# 4 CCR 904-3: COLORADO PRIVACY ACT RULES

> Colorado · Regulations · In force

URL: https://www.frixlaw.com/law-library/statutes/STATE_CO_CCR_4_CCR_904_3

## Section

- **Citation:** 4 CCR 904-3
- **Heading:** COLORADO PRIVACY ACT RULES
- **Jurisdiction:** Colorado
- **Kind:** Regulations
- **Status:** In force
- **Text as of:** August 14, 2026
- **Source:** Compiled text
- **Location:** Code of Colorado Regulations / 900 Department of Law / 904 Attorney General-Consumer Protection Section / 4 CCR 904-3

## Text

1
DEPARTMENT OF LAW
Attorney General-Consumer Protection Section
COLORADO PRIVACY ACT RULES
4 CCR 904-3
[Editor’s Notes follow the text of the rules at the end of this CCR Document.]
_________________________________________________________________________
PART 1
GENERAL APPLICABILITY
Rule 1.01
BASIS, SPECIFIC STATUTORY AUTHORITY, AND PURPOSE
The rules in this Part 904-3 are developed pursuant to C.R.S. § 6-1-108(1), which grants the Attorney
General the authority to promulgate such rules as may be necessary to administer the provisions of the
Colorado Consumer Protection Act, and to C.R.S. § 6-1-1313, which: (1) gives the Attorney General
authority to promulgate rules for the purpose of carrying out the Colorado Privacy Act; (2) requires the
Attorney General to adopt rules that detail the technical specifications for one or more Universal Opt-Out
Mechanisms that clearly communicate a Consumer’s affirmative, freely given, and unambiguous choice to
opt out of the Processing of Personal Data for purposes of Targeted Advertising or the Sale of Personal
Data pursuant to C.R.S. §§ 6-1-1306(1)(a)(I)(A) or (1)(a)(I)(B); and (3) gives the Attorney General the
authority to adopt rules that govern the process of issuing opinion letters and interpretive guidance to
develop an operational framework for business that includes a good faith reliance defense of an action
that may otherwise constitute a violation of Part 13. Effective July 1, 2025, these rules are also developed
pursuant to C.R.S. § 6-1-1314(7), which gives the Colorado Department of Law the authority to
promulgate rules for the implementation of C.R.S. § 6-1-1314.
These rules are promulgated to establish implementation and operational guidelines for the Colorado
Privacy Act, and to help ensure that the Colorado Privacy Act is carried out in a way that is consistent
with the intent of the General Assembly, as reflected in the legislative declaration at C.R.S. § 6-1-1302
ent of Law the authority to
promulgate rules for the implementation of C.R.S. § 6-1-1314.
These rules are promulgated to establish implementation and operational guidelines for the Colorado
Privacy Act, and to help ensure that the Colorado Privacy Act is carried out in a way that is consistent
with the intent of the General Assembly, as reflected in the legislative declaration at C.R.S. § 6-1-1302.
Rule 1.02
SEVERABILITY
If any provision of these Colorado Privacy Act Rules, 4 CCR 904-3, is found to be invalid by a court of
competent jurisdiction, the remaining provisions of these rules shall remain in full force and effect.
Rule 1.03
EFFECTIVE DATE
Except for the provisions that have delayed effective dates as stated in these rules or C.R.S. §§ 6-1-1301
through 6-1-1314, these rules shall become effective by the effective date published by the Secretary of
State in the Colorado Code of Regulations.
Rule 1.04
EXEMPTIONS
These Colorado Privacy Act Rules, 4 CCR 904-3, are subject to the applicability requirements and
exemptions provided in C.R.S. § 6-1-1304.
Code of Colorado Regulations
Secretary of State
State of Colorado

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

2
PART 2
DEFINITIONS
Rule 2.01
AUTHORITY AND PURPOSE
A.
The statutory authority for the rules in this Part 2 is C.R.S. §§ 6-1-108(1), 6-1-1303, and 6-1-
1313. The purpose of these rules is to define certain undefined terms that are used throughout
the Colorado Privacy Act, C.R.S. §§ 6-1-1301 through 6-1-1314, and these Colorado Privacy Act
Rules, 4 CCR 904-3, including but not limited to certain undefined terms that are used in the
definitions set forth in C.R.S. § 6-1-1303. The terms defined by this rule and C.R.S. § 6-1-1303
are capitalized where they appear in the rules to let the reader know to refer back to the
definitions. When a term is used in a conventional sense, and is not intended to be a defined
term, it is not capitalized
es, 4 CCR 904-3, including but not limited to certain undefined terms that are used in the
definitions set forth in C.R.S. § 6-1-1303. The terms defined by this rule and C.R.S. § 6-1-1303
are capitalized where they appear in the rules to let the reader know to refer back to the
definitions. When a term is used in a conventional sense, and is not intended to be a defined
term, it is not capitalized.
Rule 2.02
DEFINED TERMS
The following definitions of terms, in addition to those set forth in C.R.S. § 6-1-1303, apply to these
Colorado Privacy Act Rules, 4 CCR 904-3, promulgated pursuant to the Colorado Privacy Act, unless the
context requires otherwise:
“Authorized Agent” as referred to in C.R.S. § 6-1-1306(1)(a)(II) means a person or entity authorized by
the Consumer to act on the Consumer's behalf.
“Biometric Data” is defined as set forth in C.R.S. § 6-1-1303(2.4) and means one or more biometric
identifiers that are used or intended to be used, singly or in combination with each other or with other
personal data, for identification purposes. Biometric Data does not include the following unless the
Biometric Data is used for identification purposes: a digital or physical photograph; an audio or voice
recording; or any data generated from a digital or physical photograph or an audio or video recording.
“Biometric Identifier” is defined as set forth in C.R.S. § 6-1-1303(2.5), and means data generated by the
technological processing, measurement, or analysis of an individual’s biological, physical, or behavioral
characteristics, which data can be Processed for the purpose of uniquely identifying an individual.
Biometric Identifier includes a fingerprint; a voiceprint; a scan or record of eye retina or iris; a facial map,
facial geometry, or facial template; or other unique biological, physical, or behavioral patterns or
characteristics.
“Biometric Identifier Notice” means the notice of collection or processing of Biometric Identifiers
containing the disclosures required by C.R.S. § 6-1-1314(4)(a)
idual.
Biometric Identifier includes a fingerprint; a voiceprint; a scan or record of eye retina or iris; a facial map,
facial geometry, or facial template; or other unique biological, physical, or behavioral patterns or
characteristics.
“Biometric Identifier Notice” means the notice of collection or processing of Biometric Identifiers
containing the disclosures required by C.R.S. § 6-1-1314(4)(a).
“Bona Fide Loyalty Program” as referred to in C.R.S. § 1-6-1308(1)(d) is defined as a loyalty, rewards,
premium feature, discount, or club card program established for the genuine purpose of providing Bona
Fide Loyalty Program Benefits to Consumers that voluntarily participate in that program, such that the
primary purpose of Processing Personal Data through the program is solely to provide Bona Fide Loyalty
Program Benefits to participating Consumers.
“Bona Fide Loyalty Program Benefit” is defined as an offer of superior price, rate, level, quality, or
selection of goods or services provided to a Consumer through a Bona Fide Loyalty Program. Such
benefits may be provided directly by a Controller or through a Bona Fide Loyalty Program Partner.
“Bona Fide Loyalty Program Partner” is defined as a Third Party that provides Bona Fide Loyalty
Program Benefits to Consumers through a Controller’s Bona Fide Loyalty Program, either alone or in
partnership with the Controller.
“Child” is defined as set forth in C.R.S. § 6-1-1303(4), and means an individual under thirteen years of
age.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
am Partner” is defined as a Third Party that provides Bona Fide Loyalty
Program Benefits to Consumers through a Controller’s Bona Fide Loyalty Program, either alone or in
partnership with the Controller.
“Child” is defined as set forth in C.R.S. § 6-1-1303(4), and means an individual under thirteen years of
age.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

3
“Commercial product or service” as referred to in C.R.S. § 6-1-1304(1)(a) means a product or service
bought, sold, leased, joined, provided, subscribed to, or delivered in exchange for monetary or other
valuable consideration in the course of a Controller’s business, vocation, or occupation.
“Controller” is defined as set forth in C.R.S. § 6-1-1303(7), and means a person that, alone or jointly with
others, determines the purposes for and means of Processing Personal Data.
"Data Broker” is defined as a Controller that knowingly collects and sells to Third Parties the Personal
Data of a Consumer with whom the Controller does not have a direct relationship.
"Data Right” or “Data Rights” means the Consumer Personal Data rights granted in C.R.S. §§ 6-1-
1306(1) and 6-1-1314(5).
“Disability” or “Disabilities” has the same meaning as set forth in C.R.S. § 24-85-102(2.3).
“Employee" except as used in C.R.S. § 6-1-1314, means any person, acting as a job applicant to, or
performing labor or services for the benefit of an Employer, including contingent and temporary workers
and migratory laborers.
“Employee” as used in C.R.S. § 6-1-1314 is set forth in C.R.S. § 6-1-1314(1)(b) and means an individual
who is employed full-time, part-time, or on-call or who is hired as a contractor, subcontractor, intern, or
fellow.
"Employer" means every person, entity, firm, partnership, association, corporation, migratory field labor
contractor or crew leader, receiver, or other officer of court, and any agent or officer thereof, of the above-
mentioned classes, employing any person.
"Employment Records" as referred to in C.R.S
l-time, part-time, or on-call or who is hired as a contractor, subcontractor, intern, or
fellow.
"Employer" means every person, entity, firm, partnership, association, corporation, migratory field labor
contractor or crew leader, receiver, or other officer of court, and any agent or officer thereof, of the above-
mentioned classes, employing any person.
"Employment Records" as referred to in C.R.S. § 6-1-1304(2)(k) means the records of an Employee,
maintained by the Employer in the context of the Employer-Employee relationship having to do with
hiring, promotion, demotion, transfer, lay-off or termination, rates of pay or other terms of compensation,
as well as other information maintained because of the Employer-Employee relationship.
"Human Involved Automated Processing” means the automated processing of Personal Data where a
human (1) engages in a meaningful consideration of available data used in the Processing or any output
of the Processing and (2) has the authority to change or influence the outcome of the Processing.
“Human Reviewed Automated Processing” means the automated processing of Personal Data where a
human reviews the automated processing, but the level of human engagement does not rise to the level
required for Human Involved Automated Processing. Reviewing the output of the automated processing
with no meaningful consideration does not rise to the level of Human Involved Automated Processing.
“Information that a Controller has a reasonable basis to believe the Consumer has lawfully made
available to the general public” as referred to in C.R.S. § 6-1-1303(17)(b) means information that a
Consumer has intentionally made available to the general public or information that a Consumer has
made available under federal or state law, which may include but is not limited to:
1.
Personal Data found in a telephone book, a television or radio program, or a national or
local news publication;
2
vailable to the general public” as referred to in C.R.S. § 6-1-1303(17)(b) means information that a
Consumer has intentionally made available to the general public or information that a Consumer has
made available under federal or state law, which may include but is not limited to:
1.
Personal Data found in a telephone book, a television or radio program, or a national or
local news publication;
2.
Personal Data that has been intentionally made available by the Consumer through a
website or online service where the Consumer has not restricted the information to a
specific audience;
3.
A visual observation of an individual’s physical presence in a public place by another
person, not including data collected by a device in the individual’s possession; and

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

4
4.
A disclosure that has been made to the general public as required by federal, state, or
local law.
“Interpretive Guidance” means a written statement issued by the Attorney General that calls attention to
a well-established interpretation or principle of the Colorado Privacy Act or any rules or regulations
promulgated thereunder, without applying it to a specific factual situation.
“Intimate Image” means any visual depiction, photograph, film, video, recording, picture, or computer or
computer-generated image or picture, whether made or produced by electronic, mechanical, or other
means, that depicts an identified or identifiable person’s private parts, or a person engaged in a private
act, in circumstances in which a reasonable person would reasonably expect to be afforded privacy.
“Media” means text, audio, an image, or a video.
“Minor” is defined as set forth in C.R.S. § 6-1-1303 (16.5) and means any consumer who is under
eighteen years of age.
“Noncommercial Purpose” as referred to in C.R.S. § 6-1-1304(2)(o) includes, but is not limited to, the
following activities when conducted by: (a) a state institution of higher education, as defined in C.R.S
to be afforded privacy.
“Media” means text, audio, an image, or a video.
“Minor” is defined as set forth in C.R.S. § 6-1-1303 (16.5) and means any consumer who is under
eighteen years of age.
“Noncommercial Purpose” as referred to in C.R.S. § 6-1-1304(2)(o) includes, but is not limited to, the
following activities when conducted by: (a) a state institution of higher education, as defined in C.R.S. §
23-18-102(10), the state, the judicial department of the state, or a county, city and county, or municipality;
or (b) a Processor acting on behalf of one or more of the foregoing:
1.
Processing activities related to the delivery of services and benefits;
2.
Research purposes;
3.
Budgeting;
4.
Improving operations or the delivery services or benefits;
5.
Auditing operations or service or benefit delivery;
6.
Sharing Personal Data between these categories of entities for any of these purposes; or
7.
Any other purpose related to speech that state or federal courts have recognized as
noncommercial speech, including political speech and journalism.
“Opinion Letter” means a letter containing the Attorney General’s opinion as to the application of one or
more sections of the Colorado Privacy Act, C.R.S. § 6-1-1301, et seq., and any rules or regulations
promulgated thereunder, to a specific factual situation.
"Opt-Out Purpose” or “Opt-Out Purposes” means the categories of Personal Data Processing from
which the Consumer may opt out pursuant to C.R.S. § 6-1-1306(1)(a).
"Personal Data" is defined as set forth in C.R.S. § 6-1-1303(17), and (a) means information that is linked
or reasonably linkable to an identified or identifiable individual; and (b) does not include de-identified data
or Publicly Available Information as used in (17)(b).
"Process" or "Processing" is defined as set forth in C.R.S. § 6-1-1303(18), and means the collection,
use, sale, storage, disclosure, analysis, deletion, or modification of Personal Data and includes the
actions of a Controller directing a Processor to Process Personal Data
or identifiable individual; and (b) does not include de-identified data
or Publicly Available Information as used in (17)(b).
"Process" or "Processing" is defined as set forth in C.R.S. § 6-1-1303(18), and means the collection,
use, sale, storage, disclosure, analysis, deletion, or modification of Personal Data and includes the
actions of a Controller directing a Processor to Process Personal Data.
“Processor” is defined as set forth in C.R.S. § 6-1-1303(19), and means a person that Processes
Personal Data on behalf of a Controller.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

5

“Profiling” is defined as set forth in C.R.S. § 6-1-1303(20), and means any form of automated processing
of personal data to evaluate, analyze, or predict personal aspects concerning an identified or identifiable
individual’s economic situation, health, personal preferences, interests, reliability, behavior, location, or
movements.
“Publicly Available Information” is defined as set forth in C.R.S. § 6-1-1303(17), and does not include:
1.
Any Personal Data obtained or processed in in violation of C.R.S. §§ 18-7-107 or 18-7-
801;
2.
Biometric Data;
3.
Genetic Information; or
4.
Nonconsensual Intimate Images known to the Controller.
“Revealing” as referred to in C.R.S. § 6-1-1303(24)(a) includes Sensitive Data Inferences. For example:
1.
While web browsing data at a high level may not be considered Sensitive Data, web browsing
data which, alone or in combination with other Personal Data, infers an individual’s sexual
orientation is considered Sensitive Data under C.R.S. § 6-1- 1303(24)(a).
“Sensitive Data Inference” or “Sensitive Data Inferences” means inferences made by a Controller
based on Personal Data, alone or in combination with other data, which are used to indicate an
individual’s racial or ethnic origin; religious beliefs; mental or physical health condition or diagnosis; sex
life or sexual orientation; or citizenship or citizenship status
under C.R.S. § 6-1- 1303(24)(a).
“Sensitive Data Inference” or “Sensitive Data Inferences” means inferences made by a Controller
based on Personal Data, alone or in combination with other data, which are used to indicate an
individual’s racial or ethnic origin; religious beliefs; mental or physical health condition or diagnosis; sex
life or sexual orientation; or citizenship or citizenship status.
“Solely Automated Processing” means the automated processing of Personal Data with no human
review, oversight, involvement, or intervention.
“Universal Opt-Out Mechanism” or “Universal Opt-Out Mechanisms” means mechanisms that clearly
communicate a Consumer's affirmative, freely given, and unambiguous choice to opt out of the
Processing of Personal Data for purposes of Targeted Advertising or the Sale of Personal Data pursuant
to C.R.S. § 6-1-1306 (1)(a)(I)(A) or (1)(a)(I)(B), which meets the technical specifications set forth in 4
CCR 904-3, Rule 5.06 pursuant to C.R.S. § 6-1-1313(2).
PART 3
CONSUMER DISCLOSURES
Rule 3.01
AUTHORITY AND PURPOSE
A.
The statutory authority for the rules in this Part 3 is C.R.S. §§ 6-1-108(1), 6-1-1313, and 6-1-
1314. The purpose of the rules in Part 3 is to ensure that disclosures, notifications, and other
communications to Consumers are clear, accessible, and understandable to Consumers so that
Consumers can understand and exercise the full scope of their rights under the Colorado Privacy
Act, C.R.S. § 6-1-1303 through 6-1-1314.
Rule 3.02
REQUIREMENTS FOR DISCLOSURES, NOTIFICATIONS, AND OTHER
COMMUNICATIONS TO CONSUMERS
A.
Disclosures, notifications, and other communications to Consumers pursuant to 4 CCR 904-3,
Rules 4.02, 4.05(D), 5.03, 6.02, 6.05, and 7.04 must be:

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
s under the Colorado Privacy
Act, C.R.S. § 6-1-1303 through 6-1-1314.
Rule 3.02
REQUIREMENTS FOR DISCLOSURES, NOTIFICATIONS, AND OTHER
COMMUNICATIONS TO CONSUMERS
A.
Disclosures, notifications, and other communications to Consumers pursuant to 4 CCR 904-3,
Rules 4.02, 4.05(D), 5.03, 6.02, 6.05, and 7.04 must be:

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

6
1.
Designed to be understandable and accessible to a Controller’s target audiences,
considering the vulnerabilities or unique characteristics of the audience and paying
particular attention to the vulnerabilities of Children or Minors. For example, they shall
use plain, straightforward language and avoid technical or legal jargon.
2.
Reasonably accessible to Consumers with Disabilities, including through the use of digital
accessibility tools. For notices provided online, the Controller shall follow generally
recognized industry standards, such as the Web Content Accessibility Guidelines,
version 2.1 of June 5, 2018, from the World Wide Web Consortium, incorporated herein
by reference as described at 4 CCR 904-3, Rule 11.02. In other contexts, the Controller
shall provide information on how a Consumer with a Disability may access the disclosure
or communication or make a request in an alternative format.
3.
Available in the languages in which the Controller in its ordinary course provides web
pages, interfaces, contracts, disclaimers, sale announcements, and other information to
Consumers. Disclosures and communications sent directly to Consumers must be sent in
the language in which the Consumer ordinarily interacts with the Controller.
4.
Available through a readily accessible interface regularly used in conjunction with the
Controller’s product or service.
5.
Provided in a readable format on all devices through which Consumers normally or
regularly interact with the Controller, including on smaller screens and through mobile
applications, if applicable.
6
language in which the Consumer ordinarily interacts with the Controller.
4.
Available through a readily accessible interface regularly used in conjunction with the
Controller’s product or service.
5.
Provided in a readable format on all devices through which Consumers normally or
regularly interact with the Controller, including on smaller screens and through mobile
applications, if applicable.
6.
Unless otherwise stated, communicated in a manner by which the Controller regularly
interacts with Consumers.
7.
Straightforward and accurate, and must not be written or presented in a way that is
unfair, deceptive, false, or misleading.
B.
A written Biometric Data policy required by C.R.S. § 6-1-1314(2)(a) shall comply with all
requirements for disclosures and communications to Consumers provided in 4 CCR 904-3, Rule
3.02(A).
PART 4
CONSUMER PERSONAL DATA RIGHTS
Rule 4.01
AUTHORITY AND PURPOSE
A.
The statutory authority for the rules in this Part 4 is C.R.S. §§ 6-1-108(1), 6-1-1306, 6-1-1313,
and 6-1-1314. The purpose of the rules in Part 4 is to clarify the scope of Consumer Personal
Data rights, and standards for the processes required to facilitate the exercise of those rights.
Rule 4.02
SUBMITTING REQUESTS TO EXERCISE PERSONAL DATA RIGHTS
A.
Pursuant to C.R.S. § 6-1-1306(1), a Controller’s privacy notice must include specific methods
through which a Consumer may submit requests to exercise Data Rights.
B.
Any method specified by a Controller pursuant to this rule must comply with each of the following:
1.
Consider the ways in which Consumers normally interact with the Controller:

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
), a Controller’s privacy notice must include specific methods
through which a Consumer may submit requests to exercise Data Rights.
B.
Any method specified by a Controller pursuant to this rule must comply with each of the following:
1.
Consider the ways in which Consumers normally interact with the Controller:

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

7
a.
A Controller that interacts with Consumers exclusively online and has a direct
relationship with a Consumer from whom it collects Personal Data shall only be
required to provide an email address for submitting access, correction, deletion,
or data portability requests.
b.
A Controller that does not fall within subsection 4 CCR 904-3, Rule 4.02(B)(1)(a)
shall provide two or more designated methods for submitting a Data Rights
request. If a Controller maintains a website, mobile application, or other digital
presence, one method for submitting requests shall be through its website,
mobile application, or digital interface, such as through a webform;
c.
If a Controller interacts with Consumers in person, the Controller shall consider
providing an in-person method such as a printed form the Consumer can directly
submit or send by mail; a tablet or computer portal that allows the Consumer to
complete and submit an online form; or a telephone by which the Consumer can
call the Controller’s toll-free number.
2.
Enable the Consumer to submit the request to the Controller at any time;
3.
Comply with requirements for disclosures, notifications, and other communications to
Consumers provided in 4 CCR 904-3, Rule 3.02;
4.
Use reasonable data security measures, consistent with 4 CCR 904-3, Rule 6.09, when
exchanging information in furtherance of Data Rights requests, considering the volume,
scope and nature of Personal Data that may be exchanged; and
5.
Be easy for Consumers to execute, requiring a minimal number of steps.
C
notifications, and other communications to
Consumers provided in 4 CCR 904-3, Rule 3.02;
4.
Use reasonable data security measures, consistent with 4 CCR 904-3, Rule 6.09, when
exchanging information in furtherance of Data Rights requests, considering the volume,
scope and nature of Personal Data that may be exchanged; and
5.
Be easy for Consumers to execute, requiring a minimal number of steps.
C.
The Data Rights request method does not have to be specific to Colorado, so long as the request
method:
1.
Clearly indicates which rights are available to Colorado Consumers;
2.
Provides all Data Rights available to Colorado Consumers;
3.
Provides Colorado Consumers a clear understanding of how to exercise their rights; and
4.
Meets all other requirements of this part, 4 CCR 904-3, Rule 4.02.
D.
When a Consumer submits a Data Rights request, a Controller may only collect Personal Data
through the request process if the Personal Data is reasonably necessary to Authenticate the
Consumer, respond to the request, or effectuate the Data Rights request.
E.
A Controller must not require a Consumer to create a new user account to exercise their Data
Rights request, but may require a Consumer to use an existing password-protected account.
Rule 4.03
RIGHT TO OPT OUT
A.
A Controller shall comply with an opt-out request by:
1.
Ceasing to Process the Consumer’s Personal Data for the Opt-Out Purpose(s) as soon
as feasibly possible and without undue delay from the date the Controller receives the
request, taking into account the size and complexity of the Controller’s businesses and
burden of operationalizing the opt-out.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
request by:
1.
Ceasing to Process the Consumer’s Personal Data for the Opt-Out Purpose(s) as soon
as feasibly possible and without undue delay from the date the Controller receives the
request, taking into account the size and complexity of the Controller’s businesses and
burden of operationalizing the opt-out.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

8
a.
If a Controller does not know the identity of a Consumer submitting an online opt-
out request, such that the Controller is unable to opt the Consumer out of the
Processing of offline or other connected Personal Data, the Controller may
request the additional information necessary to do so subject to 4 CCR 904-3,
Rules 4.08 and 5.05.
b.
If a Consumer submits a request to exercise more than one Data Right and a
Controller is able to complete the opt-out request in a more timely manner than
other Data Rights requests, the Controller should complete the opt-out request
prior to any other Data Rights request.
2.
Maintaining a record of the opt-out request and response, in compliance with 4 CCR 904-
3, Rule 6.11.
3.
Using agreed upon technical, organizational or other measures or processes to instruct
its Processors, pursuant to C.R.S. § 6-1-1305(2)(a), to stop Processing the Personal
Data as needed to effectuate the Consumer’s opt-out request.
B.
To enable a Consumer to exercise the right to opt out of the Opt-Out Purposes provided in C.R.S.
§ 6-1-1306(1)(a)(I), a Controller must provide the disclosures required by C.R.S. § 6-1-
1308(1)(b).
1.
A Controller that Sells Personal Data or Processes Personal Data for Targeted
Advertising must also provide a clear and conspicuous method for Consumers to
exercise the right to opt out of the Processing of Personal Data for each or all of the Opt-
Out Purposes, as applicable.
a.
The clear, conspicuous method must be provided either directly or through a link,
in a clear, conspicuous, and readily accessible location outside the privacy
notice.
2
s Personal Data for Targeted
Advertising must also provide a clear and conspicuous method for Consumers to
exercise the right to opt out of the Processing of Personal Data for each or all of the Opt-
Out Purposes, as applicable.
a.
The clear, conspicuous method must be provided either directly or through a link,
in a clear, conspicuous, and readily accessible location outside the privacy
notice.
2.
A Controller Processing Personal Data for Profiling in furtherance of a decision that
results in the provision or denial of financial or lending services, housing, insurance,
education enrollment or opportunity, criminal justice, employment opportunities, health-
care services, or access to essential goods or services, as subject to the opt-out right
provided at C.R.S. § 6-1-1306(1)(a)(I), shall provide a clear and conspicuous method for
Consumers to exercise the right to opt out of Processing Personal Data for such Profiling
at or before the time such Processing occurs.
3.
Any clear and conspicuous method for Consumers to exercise the right to opt out of
Processing for the Opt-Out Purposes, provided pursuant to this section, must comply with
the requirements of 4 CCR 904-3, Rule 4.02(B). If a link is used, it must take a Consumer
directly to the opt-out method and the link text must provide a clear understanding of its
purpose, for example “Colorado Opt-Out Rights,” “Personal Data Use Opt-Out,” “Your
Opt-Out Rights,” “Your Privacy Choices,” or “Your Colorado Privacy Choices.”
C.
An Authorized Agent may exercise a Consumer’s opt-out right on behalf of the Consumer, so
long as the Controller is able to, with commercially reasonable effort, Authenticate the identity of
the Consumer and the Authorized Agent’s authority to act on the Consumer’s behalf.
D.
A Controller may collect the Consumer’s Personal Data necessary to effectuate the Consumer’s
opt-out right, pursuant to 4 CCR 904-3, Rule 4.02(D).

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
er is able to, with commercially reasonable effort, Authenticate the identity of
the Consumer and the Authorized Agent’s authority to act on the Consumer’s behalf.
D.
A Controller may collect the Consumer’s Personal Data necessary to effectuate the Consumer’s
opt-out right, pursuant to 4 CCR 904-3, Rule 4.02(D).

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

9
Rule 4.04
RIGHT OF ACCESS
A.
A Controller shall comply with an access request by providing the Consumer all the specific
pieces of Personal Data it has collected and maintains about the Consumer that are the subject
of the request, including without limitation, any Personal Data that the Controller’s Processors
obtained from the Controller in providing services to the Controller.
1.
Specific pieces of Personal Data include final Profiling decisions, inferences, derivative
data, marketing profiles, and other Personal Data created by the Controller which is
linked or reasonably linkable to an identified or identifiable individual.
B.
If a Consumer right to access includes Biometric Data, the Controller must also include the
additional information required at C.R.S. § 6-1-1314(5).
C.
Personal Data provided in response to an access request must:
1.
Be provided in in a form that is concise, transparent and easily intelligible and in an
appropriate, commonly used electronic format, depending on the nature of the data;
2.
Be available in the language in which the Consumer interacts with the Controller.
3.
Avoid incomprehensible internal codes and, if necessary, include explanations that would
allow the average Consumer to make an informed decision of whether to exercise
deletion, correction, or opt-out rights.
4.
Be provided in compliance with the requirements for disclosures, notifications, and other
communications, as described in 4 CCR 904-3, Rule 3.02, as applicable.
D
s with the Controller.
3.
Avoid incomprehensible internal codes and, if necessary, include explanations that would
allow the average Consumer to make an informed decision of whether to exercise
deletion, correction, or opt-out rights.
4.
Be provided in compliance with the requirements for disclosures, notifications, and other
communications, as described in 4 CCR 904-3, Rule 3.02, as applicable.
D.
The Controller shall implement and maintain reasonable data security measures, consistent with
4 CCR 904-3, Rule 6.09, in Processing any documentation relating to a Consumer’s access
request.
E.
A Controller shall not be required to disclose in response to an access request a Consumer’s
government-issued identification number, financial account number, health insurance or medical
identification number, an account password, security questions and answers, Biometric Data, or
Biometric Identifiers. The Controller shall, however, inform the Consumer with sufficient
particularity that it has collected that type of information. For example, a Controller shall respond
that it collects “unique Biometric Data including a fingerprint scan” without disclosing the actual
fingerprint scan data.
F.
If a Consumer exercises the right to access their Personal Data in a portable format pursuant to
C.R.S. § 6-1-1306(1)(e) and the Controller determines the manner of response would reveal the
Controller’s trade secrets, the Controller must still honor the Consumer’s undiminished right of
access in a format or manner which would not reveal trade secrets, such as in a nonportable
format.
Rule 4.05
RIGHT TO CORRECTION
A. Consumers have the right to correct inaccuracies in their Personal Data subject to C.R.S. § 6-1-
1306(c).

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
rets, the Controller must still honor the Consumer’s undiminished right of
access in a format or manner which would not reveal trade secrets, such as in a nonportable
format.
Rule 4.05
RIGHT TO CORRECTION
A. Consumers have the right to correct inaccuracies in their Personal Data subject to C.R.S. § 6-1-
1306(c).

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

10
B.
A Controller shall comply with a Consumer’s correction request by correcting the Consumer’s
Personal Data in its existing systems, except archive or backup systems. The Controller shall
also use agreed upon technical, organizational, or other measures or processes to instruct its
Processors, pursuant to C.R.S. § 6-1-1305(2)(a), to make the necessary corrections in their
respective systems.
C.
If a Controller or Processor stores any Personal Data on archived or backup systems, it may
delay compliance with the Consumer’s correction request with respect to an archived or backup
system until that system is restored to an active system or is next accessed or used.
D.
If a Consumer submits a request to exercise their right to correct Personal Data and the
requested correction to that Personal Data could be made by the Consumer through the
Consumer’s account settings, a Controller may respond to the Consumer’s request by providing
instructions on how the Consumer may correct the Personal Data so long as:
1.
The correction process is not unduly burdensome to the Consumer;
2.
The instructions meet all requirements of 4 CCR 904-3, Rule 3.02;
3.
The Controller’s response is compliant with the timing requirements set forth in C.R.S. §
6-1-1306(2)(a); and
4.
The process described in the instructions enable the Consumer to make the specific
requested correction.
E.
A Controller may require the Consumer to provide documentation if necessary to determine
whether the Personal Data, or the Consumer’s requested correction to the Personal Data, is
accurate.
1
er’s response is compliant with the timing requirements set forth in C.R.S. §
6-1-1306(2)(a); and
4.
The process described in the instructions enable the Consumer to make the specific
requested correction.
E.
A Controller may require the Consumer to provide documentation if necessary to determine
whether the Personal Data, or the Consumer’s requested correction to the Personal Data, is
accurate.
1.
When requesting documentation, the Controller must provide the Consumer with a
meaningful understanding of why the documentation is necessary.
2.
Any documentation provided by the Consumer in connection with the Consumer’s right to
correction shall only be Processed by the Controller in considering the accuracy of the
Consumer’s Personal Data.
3.
The Controller shall implement and maintain reasonable data security measures,
consistent with 4 CCR 904-3, Rule 6.09, in Processing any documentation relating to the
Consumer’s correction request.
4.
If the Controller did not receive the Personal Data directly from the Consumer and has no
documentation to support the accuracy of the Personal Data, the Consumer’s assertion
of inaccuracy shall be sufficient to establish that the Personal Data is inaccurate.
5.
A Controller, having exhausted the steps above may decide not to act upon a
Consumer’s correction request if the Controller determines that the contested Personal
Data is more likely than not accurate.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
he Consumer’s assertion
of inaccuracy shall be sufficient to establish that the Personal Data is inaccurate.
5.
A Controller, having exhausted the steps above may decide not to act upon a
Consumer’s correction request if the Controller determines that the contested Personal
Data is more likely than not accurate.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

11
a.
If a Controller denies a Consumer’s correction request based on the Controller’s
determination that the contested Personal Data is more likely than not accurate,
the Controller must describe in documentation required by 4 CCR 904-3, Rule
6.11(A), the Consumer’s requested correction to the Personal Data, any
documentation requested from and provided by the Consumer in support of the
correction request, and the reason for the Controller’s determination that the
Consumer’s documentation was not sufficient to support the Consumer’s
position.
Rule 4.06
RIGHT TO DELETION
A.
A Controller shall comply with a Consumer’s deletion request by:
1.
Permanently and completely erasing the Personal Data from its existing systems, except
archive or backup systems, or de-identifying the Personal Data such that it cannot
reasonably be used to infer information about, or otherwise be linked to, an identified or
identifiable individual, or a device linked to such an individual, in accordance with C.R.S.
§ 6-1-1303(11); and
2.
Using agreed upon technical, organizational, or other measures, or processes to instruct
its Processors pursuant to C.R.S. § 6-1-1305(2)(b) to delete the Consumer’s Personal
Data held by the Processors.
B.
Notwithstanding 4 CCR 904-3, Rule 4.06(A), a Controller may maintain records of a Consumer’s
deletion request consistent with 4 CCR 904-3, Rule 6.11 and as needed to effectuate the deletion
request.
C
agreed upon technical, organizational, or other measures, or processes to instruct
its Processors pursuant to C.R.S. § 6-1-1305(2)(b) to delete the Consumer’s Personal
Data held by the Processors.
B.
Notwithstanding 4 CCR 904-3, Rule 4.06(A), a Controller may maintain records of a Consumer’s
deletion request consistent with 4 CCR 904-3, Rule 6.11 and as needed to effectuate the deletion
request.
C.
If a Controller or Processor stores any Personal Data on archived or backup systems, it may
delay compliance with the Consumer’s deletion request with respect to an archived or backup
system until that system is restored to an active system or is next accessed or used.
D.
A Controller that has obtained Personal Data about a Consumer from a source other than the
Consumer shall comply with a Consumer's deletion request with respect to that Personal Data
pursuant to C.R.S. § 6-1-1306(d) by (i) retaining a record of the deletion request and the
minimum data necessary for the purpose of ensuring the Consumer’s Personal Data remains
deleted from the Consumer’s records and not using such retained data for any other purpose, or
(ii) opting the Consumer out of the Processing of such Personal Data for any purpose except for
those exempted pursuant to the provisions of C.R.S. § 6-1-1304.
E.
If a Controller complies with a deletion request by opting the Consumer out of Processing under
4.06(D) or does not opt the Consumer out of some Processing of Personal Data because the
Processing purpose is exempted pursuant to the provisions of C.R.S. § 6-1-1304, the Controller
shall provide the Consumer with the categories of Personal Data that were not deleted along with
any applicable exception. The Controller shall not use the Consumer’s Personal Data retained for
any other purpose than provided for by the applicable exception.
Rule 4.07
RIGHT TO DATA PORTABILITY
A
ause the
Processing purpose is exempted pursuant to the provisions of C.R.S. § 6-1-1304, the Controller
shall provide the Consumer with the categories of Personal Data that were not deleted along with
any applicable exception. The Controller shall not use the Consumer’s Personal Data retained for
any other purpose than provided for by the applicable exception.
Rule 4.07
RIGHT TO DATA PORTABILITY
A.
To comply with a data portability request, a Controller must transfer to a Consumer the Personal
Data it has collected and maintains about the Consumer through a secure method in a commonly
used electronic format that, to the extent technically feasible, is readily usable and allows the
Consumer to transmit the Personal Data to another entity without hindrance.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

12
B.
Pursuant to C.R.S. § 6-1-1306(1)(e), a Controller is not required to provide Personal Data to a
Consumer in a manner that would disclose the Controller’s trade secrets. When complying with a
request to access Personal Data in a portable format, Controllers must provide as much data as
possible in a portable format without disclosing the trade secret.
1.
For example, if sharing both raw or unedited Personal Data along with related inferences
or derived Personal Data in an Excel file would reveal a trade secret, the Controller may
provide either set of Personal Data in an Excel file, so long as it is clear to the Consumer
that the Controller maintains both types of Personal Data.
Rule 4.08
AUTHENTICATION
A.
Pursuant to C.R.S. § 6-1-1306(1), a Controller shall use a commercially reasonable method for
authenticating the identity of every Consumer submitting any Data Right request, and the
authority of every Authorized Agent submitting an opt-out request on behalf of a Consumer
pursuant to C.R.S. § 6-1-1306(1)(a)(II).
1
at the Controller maintains both types of Personal Data.
Rule 4.08
AUTHENTICATION
A.
Pursuant to C.R.S. § 6-1-1306(1), a Controller shall use a commercially reasonable method for
authenticating the identity of every Consumer submitting any Data Right request, and the
authority of every Authorized Agent submitting an opt-out request on behalf of a Consumer
pursuant to C.R.S. § 6-1-1306(1)(a)(II).
1.
To determine if an authentication method is commercially reasonable, the Controller shall
consider the Data Rights exercised, the type, sensitivity, value, and volume of Personal
Data involved, the level of possible harm that improper access or use could cause to the
Consumer submitting the Data Right request and the cost of authentication to the
Controller. A Controller must avoid methods that place an unreasonable burden on the
Consumer submitting a Data Right request, or Authorized Agent submitting an opt-out
request on behalf of a Consumer.
B.
When possible, a Controller shall avoid requesting additional Personal Data to Authenticate a
Consumer unless the Controller cannot Authenticate the Consumer using the Personal Data
already maintained by the Controller.
C.
Personal Data obtained to Authenticate a Consumer may only be used to Authenticate the
Consumer submitting the Data Right request, pursuant to C.R.S. § 6-1-1306(1), or to
Authenticate an Authorized Agent’s authority, pursuant C.R.S. § 6-1-1306(1)(a)(II), and must be
deleted as soon as practical after Processing the Consumer’s request, except as required by 4
CCR 904-3, Rule 6.11, or as otherwise required.
D.
A Controller shall implement reasonable security measures, consistent with 4 CCR 904-3, Rule
6.09, to protect Personal Data exchanged to Authenticate a Consumer or to Authenticate an
Authorized Agent’s authority, considering the type, value, sensitivity, and volume of information
exchanged and the level of possible harm improper access or use could cause to the Consumer
submitting a Data Right request.
E
oller shall implement reasonable security measures, consistent with 4 CCR 904-3, Rule
6.09, to protect Personal Data exchanged to Authenticate a Consumer or to Authenticate an
Authorized Agent’s authority, considering the type, value, sensitivity, and volume of information
exchanged and the level of possible harm improper access or use could cause to the Consumer
submitting a Data Right request.
E.
A Controller shall not require the Consumer or Authorized Agent to pay a fee for authentication.
For example, a Controller may not require a Consumer to provide a notarized affidavit for
authentication unless the Controller compensates the Consumer for the cost of notarization.
F.
If a Controller cannot Authenticate the Consumer submitting a Data Right request using
commercially reasonable efforts, the Controller is not required to comply with the Consumer’s
request. The Controller shall inform the Consumer that their identity could not be authenticated,
provide information on how to remedy any deficiencies, and may request additional Personal
Data if reasonably necessary to Authenticate the Consumer.
Rule 4.09
RESPONDING TO CONSUMER REQUESTS
A.
A Controller must respond to a Consumer’s Data Right request in compliance with the timing
provisions of C.R.S. § 6-1-1306(2)(a)-(b).

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

13
B.
A Controller does not have to comply with an authenticated Consumer request to access, correct,
delete, or provide Personal Data in a portable format, to the extent that the Personal Data at
issue meets the requirements of the exceptions in C.R.S. § 6-1-1307(1)(b) and 1307(3).
C.
If a Controller decides not to act on a Consumer’s Data Right request, the Controller’s response
to the Consumer must include the grounds for denial, including but not limited to (1) any conflict
with federal or state law; (2) if the Controller relied on an exception to the Colorado Privacy Act
found at C.R.S
issue meets the requirements of the exceptions in C.R.S. § 6-1-1307(1)(b) and 1307(3).
C.
If a Controller decides not to act on a Consumer’s Data Right request, the Controller’s response
to the Consumer must include the grounds for denial, including but not limited to (1) any conflict
with federal or state law; (2) if the Controller relied on an exception to the Colorado Privacy Act
found at C.R.S. § 6-1-1304(2), a description of the exception; (3) the Controller’s inability to
Authenticate the Consumer’s identity; (4) any factual basis for a Controller’s good-faith claim that
compliance is impossible; or (5) any basis for a good-faith, documented belief that the request is
fraudulent or abusive.
1.
If a Controller denies a Consumer Data Right request based on inability to Authenticate,
the Controller must describe in documentation required by 4 CCR 904-3, Rule 6.11 their
reasonable efforts to authenticate and why they were unable to do so.
2.
A Controller that decides not to act on a Consumer’s request must also provide
instructions on how to appeal the Controller’s decision in accordance with C.R.S. § 6-1-
1306(3).
D.
When a Controller complies with a Consumer’s Personal Data Right request, the Controller shall
also use agreed upon technical, organizational, or other measures or processes, to instruct its
Processors, pursuant to C.R.S. § 6-1-1305(2)(a), to fulfill requests relating to Personal Data held
by the Processors.
E.
Controllers must maintain all documentation as required by 4 CCR 904-3, Rule 6.11 of these
rules.
F
oller complies with a Consumer’s Personal Data Right request, the Controller shall
also use agreed upon technical, organizational, or other measures or processes, to instruct its
Processors, pursuant to C.R.S. § 6-1-1305(2)(a), to fulfill requests relating to Personal Data held
by the Processors.
E.
Controllers must maintain all documentation as required by 4 CCR 904-3, Rule 6.11 of these
rules.
F.
If a Consumer or Authorized Agent submits a request to opt out of the Processing of a
Consumer’s Personal Data for an Opt-Out Purpose in a manner that is not one of the Controller’s
opt-out request methods, or submits a Data Right request that is otherwise deficient in a manner
unrelated to the Authentication process, the Controller shall either: (1) treat the request as if it had
been submitted in accordance with the Controller’s specified request methods, or (2) provide the
Consumer or Authorized Agent that submitted the request with information on how to submit the
request or remedy any deficiencies in the request.
PART 5
UNIVERSAL OPT-OUT MECHANISM
Rule 5.01
AUTHORITY AND PURPOSE
A.
The statutory authority for the rules in Part 5 is C.R.S. §§ 6-1-108(1), 6-1-1306, and 6-1-1313.
The purpose of this Part 5 is to provide technical and other specifications for Universal Opt-Out
Mechanisms.
Rule 5.02
RIGHTS EXERCISED
A.
Consumers may exercise their right to opt out of the Processing of Personal Data concerning the
Consumer for purposes of Targeted Advertising or the Sale of Personal Data through a user-
selected Universal Opt-Out Mechanism that meets the technical and other specifications provided
in this Rule 5.
B.
The purpose of a Universal Opt-Out Mechanism is to provide Consumers with a simple and easy-
to-use method by which Consumers can automatically exercise their opt-out rights with all
Controllers they interact with without having to make individualized requests with each Controller.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
ns provided
in this Rule 5.
B.
The purpose of a Universal Opt-Out Mechanism is to provide Consumers with a simple and easy-
to-use method by which Consumers can automatically exercise their opt-out rights with all
Controllers they interact with without having to make individualized requests with each Controller.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

14
C.
A Universal Opt-Out Mechanism may:
1.
Express a Consumer’s choice to opt out of the Processing of Personal Data for both the
Processing of Personal Data for purposes of Targeted Advertising and Sale of Personal
Data; or
2.
Express a Consumer’s choice to opt out of the Processing of Personal Data for only one
specific purpose, either Targeted Advertising or Sale of Personal Data alone.
Rule 5.03
NOTICE AND CHOICE FOR UNIVERSAL OPT-OUT MECHANISMS
A.
If a platform, developer, or provider provides a Universal Opt-Out Mechanism, that platform,
developer, or provider shall make clear to the Consumer, whether in its configuration or
disclosures to the public, that the mechanism is meant to allow the Consumer to exercise the
right to opt out of the Processing of Personal Data for one specific purpose, either Targeted
Advertising or Sale of Personal Data, or both purposes. These notices provided to the Consumer:
1.
Shall comply with the requirements for disclosures and communications to Consumers
provided in 4 CCR 904-3, Rule 3.02;
2.
If applicable, shall state that the Universal Opt-Out Mechanism has been recognized by
the Colorado Attorney General;
3.
Shall clearly describe any limitations that may be applicable to the mechanism, for
example:
a.
That the mechanism will allow a consumer to exercise the opt-out right for only
one specific purpose, either Targeted Advertising or Sale of Personal Data; or
b.
That the mechanism applies only to a single browser or device.
4
al Opt-Out Mechanism has been recognized by
the Colorado Attorney General;
3.
Shall clearly describe any limitations that may be applicable to the mechanism, for
example:
a.
That the mechanism will allow a consumer to exercise the opt-out right for only
one specific purpose, either Targeted Advertising or Sale of Personal Data; or
b.
That the mechanism applies only to a single browser or device.
4.
Need not be tailored only to Colorado or refer to Colorado or to any other specific
provisions of these rules or the Colorado Privacy Act, provided the mechanism meets the
requirements of 4 CCR 904-3, Rule 5.03(A)(1)-(3).
a.
Example: A platform, developer, or provider discloses that its Universal Opt-Out
Mechanism permits consumers to exercise “any and all opt-out rights available to
you under state laws,” and complies with the other requirements of this Rule
5.03(A) but makes no mention of Colorado nor recites any section of these rules
or the Colorado Privacy Act. These disclosures satisfy the requirements of this
Rule 5.03(A).
B.
A valid Universal Opt-Out Mechanism must represent the Consumer’s affirmative, freely given,
and unambiguous choice to opt out of the Processing of Personal Data for the purposes listed at
C.R.S. § 6-1-1306(1)(a)(IV)(A) and (B). Controllers are not obligated to honor Consumer rights
requests for purposes other than those listed at C.R.S. § 6-1-1306(1)(a)(IV)(A) and (B) when
transmitted through a Universal Opt-Out Mechanism.
C.
The platform, developer, or provider that provides a Universal Opt-Out Mechanism is not
obligated to authenticate that a user is a Resident of Colorado. The platform, developer, or
provider may provide such authentication capabilities if it chooses.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
(B) when
transmitted through a Universal Opt-Out Mechanism.
C.
The platform, developer, or provider that provides a Universal Opt-Out Mechanism is not
obligated to authenticate that a user is a Resident of Colorado. The platform, developer, or
provider may provide such authentication capabilities if it chooses.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

15
Rule 5.04
DEFAULT SETTINGS FOR UNIVERSAL OPT-OUT MECHANISMS
A.
To comply with C.R.S. § 6-1-1313(2), a Universal Opt-Out Mechanism may not be the default
setting for a tool that comes pre-installed with a device, such as a browser or operating system.
1.
Example: An operating system manufacturer bundles a browser pre-installed with every
device shipped with the operating system. The browser sends a Universal Opt-Out
mechanism signal by default and never asks the Consumer to enable this setting. The
Consumer’s decision to use this browser does not represent the Consumer’s affirmative,
freely given, and unambiguous choice to use the Universal Opt-Out Mechanism because
it is a default choice. This is so even if the marketing for the operating system touts its
privacy protective features.
2.
Example: An operating system manufacturer bundles a browser and apps pre-installed
with every device shipped with the operating system. The first time a Consumer runs a
browser or app, the operating system asks the Consumer specifically and clearly whether
they want to opt out of the Sale of their Personal Data using a Universal Opt-Out
Mechanism signal when using the browser or app. No choice is pre-selected, meaning
the Consumer is forced to decide. The Consumer’s decision to select “yes” to enable the
signal to opt out of the Sale of Personal Data represents the Consumer’s affirmative,
freely given, and unambiguous choice to use the Universal Opt-Out Mechanism.
B
out of the Sale of their Personal Data using a Universal Opt-Out
Mechanism signal when using the browser or app. No choice is pre-selected, meaning
the Consumer is forced to decide. The Consumer’s decision to select “yes” to enable the
signal to opt out of the Sale of Personal Data represents the Consumer’s affirmative,
freely given, and unambiguous choice to use the Universal Opt-Out Mechanism.
B.
Notwithstanding 4 CCR 904-3, Rule 5.04(A), a Consumer’s decision to adopt a tool that does not
come pre-installed with a device, such as a browser or operation system, but is marketed as a
tool that will exercise a user’s rights to opt out of the Processing of Personal Data using a
Universal Opt-Out Mechanism, shall be considered the Consumer's affirmative, freely given, and
unambiguous choice to use a Universal Opt-Out Mechanism. The marketing for such a tool may
also describe functionality other than the exercise of opt out rights and it need not refer
specifically to opt-out rights in the State of Colorado.
1.
Example: A browser manufacturer markets its browser as a “privacy friendly” browser,
prominently highlighting that the browser sends a Universal Opt-Out Mechanism signal
by default. The browser does not come pre-installed with a device or operating system
and must be installed by the Consumer. The Consumer’s decision to use this browser
represents the Consumer’s affirmative, freely given, and unambiguous choice to use the
Universal Opt-Out Mechanism. The Consumer need not be given an explicit choice about
whether to use the Universal Opt-Out Mechanism in this example.
Rule 5.05
PERSONAL DATA USE LIMITATIONS
A.
A platform, developer, or provider providing a Universal Opt-Out Mechanism shall not use,
disclose, or retain any Personal Data collected from the Consumer in connection with the
Consumer’s utilization of the mechanism for any purpose other than sending or processing the
opt-out preference
ut
whether to use the Universal Opt-Out Mechanism in this example.
Rule 5.05
PERSONAL DATA USE LIMITATIONS
A.
A platform, developer, or provider providing a Universal Opt-Out Mechanism shall not use,
disclose, or retain any Personal Data collected from the Consumer in connection with the
Consumer’s utilization of the mechanism for any purpose other than sending or processing the
opt-out preference. For example, the fact that a particular device sends a Universal Opt-Out
Mechanism may not be used as part of a digital fingerprint to later identify that device.
B.
When processing a Universal Opt-Out Mechanism, a Controller may not require the collection of
additional Personal Data beyond that which is strictly necessary to authenticate a Consumer is a
resident of Colorado determine that the mechanism represents a legitimate request to opt out of
the Processing of Personal Data as permitted by C.R.S. § 6-1-1306(1)(a)(IV), or comply with the
authentication mandates of the law of another jurisdiction specifically regarding universal opt-out
mechanisms or signals.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

16
1.
Example: The law of a state other than Colorado obligates Controllers to gather specific
pieces of information from a user before the Controller honors the use of a Universal Opt-
Out Mechanism by that user. This additional information may be gathered while
processing a Universal Opt-Out Mechanism, even if is not otherwise “strictly necessary to
authenticate a Consumer is a resident of Colorado or determine that the mechanism
represents a legitimate request".
C.
Notwithstanding 4 CCR 904-3, Rule 5.05(B), a Controller may provide the Consumer with an
option to provide additional Personal Data only if it will extend the recognition of the Consumer’s
use of the Universal Opt-Out Mechanism across platforms, devices, or offline
ly necessary to
authenticate a Consumer is a resident of Colorado or determine that the mechanism
represents a legitimate request".
C.
Notwithstanding 4 CCR 904-3, Rule 5.05(B), a Controller may provide the Consumer with an
option to provide additional Personal Data only if it will extend the recognition of the Consumer’s
use of the Universal Opt-Out Mechanism across platforms, devices, or offline. For example, a
Controller may give the Consumer the option to provide their phone number or email address so
that the Universal Opt-Out Mechanism or signal can apply to offline Sale of Personal Data or link
the Consumer’s opt-out choice across devices. Any information provided by the Consumer for
this purpose shall not be used, disclosed, or retained for any purpose other than processing the
opt-out request.
D.
The Controller shall implement and maintain reasonable data security measures, consistent with
4 CCR 904-3, Rule 6.09, in Processing any Personal Data relating to the Consumer’s use of a
Universal Opt-Out Mechanism.
Rule 5.06
TECHNICAL SPECIFICATION
A.
A Universal Opt-Out Mechanism must allow for Consumers to automatically communicate their
opt-out choice with multiple Controllers.
1.
The Universal Opt-Out Mechanism may communicate a Consumer’s opt-out choice by
sending an opt-out signal. The signal must be in a format commonly used and recognized
by Controllers. An example would be an HTTP header field or JavaScript object.
B.
The Universal Opt-Out Mechanism must allow Consumers to clearly communicate one or more
opt-out rights available under C.R.S. § 6-1-1306(1)(a)(IV).
1.
The Universal Opt-Out Mechanism may allow for a Consumer to opt out of Processing for
one or more of the Opt-Out Purposes.
C.
The Universal Opt-Out Mechanism must store, Process, and transmit any Consumer Personal
Data using reasonable data security measures, consistent with 4 CCR 904-3, Rule 6.09.
D.
A Universal Opt-Out Mechanism must not prevent the Controller’s ability to determine:
1
)(IV).
1.
The Universal Opt-Out Mechanism may allow for a Consumer to opt out of Processing for
one or more of the Opt-Out Purposes.
C.
The Universal Opt-Out Mechanism must store, Process, and transmit any Consumer Personal
Data using reasonable data security measures, consistent with 4 CCR 904-3, Rule 6.09.
D.
A Universal Opt-Out Mechanism must not prevent the Controller’s ability to determine:
1.
Whether a Consumer is a Resident of the State of Colorado; or
2.
That the Universal Opt-Out Mechanism represents a legitimate request to opt out of the
Processing of Personal Data.
E.
A Universal Opt-Out Mechanism must not unfairly disadvantage any Controller. For example, a
Universal Opt-Out Mechanism may not engage in self-dealing benefiting the creator of the
Universal Opt-Out Mechanism over other Controllers.
Rule 5.07
SYSTEM FOR RECOGNIZING UNIVERSAL OPT-OUT MECHANISMS
A.
The Colorado Department of Law shall maintain a public list of Universal Opt-Out Mechanisms
that have been recognized to meet the standards of this subsection. The initial list shall be
released no later than January 1, 2024 and shall be updated periodically.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

17
B.
The goal of the public list is to simplify the options facing Controllers, Consumers, and other
actors.
C.
To be recognized, a Universal Opt-Out Mechanism must at a minimum meet these standards:
1.
Comply with all of the technical and other specifications of Rule 5; and
2.
Not create Consumer or Controller confusion about the similarities and differences
between Universal Opt-Out Mechanisms on the public list.
D.
The Colorado Department of Law may consider additional factors when determining which
Universal Opt-Out Mechanisms to recognize. These include but are not limited to:
1.
Commercial adoption by Consumers or Controllers;
2.
Ease and cost of use, implementation, and detection by Consumers and Controllers;
3
t the similarities and differences
between Universal Opt-Out Mechanisms on the public list.
D.
The Colorado Department of Law may consider additional factors when determining which
Universal Opt-Out Mechanisms to recognize. These include but are not limited to:
1.
Commercial adoption by Consumers or Controllers;
2.
Ease and cost of use, implementation, and detection by Consumers and Controllers;
3.
Whether the Universal Opt-Out Mechanism has been approved by a widely recognized,
legitimate standards body after broad multistakeholder participation in the standards-
making process; and
4.
Whether the Universal Opt-Out Mechanism is based on an open system or standard, and
whether such standard is free for adoption by device, operating system, browser, and
other manufacturers, Controllers, or Consumers without permission or on fair,
reasonable, and non-discriminatory terms.
E.
The public list shall describe recognized Universal Opt-Out Mechanisms in enough technical
detail to permit Controllers to identify them when used by Consumers.
F.
The Colorado Department of Law will allow Controllers six (6) months to recognize a Universal
Opt-Out Mechanism once that Mechanism is added to the public list.
Rule 5.08
OBLIGATIONS ON CONTROLLERS
A.
Effective July 1, 2024,
1.
A Controller that receives an opt-out request through a Universal Opt-Out Mechanism
shall treat such as a valid request to opt out of the Processing of Personal Data for
purposes of Targeted Advertising, Sale of Personal Data, or both purposes, as indicated
by the mechanism, for the associated browser or device, and, if known, for the
Consumer.
2.
After receiving a valid opt-out request through the use of a Universal Opt-Out
Mechanism, a Controller shall continue to treat the browser, device, and Consumer as
having exercised opt-out rights until the Consumer Consents to the Sale of Personal Data
or Processing of Personal Data for Targeted Advertising, as specified in 4 CCR 904-3,
Rule 5.09.
3
r or device, and, if known, for the
Consumer.
2.
After receiving a valid opt-out request through the use of a Universal Opt-Out
Mechanism, a Controller shall continue to treat the browser, device, and Consumer as
having exercised opt-out rights until the Consumer Consents to the Sale of Personal Data
or Processing of Personal Data for Targeted Advertising, as specified in 4 CCR 904-3,
Rule 5.09.
3.
A Controller shall be capable of recognizing any Universal Opt-Out Mechanism reflected
in the public list maintained by the Colorado Department of Law pursuant to subsection 4
CCR 904-3, Rule 5.07 provided the Controller has had at least six months’ notice of the
addition of new mechanisms. For example, in the case of a recognized Universal Opt-Out
Mechanism sent as a signal, the Controller must listen for the signal.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

18
B.
A Controller may also recognize Universal Opt-Out Mechanisms that are not reflected in the
public list maintained by the Colorado Department of Law pursuant to subsection 4 CCR 904-3,
Rule 5.07.
C.
Notwithstanding 4 CCR 904-3, Rule 5.08(A), a Controller may choose to honor an opt-out request
received through a Universal Opt-Out Mechanism prior to July 1, 2024, pursuant to C.R.S. § 6-1-
1306(a)(IV)(A).
D.
Unless a Controller is Authenticating a Consumer as permitted by C.R.S. § 6-1-1313(2)(f), a
Controller may not require a Consumer to login or otherwise Authenticate themself as a condition
of recognizing the Consumer’s use of a Universal Opt-Out Mechanism. A Controller may not
subject a Consumer to undertake any authentication actions that are unnecessary or
unnecessarily burdensome.
E.
A Controller may display in a conspicuous manner if it has Processed the Consumer’s opt-out
preference signal. For example, the Controller may display on its website “Opt-Out Preference
Signal Honored” when a browser, device, or Consumer utilizing a Universal Opt-Out Mechanism
visits the website.
F.
Pursuant to C.R.S
e any authentication actions that are unnecessary or
unnecessarily burdensome.
E.
A Controller may display in a conspicuous manner if it has Processed the Consumer’s opt-out
preference signal. For example, the Controller may display on its website “Opt-Out Preference
Signal Honored” when a browser, device, or Consumer utilizing a Universal Opt-Out Mechanism
visits the website.
F.
Pursuant to C.R.S. § 6-1-1313(2)(f), a Controller may authenticate that the user sending an opt-
out request through a Universal Opt-Out Mechanism is a Resident of Colorado, but they are not
obligated to do so.
Rule 5.09
CONSENT AFTER UNIVERSAL OPT-OUT
A.
A Controller may enable a Consumer to Consent to Processing that the Consumer has opted-out
of using a Universal Opt-Out mechanism, so long as the Controller’s request for Consent
complies with the Consent requirements provided in C.R.S. § 6-1-1306(1)(a)(IV)(C), and 4 CCR
904-3, Rule 7.05.
B.
A Controller shall not interpret the absence of a Universal Opt-Out Mechanism signal after the
Consumer previously utilized a Universal Opt-Out Mechanism as Consent to opt back in.
PART 6
DUTIES OF CONTROLLERS
Rule 6.01
AUTHORITY AND PURPOSE
A.
The statutory authority for the rules in this Part 6 is C.R.S. §§ 6-1-108(1), 6-1-1308, 6-1-1313,
and 6-1-1314. The purpose of the rules in this Part 6 is to provide clarity on the duties of
Controllers concerning the Personal Data of Colorado Consumers.
Rule 6.02
PRIVACY NOTICE PRINCIPLES
A.
A privacy notice shall provide Consumers with a meaningful understanding and accurate
expectations of how their Personal Data will be Processed. It shall also inform Consumers about
their rights under the Colorado Privacy Act and provide any information necessary for Consumers
to exercise those rights.
B
ers concerning the Personal Data of Colorado Consumers.
Rule 6.02
PRIVACY NOTICE PRINCIPLES
A.
A privacy notice shall provide Consumers with a meaningful understanding and accurate
expectations of how their Personal Data will be Processed. It shall also inform Consumers about
their rights under the Colorado Privacy Act and provide any information necessary for Consumers
to exercise those rights.
B.
A Controller is not required to provide a separate Colorado-specific privacy notice or section of a
privacy notice as long as the Controller’s privacy notice meets all requirements of this section and
makes clear that Colorado Consumers are entitled to the rights provided by C.R.S. § 6-1-1306.
C.
A privacy notice shall comply with all requirements for disclosures and communications to
Consumers provided in 4 CCR 904-3, Rule 3.02.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

19
D.
A privacy notice must be clear. Information contained in a privacy notice shall be:
1.
Concrete and definitive, avoiding abstract or ambivalent terms that may lead to varying
interpretations.
2.
Clearly labeled, such that Consumers seeking to understand a Controller’s Processing
activities or how to exercise their Data Rights can easily access the section of the privacy
notice containing relevant information.
E.
A privacy notice must be easily accessible. A privacy notice must be:
1.
Posted online through a conspicuous link using the word “privacy” on the Controller’s
website homepage or on a mobile application’s app store page or download page. A
Controller that maintains an application on a mobile or other device shall also include a
link to the privacy notice in the application’s settings menu.
a.
A Controller that does not operate a website shall make the privacy notice
conspicuously available to Consumers through a medium regularly used by the
Controller to interact with Consumers
mobile application’s app store page or download page. A
Controller that maintains an application on a mobile or other device shall also include a
link to the privacy notice in the application’s settings menu.
a.
A Controller that does not operate a website shall make the privacy notice
conspicuously available to Consumers through a medium regularly used by the
Controller to interact with Consumers. For instance, if a Controller interacts with a
Consumer offline, an offline version of the privacy notice must be available to the
Consumer.
F.
A privacy notice must be specific. The level of specificity in a privacy notice should enable a
Consumer to understand, in advance or at the time of the Processing, the scope of the
Controller’s Processing operations, such that a Consumer should not be taken by surprise at a
later point about Personal Data that has been collected and the ways in which Personal Data has
been Processed.
Rule 6.03
PRIVACY NOTICE CONTENT
A.
A privacy notice must include the following information:
1.
A comprehensive description of the Controller’s online and offline Personal Data
Processing practices, including but not limited to the following, linked in a way that gives
Consumers a meaningful understanding of how each category of their Personal Data will
be used when they provide that Personal Data to the Controller for a specified purpose:
a.
The categories of Personal Data Processed, including, but not limited to, whether
Personal Data of a Child or other Sensitive Data is Processed.
i.
Categories shall be described in a level of detail that provides
Consumers a meaningful understanding of the type of Personal Data
Processed. For example, categories of Personal Data described at a
sufficiently granular level of detail include, but are not limited to: "contact
information,” “government issued identification numbers,” “payment
information”, “Information from Cookies,” “data revealing religious
affiliation,” and “medical data.”
b
il that provides
Consumers a meaningful understanding of the type of Personal Data
Processed. For example, categories of Personal Data described at a
sufficiently granular level of detail include, but are not limited to: "contact
information,” “government issued identification numbers,” “payment
information”, “Information from Cookies,” “data revealing religious
affiliation,” and “medical data.”
b.
The Processing purpose described in a level of detail that gives Consumers a
meaningful understanding of how each category of their Personal Data is used
when provided for that Processing purpose.
c.
Whether the Personal Data provided for a specific purpose will be sold or used
for Targeted Advertising or Profiling in furtherance of Decisions that Produce
Legal or Similarly Significant Effects Concerning a Consumer.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

20
d.
Categories of Personal Data that the Controller Sells to or shares with Third
Parties, if any.
e.
Categories of Third Parties to whom the Controller sells, or with whom the
Controller shares Personal Data, if any. Categories of Third Parties must be
described in a level of detail that gives Consumers a meaningful understanding
of the type of, business model of, or processing conducted by the Third Party.
i.
For example, categories of Third Parties described in a sufficiently
granular level of detail include, but are not limited to: “analytics
companies,” “data brokers,” “third-party advertisers,” “payment
processors,” “lenders,” “other merchants,” and “government agencies.”
2.
If a Controller’s Processing activity involves the Processing of Personal Data for the
purpose of Profiling in furtherance of Decisions that Produce Legal or Similarly Significant
Effects Concerning a Consumer, all disclosures required by 4 CCR 904-3, Rule 9.03.
3.
A list of the Data Rights available.
4.
A description of the methods through which a Consumer may submit requests to exercise
Data Rights, as required by C.R.S
ing activity involves the Processing of Personal Data for the
purpose of Profiling in furtherance of Decisions that Produce Legal or Similarly Significant
Effects Concerning a Consumer, all disclosures required by 4 CCR 904-3, Rule 9.03.
3.
A list of the Data Rights available.
4.
A description of the methods through which a Consumer may submit requests to exercise
Data Rights, as required by C.R.S. § 6-1-1306(1) and 4 CCR 904-3, Rule 4.02, including:
a.
Instructions on how to use each method.
b.
Instructions on how an Authorized Agent may submit a request to opt out of the
Processing of Consumer Personal Data on a Consumer’s behalf pursuant to
C.R.S. § 6-1-1306(1)(a)(II).
c.
A clear and conspicuous method to exercise the right to opt out of the Processing
of Personal Data concerning the Consumer pursuant to C.R.S. § 6-1-
1306(1)(a)(I) and (1)(a)(III), or links to any online method, such as a webform or
portal, consistent with 4 CCR 904-3, Rule 4.03.
d.
A description of the commercially reasonable process the Controller uses to
Authenticate the identity of a Consumer exercising a Data Right request or to
Authenticate the authority of an Authorized Agent exercising the right to opt out
on a Consumer’s behalf.
e.
Effective July 1, 2024, an explanation of how requests to opt out using Universal
Opt-Out Mechanisms will be processed.
5.
If a Controller will delete Sensitive Data Inferences within twenty-four (24) hours pursuant
to 4 CCR 904-3, Rule 6.10, a description of the Sensitive Data Inferences subject to this
provision and the retention and deletion timeline for such Sensitive Data Inferences.
6.
A Controller’s contact information.
7.
Instructions on how a Consumer may appeal a Controller’s action in response to the
Consumer’s request, as contemplated by C.R.S. § 6-1-1306(3).
8.
The date the privacy notice was last updated.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
on and the retention and deletion timeline for such Sensitive Data Inferences.
6.
A Controller’s contact information.
7.
Instructions on how a Consumer may appeal a Controller’s action in response to the
Consumer’s request, as contemplated by C.R.S. § 6-1-1306(3).
8.
The date the privacy notice was last updated.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

21
Rule 6.04
CHANGES TO A PRIVACY NOTICE
A.
A Controller shall notify Consumers of material changes to a privacy notice. Such changes to a
privacy notice shall be communicated to Consumers in a manner by which the Controller
regularly interacts with Consumers.
1.
Material changes may include, but are not limited to, changes to: (1) categories of
Personal Data Processed; (2) Processing purposes; (3) a Controller’s identity; (4) the act
of sharing of Personal Data with Third Parties; (5) categories of Third Parties Personal
Data is shared with; or (6) methods by which Consumers can exercise their Data Rights
request.
B.
If a material change rises to the level of a secondary use, a Controller must obtain Consent from
a Consumer pursuant to 4 CCR 904-3, Rules 7.02-7.05 in order to Process Personal Data that
was collected before the change to the privacy notice for that Secondary Use.
Rule 6.05
LOYALTY PROGRAMS
A.
Pursuant to 6-1-1308(1)(d), a Controller is not prohibited from offering Bona Fide Loyalty Program
Benefits to a Consumer based on the Consumer’s voluntary participation in a Bona Fide Loyalty
Program.
B.
If a Consumer exercises their right to delete Personal Data such that it is impossible for the
Controller to provide a certain Bona Fide Loyalty Program Benefit to the Consumer, the Controller
is no longer obligated to provide that Bona Fide Loyalty Benefit to the Consumer. However, the
Controller shall provide any available Bona Fide Loyalty Program Benefit for which the deleted
Personal Data is not necessary.
C
ercises their right to delete Personal Data such that it is impossible for the
Controller to provide a certain Bona Fide Loyalty Program Benefit to the Consumer, the Controller
is no longer obligated to provide that Bona Fide Loyalty Benefit to the Consumer. However, the
Controller shall provide any available Bona Fide Loyalty Program Benefit for which the deleted
Personal Data is not necessary.
C.
If a Consumer exercises their right to opt out of the Sale of Personal Data or Processing of
Personal Data for Targeted Advertising, such that the exchange of Personal Data needed to
obtain a Bona Fide Loyalty Program Benefit through a Bona Fide Loyalty Program Partner is no
longer possible, the Controller is no longer obligated to provide that Bona Fide Loyalty Program
Benefit to the Consumer.
1.
If the Controller’s Bona Fide Loyalty Program offers Bona Fide Loyalty Program Benefits
that are unrelated to the exchange of Personal Data with a Bona Fide Loyalty Program
Partner, the Controller shall continue to provide those Benefits to a Consumer who opts
out of the Sale of Personal data or Processing of Personal Data for Targeted Advertising.
2.
The sale of Personal Data or Processing of Personal Data for Targeted Advertising that is
unrelated to sharing of information with a Bona Fide Loyalty Program Partner is a
Secondary Use that requires Consent pursuant to 4 CCR 904-3, Rule 6.08.
D.
If a Consumer refuses to Consent to the Processing of Sensitive Data necessary for a
personalized Bona Fide Loyalty Program Benefit, the Controller is no longer obligated to provide
that personalized Bona Fide Loyalty Program Benefit. However, the Controller shall provide any
available, non-personalized Bona Fide Loyalty Program Benefit for which the Sensitive Data is
not necessary. A Controller may not condition a Consumer’s participation in a Bona Fide Loyalty
Program on the Consumer’s Consent to Process Sensitive Data unless the Sensitive Data is
required for all Bona Fide Loyalty Program Benefits.
e Loyalty Program Benefit. However, the Controller shall provide any
available, non-personalized Bona Fide Loyalty Program Benefit for which the Sensitive Data is
not necessary. A Controller may not condition a Consumer’s participation in a Bona Fide Loyalty
Program on the Consumer’s Consent to Process Sensitive Data unless the Sensitive Data is
required for all Bona Fide Loyalty Program Benefits.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

22
E.
If a Consumer’s decision to exercise a Data Right impacts the Consumer’s membership in a Bona
Fide Loyalty Program, the Controller shall notify the Consumer of the impact of the Consumer’s
decision in conformance with 4 CCR 904-3, Rule 3.02 and at least twenty-four (24) hours before
discontinuing the Consumer’s Bona Fide Loyalty Program Benefit or membership, and must
provide a reference or link to the information required by subparagraph F, below.
F.
Loyalty Program Disclosures
1.
In addition to all other disclosures required by 4 CCR 904-3, Rules 6.03 and 7.03, a
Controller maintaining a Bona Fide Loyalty Program must provide the following
disclosures at the point of program registration, either directly, or in the form of a link to
the specific section of a privacy notice or terms and conditions containing such
information:
a.
The categories of Personal Data or Sensitive Data collected through the Bona
Fide Loyalty Program that will be Sold or Processed for Targeted Advertising, if
any;
b.
Categories of Third Parties that will receive the Consumer’s Personal Data and
Sensitive Data, provided in the level the detail described in 4 CCR 904-3, Rule
6.03(a)(1)(e), including whether Personal Data will be provided to Data Brokers;
c.
A list of any Bona Fide Loyalty Program Partners, and the Bona Fide Loyalty
Program Benefits provided by each Bona Fide Loyalty Program Partner.
d
if
any;
b.
Categories of Third Parties that will receive the Consumer’s Personal Data and
Sensitive Data, provided in the level the detail described in 4 CCR 904-3, Rule
6.03(a)(1)(e), including whether Personal Data will be provided to Data Brokers;
c.
A list of any Bona Fide Loyalty Program Partners, and the Bona Fide Loyalty
Program Benefits provided by each Bona Fide Loyalty Program Partner.
d.
If a Controller claims that a Consumer’s decision to delete Personal Data makes
it impossible to provide a Bona Fide Loyalty Program Benefit, then the Controller
shall provide an explanation of why the deletion of Personal Data makes it
impossible to provide a Bona Fide Loyalty Program Benefit.
e.
If a Controller claims that a Consumer’s Sensitive Data is required for a Bona
Fide Loyalty Program Benefit, then the Controller shall provide an explanation of
why the Sensitive Data is required for a Bona Fide Loyalty Program Benefit.
2.
Bona Fide Loyalty Program terms and requests for Consent to Process Sensitive Data or
Personal Data in connection with the Bona Fide Loyalty Program shall also include a link
to the Controller’s privacy notice.
G.
Example: A Consumer joins a grocery store’s Bona Fide Loyalty Program that includes both
personalized and non-personalized Bona Fide Loyalty Program Benefits. The grocery store asks
the Consumer for Consent to collect Sensitive Data about the Consumer in order to provide
personalized Bona Fide Loyalty Program Benefits. When the Consumer refuses Consent, the
Controller gives timely notice to the Consumer that it will not provide the personalized Bona Fide
Loyalty Program Benefits, but will continue to provide non-personalized Bona Fide Loyalty
Program Benefits. Moving forward, the Controller provides only the non-personalized Bona Fide
Loyalty Program Benefits following the Consumer’s decision to continue to refuse Consent to the
collection of Sensitive Data
ler gives timely notice to the Consumer that it will not provide the personalized Bona Fide
Loyalty Program Benefits, but will continue to provide non-personalized Bona Fide Loyalty
Program Benefits. Moving forward, the Controller provides only the non-personalized Bona Fide
Loyalty Program Benefits following the Consumer’s decision to continue to refuse Consent to the
collection of Sensitive Data. The Controller is not acting impermissibly because the grocery store
is still providing all available non-personalized Bona Fide Loyalty Program Benefits and did not
condition the Consumer’s participation in the Bona Fide Loyalty Program on the Consumers
Consent to process Sensitive Data that is not required for personalized Bona Fide Loyalty
Program Benefits.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

23
H.
Example: A Consumer joins a hotel chain’s Bona Fide Loyalty Program, which provides points
that can be applied to obtain discounts for that hotel chain, and for a popular restaurant chain that
is not otherwise affiliated with the hotel chain. The restaurant chain requires the hotel chain to
provide the Personal Data of each Consumer who wishes to apply the hotel chain’s points to
obtain restaurant discounts. When the Consumer opts out of the Sale of Personal Data and
Processing of Personal Data for Targeted Advertising, the Controller is unable to provide the
required information to the restaurant chain. The Controller may discontinue the Bona Fide
Loyalty Program Benefit that allows Consumers to use points for discounts for the restaurant
chain. However, the hotel chain must still provide all available Bona Fide Loyalty Benefits to be
used at the hotel chain.
I.
Example: A Consumer joins a retailer’s Bona Fide Loyalty Program that offers discounts on
products based on the Consumer’s purchase history. The retailer wishes to fund the loyalty
program, in part, by selling the Consumer’s purchase history to a Data Broker
the restaurant
chain. However, the hotel chain must still provide all available Bona Fide Loyalty Benefits to be
used at the hotel chain.
I.
Example: A Consumer joins a retailer’s Bona Fide Loyalty Program that offers discounts on
products based on the Consumer’s purchase history. The retailer wishes to fund the loyalty
program, in part, by selling the Consumer’s purchase history to a Data Broker. The retailer must
obtain the Consumer’s consent to Sell the Consumer’s Personal Data to the Data Broker because
selling Personal Data obtained through a Bona Fide Loyalty Program to a Data Broker is a
secondary use.
J.
Example: A Consumer exercises their right to opt out of the Processing of Personal Data for
Targeted Advertising. An online gaming company gives the Consumer fewer free games through
the company’s service, arguing that the additional free games are for members of its loyalty
program, which requires the use of Personal Data for Targeted Advertising. The company’s
differential treatment is prohibited if the Processing of Personal Data is not necessary to provide
the additional games. However, if the free games are provided by a Bona Fide Loyalty Program
Partner that requires the Consumer data for Targeted Advertising through a co-marketing
agreement with the Controller, the differential treatment may be appropriate.
Rule 6.06
PURPOSE SPECIFICATION
A.
Controllers shall specify the express purposes for which each category of Personal Data is
collected and Processed in both external disclosures to Consumers, including privacy notices
required by C.R.S. § 6-1-1308(1), as well as in any internal documentation required by this Part 6.
B.
The express purpose must be described in a level of detail that gives Consumers a meaningful
understanding of how each category of their Personal Data is used when provided for that
Processing purpose.
C
collected and Processed in both external disclosures to Consumers, including privacy notices
required by C.R.S. § 6-1-1308(1), as well as in any internal documentation required by this Part 6.
B.
The express purpose must be described in a level of detail that gives Consumers a meaningful
understanding of how each category of their Personal Data is used when provided for that
Processing purpose.
C.
If Personal Data is collected and Processed for more than one purpose, Controllers should
specify each unrelated purpose with enough detail to allow Consumers to understand each
individual, unrelated purpose.
1.
Controllers should not identify one broad purpose to justify numerous Processing
activities that are only remotely related.
2.
Controllers should not specify one broad purpose to cover potential future Processing
activities that are only remotely related.
3.
Controllers should not specify so many purposes for which Personal Data could
potentially be processed to cover potential future processing activities that the purpose
becomes unclear or uninformative.
D.
If the Processing purpose has evolved beyond the original express purpose such that it becomes
a distinct purpose that is no longer reasonably necessary to or compatible with the original
express purpose, the Controller must review and update all related disclosures and
documentation as necessary.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
nformative.
D.
If the Processing purpose has evolved beyond the original express purpose such that it becomes
a distinct purpose that is no longer reasonably necessary to or compatible with the original
express purpose, the Controller must review and update all related disclosures and
documentation as necessary.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

24
Rule 6.07
DATA MINIMIZATION
A.
To ensure all Personal Data collected is reasonably necessary for the specified purpose,
Controllers shall carefully consider each Processing purpose and determine the minimum
Personal Data that is necessary, adequate, or relevant for the express purpose or purposes.
B.
Personal Data should only be kept in a form which allows identification of Consumers for as long
as is necessary for the express Processing purpose(s). To ensure that the Personal Data are not
kept longer than necessary, adequate, or relevant, Controllers shall set specific time limits for
erasure or to conduct a periodic review.
1.
Any Personal Data determined to no longer be necessary, adequate, or relevant to the
express Processing purpose(s) shall be deleted by the Controller and any Processors
that the Controller has shared the Personal Data with.
2.
Biometric Identifiers, a digital or physical photograph of a person, an audio or voice
recording containing the voice of a person, or any Personal Data generated from a digital
or physical photograph or an audio or video recording held by a Controller shall be
reviewed at least once a year to determine if its storage is still necessary, adequate, or
relevant to the express Processing purpose. Such assessment shall be documented
according to 4 CCR 904-3, Rule 6.11.
3.
Sensitive Data for which Controllers no longer have consent to Process, should be
deleted or otherwise rendered permanently anonymized or inaccessible within a
reasonable period of time after withdrawal of Consent.
C
ar to determine if its storage is still necessary, adequate, or
relevant to the express Processing purpose. Such assessment shall be documented
according to 4 CCR 904-3, Rule 6.11.
3.
Sensitive Data for which Controllers no longer have consent to Process, should be
deleted or otherwise rendered permanently anonymized or inaccessible within a
reasonable period of time after withdrawal of Consent.
C.
A Controller shall not collect Personal Data other than those disclosed in its required privacy
notice. If the Controller intends to collect additional Personal Data the Controller shall revise its
privacy notice, and notify Consumers of the change to its privacy notice pursuant to 4 CCR 904-3,
Rule 6.04.
Rule 6.08
SECONDARY USE
A.
The specified Processing purpose is the purpose disclosed to Consumers at or before the time
the Personal Data is collected or processed from Consumers. Such disclosure shall be included
in any required privacy notice or Consent disclosure.
B.
Before Processing Personal Data for purposes that are not reasonably necessary to or
compatible with specified Processing purpose(s) disclosed on or after July 1, 2023, the Controller
must obtain Consent consistent with C.R.S. § 6-1-1308 and 4 CCR 904-3, Rules 7.02-7.05.
C.
When considering if the new Processing purpose is reasonably necessary to or compatible with
the original specified purpose(s), Controllers may consider the following, as applicable:
1.
The reasonable expectation of an average Consumer concerning how their Personal
Data would be Processed once it was collected;
2.
The link between the original specified purpose(s) for which the data was collected and
the purpose(s) of further Processing;
3.
The relationship between the Consumer and the Controller and the context in which the
Personal Data was collected;
4.
The type, nature, and amount of the Personal Data subject to the new Processing
purpose;

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section
riginal specified purpose(s) for which the data was collected and
the purpose(s) of further Processing;
3.
The relationship between the Consumer and the Controller and the context in which the
Personal Data was collected;
4.
The type, nature, and amount of the Personal Data subject to the new Processing
purpose;

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

25
5.
The type and degree of possible consequence or impact to the Consumer of the new
Processing purpose;
6.
The identity of the entity conducting the new Processing purposes, e.g., the same or
different Controller, or a Third Party; and
7.
The existence of additional safeguards for the Personal Data, such as encryption or
pseudonymization.
Rule 6.09
DUTY OF CARE
A.
Personal Data must be Processed in a manner that ensures reasonable and appropriate
administrative, technical, organizational, and physical safeguards of Personal Data collected,
stored, and Processed.
B.
When determining reasonable and appropriate safeguards, Controllers should consider:
1.
Applicable industry standards and frameworks;
2.
The nature, size, and complexity of the Controller’s organization;
3.
The sensitivity and amount of Personal Data;
4.
The original source of Personal Data;
5.
The risk of harm to Consumers resulting from unauthorized or unlawful access, use, or
degradation of the Personal Data; and
6.
The burden or cost of safeguards to protect Personal Data from harm assessed in 4 CCR
904-3, Rule 6.09(B)(5).
C.
Reasonable and appropriate administrative, technical, organizational, and physical safeguards
must be designed to:
1.
Protect against unauthorized or unlawful access to or use of Personal Data and the
equipment used for the Processing and against accidental loss, destruction, or damage;
2.
Ensure the confidentiality, integrity, and availability of Personal Data collected, stored,
and Processed;
3.
Identify and protect against reasonably anticipated threats to security or the integrity of
information; and
4
to:
1.
Protect against unauthorized or unlawful access to or use of Personal Data and the
equipment used for the Processing and against accidental loss, destruction, or damage;
2.
Ensure the confidentiality, integrity, and availability of Personal Data collected, stored,
and Processed;
3.
Identify and protect against reasonably anticipated threats to security or the integrity of
information; and
4.
Oversee compliance with data security policies by the Controller and Processors through
reasonable requirements.
D.
Reasonable and appropriate administrative, technical, organizational, and physical safeguards to
secure Personal Data include but are not limited to those measures provided by C.R.S. § 6-1-
713.5 and C.R.S. § 24-73-102, as interpreted by state courts and administrative orders.
Rule 6.10
DUTY REGARDING SENSITIVE DATA
A.
Controllers must obtain Consent to Process Sensitive Data, including Sensitive Data Inferences,
consistent with C.R.S. § 6-1-1308(7) and 4 CCR 904-3, Rules 7.02-7.05.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

26
B.
Controllers may be exempt from obtaining Consent to Process Sensitive Data Inferences from
Consumers over the age of thirteen (13) only if:
1.
The Processing purpose of such Personal Data would be obvious to a reasonable
Consumer based on the context of the collection and use of the Personal Data, and the
relationship between the Controller and Consumer;
2.
Sensitive Data Inferences are permanently deleted within twenty-four (24) hours of
collection or of the completion of the Processing activity, whichever comes first;
3.
Sensitive Data Inferences are not transferred, sold, or shared with any Processors,
Affiliates, or Third-Parties; and
4.
The Personal Data and any Sensitive Data Inferences are not Processed for any purpose
other than the express purpose disclosed to the Consumer.
C
nently deleted within twenty-four (24) hours of
collection or of the completion of the Processing activity, whichever comes first;
3.
Sensitive Data Inferences are not transferred, sold, or shared with any Processors,
Affiliates, or Third-Parties; and
4.
The Personal Data and any Sensitive Data Inferences are not Processed for any purpose
other than the express purpose disclosed to the Consumer.
C.
If a Controller will delete Sensitive Data Inferences within twenty-four (24) hours, pursuant to this
section, they must (1) include description of the Sensitive Data Inferences subject to this
provision and the retention and deletion timeline for such Sensitive Data Inferences in its privacy
notice, pursuant to 4 CCR 904-3, Rule 6.03, and (2) include the details of the deletion and
verification process in the Controller’s Data Protection Assessment, pursuant to 4 CCR 904-3,
Rule 8.04.
Rule 6.11
DOCUMENTATION CONCERNING DUTIES OF CONTROLLERS
A.
Controllers shall maintain records of all Consumer Data Rights requests made pursuant to C.R.S.
§ 6-1-1306 for at least twenty-four (24) months. Such records shall include, at a minimum, each
of the following:
1.
The date of request;
2.
The Consumer Data Rights request type;
3.
The date of the Controller’s response;
4.
The nature of the Controller’s response;
5.
The basis for the denial of the request if the request is denied in whole or in part; and
6.
The existence and resolution of any Consumer appeal to a denied request.
B.
Controllers shall maintain a record of all Data Rights requests made pursuant to C.R.S. § 6-1-
1306 with which the Controller has previously complied. Such records shall be retained for at
least twenty-four (24) months and shall be made available at the completion of a merger,
acquisition, bankruptcy, or other transaction in which a Third Party assumes control of Personal
Data to ensure any new Controller continues to recognize the Consumer’s previously exercised
Data Rights.
C
.R.S. § 6-1-
1306 with which the Controller has previously complied. Such records shall be retained for at
least twenty-four (24) months and shall be made available at the completion of a merger,
acquisition, bankruptcy, or other transaction in which a Third Party assumes control of Personal
Data to ensure any new Controller continues to recognize the Consumer’s previously exercised
Data Rights.
C.
Controllers shall maintain documents sufficient to demonstrate compliance with 4 CCR 904-3,
Rules 6.07, 6.08, and 7.06 for as long as the Processing activity continues, and for at least
twenty-four (24) months after the conclusion of Processing activity.
D.
Required records shall be maintained in a readable format, appropriate to the sophistication and
size of the Controller’s business.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

27
E.
The Controller shall implement and maintain reasonable security procedures and practices,
consistent with 4 CCR 904-3, Rule 6.09, in maintaining all required records.
F.
Personal Data maintained pursuant to this 4 CCR 904-3, Rule 6.11, where that information is not
used for any other purpose, shall not be subject to Data Rights requests.
G.
Personal Data maintained for required documentation shall not be used for any other purpose
except as reasonably necessary for the business to review and modify its processes for
compliance with the Colorado Privacy Act, C.R.S. § 6-1-1301, et seq., and these rules. Personal
Data maintained for required documentation shall not be shared with any Third Party except as
necessary to comply with a legal obligation or as part of a merger, acquisition, bankruptcy, or
other transaction in which a Third Party assumes control of Personal Data.
H.
Other than as required by this subsection and 4 CCR 904-3, Rule 4.06, a Controller is not
required to retain Personal Data solely for the purpose of fulfilling a Data Rights request made
under the Colorado Privacy Act, C.R.S. § 6-1-1301, et seq
y with a legal obligation or as part of a merger, acquisition, bankruptcy, or
other transaction in which a Third Party assumes control of Personal Data.
H.
Other than as required by this subsection and 4 CCR 904-3, Rule 4.06, a Controller is not
required to retain Personal Data solely for the purpose of fulfilling a Data Rights request made
under the Colorado Privacy Act, C.R.S. § 6-1-1301, et seq.
Rule 6.12
BIOMETRIC IDENTIFIER NOTICE
A.
Controllers required to provide a Biometric Identifier Notice shall comply with all requirements for
disclosures and communications to Consumers provided in 4 CCR 904-3, Rule 3.02.
B.
The Biometric Identifier Notice shall occur at or before the initial collection or Processing of any
Biometric Identifiers, or before a material change to the Processing purpose of a Biometric
Identifier.
C.
A Biometric Identifier Notice must be clear. Information contained in such notice shall be:
1.
Concrete and definitive, avoiding abstract or ambivalent terms that may lead to varying
interpretations.
2.
If included in a privacy notice, clearly labeled, such that Consumers seeking to
understand a Controller’s collection and use of Biometric Identifiers can easily access the
section of the privacy notice containing relevant information.
D.
A Biometric Identifier Notice must be reasonably accessible. Such notice may be:
1.
A separate notice, or included within a general privacy notice if the privacy notice is
clearly labeled as required by 4 CCR 904-3, Rule 6.12(C)(2); and
2.
Made available in its entirety prior to the collection or Processing of Biometric Identifiers,
or linked from a website’s homepage, and if applicable, a mobile application’s app store
page or download page.
a.
A link made available on the homepage of a website or on a mobile application’s
app store page or download page must be conspicuous and must clearly indicate
it relates to Biometric Identifiers in the link text
s entirety prior to the collection or Processing of Biometric Identifiers,
or linked from a website’s homepage, and if applicable, a mobile application’s app store
page or download page.
a.
A link made available on the homepage of a website or on a mobile application’s
app store page or download page must be conspicuous and must clearly indicate
it relates to Biometric Identifiers in the link text. A Controller that Processes
Biometric Identifiers and maintains an application on a mobile or other device
shall also include a link to the Biometric Identifier Notice in the application’s
settings menu.
b.
If the link directs to a privacy notice, it must point the Consumer to the specific
section of the privacy notice that includes the Biometric Identifier Notice
disclosures.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

28
E.
A Controller that does not operate a website shall make the Biometric Identifier Notice
conspicuously available to Consumers through a medium regularly used by the Controller to
interact with Consumers. For instance, if a Controller interacts with a Consumer offline, an offline
version of the privacy notice must be available to the Consumer.
Rule 6.13
DUTY REGARDING MINOR DATA – KNOWLEDGE STANDARD
A.
The following factors may be considered when determining if a Controller willfully disregards that
a Consumer is a Minor as contemplated in C.R.S. § 6-1-1308.5:
1.
If the Controller has directly received credible information from a parent or Consumer
indicating that the Consumer is a Minor.
a.
Example: A Controller requires or allows Consumers to provide their date of birth
at sign up and the Consumer indicates they are a Minor.
b.
Example: A Controller requires Consumers to provide their date of birth at sign
up, which can be edited once registration is completed. A Consumer uses a fake
birthdate to sign up and subsequently revises their birthdate after registration to
indicate that they are a Minor.
c
ller requires or allows Consumers to provide their date of birth
at sign up and the Consumer indicates they are a Minor.
b.
Example: A Controller requires Consumers to provide their date of birth at sign
up, which can be edited once registration is completed. A Consumer uses a fake
birthdate to sign up and subsequently revises their birthdate after registration to
indicate that they are a Minor.
c.
Example: A Controller directly receives a credible report from a parent about a
Minor using the service.
d.
Example: A Consumer provides their age in the bio section of the profile on a
Consumer’s service indicating that they are a Minor.
e.
Example: A Consumer provides relevant indicia that they are a Minor, such as
year of birth, in the profile or account set up of a service.
2.
If the Controller has intentionally directed the website or service to Minors, considering
different factors such as marketing or promotional materials that refer to the intended
audience as “minors” or “teens”, hosting or displaying advertisements that are directed to
Minors, or empirical evidence demonstrating that the intended or actual audience is
largely composed of Minors.
a.
Example: A Controller creates and distributes marketing and promotional
materials related to the website or service that specifically appeal to Minors.
b.
Example: A Controller tells advertising partners that advertisements on its
website or service will overwhelmingly reach an audience of Minors.
3.
If the Controller has categorized a Consumer as a Minor to serve advertising on the
platform or service.
a.
Example: A Controller uses Consumer data (such as user-generated content or
data provided by a third party) to estimate a Consumer’s age, which indicates
that they are a Minor, and the Controller serves ads to them based on that
estimation.
B
ll overwhelmingly reach an audience of Minors.
3.
If the Controller has categorized a Consumer as a Minor to serve advertising on the
platform or service.
a.
Example: A Controller uses Consumer data (such as user-generated content or
data provided by a third party) to estimate a Consumer’s age, which indicates
that they are a Minor, and the Controller serves ads to them based on that
estimation.
B.
In addition to the factors included in this part 4 CCR 904-3, Rule 6.13, Controllers may consider
statutes, administrative rules, and administrative guidance concerning age knowledge standards
from other jurisdictions when evaluating the appropriateness of treating a Consumer as a Minor
as contemplated in C.R.S. § 6-1-1308.5.

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

29
C.
The factors included in this part 4 CCR 904-3, Rule 6.13 are not exhaustive, and no one factor is
dispositive when considering if a Controller willfully disregards that a Consumer is a Minor as
contemplated in C.R.S. § 6-1-1308.5. The Attorney General shall consider a totality of the
circumstances when evaluating if a Controller willfully disregards that a Consumer is a Minor as
contemplated in C.R.S. § 6-1-1308.5.
D.
Consistent with C.R.S. § 6-1-1304(3)(f), nothing in this part shall require a Controller or Processor
to implement a commercially reasonable age verification or age-gating system or otherwise
affirmatively collect, retain, use, link, or combine personal data concerning a Consumer that it
would not otherwise collect, retain, use, link, or combine in the ordinary course of business,
including, for example, the age of consumers.
Rule 6.14
DUTY REGARDING MINOR DATA – SYSTEM DESIGN FEATURES
A.
The following factors may be considered when determining if a system design feature significantly
increases, sustains, or extends a Minor’s use of an online service, product, or feature and is
subject to the consent requirement as contemplated in C.R.S. § 6-1-1308.5:
1
course of business,
including, for example, the age of consumers.
Rule 6.14
DUTY REGARDING MINOR DATA – SYSTEM DESIGN FEATURES
A.
The following factors may be considered when determining if a system design feature significantly
increases, sustains, or extends a Minor’s use of an online service, product, or feature and is
subject to the consent requirement as contemplated in C.R.S. § 6-1-1308.5:
1.
Whether the controller developed or deployed the system design feature primarily to
significantly increase, sustain, or extend a Minor’s use of or engagement with an online
service, product, or feature;
2.
Whether the system design feature has been shown by competent and reliable empirical
evidence to cause harm due to increased use of or engagement with an online service,
product, or feature;
3.
Whether the system design feature has the substantial effect of subverting or impairing
Minor autonomy, decision making or choice, or unfairly, fraudulently, or deceptively
manipulating or coercing a Minor.
B.
A system design feature will likely not be found to significantly increase, sustain, or extend a
Minor’s use of an online service, product, or feature:
1.
If the Minor expressly and unambiguously requested specific media or category of media,
the Minor subscribed to specific media by the author, creator, or poster, or the Minor has
subscribed to a page or group featuring specific media, provided that the media is not
recommended, selected, or prioritized for display based, in whole or in part, on other
information associated with the Minor or the Minor's device;
2.
If media are recommended, selected, or prioritized only in response to a specific search
inquiry by the Minor, or is exclusively next in a pre-existing sequence from the same
author, creator, poster, or source;
3.
If the system design feature is one that is necessary to the core functionality of an online
service, product, or feature;
4
formation associated with the Minor or the Minor's device;
2.
If media are recommended, selected, or prioritized only in response to a specific search
inquiry by the Minor, or is exclusively next in a pre-existing sequence from the same
author, creator, poster, or source;
3.
If the system design feature is one that is necessary to the core functionality of an online
service, product, or feature;
4.
If the system design feature is based on Personal Data that is not persistently associated
with the Minor or the Minor’s device;
5.
If the system design feature does not consider the Minor’s previous interactions with
media generated or shared by other Consumers;
6.
If the online service, product, or feature contains countervailing measures that could
mitigate the harm or other negative effects of the system design feature, such as default
time of day or time use limits, or required parental controls;

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

30
7.
If the system design feature’s primary function is to enhance the safety of the platform for
Minors, remove spam, or filter out age-inappropriate content.
C.
The fact that a system design feature is commonly used is not, alone, enough to demonstrate that
any particular feature does not significantly increase, sustain, or extend a Minor’s use of an online
service, product, or feature.
D.
In addition to the factors included in this part 4 CCR 904-3, Rule 6.13, Controllers may consider
statutes, administrative rules, and administrative guidance concerning system design features
from other jurisdictions when evaluating the likelihood that a system design feature significantly
increases, sustains, or extends a Minor’s use of an online service, product, or feature as
contemplated in C.R.S. § 6-1-1308.5.
E
actors included in this part 4 CCR 904-3, Rule 6.13, Controllers may consider
statutes, administrative rules, and administrative guidance concerning system design features
from other jurisdictions when evaluating the likelihood that a system design feature significantly
increases, sustains, or extends a Minor’s use of an online service, product, or feature as
contemplated in C.R.S. § 6-1-1308.5.
E.
The factors included in this part 4 CCR 904-3, Rule 6.14 are not exhaustive, and no one factor is
dispositive when determining if a system design feature significantly increases, sustains, or
extends a Minor’s use of an online service, product, or feature. The Attorney General shall
consider a totality of the circumstances when evaluating if a system design feature significantly
increases, sustains, or extends a Minor’s use of an online service, product, or feature as
contemplated in C.R.S. § 6-1-1308.5.
F.
Consistent with C.R.S. § 6-1-1304(g), this Rule does not impose any obligation on a Controller or
Processor that adversely affects the rights of any person to freedom of speech or the freedom of
the press guaranteed by the First Amendment to the United States Constitution.
PART 7
CONSENT
Rule 7.01
AUTHORITY AND PURPOSE
A.
The statutory authority for the rules in this Part 7 is C.R.S. §§ 6-1-108(1), 6-1-1303(5), 6-1-1306,
6-1-1308, 6-1-1308.5 (eff. Oct. 1, 2025), 6-1-1313 and 6-1-1314(4) (eff. July 1, 2025). The
purpose of the rules in this Part 7 is to provide clarity on the requirements to obtain Consent when
Consent is required under the statute, including the prohibition against obtaining agreement
through the use of Dark Patterns.
Rule 7.02
REQUIRED CONSENT
A.
Pursuant to C.R.S. §§ 6-1-1303(5), 6-1-1306(1)(a)(IV)(C), 6-1-1308(4), 6-1-1308(7), 6-1-1308.5,
and 6-1-1314(4) a Controller must obtain valid Consumer Consent prior to:
1.
Processing a Consumer’s Sensitive Data;
2.
Processing Personal Data concerning a known Child, in which case the Child’s parent or
lawful guardian must provide Consent;
3
h the use of Dark Patterns.
Rule 7.02
REQUIRED CONSENT
A.
Pursuant to C.R.S. §§ 6-1-1303(5), 6-1-1306(1)(a)(IV)(C), 6-1-1308(4), 6-1-1308(7), 6-1-1308.5,
and 6-1-1314(4) a Controller must obtain valid Consumer Consent prior to:
1.
Processing a Consumer’s Sensitive Data;
2.
Processing Personal Data concerning a known Child, in which case the Child’s parent or
lawful guardian must provide Consent;
3.
Selling a Consumer’s Personal Data, Processing a Consumer’s Personal Data for
Targeted Advertising, or Profiling in furtherance of Decisions that Produce Legal or
Similarly Significant Effects Concerning a Consumer after the Consumer has exercised
the right to opt out of the Processing for those purposes;
4.
Processing Personal Data for purposes that are not reasonably necessary to, or
compatible with, the original specified purposes for which the Personal Data are
Processed;
5.
Processing the Personal Data of a Consumer whom the Controller actually knows or
willfully disregards is a Minor as contemplated in C.R.S. § 6-1-1308.5(2);

CODE OF COLORADO REGULATIONS
4 CCR 904-3
Attorney General-Consumer Protection Section

31
6.
Using any system design feature to significantly increase, sustain, or extend the use of
an online service, product, or feature by a Consumer whom the Controller actually knows
or willfully disregards is a Minor, as contemplated in C.R.S § 6-1-1308.5(2); and
7.
Selling, leasing, trading, disclosing, redisclosing, or otherwise disseminating Biometric
Identifiers, subject to the exceptions in 6-1-1314(4)(b).
B.
Controllers may rely upon valid consent obtained prior to July 1, 2023, to continue to Process a
Consumer’s previously collected Personal Data, including Sensitive Data, collected before July 1,
2023. Consent obtained before July 1, 2023, shall be considered valid only if it would comply with
the requirements set forth in C.R.S. §§ 6-1-1303(5), 6-1-1306(1)(a)(IV)(C), 6-1-1308(4), and 6-1-
1308(7) and Part 7 of these rules.
1
lid consent obtained prior to July 1, 2023, to continue to Process a
Consumer’s previously collected Personal Data, including Sensitive Data, collected before July 1,
2023. Consent obtained before July 1, 2023, shall be considered valid only if it would comply with
the requirements set forth in C.R.S. §§ 6-1-1303(5), 6-1-1306(1)(a)(IV)(C), 6-1-1308(4), and 6-1-
1308(7) and Part 7 of these rules.
1.
Controllers that do not obtain valid Consent prior to July 1, 2023 to continue to use, store,
or otherwise Process Sensitive Data collected prior to this date must obtain valid
Consent, as required by C.R.S. §§ 6-1-1303(5), 6-1-1306(1)(a)(IV)(C), 6-1-1308(4), and
6-1-1308(7) and Part 7 of these rules, by July 1, 2024 to continue to Process the
previously collected Sensitive Data.
2.
If a Controller has collected Personal Data prior to July 1, 2023 and the Processing
purpose changes after July 1, 2023 such that it is considered a secondary use pursuant
to C.R.S. § 6-1-1308(4) and 4 CCR 904-3, Rule 6.08, the Controller must obtain valid
Consent, as required by C.R.S. §§ 6-1-1303(5), 6-1-1306(1)(a)(IV)(C), 6-1-1308(4), and
6-1-1308(7) and Part 7 of these rules, at the time the Processing purpose changes to
continue to Process the previously collected Personal Data.
C.
Notwithstanding the above, a Controller Processing Sensitive Data Inferences is not required to
obtain Consent for the Processing activity if the Processi

[Text truncated at 120,000 characters. The full text is on the page linked above.]

## Nearby sections

- [4 CCR 904-1 REPOSSESSOR BONDS](https://www.frixlaw.com/law-library/statutes/STATE_CO_CCR_4_CCR_904_1.md)
- [4 CCR 904-2 INVESTIGATIVE HEARING RULES](https://www.frixlaw.com/law-library/statutes/STATE_CO_CCR_4_CCR_904_2.md)
- [4 CCR 904-3 COLORADO PRIVACY ACT RULES](https://www.frixlaw.com/law-library/statutes/STATE_CO_CCR_4_CCR_904_3.md)
- [4 CCR 904-4 TRANSFERABILITY OF TRAINING AND CREDENTIALS SUBJECT TO TRAINING REPAYMENT AGREEMENT PROVISIONS](https://www.frixlaw.com/law-library/statutes/STATE_CO_CCR_4_CCR_904_4.md)
- [4 CCR 904-5 ONLINE DATING SAFETY ACT RULES](https://www.frixlaw.com/law-library/statutes/STATE_CO_CCR_4_CCR_904_5.md)

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/statutes/STATE_CO_CCR_4_CCR_904_3. Check the current official text before relying on it. Not legal advice.
