August 08, 2021 By Colin J. Zick
Categories: Legislation & Regulation , Retail Industry & Customer Information Spotlight , State Laws , CCPA , CPRA
On July 7, 2021, Governor Jared Polis signed into law the Colorado Privacy Act (CPA), making Colorado the most recent state to enact comprehensive privacy legislation. While the CPA does not take effect until July 1, 2023, it contains robust provisions that businesses will need some time to prepare for.
The CPA draws many principles from and has a similar framework to the California Consumer Privacy Act (CCPA), California Privacy Rights and Enforcement Act (CPRA), and Virginia Consumer Protection Data Act (VCDPA), but there are some important differences in the CPA.
Overview
Similar to the CPRA and the VCDPA, the CPA gives consumers the right to access and control certain types of personal data that businesses collect and maintain by:
The CPA affords consumers in Colorado five specific data rights:
Businesses must respond to consumer requests asserting these rights within 45 days.
The CPA also contains a number of affirmative duties on businesses:
to not process personal data for purposes that are not “reasonably necessary or compatible with the specific purpose” for its collection and processing;
Covered businesses also must conduct data protection assessments for processing that involves heightened risk activities, such as targeted advertising, profiling, selling data, and processing sensitive data. They also must comply with requests by the Colorado Attorney General to give access to the assessments.
The Colorado Attorney General and state district attorneys share the power of enforcement, and the CPA does not provide for a private right of action.
Businesses covered by the law
The CPA does not apply to every business. It only applies to entities that:
Exemptions and Exceptions
While the CPA's enumerated consumer rights are broad, there are numerous types of data excluded from its scope, and several exemptions. Primarily, there is an exemption for financial institutions subject to the Gramm-Leach-Bliley Act and for Colorado's higher education institutions. The CPA also exempts “data maintained for employment purposes.” The CPA will not cover information subject to FCRA, COPPA, and FERPA. Additionally, the CPA will not cover de-identified data that cannot be linked to an identifiable person and exempts HIPAA-regulated data and data under covered entities and health care facilities and providers.
The definition of “consumers” in the CPA is limited to individuals who are Colorado residents “acting in an individual or household context” and similar to the approach of the CDPA, the definition does not include “an individual acting in a commercial or employment context, as a job applicant, or as a beneficiary of someone acting in an employment context.”
The CPA has a relatively broad definition of “sale,” but carves out a number of types of data disclosures within the definition to limit the scope that are similar to those of the CDPA. The CPA defines “sale” as “the exchange of personal data for monetary or other valuable consideration.” These “sales” do not include disclosure of personal data to a processor that processes data for the controller, the disclosure to a third party for service requested by the consumer, disclosure to an affiliate, disclosure to a third party that proposed or actual transaction where the party assumes control of the controller's assets, a disclosure requested by the consumer to a third party, or disclosure of data that a consumer intentionally made available to the general public via a channel of mass media.
Other Notable Differences between the CPA, VCDPA, CCPA and CPRA
The Colorado, California and Virginia consumer privacy laws also have different definitions for “sensitive information” and how businesses must treat that data. Each requires businesses that collect sensitive data to first obtain consumer consent. However, the CPA provides a stricter definition of consent, requiring consent to be “freely given, specific, informed and unambiguous agreement” which does not include general or broad terms, “hovering over, muting, pausing, or closing a given piece of content,” or “agreement obtained through dark patterns” (although “dark patterns” is not defined).
Changes May Be Coming
There may be some changes made to the CPA before it becomes effective in 2023. Governor Jared Polis noted that the Act needs clean-up legislation in the next year and still has “several issues outstanding,” so watch this space for future developments.
*Many thanks to summer associate, Dania Keller, for providing us with the underlying research for this post.