{"id":410,"date":"2021-07-02T13:02:20","date_gmt":"2021-07-02T17:02:20","guid":{"rendered":"https:\/\/pbacyber.com\/?p=410"},"modified":"2021-07-02T13:05:39","modified_gmt":"2021-07-02T17:05:39","slug":"a-cheat-sheet-for-colorados-forthcoming-new-privacy-act","status":"publish","type":"post","link":"https:\/\/pbacyber.com\/index.php\/2021\/07\/02\/a-cheat-sheet-for-colorados-forthcoming-new-privacy-act\/","title":{"rendered":"A Cheat Sheet for Colorado\u2019s Forthcoming New Privacy Act"},"content":{"rendered":"<p>By Joshua A. Mooney, Kennedys<\/p>\n<p>&nbsp;<\/p>\n<p>The Colorado Privacy Act (\u201cColoPA\u201d or \u201cAct\u201d) has been sent to Governor Jared Polis\u2019s office to be signed into law, making Colorado the third state to enact comprehensive privacy legislation (coming behind California and Virginia). Once signed, the Act will take effect on July 31, 2023. However, its requirements are substantive, having GDPR-like provisions addressing data security, consumers\u2019 data rights, and mandatory contracting requirements\/clauses. For a quick read, here is a brief snapshot of some highlights of the Act:<\/p>\n<h6 style=\"padding-left: 40px;\"><strong>1. Scope, enforcement and penalties<\/strong><\/h6>\n<p style=\"padding-left: 40px;\">The Act applies to companies that conduct business or produce products or services <u>intentionally targeted to Colorado residents<\/u> and either: (a) control or process personal data of <u>more than 100,000 consumers<\/u> annually; or (b) derive <u>any<\/u> revenue from the sale of personal data, and control or process the personal data of at least 25,000 consumers. (6-1-1304.(1).)<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\">The ColoPA broadly defines \u201c<strong>personal data<\/strong>\u201d as (a) \u201cinformation that is linked or reasonably linked to an identified or identifiable individual,\u201d but does not include \u201cde-identified data or publicly available information.\u201d (6-1-1303.(17).) An \u201c<strong>identified or identifiable individual<\/strong>\u201d is \u201can individual who can be readily identified, directly or indirectly, in particular reference to an identifier such as a name, an identification number, specific geolocation data, or an online identifier.\u201d (6-1-1303.(16).) The Act broadly also defines \u201c<strong>sell<\/strong>\u201d or \u201c<strong>sale<\/strong>\u201d as \u201cthe exchange of personal data for monetary or other valuable consideration by a controller to a third party.\u201d (6-1-1303.(23).)<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\">There is no private right of action. However, the Act provides district attorneys with enforcement rights. Thus, companies may see enforcement of Colorado\u2019s privacy legislation at both the state and local levels, and with greater penalties, too, with penalties topping at $20,000 per violation.<\/p>\n<p>&nbsp;<\/p>\n<h6 style=\"padding-left: 40px;\"><strong>2. Duties of a controller<\/strong><\/h6>\n<p style=\"padding-left: 40px;\">Briefly, the ColoPA imposes upon a controller the duties of transparency, specified purpose, data minimization, avoidance of secondary use, care, anti-discrimination, and consent when using sensitive data. (6-1-1308.) A detailed description of these duties is as follows:<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\"><strong>Transparency<\/strong>. Controllers must provide consumers with \u201ca reasonably accessible, clear and meaningful privacy notice\u201d that includes:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>(i) categories of personal data collected and\/or processed;<\/li>\n<li>(ii) purposes for which personal data is processed;<\/li>\n<li>(iii) how a consumer may exercise his or her rights, including right of appeal;<\/li>\n<li>(iv) categories of personal data shared with third parties;<\/li>\n<li>(v) categories of third parties with whom personal data is shared; and<\/li>\n<li>(vi) if a controller sells personal data or uses it for \u201ctargeted advertising,\u201d the controller must \u201cclearly and conspicuously\u201d disclose the sale or processing as well as the consumer\u2019s right to opt out.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\"><strong>Purpose Specification.<\/strong> The controller must specify the purposes for which personal data is collected and processed.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\"><strong>Data Minimization.<\/strong> The controller\u2019s collection of personal data \u201cmust be adequate, relevant and limited to what is reasonably necessary in relation to the specified purposes for which the data are processed.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\"><strong>No Secondary Use.<\/strong> A controller may not process personal data that is \u201cnot reasonably necessary in relation to the specified purposes for which the data are processed, unless the controller first obtains the consumer\u2019s consent.\u201d This is the mirror image of the duty of data minimization.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\"><strong>Duty of Care. <\/strong>The controller must undertake \u201creasonable measures to secure personal data during both store and use from unauthorized acquisition\u201d that are \u201cappropriate to the volume, scope, and nature of the personal data processed and the nature of the business.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\"><strong>Anti-Discrimination. <\/strong>The controller may not violate any state or federal discrimination laws in the collection or processing of personal data.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\"><strong>Consent to Process Sensitive Data<\/strong>. A controller may not process sensitive data without first obtaining the consumer\u2019s consent or, if the consumer is a child, the consent of the child\u2019s parent or legal guardian. The Act defines \u201c<strong>sensitive data<\/strong>\u201d as \u201c(a) personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life or sexual orientation, or citizenship or citizenship status; (b) genetic or biometric data that may be processed for the purpose of uniquely identifying an individual; or (c) personal data form a known child.\u201d (6-1-1303.(24).)<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\"><strong>Data security. <\/strong>Controllers and processors alike also must \u201cimplement appropriate technical and organizational measures to ensure a level of security appropriate to the risk and establish a clear allocation of the responsibilities between them to implement the measures.\u201d (6-1-1305.(4).)<\/p>\n<p>&nbsp;<\/p>\n<h6 style=\"padding-left: 40px;\"><strong>3. Mandatory data processing agreements<\/strong><\/h6>\n<p style=\"padding-left: 40px;\">Much like when effecting data transfers under GDPR, the ColoPA in effect requires data processing agreements that have mandatory contractual provisions. (6-1-1305.(5).) Under the Act, any data transfer to a processor must be governed by a written contract that:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Details processing instructions, including the nature and purpose of the processing;<\/li>\n<li>Identifies the types of personal data to be processed and the duration of such processing; and<\/li>\n<li>Imposes duties of confidentiality.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\">\u201c[T]aking into account the context of the processing,\u201d the contract also must require the parties to \u00a0\u201cimplement appropriate technical and organizational measures to ensure a level of security appropriate to the risk and establish a clear allocation of the responsibilities between them\u00a0 to implement the measures,\u201d including that the processor:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>If a sub-processor is used, require the sub-processor to adhere to the same security requirements and also provide the controller with advance notice to give the controller opportunity to object to the sub-processor\u2019s use;<\/li>\n<li>At the controller\u2019s choice, delete or return all personal data at the end of the contract;<\/li>\n<li>Provide the controller all information necessary to demonstrate compliance with the ColoPA requirements; and<\/li>\n<li>Permit \u201cand contribute to, reasonable audits and inspections\u201d by the controller or its representative.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\">(6-1-1305.(5).) For audit requirements, with the controller\u2019s consent, a processor may retain, at its own cost, an independent auditor to conduct an annual audit of its \u201cpolicies and technical and organizational measures\u201d using \u201can appropriate and accepted\u201d framework or control. (<em>Id.<\/em>) Controllers and processors cannot contract out of their ColoPA liability. (6-1-1305.(6).)<\/p>\n<h3><\/h3>\n<h6 style=\"padding-left: 40px;\"><strong>4. Consumer rights<\/strong><\/h6>\n<p style=\"padding-left: 40px;\">Consumers have rights of access, correction, deletion, and portability over their personal data. (6-1-1306.(1)(b) \u2013 (e).) They also have the right to opt-out from the processing of their personal data for targeted advertising, sale of personal data, or profiling. (6-1-1306.(1)(a).) Controllers that process personal data for targeted advertising or the sale of personal data must provide \u201ca clear and conspicuous method to exercise the right to opt out.\u201d (6-1-1306.(1)(a)(III).)<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\">Controllers have 45 days to respond to a consumer request, with the right to a 45-day extension \u201cwhere reasonably necessary.\u201d (6-1-1306.(2)(a).) The controller also must establish an \u201cinternal process\u201d to allow consumers the right to appeal any decision not to take action in response to a consumer request. (6-1-1306.(3)(a).)<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\">A controller need not comply with consumer requests if the personal data is de-identified. (6-1-1307.(1).) The Act defines \u201c<strong>de-identified data<\/strong>\u201d as \u201cdata that cannot be reasonably used to infer information about, to otherwise be linked to, an identified or identifiable individual, or a device linked to such an individual, if the controller that possess the data: (a) takes reasonable measures to ensure that the data cannot be associated with an individual; (b) publically commits to maintain and use the data only in a de-identified fashion and not attempt to re-identify the data; and\u00a0 (c) contractually obligates any recipients of the information to comply with these same requirements. (6-1-1303.(11).)<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 40px;\">Rights, other than the right to opt out, do not apply to pseudonymous data where the controller can demonstrate that the information necessary to identify the consumer is kept separately and is inaccessible to the controller. (6-1-1307.(3).) The Act defines \u201c<strong>pseudonymous data<\/strong>\u201d as \u201cpersonal data that can no longer be attributed to a specific individual without the use of additional information if the additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data re not attributed to a specific individual.\u201d (6-1-1303.(22).)<\/p>\n<p>&nbsp;<\/p>\n<h6 style=\"padding-left: 40px;\"><strong>5. Some differences with California and Virginia law<\/strong><\/h6>\n<p style=\"padding-left: 40px;\">A more detailed comparison of the Colorado Privacy Act with the California Privacy Rights Act and Virginia Consumer Data Protection Act is forthcoming. In the meantime, here are some notable differences:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Like the Virginia law, and unlike California, the ColoPA exempts personal information generated within the employment and business-to-business contexts.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>While all three privacy acts have thresholds to apply to companies that collect annual the personal data of 100,000 consumers, the ColoPA also applies to companies that derive <u>any revenue<\/u> from data sales and collect the personal data of 25,000 Colorado consumers. (Virginia law applies to companies that derive more than 50% of their gross revenue from the sale of personal data and collect the personal data of 25,000 Virginia consumers. The CPRA\u2019s other thresholds are for companies that have greater than $25 million in gross revenue, or derive at least\u00a050% of annual revenue from sharing or selling personal information of California consumers.)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>The ColoPA applies to nonprofits,\u201d unlike California or Virginia.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>The ColoPA provides district attorneys with enforcement rights.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>The ColoPA has higher penalties. Compare $20,000 per violation (ColoPA) with $7,500 per violation (California and Virginia law).<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<hr \/>\n<p>Joshua Mooney is a partner at <a href=\"https:\/\/kennedyslaw.com\/\" target=\"_blank\" rel=\"noopener\">Kennedys<\/a> in Philadelphia and a member of the law firm\u2019s global cybersecurity and data compliance team.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Joshua A. Mooney, Kennedys &nbsp; The Colorado Privacy Act (\u201cColoPA\u201d or \u201cAct\u201d) has been sent to Governor Jared Polis\u2019s office to be signed into law, making Colorado the third state to enact comprehensive privacy legislation (coming behind California and Virginia). Once signed, the Act will take effect on July 31, 2023. However, its requirements <br \/><a class=\"read-more-button\" href=\"https:\/\/pbacyber.com\/index.php\/2021\/07\/02\/a-cheat-sheet-for-colorados-forthcoming-new-privacy-act\/\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[39,4],"tags":[],"_links":{"self":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/410"}],"collection":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/comments?post=410"}],"version-history":[{"count":4,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/410\/revisions"}],"predecessor-version":[{"id":414,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/410\/revisions\/414"}],"wp:attachment":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/media?parent=410"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/categories?post=410"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/tags?post=410"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}