Connecticut's Data Privacy Act caps civil penalties at $5,000 per willful violation, enforced as a per se breach of the state's existing Unfair Trade Practices Act, and the Attorney General's office reviewed 1,830 data breach notifications in 2025 alone, according to the Office of the Attorney General's own 2025 CTDPA Enforcement Report published within its February 1, 2026 statutory deadline. Three years after the law took effect, its enforcement record looks less like courtroom fines and more like a steady stream of cure notices, warning letters, and negotiated settlements, several of which now carry real dollar figures attached.

Connecticut CTDPA: fifth US state privacy law, in effect since 2023 CTDPA Connecticut, USA, since 2023 $5,000 per willful violation,under CUTPA 35,000 consumers processedto trigger, from 7/1/2026 no private right of action,AG enforcement only, cure period ended 2024

Figure: Connecticut CTDPA at a glance. Source: Conn. Gen. Stat. sections 42-515 and 42-525; Public Act 25-113.

What is Connecticut's civil penalty for a CTDPA violation?

The Connecticut Data Privacy Act, commonly abbreviated CTDPA, does not set its own penalty schedule. Instead, Conn. Gen. Stat. section 42-525(e) makes any CTDPA violation a per se violation of the Connecticut Unfair Trade Practices Act, or CUTPA, which caps civil penalties at $5,000 per willful violation.

Figure 1: Connecticut's $5,000 cap is the lowest among the four states whose privacy laws took effect in 2023. Source: Recording Law's 2026 state comparison; corroborated by the Virginia CDPA enforcement cluster post.

That $5,000 figure comes from a state-by-state comparison compiled by Recording Law and is confirmed in the Office of the Attorney General's own enforcement reports. Enforcement runs exclusively through the Attorney General; consumers have no private right of action under the CTDPA.

Penalty size tells only part of the story. Connecticut's law originally guaranteed businesses a 60-day cure period before any enforcement action, but that guarantee expired December 31, 2024. Since January 1, 2025, the Attorney General has retained full discretion over whether to offer a cure opportunity at all, weighing the violation's severity, the entity's size, and the number of affected consumers, per the OAG's own 2025 Enforcement Report. Public Act 25-113 goes further, formally striking the cure provision from the statute's enforcement section effective July 1, 2026.

How many breach notifications and complaints has Connecticut's Privacy Section received?

The Attorney General's Privacy Section, the first standalone state privacy office in the country according to its own 2025 Enforcement Report, reviews every data breach notification filed under Connecticut's breach notice statute, Conn. Gen. Stat. section 36a-701b, whether or not the breach also implicates the CTDPA. The Office logged 1,830 such notifications in 2025, part of a caseload that has more than doubled since the law's early years.

Figure 2: Breach notifications climbed every year through 2024 before dipping slightly in 2025. Source: Office of the Attorney General, State of Connecticut, 2025 CTDPA Enforcement Report.

Complaint volume tells a similar story of a caseload that keeps growing without keeping pace on enforcement dollars. The OAG received almost 70 new CTDPA-related complaints since its prior reports, and nearly a third of those, 22 complaints, involved entities or data that the OAG determined were likely exempt under the law, most often people-search sites relying on the CTDPA's broad publicly-available-information carve-out. Separately, the Office fielded more than 60 breach-related complaints in 2025 alone and issued 63 warning letters to companies whose breach notices arrived late or lacked required detail, most citing Connecticut's 60-day outer notice deadline measured from when a company first becomes aware of suspicious activity, not when its investigation concludes.

What is Connecticut's first CTDPA-specific enforcement settlement?

Every dollar figure Connecticut has collected under its broader privacy laws to date traces back to one of two statutes: the CTDPA itself, or the state's separate, older breach-notification law. Until late 2025, every settlement fell into the second category. That changed with TicketNetwork, Inc., an online ticket marketplace whose privacy notice the OAG flagged as inordinately hard to read, missing required data-rights disclosures, and equipped with opt-out mechanisms that did not actually work.

The Office issued TicketNetwork a cure notice in November 2023, well inside the CTDPA's original guaranteed cure window. TicketNetwork did not fix the deficiencies until December 2024, more than a year later and well past the 60-day statutory cure period. Under the resulting Assurance of Voluntary Compliance, TicketNetwork agreed to review its privacy notice for CTDPA compliance at least annually, document every consumer data-rights request it receives, and report that documentation to the OAG, in addition to an $85,000 payment to the state.

Figure 3: How a CTDPA violation moves from complaint to settlement. Source: Conn. Gen. Stat. section 42-525(e); OAG 2025 CTDPA Enforcement Report.

A well-maintained, accurate privacy notice is exactly the kind of document that keeps a business out of this pipeline in the first place; businesses that generate a CTDPA-ready privacy policy covering data-rights mechanisms and opt-out links close off the single most common trigger for a Connecticut cure notice before one is ever sent.

Widen the lens beyond the CTDPA itself, and Connecticut's Attorney General has negotiated eight disclosed settlements tied to consumer privacy and data security since 2024, together worth roughly $886,085 in payments to the state. Most of that total, however, comes from breach-notification-law settlements rather than CTDPA enforcement proper, an important distinction the OAG's own reports are careful to keep separate.

CompanyStatute basisCT residents affectedPayment to state
WebTPA Employer Services, LLCBreach notice law49,855$200,000
PharMerica Corp. / BrightSpring HealthBreach notice law105,057$200,000
Illuminate EducationStudent Data Privacy Act26,680$150,000
Fresenius Medical Care HoldingsBreach notice law9,483$116,085
Omni HealthcareBreach notice law330$105,000
TicketNetwork, Inc.CTDPANot disclosed$85,000
Nextiva Servicing LLCBreach notice lawNot disclosed$15,000
Horne LLPBreach notice lawNot disclosed$15,000

Source: Office of the Attorney General, State of Connecticut, 2025 CTDPA Enforcement Report.

Figure 4: Only $85,000 of the $886,085 collected so far is a CTDPA-specific penalty; the rest comes from Connecticut's separate breach-notification and student-data statutes. Source: Office of the Attorney General, State of Connecticut, 2025 CTDPA Enforcement Report.

The six breach-notice settlements share a common thread: every one involved a company that took months, and in Nextiva's case nearly four years, to tell affected Connecticut residents their data had been exposed. The OAG has said plainly that it measures the clock from when a company first becomes aware of suspicious activity, not when an internal investigation wraps up, and that late notice alone, independent of the breach itself, is now something the state is willing to put a price on. Every settlement also required injunctive relief beyond the payment itself: new information-security programs, mandatory multi-factor authentication and access controls, and, in Illuminate Education's case, the OAG's first-ever enforcement action under Connecticut's separate Student Data Privacy Act.

None of these dollar figures existed as recently as early 2024, when the OAG's first enforcement report described a caseload made up almost entirely of cure notices with no payments attached. The shift from cure notices to negotiated payments over just two annual reporting cycles is itself one of the more citable enforcement trends to come out of Connecticut's program, and it sets up the next question: what does the law these settlements enforce actually require starting in 2026.

What changes to CTDPA enforcement take effect in 2026 and 2027?

Connecticut's legislature passed two separate bills in its 2025 and 2026 sessions that reshape who the CTDPA covers and what it requires, on a staggered timeline running from mid-2026 into 2027. The changes are broad enough that a business which concluded it fell outside the CTDPA's original 100,000-consumer threshold should not assume that conclusion still holds.

Figure 5: Connecticut's privacy law has been amended in every legislative session since it passed. Source: Public Act 22-15, Public Act 23-56, Public Act 25-113, Office of the Attorney General enforcement reports.

Public Act 25-113 lowers the CTDPA's applicability threshold from 100,000 Connecticut consumers to 35,000, effective July 1, 2026, and eliminates the law's original revenue-based trigger entirely. In its place, any business that processes any volume of sensitive data or sells any volume of personal data, regardless of consumer count, falls under the law, according to analysis from both the National Law Review and Snell and Wilmer. The amendment also raises the age covered by the CTDPA's minors' protections from under 16 to under 18, bans targeted advertising to and data sales involving minors outright where a controller has actual knowledge of a user's age, and requires privacy notices to disclose whether personal data is used to train large language models. A second bill, Senate Bill 4, adds an outright ban on selling precise geolocation data and a new data broker registration requirement, effective October 1, 2026 and January 1, 2027 respectively.

How does Connecticut's enforcement approach compare to its peer states?

Connecticut was the fourth state to pass a comprehensive privacy law, in 2022, and joined California, Colorado, Virginia, and Utah as one of five states with an effective law by the end of 2023. By January 2026, that number had grown to 20 states, according to the IAPP's US State Privacy Legislation Tracker and PrivacyTerms.io's own state-by-state privacy law tracker, and Connecticut is now one of 11 states whose regulators formally coordinate through the Consortium of Privacy Regulators, a group launched in April 2025 to share investigative resources across state lines.

Connecticut's $5,000 penalty cap sits at the bottom of its original 2023 cohort, below Virginia's and Utah's $7,500 and well below Colorado's $20,000, a gap our Virginia CDPA enforcement post breaks down in more detail, and Utah's own 100,000-consumer threshold, still unchanged as of our Utah, Iowa, and Indiana scope comparison, is nearly three times higher than Connecticut's new 35,000-consumer floor. What Connecticut's low per-violation cap does not reflect is enforcement appetite: the state's Privacy Section was the first standalone privacy office among any state attorney general, and its willingness to extract five- and six-figure payments through breach-notice settlements, even absent a single CTDPA court fine, mirrors the same steady, notice-heavy posture documented for Virginia and Colorado. For a broader look at how CTDPA thresholds and penalties stack up against every other state with a comprehensive law in force, see our full 2026 comparison of state privacy law scope.

The Bottom Line

Connecticut's CTDPA reads as a modest law on paper: a $5,000 penalty cap that ranks lowest among its founding 2023 cohort, a cure period that already sunset once and disappears from the statute entirely in July 2026, and, as of the 2025 Enforcement Report, exactly one dedicated CTDPA settlement worth $85,000. What the numbers actually show is an office that has been busy in adjacent lanes: 1,830 breach notifications reviewed in a single year, 63 warning letters over late notice, and $886,085 collected across eight settlements once the state's breach-notification and student-data statutes are counted alongside the CTDPA itself. With the applicability threshold dropping to 35,000 consumers and the cure period disappearing in mid-2026, a business that has not reviewed its Connecticut-facing privacy notice since the law's 2023 debut has considerably more reason to do so now than it did a year ago.

Frequently Asked Questions

What is the penalty for violating Connecticut's CTDPA? Up to $5,000 per willful violation, because a CTDPA violation is a per se violation of the Connecticut Unfair Trade Practices Act (CUTPA), per Conn. Gen. Stat. section 42-525(e). Enforcement runs exclusively through the Attorney General, and there is no private right of action.

Has Connecticut fined any company under the CTDPA? No court-ordered fine has been issued, but the Attorney General announced the CTDPA's first dedicated settlement in its 2025 Enforcement Report: a $85,000 Assurance of Voluntary Compliance with TicketNetwork, Inc., after the company took over a year to fix a noncompliant privacy notice.

Who will the CTDPA apply to starting July 2026? Any business conducting business in Connecticut or targeting Connecticut residents that controlled or processed the personal data of 35,000 or more consumers in the prior calendar year, down from 100,000, or that processed any volume of sensitive data or sold any personal data at all, with no revenue-based threshold remaining, effective July 1, 2026 under Public Act 25-113.

Does Connecticut still give businesses a chance to cure a CTDPA violation? Only at the Attorney General's discretion. The CTDPA's guaranteed 60-day cure period expired December 31, 2024, and Public Act 25-113 formally removes the cure right from the statute's enforcement section effective July 1, 2026, leaving cure entirely optional going forward.

Where the Numbers Come From

  1. Office of the Attorney General, State of Connecticut. (2026). "CTDPA Enforcement Report 2025." Third annual report since the CTDPA's July 1, 2023 effective date; source for the 1,830 breach notifications, 63 warning letters, ~70 complaints, TicketNetwork settlement, and all AVC payment figures.
  2. Morrison Foerster. (2024). "Connecticut AG Issues First Enforcement Report of the CT Data Privacy Act." Confirms the original 60-day cure period and its December 31, 2024 expiration.
  3. Recording Law. (2026). "US State Privacy Laws Comparison Chart." Source for the $5,000 CUTPA-based penalty figure and the Colorado, Virginia, and Utah comparison figures.
  4. The National Law Review. (2026). "Connecticut Dramatically Expands Its Data Privacy Act." Source for the 35,000-consumer threshold, elimination of the revenue-based trigger, and minors' age expansion, effective July 1, 2026.
  5. Snell and Wilmer. (2026). "Connecticut Data Privacy Act: 2026 Amendments." Corroborates the July 1, 2026 and October 1, 2026 staggered effective dates and the January 1, 2027 data broker registration date.
  6. Office of the Vermont Attorney General. (2026). "Vermont Joins Bipartisan Coalition of Privacy Regulators to Strengthen Data Privacy Efforts." Confirms Connecticut's membership among the 11-state Consortium of Privacy Regulators.
  7. IAPP. "US State Privacy Legislation Tracker." Source for the 20-states-in-effect count as of January 2026 used in the peer-state comparison.

Note: All figures verified as of August 2026. The Attorney General's enforcement posture, especially around the CTDPA's newly discretionary cure period and the 2026 threshold change, remains live and subject to change; this post is refreshed at least twice a year to track new Connecticut Attorney General enforcement reports and settlement announcements.