Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy topic

No spam. Unsubscribe anytime.

Committee approves updates to state data privacy, children’s online safety and consumer-protection measures

2730381 · March 21, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The General Law Committee advanced changes to data privacy and children’s online-safety laws, lowering the compliance threshold for covered entities and expanding the definition of sensitive data while asking for more work to limit burdens on small businesses.

The General Law Committee on March 21 approved a multipart package of bills and amendments updating Connecticut’s data privacy and online-protection laws and adding new consumer-protection measures.

Key changes in the data privacy package include: lowering the company-size threshold for coverage, expanding the definition of sensitive data, excluding certain industry exemptions, and creating a registry for data brokers. The proposal would also add a new consumer right to see a list of companies to which a consumer’s data has been sold.

Representative Lamar, summarizing the package, said earlier exemptions had allowed some entities to avoid enforcement and that the attorney general’s enforcement report suggested updates were needed. The proposal reduces the compliance threshold from 100,000 to 35,000 residents for covered entities, with a zero threshold for firms that sell sensitive data, and removes nonprofit exemptions in some cases. The bill also tightened the definition of sensitive data to explicitly include biometric and neural information, government-issued identifiers and certain financial-account information.

The committee also considered a companion children’s-privacy bill that would require social platforms to create safety pages with mental‑health and anti‑cyberbullying resources, refine the legal standard for when a service “knows” a user is a minor, require algorithmic‑impact and data‑protection assessments where services create heightened risk of harm to minors, and default certain safety tools to “on.” Representative discussion emphasized the difficulty of age verification and the choice to use a knowledge standard that includes “actual knowledge and knowledge fairly implied based on objective circumstances.”

Lawmakers acknowledged tension between consumer protections and burdens on small businesses. Several representatives asked whether small vendors — for example, a local business using Shopify or other website builders — would face new compliance burdens; sponsors said most vendors already provide privacy features or plugins and that owner protections were included if a website builder acted without the merchant’s knowledge.

Procedure and votes

- SB 13‑56 (data privacy and online monitoring): The committee moved the bill to JFS to the floor after debate. Committee members recorded individual roll-call votes; some members recorded no votes to flag outstanding concerns about the lowered threshold and government coverage.

- SB 12‑95 (children’s online safety / social media): Committee voted to add the bill to the consent calendar with further work requested.

- SB 3 and related consumer-safety items were also advanced for floor consideration.

Why it matters

Sponsors said the changes are intended to close loopholes, protect sensitive personal data (including financial identifiers and biometric data), and give consumers more transparency about where their data travels. Representatives and some members of the committee said they will continue to refine elements to reduce burdens on small businesses and make clear how government data use and public-records law will interact with the privacy protections.

Next steps

The bills were advanced to the floor for further action. Committee leadership and members pledged ongoing negotiations on the compliance threshold and on which privacy rights can be applied to state records without conflicting with Freedom of Information law.