GO
Overall Score
PixelVerdict
1. One-liner
Reads your live website and proves whether you sell sensitive data — the trigger with no consumer minimum.
2. Trend signal — why now?
Connecticut just deleted the number that kept small businesses out of privacy law.
SB 1295 (Public Act 25-113), enacted June 2025 and effective 1 July 2026, does two things. It drops the CTDPA applicability threshold from 100,000 consumers to 35,000. And — the part that actually matters — it removes the volume threshold entirely for two triggers: controlling or processing any sensitive data (payment-processing excepted), and selling consumer personal data at any scale. Snell & Wilmer’s summary is blunt: controllers who process sensitive data “without reference to volume” are in scope.
Then it widens what “sensitive” means. The amended definition now includes financial account numbers and government-issued identification numbers, plus disability/treatment status, neural data, and nonbinary/transgender status.
Read those two changes together and the picture is ugly for a small operator. A 12-person outfit that photocopies a driver’s licence at intake, or stores a bank account number for ACH, is now processing sensitive data. There is no consumer count that saves them. Feroot’s threshold tracker puts it plainly: the amendment “moves Connecticut from mid-tier applicability to one of the broadest state laws after California.”
Meanwhile the enforcement posture is already hostile. Connecticut’s cure period sunset on 1 January 2025 — the AG may proceed directly to enforcement with no 60-day notice. And this AG demonstrably runs website sweeps: the OAG’s own enforcement reports describe sweeps of privacy notices producing “over two dozen cure notices,” plus a dedicated sweep against cookie banners that made consenting easier than opting out.
The second trigger is the one nobody sees coming. State laws now treat transferring data to ad platforms as a “sale” or “share” even when no money changes hands — Meta Pixel, TikTok Pixel and LinkedIn Insight Tag all qualify. Secure Privacy notes many companies “do not know these trackers are in their websites,” and flags “shadow pixels” — scripts from vendors no longer under contract — as a top enforcement trigger. Nerd Stack’s small-business guide concedes the definition of sale “is broad enough to often include using ad pixels.”
So: a business under 35,000 consumers, which correctly concluded in 2025 that the CTDPA did not apply to it, can be in scope on 1 July 2026 because of a pixel a lapsed agency installed in 2023 and an ACH form it has run since forever. Nobody sends them a letter. The first signal is the AG.
Provenance:
- Signal 1 (demand): Connecticut SB 1295 removes volume thresholds for sensitive-data processing and any-scale data sale, effective 1 July 2026; sensitive data expanded to include financial account and government-ID numbers — https://natlawreview.com/article/connecticut-amends-connecticut-data-privacy-act and https://www.swlaw.com/publication/connecticut-data-privacy-act-2026-amendments/ — observed 2026-09-06
- Signal 2 (feasibility): Ad-tech trackers (Meta/TikTok/LinkedIn pixels) legally classified as data-sharing triggering opt-out duties; “many companies do not know these trackers are in their websites”; shadow pixels named a top enforcement trigger — https://secureprivacy.ai/blog/us-state-privacy-laws-2026-marketing — observed 2026-09-06
- Signal 3 (economic): CT cure period sunset 1 Jan 2025 (direct enforcement, no notice); OAG enforcement reports document website sweeps yielding two dozen-plus cure notices; typical 2025–26 state privacy action runs $300K–$3M — https://portal.ct.gov/-/media/ag/press_releases/2025/updated-enforcement-report-pursuant-to-connecticut-data-privacy-act-conn-gen-stat—42515-et-seq.pdf and https://www.uniconsent.com/blog/us-privacy-fines-2026 — observed 2026-09-06 Category: Regulatory arbitrage
3. The opportunity
Every incumbent in this category sells the remedy. Nobody sells the verdict.
Look at the price list. Cookiebot from $8/mo per domain. Termly under $20. Enzuzo Pro $59. Osano’s public cookie tier starts at $199 and everything above it is quote-only. What do you get? A consent banner, a policy generator, sometimes a DSAR intake form. Every one of these products assumes you have already decided you are covered and already know which duties attach. They are execution tools bolted onto a decision the customer has not made.
The free tools stop even shorter. PrivacyLawMap will “answer a few questions about your business and instantly see which state privacy laws apply” — a static questionnaire keyed off consumer counts and revenue. That questionnaire is now structurally wrong for Connecticut, because the answer no longer depends on a count. It depends on two facts about your actual operations: what sensitive fields you touch, and whether anything on your site constitutes a sale. A form cannot see either. The business itself usually cannot see the second one — that is the entire shadow-pixel finding.
That is the gap, and it is the shape my notes keep flagging: classification precedes calculation. Threshold rules always get calculators. Deciding what counts toward the trigger stays unbuilt, because it requires reading the customer’s live estate rather than reading their self-report.
The other half of the gap is evidentiary. Connecticut has no cure period. If the AG asks, “why did you conclude the CTDPA did not apply to you,” a screenshot of a free questionnaire from 2025 is not a defence — and the questionnaire didn’t ask about pixels anyway. The dated, reasoned scope determination is a document that does not currently exist anywhere in the SMB price band. Below Osano’s quote-only tier, no product produces it. That’s duty-attaches-to-the-signature and scoring-vs-proving in one: the incumbents own the number, nobody owns the proof.
So the wedge is not “another consent tool.” It is: scan the site, read the intake forms, render a defensible verdict on whether the no-threshold triggers fire, and keep re-rendering it as the site changes. The remedy — if needed — is the upsell, and half of it the customer can buy from Termly.
4. Target market
Primary customer: Owner or operations lead at a Connecticut-nexus business with 10–100 employees and under 35,000 consumer records — the band that was correctly out of scope in 2025 and is in scope now. Concretely: medical and dental practices, small lenders and mortgage brokers, staffing agencies, property managers, home-services firms, independent insurance agencies, and any B2C operator running a Meta or TikTok pixel. The common trait is an intake form that captures a bank account number, a licence scan, or health information — plus a marketing stack they did not build themselves.
Secondary customer (probably the better one): the 20–60 client digital agency or MSP serving those firms. They installed the pixels. Liability sits with the site operator, but the agency gets the angry call, and they have no way to answer “which of my 40 clients are now in scope” without opening 40 sites by hand.
Why they buy: Not because they love privacy law. Because the exposure is asymmetric and undated. Typical state privacy actions in 2025–26 run $300K–$3M. Connecticut’s AG proceeds directly to enforcement with no cure notice, and runs sweeps. A $200/mo product that produces a dated determination is trivially cheap insurance against a five-figure legal bill just to establish whether you’re covered, which is the quote a CT business lawyer will give for the scoping memo alone.
Rough TAM reasoning: Connecticut has 381,129 small businesses (SBA 2025 state profile), 99.4% of all CT firms. The addressable slice is not all of them — most are sole proprietors with no website of consequence. Take the employer-firm subset with a real web presence and a sensitive-data intake path: a defensible estimate is 15,000–30,000 CT firms, plus every out-of-state business with CT customers, which is the much larger and much vaguer pool. At $200/mo and 500 customers that’s $1.2M ARR from a single state. Connecticut is the beachhead, not the market — Montana (25K), Rhode Island and the no-threshold Texas and Nebraska regimes are the same product with a different rulepack.
Why now for them: 1 July 2026 already passed. The profiling impact-assessment duty landed 1 August 2026 and applies to profiling “created or generated” on or after that date. These businesses are currently non-compliant and do not know it. That is a rare and short window where the pain is real, dated, and undiscovered.
5. Product sketch (MVP)
- Scope verdict. Point it at a domain. It crawls the site, enumerates every third-party tag and tracker, inspects intake and checkout forms for sensitive-field capture (bank account, government ID, health, biometric), and returns one of three answers: in scope, out of scope, in scope on this specific trigger — with the statutory citation and the evidence that produced it.
- The sale question, answered. For each detected tracker, a plain-English ruling on whether the transfer constitutes a “sale” or “share” under the CTDPA definition, with the specific network, what it receives, and whether it fires before consent.
- Shadow-pixel inventory. Flags scripts from vendors the customer no longer works with — the enforcement trigger they cannot see.
- Dated determination memo. A PDF, timestamped and versioned, showing the facts found, the reasoning applied, and the conclusion. Signed off by the owner. This is the artefact you hand the AG.
- Change watch. Re-scans weekly. A new tag, a new form field, or a lapsed vendor’s script re-appearing flips the verdict and fires an alert — because scope is not a one-time question when marketing keeps shipping.
- Profiling assessment starter. Where automated decisioning is detected, pre-drafts the Aug-2026 impact assessment skeleton: purposes, data categories, benefits, risk mitigations, transparency approach, post-deployment safeguards.
- Agency console. One view across all client domains, sorted by exposure, so an agency can triage 40 sites in a morning.
- Remedy handoff. Where a fix is needed, it names the fix and links out. It does not pretend to be a consent platform.
6. AI angle — what’s load-bearing
Remove the AI and this product does not exist — it degrades into a tag scanner, which is a commodity.
The load-bearing work is classification under a legal definition, from messy live evidence. Three jobs:
- Sensitive-field detection. Deciding that a form field labelled “Acct #” next to a routing-number field is a financial account number, while “Account #” on a customer-portal login is not. This is semantic judgment over unlabelled, idiosyncratic HTML. Regex gets you a demo and a pile of false positives; false positives here destroy trust immediately, because a wrong “you’re in scope” is a wrong bill.
- Sale/share classification. Mapping an observed network request against the statutory definition of sale, accounting for the payment-processing carve-out and the contractual-processor distinction. Same tag, different verdict, depending on context and purpose.
- Reasoning that survives being read. The output is a memo a lawyer may attack. It has to state facts found, definition applied, and conclusion, in language that holds up. This is generation over a legal corpus, and it’s the reason the artefact is worth more than the scan.
The determinism matters too — the crawl and tag enumeration are ordinary engineering, and should stay that way. AI does the judgment layer only. That split is what keeps operating cost sane and the output auditable.
7. Localization angle (if any)
N/A as a country play — this is US-only by construction. But the jurisdictional localization is the whole product architecture. The scanner is generic; the rulepack is per-state. Connecticut is the sharpest wedge because it has the widest no-threshold trigger, the expanded sensitive-data definition, an expired cure period and a sweep-happy AG. Montana (25K), Rhode Island, Texas and Nebraska (no numeric threshold) reuse the same engine with a swapped rulepack. Build for CT, expand by statute — not by country.
8. Business model — path to $1M–$5M ARR
- Pricing: $149/mo single domain (SMB direct). $399/mo agency tier up to 25 client domains, $899/mo up to 75. One-off determination scan at $499 as a paid trial that converts to the monitoring subscription — this matters, because the first verdict has standalone value and gets you paid in week one.
- ACV: ~$2,400 SMB direct; ~$6,000 agency blended.
- Rough math to $1M ARR: 250 agency accounts at $400/mo = $1.2M. Or a blend: 150 agencies ($720K) + 200 direct SMBs ($358K) ≈ $1.08M. The agency route is far fewer conversations for the same revenue and is where I’d point the effort.
- Rough math to $5M ARR: Requires the multi-state rulepack — CT alone will not carry it. Roughly 700 agency accounts across 6–8 states at a higher blended ACV (~$7K, with the profiling-assessment module as a paid add-on). What has to be true: the rulepack generalizes without bespoke work per state, and agencies stay for renewal because scope drifts continuously.
- Expansion path: Domains → states → modules. An agency starts at 25 domains and grows; each new state law adds a rulepack the existing customer wants; the profiling impact assessment is a natural second SKU. Consumer-rights request handling is a third, though that lane is contested.
9. Go-to-market wedge — first 100 customers
- Scan first, ask second. Pull the Connecticut Secretary of State business registry and cross-reference against sites running Meta/TikTok/LinkedIn pixels — this is publicly observable without permission. Target the ~2,000 that both run trackers and show a sensitive-intake pattern. Send the actual finding: “your site sends visitor data to Meta before consent; under CTDPA as amended 1 July 2026 that is a sale, which now has no volume threshold. Here is the two-page determination.” Cold email with a real, specific, verifiable finding converts at a different rate than cold email with a pitch. Target 3–5% reply, 50–100 conversations.
- Agencies via the shadow-pixel report. Find CT-area digital agencies on Clutch and the local AAF chapters. Offer a free portfolio scan across their client list. The output — “6 of your 41 clients are in scope and 3 have scripts from vendors you dropped” — is a problem they created, which makes it urgent and makes them the buyer. 60 agencies scanned, expect 10–15 to convert. This is the highest-leverage channel and should get the majority of effort.
- The referral tier that actually works: CT business attorneys and fractional CFOs. They get asked “does this apply to me,” it is unbillable-feeling scoping work they dislike, and they have no tool. Give them a free agency-tier seat and a revenue share. 20 firms, each with dozens of SMB clients.
- CT SBDC and chamber channel. The Connecticut SBDC (UConn) is already publishing CTDPA guidance telling small businesses to “determine their regulatory scope” — with no tool that does it. Offer a free webinar and a free scan for attendees. Warm, credible, and the co-sign does the trust work a cold email cannot.
- Content aimed at one query. “Does the Connecticut Data Privacy Act apply to my business in 2026.” Rank for it, put the scanner behind the answer. Slow, but it compounds and it is the exact moment of intent.
10. Build complexity — justification
Medium. The crawler, headless-browser tag enumeration and network-request capture are well-trodden — off-the-shelf browser automation plus an existing tracker-signature database gets 80% of detection working in weeks. The custom work is the classification layer: sensitive-field detection over arbitrary forms, sale/share rulings with the carve-outs encoded, and memo generation that reads like a professional would write it. The rulepack abstraction needs designing properly on day one or the multi-state expansion becomes a rewrite. Realistically 10–14 weeks to a v1 a paying customer can use, for a technical founder plus a part-time domain advisor. The hard part is not the code, it’s the accuracy bar — false positives are fatal here, and getting them low needs a hand-labelled corpus of a few hundred real sites.
11. Gating checklist
| Gate | Pass? | Note |
|---|---|---|
| Legal in target market | ✅ | Scans publicly accessible pages; produces informational determinations, not legal advice. Needs a clear disclaimer and a named attorney partner for anything approaching advice. |
| Ethical — no harm / dark patterns | ✅ | Reduces covert tracking and helps businesses tell the truth about data practices. Fear-based marketing is the temptation; findings must be accurate and non-inflated. |
| Market exists (evidence above) | ✅ | Enacted statute, dated commencement, expired cure period, documented AG sweeps, priced incumbents in the adjacent lane. |
| 1–5 person team can build this | ✅ | One strong technical founder plus a domain advisor. |
| Launchable with <$50K / ₹40L | ✅ | Browser infrastructure, inference and a legal review of the memo template. Well under $25K to first revenue. |
All five pass.
12. Feasibility score
| Axis | Weight | Score | Notes |
|---|---|---|---|
| Problem intensity | 20 | 15/20 | Real and dated, with no cure period and a sweeping AG. Marked down because it is undiscovered pain — the customer does not yet know they are in scope, which means demand must be created rather than met. Hair-on-fire only after you show them the finding. |
| Demand evidence | 15 | 12/15 | Strong on the regulatory and enforcement side (statute, AG reports, fine ranges, priced incumbents). Weaker on direct customer voice — I found trade and law-firm commentary, not CT small-business owners complaining in their own words. That gap is honest and it’s the thing to validate first. |
| Build feasibility | 15 | 11/15 | Crawling is solved; classification accuracy is the real work. 10–14 weeks, not 6. |
| Distribution clarity | 15 | 12/15 | The agency channel is specific, named, and leveraged, and the scan-first cold email is concrete. Not a 15 because conversion on a pain the buyer hasn’t felt yet is genuinely unproven. |
| Revenue mechanics | 15 | 11/15 | Pricing sits sensibly between Termly and Osano’s quote-only tier, and the $499 scan gets cash early. $1M from CT alone requires either a big share of the agency channel or multi-state, sooner than is comfortable. |
| Time to first revenue | 10 | 8/10 | The paid determination scan can sell before the monitoring product is finished. Weeks, not months. |
| Defensibility | 10 | 3/10 | The weak axis, and it is genuinely weak. Tag scanning is commodity. The rulepack is copyable. The moat is a labelled accuracy corpus, agency workflow lock-in, and speed — that’s an execution moat, not a real one. An incumbent like Osano or Enzuzo could ship a scope-verdict feature in a quarter if they decided to care. The bet is that they won’t, because it cannibalizes the assumption their funnel depends on. |
| Total | 100 | 72/100 |
13. Qualitative modifiers
Founder-fit tags
technical-heavy · content-heavy
Technical because accuracy is the product. Content-heavy because the demand has to be created — the customer does not know they are in scope, so the funnel is “show them the finding,” which is content and outbound, not inbound.
Key assumptions to validate (3–5)
- Assumption: A meaningful share of CT small businesses under 35,000 consumers genuinely are in scope via the sensitive-data or sale trigger. How to test: Scan 200 CT business websites cold. Count how many capture a sensitive field or fire a pre-consent ad pixel. If it’s under 20%, the addressable population is much smaller than assumed and the whole thesis shrinks.
- Assumption: Being shown the finding converts to payment, rather than to a shrug or a call to their existing lawyer. How to test: Send 100 real findings. Measure paid $499 determinations, not replies. Replies are vanity here.
- Assumption: Agencies will buy a tool that surfaces problems they caused. How to test: Free portfolio scan for 15 agencies. Do they pay to keep monitoring after seeing the report, or do they fix the three worst clients and walk?
- Assumption: Classification can hit an accuracy bar that survives professional scrutiny. How to test: Hand-label 100 sites, measure precision on the “in scope” verdict specifically. Below ~95% precision this product is a liability generator.
Risk flags
- Regulatory risk (real, two-sided): A federal preemption bill would flatten the state patchwork and gut the multi-state expansion path. Less dramatically, CT could issue guidance narrowing the sale definition, shrinking the population overnight.
- Incumbent risk: Osano, Enzuzo, Termly and the CMP field all have the distribution and could bolt on a scope verdict. My read is they are structurally reluctant — their funnel assumes the customer already believes they’re covered — but “reluctant” is not “unable.”
- Liability risk: Telling a business it is out of scope, wrongly, is the nightmare scenario. Needs careful framing, insurance, and an attorney relationship. This constrains marketing language permanently.
- Demand-creation risk: This is the one that actually kills it. The pain is undiscovered. Every sale starts by convincing someone they have a problem, which is a materially harder and slower motion than selling to someone already searching. Ideas with this shape convert worse than their regulatory logic suggests.
- Single-state concentration: CT alone probably does not reach $1M comfortably. Multi-state has to work, and earlier than the plan wants it to.
14. Structured verdict
Score: 72/100
Verdict: GO
Confidence: Medium
Best-fit builder: Technical founder who can build an accurate scanner, paired with
a privacy attorney advisor for the rulepack and memo template
Time to revenue: 6–10 weeks (paid determination scan pre-dates the full product)
Capital to launch: $15–25K
Top 3 assumptions to validate first:
1. Scan 200 CT business sites cold — measure what share actually trip a
no-threshold trigger. Under 20% and the population thesis is wrong.
2. Send 100 real findings; measure paid $499 determinations, not replies.
3. Free portfolio scan for 15 agencies; measure whether they subscribe or
just fix their three worst clients and leave.
Kill criteria:
- Abandon if <20% of 200 scanned CT sites trip a no-threshold trigger
- Abandon if <5 paid determinations from 100 delivered findings
- Abandon if classification precision on "in scope" stays below 95% after
a 100-site labelled corpus
- Abandon if a major CMP ships a scope-determination feature before v1
15. Next step — 1-week validation sprint
- Day 1–2: Build the crude scanner — headless browser, tag enumeration, form-field capture. No AI, no polish. Run it against 200 Connecticut business websites pulled from the SoS registry. Count how many capture a sensitive field or fire an ad pixel pre-consent. This single number decides whether the population exists.
- Day 3–4: Hand-write 30 determination memos from the worst findings. Send them to those 30 businesses with a $499 offer for the full determination. Simultaneously, run free portfolio scans for 5 CT agencies and book calls.
- Day 5: Decide. Go if ≥20% of scanned sites trip a trigger AND ≥2 of 30 businesses pay the $499, or ≥1 of 5 agencies commits to a paid pilot. No-go if the population is thin or if the response to a concrete, accurate finding is silence — because if a real finding delivered to the affected party doesn’t move them, nothing later in the funnel will.
The falsifiable part is the 200-site scan. It’s cheap, it’s mechanical, and it can prove me wrong in two days before a line of the real product gets written.
Interested in a detailed proposal?
Get a deep-dive with market research, competitive analysis, and implementation roadmap.
Contact usinfo@startupbasket.ai