'Most Innovative Startup 2020' by RSA - Watch the video

Learn More

What is Colorado's Privacy Act (CPA)?

Colorado has become the third US State to pass a comprehensive data privacy law. Colorado Privacy Act (CPA) was signed into law on July 8th, 2021. Modelled pretty similarly to the Virginia Data Protection Act (VCDPA) passed earlier this year, the CPA provides comprehensive privacy rights to state residents of Colorado and imposes a new set of obligations and duties on data controllers managing consumer personal information.


Definition of Personal Data

  • Personal data means any information that is linked or reasonably linkable to an identified or identifiable individual.
  • The CPA also categorizes certain data as “Sensitive Personal Data” which includes:
    • Personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life or sexual orientation, or citizenship or citizenship status;
    • Genetic or biometric data that may be processed for the purpose of uniquely identifying an individual; or
    • Personal data from a known child.
  • Publicly available and de-identified personal data are not covered under the law.
  • Certain forms of Personal Data are exempt from the law:
    • Medical data covered under any medical laws: Many forms of health information, records, data and documents protected and covered under HIPAA, or other federal or state medical laws have been exempted.
    • FCRA covered data: Any personal information of consumers collected or used for consumer credit scoring and reporting protected under the federal Fair Credit Report Act (FCRA);
    • Driver data: Personal data collected, processed, sold, or disclosed in compliance with the federal Driver's Privacy Protection Act of 1994;
    • FERPA data: Personal data regulated by the federal Family Educational Rights and Privacy Act (FERPA);
    • Employment data: Personal data maintained for employment records;

Data Subject Rights

All consumers may invoke the following rights by sending a verified request to the data controller (in case of a child, the parent/guardian may send the request on behalf of the child):

Confirm

The consumer shall have a right to confirm whether or not a controller is processing his/her personal data.

Access

The consumer has a right to access the personal data collected and processed about him/her by the data controller.

Rectify

The consumer has a right to have inaccurate personal data being stored or processed by the data controller be corrected.

Delete

The consumer has the right to have his/her personal data stored or processed by the data controller be deleted.

Portability

The consumer has a right to obtain a copy of his/her personal data in a portable, technically feasible and readily usable format that allows the consumer to transmit the data to another controller without hindrance.

Opt-out

The consumer has the right to opt out of the processing of the personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.

  • Time period to fulfill DSR request: All data subject rights’ requests (DSR requests) must be fulfilled by the data controller within a 45 day period.
  • Extension in time period: data controllers may seek for an extension of 45 days in fulfilling the request depending on the complexity and number of the consumer's requests.
  • Denial of DSR request: If a DSR request is to be denied, the data controller must inform the consumer of the reasons within a 45 days period.
  • Appeal against refusal: Consumers have a right to appeal the decision for refusal of grant of the DSR request. The appeal must be decided within 45 days but the time period can be further extended by 60 additional days.
  • Limitation of DSR requests per year: Requests for data portability may be made only twice in a year.
  • Charges: DSR requests must be fulfilled free of charge once in a year. Any subsequent request within a 12 month period can be charged.
  • Authentication: A data controller is not to respond to a consumer request unless it can authenticate the request using reasonably commercial means. A data controller can request additional information from the consumer for the purposes of authenticating the request.

Who must comply?

  • CPA applies to all data controllers who conduct business in Colorado or produce or deliver commercial products or services that are intentionally targeted to residents of Colorado - if they match any one or both of these conditions:
    • If they control or process the personal data of 100,000 consumers or more during a calendar year; or
    • If they derive revenue or receive a discount on the price of goods or services from the sale of personal data and process or control the personal data of 25,000 consumers or more.
  • The following entities are exempt from complying with CPA:
    • GLBA entities: Financial Institutions or data which is subject to the federal Gramm-Leach-Bliley Act (GLBA) 15 U.S.C. SEC. 6801 ET SEQ., as amended, and implementing regulations, including Regulation P, 12 CFR 1016. are exempt.
    • COPPA compliant entities: Controllers and processors that comply with the Children's Online Privacy Protection Act (COPPA) will be deemed to be in compliance with the CPA;
    • Air Carriers: an air carrier as defined in and regulated under 49 U.S.C. SEC. 40101 ET SEQ., as amended, and 49 U.S.C. SEC. 41713 are exempt.
    • National Securities Association: A National Securities Association registered pursuant to the federal "Securities Exchange Act Of 1934", 15 U.S.C. SEC. 78o-3, as amended, or implementing Regulations are exempt.
    • Public Utilities and Authorities: customer data maintained by a public utility as defined in Section 40-1-103 (1)(a)(I) or an authority as defined in Section 43-4-503 (1) is exempt from the law if the data is not collected, maintained, disclosed, sold, communicated, or used except as authorized by state and federal law.
    • State Institution: data maintained by a state institution of higher education, as defined in Section 23-18-102 (10), the state, the judicial department of the state, or a county, city and county, or municipality if the data is collected, maintained, disclosed, communicated, and used as authorized by state and federal law for noncommercial purposes is exempt from the law.

Obligations of Controllers

Transparency

A controller shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice containing specific information including categories of data it shares or sells (including for targeted advertising) and means for consumers to exercise their rights and how they can appeal against the denial of their DSRs.

Accountability

A controller must undertake Data Protection Assessment (DPAs) for each processing activity which poses a heightened risk of harm to consumers, protect deidentified data from reidentification and comply with data subject requests made by consumers as well as ensure data processors it contracts with comply with the duties prescribed under this law.

Purpose Limitation and Data Minimization

Controllers shall not collect unnecessary personal data of consumers or process the personal data for purposes beyond what was disclosed to consumers without gaining their consent.

Non Discrimination

Controllers may not process the personal data to discriminate against the consumer in violation of state or federal laws that prohibit unlawful discrimination against consumers.

Consent Management

Controllers cannot process sensitive personal data or data of minors unless it has the express consent of the consumer or of the parents/guardians of a minor child, respectively.

Data Security

Establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data during both storage and use. Such data security practices shall be appropriate to the volume and nature of the personal data at issue.

Important Exceptions

The CPA does not apply to:

  • Data processed in an employment or commercial (business-to-business) context: Personal data processed by a controller, processor, or third party is exempt from the application of this law:
    • If the individual data subject is acting in a commercial or employment context, as a job applicant, or as a beneficiary of someone acting in an employment context.
    • If the personal data is maintained for employment records purposes.
    • As the emergency contact information of an individual used for emergency contact purposes;
  • Data processed for free speech or household purposes: Nothing in this law applies to information made available by a third party that the controller has a reasonable basis to believe is protected speech pursuant to applicable law or the processing of personal data by an individual in the course of a purely personal or household activity.
  • Data processed for internal purposes: Nothing in this law restricts a controller or processor from processing personal data to conduct internal research to improve or repair products, services, or technology or to identify and repair technical errors that impair existing or intended functionality or to undertake internal operations reasonably aligned with the consumer’s expectations for performance of a service or provision of a product.
  • Data processed for legal obligations: Nothing in this law restricts a controller or processor from complying with other applicable laws, to claim or defend legal claims or cooperate with government authorities or investigations.
  • Data processed to protect vital interests or security: Nothing in this law restricts a controller from processing data for protecting the vital interests of the consumer or of another individual or to prevent, detect, protect against, or respond to security incidents, identity theft, fraud, harassment, or malicious, deceptive, or illegal activity; preserve the integrity or security of systems; or investigate, report, or prosecute those responsible for any such action.
  • Data processed for public health reasons: Nothing in this law restricts controllers from processing personal data for reasons of public interest in the area of public health, but solely to the extent that the processing is subject to suitable and specific measures to safeguard the rights of the consumer whose personal data are processed; and is under the responsibility of a professional subject to confidentiality obligations under federal, state, or local law.

Key Facts

1

The provisions of this act shall become effective on July 1, 2023 unless a referendum petition is filed within 90 days after final adjournment of the general assembly and the people vote for the proposed changes to the act within the referendum at the general election to be held in November 2022. In such a case, the amended provisions will take effect July 1, 2023, or on the date of the official declaration of the vote thereon by the governor, whichever is later.

2

The CPA is structurally very similar to the VCDPA. There are only a few significant differences between the two acts.

3

Data Protection Assessments under the CPA must identify and weigh the benefits that may flow, directly and indirectly, from the processing to the controller, the consumer, other stakeholders, and the public against the potential risks to the rights of the consumer associated with the processing, as mitigated by safeguards that the controller can employ to reduce the risks. It is important to note that the controller shall make the data protection assessments available to the attorney general upon request.

4

The requirement to conduct Data Protection Assessments under the CPA shall apply to processing activities created or generated after July 1, 2023, and is not retroactive.

5

The CPA defines a minor below 13 years of age for the additional protections it provides.

6

There is no 12 months time limit as found in the CPRA or CCPA after which the business can re-ask for the consent of the consumer who chooses to exercise the right to opt-out.

7

The CPA requires that opt-in consent be collected for processing of children’s Personal Data, use of Sensitive Personal Data and use of Personal Data beyond the initial purpose for which it was collected for.

Automating privacy operations across your organization

The multi-disciplinary practice to grow trust-equity of your brand and comply with privacy regulations.

Get the Book

“By leveraging the PrivacyOps constructs from this book across our organization we were able to not only save time and money but also mitigate the risks associated with manual methods of privacy management.”

- Marty Collins, Chief Privacy and Legal Officer, QuinStreet, Inc