EnglishEspañol
Connecticut flag

Connecticut

Connecticut Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

Connecticut Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Connecticut have a standalone biometric privacy law like Illinois BIPA?

No. Connecticut protects biometric data through its comprehensive Connecticut Data Privacy Act (CTDPA, Conn. Gen. Stat. 42-515 et seq.) rather than a standalone biometric statute. The CTDPA classifies biometric data as sensitive data, which triggers opt-in consent requirements and other heightened protections. This approach provides broad coverage but does not include a private right of action like Illinois BIPA.

What biometric data does the CTDPA protect?

The CTDPA protects fingerprints, voiceprints, retina scans, iris scans, and other unique biological patterns or characteristics generated by automatic measurements and used to identify a specific individual. As of 2025, the law also covers information derived from biometric data and neural data. Photographs and audio/video recordings are excluded unless they are processed to extract biometric identifiers.

Can I sue a company in Connecticut for misusing my biometric data?

No. The CTDPA does not include a private right of action. Only the Connecticut Attorney General can enforce the law. If you believe a business has violated your biometric privacy rights, you can file a complaint with the AG's office at portal.ct.gov/ag. The AG can pursue civil penalties up to $5,000 per willful violation and seek injunctive relief, restitution, and disgorgement.

Do Connecticut employers need consent to use fingerprint time clocks?

Not under the CTDPA. The law protects consumers, and Conn. Gen. Stat. 42-515(8) excludes individuals acting in an employment context from that definition, while Conn. Gen. Stat. 42-517(b)(15)(A) separately exempts data processed in the course of an individual applying to, employed by, or acting as a contractor of a controller. An employer running a fingerprint time clock on its own workforce is therefore outside the CTDPA, and Connecticut has no standalone biometric law like Illinois BIPA that would supply a consent duty. Conn. Gen. Stat. 31-48d can still require prior written notice of electronic monitoring, and the CTDPA does apply if the same system collects biometric data from customers or visitors.

What happens if a company suffers a data breach involving biometric data in Connecticut?

Connecticut's breach notification law (Conn. Gen. Stat. 36a-701b) requires the entity to notify both the Attorney General and affected residents within 60 days of discovering the breach. The notification must describe the categories of information involved and provide contact details. Failure to comply is a violation of the Connecticut Unfair Trade Practices Act, which carries civil penalties. In 2025, the AG finalized multiple data breach settlements, including a $200,000 penalty against PharMerica for a breach affecting over 100,000 Connecticut residents.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the employer guidance, the state comparison table and the fingerprint time clock FAQ to reflect that the Connecticut Data Privacy Act exempts employee, job applicant and contractor data, and fixed the statutory pin cite for the definition of biometric data.

Updated Connecticut's biometric-privacy applicability thresholds and facial recognition technology rules to match the law now actually in force: the 35,000-consumer/sensitive-data/sale-of-data test under PA 25-113 (effective July 1, 2026), and the on-premises facial recognition database and signage rules under the separate PA 26-64 (not yet effective, October 1, 2026), removing an unsupported staff bias-training claim, a wrong statute citation, a wrong Texas cure-period figure, and outdated references to enacted laws as still-pending bills.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Connecticut Data Privacy Act full statutory text(cga.ct.gov).gov
  2. CT Attorney General CTDPA overview and guidance(portal.ct.gov).gov
  3. PA 22-15 (SB 6) original CTDPA enactment(cga.ct.gov).gov
  4. PA 25-113 (SB 1295) 2025 CTDPA amendments(cga.ct.gov).gov
  5. AG Tong 2025 CTDPA enforcement report(portal.ct.gov).gov
  6. CT AG consumer rights advisory(portal.ct.gov).gov
  7. CT breach notification reporting requirements(portal.ct.gov).gov
  8. SB 1356 (2025) bill status and analysis(cga.ct.gov).gov
  9. Public Act 26-64 (SB 4), approved May 27, 2026, effective October 1, 2026(www.cga.ct.gov)
  10. Conn. Gen. Stat. 31-48d, employer electronic monitoring notice requirement and penalties(www.cga.ct.gov)
Share: