Connecticut General Statutes, Chapter 743jj – Data Privacy and Security
- Document
- 1 July 2023
- Event
- 1 July 2023
- Retrieved
- 16 September 2026
The workload
Connecticut's privacy act requires two separate applicability checks, not one: a general test for ordinary personal data, and a stricter, separate test for anything counting as consumer health data. Verified: the state's own codified General Statutes, Chapter 743jj, Section 42-516, enacted by Public Act 22-15 and effective 1 July 2023, applies the general test to a business that controlled or processed the personal data of not less than one hundred thousand consumers, or not less than twenty-five thousand consumers while deriving more than twenty-five per cent of gross revenue from selling personal data. That threshold text has not been amended since 2022; the workload it creates is counting Connecticut consumers and, where relevant, the share of revenue tied to data sales.
What the documents show
Verified: Public Act 23-56, approved 26 June 2023 and effective 1 July 2023, added a new section applying its consumer-health-data provisions notwithstanding section 42-516 — the general threshold section — to any person conducting business in the state, with no consumer count or revenue figure attached. The Attorney General's own CTDPA guidance confirms there are no revenue or processing thresholds a consumer-health-data controller must meet. That same guidance describes the general threshold as “at least 35,000 consumers,” a lower figure than the 100,000 the codified statute itself states — a founder should rely on the statute's own wording over the summary where the two disagree.
The operating cost
The statute sets no filing fee; its cost is enforcement exposure. Verified: Section 42-525 gives the Attorney General exclusive enforcement authority and required a mandatory 60-day notice-and-cure period for violations between 1 July 2023 and 31 December 2024 for general violations, and between 1 October 2023 and 31 December 2024 for consumer-health-data violations — a guaranteed opportunity to fix a violation before any penalty attaches, but only inside that window.
The stop condition
The statute names its own stop condition: beginning 1 January 2025, the mandatory cure period ends, and the Attorney General's authority to offer a chance to cure becomes discretionary, weighed against factors including violation count, business size, and the sensitivity of the data involved.
- Does the business meet the general 100,000-or-25,000-plus-25%-revenue threshold, independent of any lower figure a summary page states?
- Does any product touch consumer health data, which carries no threshold at all under Public Act 23-56?
- Since 1 January 2025, is a compliance gap being caught before an Attorney General notice, given that curing it is no longer guaranteed?
Connecticut kept its general numeric threshold unchanged in 2023 and instead carved out an entire category — consumer health data — that answers to no threshold at all.
Sources & reading trail
States the current codified general applicability threshold: 100,000 consumers, or 25,000 consumers plus 25% of revenue from data sales.
Source published: Not established · Retrieved: 16 September 2026
Original enactment of the general threshold text, approved 10 May 2022, effective 1 July 2023.
Source published: 10 May 2022 · Retrieved: 16 September 2026
Adds the no-threshold consumer-health-data controller category and the mandatory cure-period enforcement schedule.
Source published: 26 June 2023 · Retrieved: 16 September 2026
States there are no thresholds for consumer-health-data controllers, and separately gives a 35,000-consumer figure that differs from the codified statute's 100,000.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.