Does Colorado Privacy Act Rules (4 CCR 904-3) require Risk Assessment?
Colorado • enforcing
Yes — 1 provision
Requirements at a glance
This regulation imposes 6 specific requirements for Risk Assessment across 1 provision:
- DPA for profiling — Controllers must conduct and document a Data Protection Assessment before processing consumer personal data for profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact, financial or physical injury, offensive intrusion on privacy, or other substantial injury to consumers (Rule 9.06(A))
- Risk evaluation — Assess risks to consumers from profiling activities
- Mitigation measures — Identify and document mitigation measures for identified risks
- Covers automated decisions — Applies to all three tiers of automated processing defined in Rule 2.02
- Employment boundary — “Employment opportunities” is a listed significant-effect domain, but ordinary employment-context and job-applicant processing is outside the statutory Consumer definition, and data maintained for employment records purposes is exempt under § 6-1-1304(2)(k)
- Separate biometric rule — Rule 7.09 employee biometric consent duties are distinct from Part 9 profiling assessments
Data Protection Assessments for Profiling (Rule 9.06(A)-(B))
Rule 9.06 applies to covered controllers before processing consumer personal data for profiling that presents a reasonably foreseeable risk listed in C.R.S. § 6-1-1309(2)(a). Rules 9.02 and 9.03 list employment opportunities among significant-effect decision domains, but the statute's Consumer definition excludes an employment context, a job applicant, and an employment-context beneficiary, and § 6-1-1304(2)(k) exempts employment records. Rule 7.09 separately regulates employee biometric identifiers.
Requirements
| Requirement | Details |
|---|---|
| DPA for profiling | Controllers must conduct and document a Data Protection Assessment before processing consumer personal data for profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact, financial or physical injury, offensive intrusion on privacy, or other substantial injury to consumers (Rule 9.06(A)) |
| Risk evaluation | Assess risks to consumers from profiling activities |
| Mitigation measures | Identify and document mitigation measures for identified risks |
| Covers automated decisions | Applies to all three tiers of automated processing defined in Rule 2.02 |
| Employment boundary | “Employment opportunities” is a listed significant-effect domain, but ordinary employment-context and job-applicant processing is outside the statutory Consumer definition, and data maintained for employment records purposes is exempt under § 6-1-1304(2)(k) |
| Separate biometric rule | Rule 7.09 employee biometric consent duties are distinct from Part 9 profiling assessments |
Penalties
| Violation | Fine |
|---|---|
| Per violation | Up to USD 20,000 per violation (deceptive trade practice) |