Client Alerts & Insights
Connecticut Attorney General Issues $85,000 Penalty for Deficient Privacy Policies
July 18, 2025
Authored By:
In its first fine for violations of the Connecticut Data Privacy Act (“CDPA”), the state’s omnibus data privacy law, the Connecticut Attorney General (“CT AG”) chose to make an example of deficient privacy notices.
Nearly two years to the effective date of the CDPA, the CT AG issued the first monetary penalty for violations, an $85,000 settlement with TicketNetwork (“TN”), an online event tickets marketplace, for failure to cure privacy notices deficient under the CDPA’s requirements despite the CT AG’s continued outreach since 2023. This serves as a reminder that state-by-state compliance with privacy and other consumer protection laws is the new normal for businesses operating in the U.S.
Similar to other state omnibus data privacy laws enacted in the last decade, the CDPA empowers Connecticut consumers with certain rights to their data (the right to access, correct, and delete personal data stored and collected by businesses as well as the right to opt-out of the sale of personal data and targeted advertising). Generally speaking, the CDPA requires Connecticut businesses that process certain volumes and types of Connecticut consumer data to provide those consumers (specifically through privacy policies and embedded opt-out mechanisms) with the knowledge of and the means by which data rights may be enforced through the business.
TN’s privacy policies did not meet the CDPA’s requirements. According to the CT AG’s statement, the agency flagged TN’s privacy policy as “largely unreadable, missing key data rights, and contained rights mechanisms that were misconfigured or inoperable” in November 2023. By January 1, 2025, when a right to cure expired for violations under the CDPA, TN remained the only business that had not corrected deficiencies identified by the CT AG during the four “privacy notice sweeps” conducted since 2023.
The CT AG’s settlement is a reminder that while compliance with the patchwork of U.S. privacy laws may be costly and cumbersome, the risks and consequences of non-compliance continue to increase as more states enact omnibus data privacy laws and related consumer protections that step in where the federal government has declined or failed to take action. Maintaining a proactive data compliance program that can effectively and timely respond to changes in the law, agency, and consumer complaints is critical.
Latest News
The Coming State-Law Litigation Wave of 2026-27: “Subscription Trap” Class Actions
The subscription economy keeps growing—and so does the wave of class-action litigation targeting it. While the FTC’s regulatory efforts have drawn headlines, private class actions under state laws pose an even greater exposure risk.
Updates to Fees and Grace Periods for Nonimmigrant Visas
Starting September 9, 2026, the 9-11 Response Biometric Entry-Exit Fee will apply to H-1B and L-1 extension petitions filed by employers subject to the fee. Prior to the new rule, the fee was only required for (1) initial grant of status to a foreign national seeking H-1B or L-1 status and (2) a change of employer in the same status.
Third Circuit Decision Reshapes Creditor Standing in Successor Liability Disputes
The Third Circuit recently held that when determining whether a successor liability claim belongs to a bankruptcy estate, the key question is whether the claim seeks to remedy harm suffered by all creditors collectively or a unique injury suffered by a specific creditor. The fact that creditors may be permitted to bring the claim outside of bankruptcy is not, by itself, determinative.
CMS Proposes Sweeping Restrictions on Remote Patient Monitoring: The Outsourcing Ban, Reimbursement Revaluation and Potential Code Consolidation in the CY 2027 Physician Fee Schedule Proposed Rule
CMS’s CY 2027 Proposed Rule would significantly restrict Medicare reimbursement for Remote Patient Monitoring (RPM) and Remote Therapeutic Monitoring (RTM), including banning outsourced clinical staffing, adding new patient-relationship and initiating-visit requirements, reducing certain reimbursement rates, and exploring consolidation of existing billing codes.