On May 27, 2026, Connecticut Governor Ned Lamont signed Senate Bill 4, now Public Act No. 26-64 (the “Act”),[1] significantly expanding the Connecticut Data Privacy Act (CTDPA).

The Act creates a California Delete Act-style, but Connecticut-specific, data broker registration and deletion-mechanism regime. It also restricts the sale, sharing, transfer, and provision of access to precise geolocation data;[2] imposes facial recognition transparency requirements; adds surveillance-pricing prohibitions and disclosure obligations; narrows the CTDPA’s “publicly available information” exclusion; adds rules for certain employment-related processing and profiling decisions; expands consumer deletion rights; and regulates direct-to-consumer (DTC) genetic testing companies.

At a high level, the Act adds compliance obligations for data brokers, CTDPA controllers and processors, retailers, third-party delivery services, and DTC genetic testing companies.[3]

These amendments follow shortly after the July 1, 2026 effective date for separate CTDPA amendments enacted in 2025 through SB 1295, which expanded coverage thresholds, added profiling impact assessment obligations, and imposed minors-related requirements. Companies should thus treat SB 4 as part of a broader 2026 Connecticut compliance cycle, rather than a standalone update.

Key Takeaways:

  • CPPA launched its first major enforcement action in targeting connected vehicle-maker Honda.
  • Connected vehicles often collect various kinds of sensitive driver information, including geolocation, biometric and behavioral data.
  • After the CPPA found Honda in violation of several CCPA provisions, the company agreed to settle the enforcement action for approximately $650,000 while also agreeing to adopt certain remedial measures.
  • Other Connected vehicle-makers have also experienced a spike in regulatory scrutiny, signaling rising enforcement pressure and growing expectations for privacy-by-design.

UPDATE (April 17, 2025): The below reflects a development occurring after our publication of the original post.

On April 11, 2025, the National Security Division (the “NSD”) released several documents setting out initial guidance on how to comply with the Rule, which the NSD refers to as the Data Security

2024 marked another significant year for privacy law, with new state legislation and high-stakes litigation reshaping the landscape. Legal battles over tracking technologies, biometric data, and children’s privacy intensified, while federal agencies, including the Federal Trade Commission (“FTC”) and the U.S. Department of Health and Human Services Office for Civil Rights (“HHS OCR”), ramped up their efforts through major enforcement actions and high-profile settlements, marking a new era of increased accountability.

  • Amazon faces allegations of unauthorized data collection in violation of federal and state privacy laws, including a first-of-its-kind claim under Washington’s My Health My Data Act (“MHMDA”).
  • The MHMDA restricts businesses from collecting, sharing, or selling any-health related information about a consumer without their consent of “valid authorization”, going

On August 29, 2024, the Office for Civil Rights of the United States Department of Health and Human Services (“HHS-OCR”) withdrew its appeal of an order by the United States District Court for the Northern District of Texas’ (“District Court”) declaring unlawful and vacating a portion of an HHS-OCR Bulletin

On May 16, 2024, the U.S. Securities and Exchange Commission announced the adoption of amendments to Regulation S-P that were proposed last year. The Final Amendments impose enhanced requirements on registered investment advisers, investment companies, broker dealers and transfer agents with respect to handling of consumer financial information.

Read the

As part of our commitment to keeping you informed of new regulatory developments and their potential implications, we have highlighted recent statements by federal officials concerning loyalty programs, such as those involving airline miles and credit card points. These comments signal a potential shift in how these programs are viewed under consumer protection laws, and the plaintiffs’ bar is likely to take notice.