Connecticut has joined a growing group of states imposing new obligations on data brokers, but its newly enacted consumer privacy law goes beyond California’s pioneering Delete Act in several key areas, creating additional compliance challenges for companies that buy, sell or license consumer data.
The law, signed by Connecticut Gov. Ned Lamont on May 27, establishes a regulatory framework that closely resembles California’s data broker regime, including mandatory registration requirements and the eventual creation of a centralized consumer deletion mechanism. However, according to an analysis by Davis+Gilbert, Connecticut’s law extends farther than California’s in several areas, including restrictions on surveillance pricing, protections related to automated decision-making, and limits on the sale of precise geolocation data.
The statute takes effect Oct. 1, 2026. Data broker registration requirements begin Jan. 1, 2027, while the state’s centralized deletion mechanism is scheduled to launch by July 1, 2028.
Like California’s Delete Act, Connecticut requires data brokers to register with state regulators and participate in a centralized process allowing consumers to request deletion of personal information from multiple brokers through a single submission. Connecticut’s system will require registered brokers to access the deletion platform at least every 45 days and honor verified deletion requests.
Despite these similarities, the two states define “data broker” differently, Davis+Gilbert cautions.
WHAT’S NEXT IN ANTITRUST AND TECHNOLOGY REGULATION™
California’s Delete Act applies to businesses that knowingly collect and sell personal information about consumers with whom they do not have a direct relationship. Connecticut instead focuses on the sale or licensing of specifically defined categories of “brokered personal data,” including information such as names, addresses, dates of birth, Social Security numbers and biometric data. The different definitions could bring different businesses within the scope of each law.
The registration requirements also differ. Connecticut requires registration with the Department of Consumer Protection and imposes a $2,500 annual fee. California requires registration with the California Privacy Protection Agency and charges a $6,000 annual fee. California additionally requires disclosures about whether data has been shared with foreign actors, law enforcement agencies, generative AI developers or the federal government.
Read more: Lawmakers Urge Trump To Close Loopholes in Biden-Era Data Protections
The states also diverge in how they administer their deletion systems. California’s Delete Request and Opt-Out Platform, known as DROP, became operational in January 2026 and is governed by detailed regulations addressing technical issues such as hashing, matching and processing timelines. Connecticut’s mechanism will not be operational until mid-2028 and will rely on verification using a consumer’s driver’s license number.
Perhaps the most significant distinction is that Connecticut’s law reaches well beyond traditional data broker regulation.
The statute prohibits certain forms of “surveillance pricing,” preventing retailers and third-party delivery services from using personal data collected through tracking technologies to establish individualized prices. Businesses that use online price-setting tools must disclose when personal data contributed to a price increase.
Connecticut also strengthens consumer rights involving profiling and automated decision-making. Consumers gain rights to challenge profiling outcomes, obtain explanations regarding decisions, review data used in decision-making processes and, in some housing-related contexts, seek correction and reevaluation. According to the analysis, these provisions exceed protections currently available under California’s privacy framework.
Other Connecticut provisions include a right to obtain a list of third parties that purchased their data and an outright prohibition on the sale of precise geolocation information.
For businesses operating nationally, Davis+Gilbert recommends beginning compliance planning now. Companies should first determine whether their activities qualify them as data brokers under Connecticut’s distinct definition, particularly businesses involved in data licensing, lead generation, people-search services or marketing data operations.
The firm also advises companies to evaluate dynamic pricing systems for potential surveillance-pricing risks, prepare operational capabilities needed to interact with Connecticut’s future deletion mechanism, and develop coordinated multi-state compliance programs. Despite the substantial overlap between the two state regimes, differences in definitions, registration requirements, fees and exemptions mean California compliance alone will not satisfy Connecticut’s new obligations. Businesses are also advised to monitor forthcoming Connecticut rulemakings, which are expected to provide important operational details and could significantly affect compliance requirements.