Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

Colorado · Privacy Act (CPA)

Duty of care & data-protection assessments.

Applies to: Controllers under the Colorado Privacy Act. Built · effective 1 Jul 2023

What the signed record shows

Duty-of-care security records, 45-day consumer-request signals, and assessment references.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: SB 21-190; C.R.S. §6-1-1306/1308/1309

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Colorado Privacy Act (CPA), SB 21-190, codified at C.R.S. sections 6-1-1301 to 6-1-1313 (this is the PRIVACY act, distinct from the Colorado AI Act). Provisions addressed:

§ 6-1-1306
Consumer personal data rights; controller responds within 45 days (one 45-day extension); appeals.
§ 6-1-1308
Duties of controllers; duty of care = reasonable data security measures; duty to avoid unlawful discrimination; transparency, purpose specification, data minimization.
§ 6-1-1309
Data protection assessments; Attorney General access and evaluation. Effective 1 July 2023. SECTION-NUMBER NOTE (verified 2026-06): the controller- duties section is § 6-1-1308, NOT § 6-1-1305 (which is "responsibility according to role" for processors).

Taken from the Regulayer entry for this instrument, which is built against the primary text.