Colorado Privacy Act Data Protection Assessments: Understanding the Requirements
Colorado's Privacy Act requires Data Protection Assessments before high-risk processing begins. Learn when a DPA is required, what it must include, how often it must be updated, the risks organizations should evaluate, and practical steps for building a compliant assessment framework.
The Colorado Privacy Act (CPA) requires controllers to conduct a Data Protection Assessment (DPA) before engaging in certain processing activities that present a heightened risk of harm to consumers. These include processing for targeted advertising, certain profiling activities, the sale of personal data, and the processing of sensitive data.
A Colorado DPA is more than a compliance formality. It requires organizations to identify and balance the benefits of the processing against the potential risks to consumers' rights, taking into account the effectiveness of available safeguards, the use of de-identified data, consumers' reasonable expectations, and the context of the processing.
The Colorado Attorney General has the authority to request and evaluate Data Protection Assessments to determine compliance with the CPA. However, the assessments remain confidential, are exempt from public disclosure under the Colorado Open Records Act, and producing them to the Attorney General does not waive applicable attorney-client privilege or work-product protection.
This article explains when a Colorado Data Protection Assessment is required, what it must include, how it should be maintained throughout the processing lifecycle, and practical considerations for building a compliant assessment program.
CO Rev Stat § 6-1-1309
Scope and Stakeholders
Section 4 CCR 904-3-8.02 establishes the scope and expectations for Colorado DPIA. Organizations should pay close attention to these requirements because they provide one of the most detailed regulatory frameworks for privacy risk assessments among U.S. state privacy laws.
An Assessment must be a genuine, thoughtful analysis. For every covered processing activity, the assessment must:
- identify and describe the risks to consumers' rights;
- document the safeguards and mitigation measures that were considered and implemented;
- evaluate the benefits of the processing;
- demonstrate that those benefits outweigh the remaining risks after safeguards are applied; and
- satisfy any additional requirements applicable to processing involving minors.
(CO Rules 4 CCR 904-3-8.02.A)
Colorado recognizes that many organizations already conduct privacy assessments to comply with other laws, including the GDPR or other U.S. state privacy laws. Rather than requiring duplicate work, the regulations permit organizations to reuse an existing assessment if it is reasonably similar in scope and effect to what Colorado requires. If the existing assessment does not fully address Colorado's requirements, the controller may submit a supplemental document addressing the missing elements. (CO Rules 4 CCR 904-3-8.02.B)
The level of detail depends on factors such as the sensitivity of the data, the level of risk, the size of the organization, and the complexity of the processing. (CO Rules 4 CCR 904-3-8.02.C)
Colorado allows a single Data Protection Assessment to cover a comparable set of processing operations when those operations:
- involve similar processing activities;
- present similar risks; and
- rely on similar systems and safeguards.
(CO Rules 4 CCR 904-3-8.02.D)
Example: The ACME Toy Store chain is considering using in-store paper forms to collect names, mailing addresses, and birthdays from Children that visit their stores, and using that information to mail a coupon and list of age-appropriate toys to each child during the Child's birth month and every November. ACME uses the same Processors and Processing systems for each category of mailings across all stores. ACME must conduct and document a data protection assessment because it is Processing Personal Data from known Children, which is Sensitive Data. ACME can use the same data protection assessment for Processing the Personal Data for the birthday mailing and November mailing across all stores because in each case it is collecting the same categories of Personal Data in the same way for the purpose of sending coupons and age-appropriate toy lists to Children.
A data protection assessment shall involve all relevant internal actors from across the Controller's organizational structure, and where appropriate, relevant external parties, to identify, assess and address the data protection risks. (Co. Rules 4 CCR 904-3-8.03)
Key Takeaways
- Colorado requires a meaningful analysis. A Data Protection Assessment (DPA) must be a genuine, thoughtful evaluation—not a check-the-box exercise.
- Existing assessments may be reused. DPAs prepared for other laws (such as the GDPR or another state privacy law) may satisfy Colorado's requirements if they are reasonably similar, with supplemental information added where necessary.
- The scope should be proportionate. The level of detail depends on factors such as the sensitivity of the data, the level of risk, the size of the organization, and the complexity of the processing.
- Similar processing activities can be grouped. A single DPA may cover comparable processing operations that involve similar purposes, risks, systems, and safeguards, reducing unnecessary duplication.
Content
Rather than leaving organizations to determine what constitutes an adequate assessment, the regulations identify the minimum information that controllers should document, the CPA provides a detailed roadmap. (See, CO Rules 4 CCR 904-3-8.04)
At a minimum, a Colorado DPA should include the following elements.
1. A Description of the Processing Activity: The assessment should begin with a concise overview of the processing activity being evaluated, including what the organization is doing and why the assessment is required.
2. The Personal Data Being Processed: Controllers should identify:
- the categories of personal data involved;
- whether the processing includes Sensitive Data;
- whether it involves personal data from minors or known children, where applicable; and
- the specific types of data being processed.
The sensitivity of the data directly influences the level of analysis expected.
3. The Context of the Processing: The assessment should explain the broader context of the processing, including:
- the relationship between the controller and the individuals whose data is processed;
- the reasonable expectations of those individuals; and
- any unique circumstances that may affect the level of privacy risk.
Consumer expectations play an important role in evaluating whether processing creates an unreasonable risk of harm.
4. How the Processing Operates: Colorado expects controllers to document the operational details of the processing activity, including:
- where the data comes from;
- the technologies, systems, and vendors involved;
- who receives access to the data, including processors, affiliates, and third parties;
- how the data is collected, used, stored, retained, and shared; and
- the specific categories of personal data involved.
The regulations recognize that the level of detail should be proportionate to the complexity and sensitivity of the processing.
5. The Purpose and Benefits of the Processing: The assessment should identify both the primary business purpose and the broader benefits of the processing. Benefits may include those flowing to:
- the organization;
- consumers;
- business partners;
- other stakeholders; or
- the public.
This information supports the balancing analysis required by the Colorado regulations.
6. A Detailed Analysis of Privacy Risks: One of the most significant aspects of Colorado's requirements is the breadth of risks that organizations are expected to consider. The assessment should evaluate reasonably foreseeable risks, including potential:
- Constitutional harms, such as speech harms or associational harms: These risks involve potential interference with fundamental constitutional freedoms, including freedom of speech, freedom of association, freedom of religion, and freedom of assembly. A processing activity may create constitutional harms if it discourages individuals from expressing themselves or participating in lawful activities because they fear being monitored or profiled.
Examples: Profiling individuals based on political affiliation, monitoring attendance at religious services or political events, or collecting data that could chill free expression.
- Intellectual privacy harms, such as the creation of negative inferences about an individual based on what an individual reads, learns, or debates: Intellectual privacy refers to an individual's ability to seek information, conduct research, and explore ideas without being monitored or judged. Processing that creates profiles based on reading habits, educational activities, or online research may discourage intellectual inquiry and autonomy.
Examples: Inferring medical conditions from health-related searches, creating political profiles based on news consumption, or evaluating employees based on training materials they access.
- Data security harms, such as unauthorized access or adversarial use: These risks concern the confidentiality, integrity, and availability of personal data. Organizations should evaluate whether the processing could expose personal information to unauthorized access, cyberattacks, insider misuse, or other security incidents.
Examples: Weak authentication controls, inadequate encryption, ransomware attacks, excessive employee access, or misuse of data by malicious actors.
- Discrimination harms, such as a violation of federal antidiscrimination laws or antidiscrimination laws of any state or political subdivision thereof, or unlawful disparate impact: Controllers should evaluate whether the processing could result in unlawful discrimination or disproportionately disadvantage protected groups, whether intentionally or unintentionally. This is particularly important when automated decision-making or artificial intelligence is involved.
Examples: AI hiring tools that disadvantage older applicants, credit models that disproportionately affect protected classes, or targeted advertising that excludes certain populations from housing or employment opportunities.
- Unfair, unconscionable, or deceptive treatment: This category encompasses practices that are misleading, manipulative, exploitative, or inconsistent with consumers' reasonable expectations. It aligns closely with longstanding consumer protection principles enforced by the Federal Trade Commission (FTC) and state attorneys general.
Examples: Dark patterns that manipulate users into consenting, misleading privacy notices, hidden tracking technologies, or deceptive representations regarding how personal information will be used.
- A negative outcome or decision with respect to an individual's eligibility for a right, privilege, or benefit related to financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services: Organizations should consider whether the processing could influence decisions that significantly affect an individual's life opportunities or access to essential services. These are often referred to as "high-impact" or "consequential" decisions.
Examples: Automated denial of loans, employment screening, insurance underwriting, college admissions decisions, healthcare eligibility determinations, or tenant screening.
- Financial injury or economic harm: Processing may expose individuals to direct or indirect financial losses. The assessment should evaluate both the likelihood and potential severity of those harms.
Examples: Identity theft, financial fraud, unauthorized account access, loss of employment opportunities, inaccurate pricing, or monetary losses resulting from inaccurate data.
- Physical injury, harassment, or threat to an individual or property: Certain processing activities may create risks to an individual's physical safety or facilitate harassment, stalking, or violence. These risks are particularly relevant when processing location information or other sensitive personal data.
Examples: Disclosure of home addresses, real-time location tracking, doxxing, or revealing information that could endanger victims of domestic violence.
- Privacy harms, such as physical or other intrusion upon the solitude or seclusion or the private affairs or concerns of Consumers, stigmatization or reputational injury: This category reflects the traditional concept of privacy harms recognized under both common law privacy torts and modern data protection laws. It includes unwanted intrusions into an individual's private life, as well as reputational harms resulting from inappropriate collection, disclosure, or use of personal information.
Examples: Excessive behavioral tracking, intrusive monitoring technologies, public disclosure of sensitive personal information, or inaccurate profiling that damages an individual's reputation.
- Psychological harm, including anxiety, embarrassment, fear, and other mental trauma: Privacy violations can produce emotional or psychological injuries even when no financial loss occurs. Organizations should consider whether the processing could reasonably result in emotional distress or similar harms.
Examples: Disclosure of intimate information, cyberbullying enabled by data disclosure, persistent surveillance that creates anxiety, or profiling that causes embarrassment or emotional distress.
- Other detrimental or negative consequences that affect an individual's private life, private affairs, private family matters or similar concerns, including actions and communications within an individual's home or similar physical, online, or digital location, where an individual has a reasonable expectation that Personal Data or other data will not be collected, observed, or used: This broad catch-all provision recognizes that privacy risks continue to evolve. It is intended to capture harms that may not fit neatly within the preceding categories, particularly those involving highly private environments where individuals reasonably expect not to be monitored.
Examples: Smart home devices collecting more information than expected, session replay technologies recording private online interactions, voice assistants capturing conversations inside the home, or Internet of Things (IoT) devices monitoring activities within private spaces.For services directed to or likely to be used by minors, the assessment must also consider any heightened risks to children.
Practical Consideration
The Colorado regulations do not require every assessment to identify every category of harm. Rather, controllers should systematically evaluate which risks are reasonably foreseeable given the specific processing activity, assess their likelihood and severity, and document the safeguards implemented to mitigate those risks. Demonstrating this type of structured analysis is consistent with the regulations' requirement that Data Protection Assessments be a "genuine, thoughtful analysis" of the risks presented by the processing activity.
7. Risk Mitigation Measures and Safeguards: Controllers should document the safeguards implemented to reduce identified risks, including:
- de-identification where appropriate;
- security controls;
- compliance with the CPA's controller obligations;
- consent mechanisms where required;
- consumer rights processes; and
- any additional technical or organizational safeguards.
The assessment should explain how each safeguard helps reduce the identified risks.
8. The Risk-Benefit Balancing Analysis: After evaluating both risks and safeguards, the controller must explain why the benefits of the processing outweigh the remaining risks.
Supporting information may include:
- contractual protections with processors and third parties;
- organizational policies;
- employee training;
- governance controls; and
- other measures demonstrating responsible data stewardship.
This balancing analysis is the core conclusion of the assessment.
Additional Requirements
Certain processing activities require additional documentation. For example, the assessment must address:
- profiling activities subject to the CPA's profiling requirements; and
- the specialized deletion and transfer limitations applicable to certain processing of sensitive data under the regulations.
Colorado also expects organizations to document the governance surrounding the assessment itself. The assessment should identify:
- the individuals and departments involved in preparing the assessment;
- any internal or external audits that were conducted;
- the reviewers and approvers;
- approval dates; and
- signatures or other evidence demonstrating formal review and approval.

Timing
A controller must conduct and document an Assessment before beginning any processing activity that presents a heightened risk of harm. This requirement is intended to ensure that privacy risks are identified, evaluated, and mitigated before personal information is collected or used—not after problems arise.
Unlike a one-time compliance exercise, a Colorado Assessment must be reviewed and updated as often as appropriate based on:
- the type of processing;
- the volume of personal data involved;
- the sensitivity of the data; and
- the level of risk presented by the processing.
The purpose of these reviews is to:
- monitor whether the processing is causing unforeseen harms;
- evaluate whether existing safeguards remain effective; and
- ensure that privacy considerations remain part of ongoing business decisions.
Where the processing involves profiling that produces legal or similarly significant effects, Colorado imposes an additional requirement. These assessments must be reviewed at least annually and include an updated evaluation of:
- fairness;
- disparate impact; and
- the results of those evaluations.
This reflects Colorado's heightened scrutiny of high-impact automated decision-making.
If the processing changes in a way that materially increases or alters the privacy risks, the controller must update the Assessment to address the new processing and any additional safeguards needed. Controllers must retain for the entire duration of the processing activity and for at least three years after the processing ends:
- the current Data Protection Assessment;
- prior versions reflecting material updates; and
- supporting documentation
The assessments must be maintained in an electronic, transferable format, allowing them to be provided to regulators if requested.
The assessment requirements apply only to processing activities initiated after the applicable effective dates. Specifically:
- Data Protection Assessments required under the Colorado Privacy Act generally apply to processing activities created on or after July 1, 2023.
- The additional assessment requirements applicable to certain processing involving minors apply to activities created on or after October 1, 2025.
Neither requirement applies retroactively to processing activities that began before those dates.
Minor-Focused Data Protection Assessments
In 2024, Colorado enacted Senate Bill 24-041, which expanded the Colorado Privacy Act by introducing new Data Protection Assessment (DPA) requirements for online services, products, and features offered to minors. Effective October 1, 2025, controllers that actually know—or willfully disregard—that a user is a minor must conduct an Assessment whenever the processing presents a heightened risk of harm to minors. The assessment must evaluate the purpose of the service, the categories and uses of minors' personal data, and any reasonably foreseeable risks to minors.
Like the CPA's general Assessment requirements, these assessments must be updated whenever material changes occur, retained throughout the processing lifecycle and for at least three years afterward, and may satisfy the law if a substantially similar assessment was prepared under another legal framework. If the assessment identifies a heightened risk of harm, the controller must implement measures to mitigate or eliminate that risk.
Although the Colorado Attorney General may request and review these assessments, they remain confidential, are exempt from public disclosure, and their production does not waive attorney-client privilege or work-product protection.
CO Rev Stat § 6-1-1309.5 (2025)