Connecticut's privacy law looks like a law for big firms, and it is not. It names a number: thirty-five thousand users. Most founders see that number and decide they are too small. Then they close the tab.
That is the wrong call if your product touches health data. For health data the number has never applied. The law says so in one sentence. The state's top lawyer says so too, in plain words, in his own report. And since 1 July 2026 the number does not apply to any sensitive data.
Below is the text, the duties, and seven checks you can run this week. One more thing changes on 1 October 2026. That is here too.
Two doors into the same law
The state folded health data into its main privacy law. It did not write a separate one. Washington and Nevada did. That choice is why the size question gets answered wrong so often.
There are two ways in. You need just one.
Door one is the health data door. Section 42-526 holds the health rules. Its second part starts with one word that does the whole job. The word is notwithstanding. The rules apply "notwithstanding section 42-516" to anyone who does business there. They also cover firms that aim a product at people who live there.
Section 42-516 is the size rule. So the sentence means this: ignore the size rule here.
The state's April 2025 report drops the legal grammar. The health rules, it says, "apply to all consumer health data controllers who do business in Connecticut, regardless of their size or the nature of their data processing activities."
Ten users is enough. One is enough.
Door two is new. On 1 July 2026 the size rule changed shape. It used to be one hurdle. You needed 100,000 users. Or 25,000 users plus a quarter of your income from selling data. Now there are three triggers. Any one is enough.
| Trigger | Test |
|---|---|
| Volume | Personal data of not fewer than 35,000 consumers in the prior calendar year, not counting data handled only to complete a payment transaction |
| Sensitive data | You "control or process consumers' sensitive data" — no number attached |
| Sale | You "offer consumers' personal data for sale in trade or commerce" — no number attached |
Health data is sensitive data here. It is named in that list. So a health product walks through both doors at once. The second door is the wider one. It has no number in it at all.
The gap matters. Door one pulls you into the health rules. Door two pulls you into the whole law. That means user rights, notice duties, opt-out handling, and a written risk check as well.
What counts as health data here
The meaning is short. Its shape is the part to read twice. Read it slowly.
Health data means personal data "that a controller uses to identify a consumer's physical or mental health condition, diagnosis or status." The law names two cases. Gender-affirming health data is one. Reproductive or sexual health data is the other. The list does not stop there.
Look at the verb. Uses to identify. The test is not what sits in your database. It is what your code does with it.
A row that reads steps: 8412 is not health data on its own. Feed it into logic that flags a user as sedentary. Now you have used it to work out a health status. The row did not change. Your code did.
Connecticut and Nevada ended up in the same place on this. We walked the same test in our piece on Nevada SB 370. There the wording moved from a noun test to a verb test between the filed bill and the passed one. Washington took a wider route, which we covered in the My Health My Data Act.
The word "status" is worth a note. It was added on 1 July 2026. Before that the line read "condition or diagnosis." A status is looser than a diagnosis. Pregnant is a status. So is in recovery, or trying to conceive. If your product guesses one, you are in scope.
The size limit died in two stages
Dates get muddled here. Here they are in order. Two of them are often reported wrong.
| When | What happened |
|---|---|
| 1 July 2023 | The base privacy law took effect, with the 100,000-user rule |
| 1 October 2023 | Health data rules took effect, with no size rule attached. Not 1 July 2023 — a second act moved the date |
| 31 December 2024 | The mandatory fix-it window closed |
| 1 July 2026 | Size rule rewritten. Any sensitive data now pulls you in, at any size |
| 1 August 2026 | Profiling impact assessments start to apply to new work |
| 1 October 2026 | A further act adds new duties. See below |
Look at the second row. The health rules sat in a 2023 act. That act said 1 July 2023. A later act that same year moved the date to 1 October 2023. It did so before the first one ever bit. Plenty of write-ups still carry the July date. The law's own history note logs the change.
The regulator asked for this, and got it
This part is hard to spot. You have to read the reports next to the law.
In April 2025 the state put out a list of asks for lawmakers. On size rules it wanted two moves. First, drop the number to 35,000. Second, in its own words, "fully remove applicability thresholds for the processing of sensitive data and minors' data."
It got both. The 2025 changes took effect on 1 July 2026. They set the number at 35,000. They added the sensitive data trigger with no number.
The February 2026 report lists the result. It names "Lowered thresholds for applicability." The upshot: "all sensitive data processing and all sales of personal data will be covered under the law."
The office also asked for a wider sensitive data list. It named state ID numbers, transgender or non-binary status, and neural data. All three are on the list now.
Here is why that matters to you. The gap between what this office asks for and what it gets is small. The lag is about a year. Its current asks are public. Treat them as a forecast.
The duty most AI-built products will miss
Your privacy notice now needs a line. It did not exist before 1 July 2026.
Section 42-520 lists what a notice must hold. Part (H) of that list calls for "a statement disclosing whether the controller collects, uses or sells personal data for the purpose of training large language models."
Read it again. The duty is to state whether. Saying no is fine. Saying nothing is not.
The state flags this as a headline change. It calls it a new duty tied to AI. Firms must "disclose whether personal data is used to train large language models."
Most privacy notices on AI-built products were made once, at launch, from a template. That template is older than this line by years. Was yours written before July 2026 and left alone since? Then the line is missing.
Part (I) is the tell. You must print "the most recent month and year during which the controller updated such privacy notice." A stale notice now prints its own age on the page.
The same report has been blunt two years running. The office keeps finding "privacy notices that have not been updated for years." Then it adds a warning. "Companies should consider all privacy notices and public-facing representations to be under review."
Tracking pixels are how this gets found
You might well ask how the state would ever spot a small product.
The answer sits in the April 2025 report. It was not an audit. It was a page load.
The office wrote to two telehealth firms. It said they were "transmitting sensitive health information to third-party platforms, such as Meta and Google." The cause was "tracking technologies marketed by those platforms." One firm then got a cure notice. Its way of getting consent "was insufficient under the CTDPA."
What that firm had to do is the useful part. Per the report, it "implemented an updated user consent process." It "added consumer disclosures specific to Connecticut law." And it ran "a data protection assessment for 'consumer health data'."
Three fixes. None of it needed a lawsuit. All of it began outside the building, by watching what a page sent where.
That route should worry an AI-built product. Tracking snippets get added early and checked never. A page that asks about symptoms and fires a pixel on submit is plain to see. Anyone with a browser can watch it.
See what an outsider can already reach
Before the consent questions comes a blunter one. Is the data locked up at all? Our free scan checks your live product from the outside and returns a Launch Readiness Score out of 100 with the findings behind it.
The written risk check you now owe
Touch sensitive data and you owe a written check. The law calls it a data protection assessment. It lists four kinds of work that carry a high risk of harm. The fourth is simply "the processing of sensitive data."
Health data is sensitive data. So if you touch it, you owe the document.
The check must weigh what you gain against the risk to the person. Count the safeguards you have put in. It must weigh masked data, what users expect, and how you know them.
Two notes. The state can demand it during a probe. You must hand it over. And a check you wrote for a different law can count. It has to be similar in scope and effect. Teams who did the GDPR version of this job may hold most of it already.
A second kind started on 1 August 2026. Do you profile people to drive a machine-made choice with a legal or similar effect? Then you owe its own impact check. It has seven parts. They include how you judge the profiling, and its known limits. It covers only work made on or after that date. It is not backdated.
The HIPAA way out is narrower than it looks
Firms that are covered entities or business associates under HIPAA are carved out. That carve-out is at the firm level. It shows up twice: once in the general list, and again inside the health data section.
Are you truly one of those? Then this law is not your problem. Most health products are not. A symptom tracker is not. Nor is a fertility tool, a fitness product, or a mental wellness tool. None of them are covered entities just because they hold health-shaped data. We walked that line in our piece on HIPAA and AI-built products.
The state has noticed people reaching for the exit anyway. The April 2025 report says telehealth firms "use this HIPAA exemption to avoid having to comply with the CTDPA." And much of the data they handle "is not protected health information."
It asked lawmakers to cut the HIPAA carve-out. The carve-out is still there. But the office tends to get what it asks for. Treat that as a live question, not a settled one.
One way out did narrow on 1 July 2026. Banks and lenders used to get a firm-level pass. Now only the data is out of scope. The firm is not.
Nobody can sue you. That helps less than it sounds
The law is direct here. Nothing in these sections gives anyone "the basis for" a private right of action. The state has "exclusive authority" to enforce.
The state sits with Nevada on that. Washington is the odd one out. Its law routes breaches to a trade practice statute that private plaintiffs can use. Mapping risk across all three? That split is the biggest single gap.
Two things blunt that comfort.
First, breaking these rules counts as an unfair trade practice. That is not a soft label. It is the state's main consumer tool.
Second, the grace period is over. Until 31 December 2024 the office had to send a notice first. It then had to give sixty days to fix things. That duty ran out. Since 1 January 2025 a chance to fix is a choice, not a right. Seven factors decide it. How many breaches there are. How big and complex the firm is. How likely harm to the public is. Whether a human or a machine caused it. And how sensitive the data was.
Being small is on that list. It is a factor, not a shield. And the office is busy. By the end of 2025 it had "issued dozens of notices of violations and warning letters." It had also "resolved its first enforcement action under the CTDPA."
Three states, three shapes
Do you ship to all fifty states? Then you are inside all three. They are not one template with small edits.
| Washington | Nevada | Connecticut | |
|---|---|---|---|
| Standalone law? | Yes | Yes | No — folded into the general privacy law |
| Size rule for health data | None | None | None |
| Private lawsuits | Yes, via trade practice law | No | No |
| Geofence ban radius | 2,000 feet | 1,750 feet | 1,750 feet |
| Written risk check required? | Not on this trigger | Not on this trigger | Yes, sensitive data triggers one |
People assume the geofence rule is not their problem. It is tighter than a blanket location ban. It is also wider than it sounds. The law bars a geofence inside 1,750 feet of a mental health facility. The same goes for a reproductive or sexual health facility. The ban covers three things: using it to spot or track a person, to collect data from them, or to send them any note about their health data.
Ad platforms and location toolkits draw these zones for you. You may have one running that you never drew. Our wider survey of US state privacy laws for AI-built SaaS maps how the rest of the country lines up.
What changes again on 1 October 2026
The state passed another act in May 2026. Most of it lands on 1 October 2026. This piece goes out days before that.
The state set out what is coming in a notice on 16 September 2026. Here are the items a small product is most likely to trip over.
- A ban on selling exact location data. Not an opt-out. A ban.
- Rules on face recognition, including clear signs on the premises and a visible link or QR code to your policy.
- Consent rules for genetic testing sold direct to the public, giving people a property right and sole control over the sample and the result.
- A tighter idea of "publicly available information", plus wider deletion rights over profiles built from it.
- Limits on setting prices from personal data, with duties to tell people.
- A data broker registry. Brokers must sign up with the state by 1 January 2027.
A second act passed the same month. It covers AI, chatbots aimed at children, and AI in hiring and firing. That one needs its own piece and will get one.
The health data rules above are not changed by the October act. Nor are the size rules.
Seven checks you can run this week
None of these need a lawyer. All of them need somebody to look.
- Read your own column names. Open the schema. Flag anything about symptoms, cycles, moods, medication, sleep, weight, fertility or diagnosis. Write the list down.
- Grep for the write-back. Search the code for where a computed health signal gets stored or acted on. A field like
risk_flagorwellness_scorewritten from user input is the verb test in action. - Open your site with the network tab on. Load a page that collects anything health-shaped. Submit it. Watch where the request goes. Does a third-party domain get it? That is the telehealth pattern.
- Check your privacy notice for the language model line. It must say whether you use personal data to train large language models. Yes or no, but say it.
- Check it for a last-updated month and year. That is now required. Its absence is plain from the street.
- Find your written risk check. Do you touch sensitive data with no such document on file? That is the gap. Start from your existing one if you have it.
- Check who can read the health tables. Staff and contractors need a duty of confidence to hold it. Any vendor who touches the data needs a contract. Our note on processor contracts for AI coding tools covers their shape.
Are opt-out signals new to you? The browser-level kind has been required there since 1 January 2025. We covered how they work in the piece on Global Privacy Control.
What our scan can see, and what it cannot
Worth being straight here. The honest answer is mixed, not clean.
Our scan reads a live address from the outside. That makes it good at check three. It is fair at checks four and five. Third-party calls, trackers, exposed keys and missing headers all show up out there.
It cannot answer the question the law asks. Does your code use data to work out a health status? That is a fact about your logic, not your front door. No outside scan sees it. Ours does not either.
So checks one, two, six and seven are yours to run. They decide whether this law hits you. They take an afternoon.
Across 700+ AI-built apps we have audited, the average Launch Readiness Score is 44/100, and 67% had exposed API keys or secrets. Every duty in this law assumes the data is not already leaking. Consent flows do not help if the database is wide open.
What we are not claiming
We do not know what share of AI-built products create health data this way. We do not measure it. So there is no number here, stated or implied.
We are not your lawyers. Does one guess in your code count as working out a health status? That is a judgement call. In places it is a close one. This piece points you at the text and the state's own words. Take those to a lawyer.
We have not read the October 2026 act line by line. The list above follows the state's own public notice of what it does. Read the act before you build to it.
And we have named no numbers for enforcement beyond what the office itself put out.
This law sits inside a wider job. Our compliance checklist for AI-built products is the map, and if you are writing the governing document itself, start with the AI policy guide for SaaS startups.
Frequently asked questions
Does the Connecticut Data Privacy Act apply to my SaaS if I have fewer than 35,000 users?
Maybe. The 35,000-user test is only one of three ways in. Since 1 July 2026 you are also covered if you control or process any consumer's sensitive data, or if you offer personal data for sale. Neither of those has a user number attached. Health data is sensitive data under this law. And the health data rules in section 42-526 have had no size test at all since 1 October 2023.
What counts as consumer health data in Connecticut?
Personal data that you use to work out someone's physical or mental health condition, diagnosis or status. The law names two examples: gender-affirming health data, and reproductive or sexual health data. The list is open. The test turns on what your code does, not on which table the row sits in. A step count is not health data by itself. It becomes health data once you use it to work out a health status.
Can a customer sue me under the Connecticut Data Privacy Act?
No. The statute says nothing in these sections gives the basis for a private right of action. Only the Attorney General can enforce it. Breaking the rules does count as an unfair trade practice. That office enforces those too. The sixty-day window to fix things after a notice ended on 31 December 2024. Since then, a chance to fix is a choice, not a right.
Do I have to say whether I train AI models on personal data?
Yes, if the law covers you. Since 1 July 2026 a Connecticut privacy notice must say whether you collect, use or sell personal data to train large language models. The duty is to say which. Answering no is fine. Saying nothing is not. The same rule makes you print the month and year you last updated the notice.
Am I exempt because of HIPAA?
Only if you really are a covered entity or a business associate under the federal rules. That carve-out sits at the firm level. It shows up twice, once in the general list and again inside the health data section. Most wellness, fitness, fertility and mental health products are neither. So the carve-out does not reach them. The state has named telehealth firms that used it for data which is not protected health information. It has asked lawmakers to cut it.
What do I have to do if I handle consumer health data in Connecticut?
Get consent before you handle it. Get its own consent before you sell it. Give staff and contractors access only under a duty of confidence. Put a proper contract in place with any vendor that touches it. Do not run a geofence within 1,750 feet of a mental health facility or a reproductive or sexual health facility to track people or message them about their health data. Write and keep a data protection assessment. The state can demand it. Answer user requests within 45 days, with one 45-day extension. Run an appeal route that takes 60 days and points to the state.
Research sources
- Conn. Gen. Stat. § 42-526, consumer health data privacy, disclosure, access and geofencing, read in full and the reference for the ban on staff or contractor access without a duty of confidentiality, for the processor access condition, for the geofence prohibition within one thousand seven hundred fifty feet of a mental health facility or a reproductive or sexual health facility, for the bar on selling or offering to sell consumer health data without consent, for the sentence applying these duties “notwithstanding section 42-516” to persons conducting business in the state, and for the entity exemptions including HIPAA covered entities and business associates. Its history note is the source for the effective date moving from 1 July 2023 to 1 October 2023.
- Conn. Gen. Stat. § 42-516, applicability, the source for the superseded 100,000-consumer test and for the three triggers in force since 1 July 2026: 35,000 consumers, controlling or processing consumers’ sensitive data, and offering personal data for sale in trade or commerce.
- Conn. Gen. Stat. § 42-515, definitions, the source for the definition of consumer health data as personal data a controller uses to identify a physical or mental health condition, diagnosis or status, for the addition of the word status on 1 July 2026, and for consumer health data sitting inside the definition of sensitive data.
- Conn. Gen. Stat. § 42-520, controllers’ duties and privacy notice contents, the source for the privacy notice requirement to state whether personal data is collected, used or sold for the purpose of training large language models, for the requirement to publish the month and year the notice was last updated, and for consent before processing sensitive data.
- Conn. Gen. Stat. § 42-522, data protection assessments, the source for the processing of sensitive data being a heightened risk trigger, for what an assessment must weigh, for the Attorney General’s power to demand it, for another law’s assessment counting if similar in scope and effect, and for profiling impact assessments applying to processing created on or after 1 August 2026.
- Conn. Gen. Stat. § 42-525, enforcement by the Attorney General, the source for exclusive enforcement authority, for the statement that nothing provides the basis for a private right of action, for a violation constituting an unfair trade practice, for the cure period running only to 31 December 2024, and for the seven factors weighed from 1 January 2025.
- Conn. Gen. Stat. § 42-518, consumers’ rights and appeals, the source for the 45-day response clock with one 45-day extension, and for the 60-day appeal process that must point the consumer to the Attorney General.
- Connecticut Office of the Attorney General, Updated Enforcement Report under the Connecticut Data Privacy Act, 17 April 2025, read in full and the source for every quoted passage attributed to the office here: that the health provisions apply regardless of size, the two telehealth inquiry letters over tracking technologies and the resulting cure notice and remediation, the observation about telehealth firms invoking the HIPAA exemption, the recommendation to lower the threshold to 35,000 and to remove thresholds for sensitive data entirely, the recommendation to widen the sensitive data definition, and the remarks about privacy notices that have not been updated for years.
- Connecticut Office of the Attorney General, press release on the 2025 enforcement report, 5 February 2026, the source for the summary of the amendments, including lowered thresholds covering all sensitive data processing and all sales of personal data, the broader sensitive data definition, the large language model disclosure requirement, and the statement that by the end of 2025 the office had issued dozens of notices of violations and warning letters and resolved its first enforcement action under the Act.
- Connecticut Office of the Attorney General, notice on new and updated privacy laws, 16 September 2026, the source for everything stated about 1 October 2026: the ban on selling precise geolocation data, the facial recognition signage and policy link requirements, the direct-to-consumer genetic testing consent and property right provisions, the narrowing of publicly available information, the limits on data-driven pricing, and the data broker registry with its 1 January 2027 registration date.
- Connecticut Office of the Attorney General, Connecticut Data Privacy Act FAQ, used only to confirm that the office publishes the 35,000-consumer, sensitive data and sale triggers as the current tests for who the Act covers.