Does Colorado Privacy Act Rules (4 CCR 904-3) require Risk Assessment?

Colorado • enforcing

Yes — 1 provision

Requirements at a glance

This regulation imposes 6 specific requirements for Risk Assessment across 1 provision:

Data Protection Assessments for Profiling (Rule 9.06(A)-(B))

Copy link to this provision

Obligation:
Risk Assessment
enforcing
Effective:
Jul 1, 2023
Risk tier:
all
Scope:
Controllers subject to C.R.S. § 6-1-1304 before processing consumer personal data for profiling that presents a reasonably foreseeable risk listed in Rule 9.06(A), subject to statutory thresholds and exemptions
sleepercross-domain
Rule 9.06 applies to covered controllers before processing consumer personal data for profiling that presents a reasonably foreseeable risk listed in C.R.S. § 6-1-1309(2)(a). Rules 9.02 and 9.03 list employment opportunities among significant-effect decision domains, but the statute's Consumer definition excludes an employment context, a job applicant, and an employment-context beneficiary, and § 6-1-1304(2)(k) exempts employment records. Rule 7.09 separately regulates employee biometric identifiers.

Requirements

RequirementDetails
DPA for profilingControllers must conduct and document a Data Protection Assessment before processing consumer personal data for profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact, financial or physical injury, offensive intrusion on privacy, or other substantial injury to consumers (Rule 9.06(A))
Risk evaluationAssess risks to consumers from profiling activities
Mitigation measuresIdentify and document mitigation measures for identified risks
Covers automated decisionsApplies to all three tiers of automated processing defined in Rule 2.02
Employment boundary“Employment opportunities” is a listed significant-effect domain, but ordinary employment-context and job-applicant processing is outside the statutory Consumer definition, and data maintained for employment records purposes is exempt under § 6-1-1304(2)(k)
Separate biometric ruleRule 7.09 employee biometric consent duties are distinct from Part 9 profiling assessments

Penalties

ViolationFine
Per violationUp to USD 20,000 per violation (deceptive trade practice)
View full regulation View obligation Obligation matrix