Loading
Home / Get Your Website Ready for CTDPA Compliance

Get Your Website Ready for CTDPA Compliance

Identify cookies and tracking technologies, manage consent choices and support applicable opt-out signals. Okito connects visitor preferences with configured scripts while keeping consent records and privacy settings in one central dashboard.

Get Started
Powering we provide the latest solutions for website privacy compliance
garcia.png
suaryapi.png
blackstate.png
gulbenergen.png
reportage.png
sulax.png (1)
barbertrade.png
naksanyapi.png
byonhotels.png
atlastek.png
nexonya.png
uiduk.png
endemik.png
yediiklim.png
scotty.png
pehlivan.png
mintek.png
ader.png

Practical tools for CTDPA compliance

See what your website collects

Scan your website for cookies, pixels, tags and third-party scripts that may collect or share personal data. Okito organises detected technologies by purpose, provider, category and duration, giving your team a clearer foundation for privacy decisions.

See what your website collects

Turn privacy choices into working controls

Configure consent and opt-out experiences around the way your website uses personal data. Connect visitor choices with relevant technologies, manage optional categories and support recognised privacy preference signals without disrupting the browsing experience.

Turn privacy choices into working controls

Manage settings across your websites

Review scans, consent configurations and visitor preference records through a central dashboard. Okito helps agencies and multi-site teams maintain consistent controls while adapting each website to its own technologies and data practices.

Manage settings across your websites

Build stronger CTDPA privacy controls

Identify cookies and tracking technologies

Website identifiers and browsing data may qualify as personal data when they can be linked or reasonably linked to an individual. Understanding which technologies operate on your website is the first step toward configuring appropriate privacy controls.

  • Scan for cookies, pixels, tags and third-party scripts.

  • Classify technologies by purpose, provider and duration.

  • Review your inventory when vendors or website tools change.

Okito brings detected technologies into a structured dashboard, helping you keep consent settings aligned with your website’s current setup.

Support compliant CTDPA consent management

The CTDPA requires consent before processing sensitive data. Consent should be informed, specific and based on a clear affirmative choice.

  • Present relevant information before requesting consent.

  • Provide separate choices for different optional purposes.

  • Allow visitors to revisit and withdraw their consent.

Sensitive data includes categories such as consumer health information, precise geolocation, biometric or genetic data, neural data and qualifying financial or identification information. Additional restrictions apply to the personal data of minors. Okito supports the consent layer while your organisation determines which legal requirements apply to its processing activities.

Support opt-outs and privacy signals

Connecticut consumers may opt out of personal data sales, targeted advertising and qualifying profiling. Covered controllers must also recognise applicable universal opt-out signals for sales and targeted advertising.

  • Provide clear controls for applicable opt-out rights.

  • Recognise supported signals such as Global Privacy Control.

  • Connect visitor choices with configured cookies and scripts.

Okito helps translate privacy preferences into website-level controls. Each technology should still be assessed according to its actual purpose and use of personal data.

Keep your CTDPA privacy policy up to date

Your CTDPA privacy policy should reflect the personal data, vendors and processing activities used by your website. Changes to plugins, analytics tools or advertising services may require corresponding updates.

  • Maintain records of consent and preference activity.

  • Give visitors access to their current privacy choices.

  • Review disclosures when technologies or purposes change.

Okito keeps detected technologies, consent settings and preference records together, making relevant changes easier to identify. It supports the technical consent and preference layer but does not replace legal review, consumer request procedures or required data protection assessments.

Keep your CTDPA privacy policy up to date

Simplify Your USA Laws CTDPA Compliance Today

1

Scan

Add your website and identify cookies, pixels, trackers and third-party technologies that may collect or share personal data.

2

Configure

Organise detected technologies and create consent, opt-out and preference controls that reflect your website’s actual data practices.

3

Maintain

Roll out automated compliance at scale. From GPC recognition to automated DSAR management, give your clients the ultimate protection against Connecticut’s regulatory landscape.

Please use an email address that is not associated with an existing Okito account.

What is the Connecticut Data Privacy Act?

The Connecticut Data Privacy Act (CTDPA) is a comprehensive state privacy law that took effect on July 1, 2023. It gives Connecticut residents rights over their personal data and establishes obligations for covered controllers and processors.

Changes effective July 1, 2026 expanded the law’s scope and introduced stronger protections for minors under 18. These include restrictions on targeted advertising, data sales, profiling, precise geolocation collection and design features that may encourage excessive use.

Who does the CTDPA apply to?

The CTDPA applies to persons conducting business in Connecticut or targeting products or services to Connecticut residents that meet at least one of these conditions:

  • Control or process personal data belonging to at least 35,000 Connecticut consumers.

  • Control or process consumers’ sensitive data.

  • Offer consumers’ personal data for sale in trade or commerce.

Data processed solely to complete payment transactions is excluded from the first two criteria. Consumer health data controllers can be covered regardless of their size or processing volume, while statutory entity and data-level exemptions must be assessed separately.

What rights do Connecticut consumers have?

Subject to applicable exceptions, Connecticut consumers may:

  • Confirm whether their personal data is being processed and access that data.

  • Correct inaccuracies or request deletion.

  • Obtain eligible personal data in a portable format.

  • Request information about third parties to which their data was sold.

  • Opt out of personal data sales, targeted advertising and qualifying profiling.

  • Appeal a controller’s refusal to act on a privacy request.

Controllers generally must respond within 45 days. This period may be extended by another 45 days when reasonably necessary, provided the consumer is informed of the extension and its reason.

What happens if a business does not comply?

What happens if a business does not comply?

The Connecticut Attorney General has exclusive authority to enforce the CTDPA. Violations may result in civil penalties of up to $5,000 per violation, as well as injunctive relief, restitution or disgorgement under the Connecticut Unfair Trade Practices Act.

The CTDPA does not provide a private right of action. Its general mandatory cure period expired on January 1, 2025, so businesses should not assume they will receive an opportunity to correct a violation before enforcement begins.

FAQ

Frequently Asked Questions CTDPA Compliance

Personal data is information linked or reasonably linkable to an identified or identifiable individual. It can include a name, home address, telephone number, username, device identifier, IP address or online activity associated with a person.

De-identified data and publicly available information are generally excluded from the CTDPA definition.

CTDPA stands for the Connecticut Data Privacy Act. Effective since July 1, 2023, it gives Connecticut residents rights over their personal data and establishes obligations for covered controllers and processors.

Changes effective July 1, 2026 expanded its scope, sensitive data categories and protections for minors. The law is enforced exclusively by the Connecticut Attorney General.

A sale is the exchange of personal data by a controller to a third party for money or other valuable consideration. Connecticut consumers have the right to opt out of these transactions.

Disclosures to a processor acting on the controller’s behalf, transfers to an affiliate and disclosures needed to provide a consumer-requested product or service are not automatically treated as sales. Certain merger, acquisition and consumer-directed transfers are also excluded from the statutory definition.

CTDPA compliance means meeting the obligations that apply to an organisation’s processing of Connecticut consumers’ personal data. Depending on its activities, a covered controller may need to:

  • Publish a clear and accessible privacy notice.

  • Limit data collection to what is reasonably necessary.

  • Obtain consent before processing sensitive data.

  • Provide consumer rights and appeal mechanisms.

  • Support opt-outs for sales, targeted advertising and qualifying profiling.

  • Recognise applicable universal opt-out signals.

  • Implement reasonable security measures.

  • Conduct assessments for processing that presents a heightened risk of harm.

A cookie banner may support part of this process, but it does not establish CTDPA compliance by itself.

The CTDPA contains both entity-level and data-level exemptions. Exempt entities include certain state and local government bodies, financial institutions subject to the Gramm-Leach-Bliley Act, higher education institutions, political committees, insurance entities and qualifying healthcare organisations.

Certain data regulated under laws such as HIPAA, the Fair Credit Reporting Act, the Family Educational Rights and Privacy Act and the Gramm-Leach-Bliley Act may also be excluded. Exemptions are activity-specific in some cases; for example, nonprofits can still be covered when acting as consumer health data controllers.

Subject to applicable exceptions, Connecticut consumers have the right to:

  • Confirm whether their personal data is being processed and access it.

  • Correct inaccurate personal data.

  • Request deletion of personal data.

  • Obtain eligible data in a portable format.

  • Receive information about third parties to which their data was sold.

  • Opt out of personal data sales, targeted advertising and qualifying profiling.

  • Appeal a controller’s refusal to fulfil a request.

Controllers generally must respond within 45 days. A further 45-day extension is permitted when reasonably necessary and properly communicated to the consumer.

The CTDPA does not require every website to display a cookie consent banner. The need for consent or opt-out controls depends on what the website’s cookies and tracking technologies do with personal data.

Consent is required before processing sensitive data. Clear opt-out controls are required when a covered controller sells personal data or uses it for targeted advertising. A consent management platform can support these choices, but the interface must correspond with the website’s actual data-processing activities.

Yes. Since January 1, 2025, covered controllers must recognise applicable opt-out preference signals sent by Connecticut consumers. These signals apply to the sale of personal data and its use for targeted advertising.

Global Privacy Control is a common example. The signal must enable the controller to reasonably determine that the user is a Connecticut resident, and the website’s privacy notice should explain how such signals are handled.