
You have a contact form, an email list, Google Analytics and maybe an ad pixel, and someone told you Connecticut has its own privacy law. Now you want to know whether any of that puts your business under it, what you would have to add, and what happens if you do nothing. For a Connecticut data privacy act small business question, the short answer is that the law reaches a business only when it meets one of three triggers, and having a website is not one of them. Since the July 1, 2026 amendments, the triggers are 35,000 consumers, any sensitive data, or offering personal data for sale. A plain small-business site that meets none of them is not covered by having a form, a newsletter and basic analytics. Two of the three triggers apply at any size, so they are worth a look before you relax. What follows covers who is covered, who is not, what a covered site must add, and what every Connecticut business should do anyway. It is general information, not legal advice.
Key Takeaways
The law applies to a business that conducts business in Connecticut or targets Connecticut residents and, in the preceding calendar year, handled data of at least 35,000 consumers, handled any sensitive data, or offered personal data for sale.
A contact form, an ordinary email list or basic analytics does not create coverage by itself, but sensitive data and data sales apply at any size.
A privacy notice linked from the home page, a way to make requests, opt-outs, and honoring the Global Privacy Control signal.
An accurate privacy policy, secure forms and a tag review protect you whether or not the Connecticut law applies, and the FTC Act and CAN-SPAM apply at any size.
Are you covered? Check three triggers before you spend anything
Connecticut's privacy law applies to a person that conducts business in Connecticut or targets Connecticut residents and meets one of three tests. The 2026 supplement to the Connecticut General Statutes and the Connecticut Attorney General's CTDPA page set them out. The tests look at the preceding calendar year, and a business needs to meet only one. Amendments in Public Act 25-113, effective July 1, 2026, lowered the general threshold and made sensitive data and data sales triggers of their own. Before that date, the general threshold was 100,000 consumers, or 25,000 consumers plus more than 25% of gross revenue from selling personal data. The revenue test no longer exists.
| Trigger | What it means | Size matters? |
|---|---|---|
| 35,000 consumers | Controlled or processed personal data of at least 35,000 consumers, not counting data processed only to complete a payment | Yes |
| Sensitive data | Controlled or processed any consumer sensitive data, not counting payment-only processing | No |
| Sale of personal data | Offered consumers' personal data for sale in trade or commerce | No |
Businesses that handle consumer health data are covered without any size threshold. Sensitive data includes health information, racial or ethnic origin, religious beliefs, disability or treatment, sexual activity or orientation, citizenship or immigration status, certain financial credentials, government identification numbers, and neural, genetic, biometric, child and precise-geolocation data. Processing sensitive data requires consent.
"Sale" is not limited to handing over data for cash, so a tag that passes visitor data to an ad platform deserves a close look before you decide you have no exposure. Coverage also depends on the exemptions in the statute, which is a good reason to bring a lawyer into any close call.

Know when your small site is outside the law
Plenty of Connecticut businesses will land here, and the plain answer is that a normal small business is not automatically covered because it has a contact form, an email list, Google Analytics or an advertising pixel. The law does not register every website. It covers businesses that meet a trigger, and the triggers describe what a business does with data, not whether it has a site.
If your list holds a few thousand contacts, you handle no sensitive data, and you do not sell or license personal data to anyone, none of the three tests fits. You may still have work to do, which the later sections cover, but you are not in the position of a business that must publish rights-request tools and opt-outs. A privacy policy alone also does not make a covered business compliant, so the question to answer first is which side of the line you are on.
Keep Connecticut's law separate from California's and Europe's. Owners often search for "Connecticut GDPR" or a "Do Not Sell button" and import requirements that do not automatically apply here. Connecticut wrote its own thresholds, notice rules and enforcement, and those are the ones that matter for a business serving Connecticut residents, whether you run a shop in Hartford or a service company anywhere else in the state. Business owners across Connecticut face the same three tests.
Build what a covered site must show
If you meet a trigger, the website is where most of the visible duties live. The statute asks for a "reasonably accessible, clear and meaningful" privacy notice, and from July 1, 2026 the notice must cover more ground than it used to. It should say:
- The categories of personal data processed and why.
- How a consumer exercises rights and appeals a decision.
- The categories of data sold and the third parties that receive it.
- Whether the business uses data for targeted advertising or sells it.
- An active email address or online contact mechanism.
- Whether personal data is collected, used or sold to train large language models.
- The month and year of the notice's latest update.
The notice must be linked conspicuously from the home page using the word "privacy." A covered business also needs a secure way for people to make requests, and it generally answers within 45 days. Consumers can ask for access, correction, deletion and portability, and can opt out of sale, targeted advertising and qualifying profiling.
Universal opt-out signals are the piece that most often touches a site's code. Covered businesses have had to honor qualifying signals, including Global Privacy Control, since January 1, 2025. Google's AdSense guidance dated June 30, 2025 says Connecticut's rules require those signals to opt users out of ad targeting, sale or sharing, and that Google triggers restricted-data processing for affected ad requests. In practice, a browser sends the signal, and your tags have to respect it before they fire. An "accept all" banner that ignores the signal is not enough.

Understand how the Attorney General enforces the law
The Connecticut Attorney General has exclusive enforcement authority. The law creates no private right of action, so a customer cannot sue under it. Violations can bring civil penalties of up to $5,000 per violation under the Connecticut Unfair Trade Practices Act, along with injunctive relief, restitution or disgorgement, as Conn. Gen. Stat. § 42-525 provides.
The cure period has changed. From July 1, 2023 through December 31, 2024, the Attorney General had to offer a 60-day chance to fix a problem. Beginning January 1, 2025, the office may decide whether to offer that chance, considering the number of violations, the size and complexity of the business, its processing activities, the likelihood of public injury, safety risks, human or technical error, and how sensitive the data is.
The first public action shows what gets attention. On July 8, 2025, the Attorney General announced a settlement with TicketNetwork. The company paid $85,000 after failing to correct an unreadable privacy notice and inoperable rights mechanisms. The office's 2025 enforcement report records dozens of notices and five privacy-notice sweeps. The lesson for a covered site is practical: a notice a person can read and a rights process that works are the first things to get right.
Do these basics even when the law does not apply to you
Being below every threshold does not mean privacy is someone else's problem. It means the safest, cheapest work is the same for everyone. Start with an accurate privacy notice that matches your actual forms, email marketing, analytics, ad pixels, payment tools, booking systems and vendors. Say what you collect, why, who receives it and how a person can reach you. Our post on whether your website needs a privacy policy covers what to put in it.
Then secure what you collect. Use HTTPS, limit administrator access, remove form fields you do not need, keep software updated and confirm where submissions are stored. The FTC's small-business cybersecurity guidance recommends TLS, access controls, software updates, backups, employee training, and SPF, DKIM and DMARC for business email. If your site has several plugins or forms, our website security audit looks at exactly this, and regular website maintenance keeps it from drifting.
Review your tags before assuming they are harmless. Meta, Google, TikTok, LinkedIn, remarketing, call-tracking and analytics tools each send data somewhere. Do not collect sensitive information through an ordinary contact form unless you have a clear business reason and real protection. A cookie banner is not always required, and it cannot fix an inaccurate notice, over-collection or insecure storage; our post on whether US small businesses need a cookie banner explains when one helps.

Two federal rules apply regardless of size. The FTC Act prohibits unfair or deceptive privacy and security practices, including breaking a promise you made in your own privacy policy. The FTC's consumer privacy guidance explains the approach. CAN-SPAM covers commercial email and requires truthful headers, non-deceptive subject lines, a valid postal address and a working opt-out, as the FTC's CAN-SPAM guide details.
Run a ten-minute check to see where you stand
You can get a useful first estimate without hiring anyone. It is a screening exercise, not a legal determination, and it takes about ten minutes.
- Count your contacts: Add up Connecticut contacts across your newsletter platform, CRM, booking system, customer database, form records and account system. Leave out data collected only to process payments.
- Look for sensitive data: Note whether you handle health information, precise location, biometric or genetic data, government identifiers, financial credentials or children's data.
- List your tags: Open your site and note every tool running on it, such as Google Analytics, Google Ads, a Meta Pixel, a TikTok Pixel, a LinkedIn tag, chat, heatmaps, session recording, call tracking and embedded forms.
- Read your policy against the site: Check whether it describes what you actually collect, why, who receives it, how to reach you and when it was last updated, and whether a "privacy" link sits on the home page.
- Test one form: Confirm it loads over HTTPS and that a test submission lands where you expect.
If the count is far below 35,000, you handle no sensitive data and you sell nothing, you are likely on the not-covered side and your work is the basics above. If any answer is yes or unclear, you have a reason to look closer. A lawyer can settle the legal question, and a web and security specialist can map your tags, secure your forms and test opt-out behavior.

Does the Connecticut privacy law reach your site?
Pick an answer to begin.
1. Which of these alone makes a business subject to the Connecticut Data Privacy Act?
2. Who enforces the law?
3. What must a covered business's home page include?
Frequently Asked Questions About connecticut data privacy act small business
Does every Connecticut business website fall under the law?
No. Coverage depends on the threshold of 35,000 consumers, sensitive-data processing, personal-data sales, consumer health data and the statute's exemptions.
What changed on July 1, 2026?
The general threshold dropped from 100,000 consumers to 35,000, and processing sensitive data or offering personal data for sale became triggers on their own. The old revenue test was removed.
Does a contact form automatically trigger the law?
No. A form may collect personal data, but the form alone does not create coverage.
Must a covered business honor Global Privacy Control?
Yes. Covered businesses have had to honor qualifying universal opt-out signals, including Global Privacy Control, since January 1, 2025.
Can a customer sue under the law?
No. The Connecticut Attorney General has exclusive enforcement authority and the law provides no private right of action.
What is the penalty?
Civil penalties can reach $5,000 per violation, with possible injunctive relief, restitution or disgorgement.
The Bottom Line
Connecticut's privacy law covers a business that conducts business in the state or targets its residents and meets one of three triggers: 35,000 consumers, any sensitive data, or offering personal data for sale. A contact form, an ordinary email list or basic analytics does not create coverage on its own, though sensitive data and data sales count at any size. If you are covered, the site needs a readable notice linked from the home page, a working request process, opt-outs and Global Privacy Control handling.
Whichever side of the line you are on, an accurate privacy policy, secure forms and a tag review pay off. The Attorney General's first public action targeted an unreadable notice and rights tools that did not work, so clean basics are also your best protection.
If you want help mapping the tags and forms on your site, Web Leveling can do the inventory with you, and our web design work builds sites with the notice, forms and tracking set up correctly. If your site is small and plain, we will tell you the free check above is enough. We work with small and medium businesses across the country and overseas. Tell us what your site collects, and we will help you sort it out.
Terms
Connecticut privacy law words in this post
Tap a term to see what it means.
CTDPA. The Connecticut Data Privacy Act, the state's consumer privacy law, found in Conn. Gen. Stat. § 42-515 and following.
Controller. A business that decides why and how personal data is processed.
Consumer. The individual whose personal data a business handles.
Sensitive data. A protected category such as health, biometric, genetic, children's or precise-location data, which requires consent to process.
Sale of personal data. Offering personal data in trade or commerce, which is not limited to exchanges for cash.
Global Privacy Control. A browser signal that tells a site the visitor opts out of sale and targeted advertising.
Privacy notice. The public statement of what data a business collects, why, who receives it and how people can exercise their rights.




