Privacy GuideAugust 16, 202610 min read

Connecticut's New Data Broker Law (Public Act 26-64): 2026 Guide

PT

By PrivacyOn Team

Privacy Research & Removal Operations

Connecticut's New Data Broker Law (Public Act 26-64): 2026 Guide

Don't want to do this by hand? We remove your info from 100+ broker sites automatically.

On May 27, 2026, Connecticut Governor Ned Lamont signed Public Act No. 26-64 — a sweeping expansion of the Connecticut Data Privacy Act (CTDPA) that adds a data broker registry, bans the sale of precise geolocation data, restricts surveillance pricing, and commits the state to a centralized deletion mechanism by July 1, 2028. The core amendments take effect October 1, 2026. Here's what changed, who it covers, and how Connecticut residents can enforce their new rights.

What Public Act 26-64 Actually Does

Public Act 26-64 (originally Senate Bill 4) is the largest overhaul of Connecticut privacy law since the CTDPA took effect in July 2023. It layers new obligations on data brokers, closes several loopholes in the original law, and introduces protections against emerging surveillance practices. The major provisions include:

  • A data broker registry maintained by the Connecticut Department of Consumer Protection, effective January 1, 2027.
  • A prohibition on the sale of precise geolocation data — one of the strongest location-privacy provisions in the country.
  • Surveillance-pricing disclosures and restrictions — companies that use consumer data to set prices at retail must disclose that practice.
  • Facial recognition signage and policy obligations for businesses using face-scanning for on-premises security.
  • Direct-to-consumer genetic testing protections — new consent rules for 23andMe-style services.
  • A statewide accessible deletion mechanism — a single-request deletion portal for all registered brokers, launching by July 1, 2028.

The Geolocation Ban Is Immediate on October 1, 2026

Selling, offering for sale, or licensing precise geolocation data about a Connecticut consumer becomes unlawful on October 1, 2026 — with limited exceptions for public safety, fraud prevention, and consumer-requested services. This closes one of the most abused loopholes in state privacy law: location data brokers who monetized cell-tower and mobile SDK data with weak or bundled consent.

How Connecticut's Data Broker Registry Works

Any business that sells or licenses "brokered personal data" about Connecticut residents must register with the Department of Consumer Protection. The registry mirrors California's Delete Act framework but adds tighter disclosure and enforcement.

Step 1: Registration Opens January 1, 2027

Data brokers must submit their initial registration and pay a $2,500 annual fee starting January 1, 2027. Missing the deadline triggers civil penalties enforceable by the Connecticut Attorney General.

Step 2: Public Disclosures

Each registered broker must publicly disclose:

  • The categories of personal data collected and sold
  • The sources of that data (public records, purchase histories, mobile SDKs, etc.)
  • Whether it collects data about known minors
  • How to submit deletion and opt-out requests
  • Any material data breaches from the prior year

Step 3: Universal Deletion by July 1, 2028

Public Act 26-64 directs the Department of Consumer Protection to build an "accessible deletion mechanism" — a single online portal where a Connecticut resident can submit one deletion request that is forwarded to every registered broker. This is Connecticut's version of California's DROP platform, and it goes live by July 1, 2028.

The Precise Geolocation Ban

Location data has been one of the least-regulated and most-monetized categories in the data broker economy. Public Act 26-64 makes Connecticut one of the toughest states on this issue. Beginning October 1, 2026:

  • Selling, offering for sale, or licensing precise geolocation data about a Connecticut consumer is prohibited.
  • "Precise geolocation" typically means data that identifies a person's location within about 1,850 feet (roughly a third of a mile).
  • Limited exceptions apply for public safety uses, fraud prevention, and services expressly requested by the consumer (like ride-hailing or delivery).
  • Weather apps, flashlight utilities, and other apps historically monetizing background location data through mobile SDKs are squarely in scope if the data is sold or licensed.

Ad-Tech and Mobile SDKs Are Named Targets

The bill's legislative history explicitly discussed mobile SDK operators — the companies embedded in weather, sports, and utility apps that quietly harvest location for downstream sale. If your favorite weather app suddenly changes its data practices in late 2026, this is why.

Surveillance-Pricing Restrictions

Public Act 26-64 introduces one of the first state-level responses to "surveillance pricing" — the practice of using individual consumer data to set personalized prices in real time. The FTC issued a report on surveillance pricing in early 2025, but Congress has not acted. Connecticut now becomes an early mover, requiring:

  • Clear disclosure when a company uses personal data or behavioral signals to set the price a consumer sees.
  • Additional restrictions in retail-sale contexts where personalized pricing has historically been opaque.
  • Consumer notice and opt-out obligations for companies deploying pricing algorithms tied to personal data profiles.

Genetic Testing and Facial Recognition Protections

Two additional 2026 protections round out the amendments:

Direct-to-Consumer Genetic Testing

Following the fallout from the 23andMe data breach and bankruptcy, Connecticut tightens consent rules for genetic testing companies. Testing firms must obtain express affirmative consent for the collection, use, and retention of genetic data — and separate consent for any sharing with third parties. This adds to protections already in the CTDPA and other state genetic-privacy laws.

Facial Recognition Signage and Policies

Businesses using facial recognition for on-premises security must post conspicuous signage disclosing the use, maintain a written policy, and provide a means for consumers to inquire about the practice. Retailers deploying face-scanning for loss prevention are the primary target.

Skip the manual work

PrivacyOn removes your personal information from 100+ data broker sites and keeps it removed — automatically.

Start your free scan

★★★★★ 4.8/5 · Trusted by thousands of families

How Public Act 26-64 Compares to California's Delete Act

Both create data broker registries and universal deletion mechanisms, but the two laws differ in scope and enforcement:

  • California: DROP portal live August 1, 2026. Broker registration fee ~$6,600. No blanket ban on sensitive data sales — relies on individual deletion.
  • Connecticut: Broker registry January 1, 2027. Deletion portal by July 1, 2028. $2,500 annual broker fee. Adds explicit bans on precise geolocation sales and surveillance-pricing rules that California does not have.
  • New Jersey: A5328 (June 2026) bans the sale of a broader sensitive-data category and imposes fees up to $1.5 million on brokers. See our New Jersey A5328 guide.

Together, California, Connecticut, and New Jersey now form the strictest data broker regulatory triangle in the U.S. Residents of any of these states can invoke overlapping rights against nearly every national broker.

What This Means for Connecticut Residents

You already have significant rights under the CTDPA — the right to access, correct, delete, and opt out of sales, targeted advertising, and profiling. Public Act 26-64 adds:

  • An outright ban on sales of your precise location data — enforceable against any company selling to a downstream buyer, not just "registered brokers."
  • A searchable public registry (2027) to identify who holds data about Connecticut consumers.
  • A universal deletion portal (2028) allowing a single request to reach every registered broker.
  • Notice and opt-out rights around surveillance pricing, facial recognition, and genetic testing.

How to Exercise Your Rights Today

Step 1: Submit CTDPA Deletion Requests

You do not have to wait for the 2028 universal portal. Under the CTDPA, any qualifying business must respond to your deletion request within 45 days. Focus on data brokers, ad-tech firms, and people-search sites first. See our data deletion request letter templates.

Step 2: Turn Off Precise Location on Every App

Even with the October 1, 2026 sale ban, the best defense is reducing what apps can collect in the first place. On iOS, go to Settings → Privacy & Security → Location Services and set every non-essential app to "Never" or "Ask Next Time." On Android, do the same under Settings → Location → App permissions.

Step 3: Enable Global Privacy Control

Under the CTDPA, businesses must recognize the Global Privacy Control (GPC) browser signal. Enable it in Firefox or Brave, or via a Chrome extension. Once enabled, every website you visit automatically receives an opt-out-of-sale request.

Step 4: Opt Out of Every Major People-Search Site

People-search sites are the visible layer of the data broker economy. Each has its own opt-out process. See our complete people-search opt-out guide, or use PrivacyOn to automate the entire workflow.

Step 5: File Complaints on Ignored Requests

The Connecticut Attorney General enforces the CTDPA. If a company ignores a valid deletion or opt-out request beyond the 45-day statutory window, file a complaint at portal.ct.gov/AG. Documentation of the original request and any responses (or lack thereof) is critical.

Location Data Already Sold Cannot Be Recalled

Public Act 26-64 stops future sales but does not force downstream buyers to delete location data they already purchased. This is why continuous monitoring and re-submission of removal requests matters more than a one-time cleanup — even after the October 1, 2026 effective date, your historical location trail can still circulate.

How PrivacyOn Helps Connecticut Residents Enforce Public Act 26-64

Connecticut just gave its residents some of the strongest privacy rights in the country. The gap between having those rights on paper and actually removing your data from the broker economy is enormous — dozens of brokers, dozens of opt-out flows, and endless relistings from fresh public-records feeds.

PrivacyOn is our top pick for automating this work across Connecticut and every other state. PrivacyOn submits removal requests across 100+ data broker sites, continuously monitors for relistings, tracks responses, and re-files whenever brokers add you back. Combined with 24/7 dark web monitoring and family plans covering up to 5 people, PrivacyOn turns Public Act 26-64's promise into a set-and-forget reality — starting at $8.33/month. Run a free scan to see which brokers currently hold your data.

Frequently Asked Questions

When does Connecticut's new data broker law take effect?

Governor Ned Lamont signed Public Act No. 26-64 on May 27, 2026. Most provisions — including the precise geolocation sale ban and the surveillance-pricing rules — take effect October 1, 2026. Data broker registration with the Department of Consumer Protection begins January 1, 2027. The universal deletion portal launches by July 1, 2028.

What is "precise geolocation" under Connecticut law?

Precise geolocation typically means location data that identifies a person's location within about 1,850 feet (roughly a third of a mile). It covers GPS coordinates, cell-tower positioning, Wi-Fi network fingerprints, and any combination of signals that can pin someone to a specific building or street. Coarse location like city or ZIP code generally is not covered by the ban.

Does Public Act 26-64 apply to companies outside Connecticut?

Yes. Any company selling, offering for sale, or licensing brokered personal data (including precise geolocation) about a Connecticut resident is covered, regardless of where the company is located. This mirrors how the CTDPA and other state privacy laws reach national companies.

What are the penalties for violating the new law?

Violations are enforceable by the Connecticut Attorney General under the CTDPA and the state's Unfair Trade Practices Act. Civil penalties can reach $5,000 per willful violation, plus injunctive relief and consumer restitution. Failure to register as a data broker triggers separate penalties from the Department of Consumer Protection.

How does Connecticut's law compare to New Jersey's A5328?

New Jersey's A5328 bans the sale of a broad category of sensitive data (health, immigration, sexual orientation, financial account, precise geolocation, and more) with a $50,000-per-record penalty. Connecticut's Public Act 26-64 focuses more narrowly — banning precise geolocation sales and adding registry, surveillance-pricing, facial-recognition, and genetic-testing protections. Both are stronger than California's Delete Act on the specific practices they target.

What's the fastest way to remove my data under Connecticut law?

Manual opt-outs across every major broker take 30 to 60 hours and have to be repeated because brokers relist. PrivacyOn automates the process — submitting CTDPA-compliant removal requests across 100+ brokers, monitoring for relistings, and re-filing whenever your data reappears — for $8.33/month with family coverage up to 5 people. A free scan surfaces where your data currently appears before you send your first deletion demand.

PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Your info is on 100+ broker sites. Take it down.

Let PrivacyOn automatically remove your personal information from data broker sites and keep it removed.

★★★★★ 4.8/5 · Trusted by thousands of families