Skip to content

Evidence request lists

Connecticut Data Privacy Act (CTDPA)

Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CTDPA: Consumer Rights (42-518)

CTDPA-42-518-ACCESS
Right to Confirm and Access

Consumers may confirm whether a controller is processing their personal data and access that data.

Artefacts an auditor will ask for
  • Authenticated access-request fulfilment within 45 days (extendable 45)
  • Request log
Where this commonly fails
  • Access not provided within statutory timeframe
CTDPA-42-518-AUTHAGENT
Authorized Agents

Consumers may designate an authorized agent (including via technology) to exercise the opt-out right on their behalf.

Artefacts an auditor will ask for
  • Authorized-agent verification procedure
Where this commonly fails
  • No authorized-agent handling
CTDPA-42-518-CORRECT
Right to Correct

Consumers may correct inaccuracies in their personal data, taking into account the nature and purpose of processing.

Artefacts an auditor will ask for
  • Correction request procedure + records
Where this commonly fails
  • Corrections not actioned
CTDPA-42-518-DELETE
Right to Delete

Consumers may delete personal data provided by or obtained about them.

Artefacts an auditor will ask for
  • Deletion request procedure + processor propagation
Where this commonly fails
  • Deletion not propagated
CTDPA-42-518-OPTOUT
Right to Opt Out

Consumers may opt out of processing for targeted advertising, the sale of personal data, or profiling in furtherance of solely automated decisions with legal or similarly significant effects.

Artefacts an auditor will ask for
  • Opt-out mechanism for targeted advertising/sale/profiling
Where this commonly fails
  • No opt-out for targeted advertising/sale/profiling
CTDPA-42-518-PORT
Right to Data Portability

Consumers may obtain a portable, readily usable copy of personal data they previously provided.

Artefacts an auditor will ask for
  • Portable-copy export mechanism
Where this commonly fails
  • No portability mechanism
CTDPA-42-518-RESPONSE
Response Timeline and Appeal

Controllers must respond within 45 days (extendable by 45), provide information free of charge up to twice annually, and establish an appeal process responded to within 60 days with AG-contact information.

Artefacts an auditor will ask for
  • Response-timeline + appeal procedure with AG-contact disclosure
Where this commonly fails
  • No appeal process / late responses
CTDPA-42-518-UOOM
Universal Opt-Out Mechanism

By 1 January 2025 controllers must recognise an opt-out preference signal (universal opt-out mechanism) for targeted advertising and sale.

Artefacts an auditor will ask for
  • Recognition of opt-out preference signals (UOOM)
Where this commonly fails
  • UOOM not honoured

CTDPA: Controller Duties (42-520)

CTDPA-42-520-CHILDREN
Children's and Minors' Data

Controllers must not process the personal data of a consumer known to be a child except per COPPA, nor (per PA 23-56) process minors' (under 18) data for targeted advertising, sale, or certain profiling without consent, with additional minor-protection duties.

Artefacts an auditor will ask for
  • Age-aware processing controls
  • Consent + minor-protection measures per PA 23-56
Where this commonly fails
  • Minors' data processed without the required consent/protections
CTDPA-42-520-CONSENTREVOKE
Consent and Revocation (No Dark Patterns)

Consent must be a clear affirmative act, freely given, specific, informed and unambiguous (not via dark patterns); controllers must provide a mechanism to revoke consent and cease processing within 15 days of revocation.

Artefacts an auditor will ask for
  • Consent capture free of dark patterns
  • Consent-revocation mechanism honoured within 15 days
Where this commonly fails
  • Consent via dark patterns
  • No revocation mechanism
CTDPA-42-520-NONDISCRIM
Non-Discrimination

Controllers may not process personal data in violation of anti-discrimination laws and may not discriminate against consumers for exercising their rights.

Artefacts an auditor will ask for
  • Anti-discrimination + anti-retaliation review of processing and rights handling
Where this commonly fails
  • Discrimination against consumers exercising rights
CTDPA-42-520-PRIVNOTICE
Privacy Notice

Controllers must provide a reasonably accessible, clear and meaningful privacy notice (data categories, purposes, rights and how to exercise/appeal, categories shared/sold, opt-out methods including for sale/targeted advertising).

Artefacts an auditor will ask for
  • Published privacy notice covering 42-520 elements + opt-out methods
Where this commonly fails
  • Privacy notice missing required elements
CTDPA-42-520-PURPLIMIT
Purpose Limitation and Data Minimization

Controllers must limit collection to what is adequate, relevant and reasonably necessary for the disclosed purposes.

Artefacts an auditor will ask for
  • Minimisation review tied to disclosed purposes
Where this commonly fails
  • Over-collection beyond stated purpose
CTDPA-42-520-SALEDISC
Sale and Targeted-Advertising Disclosure

Where a controller sells personal data to third parties or processes for targeted advertising, it must clearly and conspicuously disclose this and the manner to opt out.

Artefacts an auditor will ask for
  • Clear/conspicuous sale + targeted-advertising disclosure with opt-out method
Where this commonly fails
  • Sale/targeted advertising not disclosed
CTDPA-42-520-SECONDARY
No Secondary Use Without Consent

Controllers may not process personal data for purposes not reasonably necessary to or compatible with the disclosed purposes without the consumer's consent.

Artefacts an auditor will ask for
  • Secondary-use assessment + consent records
Where this commonly fails
  • Incompatible secondary use without consent
CTDPA-42-520-SECURITY
Reasonable Security Practices

Controllers must establish, implement and maintain reasonable administrative, technical and physical data-security practices appropriate to the volume and nature of the data.

Artefacts an auditor will ask for
  • Reasonable security program appropriate to data volume/nature
Where this commonly fails
  • No reasonable security safeguards
CTDPA-42-520-SENSITIVE
Sensitive Data Opt-In Consent

Controllers may not process sensitive data without the consumer's consent (or, for a known child, in accordance with COPPA).

Artefacts an auditor will ask for
  • Sensitive-data opt-in consent records
  • Child-data per COPPA
Where this commonly fails
  • Sensitive data processed without consent

CTDPA: Data Protection Assessments (42-522)

CTDPA-42-522-DPA
Data Protection Assessments

Controllers must conduct and document data protection assessments for processing that presents a heightened risk of harm: targeted advertising, sale, sensitive-data processing, and profiling presenting specified risks; the AG may require disclosure.

Artefacts an auditor will ask for
  • Data protection assessments for heightened-risk processing
  • AG-disclosure readiness
Where this commonly fails
  • No DPA for targeted advertising/sale/sensitive/profiling

CTDPA: Definitions, Scope and Exemptions (42-515 to 517)

CTDPA-42-515
Definitions

Defines consumer (Connecticut resident acting in individual/household context, not commercial/employment), controller, processor, personal data, sensitive data (racial/ethnic origin, religious beliefs, mental/physical health condition or diagnosis, sex life, sexual orientation, citizenship/immigration status, genetic/biometric data, children's data, precise geolocation), sale, targeted advertising, profiling, de-identified data and consent.

Artefacts an auditor will ask for
  • Data inventory mapping CTDPA categories incl. sensitive data + precise geolocation
  • Identification of sale/targeted-advertising/profiling
Where this commonly fails
  • Sensitive-data/geolocation not identified
  • Sale/targeted-advertising not assessed
CTDPA-42-516
Applicability Thresholds

Applies to persons conducting business in Connecticut or targeting CT residents that, in the preceding year, controlled/processed the personal data of 100,000+ consumers (excluding payment-transaction-only data), or 25,000+ consumers and derived 25%+ of gross revenue from the sale of personal data.

Artefacts an auditor will ask for
  • Applicability determination against the CTDPA thresholds
Where this commonly fails
  • Applicability not assessed
CTDPA-42-516-EXEMPT
Entity and Data Exemptions

Exempts certain entities and data (state bodies, nonprofits in some cases, higher-education institutions, GLBA financial institutions, HIPAA covered entities/PHI, FCRA, FERPA, etc.).

Artefacts an auditor will ask for
  • Exemption analysis (GLBA/HIPAA/FCRA/FERPA etc.)
Where this commonly fails
  • Exemptions not assessed

CTDPA: Enforcement and Amendments (42-525; PA 23-56)

CTDPA-42-525-AGENFORCE
Exclusive Attorney General Enforcement

The Connecticut Attorney General has exclusive authority to enforce the CTDPA; a violation is an unfair trade practice under CUTPA; there is no private right of action.

Artefacts an auditor will ask for
  • Awareness of AG exclusive enforcement + CUTPA exposure
Where this commonly fails
  • No legal-exposure assessment
CTDPA-42-525-CHD
Consumer Health Data (PA 23-56)

Connecticut's 2023 amendment adds protections for consumer health data, including consent for processing and restrictions on sale.

Artefacts an auditor will ask for
  • Consumer-health-data inventory + consent/restriction controls
Where this commonly fails
  • Consumer health data processed without the PA 23-56 protections
CTDPA-42-525-CURE
Cure Period (Sunset 31 Dec 2024)

The Attorney General provided a 60-day right-to-cure for violations until 31 December 2024, after which cure is discretionary.

Artefacts an auditor will ask for
  • Cure-period response procedures
  • Tracking of post-sunset discretionary cure
Where this commonly fails
  • No process to respond to an AG cure notice
CTDPA-42-525-GEOFENCE
Geofencing Prohibition Near Health Facilities (PA 23-56)

Prohibits establishing a geofence within 1,750 feet of a mental-health or reproductive/sexual-health facility to identify, track or send notifications to consumers about their health data.

Artefacts an auditor will ask for
  • Controls preventing prohibited geofencing around health facilities
Where this commonly fails
  • Geofencing around health facilities

CTDPA: Processor and De-identified Data (42-521/523)

CTDPA-42-521-DEIDENT
De-identified and Pseudonymous Data

Controllers in possession of de-identified data must take reasonable measures to prevent re-identification, publicly commit to maintaining de-identification, and contractually bind recipients; rights do not apply to de-identified/pseudonymous data.

Artefacts an auditor will ask for
  • De-identification controls + public commitment + recipient contracts
Where this commonly fails
  • De-identified data re-identifiable
CTDPA-42-521-PROCESSOR
Processor Obligations and Contracts

Processing by a processor must be governed by a contract setting out instructions, nature/purpose, data types, duration, confidentiality, deletion/return, audit cooperation and sub-processor flow-down; processors must assist controllers.

Artefacts an auditor will ask for
  • Controller-processor contracts with 42-521 terms
  • Sub-processor flow-down + audit cooperation
Where this commonly fails
  • No CTDPA-compliant processor contract
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Connecticut Data Privacy Act (CTDPA) framework page.