CPA § 6-1-1308

Duties of Controllers

Reference only. The Privisy audit does not test this section.

Source
Statute
In force from
May 23, 2025
Last reviewed
September 2026
Framework
CPA

What it requires

Requires controllers to specify processing purposes, minimize data collection, implement data security, avoid processing sensitive data without consent, and provide transparent privacy notices. SB 25-276 (signed 2025-05-23) amended the sensitive-data duty in subsection (7) to read 'process or sell' (the Act already defined processing to include sale), so a controller may not process or sell a consumer's sensitive data (which now includes precise geolocation data) without first obtaining the consumer's consent or, for a known child, the consent of the child's parent or lawful guardian.

Statute text

A controller shall specify the express purposes for which personal data are collected and processed. [...] A controller shall not process or sell a consumer's sensitive data without first obtaining the consumer's consent or, in the case of the processing of personal data concerning a known child, without first obtaining consent from the child's parent or lawful guardian.

Colorado Privacy Act, § 6-1-1308Read the full section from Colorado Attorney General

This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit