On October 10, 2022, the Colorado Secretary of State published draft rules for the Colorado Privacy Act (ColoPA) in the Colorado Register, thus initiating a public comment period that will run through February 1, 2023.1 The draft rules generally cover the topics that the Colorado Attorney General’s Office identified in the April 2022 “Pre-Rulemaking Considerations for the Colorado Privacy Act” and add additional details to the ColoPA’s statutory requirements.

Notable proposed requirements under the ColoPA draft rules include the following:

  • Universal Opt-Out Mechanism. The ColoPA draft rules provide considerably more guidance on recognizing and honoring user-selected Universal Opt-out Mechanisms (UOOMs) than the California Privacy Rights Act (CPRA) draft regulations. For example, the draft rules provide greater certainty for controllers about the types of signals they should recognize as the Colorado Department of Law will maintain a list of approved UOOMs that meet the standards of the ColoPA and the draft rules. The first such approved UOOM list would be released by April 1, 2024. Additionally, the draft rules would permit the UOOM to operate through means other than an opt-out signal, for example, by maintaining a “do not sell list” so long as controllers are able to query the list in an automated manner.
  • Privacy Notices. The ColoPA draft rules would not require controllers to create separate, Colorado-specific privacy notices or sections of a privacy notice, provided all ColoPA requirements are met and that the notice makes clear the rights to which Colorado consumers are entitled. Nevertheless, the ColoPA draft rules contain privacy notice disclosure requirements that would be more prescriptive than those identified in the ColoPA statute. Specifically, the ColoPA draft rules are centered on disclosures of specific “processing purposes.” In particular, controllers would have to list the categories of personal data processed for each of the controller’s processing purposes, as well as the categories of third parties to whom the controller sells or shares personal data for each processing purpose.
  • Data Minimization. To ensure personal data are not kept longer than necessary, adequate, or relevant, the ColoPA draft rules would require controllers to “set specific time limits for erasure or to conduct a periodic review.” Additionally, controllers would be obligated to review Biometric Identifiers (a newly defined term) and personal data generated from a digital or physical photograph or an audio or video recording at least once a year to determine if storage is still necessary, adequate, or relevant to the express processing purposes. What’s more, each year after the first year any such data is stored, a controller would have to obtain renewed consent to continue processing that data.
  • Sensitive Data. As noted above, under the ColoPA statute, controllers must obtain consent to process a consumer’s sensitive data. The ColoPA draft rules extend this consent requirement to “Sensitive Data Inferences,” a newly defined term that generally refers to inferences drawn from personal data that indicate an individual’s racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life or sexual orientation, or citizenship or citizenship status. Controllers can process such inferences without consent if four conditions are met: 1) the purpose of the processing would be obvious to a reasonable consumer based on the context of the collection and use of the personal data, and the relationship between the controller and consumer; 2) the personal data and sensitive data inferences are permanently deleted within 12 hours of collection, or the completion of the processing activity, whichever comes first; 3) the personal data and sensitive data inferences are not transferred, sold, or shared with any processors, affiliates, or third parties; and 4) the personal data and sensitive data inferences are not processed for any purpose other than the express purpose disclosed to the consumer.
  • Data Protection Assessments. The ColoPA draft rules provide a number of specific requirements for conducting “data protection assessments.” Nevertheless, the ColoPA draft rules clarify that a data protection assessment conducted by a controller for the purpose of complying with another jurisdiction’s law or regulation will satisfy the requirements of the ColoPA if the data protection assessment is reasonably similar in scope and effect as required by the ColoPA. Data protection assessments would have to be reviewed and updated periodically, except that data protection assessments containing processing for profiling in furtherance of decisions that produce legal or similarly significant effects must be reviewed and updated annually. Data protection assessments are required for activities conducted after July 1, 2023, and they are not retroactive. Controllers must make data protection assessments available to the Attorney General within 30 days of a request.
  • Profiling. The ColoPA draft rules provide a number of requirements that must be addressed in the controller’s privacy policy if the controller uses consumers’ personal data for profiling in furtherance of decisions that produce legal or other similarly significant effects concerning the consumers. Controllers would have to provide consumers with the right to opt out of such profiling, unless the profiling is based on human involved automated processing, in which case the controller would have to provide the consumer with additional information as provided in the ColoPA draft rules. The opt-out method would have to be clear and conspicuous, both in the privacy policy and in a location outside of the privacy policy.
  • Methods for Submitting Requests. Similar to the CPRA draft regulations, the ColoPA draft rules provide that, unless a controller operates exclusively online and has a direct relationship with a consumer, the controller must provide two or more designated methods for submitting requests. The ColoPA draft rules state that the request method does not have to be specific to Colorado, however, so long as the method, among other things, clearly indicates which rights are available to Colorado consumers, provides all data rights to Colorado consumers, and provides Colorado consumers a clear understanding of how to exercise their rights. Therefore, companies may be able to leverage their existing consumer request processes, such as those used to accept California Consumer Privacy Act (CCPA) requests.

Next Steps

The draft rules are now available for public comment through February 1, 2023. Written comments can be submitted through the Colorado Attorney General’s online comment portal.

On February 1, 2023, the Colorado Attorney General’s office will hold a public hearing on the proposed regulations; however, there will also be three virtual stakeholder meetings to discuss the ColoPA draft rules on November 10, 15, and 17 on specific topics.

We encourage businesses affected by the ColoPA proposed regulations to submit comments. Wilson Sonsini Goodrich & Rosati routinely helps companies navigate complex privacy and data security issues. For more information or advice concerning your ColoPA compliance efforts, please contact Tracy ShapiroManeesha MithalEddie HolmanClinton OxfordHale Melnick, or any member of the firm’s privacy and cybersecurity practice.

[1] We previously covered the Colorado Attorney General’s roadmap for the rulemaking process and pre-rulemaking considerations in Wilson Sonsini Alerts, “Colorado Attorney General Announces Privacy Rulemaking” and “Colorado Attorney General Issues Pre-Rulemaking Considerations for the Colorado Privacy Act.” We also provided an overview of the ColoPA’s key requirements in another Wilson Sonsini Alert, “Colorado Becomes Third State to Pass New General Privacy Law.”

[2] Although the draft rules suggest that controllers must obtain ColoPA-compliant consent for sensitive data collected prior to July 1, 2023, by January 1, 2023, we think that the draft rules intended to provide a forward-looking period by which consent needs to be obtained–i.e., by January 1, 2024.