CPA § 6-1-1309

Data Protection Assessments

Reference only. The Privisy audit does not test this section.

Source
Statute
In force from
July 1, 2023
Last reviewed
September 2026
Framework
CPA

What it requires

Mandates controllers to conduct data protection assessments for processing activities presenting a heightened risk of harm to consumers, such as targeted advertising, sale of personal data, or profiling.

Statute text

A controller shall not conduct processing that presents a heightened risk of harm to a consumer without conducting and documenting a data protection assessment of each of its processing activities that involve personal data acquired on or after July 1, 2023, that present a heightened risk of harm to a consumer.

Colorado Privacy Act, § 6-1-1309Read the full section from Colorado Attorney General

This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit