Skip to content

Evidence request lists

Colorado Privacy Act

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Colorado Privacy Act: Consumer Rights (6-1-1306)

COPA-1306-ACCESS
Right of Access

Consumers have the right to confirm whether a controller is processing their personal data and to access that data.

Artefacts an auditor will ask for
  • Authenticated access-request fulfilment within 45 days (extendable)
  • Request log
Where this commonly fails
  • Access requests not fulfilled within statutory timeframe
COPA-1306-APPEAL
Right to Appeal

A controller must establish a process for a consumer to appeal a refusal to act on a request and respond within 45 days, informing the consumer how to contact the Attorney General.

Artefacts an auditor will ask for
  • Appeal process + 45-day response records
  • AG-contact information provided on appeal denial
Where this commonly fails
  • No appeal process
COPA-1306-CORRECT
Right to Correction

Consumers may correct inaccuracies in their personal data, taking into account the nature and purpose of the processing.

Artefacts an auditor will ask for
  • Correction request procedure + records
Where this commonly fails
  • Corrections not actioned
COPA-1306-DELETE
Right to Deletion

Consumers may delete personal data concerning them.

Artefacts an auditor will ask for
  • Deletion request procedure + downstream propagation to processors
Where this commonly fails
  • Deletion not propagated to processors
COPA-1306-OPTOUT
Right to Opt Out

Consumers may opt out of processing for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.

Artefacts an auditor will ask for
  • Opt-out mechanism for sale/targeted-advertising/profiling
  • Honouring opt-out preference signals
Where this commonly fails
  • No opt-out for sale/targeted advertising/profiling
COPA-1306-PORTABILITY
Right to Data Portability

Consumers may obtain a portable, readily usable copy of their personal data (up to twice per year).

Artefacts an auditor will ask for
  • Portable-copy export mechanism
Where this commonly fails
  • No portability mechanism

Colorado Privacy Act: Controller Duties (6-1-1308)

COPA-1308-CARE
Duty of Care (Security)

A controller must take reasonable measures to secure personal data from unauthorized acquisition during storage and use, appropriate to the volume and nature of the data.

Artefacts an auditor will ask for
  • Reasonable security measures appropriate to data volume/nature
Where this commonly fails
  • No reasonable security safeguards
COPA-1308-CONSENT
Valid Consent and Dark Patterns

Consent must be a clear affirmative act that is freely given, specific, informed and unambiguous; agreement obtained through dark patterns does not constitute consent.

Artefacts an auditor will ask for
  • Consent flows free of dark patterns
  • Consent records
Where this commonly fails
  • Consent obtained via dark patterns
COPA-1308-MINIMIZATION
Duty of Data Minimization

Collection of personal data must be adequate, relevant and limited to what is reasonably necessary for the specified purposes.

Artefacts an auditor will ask for
  • Minimisation review tying collection to specified purposes
Where this commonly fails
  • Over-collection beyond stated purpose
COPA-1308-NONDISCRIM
Duty to Avoid Unlawful Discrimination

A controller may not process personal data in violation of state or federal anti-discrimination laws, and may not process for unlawfully discriminatory purposes.

Artefacts an auditor will ask for
  • Anti-discrimination review of processing
Where this commonly fails
  • Processing for unlawfully discriminatory purposes
COPA-1308-PURPOSE
Duty of Purpose Specification

A controller must specify the express purposes for which personal data is collected and processed.

Artefacts an auditor will ask for
  • Documented express purposes per data category
Where this commonly fails
  • Purposes unspecified
COPA-1308-SECONDARY
Duty to Avoid Secondary Use

A controller may not process personal data for purposes not reasonably necessary to or compatible with the specified purposes without consent.

Artefacts an auditor will ask for
  • Secondary-use assessment + consent records where required
Where this commonly fails
  • Incompatible secondary use without consent
COPA-1308-SENSITIVE
Duty Regarding Sensitive Data

A controller may not process sensitive data without first obtaining the consumer's consent (or, for a known child, consent in accordance with COPPA).

Artefacts an auditor will ask for
  • Sensitive-data consent capture records
  • Child-data consent per COPPA
Where this commonly fails
  • Sensitive data processed without consent
COPA-1308-TRANSPARENCY
Duty of Transparency (Privacy Notice)

A controller must provide a reasonably accessible, clear and meaningful privacy notice (categories of data, purposes, rights and how to exercise/appeal, categories shared/sold, opt-out method).

Artefacts an auditor will ask for
  • Published privacy notice covering the 1308(1) elements
  • Opt-out method disclosed in the notice
Where this commonly fails
  • Privacy notice missing required elements

Colorado Privacy Act: Enforcement and Rules (6-1-1310 to 1313)

COPA-1310-LIABILITY
Liability and Processor Allocation

Where controllers and processors each comply with their obligations, liability is allocated according to each party's responsibility for the violating processing.

Artefacts an auditor will ask for
  • Liability-allocation terms in contracts
Where this commonly fails
  • Unclear liability allocation between controller and processor
COPA-1311-ENFORCE
Enforcement by the Attorney General and District Attorneys

A violation is a deceptive trade practice under the Colorado Consumer Protection Act, enforceable exclusively by the Attorney General and district attorneys; there is no private right of action.

Artefacts an auditor will ask for
  • Awareness of AG/DA enforcement + CCPA deceptive-practice exposure
  • Cure-period procedures (where applicable)
Where this commonly fails
  • No legal-exposure assessment
COPA-1313-RULES
Rules and Universal Opt-Out Mechanism

The Attorney General promulgates rules (4 CCR 904-3) detailing the universal opt-out mechanism that controllers must recognise and other implementation requirements.

Artefacts an auditor will ask for
  • Recognition of the AG-specified universal opt-out mechanism
  • Monitoring of AG rules (4 CCR 904-3)
Where this commonly fails
  • Universal opt-out mechanism not honoured

Colorado Privacy Act: Processor and Assessments (6-1-1305/1309)

COPA-1305-PROCESSOR
Processor Contracts and Role Responsibility

Processing by a processor must be governed by a contract that sets out instructions, nature/purpose, data types, duration, and obligations (confidentiality, sub-processor flow-down, deletion/return, audits, assistance).

Artefacts an auditor will ask for
  • Controller-processor contracts with the 1305 terms
  • Sub-processor flow-down + audit rights
Where this commonly fails
  • No CPA-compliant processor contract
COPA-1309-DPA
Data Protection Assessments

A controller must conduct and document a data protection assessment for processing that presents a heightened risk of harm: targeted advertising, sale, profiling with specified risks, and processing sensitive data; the AG may require its disclosure.

Artefacts an auditor will ask for
  • Data protection assessments for heightened-risk processing
  • Assessment retention + AG-disclosure readiness
Where this commonly fails
  • No DPA for targeted advertising/profiling/sensitive-data processing

Colorado Privacy Act: Scope and Definitions (6-1-1303/1304/1307)

COPA-1303-DEF
Definitions

Defines consumer, controller, processor, personal data, sensitive data (racial/ethnic origin, religious beliefs, mental/physical health condition or diagnosis, sex life or sexual orientation, citizenship/immigration status, genetic/biometric data, and personal data of a known child), sale, targeted advertising, profiling and consent.

Artefacts an auditor will ask for
  • Data inventory mapping CPA categories incl. sensitive data
  • Identification of sale/targeted-advertising/profiling activities
Where this commonly fails
  • Sensitive-data categories not identified
  • Sale/targeted-advertising not assessed
COPA-1304-SCOPE
Applicability and Thresholds

Applies to a controller that conducts business in Colorado or targets Colorado residents and either controls/processes the personal data of 100,000+ consumers per year, or derives revenue or receives a discount from selling personal data and processes 25,000+ consumers' data; lists entity/data exemptions (e.g. GLBA, HIPAA, FCRA).

Artefacts an auditor will ask for
  • Applicability determination against the CPA thresholds
  • Exemption analysis (GLBA/HIPAA/FCRA etc.)
Where this commonly fails
  • Applicability/exemptions not assessed
COPA-1307-DEIDENT
De-identified and Pseudonymous Data

A controller in possession of de-identified data must take measures to prevent re-identification, publicly commit to maintaining de-identification, and contractually obligate recipients to comply; rights do not apply to de-identified data.

Artefacts an auditor will ask for
  • De-identification controls + public commitment
  • Contractual de-identification obligations on recipients
Where this commonly fails
  • Claimed de-identified data is re-identifiable
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Colorado Privacy Act framework page.