United States - Colorado

Colorado Privacy Act

21 controls. 2 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

21 controls 2 frameworks share controls with it United States - Colorado verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

Colorado Privacy Act (CPA) Evidence & Implementation Kit

21 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

If you runShared controls
GDPR13measure it →
CCPA/CPRA8measure it →

Every control

CodeControlAlso in
COPA-1304-SCOPEApplicability and Thresholds1
COPA-1305-PROCESSORProcessor Contracts and Role Responsibility2
COPA-1306-ACCESSRight of Access2
COPA-1306-APPEALRight to Appeal0
COPA-1306-CORRECTRight to Correction1
COPA-1306-DELETERight to Deletion2
COPA-1306-OPTOUTRight to Opt Out1
COPA-1306-PORTABILITYRight to Data Portability1
COPA-1307-DEIDENTDe-identified and Pseudonymous Data1
COPA-1308-CAREDuty of Care (Security)2
COPA-1308-CONSENTValid Consent and Dark Patterns1
COPA-1308-MINIMIZATIONDuty of Data Minimization1
COPA-1308-NONDISCRIMDuty to Avoid Unlawful Discrimination1
COPA-1308-PURPOSEDuty of Purpose Specification1
COPA-1308-SECONDARYDuty to Avoid Secondary Use1
COPA-1308-SENSITIVEDuty Regarding Sensitive Data1
COPA-1308-TRANSPARENCYDuty of Transparency (Privacy Notice)1
COPA-1309-DPAData Protection Assessments1
COPA-1310-LIABILITYLiability and Processor Allocation0
COPA-1311-ENFORCEEnforcement by the Attorney General and District Attorneys0
COPA-1313-RULESRules and Universal Opt-Out Mechanism0

Tell me when Colorado Privacy Act files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Minimisation review tying collection to specified purposes
  • Minimisation review tied to disclosed purposes
  • Documented purpose per data category
  • Minimisation review evidence
  • Data-collection forms mapped to purpose
  • Correction request procedure + records
  • Correction request handling + refusal-with-reasons records
  • Consumer rights portal
  • Verification procedures
  • 45-day response tracking

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Colorado Privacy Act, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition