Connecticut
Connecticut Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

Connecticut regulates biometric data under the Connecticut Data Privacy Act (CTDPA, Conn. Gen. Stat. 42-515 et seq.), which classifies biometric identifiers such as fingerprints and voiceprints as sensitive data. Businesses must obtain opt-in consent before collecting biometric data from Connecticut consumers, though employee, job applicant, and contractor data is exempt. Connecticut has no standalone biometric statute like Illinois BIPA.
Connecticut offers some of the strongest biometric privacy protections in the northeastern United States. Rather than enacting a standalone biometric law like Illinois did with BIPA, Connecticut folded biometric data protections into its comprehensive Connecticut Data Privacy Act (CTDPA), signed into law as PA 22-15 on May 10, 2022, and effective since July 1, 2023.
The CTDPA treats biometric data as sensitive data, which triggers a higher standard of protection than ordinary personal data. Any business that collects fingerprints, facial scans, voiceprints, or similar identifiers from Connecticut residents must obtain affirmative consent first.
For broader context on Connecticut's overall privacy framework, see the parent guide to Connecticut Data Privacy Laws.
How the CTDPA Defines Biometric Data
Under Conn. Gen. Stat. 42-515(4), "biometric data" means data generated by automatic measurements of an individual's biological characteristics. The statute lists specific examples:
- Fingerprints collected through scanners or touch-based devices
- Voiceprints captured through voice recognition systems
- Eye retinas and irises scanned for identification
- Other unique biological patterns or characteristics used to identify a specific individual
The definition includes an important carve-out. Photographs, audio recordings, and video recordings do not qualify as biometric data unless they are processed specifically to generate a biometric identifier template. A security camera recording a lobby, for example, is not biometric data. But running that footage through facial recognition software to extract facial geometry measurements would create biometric data subject to the CTDPA.
2025 Expanded Definition
The 2025 amendments to the CTDPA broadened what qualifies as protected biometric information in two significant ways. First, the law now covers "information derived from" biometric data, not just the raw biometric data itself. Second, the legislature added "neural data" as a new category of sensitive data, making Connecticut one of the first states alongside California and Colorado to protect brain-computer interface data.
The amendments also removed the requirement that biometric data must be "processed for the purpose of uniquely identifying an individual" to qualify as sensitive data. Under the updated law, biometric data is sensitive regardless of whether the controller is actively using it for identification.
Who Must Comply
The CTDPA applies to any person who conducts business in Connecticut or produces products or services targeted to Connecticut residents and, during the prior calendar year, met one of these thresholds (effective July 1, 2026, under PA 25-113):
- Controlled or processed the personal data of at least 35,000 consumers (excluding data processed solely for payment transactions),
- Controlled or processed any amount of consumers' sensitive data (which includes biometric data), excluding sensitive data processed solely for payment transactions, or
- Offered consumers' personal data for sale in trade or commerce
These thresholds replace the CTDPA's original 100,000-consumer / 25,000-consumer-plus-25%-revenue test. Because the sensitive-data trigger has no numeric floor, any entity that controls or processes any amount of Connecticut residents' sensitive data (which includes biometric data) must comply with the CTDPA regardless of its size, with the same payment-transaction exception.
This means even small businesses that collect fingerprints for employee time clocks or use facial recognition for building access now fall under the CTDPA if they handle biometric data from Connecticut residents.

Exemptions
The CTDPA exempts certain entities and data types from coverage:
- Government agencies and entities acting on behalf of state or local government
- Nonprofit organizations
- Higher education institutions
- Data protected under HIPAA, GLBA (Gramm-Leach-Bliley Act), and certain other federal frameworks
- Employee, job applicant, contractor, and business-to-business contact data. Conn. Gen. Stat. 42-517(b)(15)(A) exempts data processed in the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, and Conn. Gen. Stat. 42-515(8) excludes individuals acting in a commercial or employment context from the definition of "consumer." PA 25-113 re-enacted the employment exemption without narrowing it.
Consent Requirements for Biometric Data
Because biometric data qualifies as sensitive data, controllers must obtain the consumer's opt-in consent before processing it. This is a higher bar than the standard for ordinary personal data, where controllers need only provide notice and honor opt-out requests.
The consent must be:
- Freely given by the consumer without coercion
- Informed, meaning the consumer understands what biometric data is being collected and how it will be used
- Specific to the biometric processing activity
- Unambiguous, demonstrated through a clear affirmative action
Controllers cannot bury consent in a general terms-of-service agreement. The CTDPA requires that consent for sensitive data processing be separate and distinct from other permissions.
Facial Recognition Technology Requirements
Connecticut's facial-recognition-specific rules do not come from the 2025 amendments. They come from a separate law, Public Act 26-64 (SB 4), signed by Governor Lamont on May 27, 2026. These provisions are not yet in effect; they take effect October 1, 2026. Once in force, a controller that uses facial recognition technology on its premises for security or loss-prevention purposes (to prevent, detect, or respond to security incidents, fraud, or similar illegal activity) must:
- Match only against its own database: the technology may only compare images or video to a database the controller itself maintains, not third-party or public datasets
- Post entrance signage: signage at each premises entrance must alert consumers that facial recognition technology is in use and include a hyperlink or QR code to the controller's facial recognition technology policy, which must name the Attorney General's contact information
PA 26-64 does not require consumer notice, consent, a revocation mechanism, or bias-and-discrimination staff training for facial recognition use; none of those obligations appear in the enacted text. Separately, the Connecticut Attorney General's office has fielded complaints about supermarkets using biometric software for shoplifting detection and stated, in an earlier CTDPA enforcement report, that "businesses that deploy FRT must comply with the CTDPA" with no blanket exception for loss prevention.
Data Protection Assessments
Controllers that process biometric data must conduct data protection assessments (DPAs) before beginning that processing. Under Conn. Gen. Stat. 42-522, a DPA is required for any processing that presents a "heightened risk of harm to a consumer," which explicitly includes processing sensitive data.
Each assessment must weigh the benefits of the processing against the potential risks to consumers, considering:
- The use of de-identified data where possible
- Consumers' reasonable expectations
- The relationship between the processing and the stated purpose
- Any safeguards the controller has implemented
For biometric data used in profiling that produces legal or similarly significant effects, the 2025 amendments require controllers to document data inputs, outputs, performance metrics, and specific safeguards against bias and discrimination.
DPAs must be made available to the Attorney General upon request.
Enforcement and Penalties

The Connecticut Attorney General holds exclusive enforcement authority over the CTDPA. There is no private right of action, which means individuals cannot file lawsuits against businesses for biometric privacy violations.
Enforcement Timeline
The CTDPA's enforcement framework has evolved since the law took effect:
- July 1, 2023 to December 31, 2024: The AG was required to give businesses a 60-day cure period before pursuing enforcement action
- January 1, 2025 onward: The cure period expired. The AG can now pursue immediate enforcement for violations without offering an opportunity to fix them first
Penalties
Violations of the CTDPA are treated as unfair trade practices under the Connecticut Unfair Trade Practices Act (CUTPA, Conn. Gen. Stat. 42-110a et seq.). Penalties include:
- Civil penalties up to $5,000 per willful violation
- Injunctive relief to stop ongoing violations
- Restitution to affected consumers
- Disgorgement of profits gained through violations
2025 Enforcement Activity
Attorney General William Tong released a 2025 enforcement report documenting the office's first full year of active CTDPA enforcement. Key findings include:
- The office issued 63 warning letters and dozens of notices of violations
- Multiple data breach settlements were finalized, including a $200,000 settlement with PharMerica (affecting 105,000 Connecticut residents) and a $200,000 settlement with WebTPA Employer Services
- TicketNetwork paid $85,000 for privacy notice violations including hard-to-read notices and inoperable rights mechanisms
- Active investigations were opened into connected vehicles, social media platforms, gaming platforms, AI chatbots, and data brokers
While the AG's office has not yet announced a biometric-specific enforcement action, the office has made clear that biometric data compliance is a focus area, particularly around facial recognition technology deployment.
Biometric Data and Breach Notification
Connecticut's separate data breach notification statute (Conn. Gen. Stat. 36a-701b) provides an additional layer of protection for biometric data.
Any person who owns, licenses, or maintains computerized data containing personal information must notify the Attorney General and affected Connecticut residents within 60 days of discovering a breach. Connecticut law includes biometric data within its definition of personal information that triggers breach notification requirements.
If a breach involves biometric data, the affected entity must:
- Notify the AG no later than when residents are notified
- Notify affected residents without unreasonable delay and within 60 days
- Describe the categories of information involved in the breach
- Provide contact information for the entity and relevant government agencies
Failure to comply with breach notification requirements constitutes a violation of CUTPA, carrying the same penalty framework as CTDPA violations.
Employer Obligations for Biometric Data
Connecticut employers who run fingerprint time clocks, facial recognition for building access, or palm and hand geometry readers on their own workforce sit outside the CTDPA. The statute protects "consumers," and Conn. Gen. Stat. 42-515(8) defines a consumer as a Connecticut resident while expressly excluding "an individual acting in a commercial or employment context or as an employee, owner, director, officer or contractor of a company" whose dealings with the controller occur solely within that role. Conn. Gen. Stat. 42-517(b)(15)(A) adds a separate exemption for data processed or maintained "in the course of an individual applying to, employed by or acting as an agent or independent contractor of a controller," to the extent the data is collected and used within the context of that role.
Both provisions survived the 2025 amendments. PA 25-113 repealed and re-enacted section 42-517(a) and (b) effective July 1, 2026 and reproduced the employment exemption word for word, and Public Act 26-64 reprints the same "consumer" carve-out. Neither act added a sensitive-data exception to either provision.
The practical consequence is that the CTDPA opt-in consent requirement for biometric data does not reach an employer collecting fingerprints or face scans from its own employees, applicants, or contractors, and Connecticut has no standalone biometric statute like Illinois BIPA to fill that gap. That is why workplace biometric litigation concentrates in Illinois rather than Connecticut.
Requirements that can still apply to a Connecticut employer:
- Electronic monitoring notice. Conn. Gen. Stat. 31-48d requires every employer that engages in electronic monitoring to give prior written notice of the types of monitoring it may conduct, satisfied by a conspicuous posting. Electronic monitoring is defined as collecting information on the employer's premises about employees' activities or communications by any means other than direct observation, so a biometric system that logs when and where employees badge in can fall within it. The Labor Commissioner enforces the section, with civil penalties of $500 for a first offense, $1,000 for a second, and $3,000 for the third and each subsequent offense. There is no private right of action.
- The CTDPA itself, when the same technology is pointed at non-employees. Customers, visitors, and members of the public are consumers, so scanning their faces or fingerprints triggers the full sensitive-data consent rules described above.
- Contractual and collective bargaining obligations, which are governed by other law and sit outside the scope of this page.
Consumer Rights Over Biometric Data

Connecticut residents have several rights regarding their biometric data under the CTDPA:
- Right to know: Consumers can confirm whether a controller is processing their biometric data and access that data. However, under the 2025 amendments, controllers cannot directly disclose the biometric data itself in response to access requests. Instead, they must inform consumers "with sufficient particularity" about what biometric information was collected.
- Right to correct: Consumers can request correction of inaccurate biometric data.
- Right to delete: Consumers can request deletion of their biometric data.
- Right to data portability: Consumers can obtain a copy of their data in a portable format.
- Right to opt out: Consumers can opt out of the sale of biometric data, targeted advertising based on biometric data, and profiling using biometric data.
- Right to revoke consent: Consumers can withdraw previously given consent for biometric data processing. Controllers must stop processing within 15 days of receiving the revocation.
Controllers must respond to consumer rights requests within 45 days, with the possibility of a 45-day extension when reasonably necessary.
Enacted 2026 Legislation Beyond the 2025 Amendments
The Connecticut General Assembly's 2026 session (February 4 to May 6, 2026) enacted Public Act 26-64 (SB 4), signed by Governor Lamont on May 27, 2026, which goes further than the 2025 amendments described above. Its key provisions, effective October 1, 2026:
- Facial recognition technology regulation: defines FRT and imposes the database-matching and signage requirements described above (see "Facial Recognition Technology Requirements")
- Geolocation and biometric data sale restrictions: bans controllers and third parties from selling consumers' precise geolocation data
- Genetic data privacy: adds new requirements for direct-to-consumer genetic testing companies, addressing a gap the AG's office had flagged for separate legislation
The AG's 2025 enforcement report also recommended narrowing the definition of "publicly available information" to strengthen oversight of data brokers who may handle biometric data.
How Connecticut Compares to Other States
Connecticut's biometric privacy framework sits in a middle tier among U.S. states:
| Feature | Connecticut (CTDPA) | Illinois (BIPA) | Texas (CUBI) |
|---|---|---|---|
| Law type | Comprehensive privacy law | Standalone biometric law | Standalone biometric law |
| Private right of action | No | Yes | No |
| Consent required | Yes (opt-in) | Yes (written) | Yes (informed) |
| Penalties | $5,000/violation (CUTPA) | $1,000-$5,000/violation | $25,000/violation |
| Cure period | Expired Dec 2024 | None | None |
| Covers employees | No (employee, applicant and contractor data exempt) | Yes | Yes |
| Data protection assessment | Required | Not required | Not required |
Connecticut's approach of embedding biometric protections within a comprehensive privacy law reaches a wide range of consumer-facing processing that a standalone biometric statute would miss. The trade-off is that it leaves employee biometric data outside the law entirely and gives individuals no private right of action, so enforcement options are narrower than in Illinois.
Disclaimer
This article provides general legal information about Connecticut biometric privacy laws and is not legal advice. Laws and regulations change frequently, and their application varies based on specific circumstances. Consult a qualified attorney licensed in Connecticut for guidance on your particular situation.
More Connecticut Laws
Frequently Asked Questions
Does Connecticut have a standalone biometric privacy law like Illinois BIPA?
No. Connecticut protects biometric data through its comprehensive Connecticut Data Privacy Act (CTDPA, Conn. Gen. Stat. 42-515 et seq.) rather than a standalone biometric statute. The CTDPA classifies biometric data as sensitive data, which triggers opt-in consent requirements and other heightened protections. This approach provides broad coverage but does not include a private right of action like Illinois BIPA.
What biometric data does the CTDPA protect?
The CTDPA protects fingerprints, voiceprints, retina scans, iris scans, and other unique biological patterns or characteristics generated by automatic measurements and used to identify a specific individual. As of 2025, the law also covers information derived from biometric data and neural data. Photographs and audio/video recordings are excluded unless they are processed to extract biometric identifiers.
Can I sue a company in Connecticut for misusing my biometric data?
No. The CTDPA does not include a private right of action. Only the Connecticut Attorney General can enforce the law. If you believe a business has violated your biometric privacy rights, you can file a complaint with the AG's office at portal.ct.gov/ag. The AG can pursue civil penalties up to $5,000 per willful violation and seek injunctive relief, restitution, and disgorgement.
Do Connecticut employers need consent to use fingerprint time clocks?
Not under the CTDPA. The law protects consumers, and Conn. Gen. Stat. 42-515(8) excludes individuals acting in an employment context from that definition, while Conn. Gen. Stat. 42-517(b)(15)(A) separately exempts data processed in the course of an individual applying to, employed by, or acting as a contractor of a controller. An employer running a fingerprint time clock on its own workforce is therefore outside the CTDPA, and Connecticut has no standalone biometric law like Illinois BIPA that would supply a consent duty. Conn. Gen. Stat. 31-48d can still require prior written notice of electronic monitoring, and the CTDPA does apply if the same system collects biometric data from customers or visitors.
What happens if a company suffers a data breach involving biometric data in Connecticut?
Connecticut's breach notification law (Conn. Gen. Stat. 36a-701b) requires the entity to notify both the Attorney General and affected residents within 60 days of discovering the breach. The notification must describe the categories of information involved and provide contact details. Failure to comply is a violation of the Connecticut Unfair Trade Practices Act, which carries civil penalties. In 2025, the AG finalized multiple data breach settlements, including a $200,000 penalty against PharMerica for a breach affecting over 100,000 Connecticut residents.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the employer guidance, the state comparison table and the fingerprint time clock FAQ to reflect that the Connecticut Data Privacy Act exempts employee, job applicant and contractor data, and fixed the statutory pin cite for the definition of biometric data.
Updated Connecticut's biometric-privacy applicability thresholds and facial recognition technology rules to match the law now actually in force: the 35,000-consumer/sensitive-data/sale-of-data test under PA 25-113 (effective July 1, 2026), and the on-premises facial recognition database and signage rules under the separate PA 26-64 (not yet effective, October 1, 2026), removing an unsupported staff bias-training claim, a wrong statute citation, a wrong Texas cure-period figure, and outdated references to enacted laws as still-pending bills.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Connecticut General Statutes, Title 42 (Business, Selling, Trading and Collection Practices), Chapter 743jj
§ 42-520Controllers' duties. Sale of personal data to third parties. Notice and disclosure to consumers. Consumer opt-out.In forcecited in 3 of our articles
(a) A controller shall: (1) Limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer; (2) except as otherwise provided in sections 42-515 to 42-525, inclusive, not process personal data for purposes that are neither reasonably necessary to, nor compatible with, the disclosed purposes for which such personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer's consent; (3) establish, implement and maintain reasonable administrative, technical and physical data security practices to protect the confidentiality, integrity and accessibility of personal data appropriate to the volume and nature of the personal data at issue; (4) not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with COPPA; (5) not process personal data in violation of the laws of this state and federal laws that prohibit unlawful discrimination against consumers; (6) provide an effective…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at cga.ct.gov
Also relied on in: CTDPA Consumer Rights: Exercise Your Connecticut Privacy Rights, CTDPA Compliance Checklist for Businesses (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Connecticut Data Privacy Act full statutory text(cga.ct.gov).gov
- CT Attorney General CTDPA overview and guidance(portal.ct.gov).gov
- PA 22-15 (SB 6) original CTDPA enactment(cga.ct.gov).gov
- PA 25-113 (SB 1295) 2025 CTDPA amendments(cga.ct.gov).gov
- AG Tong 2025 CTDPA enforcement report(portal.ct.gov).gov
- CT AG consumer rights advisory(portal.ct.gov).gov
- CT breach notification reporting requirements(portal.ct.gov).gov
- SB 1356 (2025) bill status and analysis(cga.ct.gov).gov
- Public Act 26-64 (SB 4), approved May 27, 2026, effective October 1, 2026(www.cga.ct.gov)
- Conn. Gen. Stat. 31-48d, employer electronic monitoring notice requirement and penalties(www.cga.ct.gov)