Connecticut continues to expand its data privacy and artificial intelligence (AI) laws. Just months after significant amendments took effect in July, another new set of privacy and AI requirements will begin taking effect on October 1, 2026. As McCarter discussed in its earlier alert on Connecticut Data Privacy Act statutory changes and enforcement, those amendments expanded the Connecticut Data Privacy Act’s (CTDPA) reach and strengthened consumer protections. Additional requirements under the new laws will phase in through 2027 and beyond.
Companies that reviewed their Connecticut privacy programs earlier this year should revisit them again now, particularly if they use personal data for pricing, facial recognition, geolocation, genetic testing, data brokerage, or certain AI applications.
New Key Privacy Requirements:
- Retail sellers and third-party delivery services generally may not engage in surveillance pricing—aka setting an individualized price based on personal data collected through technologies such as cameras, device tracking, biometric monitoring, or sensors—subject to exceptions for certain discounts, loyalty programs, cost differences, and supply-and-demand pricing. Businesses using a price-setting device to increase prices in certain online transactions must clearly disclose that fact.
- Businesses using facial recognition technology for certain security purposes must limit its use to matching images or video against their own databases and provide clear notice at entrances. Required signage must alert consumers that facial recognition is in use and direct them to a facial recognition policy that includes contact information for the Connecticut Attorney General.
- Direct-to-consumer genetic testing companies face new consent, disclosure, security, access, deletion, and sample-destruction requirements, while consumers gain greater control over their biological samples and genetic testing results. The law also restricts sharing genetic data with employers, insurers, and marketers.
- Controllers subject to the CTDPA—meaning persons who determine the purposes and means of processing personal data—must account for a narrower definition of “publicly available” information and expanded consumer deletion rights covering certain information used to create consumer profiles and inferences drawn from that information.
- Controllers and third parties may no longer sell consumers’ precise geolocation data, meaning data that pinpoints an individual’s location within a radius of 1,750 feet. The law excludes from this definition the content of communications and data generated by or connected to advanced utility metering systems or equipment. For example, smart-meter data used by utilities to automatically record and transmit electricity or gas usage are still allowed under the law.
- Data brokers must register with the Connecticut Department of Consumer Protection before selling or licensing brokered personal data in the state on or after January 1, 2027. Additional deletion-related requirements, including a centralized deletion mechanism and obligations for registered data brokers to process qualifying deletion requests, will take effect in 2028.
AI Requirements Phase in Separately
Connecticut’s new AI requirements follow a timeline different from the privacy changes described above. Beginning January 1, 2027, operators of AI companions must implement safeguards addressing self-harm and violence, prevent AI companions from claiming to be human, and provide clear disclosures when users could reasonably believe they are interacting with a person. Additional protections apply to minors, including restrictions on certain harmful, sexually explicit, and manipulative interactions, as well as tools to manage screen time and account settings.
Employment-related AI is subject to a separate set of deadlines. Beginning October 1, 2026, the use of automated employment-related decision technology is not a defense against certain employment discrimination claims, and evidence of anti-bias testing or similar proactive efforts may be considered. For covered technologies deployed on or after October 1, 2027, deployers—meaning persons doing business in Connecticut who use automated employment-related decision technology in the state—must provide notice to applicants and employees about the technology, its purpose, and the personal data it uses. Also beginning October 1, 2026, employers providing notice to the Connecticut Labor Department under the federal Worker Adjustment and Retraining Notification Act, which generally requires advance notice of certain plant closings and mass layoffs, must disclose whether the layoffs are related to the employer’s use of AI or another technological change.
To discuss how these new requirements may affect your company’s operations or to review updates to your privacy and AI compliance program, please contact one of the authors or any member of McCarter & English’s Cybersecurity and Data Privacy team.
