Colorado Privacy Act Rules (4 CCR 904-3)

Jurisdiction:
Colorado
enforcing
Effective:
Jul 1, 2023
Authority:
Colorado Attorney General
Official text

Obligations Covered

Human Oversight Risk Assessment

Timeline

MilestoneDateNotes
Rules filedMar 15, 2023Filed with Secretary of State
PublishedMar 25, 20234 CCR 904-3
EffectiveJul 1, 2023Alongside CPA enforcement
General cure period expiredJan 1, 2025Former C.R.S. § 6-1-1311(1)(d)(I) repealed
Minors-specific cure effectiveOct 1, 2025A 60-day cure applies only to §§ 6-1-1305.5, 6-1-1308.5, and 6-1-1309.5 when cure is deemed possible
Minors-specific cure repealsDec 31, 2026Current § 6-1-1311(1)(d)(II) repeal date; this is not a general CPA cure period

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Provisions (2)

Automated Processing Definitions (Rule 2.02)

Copy link to this provision

Obligation:
Human Oversight
enforcing
Effective:
Jul 1, 2023
Risk tier:
all
Scope:
Controllers subject to C.R.S. § 6-1-1304 when processing personal data of statutory consumers, subject to the Act's thresholds and exemptions
sleepercross-domain
These definitions govern profiling within the CPA's controller, personal-data, and statutory-consumer scope. The significant-effects definition includes employment opportunities, but “Consumer” excludes a person acting in a commercial or employment context, a job applicant, and a beneficiary of someone acting in an employment context; C.R.S. § 6-1-1304(2)(k) separately exempts data maintained for employment records purposes. Rule 7.09 creates a distinct employee biometric-identifier consent regime and does not expand Part 9 profiling duties to ordinary employment records. Rule 9.04(B)-(C) applies the three processing definitions to profiling opt-out requests within the CPA’s covered scope.

Requirements

RequirementDetails
Solely Automated ProcessingAutomated processing of Personal Data with no human review, oversight, involvement or intervention (Rule 2.02)
Human Reviewed Automated ProcessingHuman review of automated processing that does not rise to Human Involved Automated Processing; review of output without meaningful consideration is insufficient (Rule 2.02)
Human Involved Automated ProcessingMeaningful consideration of available data used in processing or any output, and authority to change or influence the processing outcome (Rule 2.02)
Profiling opt-out effectFor covered profiling of statutory consumer personal data in furtherance of a decision with legal or similarly significant effects, Rule 9.04(B) requires honoring opt-out requests based on solely or human reviewed processing. Rule 9.04(C) allows a controller to decline a request based on human involved processing, with the required notice and information.
Employment boundary“Employment opportunities” remains one listed significant-effect domain, but the consumer definition excludes the employment context, job applicants, and employment-context beneficiaries, and § 6-1-1304(2)(k) exempts employment records
Separate biometric ruleRule 7.09 separately governs employer consent for employee or prospective-employee biometric identifiers under C.R.S. § 6-1-1314(6)

Penalties

ViolationFine
Per violationUp to USD 20,000 per violation (deceptive trade practice)

Data Protection Assessments for Profiling (Rule 9.06(A)-(B))

Copy link to this provision

Obligation:
Risk Assessment
enforcing
Effective:
Jul 1, 2023
Risk tier:
all
Scope:
Controllers subject to C.R.S. § 6-1-1304 before processing consumer personal data for profiling that presents a reasonably foreseeable risk listed in Rule 9.06(A), subject to statutory thresholds and exemptions
sleepercross-domain
Rule 9.06 applies to covered controllers before processing consumer personal data for profiling that presents a reasonably foreseeable risk listed in C.R.S. § 6-1-1309(2)(a). Rules 9.02 and 9.03 list employment opportunities among significant-effect decision domains, but the statute's Consumer definition excludes an employment context, a job applicant, and an employment-context beneficiary, and § 6-1-1304(2)(k) exempts employment records. Rule 7.09 separately regulates employee biometric identifiers.

Requirements

RequirementDetails
DPA for profilingControllers must conduct and document a Data Protection Assessment before processing consumer personal data for profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact, financial or physical injury, offensive intrusion on privacy, or other substantial injury to consumers (Rule 9.06(A))
Risk evaluationAssess risks to consumers from profiling activities
Mitigation measuresIdentify and document mitigation measures for identified risks
Covers automated decisionsApplies to all three tiers of automated processing defined in Rule 2.02
Employment boundary“Employment opportunities” is a listed significant-effect domain, but ordinary employment-context and job-applicant processing is outside the statutory Consumer definition, and data maintained for employment records purposes is exempt under § 6-1-1304(2)(k)
Separate biometric ruleRule 7.09 employee biometric consent duties are distinct from Part 9 profiling assessments

Penalties

ViolationFine
Per violationUp to USD 20,000 per violation (deceptive trade practice)
Cite this regulation

Permalink: https://everyailaw.com/regulation/colorado-cpa-rules/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Colorado Privacy Act Rules (4 CCR 904-3)”, EveryAILaw.com, Jun 30, 2026. https://everyailaw.com/regulation/colorado-cpa-rules/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.