Build1 publisher2 min readPublished
Connecticut bans the sale of precise geolocation data as Public Act 26-64 takes effect
Connecticut's Public Act 26-64 bans the sale of precise geolocation data as of October 1, 2026. Meeting that ban and the act's surveillance-pricing rules means changing the code that sends location fields to partners and sets prices.
The Engineer · Build desk
What happened
- A business using facial recognition in a physical location must post conspicuous signage with a link or QR code to a policy on the data's purpose, use, retention and deletion.
- The act narrows how publicly available information is treated and expands consumers' deletion rights in some circumstances.
- Direct-to-consumer genetic testing gets stronger consent and property protections, including limits on disclosure and secondary uses of the data.
- Data brokers must register with the Connecticut Department of Consumer Protection by January 1, 2027, according to the Attorney General.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Because the law has applicability thresholds and exemptions, each company has to establish whether it and each specific processing activity are in scope before it owes any of these changes.
- constraint The policy behind a facial recognition QR code has to match the deployed system's vendor access, storage periods and deletion workflows, so changing a retention setting now also means changing a published policy.
- cost Enrichment, people-search and machine-learning pipelines that copied data without tracking where copies went face rework, since deletion has to reach derived profiles and downstream transfers.
- constraint With 92 days between the effective date and the registration deadline, any company that counts as a data broker has to register while it is still making the code changes.
The location provision reaches further into application code than anything else in the act [4]. Joseph Sides, writing on dev.to, describes the work as an inventory: every location field, the precision attached to it, where it is sent, which partners receive it, and whether an analytics or advertising arrangement could qualify as a sale [5]. "For developers, the responsible response is not limited to changing a privacy-policy sentence," he wrote [14]. I agree with him.
The policy edit is the only part of this job that ships without a deploy. The inventory needs two attributes per field. Precision decides whether a value falls in the protected category. The recipient decides whether a transfer might be a sale. A precise value that never leaves the backend and a coarse one sent to an ad partner are different problems with different fixes. Sides points to the enacted text of Public Act 26-64 for the controlling details, with the Attorney General's September 16 guidance describing the obligations that begin October 1 [3]. The precision cutoff and the definition of a sale have to come from that text.
In my view the field list should be built from what leaves the system: SDK settings and outbound requests. A schema review finds the columns the team created. It will not find a coordinate that a third-party library collects and sends by itself.
Surveillance pricing is harder to find in code. According to the Attorney General, businesses that use personal data to set different prices or wages must follow new limitations and disclosures [6]. Sides lists the ordinary parts such a system can be built from: device identifiers, purchase histories, inferred interests, location patterns, loyalty records and risk scores [13]. His test is whether a product team can explain which data affects an offer, whether the system changes a price or wage, and what notice the consumer sees before the decision matters [15]. For a model that sets offers, the first question means tracing each input feature back to its source table and keeping that record for each decision.
For records a team treats as public, Sides wants the provenance stored with the data. Each record would name its source, the reason it qualifies for an exception, the date it was collected, the uses attached to it and the systems that received copies [12]. On new ingestion, adding those columns is a schema migration. I'd expect most of the cost to be in the backfill, because the downstream copies were made before anyone recorded where they went.
What to watch
- Attorney General guidance or enforcement that settles when an analytics or advertising arrangement counts as a sale of precise geolocation data.
- Entries in the Department of Consumer Protection's data-broker registry as the January 1, 2027 deadline approaches.