Back to the hub

When does the Colorado Privacy Act require a data protection assessment?

Colorado Revised Statutes Section 6-1-1309 bars a controller from processing that presents a heightened risk of harm without first conducting and documenting a data protection assessment. Heightened risk covers targeted advertising, profiling that risks foreseeable harm, selling personal data, and processing sensitive data. The attorney general may demand the assessment.

Applies to: Controllers covered by the Colorado Privacy Act that carry out targeted advertising, certain profiling, sales of personal data, or processing of sensitive data, for processing activities created or generated after July 1, 2023.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

The Colorado Privacy Act does not ask you to file anything with the state, which is why its assessment duty is easy to miss. It is a prohibition, not a filing requirement. Under C.R.S. 6-1-1309(1), a controller shall not conduct processing that presents a heightened risk of harm to a consumer without conducting and documenting a data protection assessment of each processing activity that presents that risk.

Read that carefully. The assessment is a precondition. Running the processing first and writing the assessment later does not satisfy the section.

What counts as a heightened risk of harm?

Section 6-1-1309(2) gives the list, and it is broader than most teams expect.

Processing personal data for targeted advertising counts, full stop. Profiling counts where it presents a reasonably foreseeable risk of unfair or deceptive treatment of consumers, unlawful disparate impact on them, financial or physical injury, a physical or other intrusion on solitude or seclusion or private affairs that would be offensive to a reasonable person, or other substantial injury. Selling personal data counts. Processing sensitive data counts.

For a typical SaaS business, the two that bite are targeted advertising and sensitive data. If you run retargeting campaigns using your customer list, you are inside the section. If you process health, biometric, or similar categories, likewise.

What has to be in the assessment?

Section 6-1-1309(3) sets the content. The assessment must identify and weigh the benefits that may flow, directly and indirectly, from the processing to the controller, the consumer, other stakeholders, and the public, against the potential risks to the rights of the consumer, as mitigated by safeguards the controller can employ to reduce those risks.

It then adds four things you must factor in: the use of de-identified data, the reasonable expectations of consumers, the context of the processing, and the relationship between you and the consumer whose data will be processed.

That last pair does real work. Data a customer handed you to run the product sits differently from data you inferred or bought, even where the processing is identical.

Can one assessment cover several activities?

Yes. Section 6-1-1309(5) says a single data protection assessment may address a comparable set of processing operations that include similar activities. In practice that means you do not need a separate document for every advertising pixel, but you do need the set to be genuinely comparable. Grouping unrelated processing under one assessment to save time is how these fall apart under scrutiny.

What happens if the attorney general asks?

Section 6-1-1309(4) requires you to make the assessment available to the attorney general on request. The attorney general may then evaluate it for compliance with the duties in Section 6-1-1308 and with other law, including the rest of article 1.

The statute protects you on two fronts. Data protection assessments are confidential and exempt from public inspection and copying under the Colorado Open Records Act. And disclosing one to the attorney general under this subsection does not waive attorney-client privilege or work-product protection that would otherwise apply.

How far back does this reach?

Not indefinitely. Section 6-1-1309(6) says the assessment requirements apply to processing activities created or generated after July 1, 2023, and are not retroactive. Processing you started before then does not need a retrospective assessment, though any material change to it will usually create a new activity that does.

How does this compare with a GDPR DPIA?

The two overlap but are not interchangeable. A GDPR data protection impact assessment is triggered by high risk to rights and freedoms and has its own required content, including consultation with the supervisory authority in some cases. Colorado's trigger list is more concrete and its content requirements shorter. A well-built DPIA usually covers most of what Colorado wants, but you should check it against Section 6-1-1309(3) rather than assume equivalence.

How ComplyFine helps

Assessment duties are the obligations most often discovered late, because nothing prompts you to do them. ComplyFine's free Obligation Scan asks how you advertise, what you sell or share, and which data categories you touch, then tells you whether Colorado's assessment duty applies to your business and which other state laws add their own version. You get the trigger list mapped to your actual processing instead of a statute to cross-reference.

Compliance checklist

  • List the processing activities that touch targeted advertising, profiling, sales of personal data, or sensitive data, because C.R.S. 6-1-1309(2) treats each as a heightened risk of harm.
  • Complete and document the assessment before that processing starts, since Section 6-1-1309(1) bars conducting the processing without one.
  • Weigh the benefits to your business, the consumer, other stakeholders, and the public against the risks to the consumer's rights, as mitigated by safeguards you can employ.
  • Factor in the use of de-identified data, consumers' reasonable expectations, the context of the processing, and your relationship with the consumer, as Section 6-1-1309(3) requires.
  • Use one assessment to cover a comparable set of similar processing operations where that fits, which Section 6-1-1309(5) allows.
  • Store assessments so you can produce them to the attorney general on request, and refresh them when the processing materially changes.

Sources

Last verified: 2026-08-19

Informational, not legal advice.