Skip to Main Content
Colorado Attorney General

Phil Weiser

Colorado Attorney General

File A Complaint
  • About Us
    • Attorney General Bio & Photos
    • Vision & Values
    • Senior Staff & Organization
    • Colorado Attorney General Annual Report
    • Attorney General Opinions
    • Budget & Accounting
    • Contact Our Office
  • Sections
    • Administration
    • Civil Litigation & Employment Law
    • Consumer Protection
    • Criminal Appeals
    • Criminal Justice
    • Natural Resources & Environment
    • Division of Community Engagement
    • Revenue & Regulatory Law
    • State Services
  • Careers
    • Attorney & Other Non-Classified Positions
    • Fellowships
    • Internships
    • Classified Staff Positions
    • Other Opportunities to Join our Team
  • Media Center
    • Press Room
    • Colorado Open Records Act – CORA
  • Resources
    • Survivors of Childhood Sexual Abuse
    • Victim Assistance
    • Data Protection Laws
    • Colorado Privacy Act
    • Funding Opportunities
    • Office of Financial Empowerment
    • Code of Colorado Regulations
    • Colorado Revised Statutes
    • Transparency Online Project (TOPS)
  • Licensing
    • Business Resources
    • Collection Agencies & Debt Collectors
    • Credit Services Organizations
    • UCCC Licensing & Notification
    • Debt Management Services Providers
    • Health Club Bonds
    • Repossessors
    • Student Loan Servicer Licensing
    • Telemarketing
  • Recursos en español

Colorado Privacy Act: Attorney General’s Office proposes rules outlining Coloradans’ data privacy rights, how companies use personal info

Oct. 10, 2022 (DENVER) – Proposed Colorado Privacy Act rules were published today in the Colorado Register and on the Colorado Secretary of State’s website, drafted according to statute by the Colorado Attorney General’s Office. The office is encouraging the public to provide feedback on the rules’ contents.

The Colorado Privacy Act protects Coloradans’ privacy in part by granting them rights to access the data that companies have collected about them and to dictate whether and how companies can continue to collect, store, use, or sell their personal information. It also requires companies to be transparent about how they use personal data and to take precautions to reduce the risk that their data collection and use might pose to consumers. Finally, the law grants the attorney general the authority not only to hold entities accountable for failing to comply with their obligations, but also to draft rules that would clarify the act’s requirements and provide guidance for compliance.

The Department of Law invites comments from all members of the public regarding the proposed draft rules during the rulemaking process. Pre-rulemaking, informal input was considered during the drafting process, and today the comment submission portal once again opened to the public for the formal rulemaking. Comments will be made part of the rulemaking record and will be posted online.

“Public input is vital to the creation of successful rules that ensure consumers are protected and businesses have guidance on how to comply with those rules,” said Attorney General Phil Weiser. “That is why the attorneys in my office are carefully considering all the input provided so far and will continue to do so.”

Members of the public will also be able to provide oral comment through three virtual stakeholder meetings, which will take place on Nov. 10, 15, and 17, 2022. In addition to written and oral comments, the department will hold a rulemaking hearing at 10 a.m. Feb. 1, 2023. The hearing will be conducted both in person and by video conference.

The department invites public comment on any provisions included in the proposed draft rules, including the below:

  • Definitions: Part 2 of the draft rules includes definitions and clarifications of key terms used in the CPA and draft rules, including “biometric data,” “bona fide loyalty programs,” and “publicly available information.”
  • Consumers’ personal data rights: Part 4 of the draft rules describes how Coloradans may exercise new rights over their personal data, including the right to access and correct personal data and to opt out of the sale of personal data, or use of personal data for targeted advertising or profiling.
  • Universal opt-out mechanisms: Part 5 of the draft rules outlines the technical specifications for a tool or mechanism that will allow consumers to opt out of the processing of personal data by all businesses, instead of on a case-by-case basis.
  • Duties of entities using consumers’ data: Part 6 of the draft rules elaborates on the duties of entities that use and control consumers’ personal data, including obligations to safeguard personal data and protect consumer privacy.
  • Bona fide loyalty programs: Rule 6.05 clarifies disclosures and limitations associated with the user of Coloradan’s personal data for bona fide loyalty programs, or programs that offer discounts, rewards, or other actual value in exchange for personal data.
  • Consent: Part 7 of the draft rules clarifies the requirements for obtaining consent from Coloradans prior to specific uses of personal data, and addresses the prohibition against obtaining consumer agreement through unclear or ambiguous means, often called “dark patterns.”
  • Data protection assessments: Part 8 of the draft rules describes the required scope, content, and timing of data protection assessments, which controllers must complete before using personal data for activities that present a heightened risk of harm to Consumers.
  • Profiling: Part 9 of the draft rules addresses when and how controllers must respond to consumers request to opt-out of specific kinds of automated profiling as well as what controllers must include in data protection assessments when conducting automated profiling.

The full list of specific questions from the department is included in the Notice of Proposed Rulemaking, available here.

Under the privacy act, rules can be enforced starting July 1, 2023. Click here to submit comments.

###

Media Contact

Lawrence Pacheco

Director of Communications

(720) 508-6553 office | (720) 245-4689 cell

Lawrence.pacheco@coag.gov

Most Recent

Statewide grand jury indicts two in home remodeling fraud scheme

Jan. 6, 2026 (DENVER) — The statewide grand jury indicted Major T. Morgan III and Dillon Rosenbrook on 34 felony counts for their alleged roles in a widespread home remodeling fraud scheme that targeted homeowners across the Denver area, Attorney […]

Cannabis company to pay new fines after violating previous settlement with the Colorado Attorney General’s Office

Jan. 5, 2026 (DENVER) — Attorney General Phil Weiser announced today a new settlement with MC Global Holdings and associated entities after the cannabis company violated the terms of a prior settlement with the state from May 2025. “Deceiving consumers […]

Attorney General Phil Weiser suit challenges federal attack on gender-affirming care

Dec. 24, 2025 (DENVER) — Attorney General Phil Weiser today joined a multistate coalition of states in filing a lawsuit to block an unlawful declaration from Health and Human Services Secretary Robert F. Kennedy, Jr. that threatens health care providers […]

Office of the Attorney General
Colorado Department of Law
Ralph L. Carr Judicial Building
1300 Broadway, 10th Floor
Denver, CO 80203

(720) 508-6000

Contact the Office of the Attorney General

Contact

ACCESSIBILITY STATEMENT

DECLARACION DE ACCESIBILIDAD

Facebook
Twitter
LinkedIn
Instagram
YouTube
BlueSky