Connecticut Data Privacy Act (CTDPA)
Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CTDPA: Consumer Rights (42-518)
Consumers may confirm whether a controller is processing their personal data and access that data.
- Authenticated access-request fulfilment within 45 days (extendable 45)
- Request log
- Access not provided within statutory timeframe
Consumers may designate an authorized agent (including via technology) to exercise the opt-out right on their behalf.
- Authorized-agent verification procedure
- No authorized-agent handling
Consumers may correct inaccuracies in their personal data, taking into account the nature and purpose of processing.
- Correction request procedure + records
- Corrections not actioned
Consumers may delete personal data provided by or obtained about them.
- Deletion request procedure + processor propagation
- Deletion not propagated
Consumers may opt out of processing for targeted advertising, the sale of personal data, or profiling in furtherance of solely automated decisions with legal or similarly significant effects.
- Opt-out mechanism for targeted advertising/sale/profiling
- No opt-out for targeted advertising/sale/profiling
Consumers may obtain a portable, readily usable copy of personal data they previously provided.
- Portable-copy export mechanism
- No portability mechanism
Controllers must respond within 45 days (extendable by 45), provide information free of charge up to twice annually, and establish an appeal process responded to within 60 days with AG-contact information.
- Response-timeline + appeal procedure with AG-contact disclosure
- No appeal process / late responses
By 1 January 2025 controllers must recognise an opt-out preference signal (universal opt-out mechanism) for targeted advertising and sale.
- Recognition of opt-out preference signals (UOOM)
- UOOM not honoured
CTDPA: Controller Duties (42-520)
Controllers must not process the personal data of a consumer known to be a child except per COPPA, nor (per PA 23-56) process minors' (under 18) data for targeted advertising, sale, or certain profiling without consent, with additional minor-protection duties.
- Age-aware processing controls
- Consent + minor-protection measures per PA 23-56
- Minors' data processed without the required consent/protections
Consent must be a clear affirmative act, freely given, specific, informed and unambiguous (not via dark patterns); controllers must provide a mechanism to revoke consent and cease processing within 15 days of revocation.
- Consent capture free of dark patterns
- Consent-revocation mechanism honoured within 15 days
- Consent via dark patterns
- No revocation mechanism
Controllers may not process personal data in violation of anti-discrimination laws and may not discriminate against consumers for exercising their rights.
- Anti-discrimination + anti-retaliation review of processing and rights handling
- Discrimination against consumers exercising rights
Controllers must provide a reasonably accessible, clear and meaningful privacy notice (data categories, purposes, rights and how to exercise/appeal, categories shared/sold, opt-out methods including for sale/targeted advertising).
- Published privacy notice covering 42-520 elements + opt-out methods
- Privacy notice missing required elements
Controllers must limit collection to what is adequate, relevant and reasonably necessary for the disclosed purposes.
- Minimisation review tied to disclosed purposes
- Over-collection beyond stated purpose
Where a controller sells personal data to third parties or processes for targeted advertising, it must clearly and conspicuously disclose this and the manner to opt out.
- Clear/conspicuous sale + targeted-advertising disclosure with opt-out method
- Sale/targeted advertising not disclosed
Controllers may not process personal data for purposes not reasonably necessary to or compatible with the disclosed purposes without the consumer's consent.
- Secondary-use assessment + consent records
- Incompatible secondary use without consent
Controllers must establish, implement and maintain reasonable administrative, technical and physical data-security practices appropriate to the volume and nature of the data.
- Reasonable security program appropriate to data volume/nature
- No reasonable security safeguards
Controllers may not process sensitive data without the consumer's consent (or, for a known child, in accordance with COPPA).
- Sensitive-data opt-in consent records
- Child-data per COPPA
- Sensitive data processed without consent
CTDPA: Data Protection Assessments (42-522)
Controllers must conduct and document data protection assessments for processing that presents a heightened risk of harm: targeted advertising, sale, sensitive-data processing, and profiling presenting specified risks; the AG may require disclosure.
- Data protection assessments for heightened-risk processing
- AG-disclosure readiness
- No DPA for targeted advertising/sale/sensitive/profiling
CTDPA: Definitions, Scope and Exemptions (42-515 to 517)
Defines consumer (Connecticut resident acting in individual/household context, not commercial/employment), controller, processor, personal data, sensitive data (racial/ethnic origin, religious beliefs, mental/physical health condition or diagnosis, sex life, sexual orientation, citizenship/immigration status, genetic/biometric data, children's data, precise geolocation), sale, targeted advertising, profiling, de-identified data and consent.
- Data inventory mapping CTDPA categories incl. sensitive data + precise geolocation
- Identification of sale/targeted-advertising/profiling
- Sensitive-data/geolocation not identified
- Sale/targeted-advertising not assessed
Applies to persons conducting business in Connecticut or targeting CT residents that, in the preceding year, controlled/processed the personal data of 100,000+ consumers (excluding payment-transaction-only data), or 25,000+ consumers and derived 25%+ of gross revenue from the sale of personal data.
- Applicability determination against the CTDPA thresholds
- Applicability not assessed
Exempts certain entities and data (state bodies, nonprofits in some cases, higher-education institutions, GLBA financial institutions, HIPAA covered entities/PHI, FCRA, FERPA, etc.).
- Exemption analysis (GLBA/HIPAA/FCRA/FERPA etc.)
- Exemptions not assessed
CTDPA: Enforcement and Amendments (42-525; PA 23-56)
The Connecticut Attorney General has exclusive authority to enforce the CTDPA; a violation is an unfair trade practice under CUTPA; there is no private right of action.
- Awareness of AG exclusive enforcement + CUTPA exposure
- No legal-exposure assessment
Connecticut's 2023 amendment adds protections for consumer health data, including consent for processing and restrictions on sale.
- Consumer-health-data inventory + consent/restriction controls
- Consumer health data processed without the PA 23-56 protections
The Attorney General provided a 60-day right-to-cure for violations until 31 December 2024, after which cure is discretionary.
- Cure-period response procedures
- Tracking of post-sunset discretionary cure
- No process to respond to an AG cure notice
Prohibits establishing a geofence within 1,750 feet of a mental-health or reproductive/sexual-health facility to identify, track or send notifications to consumers about their health data.
- Controls preventing prohibited geofencing around health facilities
- Geofencing around health facilities
CTDPA: Processor and De-identified Data (42-521/523)
Controllers in possession of de-identified data must take reasonable measures to prevent re-identification, publicly commit to maintaining de-identification, and contractually bind recipients; rights do not apply to de-identified/pseudonymous data.
- De-identification controls + public commitment + recipient contracts
- De-identified data re-identifiable
Processing by a processor must be governed by a contract setting out instructions, nature/purpose, data types, duration, confidentiality, deletion/return, audit cooperation and sub-processor flow-down; processors must assist controllers.
- Controller-processor contracts with 42-521 terms
- Sub-processor flow-down + audit cooperation
- No CTDPA-compliant processor contract
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Connecticut Data Privacy Act (CTDPA) framework page.