(1) (a) A controller that offers any online service, product, or feature to a consumer whom the controller actually knows or willfully disregards is a minor shall use reasonable care to avoid any heightened risk of harm to minors caused by the online service, product, or feature.
(b) In any enforcement action brought by the attorney general or a district attorney pursuant to section 6-1-1311, there is a rebuttable presumption that a controller used reasonable care as required under this section if the controller complied with this section.
(2) Unless a controller has obtained consent in accordance with subsection (3) of this section, a controller that offers any online service, product, or feature to a consumer whom the controller actually knows or willfully disregards is a minor shall not:
(a) Process a minor's personal data:
(I) For the purposes of:
(A) Targeted advertising;
(B) The sale of personal data; or
(C) Profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer;
(II) For any processing purpose other than the processing purpose that the controller disclosed at the time the controller collected the minor's personal data or that is reasonably necessary for, and compatible with, the processing purpose that the controller disclosed at the time the controller collected the minor's personal data; or
(III) For longer than is reasonably necessary to provide the online service, product, or feature;
(b) Use any system design feature to significantly increase, sustain, or extend a minor's use of the online service, product, or feature; or
(c) Collect a minor's precise geolocation data unless:
(I) The minor's precise geolocation data is reasonably necessary for the controller to provide the online service, product, or feature;
(II) The controller only collects and retains the minor's precise geolocation data for the time necessary to provide the online service, product, or feature; and
(III) The controller provides to the minor a signal indicating that the controller is collecting the minor's precise geolocation data and makes the signal available to the minor for the entire duration of the collection of the minor's precise geolocation data; except that this subsection (2)(c)(III) does not apply to any service or application that is used by and under the direction of a ski area operator, as defined in section 33-44-103 (7).
(3) (a) A controller shall not engage in the activities described in subsection (2) of this section unless the controller obtains:
(I) The minor's consent; or
(II) (A) If the minor is a child, the consent of the minor's parent or legal guardian.
(B) A controller that complies with the verifiable parental consent requirements established in the Children's Online Privacy Protection Act of 1998, 15 U.S.C. sec. 6501 et seq., as amended, and the regulations, rules, guidance, and exemptions adopted pursuant to said act, as amended, is deemed to have satisfied any requirement to obtain parental consent under this subsection (3)(a)(II).
(b) (I) A controller that offers any online service, product, or feature to a consumer whom that controller actually knows or willfully disregards is a minor shall not:
(A) Provide any consent mechanism that is designed to substantially subvert or impair, or is manipulated with the effect of substantially subverting or impairing, user autonomy, decision-making, or choice; or
(B) Except as provided in subsection (3)(b)(II) of this section, offer any direct messaging apparatus for use by a minor without providing readily accessible and easy-to-use safeguards to limit the ability of an adult to send unsolicited communications to the minor with whom the adult is not connected.
(II) Subsection (3)(b)(I)(B) of this section does not apply to an online service, product, or feature of which the predominant or exclusive function is:
(A) Electronic mail; or
(B) Direct messaging consisting of text, photos, or videos that are sent between devices by electronic means, where messages are shared between the sender and the recipient, only visible to the sender and the recipient, and not posted publicly.
(4) Subsections (2)(a) and (2)(b) of this section do not apply to any service or application that is used by and under the direction of an educational entity, including a learning management system or a student engagement program.
Source: L. 2024: Entire section added, (SB 24-041), ch. 296, p. 2022, � 4, effective October 1, 2025.
6-1-1309. Data protection assessments - attorney general access and evaluation - definition. (1) A controller shall not conduct processing that presents a heightened risk of harm to a consumer without conducting and documenting a data protection assessment of each of its processing activities that involve personal data acquired on or after July 1, 2023, that present a heightened risk of harm to a consumer.
(2) For purposes of this section, processing that presents a heightened risk of harm to a consumer includes the following:
(a) Processing personal data for purposes of targeted advertising or for profiling if the profiling presents a reasonably foreseeable risk of:
(I) Unfair or deceptive treatment of, or unlawful disparate impact on, consumers;
(II) Financial or physical injury to consumers;
(III) A physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers if the intrusion would be offensive to a reasonable person; or
(IV) Other substantial injury to consumers;
(b) Selling personal data; and
(c) Processing sensitive data.
(3) Data protection assessments must identify and weigh the benefits that may flow, directly and indirectly, from the processing to the controller, the consumer, other stakeholders, and the public against the potential risks to the rights of the consumer associated with the processing, as mitigated by safeguards that the controller can employ to reduce the risks. The controller shall factor into this assessment the use of de-identified data and the reasonable expectations of consumers, as well as the context of the processing and the relationship between the controller and the consumer whose personal data will be processed.
(4) A controller shall make the data protection assessment available to the attorney general upon request. The attorney general may evaluate the data protection assessment for compliance with the duties contained in section 6-1-1308 and with other laws, including this article 1. Data protection assessments are confidential and exempt from public inspection and copying under the Colorado Open Records Act, part 2 of article 72 of title 24. The disclosure of a data protection assessment pursuant to a request from the attorney general under this subsection (4) does not constitute a waiver of any attorney-client privilege or work-product protection that might otherwise exist with respect to the assessment and any information contained in the assessment.
(5) A single data protection assessment may address a comparable set of processing operations that include similar activities.
(6) Data protection assessment requirements apply to processing activities created or generated after July 1, 2023, and are not retroactive.
Source: L. 2021: Entire part added, (SB 21-190), ch. 483, p. 3462, � 1, effective July 1, 2023.
6-1-1309.5. Data protection assessments - heightened risk of harm to minors. (1) A controller that, on or after October 1, 2025, offers any online service, product, or feature to a consumer whom such controller actually knows or willfully disregards is a minor shall conduct a data protection assessment for the online service, product, or feature if there is a heightened risk of harm to minors. The controller shall conduct the data protection assessment:
(a) In a manner that is consistent with the requirements established in section 6-1-1309; and
(b) That addresses:
(I) The purpose of the online service, product, or feature;
(II) The categories of a minor's personal data that the online service, product, or feature processes;
(III) The purposes for which the controller processes a minor's personal data with respect to the online service, product, or feature; and
(IV) Any heightened risk of harm to minors that is a reasonably foreseeable result of offering the online service, product, or feature to minors.
(2) A controller that conducts a data protection assessment pursuant to subsection (1) of this section shall:
(a) Review the data protection assessment as necessary to account for any material change to the processing operations of the online service, product, or feature that is the subject of the data protection assessment; and
(b) Maintain documentation concerning the data protection assessment for the longer of:
(I) Three years after the date on which the processing operations cease; or
(II) The date the controller ceases offering the online service, product, or feature.
(3) A single data protection assessment may address a comparable set of processing operations that include similar activities.
(4) If a controller conducts a data protection assessment for the purpose of complying with another applicable law or regulation, the data protection assessment is deemed to satisfy the requirements established in this section if the data protection assessment is reasonably similar in scope and effect to the data protection assessment that would otherwise be conducted pursuant to this section.
(5) If a controller conducts a data protection assessment pursuant to subsection (1) of this section or a data protection assessment review pursuant to subsection (2)(a) of this section and determines that the online service, product, or feature that is the subject of the assessment poses a heightened risk of harm to minors, the controller shall establish and implement a plan to mitigate or eliminate the heightened risk.
(6) (a) A data protection assessment conducted pursuant to this section:
(I) Is confidential, except as provided in subsection (6)(b) of this section; and
(II) Is not a public record, and is exempt from public inspection and copying, under the Colorado Open Records Act, part 2 of article 72 of title 24.
(b) (I) A controller shall make a data protection assessment conducted pursuant to this section available to the attorney general upon request. The attorney general may evaluate the data protection assessment for compliance with section 6-1-1308.5 and with other laws, including this article 1.
(II) The disclosure of a data protection assessment pursuant to a request from the attorney general does not constitute a waiver of any attorney-client privilege or work-product protection that might otherwise exist with respect to the assessment and any information in the assessment.
(7) Data protection assessment requirements apply to processing activities created or generated after October 1, 2025, and are not retroactive.
Source: L. 2024: Entire section added, (SB 24-041), ch. 296, p. 2024, � 4, effective October 1, 2025.