USA - Connecticut: Doing Business in Jurisdiction
Applicability of Data Protection Law in Connecticut to Organizations Doing Business in the Jurisdiction
The factor of "doing business in the jurisdiction" is essential for determining the applicability of the Connecticut Data Privacy Act (CDPA). This factor ensures that organizations with a commercial presence in Connecticut are subject to the state's data protection regulations, regardless of where the data processing occurs.
Text of Relevant Provisions
CDPA Sec.2:
"The provisions of sections 1 to 11, inclusive, of this act apply to persons that conduct business in this state or persons that produce products or services that are targeted to residents of this state and that during the preceding calendar year:(1) Controlled or processed the personal data of not less than one hundred thousand consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or(2) controlled or processed the personal data of not less than twenty-five thousand consumers and derived more than twenty-five per cent of their gross revenue from the sale of personal data."
Analysis of Provisions
The CDPA specifies that its provisions apply to entities conducting business within Connecticut or targeting products or services to Connecticut residents. This includes both in-state and out-of-state businesses that meet certain data processing thresholds. The relevant section, Sec.2, outlines the conditions under which businesses are subject to the Act:
- Commercial Presence: The definition includes any person or entity conducting business in Connecticut or targeting products or services to Connecticut residents. This broad scope ensures that the law applies to both local and out-of-state entities with significant business activities in the state.
- Thresholds for Applicability:
- Data Volume: Businesses that controlled or processed the personal data of at least 100,000 consumers during the preceding calendar year, excluding data processed solely for completing payment transactions.
- Revenue from Data: Businesses that controlled or processed the personal data of at least 25,000 consumers and derived more than 25% of their gross revenue from the sale of personal data.
These thresholds ensure that the CDPA focuses on entities with substantial data processing activities, thereby excluding smaller businesses from its scope and targeting those with a larger impact on consumer privacy.
The rationale for including this factor in the law is to ensure comprehensive data protection for consumers in Connecticut. By extending the applicability to businesses operating within the state, lawmakers aim to protect the personal information of residents from both local and out-of-state entities that benefit from the Connecticut market.
Implications
For Businesses and Data Processors:
- Extended Compliance: Businesses operating in Connecticut must comply with the CDPA if they meet any of the specified thresholds. This includes implementing data protection measures and providing transparency to consumers about data collection and processing practices.
- Regulatory Oversight: The Connecticut Attorney General's office has the authority to enforce compliance with the CDPA, ensuring that businesses adhere to data protection standards.
- Case Examples:
- A retail company based outside Connecticut but with significant sales and data collection activities in the state must comply with the CDPA.
- An online service provider targeting Connecticut consumers and processing their data must adhere to the CDPA, even if its main operations are outside the state.
- Compliance Challenges: Businesses must navigate the complexities of CDPA compliance, including updating privacy policies, implementing opt-out mechanisms for data selling, and ensuring data security measures are in place.
By defining "persons that conduct business in this state," the CDPA ensures that consumer privacy protections are robust and comprehensive, covering a wide range of commercial activities that impact Connecticut residents.