Skip to main content
State Privacy Laws Remove Cure Periods: What Connecticut's 2026 Changes Mean for Your Compliance ProgramLaws and Regulations
4 min readFor Compliance Managers

State Privacy Laws Remove Cure Periods: What Connecticut's 2026 Changes Mean for Your Compliance Program

What Happened

Between July 2023 and January 2026, Connecticut's Data Privacy Act (CTDPA) allowed companies time to fix non-compliance issues before facing enforcement. This changed in July 2026 with Senate Bill 1295. The amendments not only removed the cure period but also redefined the law's applicability thresholds. The consumer-count threshold dropped from 100,000 to 35,000. More importantly, any data sale to a Connecticut resident or processing of sensitive data now subjects you to the full law, regardless of volume or revenue.

Connecticut isn't alone. Montana removed its cure period in October 2025. Oregon followed in January 2026. Minnesota's cure period ended in January 2026, and Maryland's discretionary 60-day cure will expire on April 1, 2027. States are tightening enforcement as their privacy laws mature.

Timeline

July 1, 2023: CTDPA takes effect with a 100,000-consumer threshold and cure period
January 2025: Colorado's cure period ends
October 2025: Montana removes cure period
December 2025: Delaware's 60-day cure ends
January 2026: Minnesota's cure period expires; Oregon removes cure period
July 2026: Connecticut's SB 1295 takes effect, eliminating the cure period and lowering thresholds
April 1, 2027: Maryland's discretionary cure expires

Which Controls Failed or Were Missing

The removal of cure periods reveals three control gaps:

Lack of real-time applicability monitoring. Compliance programs often assess state-law applicability annually or quarterly. Under the previous Connecticut threshold, there was room for error. Now, your first data sale to a Connecticut resident triggers full applicability. Relying on periodic reviews means discovering compliance gaps only after you're subject to enforcement.

Consent Management Platform configurations assuming grace periods. Many CMPs have technical debt, like missing purpose disclosures or pre-ticked boxes for analytics partners. These were fixable under cure periods. Without them, they're violations as soon as a Connecticut resident visits your site.

Sensitive data classification that doesn't match state definitions. Connecticut's definition of sensitive data includes precise geolocation, genetic data, biometric data, personal data from a known child, health data, and data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship status. If your data inventory misclassifies "health-adjacent" data, you're processing sensitive data without required opt-in consent.

What the Relevant Standard Requires

Connecticut's amended CTDPA now requires:

Applicability assessment before processing begins. Determine if you meet any of the three thresholds (35,000 consumers; any data sale; any sensitive data processing) before collecting data from Connecticut residents. This is a pre-deployment requirement.

Opt-in consent for all sensitive data processing. Unlike states allowing opt-out mechanisms (Iowa, Utah), Connecticut requires affirmative opt-in. Your CMP must present granular choices, obtain clear affirmative action, and block sensitive data processing until consent is granted.

Immediate compliance posture. Without a cure period, every configuration error, missing disclosure, and consent-flow violation is immediately actionable. The law doesn't differentiate between new and established operations.

Other states with zero-threshold triggers or no cure periods have similar requirements. Oregon bans the sale of all under-16 data and precise geolocation data regardless of volume. Rhode Island requires disclosing not just current third-party recipients but potential future ones.

Lessons and Action Items for Your Team

Build continuous applicability monitoring. Your compliance program needs automated alerts for crossing state thresholds. If you process any sensitive data, you're subject to Connecticut's law today. Monitor:

  • First data sale to residents of zero-threshold states (Connecticut, Rhode Island)
  • Any sensitive data processing in Connecticut, Delaware, Maryland, New Hampshire
  • Consumer counts nearing thresholds in states with remaining cure periods

Audit your CMP configuration as if cure periods never existed. Review every consent flow with this question: if a state attorney general reviewed this today, what would they flag? Common issues include:

  • Accept-all buttons more prominent than reject-all options
  • Purpose descriptions lacking clarity on "legitimate interest"
  • Vendor lists not disclosing cross-context Behavioural Advertising
  • Pre-selected toggles for non-essential cookies

Fix these before serving consent notices to residents of no-cure states.

Reclassify your sensitive data using state definitions. Connecticut includes "personal data from a known child" as sensitive. If your site has a kids' section, parental-consent flow, or age-gated content, you're processing sensitive data. Maryland bans the sale of sensitive data outright. Vermont treats neural data as sensitive. Map your data inventory to each state's definition, then configure processing controls accordingly.

Document your compliance timeline. When Connecticut, Oregon, or Montana asks why you weren't compliant on day one, your answer can't be "we didn't know the law changed." Subscribe to state legislative trackers. Set reminders for effective dates. Treat cure-period sunsets as hard deadlines.

Test your vendor contracts against zero-threshold triggers. If a third-party analytics provider sells Connecticut resident data, you've triggered Connecticut's law even if you never intended to "sell" data. Review your data processing agreements. Confirm vendors aren't selling or sharing data in ways that create unintended applicability.

The cure-period era is ending. Compliance programs built on "we'll fix it when we get a notice" assumptions won't survive 2027. Treat every state launch as a zero-defect deployment, because that's exactly what it is.

You Might Also Like