Connecticut Data Privacy Act, Minor Protections (SB 3 / Public Act 23-56, amended by SB 1295) ↗
The minor online-safety provisions added to the Connecticut Data Privacy Act by Public Act 23-56 took effect 2024-10-01 (the social-media account unpublish/delete duty began 2024-07-01). SB 1295 (signed 2025-06-24, effective 2026-07-01) tightened them into a categorical ban on targeted advertising and sale of minors' data and a bar on engagement-extending design features. No known court challenge as of 2026-07-04.
Primary Public Act 23-56 PDF verified (HTTP 200; the server presents an incomplete TLS chain, though a February 2026 archive.org snapshot corroborates it, so confirm in the US-based CI link check). Effective dates verified via multiple law-firm analyses (Wilmer, FPF, Hunton, Inside Privacy). SB 1295 (signed 2025-06-24, effective 2026-07-01) is folded in here as the operative amendment rather than a separate record; its public-act chapter number and codified section pins still need a primary-text pass. The categorical targeted-ad/sale ban and lowered CTDPA thresholds are from law-firm reporting on SB 1295. No civil-penalty amount or private right of action beyond AG/CUTPA enforcement is asserted.
Scope
The minor provisions bind a controller under the Connecticut Data Privacy Act offering an online service, product, or feature to consumers the controller has actual knowledge of, or willfully disregards, are minors (under 18).
- Coverage of the base CTDPA turns on processing thresholds, which SB 1295 lowered to 35,000 Connecticut consumers; the minor provisions apply on the actual-knowledge/willful-disregard trigger.
Penalties
- Model
- Other
- Detail
- A violation is enforced by the Attorney General as an unfair trade practice under the Connecticut Unfair Trade Practices Act; the CTDPA's cure period narrowed over time. No civil-penalty amount is verified here for the minor provisions.
- Enforcer
- Connecticut Attorney General (exclusive)
- Private right of action
- No
Key dates
- Signed
- 2023-06-26
- Effective
- 2024-10-01
Obligations (2)
Use reasonable care to avoid any heightened risk of harm to minors caused by an online service, product, or feature, and conduct a data protection assessment for any such service that presents a heightened risk of harm to minors.
Statute’s own ages: Applies to minors (consumers under 18); no narrower statutory subdivision for this duty.
Do not process a minor's personal data for targeted advertising or for sale (a categorical ban after SB 1295), restrict profiling and secondary uses, limit precise-geolocation collection, and do not use a system design feature to significantly increase, sustain, or extend a minor's use of the service.
Statute’s own ages: Applies to minors under 18; SB 1295 made the targeted-advertising and sale limits categorical rather than consent-based.
Cross-state comparisons
- similarco-sb24-041 (Colorado): Close cousin: both graft a minor-safety regime onto a comprehensive state privacy act using an actual-knowledge/willful-disregard trigger, a reasonable-care duty against heightened risk of harm, data protection assessments, and a bar on system-design features that extend minors' use.
- similarne-lb504 (Nebraska): Overlapping duties on minor data minimization and engagement-extending design features, though Nebraska's LB 504 is a standalone Age-Appropriate Design Code and Connecticut's are amendments to its comprehensive privacy act.