September 9, 2026
Connecticut’s new data broker requirements are approaching their first major implementation date.
Beginning October 1, 2026, provisions of Connecticut’s new privacy legislation affecting data brokers and other businesses begin taking effect. On September 16, Connecticut Attorney General William Tong issued a reminder to businesses and consumers about the state’s new and updated privacy requirements, specifically highlighting the creation of Connecticut’s data broker registry and the upcoming registration deadline.
For organizations that sell or license consumer information, the message is increasingly clear: Connecticut should now be part of the organization’s data broker compliance review.
What Has Happened Since Connecticut Enacted Its Data Broker Law?
Connecticut enacted Public Act 26-64 in May 2026. The legislation established a new data broker framework, including registration requirements and a future centralized consumer deletion mechanism administered through the Connecticut Department of Consumer Protection.
Shortly afterward, Connecticut enacted Public Act 26-100, which amended portions of PA 26-64, including provisions governing the state’s accessible deletion mechanism. PA 26-100 was signed by Governor Ned Lamont on June 2, 2026.
As organizations prepare for the October effective date, the operative framework therefore needs to be evaluated based on PA 26-64 as subsequently amended, rather than relying solely on the originally enacted version of PA 26-64.
October 1 Is the First Major Date.
Many provisions of Connecticut’s new framework become effective October 1, 2026.
The state’s September 16 announcement specifically called attention to several new privacy requirements becoming effective in October, including the new data broker framework. The Attorney General also reminded businesses that data brokers will be required to register with the Connecticut Department of Consumer Protection by January 1, 2027.
For potentially covered organizations, this makes the period between now and January particularly important for determining whether the registration requirement applies.
Connecticut’s Data Broker Registry.
Connecticut’s framework establishes a registration system administered by the Department of Consumer Protection.
The law generally addresses businesses, or portions of businesses, that sell or license brokered personal data to another person, subject to the statute’s definitions, exclusions, and exemptions. Determining whether a particular organization qualifies therefore requires reviewing the statutory framework against the organization’s actual activities.
This distinction matters because an organization does not have to market or describe itself as a “data broker” for the law to warrant review.
Businesses engaged in the commercial sale or licensing of consumer information should therefore consider whether Connecticut’s new requirements affect their operations before the registration deadline arrives.
The Centralized Deletion Program Is Still Coming.
Registration is only one component of Connecticut’s data broker framework.
Connecticut also requires the Department of Consumer Protection to establish an accessible deletion mechanism no later than July 1, 2028. The mechanism is intended to allow consumers to submit deletion requests affecting registered data brokers, subject to statutory requirements and exceptions.
Public Act 26-100 revised portions of the original deletion-mechanism provisions. This is one reason businesses relying on an early summary of PA 26-64 should confirm that their compliance analysis reflects the amended framework.
The longer implementation schedule does not mean the deletion requirements should be ignored. Rather, Connecticut is establishing a framework in stages, beginning with the law’s October 2026 effective date and the upcoming registration requirements.
Compliance Will Extend Beyond Registration.
Connecticut’s framework is designed to develop beyond an initial registration filing.
For example, the enacted legislation establishes future public reporting associated with deletion requests. PA 26-64 provides for disclosures beginning by July 1, 2029, and annually thereafter, concerning specified deletion-request activity for businesses that were registered data brokers during the preceding calendar year.
The amended framework also contains later requirements associated with assessing compliance with portions of the deletion program.
For businesses, the larger point is that Connecticut data broker compliance should not be viewed simply as a one-time registration exercise.
What Should Businesses Be Asking Now?
With October 1 approaching and registration following in January, organizations involved in selling or licensing consumer information should determine whether Connecticut’s data broker framework warrants further review.
That review should begin with the threshold issue: Does Connecticut’s definition apply to the organization’s activities?
If the answer may be yes, the organization can then determine which requirements and implementation dates apply.
For businesses operating nationally, Connecticut should also be considered alongside other state data broker regimes rather than treated as an isolated requirement. Definitions, exemptions, registration requirements, consumer rights, and other obligations can differ significantly among states.
Why This Matters for Multi-State Compliance.
Connecticut’s new framework adds to an increasingly state-specific data broker compliance environment.
An organization operating across multiple jurisdictions may face different requirements depending on where it operates, whose information it handles, what it does with that information, and how the applicable state statute defines regulated activity.
That makes a single “data broker/not a data broker” determination increasingly inadequate for organizations operating nationally.
Instead, applicability may need to be evaluated against the requirements of each relevant state.
CLIClaw Data Broker Compliance Solutions.
Knowing that Connecticut has enacted a data broker law is only the beginning.
Organizations still need to determine whether the law applies to their activities, understand which requirements affect them, and determine what compliance actions may be necessary.
CLIClaw‘s Data Broker Compliance Solutions provide subscribers with practical materials for evaluating state-specific data broker requirements and preparing for applicable obligations.
Current Connecticut materials include:
-
Connecticut Data Broker Quick Self-Assessment
-
Connecticut Data Broker Law — At-a-Glance
-
Connecticut Data Broker Law
Explore Data Broker Compliance Solutions →
Final Thoughts.
Connecticut’s October 1 effective date and January 1, 2027 registration deadline make this an appropriate time for businesses involved in selling or licensing consumer information to determine whether the state’s new data broker requirements affect them.
The September guidance from the Connecticut Attorney General reinforces that these requirements are moving from legislation toward implementation.
Organizations should avoid assuming that an earlier data broker analysis performed for California or another state answers the Connecticut question. Connecticut has its own statutory framework, definitions, exemptions, requirements, and implementation schedule.
For potentially covered businesses, the immediate task is straightforward: determine whether Connecticut requires closer review before the registration deadline arrives.
© 2026 CLIClaw.com
This article is for information purposes only. It is not intended to be and should not be relied on as legal advice for any particular matter.