Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy topic

No spam. Unsubscribe anytime.

Advocates and industry debate updates to Connecticut Data Privacy Act; key fixes proposed for data minimization and sensitive data

2412363 · February 26, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A separate public hearing covered Senate Bill 1356, proposed changes to the Connecticut Data Privacy Act. Consumer advocates pushed to tighten data‑minimization and to ban sale of sensitive data; industry groups asked for narrower definitions and predictable enforcement regimes for small businesses.

Lawmakers and witnesses at a General Law Committee hearing considered Senate Bill 13 56, a set of proposed updates to the Connecticut Data Privacy Act (CTDPA). The bill would tighten data‑minimization rules, update the definition of sensitive personal data and narrow certain entity‑level exemptions.

Privacy advocates including EPIC and Consumer Reports urged the committee to adopt a stricter “reasonably necessary” standard that would limit the collection of personal data to what is required to deliver a specific product or service. Katrina Fitzgerald of EPIC and Matt Schwartz of Consumer Reports pointed to Maryland’s 2024 law as a stronger model, recommending Connecticut adopt similar limits and consider a ban on the sale of sensitive categories of data.

Industry and business groups raised counterpoints. Representatives of the State Privacy and Security Coalition and other business coalitions warned that some proposed changes — notably expanded definitions of biometric or sensitive data and a lower threshold for covered entities — could create compliance burdens for small businesses and lead to uncertain rulemaking costs.

Speakers asked the committee to standardize the knowledge/age standard across the bill to avoid forcing platforms into invasive age‑verification techniques. The Center for Democracy and Technology and other civil‑society groups urged careful drafting to avoid incentives for risky age‑assurance technologies while still protecting children’s privacy.

Committee members asked for additional technical edits, and advocates offered to provide redlines. No vote was taken; the committee said it would continue technical discussions and asked the attorney general’s office and stakeholder groups to propose model language for data‑minimization, sensitive data bans and consistent knowledge standards.