Colorado Joins List Of States Proposing Privacy Laws

Fox Rothschild LLP
Contact

Fox Rothschild LLP

Colorado has introduced the “Colorado Privacy Act” bill (SB21-190).

Key things to note:
  •  Recital notes that the “EU GDPR is emerging as a model for countries across the globe in data privacy.”
  • Consumer rights: access, correction, deletion, data portability and right to opt out of general collection and use of personal data not just use for sale.
  • Opt-in consent for processing sensitive data.
  • Affirmative obligation for information security.
  • Requirement for clear, transparent privacy disclosure,
  • Requirement for data protection assessments (for targeted advertising, sale, sensitive data).
  • Enforcement by AG.
  • Definition of “consent” modeled after Article 7 of GDPR.
  • Different definition of “de-identified data” which is similar to that under HIPAA.
  • Processing must be necessary, reasonable and proportionate to the specific purpose disclosed.
  • Controller is liable for a processor’s actions.
  • Requirement for controller/processor agreement but no specifics.

Read the full text of the legislation.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Fox Rothschild LLP | Attorney Advertising

Written by:

Fox Rothschild LLP
Contact
more
less

Fox Rothschild LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide