Colorado Privacy Act
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Colorado Privacy Act: Consumer Rights (6-1-1306)
Consumers have the right to confirm whether a controller is processing their personal data and to access that data.
- Authenticated access-request fulfilment within 45 days (extendable)
- Request log
- Access requests not fulfilled within statutory timeframe
A controller must establish a process for a consumer to appeal a refusal to act on a request and respond within 45 days, informing the consumer how to contact the Attorney General.
- Appeal process + 45-day response records
- AG-contact information provided on appeal denial
- No appeal process
Consumers may correct inaccuracies in their personal data, taking into account the nature and purpose of the processing.
- Correction request procedure + records
- Corrections not actioned
Consumers may delete personal data concerning them.
- Deletion request procedure + downstream propagation to processors
- Deletion not propagated to processors
Consumers may opt out of processing for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
- Opt-out mechanism for sale/targeted-advertising/profiling
- Honouring opt-out preference signals
- No opt-out for sale/targeted advertising/profiling
Consumers may obtain a portable, readily usable copy of their personal data (up to twice per year).
- Portable-copy export mechanism
- No portability mechanism
Colorado Privacy Act: Controller Duties (6-1-1308)
A controller must take reasonable measures to secure personal data from unauthorized acquisition during storage and use, appropriate to the volume and nature of the data.
- Reasonable security measures appropriate to data volume/nature
- No reasonable security safeguards
Consent must be a clear affirmative act that is freely given, specific, informed and unambiguous; agreement obtained through dark patterns does not constitute consent.
- Consent flows free of dark patterns
- Consent records
- Consent obtained via dark patterns
Collection of personal data must be adequate, relevant and limited to what is reasonably necessary for the specified purposes.
- Minimisation review tying collection to specified purposes
- Over-collection beyond stated purpose
A controller may not process personal data in violation of state or federal anti-discrimination laws, and may not process for unlawfully discriminatory purposes.
- Anti-discrimination review of processing
- Processing for unlawfully discriminatory purposes
A controller must specify the express purposes for which personal data is collected and processed.
- Documented express purposes per data category
- Purposes unspecified
A controller may not process personal data for purposes not reasonably necessary to or compatible with the specified purposes without consent.
- Secondary-use assessment + consent records where required
- Incompatible secondary use without consent
A controller may not process sensitive data without first obtaining the consumer's consent (or, for a known child, consent in accordance with COPPA).
- Sensitive-data consent capture records
- Child-data consent per COPPA
- Sensitive data processed without consent
A controller must provide a reasonably accessible, clear and meaningful privacy notice (categories of data, purposes, rights and how to exercise/appeal, categories shared/sold, opt-out method).
- Published privacy notice covering the 1308(1) elements
- Opt-out method disclosed in the notice
- Privacy notice missing required elements
Colorado Privacy Act: Enforcement and Rules (6-1-1310 to 1313)
Where controllers and processors each comply with their obligations, liability is allocated according to each party's responsibility for the violating processing.
- Liability-allocation terms in contracts
- Unclear liability allocation between controller and processor
A violation is a deceptive trade practice under the Colorado Consumer Protection Act, enforceable exclusively by the Attorney General and district attorneys; there is no private right of action.
- Awareness of AG/DA enforcement + CCPA deceptive-practice exposure
- Cure-period procedures (where applicable)
- No legal-exposure assessment
The Attorney General promulgates rules (4 CCR 904-3) detailing the universal opt-out mechanism that controllers must recognise and other implementation requirements.
- Recognition of the AG-specified universal opt-out mechanism
- Monitoring of AG rules (4 CCR 904-3)
- Universal opt-out mechanism not honoured
Colorado Privacy Act: Processor and Assessments (6-1-1305/1309)
Processing by a processor must be governed by a contract that sets out instructions, nature/purpose, data types, duration, and obligations (confidentiality, sub-processor flow-down, deletion/return, audits, assistance).
- Controller-processor contracts with the 1305 terms
- Sub-processor flow-down + audit rights
- No CPA-compliant processor contract
A controller must conduct and document a data protection assessment for processing that presents a heightened risk of harm: targeted advertising, sale, profiling with specified risks, and processing sensitive data; the AG may require its disclosure.
- Data protection assessments for heightened-risk processing
- Assessment retention + AG-disclosure readiness
- No DPA for targeted advertising/profiling/sensitive-data processing
Colorado Privacy Act: Scope and Definitions (6-1-1303/1304/1307)
Defines consumer, controller, processor, personal data, sensitive data (racial/ethnic origin, religious beliefs, mental/physical health condition or diagnosis, sex life or sexual orientation, citizenship/immigration status, genetic/biometric data, and personal data of a known child), sale, targeted advertising, profiling and consent.
- Data inventory mapping CPA categories incl. sensitive data
- Identification of sale/targeted-advertising/profiling activities
- Sensitive-data categories not identified
- Sale/targeted-advertising not assessed
Applies to a controller that conducts business in Colorado or targets Colorado residents and either controls/processes the personal data of 100,000+ consumers per year, or derives revenue or receives a discount from selling personal data and processes 25,000+ consumers' data; lists entity/data exemptions (e.g. GLBA, HIPAA, FCRA).
- Applicability determination against the CPA thresholds
- Exemption analysis (GLBA/HIPAA/FCRA etc.)
- Applicability/exemptions not assessed
A controller in possession of de-identified data must take measures to prevent re-identification, publicly commit to maintaining de-identification, and contractually obligate recipients to comply; rights do not apply to de-identified data.
- De-identification controls + public commitment
- Contractual de-identification obligations on recipients
- Claimed de-identified data is re-identifiable
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Colorado Privacy Act framework page.