CPA § 6-1-1308
Duties of Controllers
Reference only. The Privisy audit does not test this section.
- Source
- Statute
- In force from
- May 23, 2025
- Last reviewed
- September 2026
- Framework
- CPA
What it requires
Requires controllers to specify processing purposes, minimize data collection, implement data security, avoid processing sensitive data without consent, and provide transparent privacy notices. SB 25-276 (signed 2025-05-23) amended the sensitive-data duty in subsection (7) to read 'process or sell' (the Act already defined processing to include sale), so a controller may not process or sell a consumer's sensitive data (which now includes precise geolocation data) without first obtaining the consumer's consent or, for a known child, the consent of the child's parent or lawful guardian.
Statute text
A controller shall specify the express purposes for which personal data are collected and processed. [...] A controller shall not process or sell a consumer's sensitive data without first obtaining the consumer's consent or, in the case of the processing of personal data concerning a known child, without first obtaining consent from the child's parent or lawful guardian.
Colorado Privacy Act, § 6-1-1308Read the full section from Colorado Attorney General
This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.