Colorado becomes the nation’s third state - consumerreports.org
Colorado becomes latest state - ZDNet
Regarding the basic framework, the CPA followed the trend of adopting a WPA-like controller/processor approach rather than a California Consumer Privacy Act-like business/service provider distinction.
The bill requires companies to honor browser privacy signals, such as the Global Privacy Control, in order to opt out of data sales at all companies in a single step
It requires companies to honor opt out requests submitted by agents designated on the consumer’s behalf
It prohibits the use of so-called “dark patterns” in obtaining consent to process sensitive information
The bill has stronger enforcement, by placing a sunset on the “right to cure” in administrative enforcement, so that after 2025 companies will no longer have a “get out of jail free” card for failing to protect consumer privacy
C0lorado SB 21-190, entitled “an Act Concerning additional protection of data relating to personal privacy”. Following California’s bold example of the California Consumer Privacy Act (“CCPA”) effective since January 2020, Virginia recently passed its own robust privacy law, the Consumer Data Protection Act (“CDPA”), and New York, as well as other states, like Florida, appear poised to follow suit. Furthermore, California is expanding protections provided by the CCPA, with the California Privacy Rights Act (CPRA) – approved by California voters under Proposition 24 in the November election.
fulfilling subject requests, updating privacy pages, designing products,
building apps and websites that collect personal information,
marketing using personal information
defining personal information
understanding consumer rights
communicating with consumers
implementing privacy policies
reviewing the penalties for non-compliance
planning ahead for the CPRA.
2
3
4
- buy sell or share ( no mention of receive 100,000 or more California residents or households (devices?)
50% or more of their annual revenue from selling or sharing
+ Right to Rectification+
Right to Limit Use and Disclosure of Sensitive ( SSN, driver license numbers, biometric information, precise geolocation, and racial and ethnic origin. ) Personal Information
Service provider + contractor
Creation of CPPA (not AG)
No 30 day cure period
Collection, retention, and use should be limited to what is necessary to provide goods or service.
-$2500 => 7500
+ email password or questions
+ annual audit and assessment
2
3
4
50% or more of their annual revenue from selling or sharing
of 100,000 or more California residents or households;