Legal & Compliance

Connecticut’s tightened rules on minors’ data are now live, and they are not an outlier

Connecticut Attorney General William Tong issued guidance at the start of July as major amendments to the Connecticut Data Privacy Act took effect on 1 July 2026, and three weeks in, the picture is clear enough to state plainly: the tightest US state standard for minors’ data is now in force, the regulator enforcing it is already running investigations, and it is not an outlier. It is the North American anchor of a shift we are tracking across the hemisphere.

What is now in force

The amendments, passed as SB 1295 in 2025, do several things at once. For anyone under 18, processing personal data for targeted advertising or sale is now prohibited outright, a categorical ban that consent cannot cure. Profiling minors requires consent. Design features intended to significantly increase, sustain, or extend a minor’s use of an online service, the streaks, autoplay, and engagement loops of modern product design, are prohibited. Precise geolocation of minors may only be collected where strictly necessary, and direct messaging services must default to preventing unsolicited messages from adults to minors.

The changes reach beyond children. The law’s applicability threshold drops to businesses processing data on 35,000 Connecticut residents, pulling in far smaller operations than the original act. The definition of sensitive data expands to include neural data, government-issued identification numbers, and information derived from genetic or biometric data, all requiring opt-in consent to process. And from the same date, controllers using personal data to train artificial intelligence systems must disclose it in their privacy notice, a duty arriving just as US courts test adjacent AI theories under the wiretap statutes.

An enforcer, not a statute on a shelf

Connecticut’s Attorney General has exclusive enforcement authority, and the office’s posture is not theoretical. It is investigating Roblox, has sued Meta over allegedly addictive design, and has an active investigation into TikTok, alongside newer inquiries into messaging platforms, gaming services, and AI chatbots disclosed in its most recent CTDPA enforcement report. That report states the office requests data protection assessments during investigations and expects them to have been completed before a covered processing activity begins, not assembled afterwards. It has also explicitly rejected wilful blindness about users’ ages as a defence. “For too long, Big Tech has treated our children like social media cash cows,” Tong said in announcing the protections.

What this means for email and martech teams

The instinctive reading, that this is a targeted-advertising rule for social platforms, undersells the exposure. Behavioural scoring, preference prediction, and cross-channel personalisation are profiling, and applied to a user under 18 in Connecticut they now require consent. Gamified acquisition mechanics, streak-based engagement programmes, and re-engagement loops designed to extend usage sit uncomfortably close to the addictive-design prohibition when the audience includes teens. Any programme touching education, gaming, entertainment, or family accounts should assume it has minor users and ask what the team actually knows about their ages, because the regulator has said not knowing is not a defence. And the 35,000-resident threshold means mid-sized senders who reasonably ignored the 2023 act may now be in scope.

The structural consequence is contractual. With Connecticut joining California and Colorado in elevating minors’ data enforcement, “one US standard” language in privacy notices and vendor contracts is getting harder to defend, a fragmentation problem American senders already know from the state anti-spam patchwork.

The hemisphere is moving together

Read Connecticut alongside the week’s other developments and the pattern is unmistakable. Brazil’s ANPD is commissioning the technical evidence base on child profiling, targeted advertising to minors, and manipulative design [INTERNAL LINK: Brazil ANPD evidence-base piece], with its ECA Digital statute already banning behavioural ad profiling of minors and systematic sanctions scheduled from January 2027. Colombia decreed privacy by design for children’s digital environments this week. Connecticut has the rules in force today. Three jurisdictions, three legal instruments, one direction: what counts as acceptable personalisation for younger audiences is being redefined across the Americas, and the teams that treat it as a social-media problem rather than a lifecycle-marketing problem will be the ones explaining themselves to a regulator. Audit where minors can enter your funnels, what your systems infer about them once they are there, and which engagement mechanics you could not comfortably describe to the Connecticut Attorney General.

More Info: Connecticut Attorney General guidance on the new protections.
Additional reference: Inside Investigator on the 2 July guidance.

Subscribe

Personalise your own newsletter

Step 1 of 3

What would you like to receive?

Pick the option that suits you best. You can always change this later.

Strategic Partners

Enterprise Members

Vendor Directory