Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Committee hears competing views on update to Connecticut Data Privacy Act; advocates push stricter limits on data collection
Summary
Connecticut's General Law Committee heard extensive testimony on a proposed update to the state's data privacy law that would narrow data collection allowed under privacy policies and expand definitions of sensitive data.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Connecticut's General Law Committee heard extensive testimony on Senate Bill 13 56, a proposed update to the Connecticut Data Privacy Act (CTDPA) that would revise data-minimization rules, change definitions of sensitive data, and adjust age- and knowledge-related standards for children’s online protections.
Privacy advocates urged a stricter approach. Katrina Fitzgerald of the Electronic Privacy Information Center told lawmakers that the current law allows too broad data collection because companies can simply list broad purposes in privacy policies. "The privacy policy could simply say that they're gonna collect and use my data for marketing purposes, which tells me nothing," Fitzgerald said in testimony, urging a Maryland-style standard that limits collection to what is reasonably necessary to provide the product or service the consumer requested.
Consumer Reports and other advocates pressed the committee to couple stronger minimization rules with clearer prohibitions on sales of sensitive data (health, biometric, precise geolocation, reproductive information and so on). "We support updating the CTDPA to match Maryland's baseline restriction on sensitive data collection and an explicit ban on the sale of sensitive data," Consumer Reports analyst Matt Schwartz said in written comments.
Industry witnesses and trade groups called for more precise statutory language and cautioned against changes that could force intrusive age- or identity-verification practices. Eric Noll of the Center for Democracy and Technology warned the committee that a poorly written "knowledge" standard could incentivize privacy-invasive age assurance systems; he urged that the bill avoid standards that would compel companies to collect extra personal data to determine user age.
Business groups also cautioned about operational costs and urged clear, consistent definitions. The State Privacy and Security Coalition testified that some proposed changes to biometric definitions and a move away from a long-used data-minimization baseline could create confusion and undue burdens for firms that already comply with the CTDPA.
Committee members asked technical questions about the proposed knowledge standard (actual knowledge versus constructive knowledge) and how the law should treat "publicly available" information and aggregated consumer profiles. Several lawmakers referenced the Attorney General’s earlier enforcement report, which noted that many complaints were blocked by the current public-availability exemption in CTDPA and recommended clarifying language to reduce enforcement gaps.
What happens next: The committee said it will continue drafting work and consult with the Attorney General's office and privacy stakeholders to harmonize the knowledge standard, tighten definitions for sensitive data, and craft exemptions or practical compliance support for small businesses.
Background: CTDPA, passed in 2022, was one of the early state-level consumer privacy laws. SB 13 56 seeks to close gaps identified by the Attorney General in enforcement and to align the state law with recent developments in other states such as Maryland and Massachusetts.

