Connecticut has rewritten the rules for companies that buy and sell residents’ personal data, including health-adjacent information, with a new law that took effect October 1. Governor Ned Lamont signed Senate Bill 4, now codified as Public Act 26-64, on May 27, and it layers a formal data broker registration regime on top of the state’s existing comprehensive privacy statute, the Connecticut Data Privacy Act.
What the law actually requires
Under the new act, any company that meets Connecticut’s definition of a data broker, generally a business whose primary revenue comes from collecting and reselling personal data it did not directly collect from consumers through its own products, must register with the state’s Department of Consumer Protection. Registration carries an initial and renewal fee of $2,500, and registered brokers must disclose how they have responded to consumer deletion requests. Brokers are also required to check Connecticut’s state-run centralized deletion platform every 45 days for new requests, a mechanism modeled loosely on California’s Delete Act.
Health and genetic data get specific protections
Alongside the broker registry, Public Act 26-64 adds a ban on selling precise geolocation data and new safeguards specifically covering genetic data, facial recognition and automated license plate readers. Attorneys tracking the law note that these provisions matter for health data in particular: genetic information collected by consumer DNA-testing services or health apps has increasingly been swept up by data brokers and resold to advertisers, insurers and, more recently, companies building AI models that rely on large health datasets. The law does carve out some exemptions, including for publicly available business or professional information and for data sold as part of legitimate health or safety alert services, so long as that data is not collated into a resold consumer profile.
Why Connecticut moved now
Connecticut was already seen as a privacy-forward state, having passed earlier amendments this year requiring health apps to disclose when user data trains AI models and restricting so-called surveillance pricing. Lawmakers who pushed SB 4 said the missing piece was accountability for the data brokers themselves, companies that often operate behind the scenes, aggregating information from apps, retailers and public records before selling profiles to third parties with little visibility for the consumers whose data is involved. The timeline is staggered: the broker-registration requirement doesn’t become fully active until January 1, 2027, giving the Department of Consumer Protection time to stand up its registry system, even though the rest of the October 1 provisions, including the geolocation sales ban, are already enforceable.
Industry pushback versus consumer advocates
Trade groups representing data and advertising companies have argued publicly that Connecticut’s registration fee and 45-day deletion-platform check-ins add meaningful compliance overhead for firms that already register in California, Oregon, Texas and Vermont, each of which has its own broker law with different thresholds and deadlines. Privacy advocates counter that fragmentation is the point: without a national standard, they argue, state-level registries are the only mechanism currently forcing brokers who traffic in health and location data to identify themselves publicly at all. Legal commentary from firms like Fox Rothschild and WSGR has noted that Connecticut’s version is notably broader than its 2023 original broker statute, closing what privacy lawyers described as loopholes that let some data resellers avoid registering entirely.
What it means for the AI data pipeline
The practical effect for health-data-dependent AI developers is that Connecticut now joins a small but growing list of states making it harder for health information to move anonymously from app to broker to buyer. Companies building AI models trained on consumer health signals, including wearable data, prescription histories and search behavior tied to medical conditions, will need to confirm whether their data suppliers are registered brokers under Connecticut’s definition, and brokers themselves must now decide whether to continue serving Connecticut residents under the new disclosure burden or exit the market.
What’s next
The Department of Consumer Protection is expected to publish registration guidance before the January 2027 deadline, and privacy lawyers expect a wave of compliance questions from mid-sized data firms uncertain whether they meet the broker threshold. Enforcement authority rests with the state attorney general, and Connecticut’s Combined privacy statute already allows for civil penalties, meaning the real test of the law will come once the first broker fails to register and the state decides how aggressively to pursue it.
Photo: TheDigitalArtist / PIXABAY via Pixabay