CTDPA-3 | Right to Access (Section 4) |
| CTDPA-4 | Right to Correction and Deletion |
| CTDPA-5 | Right to Portability |
| CTDPA-6 | Right to Opt Out |
| FDBR-705 | Consumer Rights (§501.705) |
| FDBR-706 | Controller Response Requirements (§501.706) |
| RIDTPPA-6 | Right to Confirm and Access |
| RIDTPPA-7 | Right to Correct and Delete |
| RIDTPPA-8 | Right to Opt Out |
| TIPA-3 | Right to Access and Confirm |
| TIPA-4 | Right to Delete |
| TIPA-5 | Right to Opt Out |
| WDPA-3 | Right to Access and Confirm |
| WDPA-4 | Right to Portability |
| WDPA-5 | Right to Correction and Deletion |
| WDPA-6 | Right to Opt Out |
| s.6(1) | Right to Deletion |
| s.6(2) | Deletion Request Processing |
| s.6(3) | Right to Withdraw Consent |
| s.7(1) | Data Security Obligations |
Consumer Rights
| Code | Title |
|---|---|
| CPA-CR-1 | Right to Access |
| CPA-CR-2 | Right to Correction |
| CPA-CR-3 | Right to Deletion |
| CPA-CR-4 | Right to Data Portability |
| CPA-CR-5 | Right to Opt Out |
| CT-DP-V2-2 | Right to Confirm and Access |
| CT-DP-V2-3 | Right to Correct |
| CT-DP-V2-4 | Right to Delete |
| CT-DP-V2-5 | Right to Portability |
| CTDPA-3 | Right to Access (Section 4) |
| CTDPA-4 | Right to Correction and Deletion |
| CTDPA-5 | Right to Portability |
| CTDPA-6 | Right to Opt Out |
| FDBR-705 | Consumer Rights (§501.705) |
| FDBR-706 | Controller Response Requirements (§501.706) |
| RIDTPPA-6 | Right to Confirm and Access |
| RIDTPPA-7 | Right to Correct and Delete |
| RIDTPPA-8 | Right to Opt Out |
| TIPA-3 | Right to Access and Confirm |
| TIPA-4 | Right to Delete |
| TIPA-5 | Right to Opt Out |
| WDPA-3 | Right to Access and Confirm |
| WDPA-4 | Right to Portability |
| WDPA-5 | Right to Correction and Deletion |
| WDPA-6 | Right to Opt Out |
| s.6(1) | Right to Deletion |
| s.6(2) | Deletion Request Processing |
| s.6(3) | Right to Withdraw Consent |
| s.7(1) | Data Security Obligations |
Controller Obligations
| Code | Title |
|---|---|
| CPA-CO-1 | Privacy Notice Requirements |
| CPA-CO-2 | Purpose Limitation |
| CPA-CO-3 | Data Minimization |
| CPA-CO-4 | Data Security |
| CTDPA-10 | Privacy Notice |
| CTDPA-7 | Data Minimization |
| CTDPA-8 | Security Practices |
| CTDPA-9 | Consent for Sensitive Data |
| LEB-14 | Registration and Licensing |
| LEB-15 | Penalties and Enforcement |
| TIPA-6 | Purpose Limitation |
| TIPA-7 | Privacy Notice |
| TIPA-8 | Sensitive Data Consent |
| TIPA-9 | Response Timeline |
| WDPA-10 | Non-Discrimination |
| WDPA-7 | Data Minimization |
| WDPA-8 | Security Practices |
| WDPA-9 | Privacy Notice |
DPIA
| Code | Title |
|---|---|
| CT-DP-V2-14 | Data Protection Assessments |
Data Protection Assessments
| Code | Title |
|---|---|
| CPA-DPA-1 | Assessment Requirement |
| CPA-DPA-2 | Targeted Advertising Assessment |
| CPA-DPA-3 | Profiling Risk Assessment |
| CTDPA-11 | DPA Requirements |
| CTDPA-12 | AG Review of DPAs |
Definitions and Scope
Sections 5-10: Key definitions and covered entities
| Code | Title |
|---|---|
| 7012(a) | Definitions |
| 7012(b)(1) | Covered Defence Information Identification |
| 7012(b)(2) | Scope of Protected Systems |
| 7012(b)(3) | COTS Exclusion |
| BIPA-SEC5-1 | Biometric Identifier Definition |
| BIPA-SEC5-2 | Biometric Information Definition |
| BIPA-SEC5-3 | Private Entity Definition |
| CTDPA-1 | Definitions |
| CTDPA-2 | Applicability Thresholds |
| MSA-5 | Definition of Modern Slavery |
| MSA-Commonwealth | Commonwealth Entities |
| MSA-Threshold | Revenue Threshold |
| NAIC-668-1 | Title and Purpose |
| NAIC-668-3 | Definitions |
| NAIC-668-9 | Exemptions |
Enforcement
| Code | Title |
|---|---|
| CT-DP-V2-19 | Enforcement and Cure Period |
| CTDPA-13 | AG Enforcement Authority |
| CTDPA-14 | Cure Period |
| FDBR-720 | Enforcement and Penalties (§501.72) |
| MMCL-Ch13-1 | Penalties |
| MMCL-Ch14-1 | Appeal Procedures |
| PY-11 | Supervisory Authority |
| PY-12 | Penalties |
| TIPA-12 | Profiling with Significant Effects |
| TIPA-13 | Children's and Teen Data Considerations |
Enforcement
| Code | Title |
|---|---|
| CT-DP-V2-19 | Enforcement and Cure Period |
| CTDPA-13 | AG Enforcement Authority |
| CTDPA-14 | Cure Period |
| FDBR-720 | Enforcement and Penalties (§501.72) |
| MMCL-Ch13-1 | Penalties |
| MMCL-Ch14-1 | Appeal Procedures |
| PY-11 | Supervisory Authority |
| PY-12 | Penalties |
| TIPA-12 | Profiling with Significant Effects |
| TIPA-13 | Children's and Teen Data Considerations |
Governance
| Code | Title |
|---|---|
| CT-DP-V2-21 | Privacy Program Documentation |
Minors
| Code | Title |
|---|---|
| CT-DP-V2-17 | Children and Adolescent Protections |
Opt Out
| Code | Title |
|---|---|
| CT-DP-V2-18 | Universal Opt Out Authentication |
| CT-DP-V2-6 | Right to Opt Out |
| CT-DP-V2-7 | Universal Opt-Out Mechanism |
Principles
| Code | Title |
|---|---|
| CT-DP-V2-10 | Purpose Limitation and Minimization |
| CT-DP-V2-11 | Secondary Use Restriction |
Rights
| Code | Title |
|---|---|
| CT-DP-V2-13 | Anti-Discrimination |
| CT-DP-V2-16 | Appeal of Refused Requests |
| CT-DP-V2-20 | Right Exercise without Account Requirement |
Scope
| Code | Title |
|---|---|
| CT-DP-V2-1 | Applicability and Thresholds |
Security
| Code | Title |
|---|---|
| CT-DP-V2-12 | Reasonable Data Security |
Sensitive
| Code | Title |
|---|---|
| CT-DP-V2-8 | Consent for Sensitive Data |
Third Party
| Code | Title |
|---|---|
| CT-DP-V2-15 | Processor Obligations |
Transparency
| Code | Title |
|---|---|
| CT-DP-V2-9 | Privacy Notice Requirements |
Your Compliance Coverage
If you comply with Connecticut Data Privacy Act (CTDPA), you already cover:
FAA Cybersecurity Framework for Aviation
25%
23 controls mapped
Compare →DFARS 252.204-7012 — Safeguarding Covered Defense Information
23%
21 controls mapped
Compare →Florida Digital Bill of Rights (SB 262)
23%
21 controls mapped
Compare →+ 651 more: Chile Personal Data Protection Law (Law No. 21.719) (22%), Azure Security Benchmark (22%)
See all 654 mapped frameworks ↓Maps to 654 other frameworks
Frequently Asked Questions
What is Connecticut Data Privacy Act (CTDPA)?
Connecticut Data Privacy Act (CTDPA) is a compliance framework from United States — Connecticut with 18 domains and 93 controls. The Connecticut Data Privacy Act (CTDPA), effective July 1, 2023, establishes comprehensive consumer privacy rights, including the right to access, delete, correct, and opt out of the sale of personal data and targeted advertising. It applies to controllers conducting business in Connecticut or producing goods/services targeted to Connecticut residents who control or process personal data of 100,000 or more consumers, or of 25,000 or more consumers and derive over 25% of their gross revenue from the sale of personal data. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Connecticut Data Privacy Act (CTDPA) have?
Connecticut Data Privacy Act (CTDPA) has 93 controls organised across 18 domains. The largest domains are Consumer Rights (25 controls), Controller Obligations (18 controls), Definitions and Scope (15 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Connecticut Data Privacy Act (CTDPA) map to?
Connecticut Data Privacy Act (CTDPA) maps to 654 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (25% coverage), DFARS 252.204-7012 — Safeguarding Covered Defense Information (23% coverage), Florida Digital Bill of Rights (SB 262) (23% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Connecticut Data Privacy Act (CTDPA) compliance?
Start your Connecticut Data Privacy Act (CTDPA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Connecticut Data Privacy Act (CTDPA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 93 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required