If your business collects health data, biometric scans, or government ID numbers from even a handful of Connecticut residents, a law that took effect on July 1, 2026, may have just pulled you into one of the country's strictest data privacy regimes — regardless of how small you are.
The Connecticut Data Privacy Act (CTDPA) has been on the books since 2023, but the amendments that landed this July rewrote the rules in three ways that matter enormously to small and mid-sized businesses: the size threshold for coverage dropped, the definition of "sensitive data" grew to include neural data, and every business using AI on customer information now has to say so in plain language. Businesses that assumed CTDPA was a "big company problem" need to recheck that assumption this week.
Why This Law Now Applies to Businesses That Used to Be Exempt
The original CTDPA only applied to entities that processed the personal data of 100,000 or more Connecticut consumers, or 25,000 consumers if the business derived more than 25% of revenue from selling data. That threshold effectively exempted most small businesses.
The 2026 amendment throws that safe harbor out. As of July 1, 2026, the CTDPA now applies to any entity conducting business in Connecticut that meets any one of these three conditions:
- Processed personal data of 35,000 or more consumers in a calendar year (down from 100,000), excluding data processed solely to complete a payment transaction
- Processed any amount of sensitive data, no matter how few consumers — even one
- Offered personal data for sale, in any volume
That second trigger is the one catching small businesses off guard. There is no floor. A five-person medical billing service, a boutique fitness studio that stores health screening forms, or a local staffing agency running background checks with government ID numbers can trigger CTDPA obligations even if they serve a few hundred Connecticut clients total.
What Counts as "Sensitive Data" Now — Including Neural Data
The amendment substantially widened the sensitive-data category that triggers coverage regardless of volume. It now includes:
- Racial or ethnic origin, religious beliefs, and health conditions or diagnoses
- Sexual orientation and gender identity
- Citizenship or immigration status
- Neural data — signals from a person's brain or nervous system, including data collected by consumer neurotech devices like EEG headbands, meditation wearables, or brain-computer interfaces
- Biometric data (fingerprints, voiceprints, facial geometry) and genetic data
- Precise geolocation
- Government-issued identification numbers
- Financial account numbers and login credentials
- Personal data of a known minor age 13–17
- Status as a victim of a crime
Neural data is the headline-grabbing addition, and Connecticut is one of the first states to explicitly regulate it as sensitive personal data. If your product touches wellness tech, meditation apps, focus-tracking wearables, or any brain-computer interface, you're squarely in scope. But don't skip past the more mundane categories — health conditions, government IDs, and financial credentials show up constantly in ordinary small-business recordkeeping (employee I-9s, client intake forms, insurance paperwork), which is exactly why the "any amount" trigger matters so much.
The New AI and LLM Training Disclosure Mandate
Separately from the sensitive-data expansion, the amendment adds a disclosure requirement aimed squarely at the AI boom. Privacy notices must now state, in a conspicuous and disability-accessible way, whether the business uses consumers' personal data to:
- Train large language models or other AI systems
- Build profiles used for automated decision-making
- Support targeted advertising
This applies even if your "AI" usage is limited to feeding customer support transcripts into a fine-tuning pipeline or using a third-party AI tool that trains on the data you upload to it. If you don't know whether your CRM, chatbot vendor, or analytics platform trains models on your customers' data, this is the moment to find out — your privacy notice has to answer that question whether or not you've asked it internally.
Consumers also gained new rights under the amendment: the right to opt out of profiling used for decisions with legal or similarly significant effects (credit, employment, housing, insurance, healthcare), the right to request an explanation of an automated decision, and the right to obtain a list of the specific third parties that received their data — a stricter standard than simply naming categories of recipients.
Other Operational Changes to Know
Profiling impact assessments. Businesses that use profiling for legally significant decisions must complete a documented impact assessment for any such processing generated after August 1, 2026. This isn't a checkbox exercise — regulators expect a written record of the risks considered and mitigations applied.
Minors' protections tightened further. Targeted advertising to, and the sale of data belonging to, anyone age 13–17 is now flatly prohibited — consent doesn't cure it. The amendment also restricts "engagement-maximizing" design features (infinite scroll, autoplay, streaks, and similar mechanics) aimed at minors.
The 60-day cure period is gone. Under the original CTDPA, businesses caught out of compliance had a guaranteed 60 days to fix the problem before the Attorney General could pursue penalties. That guarantee expired, and enforcement is no longer required to give you a warning shot. The Connecticut AG has already issued at least one public penalty (an $85,000 settlement over a deficient privacy notice) under the pre-amendment law, and the amended law's broader scope plus the loss of the cure period means more businesses are exposed to that kind of action with less room to fix mistakes quietly.
Penalties. Civil penalties run up to $5,000 per willful violation and up to $2,500 per non-willful violation, assessed per violation — which can add up quickly across a customer base, a set of vendor contracts, or a multi-page privacy notice with several deficiencies.
A Practical Compliance Checklist for Small Businesses
You don't need a compliance department to get the basics right. Work through these steps:
- Inventory what you actually collect. List every category of personal data you touch — customer records, employee files, vendor W-9s, intake forms, wearable or app data. Flag anything that falls into the expanded sensitive-data list, especially health, government ID, financial credential, or (if relevant to your product) neural data.
- Count your Connecticut footprint. Even if you're nowhere near 35,000 consumers, check whether you process any sensitive data or sell any personal data — either trigger applies with no minimum volume.
- Audit your AI and vendor stack. Ask every SaaS tool, chatbot, and analytics vendor you use whether customer data you send them trains their models. Get the answer in writing; you'll need it to write an accurate disclosure.
- Update your privacy notice. Add a conspicuous, accessible statement about AI/LLM training, profiling, and targeted advertising use — don't bury it in dense legal boilerplate that could itself trigger a deficiency claim like Connecticut's prior $85,000 settlement.
- Build an opt-out and explanation process. You need a real, working mechanism for consumers to opt out of profiling for significant decisions and to request an explanation — not just a sentence promising one exists.
- Document your profiling impact assessments if you use automated decision-making for credit, employment, insurance, healthcare, or housing-related outcomes.
- Review any minor-facing features. If teens use your product, remove targeted ads and data-sale exposure for that age group entirely, and reconsider engagement mechanics aimed at them.
Connecticut isn't acting alone — Indiana, Kentucky, and Rhode Island brought new comprehensive privacy laws online for 2026 as well, and neural data and AI-training disclosures are showing up in other states' amendments too. If you operate across state lines, treat Connecticut's list as a preview of where compliance expectations are heading nationally, not a one-off local quirk.
Keep Your Compliance Trail as Clear as Your Books
Privacy compliance and financial recordkeeping share the same underlying discipline: know exactly what data you're collecting, why, and who touches it. Beancount.io brings that same clarity to your finances with plain-text accounting — transparent, version-controlled records with no black boxes and no vendor lock-in. Get started for free and keep your financial data as auditable as your privacy practices need to be.