October 1 Brings a New Wave of State Privacy Obligations: Connecticut and Maryland

On October 1, 2026, most of Connecticut’s Public Act 26-64 (Senate Bill 4) takes effect, updating its comprehensive privacy law with a geolocation sale ban, facial recognition rules, a narrower “publicly available information” exclusion, and a data broker framework. Maryland’s first-in-the-nation surveillance pricing ban for grocers takes effect the same day.

Here are key things to know:

Connecticut: Selling Precise Geolocation Data Is Now Off the Table

Beginning October 1, controllers and third parties may not “sell” a consumer’s precise geolocation data (with “sell” meaning for monetary or other valuable consideration”). The only carve-outs are for communications content and data connected to utility metering infrastructure. Connecticut joins Maryland, Oregon, and Virginia in moving away from an opt-in consent model and imposing an outright ban on selling precise location data. Relying on the device’s location permission prompt or a privacy policy disclosure is not enough.

Connecticut: Narrows Scope of “Publicly Available” Data

Publicly available information falls outside the CTDPA’s definition of personal data. Many enrichment, lead generation, and similar models rely on this exclusion. Starting October 1, Connecticut’s privacy law will apply to:

  • •Personal data created by combining any personal data with publicly available information;

  • •Biometric data collected without the consumer’s knowledge;

  • •Genetic data, unless the consumer made it public;

  • •Information a consumer posts on a public website or service where the consumer has a reasonable expectation of privacy, such as by limiting the audience; and

  • •Obscene depictions and known nonconsensual intimate or synthetic intimate images.

Consumers also gain a new right to delete publicly available information that has been collated into a profile made available on a public website (free or paid) or offered for sale, along with any inferences drawn from it.

Connecticut: Facial Recognition Signage and Database Limits

Starting October 1, if you are a controller or consumer health data controller using facial recognition on your premises for security, fraud prevention, or similar protective purposes, you must:

  • •Match images only against a database you maintain exclusively;

  • •Post clearly legible signage at each entrance where the technology is used (other than employee-only entrances), with a conspicuous hyperlink or QR code to your facial recognition policy; and

  • •Include the Connecticut Attorney General’s contact information in that policy.

Connecticut: Data Brokers, Profiling, and Delayed Effect

The new Connecticut data broker framework technically takes effect October 1, but its main prohibition is delayed: on or after January 1, 2027, data brokers may not sell or license brokered personal data in Connecticut unless they are registered with the Department of Consumer Protection. Registration costs $2,500 per year. Modeled after California’s DROP, Connecticut’s new state-operated deletion mechanism is due by July 1, 2028, after which brokers must begin checking it every 45 days starting October 1, 2028.

Is your company a “broker”? This question is not so straightforward. First party businesses should still confirm whether they trigger compliance or fall within the exemption for businesses with a direct relationship with the consumer, including whether any business units license data sets to third parties.

The law also expands the CTDPA’s treatment of profiling used for decisions that produce legal or similarly significant effects and narrows the CTDPA’s employment-related exemption.

CT also removes the “material” qualifier from the purpose limitation rule, so consent is now arguably required before processing personal data for any new purpose that is not reasonably necessary to or compatible with the purposes originally disclosed.

Maryland: Surveillance Pricing Ban for Grocers and Food Delivery

Maryland’s Protection From Predatory Pricing Act (HB 895) takes effect October 1. It applies to food retailers operating stores of at least 15,000 square feet that sell sales-tax-exempt groceries, and to third-party services that deliver that food. Covered businesses may not use dynamic pricing or personal data to set a higher price for that food for a specific consumer or group of consumers. They also may not use protected class data in a way that withholds or denies an advantage or privilege given to others.

The law excludes loyalty programs any consumer may join, promotional and retention offers, cost- and supply-based price differences, and pricing-error corrections. Enforcement lies with the Attorney General’s Consumer Protection Division, which must provide a 45-day cure period, and there is no private right of action. As we noted in our June surveillance pricing update here, other states are moving quickly.

Business Takeaways

There are a few steps businesses should take now:

  • •Confirm your precise location data flows and third party sharing arrangements involving Connecticut consumers.

  • •Revisit your “public data” compliance. Identify where you enrich or combine public-source data with first-party data, and update deletion workflows to cover profiles and inferences built using publicly available data.

  • •For brick-and-mortar business in CT, confirm whether any store, venue, or office uses facial recognition for security or loss prevention, confirm the watchlist is not shared outside the company, post signage with the required QR code, and publish a facial recognition policy with Attorney General contact information.

  • •Audit your privacy notice to confirm it is up-to-date and accurate with data uses. With this latest amendment, arguably any new purpose that is not compatible with what you disclosed for CT residents needs new consent. Check recent product launches and AI initiatives in particular.

InfoLawGroup helps organizations stay up to date on these ever-changing state privacy law developments. To discuss how these changes may impact your business, contact us at info@infolawgroup.com.

Originally published by InfoLawGroup LLP. If you would like to receive regular emails from us, in which we share updates and our take on current legal news, please subscribe to InfoLawGroup’s Insights HERE. This summary does not constitute legal advice.