PrivacySignal
News

Connecticut Amends Privacy Law for a Third Time and Introduces New Requirements for Data Brokering, Personalized Pricing, Using Facial Recognition, Selling Geolocation Data, and More

JD Supra · · International · Surveillance & Civil Liberties

Connecticut has amended its state privacy law for the third time, adding new requirements around data brokering, personalized pricing, facial recognition technology, and the sale of geolocation data. The changes expand the scope of obligations on businesses that collect and monetize personal information about Connecticut residents.

Why this matters: Connecticut keeps tightening the screws, and this round touches things that matter in daily life. Personalized pricing means a company can charge you more based on what your data says about you. Selling your location is now more regulated. Facial recognition gets new guardrails. Data brokers, who profit from your information without ever meeting you, face more scrutiny. None of this is a total fix, but each amendment closes a gap that businesses were using. If you live in Connecticut, your privacy rights just got a little more concrete.

Who should care: Privacy officers · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

News
Schneier on Security · · International

Connected Cars Are a Surveillance Platform

Researchers from Northeastern University and Consumer Reports reviewed privacy policies and filings from 15 major automakers to assess how much data modern connected cars collect on drivers and how that data flows to third parties, including insurance technology companies and data brokers.

Who should care: Lawyers · Compliance · Privacy officers · Cybersecurity · General readers · Policy

#regulation#surveillance#privacy Read original →
News
E edition.cnn.com · · International

These were the ‘Adams and Eves’ of facial recognition technology

A report profiles the early pioneers credited with developing facial recognition technology, framing them as the foundational figures behind a surveillance tool now embedded in law enforcement, commerce, and public life.

Who should care: Privacy officers · Cybersecurity · General readers · Policy

#surveillance#privacy Read original →
News
E EPIC – Electronic Privacy Information Center · · International

Senator Markey Introduces Bill to Stop the Government’s Use of Face Surveillance and Other Biometric Surveillance Tech

Senator Ed Markey has introduced legislation that would prohibit federal government use of facial recognition and other biometric surveillance technologies. The bill represents one of the more sweeping proposed federal restrictions on government biometric data collection to date.

Who should care: Privacy officers · Cybersecurity · General readers · Policy

#surveillance#privacy Read original →
News
B Biometric Update · · International

Vendor pitches facial recognition layer for Flock camera data

A vendor is proposing to add a facial recognition capability on top of data already collected by Flock Safety cameras, which are widely used by law enforcement agencies across the United States for license plate reading and vehicle tracking.

Who should care: Privacy officers · Cybersecurity · General readers · Policy

#surveillance#privacy Read original →
News
Microsoft Threat Intelligence · · International

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog.

Who should care: Lawyers · Compliance · Privacy officers · Cybersecurity

#regulation#surveillance#security Read original →