Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

Connecticut's CTDPA Just Got a Lot Bigger — And Fintechs May Not Know They're Covered

Connecticut's CTDPA expanded on July 1, 2026 — lower thresholds, narrowed GLBA exemption, eliminated cure period, new profiling impact assessments. Here's what fintechs and nonbank lenders need to do now.

By Rebecca Leung · July 16, 2026 ·
Table of Contents

TL;DR

  • Connecticut’s CTDPA expanded on July 1, 2026: applicability threshold dropped to 35,000 residents, with additional triggers for sensitive data processing and data sales regardless of volume
  • The entity-level GLBA exemption is gone for most fintechs and nonbank lenders — replaced by a data-level exemption that leaves significant data exposure
  • A profiling impact assessment requirement kicks in August 1 for new automated systems affecting credit decisions, fraud flags, or personalized pricing
  • Connecticut eliminated the 60-day cure period — the AG can proceed directly to enforcement action without first giving you a window to fix the problem

If you run compliance for a fintech or nonbank lender and haven’t reviewed Connecticut’s data privacy law since 2023, you’re operating blind. The Connecticut Data Privacy Act — CTDPA — is no longer the law you knew.

On July 1, 2026, sweeping amendments took effect that changed who the law applies to, what exemptions remain, and how fast the Attorney General can move when something goes wrong. If your legal team is still treating this like a 2022 law with a comfortable GLBA carveout, you have a compliance gap — and Connecticut has a no-warning enforcement window to find it.

Here’s what changed and what you need to address before August 1.


What Changed on July 1

Lower Thresholds — With New Volume-Free Triggers

The original CTDPA applied to controllers that processed personal data of at least 100,000 Connecticut residents per year. The July 1 amendments cut that threshold nearly in half. More significantly, they added two new triggers that have no volume minimum at all.

The CTDPA now applies if, during the prior calendar year, your organization:

  1. Controlled or processed the personal data of at least 35,000 Connecticut consumers (down from 100,000), excluding data processed solely to complete a payment transaction; OR
  2. Controlled or processed consumers’ sensitive data — regardless of volume, excluding payment-transaction-only data; OR
  3. Offered consumers’ personal data for sale in trade or commerce — regardless of volume

Those second and third triggers are where the law picks up entities that previously weren’t paying attention. An organization that sells one Connecticut resident’s email address or profile data for marketing purposes — regardless of how small the operation — potentially triggers CTDPA applicability. A fintech that processes financial account data of even a handful of Connecticut residents is processing “sensitive data” (financial account information is now on the sensitive data list) with no volume minimum.

If your company buys, sells, or shares consumer data with third-party data brokers, marketing platforms, or analytics vendors, run the volume-free triggers before assuming you’re out of scope.


The GLBA Exemption Changed — And Fintechs Are the Losers

This is the change most financial services compliance teams missed, because it’s buried in language that sounds similar to prior law.

Under the original CTDPA: The GLBA entity-level exemption meant that if your institution was a “financial institution” subject to GLBA, the entire organization was generally exempt from the CTDPA. It didn’t matter what type of data you were processing — the exemption covered you as an entity.

Under the July 1 amendments: Connecticut replaced the entity-level GLBA exemption with a data-level exemption. The exemption now applies only to data that is regulated under GLBA — not to the organization as a whole.

This shift follows the erosion pattern tracked across multiple states. As we covered in how state privacy laws are narrowing GLBA’s safe harbor and the GLBA erosion in sensitive data treatment, California, Oregon, and Colorado had already moved in this direction. Connecticut just joined that group.

What that means practically for a bank: A bank collects data from customers for GLBA-covered financial products and services — that data gets data-level protection. But the same bank’s marketing analytics, website behavioral tracking from visitors who never became customers, or employee data from third-party HR platforms? Connecticut looks at that data separately. If it doesn’t fall within GLBA’s scope, the CTDPA applies to it.

Fintechs face a different problem. Many fintech companies are not “financial institutions” under GLBA in the first place — they’re technology vendors, data aggregators, payment facilitators, or service providers to GLBA-covered institutions. The entity-level exemptions Connecticut added to replace the GLBA blanket are narrow. They cover banks, credit unions, insurers, certain health carriers, and registered broker-dealers and investment advisers. That list doesn’t include:

  • Nonbank mortgage servicers and originators
  • Earned wage access (EWA) providers
  • Buy now, pay later (BNPL) lenders
  • Payments processors that are not chartered banks
  • Third-party administrators for financial institutions
  • Data aggregators and open banking platforms

For these entities, Connecticut’s CTDPA now applies to all personal data they handle outside GLBA’s specific coverage — and “outside GLBA” covers a lot of ground.

Compare this to Rhode Island, which we covered in RIDTPPA at six months. Rhode Island kept entity-level exemptions for clearly GLBA-covered institutions, making it more protective for traditional financial institutions. Connecticut’s approach is more aggressive and the fintech exposure is real.


Sensitive Data — Financial Account Information Is on the List Now

The amendments significantly expanded what qualifies as “sensitive data” under the CTDPA. Sensitive data requires opt-in consent before processing (with limited exceptions) and triggers applicability at any volume.

Sensitive data under the amended CTDPA now includes:

  • Financial account information — this is new and important for financial services
  • Social Security numbers and government-issued identifiers
  • Consumer health data
  • Precise geolocation data
  • Neural data
  • Biometric data used for unique identification
  • Personal data of known children under 13
  • Data revealing race, ethnicity, religious beliefs, sexual orientation, or citizenship/immigration status

The addition of financial account information to the sensitive data list has direct implications for fintechs, data aggregators, and open banking platforms. If you process bank account numbers, routing numbers, credit card numbers, investment account data, or payment history data from Connecticut residents — even in a B2B context where you serve the bank rather than the consumer directly — you are processing sensitive data. The volume threshold doesn’t apply. One Connecticut resident’s account data flowing through your platform puts you in scope.

Data mapping is not optional here. You need to know where Connecticut resident financial data lives in your systems, who it flows to, and whether you’re processing it outside the scope of a clear GLBA relationship.


The Profiling Impact Assessment: Two Weeks to Get Ready

Connecticut’s amendments introduced a formal impact assessment obligation for profiling. If profiling produces a “legal or similarly significant effect” on a consumer, an assessment is required before the activity goes live.

The August 1, 2026 trigger applies to profiling activities created or generated on or after that date. Activities built before August 1 are not permanently grandfathered — they’ll need assessments as systems are updated or materially modified.

What counts as a legal or similarly significant effect:

  • Financing, credit, or billing decisions
  • Fraud detection that suspends or restricts access to services
  • Dynamic pricing or personalized offers based on consumer profiling
  • Employment, housing, or insurance decisions made through automated profiling

For financial services firms — where automated underwriting, behavioral fraud scoring, and risk-based pricing are core operations — this requirement is directly on point. Any model or algorithm that processes Connecticut resident data to make one of these decisions, and that you’re building or modifying now, needs a completed impact assessment before it goes live.

The assessment must document:

  1. The purpose of the profiling activity
  2. A risk analysis
  3. Categories of personal data used as inputs
  4. Performance metrics for the profiling system
  5. Transparency measures in place
  6. Post-deployment monitoring plans

This overlaps substantially with SR 26-2 model validation documentation and with CFPB adverse action notice requirements for automated credit decisions — firms that already have strong model governance infrastructure have a head start. Those that don’t should treat the August 1 trigger as an accelerant.

The data privacy KRI program covers the metrics you’ll want tracking once these assessments are in place.


No More Cure Period

Under the original CTDPA, the Attorney General was required to provide a 60-day notice-and-cure period before pursuing enforcement action. That window gave businesses a chance to fix problems after being identified.

That window is eliminated.

The July 1 amendments removed the guaranteed cure period. The AG now has full discretion whether to offer businesses time to remediate before pursuing penalties. For violations involving sensitive data, willful conduct, or harm to minors, the AG is unlikely to be generous.

Civil penalties under the amended CTDPA:

  • $2,500 per non-willful violation
  • $5,000 per willful violation
  • The statute doesn’t cap aggregate penalties — regulators with aggressive enforcement postures can run up the total fast when violations are counted per affected consumer

State AG enforcement activity in the fintech space has been accelerating, as covered in state AG and CFPB enforcement trends for fintechs. Connecticut’s AG has been active on consumer protection generally, and data privacy is a natural enforcement priority given the statutory changes. The elimination of the cure period removes the safety net.

If you have been relying on the cure period as the backstop between a compliance gap and meaningful exposure, that backstop no longer exists.


What to Do Now

Before August 1 (two weeks):

1. Re-run your applicability analysis. Pull your existing CTDPA coverage memo and stress-test it against the three new triggers. If you serve Connecticut residents and you process financial account data, or you sell any data, you may be newly in scope regardless of how you scored before.

2. Map your GLBA exemption at the data level. Identify specifically which data you process falls within GLBA-regulated products and services. Marketing prospect data, employee files, third-party HR vendor feeds, website analytics, and data from visitors who aren’t customers are common areas that fall outside GLBA’s scope.

3. Inventory profiling systems. Identify every automated system that makes financing, credit, fraud, or pricing decisions affecting Connecticut residents. Flag which systems are being built or modified now — those need impact assessments before they go live.

4. Start impact assessment drafts. For systems with August 1 exposure, begin the documentation process now. The six elements required (purpose, risk analysis, data categories, performance metrics, transparency measures, monitoring plans) take time to assemble.

Within 30 days:

5. Update vendor contracts. Data processing agreements with processors handling Connecticut resident sensitive data need to address CTDPA requirements. Review DPAs for CTDPA-specific provisions and update where missing.

6. Build the third-party data sale disclosure. Connecticut consumers now have the right to request a list of third parties to whom their data was sold. Your consumer rights infrastructure needs to support this specific request type.

7. Brief compliance leadership. The elimination of the cure period changes the risk calculus on Connecticut data privacy compliance. This isn’t an update that can sit in queue — it’s a risk profile change that the CCO and general counsel need to understand.


So What?

Connecticut just created a category of “newly in scope” entities who had been ignoring the CTDPA entirely: fintechs, nonbank lenders, EWA providers, BNPL operators, data aggregators. If your GLBA exemption analysis hasn’t been updated since before July 1, 2026, it’s wrong.

The law is already in effect. The August 1 profiling assessment trigger is two weeks away. The AG can now move immediately without giving you time to fix it.

Run the applicability triggers. Map the GLBA exemption at the data level. Get the impact assessments in motion. The time to find out you’re covered is before the AG does.


Building or updating your data privacy compliance program? The Data Privacy Compliance Kit ($69) includes data inventory templates, processing agreement language, consumer rights workflows, and privacy impact assessment frameworks — mapped to current state law requirements including the Connecticut CTDPA.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

When did the Connecticut CTDPA amendments take effect?
The substantive amendments took effect July 1, 2026. A separate trigger applies to the new profiling impact assessment requirement: it covers profiling activities created or generated on or after August 1, 2026.
Does the GLBA exemption still protect my fintech from the CTDPA?
Probably not fully. Connecticut replaced the entity-level GLBA exemption with a data-level exemption. Fintechs, nonbank mortgage servicers, EWA providers, and BNPL lenders that process personal data outside GLBA's scope must now comply with the CTDPA for that data. The entity-level exemptions that replaced the GLBA blanket are narrow: banks, credit unions, insurers, registered broker-dealers, and investment advisers.
What is the new applicability threshold under the Connecticut CTDPA?
As of July 1, 2026, the CTDPA applies if you: (1) control or process personal data of at least 35,000 Connecticut residents (down from 100,000), excluding data processed solely to complete a payment transaction; OR (2) control or process consumers' sensitive data regardless of volume, excluding payment-transaction-only data; OR (3) offer consumers' personal data for sale regardless of volume.
What counts as sensitive data under the amended CTDPA?
Sensitive data now includes financial account information (new), Social Security numbers and government-issued identifiers, consumer health data, precise geolocation, neural data, biometric data used for unique identification, and data of known children under 13.
What are the penalties for CTDPA violations?
The Connecticut Attorney General can seek civil penalties of up to $5,000 per willful violation and $2,500 per non-willful violation. The guaranteed 60-day cure period has been eliminated — the AG now has full discretion whether to give businesses time to fix violations before pursuing penalties.
What is the profiling impact assessment requirement?
Effective for activities created or generated on or after August 1, 2026, businesses must complete a profiling impact assessment before engaging in profiling that produces legal or similarly significant effects — including financing and credit decisions, fraud detection that suspends service, and dynamic pricing based on profiling. The assessment must document purpose, risk analysis, data categories, performance metrics, transparency measures, and post-deployment monitoring plans.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.