Blog Commercial Contracts

Data Processing Clauses Post-CTDPA: What Commercial Contracts Need to Say

Connecticut's CTDPA created new obligations for data processing agreements. Here's the clause language that most vendor contracts still get wrong — and why the gap matters more now than it did before the Act took effect.

Privacy regulation document alongside commercial contract pages

Connecticut's Personal Data Privacy and Online Monitoring Act — the CTDPA — took effect July 1, 2023, making Connecticut one of the earlier mid-Atlantic states to enact comprehensive consumer data privacy legislation. Like the Virginia CDPA and Colorado CPA before it, the CTDPA imposes specific requirements on the contractual relationship between a controller (the business deciding why data is processed) and a processor (the vendor actually processing it on the controller's behalf).

Two years on, the vendor contracts that clients are still signing routinely fail to include the CTDPA-required data processing agreement terms. This isn't a compliance backwater issue — it's a mainstream problem in any commercial contract where one party processes personal data of Connecticut consumers on behalf of another.

What CTDPA Section 8 Actually Requires

The CTDPA's processor obligations are primarily contained in Section 8 of Public Act 22-15 (codified at Connecticut General Statutes § 42-520). The Act requires that a contract between a controller and processor govern the processor's data processing, and that the contract include specific provisions.

The required provisions include:

  • Instructions for processing personal data, specifying the nature and purpose of processing
  • The types of personal data subject to the processing
  • The duration of the processing
  • Obligations and rights of both parties
  • A requirement that the processor keep personal data confidential
  • A requirement that the processor delete or return personal data upon termination, unless retention is required by law
  • A requirement that the processor provide reasonable assistance to the controller to meet its consumer rights obligations (access, deletion, correction, portability)
  • A requirement that the processor make available all information necessary to demonstrate compliance
  • Permission for audits and inspections
  • A prohibition on the processor engaging sub-processors without prior authorization from the controller
  • A requirement that any sub-processors be bound by equivalent obligations

The practical gap in most vendor contracts is that existing DPA templates — even those drafted with GDPR or CCPA compliance in mind — may not specifically address the CTDPA's consumer rights assistance requirement, the sub-processor authorization mechanism, or the deletion/return requirement in the CTDPA's specific formulation.

The Three Clauses That Most Contracts Get Wrong

1. Sub-processor authorization language

The CTDPA requires that the controller authorize the use of sub-processors. Most vendor DPA templates address this with a general permit provision: "Processor may engage sub-processors to assist in providing the Services, provided Processor shall ensure sub-processors are bound by equivalent obligations." This satisfies the sub-processor obligation requirement, but it does not necessarily give the controller the ability to object to or approve specific sub-processors.

The GDPR-standard approach — a list of currently authorized sub-processors, with a notice-and-objection mechanism for new sub-processors — is more protective of the controller's rights and aligns with the CTDPA's intent. But most U.S. vendor DPA templates don't include this mechanism because it was driven by GDPR requirements, not CCPA or CTDPA requirements. A Connecticut client whose vendor contract was drafted against a CCPA baseline may have a weaker sub-processor provision than the CTDPA standard contemplates.

2. Consumer rights assistance obligations

Under the CTDPA, controllers must fulfill consumer rights requests: access to personal data, deletion, correction, data portability, and opt-out of sale or targeted advertising. The controller's ability to fulfill these rights depends in part on the processor's cooperation — if the data is held and processed by a vendor, the vendor needs to support the access, deletion, and portability operations.

The required DPA clause should require the processor to assist the controller in responding to consumer rights requests with respect to personal data the processor holds, and to do so within a timeframe that allows the controller to meet its statutory response window (which under the CTDPA is 45 days, extendable by an additional 45 days with notice).

The clauses that fail here typically say something like: "Processor will cooperate with Controller's reasonable requests regarding data privacy compliance." This is too vague. The processor's obligation should be specifically tied to the right types, the response timelines, and the required output format (for portability, a commonly used, machine-readable format is required under the CTDPA).

3. Data deletion and return specifications

The CTDPA requires the processor to delete or return personal data at the controller's direction, and upon termination of the contract, unless retention is required by applicable law. The problematic contract language typically says: "Upon request, Processor will delete or return personal data in its possession."

The issues with this formulation: it's conditional on request rather than being a defined obligation at contract termination; it doesn't address data in backup systems and disaster recovery infrastructure (which vendors routinely exempt from deletion obligations); and it doesn't specify a deletion timeline or certification requirement.

Better language defines a specific timeframe for deletion after termination (30-60 days), addresses the treatment of backup data explicitly (either requiring deletion after the backup cycle or carving it out with a specific end date), and requires written certification of deletion upon completion.

Scope Applicability: Who Has a CTDPA Problem

The CTDPA applies to controllers who process the personal data of Connecticut consumers. The thresholds — processing data of more than 100,000 consumers annually, or 25,000 consumers if data is also sold for revenue — are not trivial. A small B2C business with limited Connecticut customer reach may fall below them.

But the threshold question is not primarily relevant to the vendor contract review task. A business that is subject to the CTDPA needs compliant DPAs with all its processors. And a business that is not currently subject to the CTDPA may become subject to it as it grows, or may be subject to one or more of the other state privacy laws (California's CPRA, Virginia's CDPA, Colorado's CPA, Texas's TDPSA) that have similar but not identical DPA requirements. A vendor contract with non-compliant DPA language creates a problem across multiple state law regimes simultaneously.

The Multi-State Compliance Problem

The fragmentation of state privacy law creates a practical drafting problem: no single DPA template satisfies all state requirements because the requirements are not uniform. GDPR Article 28 requirements, CCPA/CPRA Section 1798.100 requirements, CTDPA Section 8 requirements, and Virginia CDPA § 59.1-578 requirements overlap significantly but are not identical.

The most defensible approach for a business with multi-state consumer data exposure is a DPA template that satisfies the most demanding applicable requirements in aggregate. In practice, a GDPR-compliant DPA template covers most of the substantive requirements across U.S. state privacy laws, because the GDPR standard is the most stringent on most points.

We're not saying that GDPR compliance is required for U.S. businesses — it's only required if you're subject to the GDPR. The point is that using a GDPR-baseline DPA template as a starting point for multi-state U.S. compliance is a reasonable drafting strategy, not overcompliance. The specific state law requirements (state-specific consumer rights, state-specific data security requirements, state-specific enforcement mechanisms) should then be layered in as state-specific addenda for the states where the client has material consumer exposure.

What Commercial Contract Review Should Now Include

When reviewing commercial contracts for clients who process personal data — which, again, is most clients at this point — the data processing provisions should now be evaluated against the following checklist as a minimum:

  • Does a DPA or data processing addendum exist? (Many vendor contracts incorporate this by reference to an online DPA; check whether the online version is current and adequately protective)
  • Does the DPA specify the types of data, the nature of processing, and the purpose?
  • Does the DPA address sub-processor authorization in a way that gives the controller visibility and objection rights?
  • Does the DPA include consumer rights assistance obligations tied to specific right types and response timelines?
  • Does the DPA address deletion and return upon termination, including backup data and certification?
  • Does the DPA permit audits and inspections by the controller?

For Connecticut-domiciled clients or clients with material Connecticut consumer exposure, the CTDPA requirements are now baseline. For clients with multi-state exposure, the analysis needs to identify which state law sets the ceiling for each category of requirement and confirm the contract meets that ceiling.

This is a review task that has gotten more complex over the past three years as state privacy laws have proliferated. The contracts that were adequate in 2020 are frequently inadequate now, and the gap has grown with each new state law that took effect. Getting ahead of that gap — before a consumer rights complaint, an AG investigation, or a contract dispute puts the inadequacy of the DPA language in front of a regulator — is significantly cheaper than addressing it after the fact.