On May 27, 2026, Connecticut Governor Ned Lamont signed Senate Bill 4, now Public Act No. 26-64 (the “Act”),[1] significantly expanding the Connecticut Data Privacy Act (CTDPA).

The Act creates a California Delete Act-style, but Connecticut-specific, data broker registration and deletion-mechanism regime. It also restricts the sale, sharing, transfer, and provision of access to precise geolocation data;[2] imposes facial recognition transparency requirements; adds surveillance-pricing prohibitions and disclosure obligations; narrows the CTDPA’s “publicly available information” exclusion; adds rules for certain employment-related processing and profiling decisions; expands consumer deletion rights; and regulates direct-to-consumer (DTC) genetic testing companies.

At a high level, the Act adds compliance obligations for data brokers, CTDPA controllers and processors, retailers, third-party delivery services, and DTC genetic testing companies.[3]

These amendments follow shortly after the July 1, 2026 effective date for separate CTDPA amendments enacted in 2025 through SB 1295, which expanded coverage thresholds, added profiling impact assessment obligations, and imposed minors-related requirements. Companies should thus treat SB 4 as part of a broader 2026 Connecticut compliance cycle, rather than a standalone update.

The rapid expansion of biometric technologies in sports has created both significant opportunities and complex legal challenges. The proliferation of wearable devices and data collection tools has ushered in what amounts to a “gold rush” for athletes, teams, universities, and companies seeking to use or commercialize biometric data. Heart rate

Earlier this year, we reported on the potential breeding ground for litigation under Illinois’ Biometric Information Privacy Act (“BIPA”).  A recent decision from an Illinois state appellate panel on the different limitations periods that apply to BIPA provides guidance for companies faced with a BIPA lawsuit and the arguments they

Illinois’ Biometric Information Privacy Act (“BIPA”) is alive and well as a potential breeding ground for litigation for tech companies. In the last month, two settlements have been announced in class actions where the plaintiffs alleged violations of BIPA in the U.S. District Court for the Northern District of Illinois. These settlements show that companies collecting biometrics should take care to ensure that their practices do not run afoul of BIPA’s requirements.

In late March, the French Data Protection Authority, Commission Nationale de l’Informatique et des Libertés (“CNIL”) released a model regulation (the “Model Regulation”) governing the use of biometric access controls in the workplace.  Unlike many items of personal information, biometric data (such as a person’s face or fingerprints) is unique and, if stolen or otherwise compromised, cannot be changed to avoid misuse.  Under Article 9 of the GDPR, biometric data collected “for the purpose of uniquely identifying a natural person” is considered “sensitive” and warrants additional protections.  The GDPR authorizes Member States to implement such additional protections.  As such, the French Data Protection Act 78-17 of 6 January 1978, as amended, now provides that employers – whether public or private – wishing to use biometric access controls must comply with binding model regulations adopted by the CNIL, the first of which is the Model Regulation.