Add your website and identify cookies, pixels, trackers and third-party technologies that may collect or share personal data.
Get Your Website Ready for CTDPA Compliance
Identify cookies and tracking technologies, manage consent choices and support applicable opt-out signals. Okito connects visitor preferences with configured scripts while keeping consent records and privacy settings in one central dashboard.
Practical tools for CTDPA compliance
See what your website collects
Scan your website for cookies, pixels, tags and third-party scripts that may collect or share personal data. Okito organises detected technologies by purpose, provider, category and duration, giving your team a clearer foundation for privacy decisions.
Turn privacy choices into working controls
Configure consent and opt-out experiences around the way your website uses personal data. Connect visitor choices with relevant technologies, manage optional categories and support recognised privacy preference signals without disrupting the browsing experience.
Manage settings across your websites
Review scans, consent configurations and visitor preference records through a central dashboard. Okito helps agencies and multi-site teams maintain consistent controls while adapting each website to its own technologies and data practices.
Build stronger CTDPA privacy controls
Identify cookies and tracking technologies
Website identifiers and browsing data may qualify as personal data when they can be linked or reasonably linked to an individual. Understanding which technologies operate on your website is the first step toward configuring appropriate privacy controls.
Scan for cookies, pixels, tags and third-party scripts.
Classify technologies by purpose, provider and duration.
Review your inventory when vendors or website tools change.
Okito brings detected technologies into a structured dashboard, helping you keep consent settings aligned with your website’s current setup.
Support compliant CTDPA consent management
The CTDPA requires consent before processing sensitive data. Consent should be informed, specific and based on a clear affirmative choice.
Present relevant information before requesting consent.
Provide separate choices for different optional purposes.
Allow visitors to revisit and withdraw their consent.
Sensitive data includes categories such as consumer health information, precise geolocation, biometric or genetic data, neural data and qualifying financial or identification information. Additional restrictions apply to the personal data of minors. Okito supports the consent layer while your organisation determines which legal requirements apply to its processing activities.
Support opt-outs and privacy signals
Connecticut consumers may opt out of personal data sales, targeted advertising and qualifying profiling. Covered controllers must also recognise applicable universal opt-out signals for sales and targeted advertising.
Provide clear controls for applicable opt-out rights.
Recognise supported signals such as Global Privacy Control.
Connect visitor choices with configured cookies and scripts.
Okito helps translate privacy preferences into website-level controls. Each technology should still be assessed according to its actual purpose and use of personal data.
Keep your CTDPA privacy policy up to date
Your CTDPA privacy policy should reflect the personal data, vendors and processing activities used by your website. Changes to plugins, analytics tools or advertising services may require corresponding updates.
Maintain records of consent and preference activity.
Give visitors access to their current privacy choices.
Review disclosures when technologies or purposes change.
Okito keeps detected technologies, consent settings and preference records together, making relevant changes easier to identify. It supports the technical consent and preference layer but does not replace legal review, consumer request procedures or required data protection assessments.
Simplify Your USA Laws CTDPA Compliance Today
Frequently Asked Questions CTDPA Compliance
Personal data is information linked or reasonably linkable to an identified or identifiable individual. It can include a name, home address, telephone number, username, device identifier, IP address or online activity associated with a person.
De-identified data and publicly available information are generally excluded from the CTDPA definition.
CTDPA stands for the Connecticut Data Privacy Act. Effective since July 1, 2023, it gives Connecticut residents rights over their personal data and establishes obligations for covered controllers and processors.
Changes effective July 1, 2026 expanded its scope, sensitive data categories and protections for minors. The law is enforced exclusively by the Connecticut Attorney General.
A sale is the exchange of personal data by a controller to a third party for money or other valuable consideration. Connecticut consumers have the right to opt out of these transactions.
Disclosures to a processor acting on the controller’s behalf, transfers to an affiliate and disclosures needed to provide a consumer-requested product or service are not automatically treated as sales. Certain merger, acquisition and consumer-directed transfers are also excluded from the statutory definition.
CTDPA compliance means meeting the obligations that apply to an organisation’s processing of Connecticut consumers’ personal data. Depending on its activities, a covered controller may need to:
Publish a clear and accessible privacy notice.
Limit data collection to what is reasonably necessary.
Obtain consent before processing sensitive data.
Provide consumer rights and appeal mechanisms.
Support opt-outs for sales, targeted advertising and qualifying profiling.
Recognise applicable universal opt-out signals.
Implement reasonable security measures.
Conduct assessments for processing that presents a heightened risk of harm.
A cookie banner may support part of this process, but it does not establish CTDPA compliance by itself.
The CTDPA contains both entity-level and data-level exemptions. Exempt entities include certain state and local government bodies, financial institutions subject to the Gramm-Leach-Bliley Act, higher education institutions, political committees, insurance entities and qualifying healthcare organisations.
Certain data regulated under laws such as HIPAA, the Fair Credit Reporting Act, the Family Educational Rights and Privacy Act and the Gramm-Leach-Bliley Act may also be excluded. Exemptions are activity-specific in some cases; for example, nonprofits can still be covered when acting as consumer health data controllers.
Subject to applicable exceptions, Connecticut consumers have the right to:
Confirm whether their personal data is being processed and access it.
Correct inaccurate personal data.
Request deletion of personal data.
Obtain eligible data in a portable format.
Receive information about third parties to which their data was sold.
Opt out of personal data sales, targeted advertising and qualifying profiling.
Appeal a controller’s refusal to fulfil a request.
Controllers generally must respond within 45 days. A further 45-day extension is permitted when reasonably necessary and properly communicated to the consumer.
The CTDPA does not require every website to display a cookie consent banner. The need for consent or opt-out controls depends on what the website’s cookies and tracking technologies do with personal data.
Consent is required before processing sensitive data. Clear opt-out controls are required when a covered controller sells personal data or uses it for targeted advertising. A consent management platform can support these choices, but the interface must correspond with the website’s actual data-processing activities.
Yes. Since January 1, 2025, covered controllers must recognise applicable opt-out preference signals sent by Connecticut consumers. These signals apply to the sale of personal data and its use for targeted advertising.
Global Privacy Control is a common example. The signal must enable the controller to reasonably determine that the user is a Connecticut resident, and the website’s privacy notice should explain how such signals are handled.
Türkçe
English