Starting Thursday, October 1, Connecticut companies that sell DNA tests directly to consumers will operate under a new set of limits on what they can do with the results. Under Public Act 26-64, the state’s expanded data privacy law, those firms may not hand genetic testing results to employers, to certain insurers for underwriting, or to outside parties they know plan to use the data for advertising or marketing.
The change is one piece of a larger privacy package taking effect the same day, and it has been described in some coverage as a ban on selling genetic data. The statute is narrower than that label: it restricts specific disclosures by a specific kind of company, and it gives residents a property interest in their own samples and test results.
Limits written into the genetic provisions
The clearest summary of the disclosure limits comes from the law firm Proskauer, which wrote that “DTC genetic testing companies may not disclose genetic testing results to employers, certain insurers for underwriting purposes, or third parties that the company knows intend to use the data for advertising, marketing or other promotional purposes.” The firm’s analysis of the amendments also lists October 1, 2026 as the effective date for the genetic data rights and the rules on direct-to-consumer testing.
Connecticut’s attorney general summarized the same section in a public notice of the new and updated privacy laws. Direct-to-consumer testing companies, the office wrote, face new limitations built around “providing consumers with a property right and exclusive control over the collection, use, retention, maintenance, disclosure, and destruction of the sample and result.” That framing treats a saliva sample and the sequence derived from it as something the customer owns, not merely something the company holds.
The law firm Mintz, in its breakdown for businesses, described further obligations: separate consent before disclosing genetic data to third parties other than service providers, security safeguards for genetic information and biological samples, and consumer rights to access, delete, destroy, and withdraw consent for certain genetic data processing. Mintz, however, did not describe a blanket prohibition on genetic data sales, which is why a headline promising a flat ban would overstate the text.
Consent, samples and who enforces the rules
A separate summary on the Inside Privacy blog, dated June 1, 2026, reads the bill as requiring express consent before a company collects, uses, discloses, or retains genetic data, with informed consent under the federal Common Rule for research or publication. It lists exceptions for licensed healthcare providers ordering tests for medical purposes, court-ordered disclosures, and de-identified data, and it says the law does not exempt human-subject research or HIPAA-covered entities.
Enforcement is narrow. The same summary says violations count as unfair or deceptive trade practices that only the Connecticut Attorney General can pursue, which closes off private lawsuits. Neither the state’s notice nor the law-firm summaries give a dollar figure for penalties, so what a violation would cost a testing company remains unstated in the sources reviewed.
For customers, the practical effect is that a company holding a Connecticut resident’s DNA results has a shorter list of people it may share them with, and a customer who wants a sample destroyed or consent withdrawn now has a statutory right to ask. Employers and life or disability underwriters are the obvious targets of the restriction, since genetic information is exactly the kind of data that could be used to screen applicants or price coverage.
The rest of the October 1 package
The genetic provisions travel with other changes. According to the CT Mirror’s September 28 report by P.R. Lockhart, the October 1 portions of the law also address facial recognition and surveillance pricing, and direct the Department of Consumer Protection to “create a system to help track and regulate data brokers.” The attorney general’s notice adds that businesses using facial recognition must post visible signage with a “conspicuous hyperlink or quick response code” pointing to the company’s facial recognition policy, and that data brokers must register with the department by January 1, 2027.
Not every piece arrives on the same date. Proskauer lists surveillance pricing obligations as taking effect July 1, 2027, while a July 2026 analysis by the firm Snell & Wilmer places them on October 1, 2026, so the timing of that section is worth confirming against the firm’s summary and the statute itself before relying on either date. The rules for AI chatbots, which are covered by a companion law, Public Act 26-15, are also on a later schedule: CT Mirror reported that chatbot requirements begin January 1, 2027, including a mandate that chatbots “disclose that they are not human beings.”
State Sen. James Maroney, D-Milford, who has led Connecticut’s privacy legislation, framed the package as a starting point. “This is a start. This is not a finish; this is not a ceiling. This is the floor,” he said, according to CT Mirror. Whether testing companies will need to change their consent flows before Thursday, and how aggressively the Attorney General’s Office will use its sole enforcement power, will only become clear once the first complaints arrive.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Supplements now rank as the fifth-leading cause of death from liver disease.
- Herbal supplements are landing Americans in the hospital with liver damage, doctors warn
- General Motors is switching on cameras that record inside your vehicle by update
- A geomagnetic storm is forecast to hit Earth today, pushing the northern lights unusually far south