Skip to content

Connecticut Workplace Compliance
News & Resources

Business moves differently in Connecticut. From Hartford and New Haven to advanced manufacturing facilities, healthcare organizations, financial services firms, and distribution centers across the state, employers face a unique mix of workplace challenges. To succeed in the Constitution State, businesses need resilience, adaptability, and a strong commitment to keeping their people safe.

That commitment includes navigating Connecticut’s workforce laws and regulations. Employers must stay current on requirements related to workplace safety, wage and hour compliance, paid leave, discrimination and harassment prevention, employee privacy, and other employment obligations. Falling out of compliance can result in costly fines, litigation, and reputational risk. Learn what you need to know to protect your employees and stay compliant with Connecticut law.

Stay on top of safety and compliance the right way with this Connecticut-specific information, but be sure to seek legal counsel when evaluating how these regulations may directly impact your business. Wherever available, KPA products are updated with the latest government notices and posters for employers.

Connecticut HR News

Connecticut Data Privacy Act Amendments Expand Coverage and Consumer Rights

Who: Connecticut employers

When: Effective immediately

Connecticut enacted SB 1295 on June 24, 2025, which amends the Connecticut Data Privacy Act (CTDPA), with most changes effective July 1, 2026, and new impact-assessment requirements effective August 1, 2026.

The amendments substantially lower the law’s applicability thresholds. The CTDPA previously applied only to businesses processing the personal data of at least 100,000 Connecticut residents or 25,000 residents where 25% or more of revenue came from data sales. As amended, the law also applies to any business processing at least 35,000 residents’ personal data, or to any business, regardless of size, that processes consumers’ sensitive data or sell personal data at all. The amendment replaces the blanket entity-level exemption for Gramm-Leach-Bliley Act–regulated entities with a narrower data-level exemption.

The amended law expands the definition of “sensitive data” to include neural data, nonbinary and transgender status, additional biometric and genetic data, government-issued identification numbers, and financial account information. Covered entities may longer sell sensitive data without consumer consent.

Consumers gain expanded rights, including the right to a list of third parties to whom their data has been sold, access to inferences drawn from their data, and new rights concerning automated profiling. They have an expanded profiling opt-out that no longer requires the decision to be based solely on automated processing, and, in housing-related decisions, the ability to correct inaccurate data and request a re-evaluation. Minors under 18 are also prohibited from having their personal data shared for targeted advertising or sales.

Businesses engaged in covered profiling must now conduct impact assessments. Privacy notices must also disclose covered entities use personal data to train large language models, and they must notify consumers before material retroactive changes to a privacy notice take effect.

The CTDPA’s statutory cure period, which previously allowed businesses an opportunity to correct violations before enforcement, expired at the end of 2024 and has not been reinstated.

How:

  • Review your internal governance practices and policies to ensure compliance.
  • Ensure that your privacy notices are up to date.

Additional Resources

SB 1295

Back To Top