Code of Colorado Regulations
900 - Department of Law
904 - Attorney General-Consumer Protection Section
4 CCR 904-3 - Colorado Privacy Act Rules
Part 4 - CONSUMER PERSONAL DATA RIGHTS
Section 4 CCR 904-3-4.02 - SUBMITTING REQUESTS TO EXERCISE PERSONAL DATA RIGHTS
Current through Register Vol. 47, No. 17, September 10, 2024
A. Pursuant to C.R.S. § 6-1-1306(1), a Controller's privacy notice must include specific methods through which a Consumer may submit requests to exercise Data Rights.
B. Any method specified by a Controller pursuant to this rule must comply with each of the following:
C. The Data Rights request method does not have to be specific to Colorado, so long as the request method:
D. When a Consumer submits a Data Rights request, a Controller may only collect Personal Data through the request process if the Personal Data is reasonably necessary to Authenticate the Consumer, respond to the request, or effectuate the Data Rights request.
E. A Controller must not require a Consumer to create a new user account to exercise their Data Rights request, but may require a Consumer to use an existing password-protected account.