Connecticut was the fourth state to pass a comprehensive privacy law, and it did so with a definition of 'consumer' that matters directly to any site running visitor identification. This page sets out the Connecticut Data Privacy Act itself, why purely business-to-business contact data sits outside its scope, and what that means in practice for teams selling into the state's insurance, manufacturing and life-sciences buyers.
At a glance
- Framework
- Connecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. §42-515 et seq. (Public Act 22-15), effective 1 July 2023, amended by SB 3
- Supervision
- Connecticut Attorney General exclusively; discretionary cure period since the mandatory 60-day cure sunset on 31 December 2024
- Usual legal basis
- Legitimate business purpose; identification stays at company level and the CTDPA excludes commercial or employment-context data entirely
- Processing location
- ISO-certified EU data centres
The Connecticut Data Privacy Act
Regulation at a glance
- FrameworkConnecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. §42-515 et seq. (Public Act 22-15), effective 1 July 2023, amended by SB 3
- SupervisionConnecticut Attorney General exclusively; discretionary cure period since the mandatory 60-day cure sunset on 31 December 2024
- Usual legal basisLegitimate business purpose; identification stays at company level and the CTDPA excludes commercial or employment-context data entirely
- Processing locationISO-certified EU data centres
The CTDPA, formally Conn. Gen. Stat. §42-515 et seq. and originally enacted as Public Act 22-15, took effect on 1 July 2023 and was subsequently amended by SB 3, which tightened obligations around minors' data and broadened certain consent requirements. It applies to businesses that either control or process the personal data of 100,000 or more Connecticut consumers in a calendar year, excluding data processed solely to complete a payment transaction, or that control or process the data of 25,000 or more consumers while deriving over 25 percent of gross revenue from selling personal data. Many mid-sized B2B websites never approach either threshold on the consumer-facing side of their business at all.
Enforcement rests exclusively with the Connecticut Attorney General; there is no private right of action, so an individual consumer cannot sue directly under the statute. For its first eighteen months the CTDPA offered violators a mandatory 60-day cure period before an enforcement action could proceed, but that cure right sunset on 31 December 2024. Since then, the Attorney General has discretion whether to offer a cure opportunity at all, which raises the practical stakes of getting notice and disclosure right from the outset rather than treating a first warning letter as a formality.
From 1 January 2025, the CTDPA also requires controllers to recognise universal opt-out signals — mechanisms like browser or device-level preference signals that communicate a consumer's choice to opt out of targeted advertising and the sale of personal data across every site they visit, rather than site by site. Controllers whose processing presents a heightened risk of harm must also conduct and document data protection assessments, a discipline that surfaces regularly in vendor due diligence even for companies well under the statute's applicability thresholds.
Why B2B contact data sits outside the CTDPA
The CTDPA defines a 'consumer' as a Connecticut resident acting only in an individual or household context, and it expressly excludes a person acting in a commercial or employment context — for example, an employee, contractor or agent of a business communicating in that capacity. That is a materially different scope from California, where the CCPA/CPRA's temporary business-to-business and employee exemptions expired on 1 January 2023, bringing B2B contact data fully under the statute. In Connecticut, a purely B2B relationship — a procurement manager's work email exchanged with a vendor, for instance — generally never falls inside the CTDPA's definition of protected consumer data in the first place.
That distinction matters for how a Hartford-based insurer or a New Haven pharma supplier frames its own vendor review, since the CTDPA question and the practical privacy-hygiene question are not the same thing. A legal team may still ask about data minimisation, retention and security as a matter of internal policy or contractual obligation to its own customers, even where the CTDPA itself would not reach the activity, and a vendor should be prepared to answer both the narrow statutory question and the broader operational one.
Draw a third, separate distinction on top of that: lead.box resolves the organisation behind a website visit — a company name, industry and size band inferred from network-level signals — not a named individual. That places company-level identification a step further removed from the CTDPA's consumer definition even before the B2B exclusion is considered, but it is a different question from personal-data scope and should be explained to a reviewer as such rather than conflated with it.
Start free
Install the snippet and see the first named companies on your own traffic.
The federal picture
This state page sits inside the wider United States market page, which covers the federal layer, cross-border transfers and the documentation a US buyer usually asks for.
United States overview →What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
What this means for Connecticut sales and marketing teams
Insurance carriers and reinsurers headquartered around Hartford, along with manufacturers and pharmaceutical and medical-device suppliers in the New Haven area, tend to run vendor questionnaires that go well beyond a simple CTDPA compliance checkbox, often drawing on frameworks borrowed from financial-services or life-sciences regulation. A sales or marketing team introducing a new tool should expect questions about data flows, sub-processors and retention regardless of whether the CTDPA technically applies to the activity in question.
In practice, being able to state plainly that identification happens at company level, that no individual profile is built, and that the underlying infrastructure runs on ISO-certified EU data centres tends to move a Connecticut procurement conversation along faster than debating statutory applicability in the abstract. Having a written data processing agreement and a published sub-processor list ready before the first legal review request lands is often what separates a quick sign-off from a multi-week back-and-forth in this corridor's more risk-averse buying committees.
None of this is legal advice, and the CTDPA's scope, its thresholds and the interaction between the B2B exclusion and a specific company's own data practices should be reviewed by qualified counsel familiar with Connecticut law before any compliance representation is made to a customer or regulator.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
Generally no. The CTDPA defines a 'consumer' as a Connecticut resident acting only in an individual or household context, and it explicitly excludes a person acting in a commercial or employment context, such as an employee or contractor communicating on behalf of their employer. A work email address exchanged during a sales conversation, or a procurement contact's name and title, typically falls outside that definition entirely, which is a different position from California, where the CCPA/CPRA's B2B and employee exemptions expired on 1 January 2023 and brought that same category of data fully into scope. Whether a specific dataset qualifies still depends on how it is collected and used, so this is not a blanket exemption for every record your CRM holds, and it should not be treated as one without review. lead.box does not make this determination for you; qualified counsel familiar with the CTDPA should confirm how it applies to your own data practices.
The Connecticut Attorney General enforces the CTDPA exclusively; there is no private right of action, so consumers cannot bring their own lawsuits under the statute. For the law's first year and a half, violators had a mandatory 60-day cure period to fix a deficiency before an enforcement action could proceed, but that cure right expired on 31 December 2024. Since then, whether to offer any cure opportunity is entirely at the Attorney General's discretion, which raises the practical cost of an initial notice compared with the law's early period. For a business handling Connecticut consumer data at any meaningful scale, that shift is a reasonable argument for tightening notice and disclosure practices proactively rather than assuming a warning will come with a grace period attached.
The CTDPA applies to businesses that control or process the personal data of 100,000 or more Connecticut consumers annually, excluding data processed solely to complete a payment transaction, or 25,000 or more consumers if the business derives over 25 percent of its gross revenue from selling personal data. Many mid-market B2B companies never reach either figure through their consumer-facing operations, and website visitor identification of the kind lead.box performs adds firmographic signals about organisations rather than growing a Connecticut consumer dataset in the sense the statute measures. That said, applicability depends on your full data footprint across every product and channel, not just one tool, so counting toward these thresholds is an exercise your legal or compliance team needs to run using your complete Connecticut data inventory, not a single vendor's activity in isolation.
lead.box resolves network-level signals — primarily IP address ranges tied to organisations — into a company name, industry and size band, without identifying a named individual, without setting cookies or device fingerprints for tracking, and without building a profile that follows a person across unrelated websites. No form submission, email address or login is required for a match to occur, and the record produced ties a visit to an organisation, not to an employee or a personal identity. That company-level focus is a separate consideration from the CTDPA's consumer definition and its B2B exclusion; even where the exclusion applies cleanly, lead.box's design keeps identification a step removed from personal data by resolving the organisation rather than a named person in the first place.
From 1 January 2025, the CTDPA requires controllers to recognise universal opt-out signals — browser or device-level mechanisms a consumer can set once to communicate a preference against targeted advertising and the sale of personal data across every site they visit. This requirement is aimed at consumer-facing tracking used for cross-context advertising and data sales, categories that company-level identification is not designed to perform, since lead.box does not build cross-site advertising profiles and does not sell personal data. Even so, if your Connecticut-facing site runs other tools that do fall within that scope, your own compliance program needs to detect and honour those signals for those tools specifically; that obligation sits with the site operator as controller and is worth confirming against your full tooling stack, not just any single vendor.
The CTDPA requires controllers to conduct and document data protection assessments for processing activities that present a heightened risk of harm to consumers, such as targeted advertising, the sale of personal data, profiling with certain legal or significant effects, and processing of sensitive data. Company-level visitor identification, which resolves an organisation rather than an individual and does not involve advertising profiles or sensitive-data categories, is generally a different kind of activity from the ones the assessment requirement targets. Whether your broader processing activities — including other tools on your site — require an assessment is a judgment your privacy program needs to make across your full data inventory, and it is worth documenting that reasoning even where the answer is that a given tool falls outside the requirement.
Insurance carriers, reinsurers, and manufacturing or pharmaceutical suppliers in the Hartford–New Haven corridor often operate under regulatory frameworks well beyond the CTDPA — state insurance codes, HIPAA-adjacent obligations, or contractual security requirements flowing down from their own enterprise customers — and their vendor questionnaires reflect that broader risk posture rather than a narrow reading of one state privacy statute. A vendor should expect to answer questions about data flows, retention, sub-processors and security controls as a matter of that buyer's own policy, independent of whether the CTDPA technically reaches the specific activity being reviewed. Coming prepared with a written data processing agreement, a published sub-processor list and a plain description of what data is collected tends to move these reviews along regardless of the underlying statutory trigger.
No tool can be described as guaranteed-compliant with a state privacy statute, because compliance depends on how a specific business collects, combines and uses data across its entire operation, not on any single vendor's product design. lead.box is built to resolve organisations rather than individuals, does not set advertising identifiers, and processes data in ISO-certified EU data centres under a written data processing agreement, all of which are relevant facts for your own CTDPA assessment. But the applicability thresholds, the scope of the B2B and employment-context exclusion, the cure period's discretionary status, and the universal opt-out and assessment requirements all need to be evaluated against your specific facts by qualified counsel familiar with Connecticut law — this page is informational, not a legal opinion, and should not be treated as one.
See which Connecticut companies are already researching you
Install a first-party snippet, watch organisations from the Hartford–New Haven corridor appear as they browse, and hand procurement the same documentation a European buyer would expect.