The Colorado Privacy Act takes effect July 1. Here’s how to get ready.

It’s only April, but 2023 has already been a big year for new and evolving data privacy legislation. In January, the California Privacy Rights Act took effect, expanding and clarifying the rights and obligations within the California Consumer Privacy Act. In addition, exceptions for business-to-business and employee and applicant data expired, ushering in new requirements and broadening the reach of the California laws. At the same time, the second major state data privacy law – the Virginia Consumer Data Protection Act – took full effect.

On July 1, the Colorado Privacy Act and the Connecticut Data Privacy Act will take effect, followed shortly by the Utah Consumer Privacy Act. That doesn’t even cover the new data privacy legislation recently passed in Iowa and Indiana, which we’ll review in future posts.

It can be daunting for consumers and business leaders alike to digest the alphabet soup of emerging data privacy legislation. Many businesses are still recovering from a big push to update consumer disclosures and implement procedures to address their new obligations in California and Virginia. But businesses cannot stop now. With the recent publication of regulations by the Colorado Attorney General’s Office, there is no better time for businesses to review existing disclosures and procedures to confirm compliance with the Colorado law.

Gov. Jared Polis (D) signed Senate Bill 190 into law in July 2021. The Colorado law applies to businesses (called “controllers” in the statute) that collect personal data from more than 100,000 Colorado residents or that collect data from 25,000 or more consumers and derive revenue or receive a discount on goods or services from the sale of that data.

Businesses should confirm that they are making appropriate disclosures to consumers in privacy notices.  Importantly, the Colorado law requires businesses to limit data collection and retention of data, which means that businesses must have strong data retention practices. Moreover, Colorado requires businesses to respond in a timely manner to consumer requests to exercise rights of access, correction, deletion, data portability, and opt-outs for certain transactions.

The recently published  regulations address a few areas of the law that may be less familiar, including the following:

  • Profiling: The CPA and regulations have restrictions and consent requirements on automated processing that evaluates, analyzes, or predicts an individual’s economic situation, health, personal preferences, interests, or behavior.
  • Data Protection Assessments: The CPA requires controllers to conduct a a Data Protection Assessment before processing that presents a “heightened risk of harm” to Colorado residents.
  • Universal opt-out mechanisms: The CPA and its regulations establish the standards for Universal Opt-Out Mechanisms that will be recognized by the Colorado Department of Law, and require controllers to respect opt-outs from any compliant Universal Opt-Out Mechanism.

Businesses subject to the CPA should keep in mind that, in addition to certain opt-out requirements, the law also requires that controllers obtain a consumer’s freely given, specific, informed, and unambiguous consent via a clear, affirmative act before collecting or processing certain sensitive personal data (such as data that reveals race or ethnicity, religious beliefs, a mental or physical health condition or diagnosis, sexual orientation or sex life, citizenship or citizenship status, or genetic or biometric data).

We will continue to keep you up to date on new data privacy laws, whether your state will be affected, and interpretations of the laws.

Looking for additional support to effectively navigate the rapid release of new laws and ensure your organization is compliant?  The Constangy Cyber Team is here to help! We assist businesses of all sizes and industries with building and enhancing their privacy and compliance programs to address these complex and evolving regulatory requirements. Please feel free to contact us directly at breachresponse@constangy.com.

The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation. 

Search

Get Updates By Email

Subscribe

Archives

Jump to Page

Constangy, Brooks, Smith & Prophete, LLP Cookie Preference Center

Your Privacy

When using this website, Constangy and certain third parties may collect and use cookies or similar technologies to enhance your experience. These technologies may collect information about your device, activity on our website, and preferences. Some cookies are essential to site functionality, while others help us analyze performance and usage trends to improve our content and features.

Please note that if you return to this website from a different browser or device, you may need to reselect your cookie preferences.

For more information about our privacy practices, including your rights and choices, please see our Privacy Policy. 

Strictly Necessary Cookies

Always Active

Strictly Necessary Cookies are essential for the website to function, and cannot be turned off. We use this type of cookie for purposes such as security, network management, and accessibility. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the site will not work. 

Functionality Cookies

Always Active

Functionality Cookies are used to enhance the functionality and personalization of this website. These cookies support features like embedded content (such as video or audio), keyword search highlighting, and remembering your preferences across pages—for example, your cookie choices or form inputs during submission.

Some of these cookies are managed by third-party service providers whose features are embedded on our site. These cookies do not store personal information and are necessary for certain site features to work properly.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek