Law note · Colorado
SB 21-190, Colorado Privacy Act (CPA)
Colorado's omnibus data-privacy statute requires a controller that conducts business in or intentionally targets Colorado residents, and meets a 100,000-consumer or a 25,000-consumer-plus-sale-revenue threshold, to give consumers notice, minimize collection, obtain affirmative opt-in consent before processing sensitive data or resuming processing after an opt-out, and honor rights to access, correct, delete, and port personal data.
Processors must follow controller instructions and assist with compliance, and a controller must complete a data protection assessment before processing that presents a heightened risk of harm.
What it asks of an app
- If you process the personal data of Colorado residents at the qualifying volume thresholds, give clear privacy notice and honor consumer requests to access, correct, delete, and port their data within 45 days.
- Obtain the consumer's affirmative opt-in consent before processing sensitive data, including biometric data used for identification, or before resuming processing for targeted advertising or sale after a consumer opts out.
- Offer consumers a way to opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects, and complete a data protection assessment before processing that presents a heightened risk of harm.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics
Primary source: Official session law text (2021 Colo. Sess. Laws ch. 483, enrolled SB 21-190) and the Colorado General Assembly's official bill page