Data visualization dashboard displayed on a computer monitor
Photo via Unsplash

TL;DR: On May 4, 2026, Connecticut's House passed Senate Bill 4 by a vote of 141-6, sending one of America's most comprehensive data privacy bills to Governor Ned Lamont's desk. The bill creates a state-run data broker registry, a centralized deletion mechanism that lets you wipe your personal data from every registered broker with a single request, a ban on surveillance pricing, restrictions on facial recognition, a ban on selling geolocation data, and new genetic data consent requirements. The Senate had already passed it 31-4. If signed, Connecticut leapfrogs California and Vermont in data broker regulation.

One Button to Delete Your Data From Every Broker

The headline feature: Connecticut is building a centralized, state-run system where you submit one request and your data gets deleted across every registered data broker in the state [1][2].

Right now, getting your data removed from data brokers is a nightmare. Each broker has its own process. Some make you mail a physical letter. Some require you to create an account just to delete your account. Services like DeleteMe charge $129/year to do it for you. Connecticut's approach cuts out the middleman: the state Department of Consumer Protection handles it.

Brokers must verify deletion requests and permanently stop using your data, with narrow exceptions for fraud prevention and legal compliance [3]. The penalty for non-compliance: $200 per day per violation [3].

California, Oregon, and Vermont already have data broker registries. But Connecticut's deletion mechanism is the most aggressive: it's not just a list, it's an enforcement tool.

The Registry: $200/Day If You Don't Register

Every company that sells or licenses Connecticut residents' personal data must register with the Department of Consumer Protection by January 1, 2027 [3]. Starting in 2031, registered brokers face compliance audits every three years.

The bill also lowered the threshold for who counts as a data controller. Previously, Connecticut's privacy law only applied to companies processing data of 100,000 or more state residents. SB4 drops that to 50,000. Companies deriving more than 25% of revenue from data sales hit the threshold at just 12,500 consumers [4].

That net catches a lot of smaller data brokers who've been flying under the radar.

Surveillance Pricing Is Now Illegal

SB4 bans businesses from charging you different prices based on your personal data, what privacy advocates call "surveillance pricing" [2][3].

This is the practice where companies track your browsing history, location, purchase patterns, and device type to decide how much to charge you. A 2024 FTC report found that major retailers including Mastercard, JPMorgan Chase, and Accenture were using personal data to set individualized prices for consumers [5].

Connecticut joins Maryland, which passed the first state surveillance pricing ban earlier this year. But SB4 carves out exemptions for loyalty programs, uniform discounts, demand-based pricing, and financial institutions regulated under federal law [3].

Dynamic pricing based on neutral factors like time, distance, and supply/demand is still allowed. Charging you more because you searched for the product three times on your iPhone? That's the part they're banning.

Facial Recognition Gets a Leash

The bill restricts how businesses can use facial recognition technology [3]:

  • Systems can only compare scans against the company's own database, not external law enforcement databases or third-party watchlists
  • Businesses must post visible signage at every public entrance where facial recognition is used
  • Every company using it must publish an accessible policy document that includes contact information for the Attorney General

This is targeted directly at the retailer surveillance trend. Companies like Rite Aid (which the FTC banned from using facial recognition in 2023 after thousands of false matches) and the kind of system MSG deployed to ban critics from Madison Square Garden would face real restrictions in Connecticut.

Your Location and Your DNA Get Protected Too

SB4 bans the sale of precise geolocation data by data controllers and third parties, with only a narrow exception for utility companies operating smart meters [3].

Location data is one of the most dangerous data types in the broker ecosystem. In 2023, the FTC took action against X-Mode Social (now Outlogic) for selling precise location data that could track people to sensitive locations: domestic violence shelters, reproductive health clinics, places of worship. Connecticut is saying: you can't sell that here.

The genetic data provisions are equally aggressive. Companies need your express, informed consent before collecting, using, disclosing, or retaining genetic data. Separate consent is required for research use, third-party sharing, and long-term storage. Sharing genetic data with insurers, employers, or marketers is restricted [3].

If you've spit in a tube for 23andMe or Ancestry, you know why this matters. 23andMe filed for bankruptcy in March 2025 with 15 million users' genetic profiles on its books.

141-6 in the House. 31-4 in the Senate.

Those aren't close votes. SB4 had bipartisan supermajority support [1][2].

Senator James Maroney (D-Milford), co-chair of the General Law Committee and co-chair of the AI Caucus, led the push along with Representatives Hubert Delany (D-Stamford) and Roland Lemar (D-New Haven) [1].

The business lobby fought it. CBIA (Connecticut Business & Industry Association) VP Chris Davis warned that "companies remain concerned that several provisions still represent a significant compliance burden" [3]. The Computer & Communications Industry Association argued the original version would hamper marketing and impede risk detection.

The bill was amended to address some business concerns, but the core provisions survived. The final vote counts suggest the privacy argument won decisively.

Connecticut's Privacy Power Play

SB4 is the companion bill to SB5, Connecticut's sweeping AI regulation bill that passed the Senate 32-4 in April 2026. Together, they make Connecticut arguably the most aggressive state in the country on tech regulation right now.

Connecticut was already the fifth state to pass a comprehensive privacy law back in 2023. SB4 builds on that foundation with specific, enforceable provisions that target the data broker industry, an industry worth $462 billion globally that has operated with almost no oversight for decades.

The bill now sits on Governor Lamont's desk. He hasn't indicated whether he'll sign it, but with 141-6 and 31-4 votes, a veto would be politically expensive, and overridable.

What You Can Do Right Now

  • If you're in Connecticut: Watch for the deletion mechanism to go live. Once the broker registry launches (January 1, 2027), you'll be able to submit a single request to wipe your data from every registered broker
  • If you're not in Connecticut: Demand the same from your state. California, Oregon, and Vermont have registries but weaker enforcement. Push your legislators to match Connecticut's deletion mechanism
  • Right now: Services like DeleteMe and Kanary can start removing your data from brokers today, though they charge for the service Connecticut is about to offer for free

References

  1. CT Mirror: "Consumer data privacy bill gets final passage in CT House" (May 4, 2026)
  2. CT Mirror: "CT Senate passes consumer data protection legislation" (April 23, 2026)
  3. CBIA: "Senate Advances Far-Reaching Data Privacy Bill" (April 2026)
  4. CBIA: "Data Privacy Law Expansion Raises Business Concerns" (2026)
  5. Connecticut Senate Democrats: "Sen. Cabrera Votes for Consumer Privacy Bill" (2026)