Connecticut AG to Businesses: Time to Implement Opt-Out Signals
The Connecticut Attorney General wants businesses to know that, starting January 1, 2025, they are required to respect opt-out signals.

Connecticut’s Data Privacy Act (CTDPA) went into effect in July 2023, and since that time the state has shown considerable interest in both enforcing and updating the law. Not all of the CTDPA’s requirements went into effect right away, however.
On January 1, 2025, two important changes came to CTDPA compliance. First, the law’s mandatory rule for a 60-day cure period expired, meaning state officials can now proceed directly to enforcement without offering businesses a chance to fix any violations. Second, businesses are now required to respect opt-out preference signals (OOPS) sent by consumers’ web browsers.
To this effect, Attorney General William Tong published a press release reminding businesses of this new obligation.
OOPS!
From a consumer perspective, the ability to opt out of targeted advertising and/or the sale of their personal information is one of the most important privacy rights. It gives them direct, tangible control over how their data is used, and helps rein in marketing practices that many find objectionable.
Privacy laws already oblige businesses to provide consumers with an easy way to opt out via conspicuous links and web forms. The point of an OOPS is to make it even easier by automating the process.
Here’s how it works: A consumer’s browser sends a signal to every website they visit, indicating that they want to opt out; the website receives the signal and automatically performs a browser-based opt-out (usually accomplished by cookie).
The currently accepted OOPS standard is Global Privacy Control (GPC). GPC can be enabled in the settings of some browsers, such as Firefox or Brave, but the browsers used by the vast majority of consumers—i.e., Chrome, Safari, and Edge—require the installation of an extension in order to enable GPC.
Complying with the New Requirement
A growing number of states require businesses to respect opt-out signals. In order to comply with that rule, businesses must:
- Understand which of their data practices require an opt-out process;
- Decide on an opt-mechanism that fulfills their obligations; and
- Add code to their website that detects opt-out signals and automatically triggers the opt-out.
TrueVault simplifies this entire process for businesses. Our comprehensive privacy platform helps you identify which data disclosures are considered targeted advertising or selling, provides easy mechanisms for accomplishing opt-outs, and includes support for Global Privacy Control. Onboard your business in as little as a few hours, drag and drop our code onto your site, and you’re ready to go!
Talk to one of our experts to see how TrueVault can help you launch your privacy program.
Privacy work that stays current — without adding more chaos.
TrueVault helps lean ecommerce teams keep privacy workflows current as vendors, tracking tools, and privacy laws keep changing.








