C.R.S.
Section 6-1-1308
Duties of controllers
(1)
Duty of transparency.(a)
A controller shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes:(I)
The categories of personal data collected or processed by the controller or a processor;(II)
The purposes for which the categories of personal data are processed;(III)
How and where consumers may exercise the rights pursuant to section 6-1-1306, including the controller’s contact information and how a consumer may appeal a controller’s action with regard to the consumer’s request;(IV)
The categories of personal data that the controller shares with third parties, if any; and(V)
The categories of third parties, if any, with whom the controller shares personal data.(b)
If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose the sale or processing, as well as the manner in which a consumer may exercise the right to opt out of the sale or processing.(c)
A controller shall not:(I)
Require a consumer to create a new account in order to exercise a right; or(II)
Based solely on the exercise of a right and unrelated to feasibility or the value of a service, increase the cost of, or decrease the availability of, the product or service.(d)
Nothing in this part 13 shall be construed to require a controller to provide a product or service that requires the personal data of a consumer that the controller does not collect or maintain or to prohibit a controller from offering a different price, rate, level, quality, or selection of goods or services to a consumer, including offering goods or services for no fee, if the offer is related to a consumer’s voluntary participation in a bona fide loyalty, rewards, premium features, discount, or club card program.(2)
Duty of purpose specification.(3)
Duty of data minimization.(4)
Duty to avoid secondary use.(5)
Duty of care.(6)
Duty to avoid unlawful discrimination.(7)
Duty regarding sensitive data.
Source:
Section 6-1-1308 — Duties of controllers, https://leg.colorado.gov/sites/default/files/images/olls/crs2023-title-06.pdf
(accessed Oct. 20, 2023).