Skip to content

Connecticut SB 4 bans the sale of precise geolocation data

Filip LuchianencoUpdated 7 min read

Last updated: 2026-10-02

Connecticut's ban on selling precise geolocation data took effect on October 1, 2026. Public Act 26-64 (Connecticut SB 4, "An Act Concerning Consumer Privacy and Protection"), signed by Governor Ned Lamont on May 27, 2026, amends the Connecticut Data Privacy Act (CTDPA), in force since July 1, 2023. Sections 14 and 15 add two sentences: "No controller shall sell any consumer's precise geolocation data" and "No third party shall sell any consumer's precise geolocation data." The Connecticut precise geolocation sale ban has no consent clause.

In the CTDPA, a controller is the person or business that decides the purpose and means of processing personal data. The Attorney General enforces the ban under the Connecticut Unfair Trade Practices Act (CUTPA), the state's consumer protection statute. Connecticut is the fifth state with such a ban in force, after Maryland, Oregon, New Jersey and Virginia.

What does Connecticut SB 4 prohibit?

Section 14 of Public Act 26-64 adds the controller sentence as subdivision (3) of § 42-520(a); Section 15 adds the third-party sentence to § 42-521(a). Both exclude "the content of communications or any data generated by or connected to advanced utility metering infrastructure systems or equipment for use by a utility."

For other sensitive data, § 42-520(a)(1)(H) requires a controller to "not sell the sensitive data of a consumer without the consumer's consent". Until October 1, 2026, a controller could sell precise geolocation data with the consumer's consent. Subdivision (3) contains no consent clause.

The statement of purpose on the bill status page describes the bill as "prohibiting the sale, sharing, transfer or allowance of access to precise geolocation data". The enacted sections use one verb, "sell".

What counts as precise geolocation data and a sale?

Section 12 of the act renumbers the CTDPA definitions and keeps the 1,750-foot definition of precise geolocation data: "information derived from technology, including, but not limited to, global positioning system level latitude and longitude coordinates or other mechanisms, that directly identifies the specific location of an individual with precision and accuracy within a radius of one thousand seven hundred fifty feet."

"Sale of personal data" is "the exchange of personal data for monetary or other valuable consideration by the controller to a third party" (§ 42-515, subdivision (39) as renumbered). The definition excludes, among others, disclosure "to a processor that processes the personal data on behalf of the controller", disclosure "to a third party for purposes of providing a product or service requested by the consumer", and disclosure where "the consumer directs the controller to disclose the personal data." The definition describes an exchange "by the controller". Section 42-521 applies the verb "sell" to third parties, and the act leaves undefined how a sale definition written for controllers applies to a sale by a third party. "Other valuable consideration" is wider than Virginia's definition, which covers "monetary consideration" only.

When does the Connecticut privacy law amendment take effect, and who must comply?

Sections 12 to 15 of Public Act 26-64, including the geolocation ban, took effect on October 1, 2026; the Attorney General's September 16, 2026 advisory lists "A ban on the sale of consumer's precise geolocation data" among the new requirements.

Public Act 25-113, section 6, in force since July 1, 2026, sets who must comply: the CTDPA applies to any person doing business in Connecticut or targeting its residents that, in the preceding calendar year, processed personal data of at least 35,000 consumers, or that "control or process consumers' sensitive data", or that "offer consumers' personal data for sale in trade or commerce." Precise geolocation data is sensitive data under the CTDPA (§ 42-515, subdivision (40)(F)), and the second test contains no user-count threshold. "Consumer" means a Connecticut resident, and the exemptions in § 42-517, as amended by Public Act 25-113, section 7, still apply.

Public Act 26-100 amends the data broker sections and repeals SB 4 sections 11 (surveillance pricing) and 16 (the § 42-524 exemptions); Public Act 26-130 re-enacts surveillance pricing, effective July 1, 2027. The word "geolocation" appears in neither act, so the ban stands as enacted in SB 4 sections 14 and 15.

Who enforces the ban, and is there a cure period?

The Connecticut Attorney General has "exclusive authority to enforce" the CTDPA (§ 42-525(a)). A violation is an unfair trade practice under CUTPA, enforced "solely by the Attorney General" (§ 42-525(e)), and the CTDPA provides no private right of action (§ 42-525(d)). Under CUTPA, the Attorney General may recover "a civil penalty of not more than five thousand dollars for each violation" where a court finds a wilful violation (§ 42-110o(b)).

A cure period is time a business gets, after notice of a violation, to fix it before enforcement. Connecticut's mandatory cure period ended on December 31, 2024. Since January 1, 2025, the Attorney General "may" grant an opportunity to cure and weighs factors that include "the substantial likelihood of injury to the public" and "the sensitivity of the data" (§ 42-525(c)).

Which states ban the sale of precise geolocation data?

Five states have a ban in force, each with a 1,750-foot radius in its definition.

State Statute and bill In force Radius in definition Who the ban binds Enforced by Cure period
Connecticut Conn. Gen. Stat. §§ 42-520(a)(3), 42-521(a)(2); SB 4, Public Act 26-64 2026-10-01 1,750 ft Controllers and third parties; sale is for "monetary or other valuable consideration" Attorney General under CUTPA; up to $5,000 per wilful violation At the Attorney General's discretion since 2025-01-01
Maryland Md. Code, Com. Law § 14-4707(a)(2) (sale of all sensitive data), enacted as § 14-4607 by SB 541, 2024 ch. 455 2025-10-01 1,750 ft; since 2026-07-01 the definition covers the location of "a consumer, a mobile device, or a vehicle" (2026 ch. 874) Controllers; sale covers exchange by a controller, processor or affiliate for "monetary or other valuable consideration" Attorney General's Consumer Protection Division, as an unfair, abusive or deceptive trade practice At least 60 days, at the Division's discretion, for violations on or before 2027-04-01
Oregon ORS 646A.578(2)(d)(B); HB 2008 (2025) 2026-01-01 1,750 ft, "present or past location" of a consumer or linkable device Controllers Attorney General; up to $7,500 per violation None since 2026-01-01
New Jersey N.J.S.A. 56:8-166.12(a)(6) (sale of all sensitive data); A5328, P.L.2026, c.25 2026-06-30 1,750 ft Controllers, "regardless of the number of consumers"; data brokers and data collectors (A5328 section 3); sale is "sharing, disclosing, or transferring" for "monetary or other valuable consideration" Attorney General, "sole and exclusive authority"; "$50,000 for each record sold" by a data broker, "including a controller", or data collector (A5328 section 5) 30-day notice, required "until the first day of the 18th month next following the effective date" of the 2023 act (§ 56:8-166.17(b))
Virginia Va. Code § 59.1-578(A)(6); SB 338, 2026 Acts ch. 820 2026-07-01 1,750 ft Controllers; "sell or offer for sale"; sale is for "monetary consideration" Attorney General; up to $7,500 per violation 30 days' written notice, mandatory

Sources: the texts linked in each row. Oregon's in-force date, penalty and cure status are from the Oregon Department of Justice. Virginia SB 338 was approved on April 13, 2026. New Jersey A5328 was approved on June 30, 2026 and "shall take effect immediately" (section 8).

Maryland's sale ban was enacted as § 14-4607 and renumbered § 14-4707 when the subtitle moved in the 2025 Replacement Volume; the cure rule is § 14-4614 in the 2024 chapter. Title 13 of the Commercial Law Article sets the Maryland penalty; this post does not quote Title 13, so the table gives no amount.

The New Jersey radius, enforcement and cure links go to justia.com's compilation of the 2025 code text of P.L.2023, c.266, an unofficial source. A5328 amends § 56:8-166.12 and leaves the cure-period text in § 56:8-166.17(b) unchanged. The New Jersey cure cell quotes the statutory end point and gives no calendar date.

California AB 1542 would have prohibited "a business, service provider, or contractor from selling or sharing sensitive personal information to a third party, except as specified". Under the California Consumer Privacy Act (CCPA), sensitive personal information includes precise geolocation. The Assembly concurred in Senate amendments on August 30, 2026, and the Governor vetoed it on September 27, 2026, per the bill history.

What does an app's network traffic show about precise geolocation?

A traffic capture records the coordinates, the receiving host and the send time. In the IAB Tech Lab's OpenRTB 2.6 bid-request format, the Geo object contains lat, lon, type (value 1 is "GPS/Location Services" in AdCOM 1.0) and accuracy, the "Estimated location accuracy in meters".

One degree of latitude is about 364,000 feet (USGS, at 38 degrees north), so a coordinate rounded to three decimal places is within about 182 feet of the true point north to south; rounded to two decimal places, within about 1,820 feet. The 1,750-foot statutory radius falls between the two.

EFF's study published on August 4, 2026, covered in our post on ad SDKs and precise location, reported that network requests from two Android apps "to a BidMachine domain include precise location coordinates", and that Verve's HyBid SDK code rounds "latitude and longitude coordinates" to "two decimal places"; Verve told EFF location is "limited to an accuracy radius of no less than 1,850 feet." The study does not address Connecticut law, and it does not establish whether any exchange it observed was a sale.

Ad SDKs and exchanges pay app publishers for ad inventory, and a bid request can contain the device's coordinates. Whether a captured transmission is a "sale" turns on facts outside the traffic: the consideration between the app publisher and the recipient, whether the recipient acts as the publisher's processor under contract, and whether the user is a Connecticut resident. Those facts are found in contracts, SDK terms and discovery.

When I scan an app, the report lists the location SDKs found in the binary, the location permissions the app declares, and the requests that contained coordinates on the test device: host, field names, decimal precision, and whether the request was sent before or after the consent prompt. Every finding cites its file and line. SDK presence in a binary shows the code is there; only a capture shows coordinates were sent. What a scan checks and the limits of a scan are on the methodology page.

I run these investigations for lawyers and for researchers working with lawyers, on one app or on a list of apps in bulk. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.