Most privacy rules give you a way through. You ask the user first. You log the answer. You carry on.
One new rule in the state does not. From 1 October 2026 you may not sell a person's precise location data. Not with consent. Not with a banner. Not at all.
The ban sits in Public Act 26-64. The governor signed it on 27 May 2026. It takes effect in days. Here is what it says, who it catches, and six checks to run first.
The ban with no consent box
Here is the new rule in full. It is one line:
"No controller shall sell any consumer's precise geolocation data."
That is the whole duty. Read it again and look for the escape hatch. There is none.
This is rare, and it is why the rule matters. Location data is on the law's sensitive list. For every other kind, consent is the key. Ask the user, get a yes, and you may process it. For selling this one kind, the lock has no key.
So the usual fix does not work here. A better banner will not help. Nor will a clearer policy page. The only way to comply is to stop.
You are already in scope. That happened in July
This is where most write-ups go wrong. It is worth slowing down.
Two acts changed this law in 2026. They landed three months apart. People treat them as one story. They are not.
| Act | In force | What it did |
|---|---|---|
| Public Act 25-113 | 1 July 2026 | Set who the law covers. Dropped the user count to 35,000 and added two triggers with no number at all. |
| Public Act 26-64 | 1 October 2026 | Added the sale ban, face recognition signs, genetic testing rules, pricing limits and a broker registry. |
So the scope change is already live. It has been since July. There are three ways in now. Any one of them is enough:
- You handled the data of 35,000 state residents or more last year.
- You control or process any sensitive data, at any volume.
- You offer personal data for sale.
Read the second one again. It carries no number. None.
This law treats precise location data as sensitive data. So if your product stores it, you are covered. Ten users or ten million. Your size is not the test. Our piece on the Connecticut health data rules walks through the same trap from the other side.
What counts as a sale
Founders hear "sale" and picture a data broker. They picture an invoice. Most will tell you they do not sell user data. They mean it.
The law uses a wider test. Here it is:
"the exchange of personal data for monetary or other valuable consideration"
Those last four words carry the weight. Money is one kind of value. It is not the only one.
So stop asking whether money moved. Ask what came back to you.
The law does carve out six things. A sale does not include passing data to a processor working for you. It does not include a transfer the user asked for. It does not cover sharing with your own affiliate. It does not cover a hand-off the user set up. Data the user published openly is out. So is a transfer in a merger.
Now look at what is missing from that list. An ad network that takes location and returns ad revenue is not on it. Nor is a free tool you pay for in data rather than cash. Neither of those is named as an exception.
That is the gap most products fall into. You never signed a deal with the word "sale" in it. You still took value for data.
How tight is 1,750 feet
The law is exact about precision. It covers data that locates a person:
"within a radius of one thousand seven hundred fifty feet"
That is about a third of a mile. So here is the practical line:
- In scope. Phone GPS. Map pins. A "near me" search that uses device location.
- Normally outside. A city name. A postcode. A rough guess from an IP address. Those are often miles out.
The radius did not change this year. It has read the same way since the 2025 amendments. Only the sale ban is new.
The ban covers your vendors too
A second line sits alongside the first. It reads:
"No third party shall sell any consumer's precise geolocation data."
So the state closed both ends at once. You may not sell it. Anyone you already handed it to may not sell it either.
Send a note to any partner holding your location data. Their duty starts the same day yours does. They may not have read the act.
Two carve-outs, and what they are not
Each ban carries the same short exception. It does not reach the content of messages. Nor does it reach meter data from a utility.
That is the entire list.
Some summaries claim wider exceptions, for public safety work, fraud checks, or a service the user asked for. Those words are not in either subsection. We looked. Do not build to an exception that is not written down.
The state's own notice is out of date
That office put out a public notice on 16 September 2026. It lists what arrives on 1 October. It is the clearest short summary of the new act anywhere.
One line in it has aged badly. The notice tells readers that the privacy law "includes specific revenue thresholds."
That was true once. It stopped being true on 1 July 2026. The old test caught firms with 25,000 users. They also had to draw a quarter of revenue from selling data. That test was deleted. No revenue test survives.
We flag it because of who it misleads. A founder reads "revenue thresholds". He decides a small product is safely outside. Then he stops reading. The statute says otherwise. Read the statute.
What else arrives on 1 October
The sale ban is one part of a long act. These land the same day.
| Change | What it asks of you |
|---|---|
| Face recognition signs | Using it on your premises for security? Post clear signs at every public entrance. Each sign needs a link or QR code to your policy. The policy must carry the Attorney General's contact details. You may only match against your own database. |
| Genetic testing | Sell tests direct to the public and the customer gains a property right in the sample and the result. Consent is layered: once to collect, and again to share, to reuse, or to keep the sample. |
| "Publicly available" narrowed | Scraped and public no longer means free to use. Combine public data with personal data and the result is regulated data. |
| Profile deletion | Users may now delete profiles built from public data, and anything inferred from them. |
| Pricing from personal data | Raise a price using a person's data and you must label it. The act sets the wording. Shops and delivery services may not do it at all. |
| Broker registry | Sell or license other people's data and you register with the state by 1 January 2027. |
A second act passed the same month covers AI, chatbots aimed at children, and AI in hiring. Its dates are staggered, and the chatbot duties do not start until 1 January 2027. Check the section dates before you plan around it.
Your section numbers move by one
This one is small, dull, and nobody flags it.
The October act adds a new term at number 17. It covers face recognition. Everything below it shifts down a place.
| Definition | Until 30 September | From 1 October |
|---|---|---|
| Precise geolocation data | (28) | (29) |
| Publicly available information | (34) | (35) |
| Sale of personal data | (38) | (39) |
| Sensitive data | (39) | (40) |
If your privacy notice cites a number, check it. If a vendor contract pins a definition by number, check that too. A stale pin cite is a small error. It is also the kind an auditor spots in seconds.
What a scan sees, and what it misses
We should be straight here. Half of the work above is out of our reach.
Our scan reads a live address from the outside. So it is good at one thing that matters here. It sees which third-party scripts your pages load. Those scripts are the usual route out for location. An ad SDK you forgot about will show up.
It cannot read your contracts. It cannot tell whether value came back to you. It cannot see a server feed to a partner, since that never touches the browser. And it cannot judge whether your data is precise enough to count.
So of the six checks below, we help with two. The other four are yours. Those are the ones that decide your answer. Location rows may sit in your database. If so, row level security on those tables is the other half of the job.
Six checks to run before 1 October
- List every place you take location. Mobile SDKs, browser prompts, delivery fields, map widgets, and any address a user types. Write them down. Most teams find one they forgot.
- Check the precision of each. A reading from a device is precise. A city field is not. Only the precise ones are caught.
- Read your contracts for value, not money. Search for revenue share, free tiers paid in data, and tracking deals. Ask what you get back.
- Inventory the scripts your pages load. This is the check we can run for you. Ad and tracking tags are where location quietly leaves.
- Check SDK defaults. Several ad libraries pass location on by default. Turning that off is usually a flag, not a rewrite.
- Fix your section numbers. Update any pin cite in a notice or contract after 1 October.
None of this takes a week. Checks one, two and three take an afternoon. You just need your own code in front of you.
Across 700+ AI-built apps we have audited, the average Launch Readiness Score is 44/100. And 67% had exposed API keys or secrets. A rule about who you sell data to assumes the data is not already walking out the front door. Fix the leak first.
What we are not claiming
We do not know what share of AI-built products sell location data. We do not measure it. So there is no figure here, stated or implied.
We are not your lawyers. Whether a given swap counts as a sale is a judgement call. In places it is a close one. This piece points you at the text. Take it to a lawyer.
We have read the act itself for the sale ban, the definitions and the signage rule. For the genetic testing, pricing and registry sections we have read the act and the state's public notice. A product in those lines should still read the full sections before building.
We could not check every act passed in the 2026 session for a late change to this date. The state has moved a privacy start date before. But it was still publicising 1 October a week ago. So a delay looks unlikely. It is an inference, not a certainty.
This rule sits inside a wider job. Our compliance checklist for AI-built products is the map. And the state privacy law comparison shows which other states ask the same questions.
Frequently asked questions
Can I sell precise geolocation data in Connecticut?
No. From 1 October 2026 the law says no controller shall sell any consumer's precise geolocation data. A second line says no third party may sell it either. The rule has no consent option. So asking the user first does not make the sale lawful. Two exceptions apply. One is the content of messages. The other is meter data from a utility. Some summaries claim a public safety or fraud exception. Neither subsection supports that.
Does the Connecticut location data ban apply to my small SaaS?
Probably, if you hold precise location data at all. Since 1 July 2026 there are three ways the law covers you. Any one is enough. The first is handling the data of 35,000 state residents or more. The second is controlling or processing any sensitive data, and that trigger has no number attached to it. The third is offering personal data for sale. This law treats precise location data as sensitive data. So storing it puts you in scope. Your user count does not matter.
What counts as precise geolocation data under Connecticut law?
Data that locates a person within a radius of 1,750 feet. That is roughly a third of a mile. A reading from a phone normally counts. So does a browser location prompt. So do map pins. A city name is normally too coarse to count. So is a postcode. A rough guess from an IP address is often miles out. The radius itself is not new in 2026. Only the ban on selling is new.
Does sharing location data with an ad network count as a sale?
It can. The law defines a sale broadly. It is the exchange of personal data for monetary or other valuable consideration. Those last words matter most. Money does not have to change hands. Say an ad network gets location data. You get ad revenue or a free service back. Value has flowed to you. Six carve-outs exist. They cover processors working for you, and transfers the user asked for. They also cover your own group firms, data the user published openly, and a merger. An ad revenue arrangement is not named among them.
Can I still collect location data in Connecticut after 1 October 2026?
Yes. The new rule bans selling precise location data. It does not ban collecting or using it. That data is sensitive data. So you still need consent before you process it. Consent means a clear affirmative act. A pre-ticked box will not do. Nor will buried terms. So collecting it with consent is still fine. It is the onward sale that becomes unlawful. And no amount of consent makes that sale lawful again.
Can a user sue me for selling their location data in Connecticut?
No. Only the state can enforce this law. The statute says nothing in it gives the basis for a private right of action. A violation does count as an unfair trade practice. That same office enforces those. The sixty-day window to fix a problem ran out on 31 December 2024. Since then a chance to fix is the regulator's choice. It is not your right.
Research sources
- Public Act 26-64, An Act Concerning Consumer Privacy, Data Brokers, Surveillance Pricing and Genetic Data (Substitute Senate Bill 4), approved 27 May 2026, read directly and the source for every quoted passage here: the controller sale ban at section 14 adding subdivision (3) to section 42-520(a), the parallel third party ban at section 15 adding subdivision (2) to section 42-521(a), the two carve-outs for the content of communications and advanced utility metering infrastructure, the new definition of facial recognition technology inserted at subdivision (17), the facial recognition signage and own-database requirements at section 16, the genetic data property right at section 18, the surveillance pricing section 11, the data broker registry sections 1 to 10 with the 1 January 2027 registration date, the narrowed definition of publicly available information, and the effective date of 1 October 2026 carried by every operative section.
- Conn. Gen. Stat. § 42-515, definitions, the source for the definition of precise geolocation data as accurate within a radius of one thousand seven hundred fifty feet, for precise geolocation data being listed as sensitive data, for the definition of the sale of personal data as an exchange for monetary or other valuable consideration together with its six exclusions, and for the definition of consent as a clear affirmative act that excludes broad terms of use and dark patterns.
- Conn. Gen. Stat. § 42-516, applicability, the source for the three triggers in force since 1 July 2026, namely 35,000 consumers, controlling or processing consumers’ sensitive data, and offering personal data for sale. Its history note is the source for the deletion of the former 25,000-consumer and 25 per cent revenue test, and for that change being made by Public Act 25-113 effective 1 July 2026 rather than by the October 2026 act.
- Conn. Gen. Stat. § 42-520, controllers’ duties, the source for the requirement of consent before processing sensitive data, which is what makes collection of precise location data lawful while its sale is not.
- Conn. Gen. Stat. § 42-525, enforcement by the Attorney General, the source for exclusive enforcement by that office, for the statement that nothing in the Act provides the basis for a private right of action, for a violation constituting an unfair trade practice, and for the cure period having run only to 31 December 2024.
- Connecticut Office of the Attorney General, notice on new and updated privacy laws, 16 September 2026, read in full and the source for the office’s own summary of what takes effect on 1 October 2026, including the ban on the sale of precise geolocation data, the facial recognition signage and policy link, the genetic testing property right, the narrowing of publicly available information, the limits on surveillance pricing, and the data broker registry. It is also the source for the sentence stating that the Act “includes specific revenue thresholds”, which the July 2026 amendments had already removed.
- Public Act 26-15, An Act Concerning Online Safety (Substitute Senate Bill 5), consulted for its section-level effective dates only, and the source for the statement that its chatbot provisions take effect on 1 January 2027 rather than on 1 October 2026.