Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • Senate Bill Would Require GAO to ‘Pick Up’ After DOGE With Cybersecurity Audits
    • Bicameral Legislation Would Restrict Use of Cell-Site Simulators
    • Bipartisan Senate Bill Aims to Jump-Start Transition to Quantum-Proof Encryption
    • House Bill Would Ban DoT From Using Chinese Mapping Tech
    • Privacy Advocates, Industry Groups Take Sides on FCC’s CALEA Cybersecurity Ruling
    • Proposed Privacy Rule Changes Open for Comment in Colorado
    • Rules on Accessible Deletion Mechanism Open for Comment in California
    • Senate Hearing Highlights Calls for National Data Protection Rules
    • Toolkit for Vulnerable Adult Data Protection Published by Irish DPC
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Proposed Privacy Rule Changes Open for Comment in Colorado, (Jul 31, 2025)

    By Tony Foley

    The Colorado Department of Law (DOL) has filed a set of proposed draft amendments to rules implementing the Colorado Privacy Act (CPA) that seek to clarify changes to the law made by a pair of recently enacted amendments to the CPA regarding online d ...

    By Tony Foley

    The Colorado Department of Law (DOL) has filed a set of proposed draft amendments to rules implementing the Colorado Privacy Act (CPA) that seek to clarify changes to the law made by a pair of recently enacted amendments to the CPA regarding online data protections for minors and definitions concerning sensitive personal information.

    According to the department’s CPA rulemaking page, the proposed regulatory amendments relate to the enactment of S.B. 41, 74th Leg, 2d Sess. (Colo. 2024), which added enhanced protections when a minor’s data is processed and there is a heightened risk of harm to a minor, and S.B. 276, 75th Leg., Reg Sess. (Colo. 2025), which, while primarily dealing with issues related to the civil rights of immigrants, amended the CPA with respect to the definition of “precise geolocation data” and added restrictions on the sale of sensitive personal data without consent.

    Children’s online protection. S.B. 41 added a variety of provisions to the CPA related to the obligations of controllers and processors regarding the data of minors (CPR, June 3, 2024). The draft amended rules add rules 6.13 and 6.14 to part 6 of the rules to implement these provisions.

    Specifically, draft rule 6.13 sets forth principles and provides examples to aid in determining if a controller has willfully disregarded that a consumer is a minor. The rule is designed to clarify provisions in Colo. Rev. Stat. §6-1-1308.5 requiring controllers providing online services, products, or features to consumers that the controller actually knows, or willfully disregards, is a minor to use reasonable care to avoid a heightened risk of harm caused by the online service, product, or feature.

    Draft Rule 6.14 identifies considerations for determining what constitutes a system design feature that significantly increases, sustains, or extends a minor’s use of an online service, product, or feature. Under the amendments to the CPA adding Colo. Rev. Stat. 6-1-1308.5, controllers employing such features are required to obtain consent from the minor or a parent or legal guardian. The proposed amendments also adjust existing Rule 7.03 to add language regarding obtaining consent to use a design system feature as outlined above. Specifically, the proposed rule would provide that if system design feature is turned off by default and later turned on or enabled by a minor, this act will constitute affirmative consent.

    Precise geolocation data. S.B. 276 amended the CPA to add precise geolocation data to the defined categories of sensitive data as provided in the law and clarified a controller’s duty to obtain consent prior to the processing or sale of sensitive data. The proposed rule amendments remove language from the regulation’s defined terms (in rule 2.02) to remove prior language regarding precise geolocation data, which was rendered irrelevant by the statutory change.

    Next steps. According to the DOL’s notice of proposed rulemaking, a public hearing on the amended rules will be held on Sept. 10, both in-person and virtually. The NPRM provides a link to register for the hearing, which is mandatory for virtual attendees but optional for persons attending in person. Prior to the hearing, interested parties may submit written comments through the CPA online comment portal.

    News: StateLegislation DataPrivacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use