Three State Privacy Laws Take Effect July 1, 2026
Three state privacy laws change on July 1, 2026. Connecticut's is the one most likely to catch NJ and NY businesses off guard.
Starting Tuesday, Connecticut's Data Privacy Act applies to any business that processes personal data for at least 35,000 Connecticut residents. That is down from 100,000. Any organization that collects financial account information, Social Security numbers, health data, or biometric data from even a single Connecticut resident is now covered with no volume threshold at all. And the cure period that used to give businesses a window to fix violations before enforcement began is gone. If Connecticut's attorney general finds a violation, enforcement can start the same day.
For businesses in the tri-state area, this one is worth taking seriously. A lot of B2B and B2C companies operating in New Jersey and New York have Connecticut customers and have never thought of themselves as being subject to Connecticut privacy law. That math changes Tuesday.
What Changed Under Connecticut's Privacy Law
The old thresholds required processing personal data for at least 100,000 Connecticut residents, or 25,000 residents if more than 25% of revenue came from selling personal data.
Effective July 1, the CTDPA covers:
- Any business processing personal data for at least 35,000 Connecticut residents
- Any business that sells personal data to a third party, even for a single Connecticut resident
- Any business that processes sensitive data from a single Connecticut resident, regardless of volume
That third trigger is the one that pulls in the most businesses that were not expecting it. The cure period is also gone. Previously, a business discovered to be in violation had a window to correct the issue before facing penalties. That option no longer exists.
Connecticut's amended law was signed on May 27, 2026, which gave businesses about five weeks to prepare. Many did not know about it.
The Sensitive Data Trigger Is the One to Watch
Connecticut now treats the following as sensitive data requiring heightened protection and, in most cases, explicit consumer consent before processing:
- Mental or physical disability status or treatment
- Biometric and genetic data
- Neural data
- Financial account information
- Government-issued identification numbers, including Social Security numbers and driver's licenses
- Precise geolocation data
Coverage at any volume means the 35,000-resident threshold does not apply. If a 40-person professional services firm in Hoboken has even one Connecticut client whose intake form collected an SSN, that firm is now covered under the CTDPA. If a 60-person staffing company in Newark runs background checks that include biometric data on candidates who happen to live in Connecticut, covered. A SaaS company in Jersey City whose software handles financial account data for clients with Connecticut employees, covered.
None of those businesses thought they were subject to Connecticut privacy law last week.
What Connecticut Now Requires From Covered Businesses
For businesses newly within scope, here is what the law requires.
Privacy notice. A privacy notice disclosing what personal data is collected, how it is used, how long it is retained, and whether it is sold or shared with third parties. Connecticut now specifies how and where the notice must be displayed. There is also a new disclosure requirement if you use customer data to train large language models. Connecticut is one of the first states to require this specific disclosure. If your business uses any AI tool that trains on customer data, that needs to appear in your privacy notice.
Material change notifications. If your data practices change in a material way, Connecticut residents must be notified and given the chance to withdraw consent before the new practices apply to their data.
Consumer rights process. Covered businesses must have a mechanism for Connecticut residents to access, delete, and correct their personal data. Residents can also request profiling opt-outs. There needs to be someone who can receive and respond to these requests.
Sensitive data consent. Processing sensitive data requires prior consumer consent. Selling sensitive data without consent is prohibited.
For a broader look at what an AI-specific policy needs to cover, the AI acceptable use policy post from June covers the governance layer businesses often skip.
Utah and Arkansas Round Out July 1
The other two state changes taking effect Tuesday are narrower.
Utah adds a right to correction under its Consumer Privacy Act. If a Utah resident believes your business holds inaccurate data about them, they can request a correction. Businesses have 45 days to respond. Utah also adds data portability requirements for social media platforms.
Arkansas bans targeted advertising tracking aimed at users under 16. If your business uses ad or analytics platforms that rely on age-based signals, check whether those tools track younger users.
What Growing Businesses Should Look at Before Tuesday
There are five questions worth working through right now.
One: How many Connecticut residents are in your CRM or customer database? If the number is 35,000 or more, you are covered under the general threshold. If you have sold any customer data to a third party and any of those customers lived in Connecticut, you are covered regardless of volume.
Two: Do you collect sensitive data from Connecticut residents? Financial information, health data, SSNs, biometric data, or government IDs all trigger coverage the moment you have one Connecticut resident in the dataset.
Three: Is your privacy notice current? Does it describe all categories of data collected, how it is used, how long it is kept, and who it is shared with? Does it mention LLM training if any of your tools train on customer data?
Four: Do you have a process for consumer data requests? Access, deletion, correction. These requests have to go somewhere and get answered within required timeframes.
Five: Who owns this at your business? At most 30-to-100-person businesses, the answer is nobody clearly. Privacy compliance tends to fall into the gap between legal, IT, and operations. Without someone who has mapped your software stack and understands what data flows where, you cannot answer questions two through four with any confidence.
The businesses that end up with enforcement problems are usually not the ones that ignored these laws. They are the ones that genuinely did not know the laws applied to them. The thresholds that provided some runway are shrinking, and the cure periods that allowed for corrections are disappearing.
We covered the New Jersey Data Privacy Act deadline for July 15 in detail earlier this month. Businesses in the tri-state area may need to assess both laws at the same time. The NJDPA and the updated CTDPA have different thresholds, different sensitive data definitions, and different enforcement postures.
Not sure whether these privacy laws apply to your business? The answer depends on what data you are collecting, from whom, and how it flows through your systems. Get in touch to work through it.
Frequently Asked Questions
Does this apply to businesses located outside Connecticut? Yes. The CTDPA applies to any business that processes personal data of Connecticut residents, regardless of where the business is located. Physical presence in Connecticut is not required.
What counts as sensitive data under Connecticut's updated law? Mental or physical disability status or treatment, biometric and genetic data, neural data, financial account information, government-issued IDs including SSNs and driver's licenses, and precise geolocation data. Processing any sensitive data from a single Connecticut resident triggers coverage under the amended law.
What happens if a business is not compliant on July 1? Connecticut eliminated the cure period that previously applied. There is no longer a guaranteed window to fix a violation before enforcement begins. Penalties under the CTDPA can reach $5,000 per violation.
How is this different from the New Jersey Data Privacy Act? The NJDPA, which has a July 15 deadline, applies to businesses processing data for 100,000 New Jersey residents, or 25,000 if data is sold. Connecticut's updated thresholds are lower and include the sensitive data trigger at any volume. Businesses in the tri-state region should evaluate both laws separately.
Why did Connecticut remove the cure period? The cure period created a dynamic where businesses could wait until they were notified of a violation before taking compliance seriously. Connecticut regulators viewed that as weakening enforcement. Without a guaranteed cure period, the risk of being caught noncompliant is an enforcement risk, not just a notice to fix something.