Colorado Privacy Act Rules (4 CCR 904-3)
Obligations Covered
Timeline
| Milestone | Date | Notes |
|---|---|---|
| Rules filed | Mar 15, 2023 | Filed with Secretary of State |
| Published | Mar 25, 2023 | 4 CCR 904-3 |
| Effective | Jul 1, 2023 | Alongside CPA enforcement |
| General cure period expired | Jan 1, 2025 | Former C.R.S. § 6-1-1311(1)(d)(I) repealed |
| Minors-specific cure effective | Oct 1, 2025 | A 60-day cure applies only to §§ 6-1-1305.5, 6-1-1308.5, and 6-1-1309.5 when cure is deemed possible |
| Minors-specific cure repeals | Dec 31, 2026 | Current § 6-1-1311(1)(d)(II) repeal date; this is not a general CPA cure period |
Related Regulations and Standards
Related instruments are selected from shared compliance obligations and jurisdiction coverage.
Provisions (2)
Automated Processing Definitions (Rule 2.02)
These definitions govern profiling within the CPA's controller, personal-data, and statutory-consumer scope. The significant-effects definition includes employment opportunities, but “Consumer” excludes a person acting in a commercial or employment context, a job applicant, and a beneficiary of someone acting in an employment context; C.R.S. § 6-1-1304(2)(k) separately exempts data maintained for employment records purposes. Rule 7.09 creates a distinct employee biometric-identifier consent regime and does not expand Part 9 profiling duties to ordinary employment records. Rule 9.04(B)-(C) applies the three processing definitions to profiling opt-out requests within the CPA’s covered scope.
Requirements
| Requirement | Details |
|---|---|
| Solely Automated Processing | Automated processing of Personal Data with no human review, oversight, involvement or intervention (Rule 2.02) |
| Human Reviewed Automated Processing | Human review of automated processing that does not rise to Human Involved Automated Processing; review of output without meaningful consideration is insufficient (Rule 2.02) |
| Human Involved Automated Processing | Meaningful consideration of available data used in processing or any output, and authority to change or influence the processing outcome (Rule 2.02) |
| Profiling opt-out effect | For covered profiling of statutory consumer personal data in furtherance of a decision with legal or similarly significant effects, Rule 9.04(B) requires honoring opt-out requests based on solely or human reviewed processing. Rule 9.04(C) allows a controller to decline a request based on human involved processing, with the required notice and information. |
| Employment boundary | “Employment opportunities” remains one listed significant-effect domain, but the consumer definition excludes the employment context, job applicants, and employment-context beneficiaries, and § 6-1-1304(2)(k) exempts employment records |
| Separate biometric rule | Rule 7.09 separately governs employer consent for employee or prospective-employee biometric identifiers under C.R.S. § 6-1-1314(6) |
Penalties
| Violation | Fine |
|---|---|
| Per violation | Up to USD 20,000 per violation (deceptive trade practice) |
Data Protection Assessments for Profiling (Rule 9.06(A)-(B))
Rule 9.06 applies to covered controllers before processing consumer personal data for profiling that presents a reasonably foreseeable risk listed in C.R.S. § 6-1-1309(2)(a). Rules 9.02 and 9.03 list employment opportunities among significant-effect decision domains, but the statute's Consumer definition excludes an employment context, a job applicant, and an employment-context beneficiary, and § 6-1-1304(2)(k) exempts employment records. Rule 7.09 separately regulates employee biometric identifiers.
Requirements
| Requirement | Details |
|---|---|
| DPA for profiling | Controllers must conduct and document a Data Protection Assessment before processing consumer personal data for profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact, financial or physical injury, offensive intrusion on privacy, or other substantial injury to consumers (Rule 9.06(A)) |
| Risk evaluation | Assess risks to consumers from profiling activities |
| Mitigation measures | Identify and document mitigation measures for identified risks |
| Covers automated decisions | Applies to all three tiers of automated processing defined in Rule 2.02 |
| Employment boundary | “Employment opportunities” is a listed significant-effect domain, but ordinary employment-context and job-applicant processing is outside the statutory Consumer definition, and data maintained for employment records purposes is exempt under § 6-1-1304(2)(k) |
| Separate biometric rule | Rule 7.09 employee biometric consent duties are distinct from Part 9 profiling assessments |
Penalties
| Violation | Fine |
|---|---|
| Per violation | Up to USD 20,000 per violation (deceptive trade practice) |
Cite this regulation
Permalink: https://everyailaw.com/regulation/colorado-cpa-rules/
JSON: https://everyailaw.com/api/v1/regulations.json
Attribution: EveryAILaw, PAICE.work PBC. “Colorado Privacy Act Rules (4 CCR 904-3)”, EveryAILaw.com, Jun 30, 2026. https://everyailaw.com/regulation/colorado-cpa-rules/
Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.