Code of Colorado Regulations — Department of Law

department-11CCR Dept. 900Regulation

901 Peace Officer Standards and Training Board

4 CCR 901-1 Peace Officer Training Programs and Peace Officer Certification {#sec-4-ccr-901-1 omnilex-key=us-co-regs-official--department-11--4 CCR 901-1}

DEPARTMENT OF LAW

PEACE OFFICER TRAINING PROGRAMS AND PEACE OFFICER CERTIFICATION

4 CCR 901-1 [Editor’s Notes follow the text of the rules at the end of this CCR Document.] _________________________________________________________________________

Rule 1 – Definitions As used in these rules (a) “Academy director” means that person responsible for the administration and operation of a POST-approved academy.

(b) “Applicant” means any person formally seeking approval by the Board.

(c) “Appointed” means sworn in and serving as a peace officer or reserve peace officer, but does not include rehiring by the same law enforcement agency if the separation is for less than six (6) months, for the purposes of Rule 29.

(d) “Approved” means formally accepted or authorized by the Board.

(e) “ACT” means Arrest Control Tactics, one of the skills training programs required for the basic, refresher and reserve training academies.

(f) “Assistant skills instructor” means an individual who has successfully completed a relevant approved skills instructor training program and who may instruct the corresponding skills training program in arrest control, law enforcement driving, or firearms under the direction and in the presence of a full skills instructor, and assist in evaluating and coaching trainees at an approved basic, refresher or reserve training academy.

(g) “Authorized emergency vehicle” means such vehicles as further defined in § 42-1-102(6), C.R.S.

(h) “Board” means the Colorado Peace Officer Standards and Training Board.

(i) “Bodily injury” means physical pain, illness, or any impairment of physical or mental condition, per § 18-1-901(3)(c), C.R.S.

(j) “Certification examination” means the written test required, per § 24-31- 305(1)(a)(III), C.R.S.

(k) “Certified peace officer” means any person who has successfully attained POST Certification, as further described in §§ 24-31-305 and 24-31-308, C.R.S.

(l) “Course” means a formal unit of instruction relating to a particular subject.

(m) “C.R.S.” means Colorado Revised Statutes, codified laws of the State of Colorado.

(n) “Director” means the director of the POST Board staff.

(o) “Disqualifying incident” means:

(I) A finding of guilt following either a verdict of guilty by the court or jury, or a plea of guilty, or a plea of nolo contendere., per § 24-31-305(1.5)(a), C.R.S. Any Colorado juvenile adjudication is not a conviction.

(II) Entering into a deferred judgment and sentencing agreement, a deferred prosecution agreement, or a pretrial diversion agreement of any disqualifying incident, whether pending or successfully completed, per §§ 24-31-305(1.5)(b) and 24-31-904(4), C.R.S.

(III) A finding of untruthfulness pursuant to § 24-31-305(2.5), C.R.S.

(IV) Convicted of or pleads guilty or nolo contendere to a crime involving unlawful use of physical force, per § 24-31-904, C.R.S., or a crime involving the failure to intervene in the use of unlawful physical force, per § 24-31-904, C.R.S. and § 18-8-802(1.5)(a) and (d), C.R.S.

(V) Found civilly liable for the use of excessive or unconstitutional physical force or the failure to intervene in the use of excessive or unconstitutional physical force, per § 24-31-904, C.R.S.

(VI) An administrative law judge, hearing officer, or internal investigation finds that a peace officer used unlawful physical force, failed to intervene, or violated section 18-1-707, C.R.S. as described in §24-31-904, C.R.S.

(VII) A court, administrative law judge, hearing officer, or a final decision in an internal investigation finds that a peace officer intentionally failed to activate a body-worn camera or dash camera or tampered with any body-worn or dash camera with the intent to conceal unlawful or inappropriate actions or obstruct justice, as described in § 24-31- 902(1)(a)(IV), C.R.S.

(VIII) Failure to satisfactorily complete peace officer training required by the POST Board, per § 24-31-305(2.7), C.R.S.

(IX) Making materially false or misleading statements of omissions in the application for certification.

(X) Knowingly or intentionally providing inaccurate data for the database created per § 24-31- 303(1)(r), C.R.S.

(XI) Otherwise failing to meet the certification requirements established by the Board.

(XII) A finding by an administrative law judge, hearing officer, or internal investigation of a law enforcement agency that a peace officer violated section 18-8-805, C.R.S. regarding the prohibited use or direction of administration of ketamine.

(O.5) “Employer” means the peace officer’s appointing authority, whether work was paid or volunteer.

(p) “Enroll” means that a person has applied to and been accepted for admission into an academy and is physically present at the academy to receive instruction.

(q) “Enrollment date” means the first day of instruction at an approved basic, refresher or reserve training academy, and shall be synonymous with the first day of instruction as reflected on the approved academy schedule.

(r) Fingerprint-based criminal history record check: a search of a person’s fingerprints, provided on a POST applicant fingerprint card or a Colorado bureau of investigation (CBI) authorized vendor, and processed by CBI and federal bureau of investigation (FBI) for the purpose of determining a person’s eligibility for certification as a peace officer in the state of Colorado.

(s) “Found Civilly Liable” as used in §24-31-904, C.R.S. means, a final judgment of civil liability is entered against a certificate holder, or a judge or jury makes a finding of fact that the certificate holder is civilly liable, in a court of competent jurisdiction.

(t) “Full skills instructor” means an individual who has successfully completed the minimum qualifications required by these Rules and who may develop, implement and evaluate a skills training program at an approved basic, refresher or reserve training academy.

(u) “Hazing” means any conduct whereby an academy recruit is caused to suffer or be exposed to an activity which a reasonable person would deem cruel, abusive, humiliating, oppressive, demeaning or harmful, which lacks a legitimate training or disciplinary purpose or outcome.

(v) “Inappropriate actions” means any action by a certificate holder a reasonable person would find to be intentional wrongdoing or misconduct.

(w) “Incident” means a single, distinct event as determined by the POST Director or designee.

(x) “Lead skills instructor” means a full skills instructor at a basic, refresher or reserve training academy who may be designated by the academy director to oversee or coordinate the administration of a specific skills program for a particular academy class.

(y) “Lesson plan” means a document that specifically describes the material presented during a course of instruction, as further described in POST Rule 21.

(z) “Moving training” means training where the academy students are involved in movement with a loaded weapon. It is recognized that during square range drills, academy students may move 1-2 steps laterally or forward/backward. The 1:1 ratio is not required for this drill. For all other drills/exercises involving movement a 1:1 ratio is required.

(aa) “Operable firearm” means a firearm that is capable of discharging a bullet if loaded. This does not include firearms designed or modified to discharge marking cartridges or airsoft projectiles during academy scenario/reality-based training.

(bb) “Peace officer” means any person, as recognized in § 16-2.5-102, C.R.S.

(cc) “POST certified” means any person possessing a valid, numbered certificate issued by the Board authorizing such person to serve as a peace officer or reserve peace officer.

(dd) “POST fingerprint card” means a fingerprint card provided by POST.

(ee) “POST Identification” (PID) means a number assigned and unique to each active peace officer's certification record. All inquiries and correspondence to POST should contain this number.

(ff) “Practical Exercise” means role playing, tabletop exercises, or other scenario/reality-based training.

(gg) “Program director” means the person responsible for the administration and operation of a POSTapproved training program.

(hh) “Provisional certification” means a signed instrument issued by the POST Board that grants interim certification for qualified out-of-state peace officers seeking Colorado certification that enables the provisional applicant to obtain appointment as a peace officer in Colorado while fulfilling the requirements for basic certification.

(ii) “Recognized disciplines for arrest control training” mean those arrest control/defensive tactics systems that have been reviewed and approved by the Board, or it’s designee, in consultation with the Arrest Control Subject Matter Expert Committee for use in an approved law enforcement academy. Such systems may include, but are not limited to, Federal Bureau of Investigation (FBI) system, Koga system and Pressure Point Control Tactics (PPCT) system.

(jj) “Records management system” is an agency-wide system that provides for the storage, retrieval, retention, archiving, and viewing of information, records, documents, or files pertaining to POST operations.

(kk) “Refresher academy” means an approved training program that consists of a minimum of 96 hours of instruction and includes POST Board approved academics, arrest control, law enforcement driving and firearms.

(ll) “Relevant approved skills instructor training program” means a basic, not advanced, instructor training program that contains a minimum of forty (40) hours of instruction with instructional content that meets or exceeds the content of the respective instructor training programs for arrest control, law enforcement driving, or firearms, and has been formally accepted or authorized by the Board.

(mm) “Renewal applicant” means an applicant whose Colorado peace officer certificate has expired per § 24-31-305(1.7)(b), C.R.S., and who has applied to renew his/her Colorado peace officer certificate in accordance with § 24-31-305(1.7)(c), C.R.S. and POST Rule 13.

(nn) “Reserve peace officer” means any person described in § 16-2.5-110, C.R.S., and who has not been convicted of a felony or convicted on or after July 1, 2001, of any misdemeanor as described in section 24-31-305 (1.5), or released or discharged from the armed forces of the United States under dishonorable conditions.

(oo) “Resigned in lieu of termination for cause” describes a peace officer voluntarily separating from an employing law enforcement agency when they knew, or reasonably should have known, that their employment from the law enforcement agency was likely to be terminated for intentional wrongdoing or misconduct. This separation type is determined by the employing law enforcement agency, but would not prevent a peace officer from seeking a variance as outlined in Rule 32.

(pp) “Serious bodily injury” means bodily injury which, either at the time of the actual injury or at a later time, involves a substantial risk of death, a substantial risk of serious permanent disfigurement, a substantial risk of protracted loss or impairment of the function of any part or organ of the body, or breaks, fractures, a penetrating knife or penetrating gunshot wound, or burns of the second or third degree, per § 18-1-901(3)(p), C.R.S.

(qq) “Skills examination” means the approved practical test of an applicant's proficiency in arrest control, law enforcement driving, or firearms.

(rr) “Skills training” means the required approved arrest control, law enforcement driving, and firearms courses.

(ss) “State” means any State in the United States, the District of Columbia, and any territory or possession of the United States.

(tt) “Subject Matter Expert” (SME) means an individual formally recognized by the chair of the Board for his or her extensive knowledge, expertise and/or experience in one of the skills areas or in academics.

(uu) “Successful completion” means a score of seventy (70) percent or greater, or a grade of “C” or better, or a rating of pass, if offered as pass/fail, in a POST approved academy or program. For the certification examination passing score, see Rule 15.

(vv) “Tamper” means any intentional action by a certificate holder to prevent, limit, or obscure the ability of a dash camera or body-worn camera from recording video or audio, or to prevent the storage or retrieval of such video or audio. This includes, but is not limited to, use of the power button, mute button, or other functions of the camera, but does not include those action(s) that are authorized by C.R.S. §24-31-902(1)(a)(ii) or other applicable law.

(ww) “Termination for cause” means the certificate holder was terminated from a peace officer position for intentional wrongdoing or misconduct. This separation type is determined by the employing law enforcement agency, but would not prevent a peace officer from seeking a variance as outlined in Rule 32.

(xx) “Test out” means a POST-scheduled skills examination where proficiency is assessed by POST Subject Matter Experts (SMEs) in all three perishable skills (Arrest Control, Law Enforcement Driving, and Firearms) and the written POST certification exam is administered.

(yy) “Training academy” means a POST-approved school, agency or other entity that provides POSTapproved training programs.

(zz) “Training program” means a POST-approved course of instruction required by statute, or Rule, or for peace officer certification and other peace officer training programs as otherwise recognized and approved by the Board.

(aaa) “Unlawful Use of Physical Force” as used in §24-31-904, C.R.S. means the use of physical force that violates title 18, C.R.S.

(bbb) “Whistleblower” means a peace officer who disclosed in good faith information to the proper supervising authority that the peace officer reasonably believed showed a danger to public health or safety, or an alleged violation of law committed by another peace officer. This definition does not apply to a peace officer who reported their own misconduct, disclosed information they knew to be false, disclosed information with disregard to the truth, or did not follow the internal reporting and administrative procedures of the peace officer’s employer.

Rule 2 – Meetings Effective November 15, 2020 (a) The Attorney General, as chairperson, shall preside over all meetings of the Board. Should the chairperson be absent, the vice-chairperson shall preside over the meeting. In the absence of the chairperson and the vice-chairperson, the most senior member present shall preside.

(b) A majority of the total positions of the Board, excluding vacancies, shall constitute a quorum for purposes of conducting official business. Should there be no quorum, the members who are present may conduct official business, subject to subsequent ratification by a quorum of the Board.

(c) Should any member, other than those sitting ex officio, be absent without good cause from three consecutive meetings, the Director shall submit a resolution to the Board calling on the member to resign.

(d) The Board may conduct its business on the basis of unanimous consent. However, any member of the Board may require separate consideration and disposition of any matter, including through a roll-call vote. When a quorum is present, a majority vote, that is a majority of the votes cast, ignoring abstentions, is sufficient for the adoption of any motion that is in order. On a tie vote the motion is lost.

(e) Unless the Director determines otherwise, all requests from the public for Board consideration or action must be submitted in writing to the Director at least thirty (30) days prior to the next scheduled Board meeting.

(f) Other than when a person comments with respect to matters of policy, the chairperson will request that the person do so under oath.

Rule 3 – Director’s Authority (a) The Director’s authority shall include:

(I) Making the initial determination as to whether an applicant has met the requirements to sit for the certification examination, or to be certified;

(II) Approving or disapproving program applications;

(III) Issuing remedial action and compliance orders for non- compliance with POST rule;

(IV) Determining the equivalency of first aid and cardiopulmonary resuscitation training;

(V) At the Director’s, or the Director’s designee’s, discretion, selecting qualified evaluators to administer the skills examinations described in Rule 16;

(VI) Determining the merit of challenges relating to the administration of examinations pursuant to Rules 15 and 16;

(VII) Determining the merits of variance requests, consistent with the basic purposes and policies of § 24-31-301, et seq., C.R.S., and of the Board, in accordance with Rule 7 and

Rule 8;

(VIII) The Director, or their designee, may approve eyewitness identification training per § 16- 1- 109, C.R.S., or other statutorily mandated training on behalf of the POST Board.

(IX) Granting an extension of time beyond what is prescribed in these rules when good cause is shown.

(X) Determining whether to file exceptions pursuant to §24-4-105, C.R.S., following the initial decision of the post administrative hearing officer.

(XI) Discharging such other powers or duties as the Board or the Attorney General may direct.

(A) Issuing summary suspensions in situations where the board has delegated

authority to the director, including:

  1. Where a certificate holder has failed to meet in-service training requirements;

  2. Where a specific law enforcement training academy class was found to be substantially deficient, such that the certificate holders of that class would pose a danger to the public health, safety and welfare.

(B) Issuing immediate orders to suspend training or shut down an academy when the health, safety or welfare of recruits or staff are endangered.

(b) If any action or determination made by the Director, or their designee, pursuant to this rule is not appealed by the applicant within thirty (30) days as provided in Rule 5(d), the Director’s, or their designee’s, action or determination shall become final agency action.

Rule 4 – Subject Matter Expert Committees (a) The Chair of the Board or the Chair’s designee shall appoint committees of Subject Matter Experts to provide professional technical support in the following areas: academic curriculum; arrest control; firearms; law enforcement driving; and other areas as needed.

(b) The number of members in each committee will be determined by the Director. The committees shall include the Director or the Director’s designee, who shall serve as the chairperson, a vicechairperson elected by the members, one member of the Board, and other Subject Matter Experts from the law enforcement community. If available, each subject matter committee shall include at least two non-law enforcement members who have law enforcement expertise or expertise in providing effective training through professional experience or subject matter training.

§ 24-31-303, C.R.S.

(c) A majority of the total members of each committee shall constitute a quorum for purposes of conducting official business.

(d) Any person wishing to be appointed, either active or retired peace officer or Subject Matter Expert from the law enforcement or non-law enforcement community, and who meets the minimum qualifications for membership, may apply for membership at any time throughout the calendar year. Only one person per agency may serve on a single committee at any one time, unless otherwise authorized by the Director.

(e) Appointments will be made upon the applicant’s merit and at the discretion of the Chair of the Board or their designee, and each of the committee chairs.

(f) Members serve for a term of up to one year that is automatically renewed in December of each year provided the member remains in good standing with the Board, and the member’s agency or employer, as applicable, continues its support of the member, as evidenced by a letter of support.

A change in employer will require a new letter of support to remain on the committee. There is no maximum number of terms that a member may serve.

(g) Members of the committees shall receive no compensation for their services, but may be reimbursed for actual and necessary expenses incurred in the performance of their official duties.

(h) Duties of the Committees include, but are not limited to:

  1. Developing skills training programs, academic curricula and POST Board Rules;

  2. Reviewing documents and providing recommendations to POST Board staff to approve or deny academy programs, lesson plans, training sites, instructor programs, skills instructors, and other courses or programs that pertain to the establishment and maintenance of standards for peace officer training; and 3. Assisting POST Board staff with academy and instructor program inspections and skills test-outs.

  3. Members of the committees shall not participate in subject matter expert committee functions related to their respective organization or organization employees.

(i) Committees shall comply with the requirements of Colorado’s open meetings law pursuant to § 24-6-402, C.R.S.

Rule 5 – Hearings a) Show Cause Hearings for revocation or suspension of certification for criminal disqualifying incidents (I) At any time, the Director or the Director’s designee may direct a respondent to appear at a hearing and show cause why the Board should not take disciplinary action of certification for criminal convictions, deferred judgment and sentence agreements, deferred prosecution agreements, or pretrial diversion agreements. Disciplinary action may include revoking, suspending, or voluntary surrender of the certification of a peace officer for a qualifying criminal act.

(A) Not less than forty (40) days prior to the date set for such hearing, the Director or the Director’s designee shall transmit to the respondent written notice of the hearing, which must include:

  1. The date, time and place of the hearing;

  2. An advisement that the respondent has the right to appear and be heard at such hearing, either in person or through legal counsel;

  3. An advisement that the respondent has the burden of going forward, and the burden of proving all facts relevant to their position;

  4. A concise statement setting forth the subject of the hearing, facts relevant to the matter, and the statute, rule, or order, to which the matter relates;

  5. Copies of all documents considered by the Board in setting the hearing;

  6. The nature of the proposed disciplinary action.

(B) Not less than ten (10) days prior to the date set for a hearing pursuant to section (a) of this rule, the respondent shall file a response, including:

  1. A concise statement setting forth the respondent's position;

  2. All facts relevant to the matter; and 3) Copies of all documents the respondent wishes the Director or the Director’s designee to consider in the matter;

  3. If applicable, a list of witnesses from whom respondent intends to elicit a statement relevant to the matters at issue; and 5) Notification of the respondent’s intent to appear at the hearing. If no such notification is received, the hearing will be cancelled, and the Director or the Director’s designee will make a finding on the basis of documents presented.

(C) Actions against certifications may be based upon criminal disqualifying incidents, as defined in Rule 1, of certain offenses as identified or referenced in §§ 24-31- 305(1.5), 24-31-904(1)(a)(I), (2)(a)(I).

(D) When the Director receives notice or otherwise learns that a certificate holder was engaged in a criminal disqualifying incident of the enumerated offenses listed in §§ 24-31-305(1.5), 24-31-904(1)(a)(I), (2)(a)(I), the Director shall issue an Order to Show Cause for why the officer’s certification should not be revoked.

  1. At the show cause hearing, the court record of the conviction or agreement shall constitute prima facie evidence of the conviction or agreement.

  2. The certificate holder may be represented by counsel.

  3. The certificate holder bears the burden of proving that an exemption from revocation would meet the requirements articulated in Rule 8.

(E) The Director will consider all information provided at the show cause hearing. If the Director determines by a preponderance of the evidence that disciplinary action is not appropriate, no further action will be taken. If the Director determines by a preponderance of the evidence that the disciplinary action is appropriate, the Director will make a recommendation to the Board regarding appropriate disciplinary action or actions.

(II) Any certificate holder or chief law enforcement officer of the employing law enforcement agency (“petitioner”) may request a hearing before the Director to address matters of this

section (a), through the filing of a petition.

(A) The petition supporting such request must include:

  1. The name and address of the petitioner and whether the petitioner currently possesses Colorado POST certification;

  2. A concise statement setting forth the subject of the hearing, all facts necessary to the matter, and the statute, rule, or order to which the petition relates;

  3. A list of witnesses from whom petitioner intends to elicit a statement relevant to the matters at issue;

  4. Copies of all documents the petitioner wishes the Director to consider in the matter; and 5) The action the petitioner wishes the Director to take.

(B) No less than thirty (30) days prior to the date set for a hearing on a petition, the Director shall provide a written response to the petitioner, including:

  1. The date, time and place of such hearing;

  2. An advisement that the petitioner has the right to appear and be heard at such hearing, either in person or through legal counsel;

  3. An advisement that the petitioner has the burden of going forward, and the burden of proving all facts relevant to their petition; and (III) The parties may mutually agree to shorten or lengthen any of the time frames set forth in these sections a) and b).

b) Administrative Hearings for Disqualifying Incidents Other Than Those Addressed in Subsection (a)(I)(C) of This Rule 5 (not criminal disqualifying incidents)

(I) When POST Staff receives appropriate written notification that a peace officer is subject to action against the peace officer’s POST certificate pursuant to disqualifying incidents not related to criminal conduct, POST Staff shall take the following actions:

(A) The Director shall review the written notification to determine whether the information provided complies with the statutory requirements.

  1. If the Director determines that the information provided in the written notification does not comply with statutory requirements, the Director shall advise the notifying party that determination, and POST will take no further action.

  2. If the certificate holder is subject to board action under § 24-31-305(2.5) or for a finding in an internal investigation as outlined in § 24-31- 904(1)(a)(III)-(V) or (2)(a)(III)-(IV), C.R.S., and the Director determines that the information provided in the written notification does comply with the statutory requirements, the Director shall notify the peace officer of the right to request a hearing before a hearing officer to determine whether the peace officer certification should be revoked or suspended.

The notice must also inform the peace officer that the peace officer must request the hearing within thirty (30) days of the date of the notice, which may be extended for good cause shown.

a. If the peace officer does not request a hearing within the required time frame, the Director will recommend revocation or suspension and the Board will vote on revoking or suspending the certification at its next regular meeting.

b. If the peace officer requests a hearing, the Director will request the law enforcement agency to provide documentation relevant to the information provided in the written notification. The Director will review the documentation provided by the law enforcement agency and conduct additional investigation, if necessary and appropriate. Upon the conclusion of the Director’s review and investigation, the Director will either recommend no action or refer the matter for hearing.

(B) If the certificate holder is subject to board action for any other disqualifying incidents not addressed in (a) or (b)(1)(A)(2) of this rule, and the Director determines that the information provided in the written notification does comply with the statutory requirements, the Director shall review the documentation provided by the notifying party and conduct additional investigation if necessary and appropriate. Upon the conclusion of the Director’s review and investigation, the Director will either recommend no action or refer the matter for hearing.

(C) If the matter is referred for hearing, the Director shall appoint a hearing officer to conduct the hearing in accordance with §§ 24-4-104 and 105, C.R.S.

  1. The Director shall advise the notifying party in writing that the matter will be set for hearing and that the law enforcement agency may submit any documentary evidence or argument that it wishes to provide to the hearing officer, and must serve any documentary evidence or argument on all parties. The law enforcement agency may not intervene or participate as a party to the hearing. Documentary evidence or argument must be submitted within fifteen (15) days of notification.

  2. The hearing shall be conducted in accordance with § 24-4-105, C.R.S. upon filing of a notice of hearing, the hearing officer shall issue a protective order maintaining confidentiality of internal affairs investigation records, if any.

  3. POST will appear at the hearing through its counsel, and will bear the burden of proving grounds for revocation or suspension of the certification by a preponderance of the evidence. The peace officer may be represented by counsel of their choice.

  4. At a minimum, the hearing will be audio recorded.

  5. Within forty-two (42) days of the conclusion of the hearing, the hearing officer shall prepare and file an initial decision, which the agency shall serve upon the parties. Each decision and initial decision must include a statement of findings and conclusions upon all the material issues of fact, law, or discretion presented by the record and the appropriate order, sanction, relief, or denial. A notice of appeal rights shall be attached to the initial decision.

  6. Either party may file an appeal of the initial decision with the POST Board pursuant to § 24-4-105(14), C.R.S. by filing written exceptions within thirty (30) days of the date of service of the initial decision. Any party who seeks to reverse or modify the initial decision shall file a designation of the relevant parts of the record described in § 24-4- 105(14), C.R.S. within twenty (20) days of the initial decision. Within ten (10) days thereafter, any other party or the law enforcement agency may also file a designation of additional parts of the transcript of the proceedings which is to be included and advance the cost thereof. All deadlines are jurisdictional and will not be extended. Timely filing is determined by the date the POST Board receives the appeal. Any appeal must be filed with the POST Board and not the hearing officer.

  7. If a party appeals the initial decision of the hearing officer, the appeal must describe in detail the basis for the appeal, the specific findings of fact and/or conclusions of law to be reviewed, and the remedy being sought.

  8. The record shall be certified within 60 days of the appeal. Any party that designates a transcript as part of the record is responsible for obtaining and paying a certified court reporter who shall prepare the transcript and file it with the Board no more than 59 days after the designation of record. If no transcript has been filed within the time limit, the record will be certified and the transcript will not be included in the record or considered on appeal. In the absence of a transcript, the POST Board is bound by the hearing officer’s findings of fact. No transcript is required if the review is limited to a pure question of law.

  9. The POST Board will notify the parties when the record is certified.

Opening briefs are due ten (10) days after the notice is served. Answer briefs are due ten (10) days after the opening brief is filed. Reply briefs are due ten (10) days after the answer brief is filed. These deadlines may be extended by the Director or Director’s designee upon motion filed before the deadline upon good cause shown. No brief may exceed ten (10) pages without leave of the Director or Director’s designee, which must be requested before the due date for the brief.

  1. In general, no oral argument will be heard and the POST Board will decide the appeal based upon the briefs. A party may request an oral argument and if requested must be made no later than the date the requesting party’s brief is due. If oral argument is granted, the parties will be given notice of the time and place. If granted, oral argument will be limited to no more than ten (10) minutes per side. The moving party may reserve part of its time for rebuttal.

  2. If neither party appeals, the initial decision of the hearing officer becomes the final decision of the POST Board thirty (30) days after the date of the initial decision.

  3. Hearings under this section shall be subject to the procedural rules as outlined in POST Rule 33.

c) Appeals of fines or other administrative sanctions issued by the Attorney General:

(I) The administration of a fine or other administrative sanction by the Attorney General for violations of part 3, article 31, title 24 of the Colorado Revised Statutes or any rule promulgated under such authority is final unless appealed to the Director within thirty (30) days of such decision.

(II) Appeals of fines or other administrative sanctions shall be referred to a hearing officer, per § 24-4-105, C.R.S.

(A) The initial decision of the hearing officer, including the hearing officer’s recommendations and any exceptions by the parties, shall be reviewed by the Board, which will adopt or reject the initial decision in whole or in part upon the issuance of a final agency order.

d) Appeals for certain types of database reports.

(I) A peace officer reported to POST for inclusion on the peace officer database pursuant to § 24-31-321(1)(e) or (1)(f), C.R.S., may request a show cause hearing with the Director or the Director’s designee to appeal this inclusion.

(A) POST shall request all documents related to the report from the reporting organization.

  1. All documents received from the reporting organization shall be provided to the appellant peace officer.

  2. Pursuant to § 24-31-321(2), C.R.S., documents submitted for review by POST and the appellant peace officer for the purposes of the show cause hearing remain the property of the reporting organization and are not subject to public release.

a. Public release of protected documents by other than the reporting organization may result in administrative sanctions pursuant to Rule 31 or other legal remedies.

e) Appeals of Decisions of the Director or their designee relating to Show Cause Hearings, Variance Decisions, or Other Decisions:

(III) A decision by the Director or their designee is final unless appealed to the Board within thirty (30) days of the date of such decisions.

(IV) If a decision by the Director or their designee is appealed to the Board, the Board will decide whether to hear the appeal. An appeal of the Director’s, or their designee’s, decision in the form of a notice of appeal must be made in writing and submitted to the POST Director. A notice of appeal will be brought before the board at the next scheduled meeting date. If a majority of the POST Board members agree to hear the appeal, a fivemember panel of Board members shall proceed to hear the Board appeal. The appeal hearing must commence within forty-five (45) days from the date the Board agreed to hear the appeal. The certificate holder will be notified of the Board’s action. This decision, whether summarily affirmed or decided by the board subcommittee, shall constitute Final Agency Action. The appellant will be notified of the Board’s action.

f) Final Agency Action relating to the application of this Rule 5 is subject to judicial review under § 24-4-106, C.R.S.

Rule 6 – DECLARATORY ORDERS Any person may petition the Board for a declaratory order regarding the application to the petitioner of any statutory provision or of any rule or order of the Board. All such petitions shall be considered in accordance with Rule 5.

Rule 7 – Variances (a) The Board may, upon sufficient cause shown, authorize variances to persons who are otherwise required to meet the requirements of these rules.

(b) To request a variance, an applicant must submit a written petition to the Director or the Director’s designee, fully explaining all relevant facts. Any person seeking a temporary or permanent variance has the burden of establishing that:

(I) The variance is consistent with the basic purposes and policies of § 24-31-301, et seq., C.R.S.; and (II) Strict application of the statutes and rules pertaining to the certification process would present a practical difficulty or unnecessary hardship. Mere inconvenience or expense does not suffice.

(c) The Director or the director’s designee, in their discretion, may determine the merits of the request based upon the applicant’s written submissions, or may request additional information, or may hold a meeting.

(d) Any variance granted under this rule shall be subject to such limitations or conditions as the Director, Director’s designee, or Board deems necessary in order to conform to the basic purposes and policies of applicable law.

(I) A temporary variance is valid for six (6) months from the date of issue. One variance may be granted at the discretion of the Director or the Director’s designee per incident.

(e) If any determination made by the Director or the Director’s designee pursuant to this rule is not appealed by the applicant within thirty (30) days pursuant to Rule 5(d), such determination shall become final.

(f) Pursuant to § 24-31-303(5)(a) and § 24-31-305(1)(a)(III), C.R.S., no person may, through a variance or otherwise, serve as a certified peace officer, as defined in § 16-2.5-102, C.R.S., without having first passed the required certification examination and become certified.

(g) Pursuant to § 24-31-303(1)(t), C.R.S., the process outlined in subsection (b) of this Rule 7 applies to a peace officer seeking review of a peace officer’s status in the database created per §§24-31- 303(1)(r) and 24-31-321, C.R.S.

(I) For variances related to database entries, POST will request all documents related to the database entry from the reporting organization.

(II) POST shall give consideration to a peace officer’s whistleblower status, as defined in

Rule 1, during an appeal process related to their inclusion on the database.

Rule 8 – Process for Seeking Exemption from Statutory Certification Restrictions (a) The Board has promulgated these rules to ensure orderly and fair treatment of all POST approved training academy, renewal and provisional peace officer applicants. § 24-31-305, C.R.S., requires the POST Board to deny or revoke certification of any person with a disqualifying incident.

(b) If an applicant anticipates prior to the denial of certification that they will be denied certification on the ground that the applicant has a disqualifying incident, the applicant must provide a fingerprintbased criminal history record check, by submitting fingerprints to the Colorado Bureau of Investigation and the U.S. Federal Bureau of Investigation, and request an exemption from denial of certification. When POST receives the criminal history and exemption request, it will process the exemption request using the process described in section (c) of this Rule 8.

(c) To seek an exemption of a certification denial, or to request a reinstatement following a certification revocation or suspension, the applicant or the chief law enforcement officer, if any, of the potential employing agency, or the effected certificate holder, must submit a written petition to the Director or their designee, notifying of such disqualifying incident, and requesting that the Director or their designee to grant the applicant an exemption from certification denial, or to the affected certificate holder certificate reinstatement of the certificate. The petition must fully explain all relevant facts. Any person seeking an exemption from certificate denial or reinstatement of a certificate due to a disqualifying incident has the burden to establish:

(I) The exemption or reinstatement is consistent with the basic purposes and policies of § 24-31-305, et seq., C.R.S., including § 24-31-305(1.5)(b), if applicable;

(II) Mitigating circumstances exist that warrant exemption or reinstatement;

(III) Certification would be in the public interest; and (IV) A true and accurate copy of the court record with disposition, law enforcement offense/case report from the disqualifying incident, and/or any other relevant documentation of a disqualifying incident, is attached to the petition. If the charging agency no longer has a copy of the report, a letter from the agency verifying that fact should be attached.

(d) The Director or their designee, at their discretion, may determine the merits of the request based upon the petitioner’s written submissions, may request additional information, or may hold a (e) Any exemption granted under this rule shall be subject to such limitations or conditions as the Director, or their designee, or Board deems necessary in order to conform to the basic purposes and policies of applicable law.

(f) The Director’s, or their designee’s, decision may be appealed by following the process outlined in

Rule 5 – Hearings.

(g) In accordance with § 24-31-303(5)(a) and § 24-31-305(1.6)(a)(b), C.R.S., no person may, through an exemption or otherwise, serve as a certified peace officer, as defined in § 16-2.5-102 or § 16- 2.5-110, C.R.S., without having first passed the required certification requirements and become certified.

(h) No person convicted of a felony may request an exemption from denial of enrollment.

Rule 9 – Actions on Certification (a) The POST Board has authority, pursuant to § 24-31-305, C.R.S., to suspend or revoke a Colorado peace officer certification for a disqualifying incident.

(b) The certificate holder may voluntarily surrender a peace officer certification at any time by entering into a signed agreement affirming the same with the POST Board.

(c) For purposes of revocations or suspensions for a disqualifying incident, a true and accurate copy of the court conviction or agreement shall constitute prima facie evidence of the conviction or agreement.

(d) The certificate holder or the chief law enforcement officer of the agency employing such certificate holder may, within thirty (30) days after the effective date of the denial, suspension, or revocation for any disqualifying incident, petition the Board for an exemption by following the requirements of Rule 8.

(e) For purposes of this Rule 9, the procedural rules set forth in Rule 5 shall apply.

(f) Certificate holders suspended for a disqualifying incident per this Rule 9 must follow the renewal procedure in Rule 13 prior to reinstatement.

Rule 10 – Basic Peace Officer Certification a) The POST Board is authorized to issue POST Basic Peace Officer Certification to any applicant who meets the following requirements:

(I) Possesses and submits a copy of their high school diploma, high school equivalency certificate, or other evidence of successful completion of high school, including official college transcripts or degree;

(II) Possesses and submits a copy of their current first aid and cardiopulmonary resuscitation certification, or equivalents;

(III) Truthfully completes and submits the POST Form 1 - Application for Basic Peace Officer Certification;

(A) If previously certified as an officer in another state but is ineligible to apply as a provisional applicant, the applicant must be in good standing with the other certifying state and must complete and submit to POST a POST Form 3 – Application for Provisional Certification and a Release of Information Form within thirty (30) days of starting the academy.

(IV) Is in good standing with Colorado POST as determined by the Director; and, (V) Successfully completes the fingerprint-based criminal history record check required under

Rule 14 and meets all of the following requirements:

(A) If applicable, submits a copy of their official military discharge documents showing character of service other than discharge under dishonorable conditions, per § 24-31-301(5), C.R.S.

(B) Successfully completes an approved basic training academy, including skills training, and passes the written certification examination.

(C) Submits a copy of their academy certificate of completion.

(D) Possesses and submits a copy of their current Driver’s License or State-Issued Identification card.

(E) Documentation pertaining to certification requirements must be submitted to POST via the law enforcement training academy, if applicable.

(F) Testing is valid for two years from the date of completion. After this time has elapsed, if full certification was not issued, the applicant must successfully complete an additional basic academy program.

b) POST Basic Peace Officer Certification qualifies the person to seek employment and serve as a fully authorized peace officer with any Colorado law enforcement agency recognized in Article 2.5 of Title 16, C.R.S.

c) Upon issuance of a basic certification, if all training requirements under § 24- 31-315, C.R.S., have not previously been met, the individual must complete all requirements within six (6) months from date of appointment.

(I) Complete two (2) hours of training in each of the following areas: anti- bias; community policing; situational de-escalation; and proper holds and restraints.

(II) Complete one (1) hour of training in each of the following areas: improving first responder interactions with persons with disabilities; and issues related to missing and murdered d) If a basic certificate holder has not served as a peace officer or reserve peace officer for a total of at least six (6) months during any consecutive three-year period, the certification automatically expires at the end of such three-year period, unless the certificate holder is then serving as a peace officer or reserve peace officer.

(I) If a basic certificate holder is deployed for military service, the certification automatically expires at the end of a three-year period from the date of certification or the date of separation from a Colorado law enforcement agency. If expired, the basic certificate holder is eligible to complete the certification renewal process. If employed at time of deployment, the certificate holder, at the agency’s discretion, may remain on the employment roster and their certification will not expire.

(II) A certificate may remain active and unexpired if the certificate holder works for a law enforcement agency in a non-peace officer role and maintains annual training requirements established by the POST Board. Such training must be completed each calendar year and cannot be completed cumulatively before entering a peace officer role.

(A) Persons serving in this capacity do not have peace officer authority and may not act as a peace officer.

(B) Failure to complete the annual in-service training within 30 days after receiving the preliminary report from POST pursuant to Rule 28(e)(II)(A)(2)(a) will result in certification expiration three (3) years from the last date worked in a peace officer role.

e) A certified peace officer who has obtained basic certification may maintain current status as a certified peace officer while serving in a reserve peace officer position, recognized in § 16-2.5- 110, C.R.S.

f) A certified reserve peace officer seeking regular basic peace officer certification may apply their successfully completed skills training, obtained through the reserve peace officer certification program at a POST approved reserve academy, towards basic peace officer certification.

Acceptance of the skills training is at the option of the Director of the basic peace officer training academy to which the applicant is seeking enrollment.

Rule 11 – Provisional Certification (a) The Board is authorized to issue a provisional certification letter to any applicant who is authorized to serve as a certified peace officer by any other state or federal jurisdiction, which has established minimum law enforcement training standards that are substantially equivalent to the standards established by Colorado as determined by the Director. The provisional applicant must be fully certified within the preceding three years and have served as a certified law enforcement officer in a full or part-time status in good standing in such other state or federal jurisdiction for more than one year, per § 24-31-308 (1)(a), C.R.S. The applicant must additionally meet all of the following requirements:

(I) Possess and submit a copy of their high school diploma, or high _school equivalency certificate, or other evidence of successful completion of high school, including official college transcripts or degree, (II) Possess and submit a copy of their current first aid and cardiopulmonary resuscitation certification, or equivalents;

(III) Truthfully complete and submit the POST Form 3 – Application for Provisional Certification and a notarized copy of the Release of Information Form;

(IV) Is in good standing with Colorado POST as determined by the Director;

(V) Successfully completes the fingerprint-based criminal history record check required under

Rule 14;

(VI) If applicable, submits a copy of their official military discharge documents showing character of service and discharge under other than dishonorable conditions; and (VII) Pass the certification examination or, if leaving active out-of-state (the state in which the individual is certified) or federal peace officer employment, pass the certification exam within six (6) months from the date of issuance of the provisional certification.

(VIII) Provisional certification applications are valid for one year from date of submission.

(b) If an applicant becomes ineligible prior to receiving their provisional certification letter due to timein-service requirements, the applicant must request and be granted a Rule 7 variance in order to move forward in the provisional process.

A provisional certification letter authorizes the holder to serve as a certified Colorado peace officer for not more than six (6) months.

(c) At the discretion of the Director or their designee, a variance may grant a single six (6) month extension to the provisional certification, upon the showing of good cause.

(d) The Board shall issue a basic certificate to the holder of a provisional certification letter if such person satisfies one or any acceptable combination of the following skills proficiency requirements, or, if leaving active out-of- state (the state in which the individual is certified) or recognized federal peace officer employment, satisfies one or any acceptable combination of the following skills proficiency requirements with prior post approval within six (6) months from the date of issuance of the provisional certification:

(I) Successfully completes skills training at a POST-approved basic peace officer training academy, or;

(II) Successfully completes a POST-approved refresher academy, including the arrest control, law enforcement driving, and firearms skills training and submits a copy of their certificate of completion, or;

(III) Passes a test out pursuant to Rule 16 with SME committee members or POST-approved designees who are not members of the applicant’s employing agency.

(e) Upon issuance of a provisional certification and appointment to an agency the individual must comply with the training requirements outlined in § 24- 31-315, C.R.S., within six (6) months of date of appointment.

(I) Complete two (2) hours of training in each of the following areas: anti-bias; community policing; situational de-escalation; and proper holds and restraints, and;

(II) Complete one (1) hour of training in each of the following areas: improving first responder interactions with persons with disabilities; and issues related to missing and murdered (f) The POST-approved skills instructor must submit the completed POST Skills Testing Grade Sheet to POST.

(g) Persons desiring additional time to complete the basic certification requirements beyond the initial six (6) months provided by the provisional certification letter must submit a variance request to the Director or their designee and demonstrate good cause why such additional time should be granted.

(h) An applicant may complete the provisional certification process while their application is valid, regardless if their provisional certification letter has expired. However, the applicant may not work as a certified peace officer if their provisional certification letter is not valid or has expired.

(i) Effective July 9, 2025 there will be a Federal Reciprocity Provisional Certification Pilot program.

This pilot program expires on December 31, 2026, unless extended or made permanent by a vote of the POST board. The pilot program shall meet the following elements:

(I) Program participants must meet the statutory requirements of § 24- 31-308, C.R.S., having served for at least one year in the preceding three years in good standing in the federal equivalent of a certified peace officer, as determined by the Director or their designee.

(A) Substantial equivalence to Colorado POST standards, as required by Rule 11(a), is not a requirement for the pilot program.

(B) The federal equivalent of a certified peace officer includes, but is not limited to, armed forces police officers / military police officers for the purpose of this pilot program.

(II) Program participants must be hired by, or must provide a notarized “intent to hire” letter from, a Colorado law enforcement agency.

(III) Hiring organizations will conduct a gap analysis using POST training standards for basic certification and the program participant’s training records to identify knowledge, skills, abilities and other characteristics the hiring organization will required to include in the program participant’s training.

(A) Hiring organizations may use a previously developed gap analysis for subsequent hires from the same federal agency, so long as their basic training was within five (5) years of the basic training date from the previous gap analysis.

(B) Hiring organizations are encouraged to use existing lesson plans developed by their local law enforcement training academy to use as a foundational basis for their gap training.

(C) Hiring organizations are required to issue a certificate of completion for each gap target area successfully completed and provide post with a copy of the certificate.

(IV) Hiring organizations shall evaluate the program, including participant performance and readiness to serve as a Colorado POST certified peace officer, providing this feedback to post in a manner determined by POST.

(V) Program participants may otherwise seek provisional and basic peace officer certification using the process described in this Rule 11, so long as all the requirements of the federal reciprocity provisional certification pilot program are met.

Rule 12 – Reserve Certification a) The Board is authorized to issue a reserve certificate to any applicant who meets the following requirements:

(I) Possesses and submits a copy of their high school diploma, or high school equivalency certificate, or other evidence of successful completion of high school, including official college transcripts or degree; and (II) Possesses and submits a copy of their current first aid and cardiopulmonary resuscitation certification, or equivalents; and (III) Truthfully completes and submits the POST Form 2 – Application for Reserve Certification; and (IV) Is in good standing with Colorado POST as determined by the Director; and (V) Successfully completes the fingerprint-based criminal history record check required under

Rule 14 and meets all of the following requirements:

(A) If applicable, submits a copy of their official military discharge documents showing character of service other than dishonorable conditions, per § 24-31- 301(5), C.R.S.

(B) Successfully completes an approved reserve academy including skills training. within two (2) years of the graduation date.

(C) Submits a copy of their academy certificate of completion.

(D) Possesses and submits a copy of their current driver’s license or state-issued identification card.

(VI) Testing is valid for two years from the date of completion. After this time has elapsed, if reserve certification was not issued, the applicant must successfully complete an additional reserve academy program.

b) Upon issuance of a reserve certification and appointment to an agency the individual must comply with training requirements outlined in § 24-31-315 C.R.S. within six (6) months.

(I) Complete two (2) hours of training in each of the following areas: anti- bias; community policing; situational de-escalation; and proper holds and restraints, and;

(II) Complete one (1) hour of training in each of the following areas: improving first responder interactions with persons with disabilities; and issues related to missing and murdered c) Any law enforcement agency assigning duties to a reserve peace officer beyond those included in the approved reserve training shall assume the responsibility for ensuring that such reserve peace officer is adequately trained for such duties.

d) If a reserve certificate holder has not served as a reserve peace officer for a total of at least six (6) months during any consecutive three-year period, the certification automatically expires at the end of such three-year period, unless the certificate holder is then serving as a reserve peace officer. If expired, the reserve certificate holder must complete a new reserve training academy.

(I) If a reserve certificate holder is deployed for military service, the certification automatically expires at the end of a three-year period from the date of certification or the date of separation from a Colorado law enforcement agency. If employed at time of deployment, the certificate holder, at the agency’s discretion, may remain on the employment roster and their certification will not expire.

e) Reserve certifications may not be renewed once expired.

f) A certified peace officer may maintain current status as a certified peace officer while serving in a reserve peace officer position, recognized in § 16-2.5- 110, C.R.S.

Rule 13 – Renewal of Basic Certification The Board is authorized to renew a basic certificate for any applicant who:

(a) Has not served as a peace officer or reserve peace officer within the previous three (3) years or who has been suspended pursuant to rule 9; and (b) Possesses and submits a copy of their current first aid and cardiopulmonary resuscitation certification, or equivalents; and (c) Truthfully completes and submits the POST Form 4 – Application for Renewal of Basic Certification; and (I) If an applicant has worked in another state as a certified peace officer after being certified in Colorado, they must truthfully complete and submit the POST Form 3 – Application for Provisional Certification, and a notarized copy of the Release of Information Form; and (II) Is in good standing with Colorado POST as determined by the Director; and (e) Successfully completes the fingerprint-based criminal history record check required under Rule 14; and (f) Passes the certification examination pursuant to Rule 15; and (g) Satisfies any combination of the following skills proficiency requirements with prior post approval:

(I) Successfully completes skills training at a POST approved basic peace officer training academy;

(II) Successfully completes a POST approved refresher academy, including the arrest control, law enforcement driving, and firearms skills training;

(A) Submits a copy of their refresher academy certificate of completion.

(III) Passes a test out pursuant to Rule 16 with SME committee members or POST approved designees who are not members of the applicant’s employing agency.

(h) The POST SME Committee member or POST approved designee must submit the completed POST Skills Testing Grade Sheet to POST.

(i) Upon renewal of a Colorado basic peace officer certification and appointment to an agency the individual must comply with training requirements outlined in C.R.S. §24-31-315 within six (6) months.

(I) Complete two (2) hours of training in each of the following areas: anti- bias; community policing; situational de-escalation; and proper holds and restraints.

(II) Complete one (1) hour of training in each of the following areas: improving first responder interactions with persons with disabilities; and issues related to missing and murdered

Rule 14 – Fingerprint-Based Criminal History Record Check a) No person shall be eligible for certification as a Colorado peace officer if they have a disqualifying incident.

b) Per § 24-31-304, C.R.S. and POST Rules, all persons seeking to enroll in a training academy shall submit their fingerprints to CBI no more than 60 days prior and at least one week before enrolling in the training academy. The academy must notify POST when fingerprints are submitted. POST staff may, in their discretion, grant an extension of time beyond one week for good cause.

(I) All fingerprint results must be received by POST no later than two weeks after enrollment date.

c) All persons seeking to apply for provisional or renewal certification must submit fingerprints to CBI as part of the application process pursuant to Rule 11 and 13.

d) POST Applicant Fingerprint results.

(I) The Board recommends that an applicant’s fingerprints be submitted electronically by a CBI-authorized vendor or a LEA authorized by CBI to submit fingerprints for POST. When this is not possible, the applicant can submit fingerprints using the POST Applicant Fingerprint Card, obtained directly from POST. Any fees associated with this service are the responsibility of the applicant.

(II) Provisional and renewal applicants may request the POST Applicant Fingerprint Card when they are unable to submit fingerprints electronically. The applicant is responsible for having their fingerprints taken prior to the applicant’s participation in the testing process as a provisional or renewal applicant.

(III) Applicants enrolling in a basic or reserve training academy shall be fingerprinted in accordance with the academy’s policies and procedures. The academy is responsible for ensuring that fingerprints are submitted to CBI by a CBI-authorized vendor or that the completed POST Applicant Fingerprint Card and fee are submitted to CBI prior to the applicant’s enrollment in the academy.

(IV) Fingerprint results are valid throughout the certification process and through the life of certification. If certification expires or is revoked they become invalid. Applicants renewing their certification must submit new fingerprints.

e) Results from completed criminal history record checks.

(I) The Board shall be the authorized agency to receive the results from all POST Applicant Fingerprint submissions that have been processed for the state and national fingerprintbased criminal history record checks.

(II) All results from the completed criminal history record checks will be provided to the POST Director or their designee. Notice of subsequent arrests and convictions resulting in denial of certification will be provided to the Board.

f) Basic and reserve training academies.

(I) A training academy shall not enroll any person who has been convicted of an offense that would result in the denial of certification pursuant to § 24-31-305(1.5), C.R.S. The only exception shall be if the Board has granted the person an exemption from denial of enrollment pursuant to § 24-31-304(4)(a), C.R.S. and POST Rule 7, Variances.

(II) No person shall be enrolled in a training academy unless the person has been fingerprinted on a POST Applicant Fingerprint Card and an academy has submitted the person’s completed POST Applicant Fingerprint Card and fee to CBI, or fingerprints have been submitted by a CBI-authorized vendor, prior to enrolling the person in the academy.

(III) A POST Form 11-E, Enrollment Advisory Form, shall be completed both by the person enrolled in the academy and the academy director or designee. The completed enrollment advisory form shall be submitted to POST with other enrollment documents and maintained at the academy.

(IV) The academy director shall ensure that an accurate and complete enrollment roster for each academy class is received at POST electronically one week prior to the first day of the academy. The enrollment roster will be completed on the template provided by POST to the academy director.

(A) The enrollment roster must be fully completed with all personal information, education, military service, etc. and returned to POST staff. After entry, the roster will be returned to the academy director with assigned PID numbers.

(V) If the results of a criminal history record check reveal that a person currently enrolled in an academy is prohibited from enrolling pursuant to § 24-31-304(2), C.R.S., the Board or its designated representative(s) shall notify the academy. The academy shall take appropriate measures to immediately dismiss the person from the academy.

g) Exemption from denial of enrollment.

(I) If a person anticipates that he or she will be prohibited from either enrolling in a training academy or participating in the testing process as a provisional or renewal applicant because he or she has a disqualifying incident as described in POST Rule 1(o), the person may submit a request for exemption from denial of enrollment under POST Rule 8, process for seeking exemption from statutory certification restrictions.

(II) Only if the person has, in fact, submitted a request for exemption from denial of enrollment under POST Rule 8, Process for seeking exemption from statutory certification restrictions, and the request has been granted by the Board, will the person be permitted to either enroll in a training academy or participate in the testing process as a provisional or renewal applicant.

(III) No person convicted of a felony may request an exemption from denial of enrollment.

Rule 15 – Certification Examination Basic, Provisional, Renewal (a) To be eligible to take the certification examination, an applicant must have completed and submitted to POST, as applicable:

(I) Form 1 - Application for Basic Peace Officer Certification; or Form 3 - Application for Provisional Certification; or Form 4 - Application for Renewal of Basic Certification; and (II) A copy of their approved basic training academy diploma, or other evidence of successful completion; and (III) A copy of their high school diploma, high school equivalency certificate or other evidence of successful completion of high school, including official college transcripts or college degree as evidence that the applicant has met the high school completion requirement;

(IV) A copy of their current first aid and cardiopulmonary resuscitation certification, or equivalents; and (V) A copy of their current driver’s license or state-issued identification card; and (VI) If applicable, a copy of their official military discharge documents showing character of service other than dishonorable conditions per § 24-31-301(5), C.R.S.

(VII) A law enforcement agency check, certified check, money order, or electronic payment in the prescribed amount.

(b) Certification examinations will be conducted by POST staff or POST approved designated proctor at academy locations. However, if the number of students sitting for the examination is four (4) or fewer, the students shall be required to take the examination at a location designated by POST.

Additional exam dates will be offered periodically at POST for individuals.

(c) Refunds of certification examination fees shall not be provided unless the examination is postponed or canceled or under such other exceptional circumstances as determined by the Director, or their designee. Otherwise, non-refunded fees may be credited to allow the applicant to take the next administration of the certification examination. Further credits or extensions shall not be permitted.

(d) An applicant has a maximum of three attempts to pass the POST certification examination within two years of graduating the academy, or within one year of beginning the provisional or renewal process. Applicants taking the examination for a second or third time must pay the fee for the additional examination, and such examination shall not be comprised of the same questions that comprised the prior examinations. If an applicant cannot pass the certification examination after three attempts, the applicant must retake and successfully complete the academic portion of a basic academy in accordance with Rule 10 at the discretion of the academy director and in coordination with POST.

(e) Any protest or challenge to an examination or its administration must be made in writing within ten (10) days of the examination. The Director, or their designee, shall issue his decision in writing within twenty (20) working days. The decisions of the Director, or their designee, shall be final, unless appealed to the Board in accordance with Rule 5(d).

(f) POST sets a passing score that reflects the level of knowledge and skills required for minimally competent performance as an entry-level Peace Officer in the State of Colorado. POST uses national testing standards in setting the passing score which falls on a test score scale that ranges from 0 to 100.

(g) Cheating on, recording or attempting to record, or violating the confidentiality agreement for the POST certification examination shall result in the invalidation of that test score and a prohibition on future examination attempts. These actions may also result in an entry on the National Decertification Index as misconduct.

Rule 16 – Skills Examinations for Provisional and Renewal Applicants (a) To be eligible to take any of the skills examinations, an applicant must complete and submit all applicable POST form(s) as set forth in POST Rule, including POST Form 3 – Application for Provisional Certification and/or POST Form 4 – Application for Renewal of Basic Certification along with a law enforcement agency check, certified check, money order, or electronic payment in the prescribed amount for each examination to be taken (prior to the day of the exam).

(b) Refunds of skills examination fees shall be provided only if requested more than twenty (20) days prior to the scheduled examination, unless the examination is postponed or canceled, or under such other exceptional circumstances as may be determined by the Director, or their designee.

(c) All skills examinations must be coordinated and pre-approved by post staff. Only SME members, or the Director’s designee, may conduct skills examinations.

(d) An applicant will be permitted three formal attempts to successfully complete each skills exam.

(I) Starting any skills exam is considered one attempt.

(II) An applicant may only coordinate additional attempts with POST staff in advance.

(III) Payment for each attempt must be submitted prior to the exam.

(IV) Multiple attempts may be permitted at the discretion of the SME member administering the test out. POST may or may not assess an additional exam fee.

(e) If an applicant has failed a skills examination on three (3) formal attempts, the applicant then has two (2) years to complete the basic academy training program for that skill at a Colorado POSTapproved basic or reserve academy at the discretion of the academy director and in coordination with POST. If the applicant does not complete the required training within the two (2) years following their last skills examination attempt, they must complete a full basic academy.

(f) Skills examination scores are valid for two (2) years from the date of the last registered score with POST. All skills exams must be taken and successfully completed within two years of the initial application date.

(g) Any protest or challenge to an examination or its administration must be made in writing within ten (10) days of the examination. The Director, or their designee, shall issue a decision in writing within twenty (20) working days. The decision of the Director, or their designee, shall be final, unless appealed to the Board in accordance with Rule 5(d).

Rule 17 – Certification Records and Reporting Requirements a) POST certificate holder reporting requirements (I) Every POST certificate holder shall keep current the POST certificate holder’s name, mailing address, email address, home telephone number, or cell phone number to the POST records management system.

(II) A POST certificate holder shall submit an update to POST within fifteen (15) days of a disqualifying incident.

(III) If a peace officer is exonerated pursuant to § 24-31-904, C.R.S., the peace officer shall submit an update to POST to effectuate reinstatement of a revocation of a certificate, pursuant to the process outlined in Rule 7.

(IV) Pursuant to § 18-8-805(4), C.R.S., if a peace officer witnesses another peace officer use or direct the use of ketamine on another person, the peace officer shall report such use within ten (10) days of the occurrence, including date, time, and place of the occurrence, identity, if known, of the participants; and a description of events.

b) Employing, or formerly employing, agency reporting requirements (I) The employing agency shall submit an update in the manner prescribed to POST within fifteen (15) days of:

(A) Appointment of a basic peace officer, provisional peace officer, or reserve peace officer as defined in section § 16-2.5-102, § 24- 31- 308 and § 16-2.5-110, C.R.S.

Submissions must include physical and psychological examinations affirmation (Form 6).

(B) Separation of a certified peace officer from a law enforcement agency.

Separation includes retirement of a certified police officer.

(C) Any new hire, appointment or transfer of an existing employee to a position that requires a POST certification.

(D) Reporting any incident as required under Rule 32.

  1. The employing, or formerly employing, organization must report when a peace officer is charged with a criminal offense that could result in revocation or suspension of certification as soon as practicable.

(E) A certificate holder employed by the law enforcement agency engaging in a disqualifying incident as described in Rule 1.

(F) A law enforcement agency must appoint and separate any non-POST certified VIN Inspectors to POST in accordance to (b)(I) of this Rule.

(II) Each year, between November 1 and January 31 of the following year, each law enforcement agency shall verify the accuracy of the certified peace officers employed by with the law enforcement agency listed on the POST records management system by submitting the Rule 17 Form to POST. By submitting the form, each agency is certifying that the agency has confirmed all certified peace officers associated with their law enforcement agency have no disqualifying incidents that would prevent the individual from being a certified peace officer in Colorado, and that each certified peace officer has a current driver's license or state-issued identification card.

(A) Submissions not received by January 31st may be subject to fines or other administrative sanctions.

(III) A law enforcement agency is required to provide accurate data for the POST records management system and Peace Officer Database.

(IV) Failure to adhere to the requirements of this Rule 17 may subject individual certificate holders and law enforcement agencies to fines or other administrative sanctions as determined in accordance with Rule 31.

Rule 18 – Certification, Suspension, and Revocation; Basic, Provisional, Renewal, and Reserves (a) A suspension temporarily invalidates the subject certification until such time as the defect has been remedied. Any certification shall be suspended by the Board if the holder wrongfully obtained the certificate through misrepresentation, neglect, mistake or otherwise failed to meet the certification requirements established by the Board.

(b) The Board shall suspend a peace officer's certification if the peace officer fails to comply with the training requirements. The POST Director shall reinstate a peace officer's certification that was suspended pursuant to this paragraph (a) upon completion of the training requirements. The reinstatement will be effective immediately.

(c) Failure to comply with POST training requirements may result in certification revocation by the POST Board if a peace officer fails to satisfactorily complete the training required, and fails to remedy such failure by satisfactorily completing the training within 30 calendar days of receiving notification of failure from the POST Board.”

(d) A revocation permanently invalidates the subject certification. Any certification shall be revoked by the Board if the holder has a disqualifying incident.

Rule 19 – Vehicle Identification Number Inspectors (a) Any person seeking certification as a Vehicle Identification Number Inspector must meet each of the following requirements:

(I) Currently serving as a peace officer recognized in Title 16, Article 2.5 of the Colorado Revised Statutes or as “Inspector” defined in Title 42 Article 5 of the Colorado Revised Statutes; and (II) Successfully completes and submits his/her certificate of completion from an approved Vehicle Identification Number course; and (III) Completes and submits the POST Form 9 – Application for VIN Inspector Certification.

(IV) VIN Inspector certifications are valid for three (3) years from the date of issue or from the most recent renewal date.

(b) The following are requirements for renewing a VIN Inspector certification:

(I) The VIN Inspector must successfully complete the approved POST VIN Inspector renewal training either on-line or in-person (if available).

(II) The renewal training must be completed prior to the inspector’s current expiration date.

(III) The training must be reported to the POST records management system. This may occur automatically in the case of POST on-line training.

(IV) Once renewal training is successfully completed and submitted to POST, the VIN Inspector certification will be renewed and given an expiration date of three (3) years from the training completion date.

(V) Any inspector who fails to successfully complete the renewal training prior to their expiration date must complete the full VIN Inspector training in order to be re-certified.

(VI) All VIN Inspectors who were certified prior to August 2, 2019 (the effective date of § 42-5- 206(4), C.R.S.,) will have until June 30, 2020 to complete the renewal training for the first time.

Rule 20 – Vehicle Identification Number Inspector Programs (a) Every vehicle identification number (VIN) inspector program must contain a minimum of seventeen (17) hours, adhere to POST curriculum requirements and be approved prior to the start of instruction.

(b) The program director must submit all of the following documentation to POST staff at least sixty (60) days prior to the start of instruction:

(I) A narrative of performance objectives for the program (new programs only);

(II) A list of courses to be taught and the time allocated for each course (new programs only);

(III) A completed POST Form 9A, Application for VIN Inspector Training Program Approval, and a list of instructors and their qualifications. Instructors shall be approved only for a specific program under this rule (all programs).

(c) To be approved, a program must include all of the following:

(I) Legal aspects of VIN inspection;

(II) Use of the National Insurance Crime Bureau (NICB) Passenger and Commercial Vehicle Identification Manuals;

(III) How to conduct a VIN inspection; and (IV) How to meet the reporting requirements of a VIN inspection.

(d) The program director must submit a roster of passing students to POST within thirty (30) days of the end of the program.

Rule 21 – Basic, Refresher and Reserve Training Academies a) General Academy Requirements.

(I) All aspects of an academy must be in compliance with POST Rules and Program requirements before academy approval will be considered.

(II) Only an academy that is approved by POST may provide training required for certified peace officer status; and (III) Each scheduled academy class of an approved training academy must be approved prior to the start of instruction.

(IV) Effective January 1, 2024, each academy shall implement an anti-hazing policy, including anti-hazing training for all staff that have contact with academy recruits. Hazing, as defined in Rule 1, shall not be tolerated.

(A) Anti-hazing policies shall include a primary reporting mechanism to the academy and will make evident how to report hazing to POST, as a secondary option.

(B) There shall be no retaliation or punishment against individuals for making good faith reports of hazing.

(V) All academy training must be conducted in a safe manner.

(VI) Academies implementing pilot curriculum modules created or approved by POST are deemed to be in compliance with POST requirements for that curriculum module.

b) Continuing academies.

(I) A continuing academy is an approved Basic, Refresher or Reserve academy that conducts and completes at least one approved academy class every three (3) years and operates in compliance with these rules. Three (3) years is defined by the enrollment date of the last academy completed.

(II) If a continuing academy does not complete at least one approved academy class in any consecutive three (3) year period, approval of the academy shall expire. An expired academy must reapply for approval as a new academy and must be approved by POST prior to providing any academy instruction.

(III) Other than as referenced in the preceding paragraph (II), a continuing academy may remain approved unless its status is surrendered, suspended or revoked.

(IV) The academy director must ensure that the following items are submitted electronically to POST at the same time and are received by POST at least thirty (30) days, but no more than sixty (60) days, prior to the start of instruction for each scheduled academy class of the approved training academy:

(A) A completed POST Form 7, Application for Academy Approval;

(B) A completed “Scheduling Request for POST Exam” form (Basic and Refresher academies only); and (C) A complete and accurate academy schedule with the following information clearly noted on the schedule:

  1. Name of the academy and academy class number as listed on the POST Form 7, Application for Academy Approval; and 2) All courses, dates and times in chronological order for each course, major exams and the name of the primary instructor for each course;

  2. All dates and times when arrest control drill training, night driving and dim light shooting will be instructed;

  3. For arrest control and firearms training, if the schedule shows more than eight (8) hours of instruction in any one day, then the schedule must denote lab or lecture hours, as appropriate; and 5) If multiple courses are listed within the same block of time on the schedule, then either the schedule itself or accompanying documents must specify the amount of time that will be instructed for each course.

  4. All courses required by the basic academic training program must be scheduled and completed prior to administration of the POST certification examination.

(V) The academy director shall ensure that an accurate and complete enrollment roster for each academy class is received no later than one week prior to the start of each academy session. All other required enrollment documents must be received at POST electronically by the day after the academy commences. The enrollment roster will be completed on the template provided by POST to the academy director. See the enrollment checklist and POST Rule 14, Fingerprint-Based Criminal History Record Check.

(VI) The academy director shall notify POST prior to the occurrence of any change of the academy’s approved schedule, to include cancellation of the academy, as submitted to POST on the Form 7, Application for Academy Approval.

(VII) All academies not based at a law enforcement agency shall establish an advisory committee that consists of law enforcement officials, administrators and community members to assist with providing logistical support and validation of training.

(VIII) Existing academies must petition the POST Board every five (5) years to renew their

authority to operate a law enforcement training academy.

c) New academies.

(I) A new academy is either a Basic, Refresher or Reserve academy that has never conducted approved training, or a Basic, Refresher or Reserve academy that has not conducted approved training within the previous three (3) years.

(II) Entities interested in creating a new POST Approved Law Enforcement Training Academy must receive approval from the POST Board prior to application. The entity must present a feasibility study to demonstrate the academy could be successful, demonstrate the need for a new academy, as well as mitigation of workload on POST staff and SME’s.

(III) The academy director of a proposed new academy shall contact POST at least twelve (12) months prior to the anticipated start date of the new academy to ascertain application procedures and deadlines for submitting documents for new academy approval.

(IV) The following types of academies are considered separate academies that must be individually approved:

(A) Basic, Refresher and Reserve academies even if operated by the same agency, organization, or academic institution.

(B) Academies located either on a satellite campus, or at a different physical location than the primary academy.

(V) The proposed formal name of an academy must neither misrepresent the status of the academy, nor mislead law enforcement or the public.

(VI) Required documentation that must be submitted for new academy approval includes, but is not limited to, a video in a digital media format approved by POST of all proposed sites where academic instruction and skills training will take place, site safety plans, lesson plans for all academic courses and all skills training programs for the Basic, Refresher or Reserve Academic Training Program, resumes for all academic instructors, and documentation of qualifications for all skills instructors.

(VII) The official approval process begins once a proposed new academy’s initial application and feasibility study is approved by the POST board. The proposed new academy shall have a maximum of eighteen (18) months to complete the new academy approval process, including approval of all site safety plans, lesson plans, and other associated documents.

(VIII) The director of a proposed new academy shall also ensure that the documents required to be submitted by continuing academies, as listed in paragraph (b)(IV) of this Rule, are received at POST at least thirty (30) days, but no more than sixty (60) days, prior to the start of instruction.

(IX) Prior to approval, the proposed new academy must pass an on-site pre- approval inspection conducted by the Director or the Director’s designated representative(s).

d) Training sites, site safety plans and equipment.

(I) An academy shall have the following training sites and facilities:

(A) For academics: A classroom with adequate heating, cooling, ventilation, lighting, acoustics and space, reasonable access to restroom facilities and a sufficient number of desks or tables and chairs in the classroom for each trainee;

(B) For firearms: A firing range with adequate backstop and berms to ensure the safety of all persons at or near the range, and some type of visual notification (range flag, signs, lights, or other) whenever the range is being utilized for live fire;

(C) For driving: A safe driving track for conducting law enforcement driving;

(D) For arrest control: An indoor site for instructing arrest control training with sufficient space and mats to ensure trainee safety;

(E) For practical exercises and wellness training: Appropriate and safe locations for conducting all practical exercises and wellness lab training;

(F) Where practicable, all training sites should be clearly marked denoting that law enforcement training is in progress; and (G) Online/remote training is not allowed without expressed written permission from POST.

(II) Approval of training sites.

(A) All new training sites for academic classroom instruction and skills training must be approved by POST in consultation with the appropriate subject matter expert committee prior to conducting any training at the site.

(B) Each academy is responsible for obtaining approval for all of its training sites of academic instruction and skills training.

(C) Academy directors shall ensure that all sites for practical exercises and wellness lab training are safe and that appropriate training can be accomplished at the site to achieve the course objectives or performance outcomes.

(D) Presumed approval or use of a specific site by one academy does not extend to automatic approval of the site for use by other academies.

(E) If an approved site is not utilized during any consecutive three (3) year period by any academy for the type of training for which the site was initially approved, then site approval expires. In order to resume training at an expired site, the site must be resubmitted for approval and approved.

(F) The following items must be submitted to POST in order for approval of a new or expired training site to be considered:

  1. Video in a digital media format approved by POST that accurately depicts the site where instruction is to take place;

  2. A detailed description of the site must be included, either as verbal narrative on the video or as a written supplement; and 3) An up-to-date written site safety plan.

(G) If an approved site has been in continuous use by at least one approved academy for at least the previous three (3) consecutive years and an additional academy seeks approval of the same site:

  1. The director of the additional academy may submit a written request to POST that includes the location and/or description of the site, in lieu of the video; and 2) An up-to-date written site safety plan must be submitted to POST that is specific to the site and to the additional academy; and 3) Both the site and the safety plan must be approved by POST in consultation with the appropriate subject matter expert committee prior to conducting any training at the site.

(H) Academy Directors have discretion to utilize other classroom facilities as necessary for academic programs, provided those facilities are appropriate, safe and adhere substantially to the statements set forth in this part (d). This section is intended to allow such use of other facilities due to a facility emergency or for unique situations where a primary facility is not available or it is not desirable for the intended academic class.

  1. In such cases where a primary classroom facility is rendered unusable for a period reasonably anticipated to exceed 21 continuous days, the Academy Director shall notify POST and submit an alternative training site plan for approval.

(III) Site safety plans.

(A) Each site of skills training and academic or classroom instruction must have an up-to-date and approved written site safety plan posted on site during any academy training at the site, or issued to, and present on the person of, each recruit and instructor.

(B) Copies of all site safety plans must also be on file at the academy at all times.

(C) Each site safety plan shall include procedures for managing medical emergencies, injuries, or accidents that are probable or likely to occur at the site.

(D) All site safety plans must include the information contained in POST Rule 21 (h), Duty to Report.

(E) All academy staff members, instructors and trainees shall be familiar with the content of each site safety plan as it pertains to the nature and scope of their involvement with the academy.

(IV) Equipment.

(A) An academy shall have and maintain the necessary equipment and instructional aids in sufficient quantities for conducting all aspects of the required academy training program; and (B) All training sites and facilities, equipment, books, supplies, materials and the like shall be updated and maintained in good condition.

(C) The following items shall be present at each training site during any academy training at the site:

  1. An effective means of summoning emergency medical assistance; and 2) A first aid kit that contains appropriate supplies to treat medical emergencies or injuries that are likely to be sustained at the site.

e) Academy directors.

(I) Qualifications. Each academy shall designate an on-site academy director whose qualifications, based upon education, experience and training, demonstrate his or her ability to properly manage the academy.

(II) Compliance. The academy director shall ensure that the academy operates in compliance with all POST Rules.

(III) Records. The academy director shall be responsible for establishing and maintaining a records management system that includes, but is not limited to, enrollment rosters, POST Form 11-E’s, trainee files, trainee manuals, attendance records, lesson plans, source material, instructor files, instructor/course evaluations and site safety plans.

(IV) Change of director. The academy director or authorized representative of an academy shall notify POST as soon as practicable of any change of academy director or any change of the academy director’s electronic mailing address.

f) Curriculum requirements.

(I) Academic standards.

(A) All training academies shall meet or exceed the required course content and minimum number of hours for each academic course of instruction and for each of the skills programs as required by the Basic, Refresher or Reserve Academic Training Programs.

(B) Successful completion required.

  1. Trainees must successfully complete the Basic, Refresher or Reserve Academic Training Programs with a minimum score of seventy percent (70%); and 2) Trainees must successfully complete all skills training as required by the Arrest Control Training Program, Law Enforcement Driving Program and Firearms Training Program.

  2. If an academy applies a higher standard than what is required by the preceding paragraphs (1) and (2), the higher standard must be described in the Trainee Manual and in the respective skills lesson plans or course materials, as applicable.

(II) Attendance.

(A) Skills training. For all hours of all skills training programs, 100 percent attendance and participation are required.

  1. Skills training classes missed due to circumstances beyond the student’s control shall be completed in person and before the end of the academy session.

(B) Academic training. For all hours of academic training, 100 percent attendance and participation are required.

  1. Academic classes missed due to circumstances beyond the student’s control may be made up in a virtual format. These virtual make up courses may not exceed ten percent of the academy session’s total hours and must be completed before the end of the academy session.

(C) Written attendance records are required.

  1. For trainees: Written daily attendance records that are accurate and up to date shall be kept for all trainees enrolled in all academic classes and all skills training programs.

  2. For instructors: Written attendance records that are accurate and up to date shall be kept for all instructors who teach any portion of a training program.

  3. For skills training, the format of the attendance records must clearly substantiate that the minimum ratios required by Rule 24, Skills Training Safety and Skills Program Requirements for Basic, Refresher and Reserve Academies, have been met.

(III) Lesson plans.

(A) All Basic, Refresher and Reserve training academies shall develop and maintain up-to-date lesson plans for each academic course of instruction and for each of the skills training programs.

(B) Academic lesson plans shall be organized and readily accessible and may be maintained either electronically or as physical copies.

(C) Each academic and skills lesson plan must include at least the following information, as applicable:

  1. Course title as specified in the POST Academic Training Program (Basic, Refresher or Reserve) or the POST skills training program; and 2) Date the lesson plan was prepared and date of last revision, if applicable; and 3) Name and title of author of lesson plan and name and title of the person who approved the lesson plan; and 4) Number of hours for the course required by the POST Academic Training Program and the number of actual course hours that will be instructed;

  2. Learning goals, course objectives and/or performance outcomes for the course as specified in the POST academic training program (basic, refresher or reserve) or the POST skills training programs. Additional outcomes may be added as long as such outcomes are supported in the content and are consistent with generally accepted academic practices.

Any additional learning goals, course objectives, and/or performance outcomes must not conflict with those listed in the applicable POST basic training or skills training programs; and 6) Methods of instruction; and 7) A copy of the handouts, multimedia and/or PowerPoint presentations referenced in the lesson plan that will be used during the instruction; and 8) A list of all source materials used to develop the course, including internet links. In matters of law, primary authority, such as case law, regulations and statutes, shall provide the foundation for source material used in the lesson plan along with any additional secondary authority, i.e., articles and other references, subject to that primary authority; and 9) Testing and/or assessment methods, such as test questions and answers, performance rubrics, or other assessment tools, that are appropriate to measure the learning goal, performance outcomes and/or objectives; and 10) Safety plan control measures specific to any practical exercise, role-play, scenario or other reality-based classroom and outside the classroom;

  1. Comprehensive content information that must be delivered to teach the subject matter to a level of proficiency that allows the student to perform the tasks on the job and that satisfies the required course objectives.

a) The required material can reasonably be taught given the time constraints using appropriate instructional methodologies.

b) Written content must be supported by currently accepted laws, policies, rules, regulations, and generally accepted law enforcement practices if challenged.

(D) All lesson plans must be written to ensure consistency between instructors and between all sessions of the academy over time. Content must be sufficient in scope and specificity to allow an instructor who did not author the lesson plan or develop the supporting materials to effectively teach the course.

(E) The curriculum SME committee may create guidelines to clarify expectations from time to time. These guidelines must be published on the POST website.

(F) Skills lesson plans must additionally include the program- specific documentation referenced within the applicable POST skills training program.

(IV) Daily schedules.

(A) For all skills training programs, daily schedules are required that contain the information referenced in each of the skills training programs, as referenced in

Rule 21(b)(IV)(C).

(B) Daily schedules will be submitted on the form provided by POST.

(V) Source material.

(A) For source material identified as required source material in the current POST Curriculum Bibliography, at least one (1) copy of each of the publications or sources must be maintained at the place of academic instruction. For those sources that are referenced with a website address, providing the trainees with readily available Internet access is acceptable in lieu of maintaining at least one (1) copy of each of the publications or sources.

(VI) Academy examinations.

(A) All academies shall administer written, oral or practical examinations periodically during each academy in order to measure the attainment of course objectives or performance outcomes as specified in the Basic, Refresher or Reserve Academic Training Programs.

(B) The academy director shall prescribe the manner, method of administration, frequency and length of academy examinations.

(C) For academic courses, the time allotted for examinations shall be in addition to the number of Required Minimum Hours for each course as specified in the Basic, Refresher or Reserve Academic Training Programs.

(D) For skills training programs, the time allotted for examinations or testing is included within the total program hours of each program.

(VII) Academy and skills programs certificates of completion.

(A) The academy director shall immediately issue certificates of completion to each trainee who successfully completes all requirements of the approved academy. A certificate of completion shall be issued for each skills program and the overall academy.

(B) Only a trainee who has attended and successfully completed a skills program shall be issued a certificate of completion for that skill. A trainee who has attended all academic classes and all required skills training programs shall be issued an academy certificate of completion.

(C) Each certificate of completion shall contain the following information:

  1. Trainee’s name; and 2) Name of the approved academy; and 3) Type of skills program or academy (Basic, Refresher or reserve); and 4) Date of skills program or academy completion (month, day, year); and 5) Total number of hours of the completed skills program or academy; and 6) Signature of the academy director and/or agency or academic representative; and 7) Reserve academy certificates of completion shall additionally state whether the total number of academy hours does or does not include the approved law enforcement driving program.

g) Instructors (I) Minimum qualifications.

(A) Academic instructors shall possess the requisite education, experience and/or training necessary, as determined by the academy director, to competently instruct specific academic courses or blocks of instruction.

(B) Skills instructors shall meet the minimum qualifications as described in Rule 23, Academy Skills Instructors.

(II) Instructor files.

(A) A file (electronic or hard copy) shall be maintained for each instructor who teaches any portion of an academic class or skills training class.

  1. For academic instructors, the file must contain a current resume and/or other documentation that substantiates the instructor’s qualifications.

  2. For skills instructors, the file must contain copies of the relevant certificates of completion referenced in Rule 23, Academy Skills Instructors, and/or a copy of the applicable skills instructor approval letter issued by POST.

(B) The academy shall maintain current contact information for each instructor.

(C) Exception. Licensed attorneys from the same office or firm may be included in one instructor file, as long as the file contains the names of all attorneys from that office or firm who provide instruction at the academy.

(III) Instructor/course evaluations.

(A) Trainees shall complete written evaluations for each instructor and/or course of instruction for all academic courses and skills training programs of the approved academy.

(B) Either the POST Form 10, Instructor/Course Evaluation, or comparable academy forms and/or documents may be used for this purpose.

(C) The academy director shall determine the most meaningful format and method of administration of the instructor/course evaluations in order to monitor instructor quality and course content and to meet the needs of the individual academy.

h) Duty to report.

(I) In addition to any notifications that may be required administratively or under federal, state or local law, it shall be the duty of every academy director or the academy director’s designee to report the following events to POST immediately or as soon as practicable after the event, in a manner designated by POST:

(A) Any death, gunshot wound, serious bodily injury, diagnosed concussion, or any injury which caused a recruit’s departure from the academy that was either caused by, or may have been caused by, any training or activity associated with the academy; or (B) Any bodily injury that occurs to any person who is not affiliated with the academy, i.e., an innocent bystander, whose bodily injury was either caused by, or may have been caused by, any training or activity associated with the academy.

(C) Academies are encouraged to report any other injuries in order to allow POST to track injury trends statewide in an effort to ensure safe training environments.

(II) Training to cease.

(A) In the event of any death or gunshot wound as described in paragraph (h)(I)(A) of this section, all training shall immediately cease at the training site where the death or gunshot wound occurred.

(B) Training may resume only after the Board or its designated representative(s) have ensured that the program is operating in compliance with POST Rules.

(III) Serious bodily injury means those injuries as defined in § 18-1- 901(3)(p), C.R.S.

(IV) Bodily injury means those injuries as defined in § 18-1-901(3)(c), C.R.S.

(V) All instructors shall be familiar with the information contained in this Section (h) as it pertains to the nature and scope of their involvement with the academy.

i) Academy records requirements.

(I) Trainee files. During the academy, a file shall be maintained for each trainee or a systematic filing system must exist that contains at least the following records:

(A) Trainee’s full legal name and date of birth; and (B) Photocopy of the trainee’s high school diploma, high school equivalency certificate or other evidence of successful completion of high school; and (C) Photocopy of the trainee’s valid driver’s license; and (D) Form 11-E, Enrollment Advisory Form; and (E) Current contact information; and (F) Signed and dated acknowledgment of privacy and appeal rights forms.

(II) Trainee manual.

(A) Each academy shall maintain an up-to-date trainee manual that contains relevant and accurate information. At a minimum, the trainee manual shall contain the academy’s rules and regulations, academic requirements, attendance policies and site safety plans.

(B) Upon entry into the academy, each trainee should be issued a copy of the trainee manual and acknowledge receipt of the manual in writing.

(III) The following records shall be maintained at the academy and shall be readily available for inspection at any reasonable time by the Board or its designated representative(s).

(A) A completed Form 11-E, Enrollment Advisory Form, for each trainee enrolled in the academy in progress; and (B) Current trainee manual; and (C) Current lesson plans; and (D) Current source material; and (E) Instructor files for current instructors; and (F) Copies of all site safety plans; and (G) Trainee files; and (H) Tests, including a record of written test results and copies of associated rubrics;

(I) Attendance records; and (J) Instructor/course evaluations.

(IV) Academy records must be retained for at least the three (3) year period as referenced in the Uniform Records Retention Act, § 6-17-101, et seq., C.R.S.

Rule 22 – Concerning Sunrise Review of Peace Officer Status The Colorado General Assembly and Colorado Peace Officer Standards and Training Board (POST) find that it is necessary to ensure that clear standards exist for obtaining peace officer status in the state of Colorado. The General Assembly and POST Board, during the 2003 legislative session, made statutory changes to end the stratification of peace officers and to ensure that all peace officers receive a consistent level of statutory protection. During the 2004 legislative session, SB04-224 required that the POST Board review any group seeking peace officer status, either for a group or a specific position.

These POST Board actions are to be accomplished prior to the group seeking authorization from the General Assembly.

(a) Proposal Submission to POST (I) No later than July 1 of any year, a group or political subdivision of the state that seeks peace officer status, either for the group or a specific position, shall submit to the POST Board for its review, a completed POST Form 12 and proposal containing the following information.

(A) A complete description of the group or specific position, its enforcement responsibilities and purpose for seeking peace officer status.

(B) An estimate of the number of persons who hold the position or are in the group affected.

(C) A description of the specific need for the authority and protections required for the group or specific position.

(D) The direct benefit to the public that would result from granting the peace officer status to the group or specific position.

(E) The costs associated with granting the status to the applicant group or specific position.

(F) A resolution or letter of support for the proposed change in status from the chief executive officer of the unit of government or political subdivision employing the applicant group or overseeing the proposed position.

(G) All other information requested or required by the POST Director or POST Board Sub-committee for Peace Officer status.

(II) The Director will review item (A) through (G) and will coordinate with the group or specific position on additional information needed for POST Board review. A date will then be set for POST Board Sub-committee hearing.

(b) POST Board Sub-committee Hearing (I) POST Board Sub-committee for peace officer status (A) The Sub-committee shall include the following POST Board members – 2 Police Chiefs, 2 Sheriffs, and 1 additional Board member. The Director shall staff the Sub-committee.

(II) After receiving the required information specified in subsections (a)(I) and (II) of this rule, the POST Board sub-committee for Peace Officer status shall conduct a hearing with the group’s representatives seeking peace officer status for the group or position.

(III) At the hearing a determination as to whether Peace Officer status is needed shall be based upon the following criteria:

(A) Sufficient need for one or more of the “primary” Peace Officer powers:

  1. Authority to enforce all laws in the State of Colorado.

  2. Authority to arrest (PC, warrant, restraining order, court order).

  3. Authority to use force in effecting arrest or preventing escape.

  4. Authority to “stop and frisk.”

  5. Authority to execute search warrants.

  6. Authority to carry concealed without Sheriff’s permit.

(B) Employment by a government entity or a political subdivision thereof.

(C) Endorsement by the governing body or bodies of every group or position that the proposed legislation would include.

(D) Copies of letters of notification from the group seeking status to the affected law enforcement agencies with concurrent jurisdiction.

(E) “Draft” copy of the position/group's proposed bill language. The draft shall be completed through the use of a POST provided bill language template. Any specific limitations to Peace Officer authority need to be clearly delineated in the language of the proposed legislation.

(IV) Identification and assessment of the range and scope of authority, limits on authority, and the availability of Peace Officers with concurrent jurisdiction will be considered by the sub-committee regarding POST recommendations and training standards for each group.

(V) The preferred standards for any group or position requesting Peace Officer status are full POST certification (including background standards), and 40 hours annual continuing education.

(VI) The POST Board sub-committee for Peace Officer status shall submit a report and recommendation to the full POST Board for review and action. The applicant group or position will receive a copy of the report and recommendation.

(c) POST Board Review (I) Upon receipt of the POST Board sub-committee report and recommendation, the POST Board shall review the sub-committee recommendations at a scheduled POST Board (II) At the scheduled meeting, the POST Board shall review the report, recommendation(s) and the information submitted by the sub-committee, and shall grant the groups' or positions' representatives a hearing to address the report and recommendations of the sub-committee. The POST Board can approve the recommendations or return the application to the POST sub-committee requiring additional information, requirements, and/or further review. Should the POST Board require the sub-committee to conduct a further review of the Positions' or Groups' application, the sub-committee's final report and recommendations shall be presented to the full Board at a scheduled POST Board Meeting. The affected group/position will be notified of the meeting at which the final report and recommendations will be considered by the Board.

(III) Upon completion of sections (c)(I) and (II) of this rule, the POST Board shall submit a final report and recommendations to the group seeking Peace Officer status for the group or for a specific position and to the Judiciary Committees of the Senate and House of Representatives. The report will be submitted no later than October 15 of the year following the year in which the proposal was submitted. The report may include legislative recommendations.

(d) Limitations – § 16-2.5-201(6)

(I) The group seeking Peace Officer status for the group or specific position may request members of the General Assembly to present appropriate legislation to the General Assembly during each of the two regular sessions that immediately succeed the date of the report required pursuant to subsection (c)(III) without having to comply again with the provisions of this rule.

(II) Bills introduced pursuant to the statute and this rule shall count against the number of bills to which members of the General Assembly are limited by joint rule of the Senate and House of Representatives. The General Assembly shall not consider Peace Officer status of more than five positions or groups in any one session of the General Assembly.

Rule 23 – Academy Skills Instructors a) Recognition of academy skills instructors.

(I) A skills instructor may be recognized to teach at an approved academy as either an assistant skills instructor or a full skills instructor in each of the three (3) required skills training programs: arrest control, law enforcement driving, and firearms.

(II) All skills instructors who teach any portion of a skills training program at a POST approved basic or reserve training academy shall be qualified and approved as required by this Rule.

(III) Each academy shall maintain the applicable certificates of completion and/or documentation for all skills instructors.

(IV) New academies requesting POST approval and POST approved academies that have not conducted an academy within the previous three (3) years shall submit the appropriate documentation to POST and obtain approval for all assistant skills instructors and all full skills instructors.

b) Assistant skills instructors.

(I) An assistant skills instructor may instruct under the direction and in the presence of a full skills instructor and assist in evaluating and coaching trainees.

(II) Minimum qualifications for an assistant skills instructor:

(A) In order to begin serving or to serve as an assistant skills instructor, a person must have successfully completed the relevant approved skills instructor training program (See Rule 1, Definitions); and (B) For arrest control skills instructors, the relevant approved skills instructor training program shall be the same recognized discipline for arrest control training in which the person will be instructing.

(C) Effective July 1, 2027, all assistant skills instructors for firearms must complete a 16-hour red dot sight POST approved instructor course.

(III) Approval of assistant skills instructors.

(A) Effective March 1, 2011, assistant skills instructors for firearms, arrest control and driving do not need to have certificates of completion reviewed by POST if the academy director or new assistant skills instructor is certain that the instructor has completed the relevant approved skills instructor training program.

(B) POST will review certificates of completion and/or documentation for assistant firearms, arrest control, and driving assistant skills instructors if an academy director or new assistant skills instructor applicant is not certain that a particular instructor training program qualifies as the relevant approved skills instructor training program.

(C) Either the academy director or the assistant skills instructor applicant may submit the certificates of completion and/or documentation to POST for review.

c) Full skills instructors.

(I) A full skills instructor may develop, implement, and evaluate a skills training program. In order to begin serving or to serve as a full skills instructor, a person must have satisfied the three (3) minimum qualifications listed in the following paragraph (II).

(II) Minimum qualifications for a full skills instructor.

(A) Successful completion of the relevant approved skills instructor training program (See Rule 1, Definitions); and (B) Successful completion of an approved forty (40) hour instruction methodology training program; and (C) For arrest control and law enforcement driving, completion of a minimum of eighty (80) hours of instructional experience as an assistant skills instructor at a Colorado POST approved academy. For arrest control training, the eighty (80) hours may be completed in any recognized discipline(s) for arrest control training in which the instructor has completed the relevant approved skills instructor training program.

(D) For firearms training, completion of a minimum of two times as many hours as a POST academy firearms program as an assistant skills instructor at a Colorado POST approved academy. Effective July 1, 2027, all current full skill instructors and applicants for full skills instructor must complete a 16-hour red dot sight instructor course.

(E) All training shall be completed within the previous five (5) years prior to application.

(III) Approval of full skills instructors.

(A) All new full skills instructors must be approved by the Board in consultation with the corresponding subject matter expert committee(s) for arrest control, law enforcement driving or firearms prior to serving as a full skills instructor.

(B) To apply for approval as a full skills instructor, either the academy director or the full skills instructor applicant, if the applicant has no current academy affiliation, may submit the appropriate documentation to POST to substantiate that the minimum qualifications have been satisfied.

(C) A written statement from the director of the academy where the applicant served as an assistant skills instructor is acceptable documentation as it applies to the hour requirement. The statement must include the applicant’s full name, the dates that the applicant instructed and number of hours on each of those dates showing the applicant’s instructional experience.

(D) Instructional experience completed at other than a Colorado POST approved academy may be considered as part of the eighty (80) hour requirement.

However, the full skills instructor applicant must request a variance in accordance with POST Rule 7, Variances, and the applicant may be required to appear in person before the appropriate subject matter expert committee to demonstrate skills instructional proficiency.

(E) The completed documents received at POST will be reviewed by POST in consultation with the appropriate subject matter expert committee during the committee’s next regularly scheduled meeting.

(F) POST will provide written notification to the academy director or the full skills instructor applicant who submitted the documents as to whether the applicant was approved or denied approval as a full skills instructor.

d) Lead skills instructors.

(I) A lead skills instructor is a full skills instructor who may be designated by the academy director to oversee or coordinate the administration of a specific skills program of a particular academy class.

(II) Lead skills instructors require no additional approval by POST beyond approval as a full skills instructor.

(III) POST will review certificates of completion and/or documentation for lead skills instructors only as such documentation pertains to approval as a full skills instructor.

e) Any applicant denied approval under section (b) or (c) of this Rule may appeal such denial in writing to the Director within ten days of notification of denial.

Rule 24 – Skills Training Safety and Skills Program Requirements for Basic and Reserve Academies (a) For ALL skills training programs: arrest control, law enforcement driving and firearms (I) A daily schedule is required.

(A) The daily schedule shall be in addition to the lesson plan requirement of Rule 21, Basic and Reserve Training Academies.

(B) The daily schedule shall contain the information described in each of the skills training programs: Arrest Control Training Program, Law Enforcement Driving Program, and Firearms Training Program.

(C) The format, number of pages and organization of information on the daily schedule(s) shall be at the discretion of the primary skills instructor and/or academy director.

(II) Written daily attendance records are required.

(A) Written attendance records for all dates of skills training shall be maintained for all trainees enrolled in the skills training program AND for all skills instructors who teach any portion of the skills training program; and (B) Attendance records shall be accurate and up-to-date and must be available during POST inspections of the skills program in progress.

(III) Site safety plans are required.

(A) Each site of skills training must have an up-to-date and approved written site safety plan present on site during any academy training at the site; and (B) All academy staff members, instructors and trainees shall be familiar with the content of each site safety plan as it pertains to the nature and scope of their involvement with the academy.

(IV) For all hours of all skills training programs, 100% attendance and participation are mandatory.

(V) There must be at least one full skills instructor present at the site of instruction for each skills training session, excluding lecture-only sessions conducted in a classroom setting.

(VI) Successful completion is required.

(A) For the Arrest Control Training Program and the Law Enforcement Driving Program, the minimum requirement for successful completion is seventy percent (70%); and (1) Each academy may apply a higher standard for successful completion of any portion of the skills training program that is greater than seventy percent (70%); and (2) If such a higher standard is applied, the higher standard must be described in the respective skills lesson plan and in the Trainee Manual.

(B) For the Firearms Training Program, the mandatory requirement for successful completion of the Handgun Qualification Course is to fire the course exactly as prescribed in the Firearms Training Program with all rounds being on the silhouette.

(b) Arrest control training (I) There must be at least one arrest control instructor for every ten (10) trainees (i.e., 1:10 ratio) during any practicum or lab session.

(II) No practicum or lab session may exceed eight (8) hours in any one-day.

(III) Mats or mat coverings must be serviceable and cleaned on a regular basis and immediately before use with an appropriate cleansing agent and/or disinfectant.

(IV) Only those arrest control disciplines that have been reviewed and approved as recognized disciplines for arrest control training are acceptable instruction for the Arrest Control Training Program.

(V) Each academy shall ensure that all arrest control instructors maintain current certification for the academy’s arrest control discipline in accordance with the standards for recertification, if any, of the recognized discipline for arrest control training.

(VI) All trainees must successfully complete a skills test out and written examination in accordance with the discipline being taught. If the program does not have a test out, then each trainee at a minimum must successfully complete the arrest control skills test as used in the POST provisional/renewal of certification process.

(VII) All academy Arrest Control Training programs must be comprised of at least 60% lab hours. Lab hours are defined as any hands-on skills training.

(VIII) Operable firearms, as defined in POST Rule 1, shall not be utilized during any arrest control training.

(c) Law enforcement driving training (I) There must be at least one driving track vehicle and one law enforcement driving instructor for every six (6) trainees (i.e., 1:6 ratio) during any instruction at the track.

(II) No track exercise and/or practicum may exceed twelve (12) hours in any 24-hour period.

(III) Academy directors shall ensure that no trainee be permitted to participate in a law enforcement driving program unless the trainee possesses a valid driver’s license.

(IV) There must be at least one (1) fully charged five (5) pound size or larger, dry chemical, Class ABC fire extinguisher on site during any instruction at the track.

(V) Prior to receiving any nighttime Law Enforcement Driving Program instruction at the track, each trainee shall receive a minimum of twelve (12) hours of daylight driving instruction at the track.

(VI) Night driving shall start no earlier than thirty (30) minutes prior to sunset.

(VII) Operable firearms, as defined in POST Rule 1, shall not be utilized during any law enforcement driving training.

(d) Firearms training (I) There must be at least one firearms instructor for every four (4) trainees enrolled in the academy program (i.e., 1:4 ratio) anytime a trainee is handling an operable firearm, whether loaded or unloaded, at any location, including in the classroom and at the range, except as noted in the following paragraph (III). This 1:4 instructor to trainee ratio shall not include the instructor running the range exercise. For live fire tactical exercises, drills, and dim light shooting that requires movement, the instructor to trainee ratio shall be 1:4 with an emphasis on the four (4) rules of firearms safety.

(II) No range exercise and/or lab session may exceed eight (8) hours in any one day.

(III) For all decisional shooting scenarios, there must be an instructor to trainee ratio of 1:1.

(IV) Only POST approved firearms instructors and not agency trained safety officers may be utilized to satisfy the minimum ratios of firearms instructors to trainees.

(V) Prior to receiving any dim light firearms instruction at the range, each trainee shall receive a minimum of forty (40) hours of Firearms Training Program instruction, to include at least eight (8) hours of classroom lecture and thirty-two (32) hours of daylight live range instruction.

(VI) Dim light live-fire shooting shall start no earlier than thirty (30) minutes prior to sunset.

Indoor ranges are exempt from sunset requirement.

(VII) Only high-visibility, fluorescent colored “dummy” ammunition may be used for any weapons handling other than actual live fire shooting.

(VIII) Trainees must be provided written and oral reminders over the course of the training of the four (4) rules of firearms safety:

(A) All weapons must be treated as if they are always loaded; and (B) Never let the muzzle of a weapon point at anything you are not willing to destroy;

(C) Keep your finger off the trigger and out of the trigger guard until the sights are on the target and you are prepared to shoot; and (D) Always be certain of the target and beyond.

(IX) All trainees must be familiar with the four (4) rules of firearms safety prior to handling any operable firearm.

(X) Firearms ranges must display some type of visual notification (range flag, signs, lights, or other) whenever the range is being utilized for live fire.

(XI) Each trainee must fire the minimum number of live rounds of handgun ammunition in a single weapons system, revolver or semi-automatic, as stipulated in the current POST firearms training program, before completing the program.

(XII) Each academy shall ensure that all firearms instructors meet current minimum requirements for full and assistant skills instructors in accordance with POST Rule 23.

Rule 25 – Academy Instructor Training Programs (a) Only the following Colorado POST academy instructor training programs (Instructor Program/s) shall be recognized under this Rule:

(I) Instruction Methodology Program;

(II) Arrest Control Instructor Program;

(III) Handgun Instructor Program;

(IV) Law Enforcement Driving Instructor Program;

(V) Red dot sight instructor program.

(b) Each scheduled training class of a recognized Instructor Program must:

(I) Contain a minimum of forty (40) hours of instruction; and (II) Be approved prior to the start of instruction.

(c) Continuing Instructor Programs (I) A continuing Instructor Program is one that has been approved, conducts and completes at least one approved training class every five (5) years and operates in compliance with this Rule. If a continuing program does not complete at least one approved training class in any consecutive five (5) year period, approval of the program shall expire. An expired program must be submitted to POST for approval as a new program and be approved prior to providing any instruction.

(II) The program director must ensure that the following documents are received at POST at least thirty (30) days but no more than sixty (60) days prior to the start of instruction for each scheduled training class.

(A) A completed POST Form 8, Application for Academy Instructor Training Program Approval; and (B) If instruction will take place outside of normal weekday business hours, a schedule that accurately displays the dates and times when instruction will be conducted must be provided.

(III) The program director shall notify POST prior to the occurrence of any of the following:

(A) The program is cancelled for any reason; or (B) There is any change of the program’s start date or end date; or (C) There is any change of training site.

(d) New Instructor Programs (I) A new Instructor Program is a recognized program that has either never conducted approved training, or a previously approved program that has not conducted approved training within the previous five (5) years.

(II) The program director of a proposed new Instructor Program is advised to contact POST at least ninety (90) days prior to the anticipated start date to ascertain application procedures and deadlines for submitting the required documentation to POST for approval.

(III) Required documentation for a new Instructor Program may include, but is not limited to, the program’s lesson plan, instructor documents and site video.

(IV) The program director must also ensure that the documents listed in paragraph (c)(II) of this Rule are received at POST at least thirty (30) days but no more than sixty (60) days prior to the start of instruction.

(e) Lesson Plans (I) Each lesson plan of a recognized Instructor Program must include the following information, as applicable:

(A) Program provider’s name or agency; and (B) Program title as specified in the applicable POST Instructor Program; and (C) Most recent date the lesson plan was created or revised, and name(s) of the person(s) who created or revised it; and (D) Number of actual hours the program will be instructed, and the number of hours required by the POST Instructor Program; and (E) Learning goals, course objectives and/or performance outcomes; and (F) Instructional content of the course that substantiates the stated goals, objectives and/or performance outcomes meet the POST requirements; and (G) Testing and/or assessment methods utilized to measure the objectives and/or performance outcomes; and (H) A copy of any handouts, multimedia and/or PowerPoint presentations that will be used during the instruction.

(II) The program director shall ensure that each lesson plan is updated, as necessary, to confirm the content complies with current POST program requirements and POST Rules.

(III) The current lesson plan must be present at the site of instruction whenever training for the Instructor Program is being conducted.

(IV) If a provider seeks to utilize a substantially different lesson plan than the one initially approved, the lesson plan must be resubmitted to POST for approval.

(V) The program director shall ensure that all instructors who teach any portion of an Instructor Program for a particular provider utilize only the lesson plan specific to that provider.

(f) Attendance (I) For all hours of an approved Instructor Program for arrest control, handgun, or law enforcement driving, 100% attendance and participation are required.

(II) For Instruction Methodology Programs, enrollees are expected to attend and participate in all required hours of the approved program.

(g) Training Sites (I) Upon the effective date of this Rule, only POST approved sites shall be utilized to conduct any practical skills training of the Instructor Programs for arrest control, handgun, or law enforcement driving.

(II) Sites for lecture portions of the skills Instructor Programs as well as sites for Instruction Methodology Programs do not require POST approval. However, such sites must be safe and appropriate for the nature and scope of lecture provided.

(III) Sites that are currently approved for skills training at POST approved Basic, Reserve or Refresher academies may be utilized for conducting the same nature of practical skills training for Instructor Programs.

(IV) The program director is responsible for confirming with POST that all of its sites for practical skills training are currently approved.

(V) If an approved site is not utilized during any consecutive three (3) year period for the type of training for which the site was approved, site approval expires. Before training can resume at an expired site, the site must be submitted for approval and approved by POST in consultation with the appropriate Subject Matter Expert (SME) Committee.

(VI) To request approval of a new or expired site of practical skills training, the following items must be submitted to POST:

(A) Video in a digital media format approved by POST that accurately depicts the site where instruction is to take place; and (B) A detailed description of the site must be included, either as verbal narrative on the video or as a written supplement.

(VII) All sites are required to comply with the provisions of Rule 21(d).

(h) Duty to Report (I) The program director shall ensure that all instructors who teach any portion of an Instructor Program are familiar with this Section (h), Duty to report.

(II) In addition to any notifications that may be required administratively or under federal, state or local law, it shall be the duty of every program director or his designee to report the following events to POST as soon as practicable after the event:

(A) Any death, gunshot wound, serious bodily injury (SBI), diagnosed concussion, or any injury which caused a student’s departure from the course that was either caused by, or may have been caused by, any training or activity associated with the program; or (B) Any bodily injury that occurs to any person who is not affiliated with the program, i.e., an innocent bystander, whose bodily injury was either caused by, or may have been caused by, any training or activity associated with the program.

(III) Training to Cease (A) In the event of any death or gunshot wound as described in paragraph (h)(II)(A) of this section, all training shall immediately cease at the training site where the death or gunshot wound occurred.

(B) Training may resume only after the Board or its designated representative(s) have ensured that the program is operating in compliance with POST Rules.

(IV) Serious bodily injury means those injuries as defined in §18-1- 901(3)(p), C.R.S.

(V) Bodily injury means those injuries as defined in §18-1-901(3)(c), C.R.S.

(i) Instructors (I) For new Instructor Programs, all instructors shall be approved by POST in accordance with the minimum instructor qualifications identified in the applicable Instructor Program.

(II) For continuing Instructor Programs, the program director shall ensure that all instructors who instruct any portion of the program meet the minimum instructor qualifications identified in the applicable Instructor Program.

(j) Certificates of Completion (I) The program director shall issue a certificate of completion to each individual who successfully completes all requirements of the approved Instructor Program.

(II) Each certificate of completion shall contain at least the following information:

(A) The exact name of the Instructor Program as it appears in Section (a) of this

Rule; and (B) The exact words “POST Approved”; and (C) Name of the individual who completed the program; and (D) Program provider’s name or agency; and (E) Dates of the program; and (F) Total number of hours of the completed program; and (G) Signature of the program director and/or agency or academic representative; and (H) Arrest control Instructor Program certificates of completion shall also contain the name of the arrest control discipline.

(k) POST Grant Funds (I) In order to be eligible to receive POST grant funds for an Instructor Program, the program must comply with the current “Peace Officer Standards and Training Law Enforcement Continuing Education Program Guidelines for Colorado POST Award Recipients” (i.e., Grant Guidelines).

(II) For purposes of this Rule, current Grant Guidelines are considered to be those in effect on the start date of the program.

Rule 26 – Academy and Academy Instructor Training Program Inspections (a) Members of the Board, or its designated representative(s) may at any reasonable time inspect any approved academy or academy Instructor Training Program (Instructor Program), or any Academy or Instructor Program believed to be operating contrary to these Rules.

(b) An academy or Instructor Program inspection may include, but is not limited to, a review of any records required to be maintained under these Rules, examination of the academy’s facilities, training sites, and equipment, observation of classroom instruction and skills training, and interviews with trainees, staff and instructors.

(c) Training that is not required by POST but is incorporated within the approved academy or Instructor Program may be inspected to the extent necessary to ensure it is legitimate (i.e., in accordance with established or accepted patterns and standards) and safe (i.e., secure from danger, harm or injury).

(d) The POST Director or the Director’s designee shall be informed of all inspection results.

(e) Should the POST Director or the Director’s designee determine, in consultation with the appropriate Subject Matter Expert committee(s), as applicable, that an academy or Instructor Program is not in compliance with POST Rules or is providing training that is not legitimate or safe, he/she shall notify the academy director or program director in writing of the specific deficiencies or findings and order remedial action.

(f) The academy director or program director may appeal the POST Director’s, or their designee’s, order to the Board within thirty (30) days in accordance with Rule 5(d).

(g) Failure to comply with the POST Director’s, or their designee’s, order shall result in the immediate suspension of the academy or Instructor Program, pending review by the Board at its next regular

Rule 27 – Retired Law Enforcement Officer Authority to Carry Concealed Firearms Repealed February 7, 2014

Rule 28 – In-Service Training Program The purpose of in-service training is to provide continuing education to certified peace officers to develop their knowledge and/or skills. The POST Board’s duties relating to annual in-service training are addressed in Colorado Revised Statutes § 24-31-303(1). The POST Board can “promulgate rules deemed necessary by the Board concerning annual in-service training requirements for certified peace officers, including but not limited to evaluation of the training program and processes to ensure substantial compliance by law enforcement agencies and departments.” In-service training is mandatory for all certified peace officers who are currently employed. This includes certified fulltime, part-time and reserve peace officers. Failure to satisfactorily complete training may result in suspension or revocation of an individual’s POST certification, or other administrative sanction in accordance with Rule 31.

a) Annual Hour Requirement The in-service training program requires certified peace officers to complete a minimum of 24 hours of in-service training annually. Of the 24 hours, a minimum of 12 hours shall be perishable skills training as specified below.

b) Training Period (I) The training period shall be the calendar year, from January 1 to December 31, of each year. In-service training in excess of 24 hours each year shall not be credited towards any future or prior training period.

(II) Remedial training hours completed after January 1 to gain compliance for a prior calendar year shall not count towards the current year requirement.

c) Approved Training for POST Credit The authority and responsibility for training shall be with the chief executive of each law enforcement agency. The chief executive accepts responsibility and liability for the course content and instructor qualification. Legislatively mandated training may also be used for credit towards the training requirement.

The following are examples of training that would qualify for in-service credit:

(I) Training received during the Basic Academic Training Program (Basic Academy).

(II) Computer or web-based courses that have been approved by the chief executive may be used for in-service credit.

(III) The viewing of law enforcement related audiovisual material (DVD, video, etc.) or material related to the viewer’s position or rank can be used in conjunction with a facilitated discussion or other presentation. This could include roll call or lineup briefings where the session is dedicated to training and not for the purpose of information exchange.

(IV) For each class hour attended at an accredited college or university in any course related to law enforcement or criminal justice that is required to earn a degree, one hour of inservice credit may be awarded.

d) Perishable Skills Training Perishable skills training shall consist of a minimum of 12 hours. The required 12 hours must include a minimum of one hour of training in each of the three perishable skills (Arrest Control, Driving, and Firearms) each calendar year. Examples of perishable skills training could include:

(I) Arrest Control-live or simulator exercises and scenarios, classroom discussion followed by interactive scenario events. Arrest control fundamentals, agency policies and/or legal issues.

(II) Driving-behind-the-wheel or simulator training, classroom discussion regarding judgment/decision making in driving, agency policies and/or legal issues.

(III) Firearms-live or simulator exercises and scenarios, firearms fundamentals, use of force training or discussions, classroom training requiring student interaction and/or decision making, classroom discussion on agency policies and/or legal issue. Firearms qualification alone is insufficient to meet this mandate.

e) Agency Maintenance of Training Records The chief executive of each agency is responsible for the true, accurate and verifiable entry of training records into the POST database.

Agencies are encouraged to enter training as it occurs, but shall enter training no later than the end of each calendar year for the certified peace officers employed at any time during that year, regardless of current employment status. This information shall be entered into the POST database. For in-person courses, agencies are required to keep records of sign-in sheets, topics covered, and lesson plans (if they exist).

(I) Waiver of In-Service Requirements All certified peace officers shall meet the minimum annual hours. However, under the circumstances listed below, an agency may request a waiver for a portion of the annual in-service training requirement. Any waiver of the annual training request must be made in writing to the POST Director or their designee by January 31st of the following year.

(A) Perishable Skills Waiver Agency executives may request an exemption from the perishable skills training requirement. This request shall be in writing to the POST Director or their designee. This request shall state that either their certified peace officers do not carry firearms, or they infrequently interact with or effect physical arrests, or they do not utilize marked or unmarked emergency vehicles as part of their normal duties.

(B) Partial Year Employment Waiver The 24 hours of in-service training is required if a certified peace officer is employed for the entire calendar year. Certified peace officers who are employed after the start of the calendar year only need to complete a prorated number of training hours. Therefore, two hours of training per month, with a minimum of one hour of perishable skills training shall be required. (Example: If a certified peace officer is hired in July, 12 hours of training with a minimum of six hours of perishable skills training must be completed for that calendar year).

(C) Long Term Disability, Medical Leave or Restricted Duty If a certified peace officer is unable to complete the in-service annual hours due to long term disability, medical leave or restricted duty, the agency must obtain a letter from a physician stating that participation in any type of training including audiovisual or online training would be detrimental to the officer’s health. The letter should define the time that the officer is unable to attend any training.

Those granted a waiver will be on a prorated basis for the time stated in the physician’s letter. The agency does not need to forward the physician’s letter to POST but only reference it in a waiver request.

(D) Military Leave Those certified peace officers deployed in military service only need to complete a prorated number of training hours.

(E) Administrative Leave If a certified peace officer is unable to complete the in-service annual hours due to placement on administrative leave, the officer must complete a prorated number of training hours.

(II) Compliance (A) Agencies and individual peace officers shall comply with the in-service training requirements.

  1. Agencies a) POST will send out a preliminary compliance report following each training period. The report will provide the compliance status of each agency and its certified peace officers. Agencies shall have thirty (30) days from the date of the preliminary report to dispute the POST data and provide additional training information. Following the thirty-day period, POST will distribute the final compliance reports to all agencies.

b) POST may declare an agency noncompliant after the final compliance report has been issued if new information is discovered.

c) Once the final compliance report has been sent to all agencies; an agency seeking to appeal the POST data must do so within thirty (30) days of being notified of failure to comply with Rule 28.

Agencies may appeal this by following the process outlined in

Rule 5, Hearings. Upon conclusion of all appeal hearings POST will issue a final report indicating whether the agency was found in compliance.

d) If POST finds that the agency failed to comply, such finding shall constitute a basis for the Board to impose an administrative sanction pursuant to Rule 31.

  1. Individual peace officers a) POST will send out a preliminary compliance report following each training period. The report will provide an individual peace officer’s compliance status. Individuals shall have thirty (30) days from the date of the preliminary report to dispute the POST data and/or complete the training requirements.

b) Individual peace officers failing to satisfactorily complete the training requirements within the 30 day period may have their POST certification suspended by the POST Director pursuant to

Rule 3, until such time as they come into compliance. If an individual peace officer is suspended, the peace officer may appeal the suspension within thirty (30) days, as provided in rule 5(d).

c) Failure to satisfactorily complete POST training requirements may result in a recommendation by the Director or their designee to the Board for revocation of the individual’s POST certification, or other administrative sanction pursuant to Rule 31.

(III) The POST Board shall evaluate the program annually following the release of the final compliance reports. Such evaluation will include a review and evaluation of the program.

The evaluation may be based on the compliance rate, agency survey and other performance metrics.

Rule 29 - Hiring Standards Effective November 1, 2022 Each agency hiring a Basic certified peace officer, Provisionally certified peace officer, or Reserve certified peace officer should first ensure that they meet the POST minimum standards of employment:

a) Individuals must hold current Basic, Provisional or Reserve certification in the state of Colorado.

Hiring agency will confirm certification with POST or utilize this weblink https://post.coag.gov/s/ to verify current POST certifications.

b) Each agency should complete a comprehensive agency background investigation, which may include:

(I) Criminal record checks - local, state, and national;

(II) Employment history checks;

(III) Driving record check;

(IV) Polygraph;

(V) Citizenship or legal residency verification;

(VI) Personal history statements;

(VII) Neighborhood checks;

(VIII) Relatives/personal references checks;

(IX) Credit records check;

(X) Any other investigative measures that the agency finds appropriate.

c) Employment in the state of Colorado as a Basic peace officer, Provisional peace officer, or Reserve peace officer as defined in § 16-2.5-102, § 24-31- 308 and § 16-2.5-110, C.R.S. requires completion of a physical and psychological evaluation within one year prior to the date of appointment.

(I) Physical and psychological evaluations completed for non-certified peace officer positions remain valid for an employee who transfers to a post-certified position at the same organization.

d) Any person renewing their Colorado Basic certification must complete a physical and psychological evaluation within one year prior to the date of appointment.

e) The physical and psychological evaluation affirmation must be submitted to POST.

f) Any person separating from one agency and appointed by another agency must complete a physical and psychological evaluation if one has not been conducted within the preceding three years and made available to the receiving agency.

g) Any person separated from an agency and returning to the same agency within six months does not need a new physical and psychological evaluation.

h) Each agency shall comply with the requirements for physical and psychological evaluations pursuant to § 24-31-303(5), C.R.S.

Rule 30 – Peace Officer Continuing Education Grant Training Program POST funding was created under the authority of SB 03-103 and defined in § 24-31-303 (2) (B) & (3), C.R.S.; § 24-31-310, C.R.S.; and § 42-3-304 (24), C.R.S. for the training of Colorado Peace Officers through awards by the POST Board.

(A) The Grant Sub-Committee Board shall consist of eight members, appointed by the Chair of the Board from the POST Board. They may serve as members of the Grant Sub-Committee Board for one three (3) year term.

(B) Eligible applicants for a grant award are local governments, colleges, universities, or not for profit organizations providing peace officer training programs. State agencies are not eligible applicants, but may apply for funds through their training region.

(C) The Grant Guidelines is a Department of Law-Peace Officer Standards and Training (POST) policy document. Grant applicants and award recipients must adhere to the requirements in the Grant Guidelines, found at the POST website. The current Grant Guidelines are also available through POST staff.

(D) At the discretion of the Director or the Director’s designee, failure to adhere to the requirements in the grant guidelines shall constitute a basis for a reduction of future grant awards, or rescission of current grant awards.

Rule 31 – Administrative Sanctions (A) The authority for the promulgation of this rule by the Colorado POST Board is set forth in §§ 24- 31-303(1)(l), 24-31-303(1)(m), and 24-31-307(1) and (3), C.R.S.

(B) The purpose of this rule is to provide for the assessment of administrative fines or other sanctions by the Attorney General for violations of Title 24, Article 31, Part 3.

(C) The Attorney General, or the Attorney General’s designee, may impose an administrative fine or other sanction against a certificate holder, law enforcement agency, or both as prescribed in this

Rule 31. The imposition of an administrative fine does not preclude the Attorney General, or Attorney General’s designee, from also pursuing other lawful enforcement actions against the certificate holder, law enforcement agency, or both, consistent with § 24-31-307.

(D) The administrative fine or other sanctions assessed shall be reasonably based on the following criteria:

(I) Type of violation;

(II) Severity of the violation;

(III) Repetition of violations; and (IV) Any other mitigating or aggravating circumstances.

(E) Fine amounts.

(I) For failure to successfully comply with In-Service Training requirements by a law enforcement agency, individual certificate holder, or both:

(a) For a first offense, a violator may be fined up to $100 per employed peace officer for law enforcement agencies, or up to $300 per individual certificate holder, as applicable; and (b) For a second or subsequent offense, a violator may be fined up to $200 per employed peace officer for law enforcement agencies, or up to $600 per individual certificate holder, as applicable.

(II) For failure to successfully comply with Rule 17 requirements by an agency:

(a) For a first offense, a violator may be fined up to $100 per employed peace officer, for each day in violation; and (b) For a second or subsequent offense, a violator may be fined up to $200 per employed peace officer, for each day in violation.

(III) For public release of protected documents described in § 24-31-321, C.R.S., by anyone other than the reporting organization, the releasing party may be fined up to $10,000 per occurrence.

(IV) For knowingly or willfully submitting false or inaccurate information for inclusion in the peace officer database as described in Rule 32:

(a) For a first offense, the agency head may be fined up to $5,000.

(b) For a second offense, the agency head may be fined up to $10,000.

(V) For any other violation of a POST Board rule requiring compliance by a law enforcement agency or individual certificate holder:

(a) For a first offense, a violator may be fined up to $100 per employed peace officer for law enforcement agencies for each day in violation, or up to $300 per individual certificate holder, as applicable; and (b) For a second or subsequent offense, a violator may be fined up to $200 per employed peace officer for law enforcement agencies for each day in violation, or up to $600 per individual certificate holder, as applicable.

(F) Any fine assessed pursuant to this Rule 31 to law enforcement agencies may be deducted from POST Training Grant-related awards.

(G) Failure to disclose an applicant’s files, including internal affairs files, to the requesting hiring agency within six days after being contacted by POST, pursuant to § 24-33.5-115, C.R.S., shall result in the loss of POST board funding for a period of one year or the imposition of fines by the Attorney General, or both.

(I) Assessment of fees or the implementation of other barriers to the release of an applicant’s files may be determined by the Director, or the Director’s designee, to constitute a failure to disclose the files subject to administrative sanctions pursuant to this

Rule 31.

(H) In addition to fines prescribed pursuant to this Rule 31, the following additional penalties may be prescribed at the Attorney General’s, or Attorney General’s designee’s, discretion:

(I) Suspension from POST grant funding or activities;

(II) Suspension or revocation of a certificate holder’s certification; or (III) Imposition of other fines, administrative sanctions, or both.

(I) Upon receipt of notice of fines from the POST Board Director, the agency or peace officer receiving the fine must remit payment within 60 days. Failure to timely comply with fines or other administrative sanctions is a violation of a Board Order and of this Rule.

(J) Fine revenue collected pursuant to this Rule 31 shall be credited to the POST Board cash fund.

(K) All implementation of this Rule shall be in accordance with processes stated in Rule 5.

RULE 32 - POST Database (a) Per §§ 24-31-303(1)(r) and 24-31-321, C.R.S., POST will maintain a database that contains information related to any of the following actions by a peace officer:

(I) Untruthfulness;

(II) Three or more failures to follow POST Board training requirements within ten (10) consecutive years;

(III) Revocation of a POST certification, including the basis of the revocation;

(IV) Termination for cause by the peace officer’s employer;

(V) Resignation or retirement while under investigation by the peace officer’s employing organization or another law enforcement agency in which the alleged misconduct, if sustained, would more likely than not result in being entered into the database;

(VI) Resignation or retirement following an incident that leads to the opening of an investigation by the peace officer’s employing organization or another law enforcement agency in which the alleged misconduct, if sustained, would more likely than not result in being entered into the database, within six months after the peace officer’s resignation or retirement;

(VII) Being charged with a crime that could result in revocation or suspension of certification pursuant to section 24-31-305 or 24-31-904, C.R.S.; and (VIII) Actions described by the applicable statutory provision identifying the basis for a credibility disclosure notification as set forth in section 16- 2.5-502(2)(c)(I), C.R.S.

(A) Knowingly made an untruthful statement concerning a material fact, knowingly omitted a material fact in an official criminal justice record, or knowingly omitted a material fact while testifying under oath or during an internal affairs investigation or administrative investigation and disciplinary process;

(B) Demonstrated a bias based on race, religion, ethnicity, gender, sexual orientation, age, disability, national origin, or any other protected class;

(C) Tampered with or fabricated evidence; or (D) Been convicted of any crime involving dishonesty, been charged in a criminal proceeding with any felony or any crime involving dishonesty, or violated any policy of the law enforcement agency regarding dishonesty.

(IV) Resignation in lieu of termination for cause, where a peace officer voluntarily separated from an employing law enforcement agency when the peace officer knew, or reasonably should have known, they were likely to be terminated for intentional wrongdoing or misconduct.

(b) A peace officer’s employer or former employer may report incidents to POST for a database entry.

(c) POST may make database entries on behalf of an organization when POST has a reasonable belief that an entry is required by statute or POST rule.

(d) The agency executive shall certify the accuracy of the information reported to POST for use on the database.

(e) Knowingly or willfully failing to submit the required information or certification, or submittal of false or inaccurate information, may result in administrative sanctions pursuant to Rule 31, and shall be referred to the appropriate district attorney for a criminal investigation.

(f) Employers shall provide POST with documents relevant for a database entry upon request, whether the employer submitted a report for a database entry or if POST receives information regarding a peace officer that would require a report.

(g) POST may subpoena records related to database reports, if the employing organization does not provide the records upon request. POST may seek attorney fees and costs for the issuance of the subpoena, when deemed appropriate.

(h) Records submitted to POST pursuant to § 24-31-321, C.R.S., remain the property of the employing organization and are not subject to public release.

(i) A peace officer may seek review of the peace officer’s status in the database with presentation of new evidence related to the entry. To have POST review the entry, the peace officer shall comply with Rule 7.

(I) POST shall give consideration to a peace officers whistleblower status, as defined in

Rule 1, during an appeal process related to their inclusion on the database.

(II) The final employing agency determination, including any internal appeals, will be used in deciding any appeal request to be removed from the database.

(j) Once a peace officer no longer meets the statutory requirements for inclusion on the database, POST will remove the peace officer from the database without a request for a variance.

(k) POST shall remove database entries upon notice from the reporting agency, after determining the entry was made in error. POST may request additional documentation regarding the database entry to verify the report was made in error.

Rule 33 - Administrative Hearing Procedures (a) This Rule 33 is intended to apply only to administrative hearings for revocation or suspension that are filed before the POST Hearing Officer for disqualifying incidents other than criminal convictions. This Rule does not apply to Show Cause Hearings before the Director for disqualifying criminal convictions.

(b) Rules of Civil Procedure. To the extent practicable, and unless inconsistent with these rules, the Colorado Rules of Civil Procedure apply to matters before the POST Hearing Officer. Unless the context otherwise requires, whenever the word “court” appears in a rule of civil procedure, that word shall be construed to mean the POST Hearing Officer. The following do not apply: C.R.C.P. 16 and 16.1.

(c) Rules of Evidence. To the extent practicable, the Colorado Rules of Evidence apply in all hearings conducted by the POST Hearing Officer. Unless the context requires otherwise, whenever the word “court”, “judge”, or “jury” appears in the Colorado Rules of Evidence, such word shall be construed to mean the POST Hearing Officer. The POST Hearing Officer has the discretion to admit evidence not admissible under such rules, as permitted by § 24-4-105(7), C.R.S., or other law.

(d) Entry of Appearance and Withdrawal of Counsel. Entries of Appearance and Withdrawals of Counsel shall be in conformance with C.R.C.P. 121 § 1-1. Any out-of-state attorney shall comply with C.R.C.P. 221.1.

(e) Expanded Media Coverage. Expanded media coverage of cases before the POST Hearing Officer may be permitted at the discretion of the POST Hearing Officer, under such conditions as the POST Hearing Officer may designate. In determining whether expanded media coverage should be permitted, the POST Hearing Officer shall consider the following factors:

(I) Whether there is a reasonable likelihood that expanded media coverage would interfere with the rights of the parties to a fair hearing;

(II) Whether there is a reasonable likelihood that expanded media coverage would unduly detract from the solemnity, decorum and dignity of the proceedings;

(III) Whether expanded media coverage would create adverse effects that would be greater than those caused by traditional media coverage.

(f) Default Procedures. A person who receives notice of an agency adjudicatory hearing is required to file a written answer within 30 days after the service or mailing of notice of the proceeding. If a person receiving such notice fails to file an answer, the POST Hearing Officer may enter a default against that person pursuant to § 24-4-105(2)(b), C.R.S.

(I) The POST Hearing Officer will not grant a motion for entry of a default under this statutory provision unless the following requirements are met:

(A) The motion for entry of a default must be served upon all parties to the proceeding, including the person against whom a default is sought.

(B) The motion shall be accompanied by an affidavit establishing that both the notice of the proceeding and the motion for entry of default have been personally served upon the person against whom a default is sought, or have been mailed by first class mail to the last address furnished to the agency by the person against whom the default is sought.

(g) Discovery. To the extent practicable, C.R.C.P. 26 through 37 and 121, Section 1-12 and the duty to confer at Section 1-15(8) apply to proceedings within the scope of these rules, except to the extent that they provide for or relate to required disclosures, or the time when discovery can be initiated. Discovery may be conducted by any party without authorization of the POST Hearing Officer.

(I) In addition to the requirements of C.R.C.P. 36, a request for admission shall explicitly advise the party from whom an admission is requested that failure to timely respond to the request may result in all of the matters stated in the request being deemed established unless the POST Hearing Officer on motion permits withdrawal or amendment of the admission. The failure to comply with this rule may result in the matters contained in the request being deemed denied.

(II) Discovery requests and responses should not be filed with the POST Hearing Officer, except to the extent necessary for the POST Hearing Officer to rule upon motions involving discovery disputes.

(III) Either party may move to modify discovery deadlines and limitations.

(h) Determination of Motions. The duty to confer pursuant to C.R.C.P. 121 § 1-15(8) shall apply to all motions filed within the scope of these rules. Any motion involving a contested issue of law shall be supported by a recitation of legal authority. References to agency rules shall include the appropriate Colorado Code of Regulations citation. A responding party shall have 21 days from service or such lesser or greater time as the POST Hearing Officer may allow in which to file and serve a responsive brief. Reply briefs will be permitted only upon order of the POST Hearing Officer. If so ordered, the reply brief must be filed within 7 days of the order of the POST Hearing Officer.

(I) If facts not appearing of record before the POST Hearing Officer are to be considered in disposition of the motion, the parties may file affidavits at the time of filing the motion or responsive or reply brief. Copies of such affidavits and any documentary evidence used in connection with the motion shall be served on all other parties.

(II) If the moving party fails to incorporate legal authority into the motion and fails to file a separate brief with the motion, the POST Hearing Officer may deem the motion abandoned and may enter an order denying the motion. Failure of the responding party to file a responsive brief may be considered a confession of the motion.

(III) If possible, motions will be determined upon the written motion and briefs submitted. The POST Hearing Officer may order oral argument or evidentiary hearing on the POST Hearing Officer’s own motion or on request of a party. If any party fails to appear at an oral argument or hearing without prior showing of good cause for non-appearance, the POST Hearing Officer may proceed to hear and rule on the motion.

(i) Place of Hearing. Hearings conducted within the scope of these rules will be heard in the Ralph Carr Judicial Building. The POST Hearing Officer will make arrangements to reserve a room when necessary. The POST Hearing Officer may change the place of hearing when the convenience of witnesses and parties and the ends of justice will be served, including holding hearings virtually or telephonically.

(j) Prehearing Procedures, Statements and Conferences. Unless otherwise ordered by the POST Hearing Officer, each party shall file with the POST Hearing Officer and serve on each other party a prehearing statement in substantial compliance with the form available on the POST website.

Prehearing statements shall be filed and served no later than 30 days prior to the date set for hearing or such other date established by the POST Hearing Officer. Exhibits shall not be filed with prehearing statements, unless ordered by the POST Hearing Officer. Exhibits shall be exchanged between the parties by the date on which prehearing statements are to be filed and served on such other date as ordered by the POST Hearing Officer.

(I) The authenticity of exhibits, statutes, ordinances, regulations or standards set forth in the prehearing statement shall be admitted unless objected to in a written objection filed with the POST Hearing Officer and served on other parties no later than 10 days prior to hearing.

(II) The information provided in a prehearing statement shall be binding on each party throughout the course of the hearing unless modified to prevent manifest injustice. New witnesses or exhibits may be added only if the need to do so was not reasonably foreseeable at the time of filing of the prehearing statement and then only if it would not prejudice other parties or necessitate a delay of the hearing. An agency shall use numbers to identify exhibits and any opposing party shall use letters.

(III) In the event of noncompliance with this rule, the POST Hearing Officer may impose appropriate sanctions including, but not limited to, the striking of witnesses, exhibits, claims and defenses.

(IV) Prehearing conferences may be held at the request of either party or upon motion of the POST Hearing Officer.

(V) A case management conference shall be held at the request of either party or at the discretion of the POST Hearing Officer. The party requesting the case management conference shall confer with all other parties as necessary upon the content of the proposed case management order. An example of a format for a case management order appears on the “Forms” tab of the POST website. The party requesting the case management conference shall submit the proposed case management order to the POST Hearing Officer no later than 3 days before the case management conference.

(k) Motions for Continuance. Continuances shall be granted only upon a showing of good cause.

Motions for continuance must be filed in a timely manner. Stipulations for a continuance shall not be effective unless and until approved by the POST Hearing Officer.

(l) Subpoenas. Upon oral or written request of any party or of counsel for any party, the POST Hearing Officer shall sign a subpoena or subpoena duces tecum requiring the attendance of a witness or the production of documentary evidence, or both, at a deposition or hearing. Unless otherwise provided by agency statute, rule or regulation, practice before the POST Hearing Officer regarding subpoenas shall be governed by C.R.C.P. 45.

(I) Any attorney representing a party to a proceeding before the POST Hearing Officer may issue a subpoena or subpoena duces tecum requiring the attendance of a witness or the production of documentary evidence, or both, at a deposition or hearing.

(m) Settlements. Parties shall promptly notify the POST Hearing Officer of all settlements, stipulations, agency orders or any other action eliminating the need for a hearing. POST shall file a motion to dismiss when a case has settled.

(n) Ex Parte Communications. With the exception of scheduling or other purely administrative matters, a party or counsel for a party shall not initiate any communication with the POST Hearing Officer pertaining to a matter before the POST Hearing Officer unless prior consent of all other parties or their counsel has been obtained. Copies of all pleadings or correspondence filed with the POST Hearing Officer or directed to the POST Hearing Officer by any party shall be served upon all other parties or their counsel.

(o) Procedure for expedited hearings. The POST Hearing Officer may, in their discretion, adjust deadlines and court dates to meet any specific statutory deadlines for revocation or suspension, when applicable.

(p) Computation and Modification of Time. In computing any period of time prescribed or allowed by these rules, the provisions of C.R.C.P. 6 shall apply. The time periods of these rules may be modified at the discretion of the POST Hearing Officer.

(q) Filing of Pleadings and Other Papers. Pleadings and other papers must be filed with the POST Hearing Officer by email at: posthearingofficer@coag.gov.

(I) All pleadings and papers filed with the POST Hearing Officer shall contain the case number assigned by POST at the time of referral.

(r) Service of Pleadings and Other Papers. Service of pleadings or other papers on a party or on an attorney representing a party may be made by hand delivery, by mail to the address given in the pleadings, by facsimile transmission to a facsimile number given in the pleadings, or to the party’s last known address, or with agreement of the parties, by e-mail. When a party is represented by an attorney, service shall be made on the attorney.

(I) Pleadings or other papers sent to the POST Hearing Officer must contain a certificate of service attesting to service on the opposing party and in the case of service by mail providing the address where pleadings or other papers were served.

(II) Attorneys and parties not represented by attorneys must inform the POST Hearing Officer and all other parties of their current address and of any change of address during the course of the proceedings.

(s) Testimony by Telephone or Other Electronic Means. Upon motion of any party the POST Hearing Officer may conduct all or part of a hearing virtually or telephonically. The motion must be filed sufficiently prior to hearing to permit a response and ruling.

(I) All arrangements for the taking of testimony by telephone or videophone shall be made by the party requesting such testimony, who shall be responsible for all costs associated with the testimony.

(II) Exhibits and other documents that will be used or referred to during all or part of a hearing conducted by telephone or other electronic means must be filed with the POST Hearing Officer and, unless previously supplied, provided to all other parties at least two days before the hearing.

(t) Court Reporters. The POST Hearing Officer will not supply court reporters. If any party wishes to have all or a portion of a proceeding transcribed by a court reporter, that party may make private arrangements to do so at that party’s own expense.

(I) All POST hearings will be, at minimum, audio recorded. The recording will be made available to any party upon request.

(u) Exhibit Notebooks. Whenever a party is represented by an attorney, that party shall supply an exhibit list and three notebooks of tabbed exhibits at the commencement of every merits hearing.

The notebooks shall be for the POST Hearing Officer, the opposing party, and the testifying witness. All documentary exhibits listed in such party’s prehearing statement, unless they are too lengthy, shall appear in the exhibit notebooks. _________________________________________________________________________ Editor’s Notes

History Rules 1, 10, 12, 17, 24 eff. 03/01/2008.

Rules 21, 23, 24 eff. 03/01/2009.

Rules 10, 21 eff. 03/01/2010.

Rules 1, 23, 24 eff. 07/01/2010.

Rules 19, 21, 23-25 eff. 02/01/2011.

Rule 27 eff. 07/30/2011.

Rules 10-12, 15, 17, 23 eff. 01/01/2012.

Rules 1, 10, 15, 18 emer. rules eff. 08/08/2012.

Rules 1, 10, 15, 18 eff. 12/01/2012.

Rule 10 eff. 02/01/2013.

Rules 1,15, 20 eff. 11/15/2013.

Rules 1, 11, 13 eff. 02/07/2014. Rule 27 repealed eff. 02/07/2014.

Rules 14, 17, 20, 21, 28 eff. 01/14/2015.

Rules 1, 4, 5, 7, 10-18, 24-26, 28, 29 eff. 01/31/2016.

Rules 7-18, 21 eff. 07/01/2017.

Rule 8 emer. rule eff. 12/01/2017; expired 03/31/2018.

Rule 28 eff. 01/01/2018.

Rules 1, 8, 9 eff. 04/30/2018.

Rules 11, 15, 16, 21, 24, 28 eff. 07/01/2018.

Rules 1, 8, 9, 10, 11, 12, 13, 14, 19, 24, 28 eff. 01/30/2019.

Rules 5, 9, 19 eff. 01/30/2020.

Rules 1-5, 7-11, 21, 28 eff. 11/15/2020.

Rules 1, 3, 5, 10, 12-20, 22, 28, 30 eff. 01/30/2021.

Rules 5, 8, 9, 17, 21, 28, 31 eff. 05/15/2021.

Rules 1, 5, 7, 9, 10, 17, 21, 32 eff. 11/15/2021.

Rule 1 eff. 01/30/2022.

Rules 5, 7 eff. 05/15/2022.

Rules 3, 10, 12, 14, 17, 21, 23, 28, 29 eff. 11/01/2022.

Rules 1, 3, 5, 7, 8, 11, 14, 15, 16, 21, 26, 28 eff. 01/30/2023.

Rules 3, 4, 5, 14, 17, 21, 23, 24, 32, 33 eff. 11/15/2023.

Rule 1 eff. 01/01/2024.

Rules 3, 9, 10, 11, 12, 13, 16, 17, 25, 32 eff. 11/15/2024.

Rules 1, 5, 7, 10, 11, 12, 14-15, 17, 21, 23, 31-32 eff. 11/15/2025.

902 Administrator-Uniform Consumer Credit Code and Commission on Consumer Credit

4 CCR 902-1 Uniform Consumer Credit Code Rules {#sec-4-ccr-902-1 omnilex-key=us-co-regs-official--department-11--4 CCR 902-1}

DEPARTMENT OF LAW

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit UNIFORM CONSUMER CREDIT CODE RULES 4 CCR 902-1 [Editor’s Notes follow the text of the rules at the end of this CCR Document.] _________________________________________________________________________

Rule 1 Right to Rescind Certain Transactions (Repealed effective November 1, 2000).

Rule 2 Limitations on Garnishment of Earnings for Pay Periods Other Than a Week (a) For purposes of § 5-5-106(2)(b), C.R.S., the “multiple” of the federal minimum hourly wage equivalent to that applicable to the disposable earnings for one week is represented by the following formula:

The number of workweeks, or fractions thereof, times 30 times the applicable federal minimum wage. For the purpose of this formula, a calendar month is considered to consist of 4 1/3 workweeks.

Rule 3 Permissible Additional Charges – Single Premium Non-Credit Insurance (a) A creditor may sell single premium non-credit insurance in connection with a consumer credit transaction provided that:

(1) The insurance coverage in not a factor in the approval of credit and this fact is clearly disclosed in writing to the consumer.

(2) In order to obtain the insurance the consumer gives specific affirmative written indication of the consumer's desire to purchase the insurance after receiving written disclosure of the cost.

(3) The insurance policy allows the insured consumer thirty (30) days to cancel the policy, without cost.

(4) If the insured does cancel the policy within the thirty (30) day period the premium shall be returned directly to the insured.

(5) If the insured makes a valid claim the benefits shall be paid directly to the insured, the designated beneficiaries, or the estate, but not to the creditor.

(b) If the insurance sold meets both the definition of non-credit insurance in part (c) of this rule and all of the five conditions listed above, the charge for such insurance may be excluded as a permissible additional charge from the finance charge.

(c) “Non-credit insurance” means insurance conferred on the consumer, if the benefits are of value to the consumer and if the charges are reasonable in relation to the benefits, and are of a type that is not for credit.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit

Rule 4 Permissible Additional Charges - Involuntary Unemployment Insurance Premiums (a) Pursuant to § 5-2-202(1)(d), C.R.S., the administrator finds that involuntary unemployment insurance sold in conformity with the provisions of this rule is a benefit to the borrower and that the charges are reasonable in relation to the benefits and are not of a type for credit.

(b) Premiums for involuntary unemployment insurance are permissible additional charges if all of the following conditions are met fully:

  1. The insurance coverage is not a factor in the extension of credit and this fact is clearly disclosed in writing to the consumer.

  2. The premium for the initial term of insurance coverage is disclosed. If the term of insurance is less than the term of the transaction, the term of insurance also shall be disclosed. The premium may be disclosed on a unit-cost basis only in revolving credit transactions.

  3. The number of installment or other payments payable by the insurance covering the consumer and any limitation on the amount of such payments are disclosed clearly in writing to the consumer.

  4. The creditor secures that consumer’s consent for a specific amount and cost of insurance if sold by the creditor before inclusion of the insurance premium in any quoted installment or other payment or in any document prepared for closing. In order to obtain the insurance the consumer gives specific written affirmative indication of the consumer’s desire to purchase the insurance after receiving the disclosures specified in this rule.

  5. The insurance policy allows the insured consumer to cancel the policy within thirty (30) days with a refund of all of the premiums and without cost, and to cancel the policy at any time thereafter with a refund of unearned premiums, and the insured receives written disclosure of these facts.

  6. If the insured does cancel the policy the premium refund is returned directly to the consumer or credited to the consumer’s account as a partial prepayment of the indebtedness.

  7. The sale of the insurance fully complies with all federal and Colorado laws and regulations concerning consumer credit insurance, including without limitation parts 1 and 2, article 4, title 5, C.R.S.

  8. The consumer receives written disclosure of the length of any deductible period before the insurance benefits are payable and whether the benefits are retroactive to the commencement of involuntary unemployment.

  9. The creditor makes a prompt refund to the consumer of all applicable finance charges calculated according to the actuarial method based upon the refunded premiums and the terms of the transaction if the creditor financed the premiums in a precomputed transaction, the consumer cancels the insurance, and the creditor refunds the premiums by credit to the consumer’s account.

  10. In the event the creditor sells both involuntary unemployment insurance and another form of consumer credit insurance, neither policy provides for a denial of benefits because of pre-existing coverage by the other policy if insured events under both policies lead to simultaneous claims, and benefits are coordinated until all liability is paid in full.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit 11. In the event of either voluntary or involuntary prepayment of the indebtedness, a refund of unearned premiums is made in accordance with article 4, title 5, C.R.S.

  1. If the policy provides for a waiting period after the effective date of the policy during which no claim may be made, that fact is disclosed in writing to the consumer.

(c) “Involuntary unemployment insurance” means insurance providing the insured consumer with coverage for consumer credit repayment obligations for a period or periods during which the consumer is involuntarily unemployed. “Involuntary unemployment insurance” includes only insurance at least providing benefits for loss of employment income caused by individual or mass layoff, general strike, termination by employer, unionized labor dispute, and lockout. “Involuntary unemployment insurance” does not include insurance as to which a finance charge is imposed and provided in relation to a credit transaction in which a payment is scheduled more than ten (10) years after the extension of credit.

Rule 5 Class of Transactions Exempt From the Balloon Payment Refinance Provision The class of consumer credit transactions that provides for periodic payments of interest only throughout the term of the consumer credit sale or loan and that has a scheduled payment more than twice as large as the average of all other regularly scheduled payments is not subject to the disclosure and right to refinance provisions of § 5-3-208, C.R.S. However, if the transaction, as originally scheduled, does not provide for periodic payments sufficient to pay all the interest due to the date of each scheduled payment then the transaction is subject to the provisions of § 5-3-208, C.R.S.

Rule 6 Actuarial Method For all purposes under the Uniform Consumer Credit Code, as far as practicable, “actuarial method” shall be that set forth in the federal Truth in Lending Act and any regulation thereunder, including 12 C.F.R. 226, appendix J (Regulation Z, appendix J - Annual Percentage Rate Computations for Closed-End Credit Transactions, promulgated by the Board of Governors of the Federal Reserve System). “Actuarial method” shall include the United States Rule method set forth in 12 C.F.R. 226, appendix J (a)(3).

Rule 7 Multiple Agreements and Post Dated Checks (Repealed effective November 1, 2000)

Rule 8 Permissible Additional Charges - Guaranteed Automobile Protection A fee or charge for guaranteed automobile protection (“GAP” ) may be contracted for and received as an additional charge if all of the conditions listed below are met. Failure to comply with all provisions of this

rule shall mean that the fee or charge for GAP is not a permitted additional charge under Uniform Consumer Credit Code (“UCCC” ) § 5-2-202(1)(d). This rule is inapplicable to GAP included in consumer leases, to other debt cancellation agreements in consumer credit sales or consumer loans that do not meet this definition, and to transactions not subject to the UCCC.

(a) GAP means an agreement structured as either an insurance policy or a contractual term sold or written in consumer credit sales [5-1-301(11)] or consumer loan transactions [5-1-301(15)] that relieves the consumer of liability for the deficiency balance remaining after the payment of all insurance proceeds (or deducting the amount that would have been paid if the contractually required insurance had been maintained at the time of the loss) for property damage upon the total loss of the consumer’s automobile(s) that was collateral securing the credit sale or consumer loan, whether the loss occurred from the total destruction of the vehicle, the theft of the vehicle, or both. “Automobile” includes any motor vehicle that may be used as collateral securing a consumer credit transaction.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit (b) The consumer must provide affirmative written authorization for the purchase of GAP after receiving written notice of the following in bold face type before credit is extended:

(1) that the purchase of GAP is not required in order to obtain the credit or any particular or favorable credit terms;

(2) the fee or premium for GAP;

(3) that the consumer may wish to consult an insurance agent to determine whether similar coverage may be obtained and at what cost;

(4) that GAP benefits may decrease over the term of the consumer credit sale or consumer loan;

(5) that the consumer may cancel GAP for any or no reason within thirty (30) days after GAP was purchased and receive a full refund of the GAP fee or premium so long as no loss or event covered by GAP has occurred; and, (6) GAP is not a substitute for collision or property damage insurance.

(c) At the time the consumer provides affirmative written authorization to purchase GAP, the creditor shall provide the consumer with a separate written cancellation form. The form shall:

(1) include the name and mailing address to be used to cancel GAP;

(2) state clearly and conspicuously that the consumer has an unconditional right to cancel GAP for a full refund within thirty (30) days after it was purchased; and, (3) state that in order to cancel GAP, the consumer must complete and return the form or send any other written notice of cancellation to the address provided postmarked no later than thirty (30) days after GAP was purchased.

(d) At the time the consumer provides affirmative written authorization to purchase GAP, the creditor must deliver to the consumer the GAP insurance policy, certificate, or written description of GAP’s benefits, terms, conditions, and exclusions and the procedure and timing to be followed to make a claim after a total loss.

(e) GAP must pay or forgive the deficiency balance owed by the consumer at the time of the total loss with the exception of amounts previously owed for unpaid installments, legally permitted delinquency fees, fees for the return or dishonor of checks or other instruments tendered as payment, premiums for creditor-imposed property damage insurance, and deferral fees. GAP must pay or forgive the deficiency balance that would have been owed if the consumer had maintained property damage insurance on the automobile (even if the consumer has not done so) or if the creditor has purchased property damage insurance for the automobile and added it to the amount of the debt pursuant to UCCC § 5-2-209, C.R.S.

(f) As part of payment of or relief from liability of the deficiency balance, GAP must provide the consumer with a full refund or credit of the amount of the consumer’s deductible for property damage insurance up to an amount including five hundred ($500) dollars.

(g) GAP may not be sold pursuant to this rule if (1) the consumer; (2) the credit terms including but not limited to cash price, automobile value or amount financed; or, (3) the automobile used as collateral for the credit transaction, do not qualify for or conflict with any restrictions or limitations of the GAP policy or contract conditions. For example:

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit (1) if GAP will not provide coverage or debt cancellation for identified automobile makes and models frequently subject to theft or to consumers living in certain neighborhoods, it may not be sold pursuant to this rule if the automobile securing the loan is one of the identified makes and models or if the consumer lives in an excluded neighborhood; or, (2) if GAP will not provide coverage or debt cancellation if the automobile sale price is more than the manufacturer’s suggested retail price (“MSRP” ) or if the retail value of the automobile exceeds 120% of “Blue Book” value, it may not be sold pursuant to this rule if the price exceeds the MSRP or if the loan to value ratio is 125%.

In addition, GAP may not be sold pursuant to this rule if the transaction would be unconscionable pursuant to UCCC § 5-4-106, 5-5-109, or 5-6-112, C.R.S.

(h) If the consumer credit sale or consumer loan is prepaid prior to maturity or the vehicle is no longer in the consumer’s possession due to the creditor’s lawful repossession and disposition of the collateral, and if no GAP claim has been made, the creditor must refund to the consumer the unearned fee or premium paid for GAP. If GAP was provided as a contractual term, the refund shall be made using a pro-rata method. If GAP is determined to be insurance, the refund method used shall be any method authorized under applicable insurance statutes, rules, or interpretations of the Colorado Division of Insurance.

(i) Only one fee or charge for GAP may be contracted for and received regardless of the number of co-borrowers, co-signers, or guarantors in the credit transaction. In the event that GAP has been sold and a valid claim has been made, the creditor may not seek indemnification from the consumer, co-borrowers, co-signers, or guarantors.

(j) A consumer shall have ninety (90) days after the loss settlement from any property damage insurance or from the date the creditor notifies the consumer of any deficiency balance owed, whichever is later, to file a GAP claim or seek debt cancellation from the creditor.

(k) The maximum fee that may be charged for GAP shall not exceed the following: $300 or 2% of the amount financed, whichever is higher.

This provision (k) shall not apply to any GAP insurance that is subject to regulation by the Colorado Division of Insurance.

(l) Every provision of this rule applies equally to any assignee or holder of a consumer credit sale or consumer loan containing a fee or charge for GAP. No creditor, assignee, or holder shall have any subrogation rights against the consumer.

(m) Every consumer credit sale or consumer loan that includes a fee or premium for GAP shall contain in the written agreement signed by the consumer a provision substantially similar to the following:

If this transaction contains a fee or premium for guaranteed automobile protection, all holders and assignees of this consumer credit transaction are subject to all claims and defenses which the consumer could assert against the original creditor resulting from the consumer’s purchase of guaranteed automobile protection.

(n) This rule shall remain in effect and apply to consumer credit sales and consumer loan transactions entered into before January 1, 2024.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit

Rule 9 Supervised Lender License Applications, Surety Bonds, and Changes of Ownership (a) Application.

(1) An application for a supervised lender’s license shall be considered “filed” for purposes of Uniform Consumer Credit Code § 5-2-302(3) once all information required by the Administrator from the applicant has been received.

(2) If the applicant has not filed all material requested within two (2) months after being notified by the Administrator of incomplete or missing information, the application may be denied.

(b) Financial Responsibility .

(1) The references to financial responsibility in Uniform Consumer Credit Code (“UCCC” ) § 5-2-302(2) and 5-2-304(2), C.R.S. shall be satisfied by one or more of the forms permitted by this rule in an amount based on the volume of Colorado supervised loans made and taken by assignment in the prior calendar year as reflected in the table below.

If no supervised loans were made or taken by assignment in the prior calendar year, and the supervised lender is required by law to maintain a supervised lender’s license, the lender shall maintain the minimum amount of financial responsibility required by this rule.

In lieu of filing and maintaining evidence of financial responsibility for each master and branch licensed location, the applicant/licensee may maintain one form of financial responsibility for all licensed locations but the aggregate dollar amount required for all licensed locations need not exceed $250,000.

Volume of Supervised Loans Made and Taken by Assignment in Prior Calendar Year (excluding finance charges)

Amount per License 0 to $500,000 (or initial application) $15,000 $500,001 to $1,000,000 $20,000 >$1,000,000 $25,000 (A) Surety Bond (I) The bond shall be in the manner prescribed by the Administrator, shall be issued by a surety licensed by the Colorado Commissioner of Insurance to transact the business of fidelity and surety insurance, and shall contain original signatures. The bond shall be in favor of the Attorney General of the State of Colorado for use by the Administrator of the Uniform Consumer Credit Code on behalf of the People of the State of Colorado. The bond shall be conditioned upon the compliance by the licensee with all provisions of the UCCC and rules and regulations lawfully adopted thereunder and the payment to the UCCC Administrator or to any person(s) who may have a cause of action against the licensee under the UCCC, of any and all amounts of money that may become due or owing to the UCCC Administrator or to such person(s) from the licensee.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit (II) Should the surety cancel or reduce the penal sum of the bond, the surety must immediately provide written notification to the Administrator of the UCCC. The bond may be canceled or reduced no sooner than thirty (30) days after receipt of the cancellation or reduction notice by the Administrator. Upon receipt of a notice of cancellation or reduction of a bond, the Administrator must mail written notification to the licensee of its obligation to file with the administrator, on or before the effective date of cancellation or reduction, a new surety bond, rider or other document increasing the bond, or notice from the surety rescinding the cancellation or reduction.

(III) The bond must provide that the liability of the surety upon the bond shall cease no sooner than two (2) years after the surrender, revocation, or expiration of the license.

(B) Cash Surety - evidence of a savings account, deposit, or certificate of deposit in or issued by a state bank, national bank, or savings and loan association doing business in Colorado, containing original signatures, and assigned to the Administrator of the Colorado Uniform Consumer Credit Code for use by the People of the State of Colorado. Interest and dividends earned on the principal amount may be retained by the applicant/licensee. Cash surety assignments may not be released prior to two (2) years after the surrender, revocation, or expiration of the license. The cash surety must comply with section 11-35-101, C.R.S. (alternatives to surety bonds permitted - requirements).

(C) Letter of credit - an irrevocable letter of credit containing original signatures and written in favor of the Administrator of the Colorado Uniform Consumer Credit Code for use by the People of the State of Colorado issued by a state bank, national bank, or savings and loan association doing business in Colorado. The letter of credit shall be for a term of two years and must provide that the liability of the issuer shall cease no sooner than two (2) years after the surrender, revocation, or expiration of the license. The letter of credit must comply with

section 11-35-101.5, C.R.S. (irrevocable letter of credit permitted - requirements).

(c) Change of Ownership.

(1) Within thirty (30) days after a change of ownership of a licensed supervised lender consisting of 50% or more of the membership interests in a limited liability company or 50% or more of the voting stock of a corporation, in any one transaction or a cumulative change of ownership of fifty percent or more from the date of the issuance of the license or from the date of the last notification and payment of the annual license fee, the licensee shall provide written notification of the change. The Administrator may require the licensee to provide additional information or file a new license application. If the Administrator requests additional information or a new license application, the licensee may continue to operate as a supervised lender until notified that the change is approved.

This requirement shall not apply to corporations or other entities filing registration statements and periodic current reports under the federal Securities Exchange Act of 1934 [15 U.S.C. § 78a et seq.].

(2) At least fifteen (15) days prior to a change of ownership of a licensed supervised lender consisting of a change of partner or sole proprietor, the licensee shall reapply for a new license in the manner prescribed by the Administrator. The licensee may continue to operate as a licensed supervised lender until the Administrator has acted on the license application.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit

Rule 10. Records to be Maintained by Creditors (a) Definitions 1. The term “log” shall mean a separate, unique record of an activity organized in an orderly fashion, typically chronologically. It should include, as applicable, names of consumers, account numbers, activity information, and other pertinent information as required by this

rule for that activity. A log is not a collection of documents.

(b) Examples of Documents to Maintain. A creditor must maintain and make available records for compliance examinations and investigations that enable the Administrator to determine that the creditor is in compliance with the Colorado Uniform Consumer Credit Code (“UCCC”). A creditor may maintain records in hard copy or electronic format but must make the records in the format maintained reasonably available to the Administrator. The Administrator provides the following examples of documents creditors should maintain. This is not an exhaustive list, and creditors should maintain all documents required to demonstrate compliance with the UCCC. The creditor shall make this information reasonably available to the Administrator. If the creditor does not maintain information that is reasonably available to the Administrator, it violates C.R.S. § 5-2- 304(1) and § 5-3-109, as applicable.

  1. Advertising and solicitation material.

  2. Credit applications and any other documents obtained by a creditor or required by law verifying the financial information contained in the application, approvals, and denials.

  3. Disclosures required by the UCCC, including the Deferred Deposit Loan Act, and the federal Truth in Lending and Truth in Leasing Acts, and any regulations thereunder.

  4. Promissory notes, loan agreements, lease agreements, retail installment sales contracts, invoices, purchase orders, and buyer’s orders.

  5. Co-signer notices.

  6. Rescission notices.

  7. Payment and account history documents including application of each payment (including payment attempts and returns) to principal and, if applicable, interest, prepayment, payment in full, delinquency fees, deferral fees, fees for the return or dishonor of checks or other instruments tendered as payment, credits and refunds, court costs, attorneys fees, and ledger transaction codes. The payment history should also provide the remaining balance after each transaction. The payment and account history should show the date(s) funds were disbursed, the date(s) consumers received funds, if different, and the dates of all other transactions affecting the balance. In addition, these records include origination/acquisition and monthly maintenance fees for loans made under the Deferred Deposit Loan Act; and acquisition and monthly installment account handling charges for loans made under § 5-2-214, C.R.S.

  8. Delinquency fee and deferral notices.

  9. Change in terms notices.

  10. Right to cure, default, and repossession of collateral notices.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit 11. Collection attempts. These activities should be documented in a record log. The record log should list the activities in chronological order, and document the time, date, and substance of the activities. The creditor must document all collection activity in the record log, including, but is not limited to, collection letters, e-mails, phone calls, right to cure notices, and texts. If the creditor records calls, the call recordings must be retained.

  1. Insurance authorizations, policies, premiums, and certificates.

  2. Authorization for benefits permitted as additional charges by UCCC rule.

  3. Receipts for cash payments.

  4. Release of security interests, termination of financing statements, and payment in full notices.

  5. Credit reports, appraisals, title policies, and other records of closing costs on real estate secured transactions legally permitted to be excluded from the finance charge.

  6. For deferred deposit/payday loans, a consumer log including the consumer’s name, date of all loans made to the consumer for the prior four years, amount financed, dollar amount of each of the three charges contracted for under section 5-3.1-105, C.R.S.

(origination or acquisition fee earned as of the date of the loan, interest, and monthly maintenance fees), loan term, date of final payment, method of payment (e.g., consumer’s check deposited or cashed; payment electronically debited from consumer’s bank account; consumer redeems check or debit authorization with cash; loan renewed), for renewals the amount of any loan proceeds given to the consumer directly and/or paid to others on the consumer’s behalf, and if applicable, the dates the lender offered written payment plans and the dates payment plans were established.

  1. For deferred deposit/payday loans, daily activity logs, check and cash disbursement registers, and bank records including bank statements and deposit slips reflecting disbursements of loan proceeds and payments on deferred deposit/payday loans.

  2. For deferred deposit/payday loans, records of postings of charges, notices on assignment or sale of instruments, and compliance with renewal limitations and payment plan requirements.

  3. For loans made under section 5-2-214, “Alternative charges for loans not exceeding one thousand dollars:”

(a) For each consumer, a consumer log including the consumer’s name, date of all loans made to the consumer for the prior four years, date of actual final payment, amount financed, dollar amount of contractual acquisition charge, total dollar amount of contractual monthly installment account handling charge, loan term, method of payment (e.g., paid by consumer, refinanced, or consolidated), the dollar amount of any refunds paid to the consumer upon prepayment, and for refinances and consolidations the amount of any loan proceeds given to the consumer directly and/or paid to others on the consumer’s behalf.

(b) Daily activity logs of all loans made, refinanced, or consolidated, including the consumer’s name, whether the consumer is new, a former customer, or a current customer; check and cash disbursement registers; and bank records including bank statements and deposit slips reflecting disbursements of loan proceeds and loan payments.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit 21. Creditors must maintain a record log listing in chronological order all loans and credit extensions to consumers.

  1. Creditors must maintain daily activity logs, check and cash disbursement registers, and bank records including bank statements and deposit slips reflecting disbursements of loan proceeds and payments.

  2. For guaranteed asset protection agreements (“GAP”) under C.R.S. § 5-9.3-101 et seq., creditors must maintain and/or make reasonably available to the Administrator any GAP agreements with consumers; agreements with GAP administrators related to GAP; and records of GAP fees received, refunds provided, benefits provided and any deductions to the benefit.

(a) Creditors must maintain either correspondence with consumers related to GAP claims and refunds, and correspondence with GAP administrators related to GAP claims and refunds; or creditors may alternatively maintain a log.

i. If the creditor maintains a log for correspondence with consumers, the log should contain the date and substance of the communication, the date and amounts of GAP fees paid by the consumer, any refunds noticed or provided by the creditor, and any benefits provided and any deductions to the benefit by the creditor.

ii. If the creditor maintains a log for correspondence with GAP administrators, the log should contain the date and substance of the communication, any refunds noticed or provided by the creditor, and any benefits provided and any deductions to the benefit by the creditor.

(c) Effective Date. The modifications to this rule shall be effective February 1, 2025.

Rule 11 Payoff Quotes (a) A creditor must deliver or mail a written payoff quote to a consumer within five (5) business days after receipt of the consumer's written request. If so requested by the consumer, the quote may be made by electronic means or orally. A business day does not include a Saturday, Sunday, or legal holiday. No fee may be charged for a payoff quote.

(b) The payoff quote must include the date by which payment must be made for the payoff quote to be valid.

(c) The creditor may require the consumer to provide reasonable identifying information such as the consumer(s) name, date of birth, social security number, account number, and consumer's signature.

Rule 12 Prompt Crediting of Payments (a) A creditor shall credit an accepted payment to the consumer's account as of the date of receipt except when a delay in crediting does not result in imposition of a finance charge, delinquency fee, or other charge or in the payment being reported as a slow or late payment. Deferred deposit loans, if paid by deposit of the consumer's check in the creditor's account, shall be credited as of the date of deposit.

(b) This rule does not prohibit subsequent adjustments to a consumer's account to reflect dishonored checks, drafts, or other payment instruments.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit

Rule 13 Rebate of Prepaid Finance Charge Pursuant to § 5-2-207, C.R.S.

(1) For purposes of Uniform Consumer Credit Code § 5-2-207, C.R.S., if within one year after making a consumer credit transaction for which a prepaid finance charge was imposed, the creditor refinances or consolidates the transaction and chooses to impose a prepaid finance charge on the aggregate principal resulting from the refinance or consolidation [5-2-207(2)(b)], the creditor must rebate any portion of the prepaid finance charge [5-1-301(20)] imposed on the previous transaction that:

(a) on a fixed rate consumer credit transaction, exceeds the disclosed annual percentage rate; or (b) on a variable or adjustable rate consumer credit transaction, exceeds the lesser of 21% per year on the unpaid balance of the principal [5-2-201] or the maximum annual percentage rate imposed pursuant to the written credit agreement since the inception of the consumer credit transaction.

(2) With respect to a transaction subject to § 5-2-207(2), C.R.S., if a creditor imposes a prepaid finance charge and the charge is set as a fixed dollar amount rather than a percentage of the loan amount, it may only impose a new prepaid finance charge on a refinance or consolidation within a one year period if it complies with § 5-2-207(2)(b), C.R.S.

Rule 14 Fee Schedule (Repealed effective January 1, 2010)

Rule 15 Notification Fees and Volume Fees (Repealed effective January 1, 2004)

Rule 16 Deferred Deposit Loan Payment Plans This rule is repealed effective August 11, 2010 with respect to loans made or renewed under the Deferred Deposit Loan Act on or after that date. It remains in effect with respect to loans made or renewed prior to the repeal of § 5-3.1-108(5), C.R.S.

For deferred deposit loans subject to section 5-3.1-108(5), C.R.S. on voluntary payment plans, a lender shall also comply with this rule.

(a) Notice of Written Payment Plan Offers (1) The written notice of the option to participate in a voluntary payment plan required in

section 5-3.1-108(5)(a), C.R.S. shall state the following language in at least ten-point type:

“NOTICE OF PAYMENT PLAN OPTION

YOU HAVE THE RIGHT TO PARTICIPATE IN A VOLUNTARY PAYMENT PLAN TO REPAY

THIS LOAN. IF YOU SELECT A PAYMENT PLAN, YOU MAY REPAY ANY AMOUNTS DUE IN

AT LEAST 6 EQUAL INSTALLMENTS RATHER THAN 1 SINGLE PAYMENT. PAYMENTS WILL

BE DUE ON YOUR PAYDAY OR DATE YOU RECEIVE BENEFITS. THERE IS NO

ADDITIONAL FEE FOR A PAYMENT PLAN.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit YOU MAY SELECT THE PAYMENT PLAN NOW OR AT ANY TIME BEFORE THE CLOSE OF BUSINESS ON THE DAY BEFORE THIS LOAN IS DUE. TO SELECT A PAYMENT PLAN (select either or both of the phrases below as applicable)

RETURN TO THIS LOCATION OR ANY OTHER BRANCH LOCATIONS WE OPERATE IN

COLORADO. CONTACT OUR OFFICE FOR THE NAMES AND ADDRESSES OF OTHER

BRANCH LOCATIONS, IF ANY, WE OPERATE IN COLORADO.

(and/or)

IF THIS LOAN WAS ORIGINATED AT A WEB SITE, BY TELEPHONE, OR AT ANOTHER

REMOTE LOCATION, VISIT OR CONTACT US AT (insert applicable information).

THE DECISION TO SELECT A PAYMENT PLAN IS YOURS TO MAKE. IF YOU SELECT A

PAYMENT PLAN, THE LENDER MUST PROVIDE A PLAN THAT MEETS THE

REQUIREMENTS DESCRIBED ABOVE. YOU ARE ENTITLED TO RECEIVE A COPY OF THIS

NOTICE.

BY SIGNING BELOW I ACKNOWLEDGE THAT I WAS OFFERED THE OPTION OF A

PAYMENT PLAN. ________________________________ ___________________

(signature) (date)”

(2) The Notice of Payment Plan Option shall prominently include the lender’s business name, physical location address, and telephone number, and shall also include the consumer’s signature and the date the notice was provided. It shall be contained in a document separate from the loan application, loan agreement, contract, and any other disclosures required by state or federal law, except that the notice may also contain the written payment plan. The lender shall provide the consumer with a copy of the notice of payment plan option in a form the consumer may keep.

(b) Contents of Written Payment Plan. The written payment plan shall contain all of the following information:

(1) Total amount of existing debt, (2) Dates of each payment, (3) Amount of each payment, (4) That there is no additional fee to select a plan, (5) That the lender is prohibited by law from collection activities while the consumer meets the terms of the plan, (6) That the lender and its affiliates are prohibited by law from making any deferred deposit loans to the consumer before a plan is completed, and (7) That if the consumer does not pay the full amount of each payment by the due date, the lender may collect all of the remaining debt due and charge the consumer a $25.00 default fee.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit A lender that requires a consumer to provide post-dated checks or electronic authorizations for the payments under the plan must disclose that information in the written payment plan. The payment plan must be dated and signed by both the lender and consumer (c) Record Retention. A lender shall maintain records relating to all of its written payment plan offers and payment plans pursuant to Rule 10 of the Uniform Consumer Credit Code Rules.

Rule 17 Deferred Deposit/Payday Loans For deferred deposit/payday loans, the following rules apply. All references to payday loans also include deferred deposit loans.

(A) Origination/Acquisition Fee The finance charge permitted by section 5-3.1-105, C.R.S. of up to 20% of the first $300 loaned plus 7.5% of any amount loaned in excess of $300 may be referred to as an “origination” or “acquisition” fee.

(B) Installments 1. The lender and consumer may contract for payments to be made in a single installment or multiple installments of substantially equal amounts due at equal periodic intervals.

  1. All applications for payday loans and payday loan agreements shall clearly and conspicuously disclose that under Colorado law, loans may be structured to be repaid in a single installment or multiple installments. If a lender does not offer both installment options, it shall also clearly and conspicuously disclose in its applications and loan agreements the option it provides.

(C) Interest Rate The interest rate of up to 45% per annum permitted by section 5-3.1-105, C.R.S. may be assessed only on the amount financed of $500 or less. It may not be assessed on the origination/acquisition fee or monthly maintenance fees.

(D) Monthly Maintenance Fees 1. A monthly maintenance fee may be charged for each month the loan is outstanding after the first 30 days of the loan. The number of monthly maintenance fees permitted is equal to the number of months in the loan term less one month. For example, on a six month loan, a monthly maintenance fee may be charged at the end of the second through sixth months if the loan is outstanding during that time.

  1. A monthly maintenance fee may be charged on each $100 increment of the amount financed. No fee may be collected on amounts of less than $100. For example, on a $350 loan, the permitted monthly maintenance fee is $22.50 (3 increments of $100 x $7.50 = $22.50).

  2. A monthly maintenance fee is not earned until the end of the month. If a payday loan is prepaid in full at any time during a month, no monthly maintenance fee may be collected for that month.

  3. The monthly maintenance fee may be based on the amount financed rather than the actual balance remaining each month.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit (E) Posting of Charges To comply with section 5-3.1-113, C.R.S., a lender shall post in its place of business examples of the total of all charges for a 6-month loan in the amounts of $100, $300 and $500 based on the assumption that the loan will be paid as scheduled. If the lender does not offer loans in those amounts, it shall post examples for its minimum and maximum loan amounts. If the lender offers both single and multiple installment loans, it shall provide the examples for both single and multiple installment loans. If a lender offers renewals, it shall also post the total of all charges for renewal of a 6-month loan using the same examples. If a lender does not offer renewals, it shall post a statement that although state law permits renewals, it does not offer renewals. Lenders that make loans over the internet shall post the charges required by this rule on their web sites.

No other loan terms or payment information may be included in the required posting of charges.

(F) Payment Instruments If a payday loan is payable in multiple installments, the lender may hold a single payment instrument or a payment instrument for each installment. The amount of the payment instrument may include the loan principal and origination/acquisition fee. The payment instrument or authorization may not include interest or the monthly maintenance fee. The lender may collect the remaining amount due under each installment but may not hold a payment instrument or authorization for such additional amount.

(G) Application of Payments Subject to Rule 17(I), a lender may contract for and apply payments on a payday loan using a precomputed or non-precomputed method. A lender that contracts for a non-precomputed loan shall clearly and conspicuously disclose in the loan agreement “Late payments made after the due date will result in additional interest charges.”

(H) Renewals 1. Upon renewal of a payday loan, the lender may not charge an origination fee, acquisition fee, or monthly maintenance fees.

  1. Upon renewal of a payday loan, the lender may refinance an amount up to $500. If the amount owed exceeds $500, the lender may refinance up to $500 and the consumer must pay any remaining amount.

(I) Prepayments and Refunds 1. A consumer may at any time prepay a payday loan in full or in part without a penalty prior to the due date or date the last installment is due.

  1. The refund required by section 5-3.1-105, C.R.S. shall include the pro-rata portion of the origination/acquisition fee, the interest rate, and the monthly maintenance fee.

  2. Consumer refunds may be paid to the consumer by cash, check, or similar method, or by appropriate credit to the remaining balance of the loan but may not be applied as a credit to another open account or for a future loan with that lender or any other lender. If a lender makes a cash refund, it shall provide the consumer with a cash receipt and comply with Rule 10(a)(14).

  3. If a consumer exercises the right to rescind the loan by 5 p.m. of the next business day pursuant to section 5-3.1-106(2), C.R.S, the lender shall refund all charges imposed pursuant to section 5-3.1-105, C.R.S.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit (J) Default 1. If a payday loan is payable in 5 or more installments and the consumer is in default for failure to make a required payment, the lender may not accelerate the balance or enforce a security interest, including depositing any remaining payment instruments, unless it complies with the right to cure default provisions in UCCC sections 5-5-110 and 5-5-111.

  1. The lender may not charge or collect more than one returned instrument charge on a payday loan, regardless of the number of payment instruments returned unpaid or the number of times a payment instrument is presented and returned unpaid. The amount of the single returned instrument charge may not exceed $25 and must be contracted for in the loan agreement.

  2. The lender may not charge or collect monthly maintenance fees for any months the loan remains unpaid after the end of the scheduled final due date.

Rule 18 - Income Share Agreements For income share agreements made in this state, as provided in C.R.S. § 5-1-201, the following rules apply.

(a) Definitions applicable to this rule (1) “Earned finance charge” is equal to the finance charge that would have been earned by a creditor applying the greater of the annual percentage rate disclosed pursuant to 12 C.F.R. § 1026.18(e) or, if disclosed, the maximum annual percentage rate disclosed pursuant to 12 C.F.R. § 1026.18(f)(1)(ii) to the amount financed and calculated as of the current date.

(2) “Income share agreement” or “ISA” means a consumer credit transaction, as defined in C.R.S. § 5-1-301(12), under which the amount of the consumer’s installment and total repayment obligation for the transaction is calculated based upon the amount of the consumer’s future qualified income, and there is a duration of time identified in the agreement after which the consumer’s obligation is complete without regard for the amount paid.

(3) “Maximum income threshold” means the consumer’s qualified income amount at or above which the qualifying payment will not increase.

(4) “Maximum payment term” means the time period, measured in months, during which a consumer remains obligated under an income share agreement regardless of whether the consumer’s income is greater than the minimum income threshold.

(5) “Maximum required payments” means the maximum number of qualifying payments a consumer is required to make under an income share agreement.

(6) “Minimum income threshold” means the consumer’s qualified income amount at or below which the consumer’s qualifying payment is reduced to zero dollars.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit (7) “Payment cap” means the maximum amount of money a consumer is required to pay to satisfy the consumer’s payment obligation under an income share agreement, which, for example, may be expressed as a dollar value, a multiple of the amount funded to the consumer or on the consumer’s behalf, or as a maximum effective annual percentage rate, excluding charges related to default or other charges and fees that are due under the income share agreement. These examples are not exhaustive, and the disclosure of a Payment Cap may take other forms, as appropriate for the agreement.

(8) “Payment percentage” means the share or proportion of qualified income a consumer must pay pursuant to the terms of an income share agreement. The payment percentage may also be expressed as a fixed number or a variable or tiered rate.

(9) “Qualified income” means that part of the consumer’s income, as defined in contract, to which the payment percentage will be applied to determine the amount of a consumer's (10) “Qualifying payment” means a calculated installment payment that counts toward the maximum required payments pursuant to the terms of an income share agreement.

(b) Required disclosure under TILA, Regulation Z, and the UCCC A creditor entering into an income share agreement shall disclose to the consumer to whom credit is extended the information, disclosures, and notices required by the Uniform Consumer Credit Code, C.R.S. § 5-1-101, et seq. (UCCC), including C.R.S. § 5-3-101. A creditor entering into an income share agreement shall comply with the federal Truth in Lending Act (TILA) and its implementing regulation, Regulation Z.

(c) Supplemental Colorado disclosure A creditor entering into an income share agreement shall, in addition to disclosures required by

Rule 18(b), include a supplemental Colorado disclosure.

(1) Scenarios: For each of the following scenarios, the creditor shall disclose the installment payment amount, number of installment payments, total of payments, and the qualified income amount used to calculate the disclosures.

When calculating the scenarios for disclosure, the creditor shall assume that the disclosed number, amounts, and timing of the qualifying payments are received as scheduled. When disclosing the Scenarios, the creditor shall include a statement explaining that the Scenarios are illustrations of what may occur and not guarantees of what will occur. The creditor shall include a brief statement explaining that the amount paid by the consumer will vary in proportion to the consumer’s future qualified income.

A. Scenario 1. The consumer’s annual qualified income stays constant for the term of the income share agreement at an amount less than the minimum income threshold. This scenario shall be accompanied by a brief description such as, “if your qualified income is below the minimum income threshold.” If an income share agreement does not have a minimum income threshold, Scenario 1 shall be calculated using an annual qualified income of $0.

B. Scenarios 2-4. The consumer’s annual qualified income stays constant for the term of the income share agreement at $10,000, $20,000, and $30,000 less than the qualified income in Rule 18(c)(1)(C) below. If the qualified income used to calculate any of the Scenarios 2-4 is an amount less than the minimum income threshold, then that Scenario may be eliminated from the disclosure.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit C. Scenario 5. The consumer’s annual qualified income stays constant for the term of the income share agreement at the qualified income used to calculate the APR disclosed pursuant to 12 C.F.R. § 1026.18(e), as required under Rule 18(b), rounded to the nearest hundred dollars ($100).

D. Scenarios 6-8. The consumer’s annual qualified income stays constant for the term of the income share agreement at $10,000, $20,000, and $30,000 more than the qualified income in Rule 18(c)(1)(C) above. If the qualified income used to calculate any of the Scenarios 6-8 is an amount more than the maximum income threshold, then that Scenario may be eliminated from the disclosure.

E. Scenario 9. The consumer’s annual qualified income stays constant for the term of the income share agreement at the maximum income threshold. This scenario shall be accompanied by a brief description such as, “if your qualified income is above the maximum income threshold.” If an income share agreement does not have a maximum income threshold, Scenario 9 may be eliminated from the disclosure.

F. If any of the Scenarios would result in a rebate under Rule 18(f), the creditor shall disclose the amount of the rebate or, alternatively, the installment amount that the creditor will charge in order to avoid providing a rebate. If an installment amount is calculated to avoid providing a rebate, then the creditor shall disclose that fact. This disclosure shall consist of a brief description such as “this installment amount has been reduced to maintain an APR of XX%” or “the number of payments has been reduced to maintain an APR of XX%,” as applicable.

G. If Scenarios 6-9 would result in a total of payments in excess of the payment cap established in the ISA loan agreement, the creditor shall disclose the installment amount or the number of installment payments that the creditor will charge in order to avoid collecting an amount in excess of the payment cap, if one exists. If an installment amount is calculated to accommodate a payment cap, then the creditor shall disclose that fact. This disclosure shall consist of a brief description such as “this installment amount has been reduced to meet the payment cap of $XX or “the number of payments has been reduced to meet the payment cap of $XX,” as applicable.

(2) A creditor offering an income share agreement shall disclose the following to the extent that they are terms of the income share agreement, together with a clear and conspicuous description of the meaning of each term:

A. the amount financed, to be featured prominently relative to other terms in this subsection;

B. the payment percentage;

C. the maximum required payments;

D. the maximum payment term;

E. the minimum income threshold;

F. the maximum income threshold;

G. the payment cap;

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit H. the maximum annual percentage rate, labeled as the “maximum annual percentage rate,” if such a rate is disclosed as a limit to a variable rate pursuant to 12 C.F.R. § 1026.18(f)(1)(ii);

I. a complete description of the income that shall be considered qualified income and any form(s) of income that are exempted from qualified income;

J. a complete description of the manner in which the creditor will calculate the qualified income for the income share agreement;

K. how the creditor will calculate the balance owed to prepay the income share agreement in full;

L. the types of fees, including late fees, and the method for calculating such fees;

M. how the creditor will calculate the date repayment will begin; and N. all acts or omissions that constitute a default on the agreement.

(3) A creditor offering an income share agreement shall disclose that the income share agreement is not a wage assignment, in a statement substantially similar to:

By entering into this agreement, you are not selling or assigning any portion of your future earnings. You are not granting the creditor a security interest in any portion of your future earnings. To the extent that you default on this agreement, the creditor must obtain a valid court judgment against you before the creditor is entitled to collect from your earnings.

(d) Finance charges and other UCCC requirements Creditors making consumer credit transactions that meet the definition of income share agreements shall comply with the finance charge maximums in C.R.S. § 5-2-201 and other requirements of the UCCC.

(e) Prohibition against assignment of earnings No income share agreement may include a sale or assignment of any portion of the consumer’s future earnings to the creditor. A creditor may not take any portion of a consumer’s future earnings as security for repayment of amounts owed by the consumer under an income share agreement.

(f) Prepayment and rebate An income share agreement is paid in full when the sum of the amount(s) paid is equal to the sum of the amount financed and the earned finance charge.

Upon prepayment in full of the income share agreement obligation, the creditor shall rebate to the consumer within 35 days the difference between the amount paid and the sum of the amount financed and the earned finance charge.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit (g) Prohibition against false, misleading, or deceptive statements or representations With respect to income share agreements made in Colorado, the prohibition against false, misleading, or deceptive statements or representations set forth in C.R.S. § 5-3-110 includes, but is not limited to: (1) a prohibition against any representation that an income share agreement is not a loan, is not credit, or otherwise is not a consumer credit transaction as defined in C.R.S. § 5-1-301(12); and (2) a prohibition against any representation that the consumer must or should report the income share agreement as a sale of income to any tax authority.

(h) Notice of change in qualifying payment The creditor shall provide notice of any changes to the amount of the qualifying payment. If the qualifying payment will increase, the creditor shall provide the notice at least 30 days prior to the change. If the qualifying payment will decrease, the creditor shall provide the notice at least 7 days prior to the change.

The notice shall include:

(1) The amount of the qualifying payment before and after the change;

(2) The date on which the change will become effective; and (3) a description of the information relied on to determine the consumer's calculated (i) Annual statement of account The creditor shall provide an annual statement of account that shall include the following to the extent that the terms are part of the income share agreement:

(1) The amounts and dates of every payment made in the preceding 12 months, along with the indication of whether that payment was a “qualifying payment” or “not a qualifying payment” (using those terms).

(2) the dollar total and number of qualifying payments received;

(3) the dollar total and number of payment(s) received that did not constitute a qualified payment;

(4) the dollar total of all payments received;

(5) the dollar total of all fees assessed and the method for calculating the fees;

(6) the number of qualifying payments remaining toward achieving the maximum required payments;

(7) the number of months remaining toward achieving the maximum payment term;

(8) the dollar amount required to prepay all obligations under the income share agreement as calculated under Rule 18(f); and (9) A description of how the prepayment amount and rebate are calculated; and (10) a description of the information relied on to determine the consumer's calculated Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit (j) License application information and notification information In addition to the other license application information that the Administrator requires pursuant to C.R.S. § 5-2-302, creditors who apply for a license to make supervised loans in Colorado and who intend to make supervised loans that meet the definition of income share agreements shall include the following information in their application and shall provide updated information, to the extent it changes, each time they submit a renewal application pursuant to C.R.S. § 5-2-302(8).

(1) an explanation of the manner in which the income share agreement terms used, or to be used, by the creditor in Colorado are drafted to ensure compliance with the finance charge limits set forth in C.R.S. § 5-2-201, regardless of the consumer’s qualified income, prepayment, or other potential factual developments during the course of repayment of the income share agreement;

(2) examples of any income share agreement contracts that the creditor intends to use in Colorado;

(3) examples of any disclosure form that the creditor uses or intends to use in Colorado to meet the requirements of this Rule 18(c); and (4) examples of any disclosure forms that the creditor uses or intends to use in Colorado to meet the requirements of the TILA and Regulation Z.

(k) Record keeping In addition to the recordkeeping requirements of C.R.S. § 5-2-304, C.R.S. § 5-3-109, and Rule 10, the creditor shall retain data and documentation sufficient to demonstrate the manner and methodology used to calculate disclosures required under this Rule 18(b) and 18(c).

Rule 19. Legal Funding Deferral Charges for Consumer Legal Funding Transactions A Legal Funding Deferral Charge for a Consumer Legal Funding Transaction imposed by a creditor pursuant to this rule shall be contracted for and may only be received if the creditor complies fully with this rule. Failure to comply with all provisions of this rule shall mean that the Legal Funding Deferral Charge is not permitted under the UCCC, and the Legal Funding Deferral Charge is not a permitted deferral charge pursuant to C.R.S. § 5-1-301(20)(b) and C.R.S. § 5-2-204(6).

(a) Definitions.

  1. “Advertise” means the attempt by publication, dissemination, solicitation, or circulation, visual, oral, or written, to induce directly or indirectly any person to enter into any Consumer Legal Funding Transaction.

  2. “Associated Legal Claim” means a bona fide civil claim or cause of action the potential proceeds of which are the subject of a Consumer Legal Funding Transaction.

  3. “Consumer Legal Funding Transaction” means a nonrecourse consumer credit transaction as defined in C.R.S. § 5-1-301(12) contracted for in a written agreement between the creditor and consumer structured as an interest-bearing loan with monthly periodic payments that the creditor must collect from the potential proceeds, if any, resulting from the settlement or judgment of the consumer’s Associated Legal Claim.

  4. “Deferral” means the deferral of any periodic payment to a single installment owed at the end of the loan term if the consumer does not pay on the originally scheduled due date.

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit 5. “Legal Funding Deferral Charge” means a charge for a Deferral that a creditor may assess to a consumer with a Consumer Legal Funding Transaction in accordance with this rule.

  1. “Total Cost of Credit” means the original finance charge, any additional finance charge resulting from the Deferral(s), and the Legal Funding Deferral Charge(s).

(b) Scope.

  1. This rule applies to creditors who enter into Consumer Legal Funding Transactions with consumers and charge consumers the Legal Funding Deferral Charge(s).

(c) Process.

  1. Creditors may allow consumers to voluntarily elect to make the Deferral(s) of periodic payments such that a Consumer Legal Funding Transactions has no periodic payments on or before the commencement date of the Consumer Legal Funding Transaction in exchange for a Legal Funding Deferral Charge. The creditor must obtain a written acknowledgement from the consumer that the consumer has elected to make the Deferral.

  2. If a consumer elects to make the Deferral(s), in addition to the disclosures required under C.R.S. § 5-3-101 reflecting the original cost of the credit for the Consumer Legal Funding Transaction structured with periodic payments, the creditor must make, at the time of the election, the following separate disclosure reflecting the additional costs resulting from the Deferral(s) (“Additional Disclosure”). The Additional Disclosure must state the amount financed, the APR corresponding to the finance charge, the Total Cost of Credit, the total of payments, and the payment schedule reflecting a single installment owed at the end of the loan term. The Total Cost of Credit must be itemized listing the original finance charge, any additional finance charge resulting from the Deferral(s), and the total of the Legal Funding Deferral Charge(s), and also disclosed as a lump sum.

  3. The consumer must acknowledge receipt of the Additional Disclosure in writing.

(d) Legal Funding Deferral Charge 1. For Consumer Legal Funding Transactions, if contracted for by the consumer, creditors may charge the consumer Legal Funding Deferral Charge(s). The Legal Funding Deferral Charge shall only be earned after a Deferral when a periodic payment is not paid by the consumer on the originally scheduled due date. The Legal Funding Deferral Charge is not earned at the time of election.

  1. The creditor may charge a Legal Funding Deferral Charge equal to $15.

  2. The Legal Funding Deferral Charge may only be collected by the creditor from the potential proceeds, if any, resulting from the settlement or judgment of the consumer’s Associated Legal Claim.

  3. Creditors may not charge interest on the Legal Funding Deferral Charge(s).

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit (e) Refinance.

  1. If the term of the Consumer Legal Funding Transaction reaches maturity and the Associated Legal Claim has not concluded, the creditor shall offer the consumer the option to refinance the Consumer Legal Funding Transaction. If the consumer elects to refinance, the creditor must fully comply with this rule, including by issuing a new Additional Disclosure.

(f) Prepayment.

  1. The consumer may prepay the Consumer Legal Funding Transaction, in full or in part, either from the proceeds of the Associated Legal Claim or otherwise, at any time without penalty.

(g) Prohibited Acts.

  1. A creditor that enters into a Consumer Legal Funding Transaction with a consumer shall not:

i. pay or offer to pay a commission, referral fee, rebate, or other form of consideration to any attorney, law firm, medical provider, chiropractor, or physical therapist or to any employee thereof, in exchange for referring a consumer to the creditor;

ii. accept a commission, referral fee, rebate, or other form of consideration from any attorney, law firm, medical provider, chiropractor, or physical therapist or to any employee thereof;

iii. advertise materially false or misleading information regarding the company’s products or services;

iv. (A) except as provided in subsection (g)(1)(iv)(B) of this section, refer a consumer or a potential consumer to a specific attorney, law firm, medical provider, chiropractor, physical therapist in furtherance of a Consumer Legal Funding Transaction. (B) if a consumer needs legal representation, a creditor may refer the consumer to a local or state bar association referral service.

v. fail to supply a copy of the executed contract for the Consumer Legal Funding Transaction to the consumer’s attorney for the Associated Legal Claim, the potential proceeds of which are the subject of the Consumer Legal Funding Transaction.

vi. (A) except as provided in subsection (g)(1)(vi)(B) of this section, knowingly provide a Consumer Legal Funding Transaction to a consumer who has previously assigned or sold to another creditor a portion of the consumer’s right to proceeds from the Associated Legal Claim without first reimbursing the other creditor for its entire funded amount and the Legal Funding Deferral Charge(s), unless another amount is agreed to in writing by the creditors. (B) multiple creditors may be parties to a Consumer Legal Funding Transaction if the consumer and the consumer’s attorney consent to the arrangement in writing.

vii. make or influence any decisions by the court or by the parties with respect to a pending Associated Legal Claim or any settlement or resolution of an Associated Legal Claim;

Administrator of the Uniform Consumer Credit Code and Commission on Consumer Credit viii. pay or offer to pay for court costs, filing fees, attorneys’ fees, or other court costs related to the litigation, settlement, or resolution of the Associated Legal Claim using fund from the Consumer Legal Funding Transaction;

ix. report a consumer to a credit reporting agency if insufficient funds remain from the net proceeds from the Associated Legal Claim to repay the creditor; or x. collect any prepaid finance charges;

xi. charge any fees in addition to the Legal Funding Deferral Charge(s), including but not limited to late fees or insufficient funds fees. _________________________________________________________________________ Editor’s Notes

History Rules 10, 16 eff. 08/01/2007.

Rules 14, 16 eff. 01/01/2008.

Rule 14 eff. 10/01/2008.

Rules 2, 3, 4, 6, 8, 9, 10, 13 eff. 07/30/2009. Rule 14 repealed eff. 07/30/2009.

Rules 10 a (7), 10 a (17-20), 16 (1st un-numbered paragraph), 17 eff. 11/29/2010.

Rule 18 eff. 11/30/2023.

Rules 8(n), 10, 19 eff. 09/14/2024.

4 CCR 902-2 Uniform Debt-Management Services Act Rules {#sec-4-ccr-902-2 omnilex-key=us-co-regs-official--department-11--4 CCR 902-2}

DEPARTMENT OF LAW

Administrator-Uniform Consumer Credit Code and Commission on Consumer Credit UNIFORM DEBT-MANAGEMENT SERVICES ACT RULES 4 CCR 902-2 [Editor’s Notes follow the text of the rules at the end of this CCR Document.] _________________________________________________________________________

Rule 1 Fee Schedule The fees for debt management service providers shall be those listed below.

Registration fees are payable by fiscal year from July 1 to June 30. Registration fees are not pro-rated for

part of a year nor are they refundable. Registration fees are assessed per provider, rather than per business location.

Fee Amount Initial Registration Fee [§ 5-19-205] $1,000/fiscal year Renewal Registration Fee [§ 5-19-211] $1,000/fiscal year Examination Fee [§ 5-19-232] $60/hour plus reasonable and actual travel costs

Rule 2 Adjustment of Dollar Amounts – Consumer Price Index (a) The base year for adjustment of dollar amounts to reflect inflation shall be the 2007 Consumer Price Index for all Urban Consumers (CPI-U), U.S. City Average, 1982-84 = 100, All Items, Annual data (not seasonally adjusted) issued by the United States Bureau of Labor and Statistics.

If the CPI-U is revised after 2007, the percentage of change shall be calculated on the basis of the revised index.

Rule 3 Insurance Cancellation Notice (a) Any insurance policy submitted by a provider as evidence of insurance required by § 12-14.5- 205(b)(4), C.R.S. shall include the insurer’s written agreement to provide the Administrator with written notice of termination or reduction of the policy. On or before July 30, 2008, providers that previously submitted insurance policies shall supplement the policy by filing with the Administrator the insurer’s written agreement to provide written notice of termination or reduction.

(b) The written notice of termination or reduction of the policy shall be sent by certified U.S. mail to the Administrator, Uniform Consumer Credit Code, 1525 Sherman St., 7th Floor, Denver, CO 80203, or the most current address for the Administrator.

(c) The insurer’s termination or reduction of liability shall be effective from and after the expiration of thirty days from the Administrator’s receipt of such written notice or on such later date as is stated in the written notice. The insurer’s termination or reduction of liability shall not affect, reduce, or release its liability for any acts or practices that occurred during the time the policy was in force and prior to the effective date of termination or reduction of the policy.

Administrator-Uniform Consumer Credit Code and Commission on Consumer Credit

Rule 4. Fees Charged to Consumers for Debt-Management Services (a) A provider may not request or receive payment of any fee or consideration until and unless:

  1. The fee or consideration either: Bears the same proportional relationship to the total fee for settling the terms of the entire debt balance as the individual debt amount bears to the entire debt amount, in which case the individual debt amount and the entire debt amount are those owed at the time the debt was enrolled in the service; or is a percentage of the amount saved as a result of the settlement. The percentage charged cannot change from one individual debt to another. The amount saved is the difference between the amount owed at the time the debt was enrolled in the plan and the amount actually paid to satisfy the debt.

(b) Except as otherwise provided section 5-19-228 (d), if an individual does not assent to an agreement, a provider may receive for educational and counseling services it provides to the individual a fee not exceeding one hundred dollars or, with the approval of the administrator, a larger fee. The administrator may approve a fee larger than one hundred dollars if the nature and extent of the educational and counseling services warrant the larger fee.

  1. If, before the expiration of ninety days after the completion or termination of educational or counseling services, an individual assents to an agreement, the provider shall refund to the individual any fee paid pursuant to subsection (d)(4) of this section. _________________________________________________________________________ Editor’s Notes

History New rule eff. 03/30/2008.

Rules 2, 3 eff. 07/30/2008.

Rule 4 eff. 03/30/2025.

4 CCR 902-3 Colorado Student Loan Equity Act Rules {#sec-4-ccr-902-3 omnilex-key=us-co-regs-official--department-11--4 CCR 902-3}

DEPARTMENT OF LAW

Administrator – Uniform Consumer Credit Code COLORADO STUDENT LOAN SERVICERS ACT RULES 4 CCR 902-3 [Editor’s Notes follow the text of the rules at the end of this CCR document] _________________________________________________________________________

Rule 1. Nonrefundable Initial and Annual Renewal License Fees for Student Loan Servicers The amount of the initial license fee for a license commencing January 31, 2020 for a student loan servicer is $12,500. The amount of the annual renewal fee is $12,500. The amount of the initial license fee and the annual renewal fee may be reduced or increased periodically based upon the Administrator’s determination of anticipated changes to the cost of administering the Student Loan Servicer Act.

Rule 2. Nonrefundable Investigation Fee The investigation fee for a student loan servicer, applicant for licensure pursuant to section 5-20-106(2), C.R.S. is $500 and must be paid only at the time of and in conjunction with the initial license application.

Rule 3. Federal Contractor Exemption A student loan servicer seeking licensure pursuant to section 5-20-106(1), C.R.S., shall document eligibility for the exemption by submitting at least one of the following documents:

A. The signed signature page to a currently operative contract showing that the servicer is a party to a contract awarded by the United States Secretary of Education under 20 U.S.C. § 1087f; or B. Any other document that serves as the functional equivalent to (A), which will be judged in the Administrator’s sole discretion.

Rule 4. Nonrefundable Registration Fees for Private Education Lenders The amount of the registration fee for a private education lender is $1500. The amount of the registration fee may be reduced or increased periodically based upon the Administrator’s determination of anticipated changes to the cost of administering Part 2 of the Colorado Student Loan Equity Act.

Rule 5. Registration Documents and Information Due Date The documents and information required for registration in section 5-20-203(2)(b), C.R.S. shall be provided to the Administrator with the registration fee and annually thereafter on or before September 1.

A. [Expired 05/15/2023 per Senate Bill 23-102]

Administrator – Uniform Consumer Credit Code

Rule 6. Alternative Registration Process and Fee Structure for Public and Private Nonprofit Postsecondary Educational Institutions A public or private nonprofit postsecondary educational institution may alternatively register with the Administrator by submitting a registration fee of $300 and providing the following documents and information by September 1 each year:

A. the volume of private education loans made annually by the public or private nonprofit postsecondary educational institution to private education loan borrowers in Colorado;

B. the default rate for private education loan borrowers in Colorado obtaining private education loans from the public or private nonprofit postsecondary educational institution;

C. a copy of each model promissory note, agreement, contract, or other instrument used by the public or private nonprofit postsecondary educational institution during the previous year to substantiate that a private education loan has been extended to a private education loan borrower or that a private education loan borrower owes a debt to the public or private nonprofit postsecondary educational institution;

D. for a private nonprofit postsecondary educational institution, documentation that establishes that it is a private nonprofit postsecondary educational institution, to be evaluated in the Administrator’s discretion. _________________________________________________________________________ Editor’s Notes

History New rule eff. 11/14/2019.

Rules 4, 5, 6 emer. rules eff. 07/30/2021; expired 11/27/2021.

Rules 4, 5, 6 eff. 01/30/2022.

Annotations

Rule 5.A. (adopted 12/21/2021) was not extended by Senate Bill 23-102 and therefore expired 05/15/2023.

903 Administrator of the Uniform Consumer Credit Code

4 CCR 903-1 Colorado Fair Debt Collection Practices Act Rules {#sec-4-ccr-903-1 omnilex-key=us-co-regs-official--department-11--4 CCR 903-1}

DEPARTMENT OF LAW

COLORADO FAIR DEBT COLLECTION PRATICES ACT RULES

4 CCR 903-1 [Editor’s Notes follow the text of the rules at the end of this CCR Document.] _________________________________________________________________________ Scope of Rules These rules apply to all collection agencies and debt collectors, whether or not exempt from licensing under the Colorado Fair Debt Collection Practices Act, unless the rule is limited to “licensees” or “applicants.” The words “client” and “creditor” have the same meaning throughout these rules.

Chapter 1 Licensing and Disciplinary Matters

Rule 1.01 Collections Manager (1) Whenever an applicant or licensee designates a new collections manager, it shall notify the Administrator by filing a collections manager application form. The collections manager shall meet the qualifications of sections 5-16-119, 5-16-123(2), and the other applicable provisions of the Colorado Fair Debt Collection Practices Act.

(2) Pursuant to section 5-16-122(3)(a), C.R.S., an application filed due to a change of collections manager shall be filed within thirty days of the change. The temporary absence of an approved collections manager does not constitute a change requiring designation of a new manager.

(3) Repealed

Rule 1.02 Licensure (1) No license shall issue until all necessary documents and information have been filed, all fees paid, and the designated collection manager's qualifications to collect debts has been determined. No debts may be collected nor creditor accounts solicited until a license has been issued.

(2) Within sixty-three (63) days after notice from the Administrator that the application is incomplete, the applicant must complete the application for licensure by providing all necessary documents, information, and fees specified. If the licensure application is not completed within that time, the application shall be null and void and the applicant must then reapply for licensure, including payment of all fees.

Rule 1.03 Aliases (1) Licensees must retain records reflecting the true name of all debt collectors and, if applicable, the one alias used by each debt collector. These records shall be retained for two (2) years after the debt collector leaves the licensee's employment. The Administrator may require a licensee to submit these records at any time.

(2) No debt collector may use more than one alias. The alias must consist of both a first and last name. Debt collectors employed by a licensee may not use the same alias.

Rule 1.04 Letters of Admonition (1) Any letter of admonition issued against a licensee or collections manager shall be mailed by firstclass certified mail or emailed to the general mailings contact provided in the licensee’s most recent renewal application.

(2) A licensee or collections manager receiving a letter of admonition may appeal the admonishment by filing a written request within forty-two (42) days after the date of the letter. Upon receipt of a timely appeal, a hearing will be held. While an appeal is pending, the letter of admonition shall be vacated until conclusion of a hearing held pursuant to Rule 1.04(3).

(3) Any hearing held following a request to appeal the issuance of a letter of admonition shall be conducted pursuant to the State Administrative Procedure Act, title 24, article 4, of the Colorado Revised Statutes. If a violation of the Colorado Fair Debt Collection Practices Act, the rules adopted pursuant thereto, or a lawful order has occurred, or the licensee fraudulently obtained a license, the licensee, collections manager, or both, as applicable, may be disciplined as provided in section 5-16-127(10), C.R.S.

Rule 1.05 Termination of License (1) Upon the revocation, expiration, or surrender of a license, the licensee must immediately cease collection activities. All client accounts must be returned to the clients within thirty-five (35) days unless the licensee has written authorization from the client to transfer or assign the accounts to another collection agency for collection. No later than the end of the thirty day period, the licensee must file a notarized affidavit with the Administrator stating its compliance with this rule and providing the names and addresses of all clients for whom it was attempting to collect debts.

(2) The licensee shall not charge or retain any fee or commission for the return or transfer of client accounts made pursuant to Rule 1.05(1).

(3) All consumer payments received after the revocation, expiration, or surrender of a license shall be immediately forwarded in full to the applicable client without the licensee's retention of any fee or commission.

(4) This rule does not prohibit the bulk sale of the licensee's business, assets, and goodwill as a unit, including the provision of information to enable the purchaser to solicit reassignment of client accounts directly from the client after termination of a license.

(5) This rule does not apply to any license voluntarily surrendered in conjunction with the simultaneous issuance of a new license due to any of the changes listed in section 5-16- 122(2)(c), C.R.S.

Rule 1.06 License Renewals Collection agency licenses shall be valid from the date of issuance to the following July 1. In order to renew its license, a licensee must file its completed renewal application and renewal fee on or before July 1 of each year or its license shall automatically expire.

Rule 1.07 Address Changes A collection agency’s obligation to provide written notice to the administrator within thirty days after an address change pursuant to section 5-16-122(1)(a), C.R.S. applies to both the local Colorado office and the principal place of business printed on the collection agency’s license, and may be provided by electronic mail, U.S. mail, or any other delivery method.

Rule 1.08 Abbreviated Applications (1) A licensee filing an abbreviated license application upon a change of ownership structure pursuant to section 5-16-122(2)(c)(III), C.R.S. is not required to submit the following:

(a) Investigation fee;

(b) List of currently employed debt collectors and solicitors;

(c) License verification forms from other states that license the applicant; and, (d) If there has been no change in any of the documentation on file with the administrator:

(i) Personal affidavits of owners, officers, members/managers, and partners;

(II) Collections manager application; and (iii) List of branch offices.

Rule 1.09 Local Colorado Office (1) A collection agency may satisfy the local Colorado office requirement of section 5-16-123(1)(b), C.R.S. by contracting with a third-party if the third-party:

(a) maintains an office in Colorado open to the public during normal business hours that may be a shared office location if signs or directories are posted or displayed listing all collection agencies for whom the third-party provides a local Colorado office;

(b) maintains at that office records, or free and easy access to records, of all moneys collected and remitted for Colorado residents;

(c) accepts payments physically made at that office for any debt the agency is attempting to collect;

(d) staffs that office with a full time employee who may be a shared employee;

(e) provides a telephone number that may be a shared telephone number, that rings to the local Colorado office, and is answered in a manner that does not mislead consumers; and, (f) complies with all applicable provisions of the Colorado Fair Debt Collection Practices Act.

(2) A collection agency that uses a third-party to provide a local Colorado office is responsible for actions of the third-party that violate the Colorado Fair Debt Collection Practices Act.

Chapter 2 Consumer Protections

Rule 2.01 Notices (1) The consumer rights information required to be in the initial written communication and the validation of debts notice may be printed on two (2) separate pages provided that the first page contains language referring the consumer to the second page and the two (2) pages are attached together.

(2) Every collection notice mailed or delivered by a licensee must contain the collection agency's name, mailing address, toll-free telephone number, and the address and telephone number of its local Colorado office. The collection agency's address(es) may not be printed only on any portion of the collection notice designed to be returned to the agency with the consumer’s communication or payment. “Toll-free” means a call made at no cost to the consumer.

Rule 2.02 Payment Agreements and Schedules No collection agency shall engage in unnecessary, additional collection activities on a debt while a consumer is complying with the terms of a payment agreement or schedule agreed to by the collection agency and consumer concerning that debt.

Rule 2.03 Costs of Collection (1) No collection agency shall add, collect, or attempt to collect a charge for costs of collection unless such costs are expressly authorized by statute or by the contract, agreement, note, or other instrument creating the debt and are not otherwise prohibited by law.

(2) No licensee shall advise, suggest, or request that a client add collection costs to any existing debt unless such costs are specifically authorized by statute or by the contract, agreement, note, or other instrument creating the debt and that are not otherwise prohibited by law.

(3) If a statute, contract, agreement, note, or other instrument specifically authorizes the addition of collection costs and such costs are collected, the licensee may retain only those collection costs exclusive of attorney fees and court costs as its fee or commission for the collection of the debt, unless otherwise agreed to in writing with the assignor.

(4) No collection agency shall add, collect, or attempt to collect costs of collection pursuant to §13- 21-109(1)(b) (II), C.R.S. on any dishonored check, draft, or payment order payable to it unless the check is assigned for collection to another collection agency not owned in whole or in part by the payee collection agency.

Rule 2.04 Overpayment If a collection agency has received final payment of any debt which overpays the debt by more than five dollars ($5.00), it shall issue a refund to the consumer of the amount of the overpayment within thirty-five (35) days after the end of the month in which the payment was received unless otherwise required by law or as directed by court order.

Rule 2.05 Cash Payments A collection agency shall provide the consumer with a receipt for all payments made in cash or by any other means which does not in and of itself provide evidence of payment. The receipt shall be provided to the consumer within seven (7) days after the payment is received.

Rule 2.06 Account Statements (1) Subject to the payment record retention requirements of Rule 3.03, a collection agency shall provide the consumer with a written statement of the consumer’s payments for as long as the collection agency has had assignment of the debt within fourteen (14) days after the consumer makes a written request. The statement shall include the consumer’s name, the creditor’s name, the amounts paid, the dates on which payments were received, the allocation of each payment to, as applicable, principal, interest, court costs, attorney fees, other costs, the interest rate, and the current balance due. Account statements shall be provided upon request without charge once during any twelve (12) month period. If additional statements are requested, they may be provided upon payment of a reasonable fee not to exceed ten dollars ($10.00) per statement.

(2) After a debt has been paid or settled in full, a collection agency shall provide a written statement or receipt that the debt has been paid or settled in full within fourteen (14) days after request by the consumer. Such a statement shall be provided free of charge.

Rule 2.07 Consumer Communication Records Collection agencies shall maintain accurate summaries or records of all communication in connection with the collection or attempted collection of a debt with consumers, a consumer’s attorney or representative, the consumer’s employer, consumer reporting agencies, and persons contacted to obtain location information, for two (2) years following the date of the communication. If the collection agency records calls, the call recordings must be retained for two (2) years, in an accessible format upon request by the Administrator. Where summaries and records are both kept, both must be accurate.

Rule 2.08 Business Cards (1) No collection agency shall use a business card in obtaining or attempting to obtain location information about a consumer or in communicating or attempting to communicate with a consumer unless:

(a) The business card does not indicate in any way that the collection agency is in the business of collections or is attempting to collect a debt, or, (b) The business card is placed in a sealed envelope which contains the consumer's name and does not indicate by means of name, symbol, or any marking, that the envelope is from a collection agency.

Rule 2.09 Attorney Letters (1) During the time that a licensee is in possession of a creditor account, the licensee shall not use or deliver any communication from an attorney unless the creditor has previously provided specific written authorization to commence legal action to collect the debt, which may be provided in electronic form so long as the licensee maintains a contemporaneous record of such authorization.

(2) This rule does not prohibit any direct communication from an attorney if the attorney is authorized to collect the debt.

Rule 2.10 Dual Collections No collection agency may knowingly collect a debt that is being collected by another collection agency or attorney.

Rule 2.11 Office Location A collection agency may share an office location with another business as long as signs, directories, and other business identification information clearly contain the collection agency's name.

Rule 2.12 Consumer Payments (1) All accepted consumer payments must be credited to a consumer's account to reflect payment on the day payment was received unless the payment is by postdated check. Post-dated checks shall be credited to the consumer's account to reflect payment as of the date of deposit in the collection agency's trust account.

(2) This rule does not prohibit subsequent adjustments to a consumer's account to reflect dishonored checks, drafts, or other payment instruments.

Rule 2.13 Checks Not Paid Upon Presentment A collection agency collecting a check draft, or order not paid upon presentment shall send the consumer its validation of debts notice required by section 5-16-109, C.R.S. at least fifteen (15) days prior to the mailing or service of the notice of nonpayment required by §13-21-109(2)(a) and (3), C.R.S.

Rule 2.14 Payment Authorization by Telephone (1) If a consumer's authorization for payment of a debt is provided orally, the licensee must also:

(a) Obtain the consumer's written authorization for the payment prior to the date of payment, or (b) If permitted by law, record by audio tape or other digital means the consumer's verbal authorization and retain the recording, or (c) Transfer the consumer's telephone call to a manager or another debt collector to verify the amount, means, and verbal authorization for payment.

(2) If a consumer denies or disputes the purported oral payment authorization, the collection agency must refund the payment amount within seven (7) days of receipt of good funds.

Rule 2.15 Disclosure of Contact Information Upon the request of a consumer or person contacted for location information, a licensee shall provide the address of its principal place of business and mailing address, its toll-free telephone number, and the address and telephone number of its local Colorado office.

Rule 2.16 Debt Collector Obligations Except as otherwise provided, all references in this Chapter 2 to collection agencies shall apply to debt collectors.

Chapter 3 Creditor Protections

Rule 3.01 Trust Accounts (1) A licensee shall maintain the trust account required by section 5-16-123(1)(c), C.R.S., but need not maintain the account in a Colorado bank or financial institution if the licensee maintains one or more trust accounts in other states for the benefit of its clients, including its Colorado clients, and it executes and files annual written authorization with the Administrator on an approved form acknowledging the account(s) may be attached upon order of a Colorado court.

(2) If any of the trust account information in a licensee's license or renewal application changes, the licensee must file a new bank authorization form within thirty-five (35) days of the date of the change.

(3) No trust account is required if the licensee does not receive nor have access to any consumer payments because they are made directly to the client according to all of the licensee's contracts or agreements.

(4) A licensee, other than one that only collects debts it owns, shall maintain in its trust account the minimum liquid assets referred to in section 5-16-123(1)(a), C.R.S.

Rule 3.02 Unidentified Accounts (1) If a licensee receives a consumer payment but is unable to identify the client account on whose behalf the payment is made, the licensee shall return the entire payment to the consumer within thirty-five (35) days after the end of the month in which the payment was received.

(2) No amount may be retained by a licensee as fee or commission from any consumer payment made on an unidentified account.

(3) If a licensee is able to identify, but cannot locate, a client on whose behalf payment is made, the licensee shall comply with applicable state laws on unclaimed property.

Rule 3.03 Payment Records (1) Licensees shall maintain a record of all consumer payments for two (2) years following the date the payment was received.

(2) Records of consumer payments shall include the consumer's name, the client's name, the amounts paid, the dates on which payments were received, the allocation of each payment to, as applicable, principal, interest, court costs, attorney fees, other costs, the interest rate, the current balance due, and the date of deposit of the payment to the trust account.

Rule 3.04 Bonds (1) The bond required of each licensee shall be in the form and manner prescribed by statute, and shall be filed with the Administrator.

(2) As an alternative to the bond, a licensee may present a savings account, deposit, or certificate of deposit.

(a) The savings account, deposit, or certificate of deposit shall be in a federally insured bank or savings and loan association doing business and located in this state or accessible in a branch in this state.

(b) The savings account, deposit, or certificate of deposit shall be assigned to the Attorney General of the State of Colorado for the use of the People of the State of Colorado in the form and manner prescribed by the Administrator. The assignment shall be for a period ending two (2) years after the revocation, expiration, or surrender of a license or on such earlier date as may be determined by the Administrator.

(c) As far as practical, the procedure used to determine claims against a bond shall be used for claims against a savings account, deposit, or certificate of deposit.

Rule 3.05 Return of Accounts (1) If a licensee may retain accounts in the process of collection, as defined in section 5-16-124(6), C.R.S., it must disclose that information to its clients at the time it initially accepts accounts for collection.

(2) This Rule 3.05 takes effect May 1, 2009 and applies to all of the licensee’s current and future clients.

Rule 3.06 Licensee Obligations Except as otherwise provided, all references in this Chapter 3 to licensees shall apply to applicants. _________________________________________________________________________

Editor's Notes

History Rules 1.01, 1.02, 1.06 - 2.01, 2.03, 2.06, 2.07, 2.15 - 3.06, SB&P eff. 11/1/2008.

Rules 1.07, 1.09, 2.01, 2.11, 2.15 eff. 07/30/2010.

Rules 1.02(2), 1.04, 1.05(1), 1.05(4), 1.07, 2.03(2), 2.04-2.07, 2.09(1), 2.14(2), 2.15, 3.01(2), 3.02(1) eff. 06/30/2021.

4 CCR 903-2 Rules of the Administrator, Collection Agency Board for Private Child Support Collectors {#sec-4-ccr-903-2 omnilex-key=us-co-regs-official--department-11--4 CCR 903-2}

DEPARTMENT OF LAW

Collection Agency Board RULES OF THE ADMINISTRATOR, COLLECTION AGENCY BOARD FOR PRIVATE CHILD SUPPORT COLLECTORS 4 CCR 903-2 [Editor’s Notes follow the text of the rules at the end of this CCR Document.] _________________________________________________________________________

Rule 1 Scope of Rules These rules apply to private child support collectors as defined in section 5-17-102(9)(a), C.R.S. of the Colorado Child Support Collection Consumer Protection Act and supplement the rules adopted by the Administrator, Colorado Collection Agency Board, implementing the Colorado Fair Debt Collection Practices Act.

Rule 2 Notice of Obligee’s Rights (a) The notice required by section 5-17-106(2), C.R.S. must be conspicuous, in bold type face at least as large as the type size used for other contract terms, included in or attached to the private child support enforcement contract prior to the space for the obligee’s signature agreeing to the contract terms, and read as follows:

Child support collection services are offered at low or no cost through government child support collection services in every county in Colorado and in every state. A state agency may provide services that we cannot provide, such as driver’s license suspension and tax refund intercepts.

We cannot require a government child support collection service to send payments to any person but you.

We will not provide legal advice or act as your attorney. If we hire an attorney to assist in collections, you will not have to pay any additional fees.

You have the right to receive a monthly accounting of payments collected, the fees we have charged, and the amount still due.

You have certain rights to cancel this contract. See the contract for cancellation terms and the “Notice of Cancellation” provided with this contract.

You have the right to sue us if we violate the law. You also have the right to file a complaint with the Administrator of the Collection Agency Board in the Colorado Attorney General’s Office. For more information about private child support collection or to file a complaint visit http://www.ago.state.co.us/CADC/CADCmain.cfm.

You may have this contract reviewed by an attorney of your choice before you sign it.

(b) If the Web site address listed in subsection (a) above becomes outdated, private child support collectors must print in their notice the current Web site address.

Collection Agency Board (c) A private child support collector may substitute its name for the words “we”and “us”in the notice described above in subsection (a).

Rule 3 Accounting (a) In addition to the information required by section 5-17-107(1), C.R.S., a private child support collector’s monthly accounting to the obligee must include:

  1. The specific dollar amount to be collected according to the contract;

  2. The date and amount of any child support collected by the private child support collector in the prior month, which amount collected shall be listed as both a gross amount and also itemized and described as principal, interest, and other fees as applicable and if allowed by law;

  3. The amount due to the obligee from the prior month’s collections, the amount actually paid to the obligee from the prior month’s collections, and the date of payment;

  4. The amount retained by the private child support collector pursuant to the contract with a description of how that amount was calculated, such as by providing the specific percentage amount or dollar amount contracted for; and, 5. A running total since the inception of the contract of the amount collected by the private child support collector, the amount it has paid to the obligee, and the remaining balance.

(b) Unless a shorter timeframe is required by applicable state or federal law, a private child support collector shall deliver to the obligee any payment due under the contract and the monthly accounting no later than by the tenth day of the month following receipt of the payment. The accounting shall be provided monthly, whether or not the private child support collector has collected any payments in the prior month.

STATEMENT OF BASIS, SPECIFIC STATUTORY AUTHORITY, AND PURPOSE

The basis, specific statutory authority, and purpose of these rules are to implement section 5-17-113, C.R.S. That section requires the Administrator of the Collection Agency Board (and of the Uniform Consumer Credit Code in the Colorado Attorney General’s Office) to adopt rules under the Colorado Child Support Collection Consumer Protection Act (Act) on notices to obligees and accounting. The Act was passed as House Bill 06-1066, took effect July 1, 2006, and is codified at section 5-17-101 et seq., in the Colorado Revised Statutes. The Act applies to private child support collectors. _________________________________________________________________________ Editor’s Notes

History

904 Attorney General-Consumer Protection Section

4 CCR 904-1 Repossessor Bonds {#sec-4-ccr-904-1 omnilex-key=us-co-regs-official--department-11--4 CCR 904-1}

DEPARTMENT OF LAW

Attorney General - Consumer Protection Unit REPOSSESSOR BONDS 4 CCR 904-1 [Editor’s Notes follow the text of the rules at the end of this CCR Document.] _________________________________________________________________________ FILING WITH THE ATTORNEY GENERAL 1. A repossessor wishing to file a surety bond in accordance with the provisions of § 4-9-629, CRS (hereinafter “applicant” ) shall submit the following items to the Colorado Attorney General, Consumer Protection Unit, 1525 Sherman Street, 7th Floor, Denver, CO 80203:

a. Completed original Application for Repossessor Bond. Such application, on a form approved by the Colorado Attorney General, shall request general information including, but not limited to, trade names, business address, individual owners, registered agents, surety company, etc.

b. Original fully executed surety bond in the amount of $50,000.00 (Fifty Thousand Dollars) drawn in favor of the Colorado Attorney General. The surety bond shall be on a form approved by the Colorado Attorney General.

c. Non-refundable filing fee in an amount approved by the Colorado Attorney General, payable to the Colorado Attorney General.

  1. The Colorado Attorney General shall promptly notify applicant that its repossessor application materials have been received. Such notification shall designate whether the materials (application, bond, filing fee) comply with the applicable rules and statutory requirements.

  2. A repossessor bond shall be deemed filed with the Colorado Attorney General pursuant to § 4-9- 629, CRS when the Colorado Attorney General receives application materials which comply with rules 1 a-c above.

  3. If information contained in a filed application for repossessor bond form becomes outdated or inaccurate, the bonded repossessor shall, within thirty (30) days, submit the new information to the Colorado Attorney General on a revised application. Said revised application shall be on a form approved by the Colorado Attorney General.

CONTINUATION OF REPOSSESSOR BOND

  1. A repossessor who has filed a surety bond with the Colorado Attorney General and wishes such bond to remain effective must annually notify the Colorado Attorney General that the bond remains in full force and effect.. Such notification shall be on a form approved by the Colorado Attorney General, shall be accompanied by a filing fee in an amount approved by the Colorado Attorney General and shall be received by the Colorado Attorney General annually, on or before the anniversary of the original surety bond filing date. Provided further that:

a) Bonds that are issued due solely to the change in name of a repossessor may be continued under this provision so long as the new bond is reissued under the repossessor’s new name and the bond has the same terms as the prior bond. The repossessor must provide notification to the Attorney General within 30 (thirty) days of the issuance of the new bond. If there has been a change in ownership or corporate structure of the repossessor, a new bond must be filed in accordance with the provisions of paragraph 6 below.

b) If the bond sought to be continued has expired, it may be continued under the provisions of this paragraph so long as:

(i) The bond has been reinstated;

(ii) The bond has not lapsed more than 60 (sixty) days; and (iii) The terms of reinstatement include coverage for the period of time during which the bond was lapsed.

c) All other new or reinstated bonds must be processed as new bonds under the provisions of paragraph 6 below.

  1. If a new surety bond is executed on behalf of a bonded repossessor to continue or replace an existing bond, the repossessor shall file the new surety bond with the Colorado Attorney General in accordance with rules 1 a-c above.

CLAIMS AGAINST BONDED REPOSSESSORS

  1. Any person claiming damages or loss caused by the conduct of a bonded repossessor acting in the course of recovering or taking possession of collateral may individually commence appropriate legal action against the bonded repossessor and its surety. For the purpose of these rules, a bonded repossessor is a person or business entity that has complied with the provisions of these rules.

  2. In the event a person obtains a final judgment from a court of competent jurisdiction or through binding arbitration against a bonded repossessor for damages referred to in rule 7 above, and the bonded repossessor fails to satisfy the judgment within thirty (30) days of when the judgment becomes final, the Colorado Attorney General will assist said person pursuant to rules 9 and 10 below for the purpose of seeking full satisfaction of judgment. Said person shall first notify the Colorado Attorney General of the judgment and failure to satisfy the judgment, and submit to the Colorado Attorney General a copy of the certified judgment.

  3. The aforementioned involvement by the Colorado Attorney General shall include:

a. Providing written notice to the surety that a judgment against a bonded repossessor has been obtained; and b. Presentation of a copy of the judgment; and c. Providing a written demand for satisfaction of the judgment by the surety.

  1. If the judgment is not satisfied by the surety within a specified period not to exceed thirty (30) days, the Colorado Attorney General may commence a lawsuit against the surety to recover the amount of the judgment, interest, costs and attorney fees.

TERMINATION OF SURETY'S OBLIGATION

  1. The surety may terminate its obligation under the bond only by giving the bonded repossessor and the Colorado Attorney General written notice of such termination, in accordance with the requirements provided by § 10-4-109.7, C.R.S., addressed to the bonded repossessor and the Colorado Attorney General, Consumer Protection Unit, 1525 Sherman Street, 7th Floor, Denver, CO 80203.

  2. Surety's obligation will not terminate with respect to liability that arises before the effective date of termination.

  3. After giving such notice of termination, if the surety wishes to continue to serve as a surety for the repossessor, a new bond, rider or certification of reinstatement must be duly executed and filed with the Colorado Attorney General in accordance with these rules.

ATTORNEY GENERAL FILES

  1. The Colorado Attorney General shall maintain official files for all bonded repossessors in Colorado.

Said files shall be open for inspection by the public during regular business hours and shall be available upon written request and payment of photocopying fees determined by the Colorado Attorney General.

AG Alpha No. LW CP ZFTBC AG File No. DEN8903686/3NH _________________________________________________________________________ Editor’s Notes

History Entire rule eff. 10/30/2007.

4 CCR 904-2 Investigative Hearing Rules {#sec-4-ccr-904-2 omnilex-key=us-co-regs-official--department-11--4 CCR 904-2}

DEPARTMENT OF LAW

Consumer Protection Section INVESTIGATIVE HEARING RULES 4 CCR 904-2 [Editor’s Notes follow the text of the rules at the end of this CCR Document.] _________________________________________________________________________ The following non-exhaustive list of rules shall govern Investigative hearings conducted by the Office of the Attorney General, pursuant to the Colorado Consumer Protection Act, C.R.S. § 6-1-108(1), and the Colorado Antitrust Act, C.R.S. § 6-4-110(1)(b).

A. Investigative Hearings – Form. Investigative Hearings, conducted by the Attorney General, may be conducted in the form of a deposition, under oath, at the sole discretion of the Attorney General. Investigative Hearings may be conducted in-person, over the phone, or through videoconferencing technology, at the sole discretion of the Attorney General. Unless otherwise stated in C.R.S. §§ 6-1-108 and 6-4-110, such Investigative Hearings are not subject to the Colorado Rules of Civil Procedure.

B. Who May Conduct Investigative Hearings. The Attorney General, at its sole discretion, may designate which personnel will conduct Investigative Hearings, ask questions, and state objections during such hearings. The Attorney General expressly prohibits counsel representing a witness during Investigative Hearings from asking questions during such hearings absent express consent from the Attorney General.

C. Who May Attend Investigative Hearings. Absent the Attorney General’s express consent, attendance at the Investigative Hearing shall be limited to the witness and his or her counsel; any employees and unpaid personnel of the Attorney General; any experts retained by the Attorney General; any court reporter, videographer, stenographer, or other person designated to produce a record of the Investigative Hearing by the Attorney General; and employees and unpaid personnel of state and federal law enforcement agencies designated by the Attorney General.

D. Investigative Hearings of Entities. The Attorney General may issue subpoenas to any for-profit or non-profit corporation or partnership or association or governmental entity to produce witnesses to appear and give oral testimony at Investigative Hearings. The subpoenas may designate with reasonable particularity the matters on which examination is requested. In response to such subpoenas, the entity must designate one or more officers, directors, or managing agents, or designate other persons to testify on its behalf. Unless a single individual is designated by the entity, the entity must designate in advance and in writing the matters on which each designee will testify. The persons designated must testify about information known or reasonably available to the entity and their testimony shall be binding upon the entity.

E. Recording of Investigative Hearings. The Attorney General may, at its sole discretion, direct that the testimony be transcribed by a certified court reporter and recorded by audio, audiovisual, or other means.

F. Permissible Objections. Any objection during an Investigative Hearing shall be stated concisely and in a non-argumentative and non-suggestive manner. An instruction not to answer may be made during an Investigative Hearing only when necessary to preserve a legally recognized privilege.

Consumer Protection Section G. Length of Investigative Hearings. Investigative Hearings are not subject to the time limitations described in C.R.C.P. 30(d)(2)(A) or the Federal Rules of Civil Procedure. An Investigative Hearing shall be continuing for a reasonable amount of time unless and until the Attorney General specifies that it has ended.

H. Number of Investigative Hearings. The Attorney General may conduct as many Investigative Hearings of an individual or organization as reasonably necessary to carry out an investigation.

Investigative Hearings are not subject to the quantitative limitations described in C.R.C.P. 26(b)(2)(A) or the Federal Rules of Civil Procedure.

I. Confidential Nature. Exhibits and copies of exhibits used during Investigative Hearings are a part of the confidential investigation files of the Office of the Attorney General and disclosure during an interview does not waive the confidential nature of the investigation. Transcripts and recordings of Investigative Hearings are a part of the confidential investigation files of the Office of the Attorney General and will not be made available without the express consent of the Attorney General.

Witnesses and counsel may not record the Investigative Hearing or retain exhibits, or copies of exhibits, used during the Investigative Hearing. _________________________________________________________________________ Editor’s Notes

History New rule eff. 11/14/2021.

4 CCR 904-3 Colorado Privacy Act Rules {#sec-4-ccr-904-3 omnilex-key=us-co-regs-official--department-11--4 CCR 904-3}

DEPARTMENT OF LAW

COLORADO PRIVACY ACT RULES

4 CCR 904-3 [Editor’s Notes follow the text of the rules at the end of this CCR Document.] _________________________________________________________________________

PART 1 GENERAL APPLICABILITY

Rule 1.01 BASIS, SPECIFIC STATUTORY AUTHORITY, AND PURPOSE The rules in this Part 904-3 are developed pursuant to C.R.S. § 6-1-108(1), which grants the Attorney General the authority to promulgate such rules as may be necessary to administer the provisions of the Colorado Consumer Protection Act, and to C.R.S. § 6-1-1313, which: (1) gives the Attorney General

authority to promulgate rules for the purpose of carrying out the Colorado Privacy Act; (2) requires the Attorney General to adopt rules that detail the technical specifications for one or more Universal Opt-Out Mechanisms that clearly communicate a Consumer’s affirmative, freely given, and unambiguous choice to opt out of the Processing of Personal Data for purposes of Targeted Advertising or the Sale of Personal Data pursuant to C.R.S. §§ 6-1-1306(1)(a)(I)(A) or (1)(a)(I)(B); and (3) gives the Attorney General the

authority to adopt rules that govern the process of issuing opinion letters and interpretive guidance to develop an operational framework for business that includes a good faith reliance defense of an action that may otherwise constitute a violation of Part 13. Effective July 1, 2025, these rules are also developed pursuant to C.R.S. § 6-1-1314(7), which gives the Colorado Department of Law the authority to promulgate rules for the implementation of C.R.S. § 6-1-1314.

These rules are promulgated to establish implementation and operational guidelines for the Colorado Privacy Act, and to help ensure that the Colorado Privacy Act is carried out in a way that is consistent with the intent of the General Assembly, as reflected in the legislative declaration at C.R.S. § 6-1-1302.

Rule 1.02 SEVERABILITY If any provision of these Colorado Privacy Act Rules, 4 CCR 904-3, is found to be invalid by a court of competent jurisdiction, the remaining provisions of these rules shall remain in full force and effect.

Rule 1.03 EFFECTIVE DATE Except for the provisions that have delayed effective dates as stated in these rules or C.R.S. §§ 6-1-1301 through 6-1-1314, these rules shall become effective by the effective date published by the Secretary of State in the Colorado Code of Regulations.

Rule 1.04 EXEMPTIONS These Colorado Privacy Act Rules, 4 CCR 904-3, are subject to the applicability requirements and exemptions provided in C.R.S. § 6-1-1304.

PART 2 DEFINITIONS

Rule 2.01 AUTHORITY AND PURPOSE A. The statutory authority for the rules in this Part 2 is C.R.S. §§ 6-1-108(1), 6-1-1303, and 6-1- 1313. The purpose of these rules is to define certain undefined terms that are used throughout the Colorado Privacy Act, C.R.S. §§ 6-1-1301 through 6-1-1314, and these Colorado Privacy Act Rules, 4 CCR 904-3, including but not limited to certain undefined terms that are used in the definitions set forth in C.R.S. § 6-1-1303. The terms defined by this rule and C.R.S. § 6-1-1303 are capitalized where they appear in the rules to let the reader know to refer back to the definitions. When a term is used in a conventional sense, and is not intended to be a defined term, it is not capitalized.

Rule 2.02 DEFINED TERMS The following definitions of terms, in addition to those set forth in C.R.S. § 6-1-1303, apply to these Colorado Privacy Act Rules, 4 CCR 904-3, promulgated pursuant to the Colorado Privacy Act, unless the context requires otherwise:

“Authorized Agent” as referred to in C.R.S. § 6-1-1306(1)(a)(II) means a person or entity authorized by the Consumer to act on the Consumer's behalf.

“Biometric Data” is defined as set forth in C.R.S. § 6-1-1303(2.4) and means one or more biometric identifiers that are used or intended to be used, singly or in combination with each other or with other personal data, for identification purposes. Biometric Data does not include the following unless the Biometric Data is used for identification purposes: a digital or physical photograph; an audio or voice recording; or any data generated from a digital or physical photograph or an audio or video recording.

“Biometric Identifier” is defined as set forth in C.R.S. § 6-1-1303(2.5), and means data generated by the technological processing, measurement, or analysis of an individual’s biological, physical, or behavioral characteristics, which data can be Processed for the purpose of uniquely identifying an individual.

Biometric Identifier includes a fingerprint; a voiceprint; a scan or record of eye retina or iris; a facial map, facial geometry, or facial template; or other unique biological, physical, or behavioral patterns or characteristics.

“Biometric Identifier Notice” means the notice of collection or processing of Biometric Identifiers containing the disclosures required by C.R.S. § 6-1-1314(4)(a).

“Bona Fide Loyalty Program” as referred to in C.R.S. § 1-6-1308(1)(d) is defined as a loyalty, rewards, premium feature, discount, or club card program established for the genuine purpose of providing Bona Fide Loyalty Program Benefits to Consumers that voluntarily participate in that program, such that the primary purpose of Processing Personal Data through the program is solely to provide Bona Fide Loyalty Program Benefits to participating Consumers.

“Bona Fide Loyalty Program Benefit” is defined as an offer of superior price, rate, level, quality, or selection of goods or services provided to a Consumer through a Bona Fide Loyalty Program. Such benefits may be provided directly by a Controller or through a Bona Fide Loyalty Program Partner.

“Bona Fide Loyalty Program Partner” is defined as a Third Party that provides Bona Fide Loyalty Program Benefits to Consumers through a Controller’s Bona Fide Loyalty Program, either alone or in partnership with the Controller.

“Child” is defined as set forth in C.R.S. § 6-1-1303(4), and means an individual under thirteen years of age.

“Commercial product or service” as referred to in C.R.S. § 6-1-1304(1)(a) means a product or service bought, sold, leased, joined, provided, subscribed to, or delivered in exchange for monetary or other valuable consideration in the course of a Controller’s business, vocation, or occupation.

“Controller” is defined as set forth in C.R.S. § 6-1-1303(7), and means a person that, alone or jointly with others, determines the purposes for and means of Processing Personal Data.

"Data Broker” is defined as a Controller that knowingly collects and sells to Third Parties the Personal Data of a Consumer with whom the Controller does not have a direct relationship.

"Data Right” or “Data Rights” means the Consumer Personal Data rights granted in C.R.S. §§ 6-1- 1306(1) and 6-1-1314(5).

“Disability” or “Disabilities” has the same meaning as set forth in C.R.S. § 24-85-102(2.3).

“Employee" except as used in C.R.S. § 6-1-1314, means any person, acting as a job applicant to, or performing labor or services for the benefit of an Employer, including contingent and temporary workers and migratory laborers.

“Employee” as used in C.R.S. § 6-1-1314 is set forth in C.R.S. § 6-1-1314(1)(b) and means an individual who is employed full-time, part-time, or on-call or who is hired as a contractor, subcontractor, intern, or fellow.

"Employer" means every person, entity, firm, partnership, association, corporation, migratory field labor contractor or crew leader, receiver, or other officer of court, and any agent or officer thereof, of the abovementioned classes, employing any person.

"Employment Records" as referred to in C.R.S. § 6-1-1304(2)(k) means the records of an Employee, maintained by the Employer in the context of the Employer-Employee relationship having to do with hiring, promotion, demotion, transfer, lay-off or termination, rates of pay or other terms of compensation, as well as other information maintained because of the Employer-Employee relationship.

"Human Involved Automated Processing” means the automated processing of Personal Data where a human (1) engages in a meaningful consideration of available data used in the Processing or any output of the Processing and (2) has the authority to change or influence the outcome of the Processing.

“Human Reviewed Automated Processing” means the automated processing of Personal Data where a human reviews the automated processing, but the level of human engagement does not rise to the level required for Human Involved Automated Processing. Reviewing the output of the automated processing with no meaningful consideration does not rise to the level of Human Involved Automated Processing.

“Information that a Controller has a reasonable basis to believe the Consumer has lawfully made available to the general public” as referred to in C.R.S. § 6-1-1303(17)(b) means information that a Consumer has intentionally made available to the general public or information that a Consumer has made available under federal or state law, which may include but is not limited to:

  1. Personal Data found in a telephone book, a television or radio program, or a national or local news publication;

  2. Personal Data that has been intentionally made available by the Consumer through a website or online service where the Consumer has not restricted the information to a specific audience;

  3. A visual observation of an individual’s physical presence in a public place by another person, not including data collected by a device in the individual’s possession; and 4. A disclosure that has been made to the general public as required by federal, state, or local law.

“Interpretive Guidance” means a written statement issued by the Attorney General that calls attention to a well-established interpretation or principle of the Colorado Privacy Act or any rules or regulations promulgated thereunder, without applying it to a specific factual situation.

“Intimate Image” means any visual depiction, photograph, film, video, recording, picture, or computer or computer-generated image or picture, whether made or produced by electronic, mechanical, or other means, that depicts an identified or identifiable person’s private parts, or a person engaged in a private act, in circumstances in which a reasonable person would reasonably expect to be afforded privacy.

“Media” means text, audio, an image, or a video.

“Minor” is defined as set forth in C.R.S. § 6-1-1303 (16.5) and means any consumer who is under eighteen years of age.

“Noncommercial Purpose” as referred to in C.R.S. § 6-1-1304(2)(o) includes, but is not limited to, the following activities when conducted by: (a) a state institution of higher education, as defined in C.R.S. § 23-18-102(10), the state, the judicial department of the state, or a county, city and county, or municipality; or (b) a Processor acting on behalf of one or more of the foregoing:

  1. Processing activities related to the delivery of services and benefits;

  2. Research purposes;

  3. Budgeting;

  4. Improving operations or the delivery services or benefits;

  5. Auditing operations or service or benefit delivery;

  6. Sharing Personal Data between these categories of entities for any of these purposes; or 7. Any other purpose related to speech that state or federal courts have recognized as noncommercial speech, including political speech and journalism.

“Opinion Letter” means a letter containing the Attorney General’s opinion as to the application of one or more sections of the Colorado Privacy Act, C.R.S. § 6-1-1301, et seq., and any rules or regulations promulgated thereunder, to a specific factual situation.

"Opt-Out Purpose” or “Opt-Out Purposes” means the categories of Personal Data Processing from which the Consumer may opt out pursuant to C.R.S. § 6-1-1306(1)(a).

"Personal Data" is defined as set forth in C.R.S. § 6-1-1303(17), and (a) means information that is linked or reasonably linkable to an identified or identifiable individual; and (b) does not include de-identified data or Publicly Available Information as used in (17)(b).

"Process" or "Processing" is defined as set forth in C.R.S. § 6-1-1303(18), and means the collection, use, sale, storage, disclosure, analysis, deletion, or modification of Personal Data and includes the actions of a Controller directing a Processor to Process Personal Data.

“Processor” is defined as set forth in C.R.S. § 6-1-1303(19), and means a person that Processes Personal Data on behalf of a Controller.

“Profiling” is defined as set forth in C.R.S. § 6-1-1303(20), and means any form of automated processing of personal data to evaluate, analyze, or predict personal aspects concerning an identified or identifiable individual’s economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

“Publicly Available Information” is defined as set forth in C.R.S. § 6-1-1303(17), and does not include:

  1. Any Personal Data obtained or processed in in violation of C.R.S. §§ 18-7-107 or 18-7- 801;

  2. Biometric Data;

  3. Genetic Information; or 4. Nonconsensual Intimate Images known to the Controller.

“Revealing” as referred to in C.R.S. § 6-1-1303(24)(a) includes Sensitive Data Inferences. For example:

  1. While web browsing data at a high level may not be considered Sensitive Data, web browsing data which, alone or in combination with other Personal Data, infers an individual’s sexual orientation is considered Sensitive Data under C.R.S. § 6-1- 1303(24)(a).

“Sensitive Data Inference” or “Sensitive Data Inferences” means inferences made by a Controller based on Personal Data, alone or in combination with other data, which are used to indicate an individual’s racial or ethnic origin; religious beliefs; mental or physical health condition or diagnosis; sex life or sexual orientation; or citizenship or citizenship status.

“Solely Automated Processing” means the automated processing of Personal Data with no human review, oversight, involvement, or intervention.

“Universal Opt-Out Mechanism” or “Universal Opt-Out Mechanisms” means mechanisms that clearly communicate a Consumer's affirmative, freely given, and unambiguous choice to opt out of the Processing of Personal Data for purposes of Targeted Advertising or the Sale of Personal Data pursuant to C.R.S. § 6-1-1306 (1)(a)(I)(A) or (1)(a)(I)(B), which meets the technical specifications set forth in 4 CCR 904-3, Rule 5.06 pursuant to C.R.S. § 6-1-1313(2).

PART 3 CONSUMER DISCLOSURES

Rule 3.01 AUTHORITY AND PURPOSE A. The statutory authority for the rules in this Part 3 is C.R.S. §§ 6-1-108(1), 6-1-1313, and 6-1- 1314. The purpose of the rules in Part 3 is to ensure that disclosures, notifications, and other communications to Consumers are clear, accessible, and understandable to Consumers so that Consumers can understand and exercise the full scope of their rights under the Colorado Privacy Act, C.R.S. § 6-1-1303 through 6-1-1314.

Rule 3.02 REQUIREMENTS FOR DISCLOSURES, NOTIFICATIONS, AND OTHER COMMUNICATIONS TO CONSUMERS A. Disclosures, notifications, and other communications to Consumers pursuant to 4 CCR 904-3, Rules 4.02, 4.05(D), 5.03, 6.02, 6.05, and 7.04 must be:

  1. Designed to be understandable and accessible to a Controller’s target audiences, considering the vulnerabilities or unique characteristics of the audience and paying particular attention to the vulnerabilities of Children or Minors. For example, they shall use plain, straightforward language and avoid technical or legal jargon.

  2. Reasonably accessible to Consumers with Disabilities, including through the use of digital accessibility tools. For notices provided online, the Controller shall follow generally recognized industry standards, such as the Web Content Accessibility Guidelines, version 2.1 of June 5, 2018, from the World Wide Web Consortium, incorporated herein by reference as described at 4 CCR 904-3, Rule 11.02. In other contexts, the Controller shall provide information on how a Consumer with a Disability may access the disclosure or communication or make a request in an alternative format.

  3. Available in the languages in which the Controller in its ordinary course provides web pages, interfaces, contracts, disclaimers, sale announcements, and other information to Consumers. Disclosures and communications sent directly to Consumers must be sent in the language in which the Consumer ordinarily interacts with the Controller.

  4. Available through a readily accessible interface regularly used in conjunction with the Controller’s product or service.

  5. Provided in a readable format on all devices through which Consumers normally or regularly interact with the Controller, including on smaller screens and through mobile applications, if applicable.

  6. Unless otherwise stated, communicated in a manner by which the Controller regularly interacts with Consumers.

  7. Straightforward and accurate, and must not be written or presented in a way that is unfair, deceptive, false, or misleading.

B. A written Biometric Data policy required by C.R.S. § 6-1-1314(2)(a) shall comply with all requirements for disclosures and communications to Consumers provided in 4 CCR 904-3, Rule 3.02(A).

PART 4 CONSUMER PERSONAL DATA RIGHTS

Rule 4.01 AUTHORITY AND PURPOSE A. The statutory authority for the rules in this Part 4 is C.R.S. §§ 6-1-108(1), 6-1-1306, 6-1-1313, and 6-1-1314. The purpose of the rules in Part 4 is to clarify the scope of Consumer Personal Data rights, and standards for the processes required to facilitate the exercise of those rights.

Rule 4.02 SUBMITTING REQUESTS TO EXERCISE PERSONAL DATA RIGHTS A. Pursuant to C.R.S. § 6-1-1306(1), a Controller’s privacy notice must include specific methods through which a Consumer may submit requests to exercise Data Rights.

B. Any method specified by a Controller pursuant to this rule must comply with each of the following:

  1. Consider the ways in which Consumers normally interact with the Controller:

a. A Controller that interacts with Consumers exclusively online and has a direct relationship with a Consumer from whom it collects Personal Data shall only be required to provide an email address for submitting access, correction, deletion, or data portability requests.

b. A Controller that does not fall within subsection 4 CCR 904-3, Rule 4.02(B)(1)(a) shall provide two or more designated methods for submitting a Data Rights request. If a Controller maintains a website, mobile application, or other digital presence, one method for submitting requests shall be through its website, mobile application, or digital interface, such as through a webform;

c. If a Controller interacts with Consumers in person, the Controller shall consider providing an in-person method such as a printed form the Consumer can directly submit or send by mail; a tablet or computer portal that allows the Consumer to complete and submit an online form; or a telephone by which the Consumer can call the Controller’s toll-free number.

  1. Enable the Consumer to submit the request to the Controller at any time;

  2. Comply with requirements for disclosures, notifications, and other communications to Consumers provided in 4 CCR 904-3, Rule 3.02;

  3. Use reasonable data security measures, consistent with 4 CCR 904-3, Rule 6.09, when exchanging information in furtherance of Data Rights requests, considering the volume, scope and nature of Personal Data that may be exchanged; and 5. Be easy for Consumers to execute, requiring a minimal number of steps.

C. The Data Rights request method does not have to be specific to Colorado, so long as the request method:

  1. Clearly indicates which rights are available to Colorado Consumers;

  2. Provides all Data Rights available to Colorado Consumers;

  3. Provides Colorado Consumers a clear understanding of how to exercise their rights; and 4. Meets all other requirements of this part, 4 CCR 904-3, Rule 4.02.

D. When a Consumer submits a Data Rights request, a Controller may only collect Personal Data through the request process if the Personal Data is reasonably necessary to Authenticate the Consumer, respond to the request, or effectuate the Data Rights request.

E. A Controller must not require a Consumer to create a new user account to exercise their Data Rights request, but may require a Consumer to use an existing password-protected account.

Rule 4.03 RIGHT TO OPT OUT A. A Controller shall comply with an opt-out request by:

  1. Ceasing to Process the Consumer’s Personal Data for the Opt-Out Purpose(s) as soon as feasibly possible and without undue delay from the date the Controller receives the request, taking into account the size and complexity of the Controller’s businesses and burden of operationalizing the opt-out.

a. If a Controller does not know the identity of a Consumer submitting an online optout request, such that the Controller is unable to opt the Consumer out of the Processing of offline or other connected Personal Data, the Controller may request the additional information necessary to do so subject to 4 CCR 904-3, Rules 4.08 and 5.05.

b. If a Consumer submits a request to exercise more than one Data Right and a Controller is able to complete the opt-out request in a more timely manner than other Data Rights requests, the Controller should complete the opt-out request prior to any other Data Rights request.

  1. Maintaining a record of the opt-out request and response, in compliance with 4 CCR 904- 3, Rule 6.11.

  2. Using agreed upon technical, organizational or other measures or processes to instruct its Processors, pursuant to C.R.S. § 6-1-1305(2)(a), to stop Processing the Personal Data as needed to effectuate the Consumer’s opt-out request.

B. To enable a Consumer to exercise the right to opt out of the Opt-Out Purposes provided in C.R.S. § 6-1-1306(1)(a)(I), a Controller must provide the disclosures required by C.R.S. § 6-1- 1308(1)(b).

  1. A Controller that Sells Personal Data or Processes Personal Data for Targeted Advertising must also provide a clear and conspicuous method for Consumers to exercise the right to opt out of the Processing of Personal Data for each or all of the Opt- Out Purposes, as applicable.

a. The clear, conspicuous method must be provided either directly or through a link, in a clear, conspicuous, and readily accessible location outside the privacy notice.

  1. A Controller Processing Personal Data for Profiling in furtherance of a decision that results in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, healthcare services, or access to essential goods or services, as subject to the opt-out right provided at C.R.S. § 6-1-1306(1)(a)(I), shall provide a clear and conspicuous method for Consumers to exercise the right to opt out of Processing Personal Data for such Profiling at or before the time such Processing occurs.

  2. Any clear and conspicuous method for Consumers to exercise the right to opt out of Processing for the Opt-Out Purposes, provided pursuant to this section, must comply with the requirements of 4 CCR 904-3, Rule 4.02(B). If a link is used, it must take a Consumer directly to the opt-out method and the link text must provide a clear understanding of its

purpose, for example “Colorado Opt-Out Rights,” “ Personal Data Use Opt-Out,” “ Your Opt-Out Rights,” “ Your Privacy Choices,” or “Your Colorado Privacy Choices.”

C. An Authorized Agent may exercise a Consumer’s opt-out right on behalf of the Consumer, so long as the Controller is able to, with commercially reasonable effort, Authenticate the identity of the Consumer and the Authorized Agent’s authority to act on the Consumer’s behalf.

D. A Controller may collect the Consumer’s Personal Data necessary to effectuate the Consumer’s opt-out right, pursuant to 4 CCR 904-3, Rule 4.02(D).

Rule 4.04 RIGHT OF ACCESS A. A Controller shall comply with an access request by providing the Consumer all the specific pieces of Personal Data it has collected and maintains about the Consumer that are the subject of the request, including without limitation, any Personal Data that the Controller’s Processors obtained from the Controller in providing services to the Controller.

  1. Specific pieces of Personal Data include final Profiling decisions, inferences, derivative data, marketing profiles, and other Personal Data created by the Controller which is linked or reasonably linkable to an identified or identifiable individual.

B. If a Consumer right to access includes Biometric Data, the Controller must also include the additional information required at C.R.S. § 6-1-1314(5).

C. Personal Data provided in response to an access request must:

  1. Be provided in in a form that is concise, transparent and easily intelligible and in an appropriate, commonly used electronic format, depending on the nature of the data;

  2. Be available in the language in which the Consumer interacts with the Controller.

  3. Avoid incomprehensible internal codes and, if necessary, include explanations that would allow the average Consumer to make an informed decision of whether to exercise deletion, correction, or opt-out rights.

  4. Be provided in compliance with the requirements for disclosures, notifications, and other communications, as described in 4 CCR 904-3, Rule 3.02, as applicable.

D. The Controller shall implement and maintain reasonable data security measures, consistent with 4 CCR 904-3, Rule 6.09, in Processing any documentation relating to a Consumer’s access E. A Controller shall not be required to disclose in response to an access request a Consumer’s government-issued identification number, financial account number, health insurance or medical identification number, an account password, security questions and answers, Biometric Data, or Biometric Identifiers. The Controller shall, however, inform the Consumer with sufficient particularity that it has collected that type of information. For example, a Controller shall respond that it collects “unique Biometric Data including a fingerprint scan” without disclosing the actual fingerprint scan data.

F. If a Consumer exercises the right to access their Personal Data in a portable format pursuant to C.R.S. § 6-1-1306(1)(e) and the Controller determines the manner of response would reveal the Controller’s trade secrets, the Controller must still honor the Consumer’s undiminished right of access in a format or manner which would not reveal trade secrets, such as in a nonportable format.

Rule 4.05 RIGHT TO CORRECTION A. Consumers have the right to correct inaccuracies in their Personal Data subject to C.R.S. § 6-1- 1306(c).

B. A Controller shall comply with a Consumer’s correction request by correcting the Consumer’s Personal Data in its existing systems, except archive or backup systems. The Controller shall also use agreed upon technical, organizational, or other measures or processes to instruct its Processors, pursuant to C.R.S. § 6-1-1305(2)(a), to make the necessary corrections in their respective systems.

C. If a Controller or Processor stores any Personal Data on archived or backup systems, it may delay compliance with the Consumer’s correction request with respect to an archived or backup system until that system is restored to an active system or is next accessed or used.

D. If a Consumer submits a request to exercise their right to correct Personal Data and the requested correction to that Personal Data could be made by the Consumer through the Consumer’s account settings, a Controller may respond to the Consumer’s request by providing instructions on how the Consumer may correct the Personal Data so long as:

  1. The correction process is not unduly burdensome to the Consumer;

  2. The instructions meet all requirements of 4 CCR 904-3, Rule 3.02;

  3. The Controller’s response is compliant with the timing requirements set forth in C.R.S. § 6-1-1306(2)(a); and 4. The process described in the instructions enable the Consumer to make the specific requested correction.

E. A Controller may require the Consumer to provide documentation if necessary to determine whether the Personal Data, or the Consumer’s requested correction to the Personal Data, is accurate.

  1. When requesting documentation, the Controller must provide the Consumer with a meaningful understanding of why the documentation is necessary.

  2. Any documentation provided by the Consumer in connection with the Consumer’s right to correction shall only be Processed by the Controller in considering the accuracy of the Consumer’s Personal Data.

  3. The Controller shall implement and maintain reasonable data security measures, consistent with 4 CCR 904-3, Rule 6.09, in Processing any documentation relating to the Consumer’s correction request.

  4. If the Controller did not receive the Personal Data directly from the Consumer and has no documentation to support the accuracy of the Personal Data, the Consumer’s assertion of inaccuracy shall be sufficient to establish that the Personal Data is inaccurate.

  5. A Controller, having exhausted the steps above may decide not to act upon a Consumer’s correction request if the Controller determines that the contested Personal Data is more likely than not accurate.

a. If a Controller denies a Consumer’s correction request based on the Controller’s determination that the contested Personal Data is more likely than not accurate, the Controller must describe in documentation required by 4 CCR 904-3, Rule 6.11(A), the Consumer’s requested correction to the Personal Data, any documentation requested from and provided by the Consumer in support of the correction request, and the reason for the Controller’s determination that the Consumer’s documentation was not sufficient to support the Consumer’s position.

Rule 4.06 RIGHT TO DELETION A. A Controller shall comply with a Consumer’s deletion request by:

  1. Permanently and completely erasing the Personal Data from its existing systems, except archive or backup systems, or de-identifying the Personal Data such that it cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, or a device linked to such an individual, in accordance with C.R.S. § 6-1-1303(11); and 2. Using agreed upon technical, organizational, or other measures, or processes to instruct its Processors pursuant to C.R.S. § 6-1-1305(2)(b) to delete the Consumer’s Personal Data held by the Processors.

B. Notwithstanding 4 CCR 904-3, Rule 4.06(A), a Controller may maintain records of a Consumer’s deletion request consistent with 4 CCR 904-3, Rule 6.11 and as needed to effectuate the deletion C. If a Controller or Processor stores any Personal Data on archived or backup systems, it may delay compliance with the Consumer’s deletion request with respect to an archived or backup system until that system is restored to an active system or is next accessed or used.

D. A Controller that has obtained Personal Data about a Consumer from a source other than the Consumer shall comply with a Consumer's deletion request with respect to that Personal Data pursuant to C.R.S. § 6-1-1306(d) by (i) retaining a record of the deletion request and the minimum data necessary for the purpose of ensuring the Consumer’s Personal Data remains deleted from the Consumer’s records and not using such retained data for any other purpose, or (ii) opting the Consumer out of the Processing of such Personal Data for any purpose except for those exempted pursuant to the provisions of C.R.S. § 6-1-1304.

E. If a Controller complies with a deletion request by opting the Consumer out of Processing under 4.06(D) or does not opt the Consumer out of some Processing of Personal Data because the Processing purpose is exempted pursuant to the provisions of C.R.S. § 6-1-1304, the Controller shall provide the Consumer with the categories of Personal Data that were not deleted along with any applicable exception. The Controller shall not use the Consumer’s Personal Data retained for any other purpose than provided for by the applicable exception.

Rule 4.07 RIGHT TO DATA PORTABILITY A. To comply with a data portability request, a Controller must transfer to a Consumer the Personal Data it has collected and maintains about the Consumer through a secure method in a commonly used electronic format that, to the extent technically feasible, is readily usable and allows the Consumer to transmit the Personal Data to another entity without hindrance.

B. Pursuant to C.R.S. § 6-1-1306(1)(e), a Controller is not required to provide Personal Data to a Consumer in a manner that would disclose the Controller’s trade secrets. When complying with a request to access Personal Data in a portable format, Controllers must provide as much data as possible in a portable format without disclosing the trade secret.

  1. For example, if sharing both raw or unedited Personal Data along with related inferences or derived Personal Data in an Excel file would reveal a trade secret, the Controller may provide either set of Personal Data in an Excel file, so long as it is clear to the Consumer that the Controller maintains both types of Personal Data.

Rule 4.08 AUTHENTICATION A. Pursuant to C.R.S. § 6-1-1306(1), a Controller shall use a commercially reasonable method for authenticating the identity of every Consumer submitting any Data Right request, and the

authority of every Authorized Agent submitting an opt-out request on behalf of a Consumer pursuant to C.R.S. § 6-1-1306(1)(a)(II).

  1. To determine if an authentication method is commercially reasonable, the Controller shall consider the Data Rights exercised, the type, sensitivity, value, and volume of Personal Data involved, the level of possible harm that improper access or use could cause to the Consumer submitting the Data Right request and the cost of authentication to the Controller. A Controller must avoid methods that place an unreasonable burden on the Consumer submitting a Data Right request, or Authorized Agent submitting an opt-out request on behalf of a Consumer.

B. When possible, a Controller shall avoid requesting additional Personal Data to Authenticate a Consumer unless the Controller cannot Authenticate the Consumer using the Personal Data already maintained by the Controller.

C. Personal Data obtained to Authenticate a Consumer may only be used to Authenticate the Consumer submitting the Data Right request, pursuant to C.R.S. § 6-1-1306(1), or to Authenticate an Authorized Agent’s authority, pursuant C.R.S. § 6-1-1306(1)(a)(II), and must be deleted as soon as practical after Processing the Consumer’s request, except as required by 4 CCR 904-3, Rule 6.11, or as otherwise required.

D. A Controller shall implement reasonable security measures, consistent with 4 CCR 904-3, Rule 6.09, to protect Personal Data exchanged to Authenticate a Consumer or to Authenticate an Authorized Agent’s authority, considering the type, value, sensitivity, and volume of information exchanged and the level of possible harm improper access or use could cause to the Consumer submitting a Data Right request.

E. A Controller shall not require the Consumer or Authorized Agent to pay a fee for authentication.

For example, a Controller may not require a Consumer to provide a notarized affidavit for authentication unless the Controller compensates the Consumer for the cost of notarization.

F. If a Controller cannot Authenticate the Consumer submitting a Data Right request using commercially reasonable efforts, the Controller is not required to comply with the Consumer’s request. The Controller shall inform the Consumer that their identity could not be authenticated, provide information on how to remedy any deficiencies, and may request additional Personal Data if reasonably necessary to Authenticate the Consumer.

Rule 4.09 RESPONDING TO CONSUMER REQUESTS A. A Controller must respond to a Consumer’s Data Right request in compliance with the timing provisions of C.R.S. § 6-1-1306(2)(a)-(b).

B. A Controller does not have to comply with an authenticated Consumer request to access, correct, delete, or provide Personal Data in a portable format, to the extent that the Personal Data at issue meets the requirements of the exceptions in C.R.S. § 6-1-1307(1)(b) and 1307(3).

C. If a Controller decides not to act on a Consumer’s Data Right request, the Controller’s response to the Consumer must include the grounds for denial, including but not limited to (1) any conflict with federal or state law; (2) if the Controller relied on an exception to the Colorado Privacy Act found at C.R.S. § 6-1-1304(2), a description of the exception; (3) the Controller’s inability to Authenticate the Consumer’s identity; (4) any factual basis for a Controller’s good-faith claim that compliance is impossible; or (5) any basis for a good-faith, documented belief that the request is fraudulent or abusive.

  1. If a Controller denies a Consumer Data Right request based on inability to Authenticate, the Controller must describe in documentation required by 4 CCR 904-3, Rule 6.11 their reasonable efforts to authenticate and why they were unable to do so.

  2. A Controller that decides not to act on a Consumer’s request must also provide instructions on how to appeal the Controller’s decision in accordance with C.R.S. § 6-1- 1306(3).

D. When a Controller complies with a Consumer’s Personal Data Right request, the Controller shall also use agreed upon technical, organizational, or other measures or processes, to instruct its Processors, pursuant to C.R.S. § 6-1-1305(2)(a), to fulfill requests relating to Personal Data held by the Processors.

E. Controllers must maintain all documentation as required by 4 CCR 904-3, Rule 6.11 of these rules.

F. If a Consumer or Authorized Agent submits a request to opt out of the Processing of a Consumer’s Personal Data for an Opt-Out Purpose in a manner that is not one of the Controller’s opt-out request methods, or submits a Data Right request that is otherwise deficient in a manner unrelated to the Authentication process, the Controller shall either: (1) treat the request as if it had been submitted in accordance with the Controller’s specified request methods, or (2) provide the Consumer or Authorized Agent that submitted the request with information on how to submit the request or remedy any deficiencies in the request.

PART 5 UNIVERSAL OPT-OUT MECHANISM

Rule 5.01 AUTHORITY AND PURPOSE A. The statutory authority for the rules in Part 5 is C.R.S. §§ 6-1-108(1), 6-1-1306, and 6-1-1313.

The purpose of this Part 5 is to provide technical and other specifications for Universal Opt-Out Mechanisms.

Rule 5.02 RIGHTS EXERCISED A. Consumers may exercise their right to opt out of the Processing of Personal Data concerning the Consumer for purposes of Targeted Advertising or the Sale of Personal Data through a userselected Universal Opt-Out Mechanism that meets the technical and other specifications provided in this Rule 5.

B. The purpose of a Universal Opt-Out Mechanism is to provide Consumers with a simple and easyto-use method by which Consumers can automatically exercise their opt-out rights with all Controllers they interact with without having to make individualized requests with each Controller.

C. A Universal Opt-Out Mechanism may:

  1. Express a Consumer’s choice to opt out of the Processing of Personal Data for both the Processing of Personal Data for purposes of Targeted Advertising and Sale of Personal Data; or 2. Express a Consumer’s choice to opt out of the Processing of Personal Data for only one specific purpose, either Targeted Advertising or Sale of Personal Data alone.

Rule 5.03 NOTICE AND CHOICE FOR UNIVERSAL OPT-OUT MECHANISMS A. If a platform, developer, or provider provides a Universal Opt-Out Mechanism, that platform, developer, or provider shall make clear to the Consumer, whether in its configuration or disclosures to the public, that the mechanism is meant to allow the Consumer to exercise the right to opt out of the Processing of Personal Data for one specific purpose, either Targeted Advertising or Sale of Personal Data, or both purposes. These notices provided to the Consumer:

  1. Shall comply with the requirements for disclosures and communications to Consumers provided in 4 CCR 904-3, Rule 3.02;

  2. If applicable, shall state that the Universal Opt-Out Mechanism has been recognized by the Colorado Attorney General;

  3. Shall clearly describe any limitations that may be applicable to the mechanism, for example:

a. That the mechanism will allow a consumer to exercise the opt-out right for only one specific purpose, either Targeted Advertising or Sale of Personal Data; or b. That the mechanism applies only to a single browser or device.

  1. Need not be tailored only to Colorado or refer to Colorado or to any other specific provisions of these rules or the Colorado Privacy Act, provided the mechanism meets the requirements of 4 CCR 904-3, Rule 5.03(A)(1)-(3).

a. Example: A platform, developer, or provider discloses that its Universal Opt-Out Mechanism permits consumers to exercise “any and all opt-out rights available to you under state laws,” and complies with the other requirements of this Rule 5.03(A) but makes no mention of Colorado nor recites any section of these rules or the Colorado Privacy Act. These disclosures satisfy the requirements of this

Rule 5.03(A).

B. A valid Universal Opt-Out Mechanism must represent the Consumer’s affirmative, freely given, and unambiguous choice to opt out of the Processing of Personal Data for the purposes listed at C.R.S. § 6-1-1306(1)(a)(IV)(A) and (B). Controllers are not obligated to honor Consumer rights requests for purposes other than those listed at C.R.S. § 6-1-1306(1)(a)(IV)(A) and (B) when transmitted through a Universal Opt-Out Mechanism.

C. The platform, developer, or provider that provides a Universal Opt-Out Mechanism is not obligated to authenticate that a user is a Resident of Colorado. The platform, developer, or provider may provide such authentication capabilities if it chooses.

Rule 5.04 DEFAULT SETTINGS FOR UNIVERSAL OPT-OUT MECHANISMS A. To comply with C.R.S. § 6-1-1313(2), a Universal Opt-Out Mechanism may not be the default setting for a tool that comes pre-installed with a device, such as a browser or operating system.

  1. Example: An operating system manufacturer bundles a browser pre-installed with every device shipped with the operating system. The browser sends a Universal Opt-Out mechanism signal by default and never asks the Consumer to enable this setting. The Consumer’s decision to use this browser does not represent the Consumer’s affirmative, freely given, and unambiguous choice to use the Universal Opt-Out Mechanism because it is a default choice. This is so even if the marketing for the operating system touts its privacy protective features.

  2. Example: An operating system manufacturer bundles a browser and apps pre-installed with every device shipped with the operating system. The first time a Consumer runs a browser or app, the operating system asks the Consumer specifically and clearly whether they want to opt out of the Sale of their Personal Data using a Universal Opt-Out Mechanism signal when using the browser or app. No choice is pre-selected, meaning the Consumer is forced to decide. The Consumer’s decision to select “yes” to enable the signal to opt out of the Sale of Personal Data represents the Consumer’s affirmative, freely given, and unambiguous choice to use the Universal Opt-Out Mechanism.

B. Notwithstanding 4 CCR 904-3, Rule 5.04(A), a Consumer’s decision to adopt a tool that does not come pre-installed with a device, such as a browser or operation system, but is marketed as a tool that will exercise a user’s rights to opt out of the Processing of Personal Data using a Universal Opt-Out Mechanism, shall be considered the Consumer's affirmative, freely given, and unambiguous choice to use a Universal Opt-Out Mechanism. The marketing for such a tool may also describe functionality other than the exercise of opt out rights and it need not refer specifically to opt-out rights in the State of Colorado.

  1. Example: A browser manufacturer markets its browser as a “privacy friendly” browser, prominently highlighting that the browser sends a Universal Opt-Out Mechanism signal by default. The browser does not come pre-installed with a device or operating system and must be installed by the Consumer. The Consumer’s decision to use this browser represents the Consumer’s affirmative, freely given, and unambiguous choice to use the Universal Opt-Out Mechanism. The Consumer need not be given an explicit choice about whether to use the Universal Opt-Out Mechanism in this example.

Rule 5.05 PERSONAL DATA USE LIMITATIONS A. A platform, developer, or provider providing a Universal Opt-Out Mechanism shall not use, disclose, or retain any Personal Data collected from the Consumer in connection with the Consumer’s utilization of the mechanism for any purpose other than sending or processing the opt-out preference. For example, the fact that a particular device sends a Universal Opt-Out Mechanism may not be used as part of a digital fingerprint to later identify that device.

B. When processing a Universal Opt-Out Mechanism, a Controller may not require the collection of additional Personal Data beyond that which is strictly necessary to authenticate a Consumer is a resident of Colorado determine that the mechanism represents a legitimate request to opt out of the Processing of Personal Data as permitted by C.R.S. § 6-1-1306(1)(a)(IV), or comply with the authentication mandates of the law of another jurisdiction specifically regarding universal opt-out mechanisms or signals.

  1. Example: The law of a state other than Colorado obligates Controllers to gather specific pieces of information from a user before the Controller honors the use of a Universal Opt- Out Mechanism by that user. This additional information may be gathered while processing a Universal Opt-Out Mechanism, even if is not otherwise “strictly necessary to authenticate a Consumer is a resident of Colorado or determine that the mechanism represents a legitimate request".

C. Notwithstanding 4 CCR 904-3, Rule 5.05(B), a Controller may provide the Consumer with an option to provide additional Personal Data only if it will extend the recognition of the Consumer’s use of the Universal Opt-Out Mechanism across platforms, devices, or offline. For example, a Controller may give the Consumer the option to provide their phone number or email address so that the Universal Opt-Out Mechanism or signal can apply to offline Sale of Personal Data or link the Consumer’s opt-out choice across devices. Any information provided by the Consumer for this purpose shall not be used, disclosed, or retained for any purpose other than processing the opt-out request.

D. The Controller shall implement and maintain reasonable data security measures, consistent with 4 CCR 904-3, Rule 6.09, in Processing any Personal Data relating to the Consumer’s use of a Universal Opt-Out Mechanism.

Rule 5.06 TECHNICAL SPECIFICATION A. A Universal Opt-Out Mechanism must allow for Consumers to automatically communicate their opt-out choice with multiple Controllers.

  1. The Universal Opt-Out Mechanism may communicate a Consumer’s opt-out choice by sending an opt-out signal. The signal must be in a format commonly used and recognized by Controllers. An example would be an HTTP header field or JavaScript object.

B. The Universal Opt-Out Mechanism must allow Consumers to clearly communicate one or more opt-out rights available under C.R.S. § 6-1-1306(1)(a)(IV).

  1. The Universal Opt-Out Mechanism may allow for a Consumer to opt out of Processing for one or more of the Opt-Out Purposes.

C. The Universal Opt-Out Mechanism must store, Process, and transmit any Consumer Personal Data using reasonable data security measures, consistent with 4 CCR 904-3, Rule 6.09.

D. A Universal Opt-Out Mechanism must not prevent the Controller’s ability to determine:

  1. Whether a Consumer is a Resident of the State of Colorado; or 2. That the Universal Opt-Out Mechanism represents a legitimate request to opt out of the Processing of Personal Data.

E. A Universal Opt-Out Mechanism must not unfairly disadvantage any Controller. For example, a Universal Opt-Out Mechanism may not engage in self-dealing benefiting the creator of the Universal Opt-Out Mechanism over other Controllers.

Rule 5.07 SYSTEM FOR RECOGNIZING UNIVERSAL OPT-OUT MECHANISMS A. The Colorado Department of Law shall maintain a public list of Universal Opt-Out Mechanisms that have been recognized to meet the standards of this subsection. The initial list shall be released no later than January 1, 2024 and shall be updated periodically.

B. The goal of the public list is to simplify the options facing Controllers, Consumers, and other actors.

C. To be recognized, a Universal Opt-Out Mechanism must at a minimum meet these standards:

  1. Comply with all of the technical and other specifications of Rule 5; and 2. Not create Consumer or Controller confusion about the similarities and differences between Universal Opt-Out Mechanisms on the public list.

D. The Colorado Department of Law may consider additional factors when determining which Universal Opt-Out Mechanisms to recognize. These include but are not limited to:

  1. Commercial adoption by Consumers or Controllers;

  2. Ease and cost of use, implementation, and detection by Consumers and Controllers;

  3. Whether the Universal Opt-Out Mechanism has been approved by a widely recognized, legitimate standards body after broad multistakeholder participation in the standardsmaking process; and 4. Whether the Universal Opt-Out Mechanism is based on an open system or standard, and whether such standard is free for adoption by device, operating system, browser, and other manufacturers, Controllers, or Consumers without permission or on fair, reasonable, and non-discriminatory terms.

E. The public list shall describe recognized Universal Opt-Out Mechanisms in enough technical detail to permit Controllers to identify them when used by Consumers.

F. The Colorado Department of Law will allow Controllers six (6) months to recognize a Universal Opt-Out Mechanism once that Mechanism is added to the public list.

Rule 5.08 OBLIGATIONS ON CONTROLLERS A. Effective July 1, 2024, 1. A Controller that receives an opt-out request through a Universal Opt-Out Mechanism shall treat such as a valid request to opt out of the Processing of Personal Data for purposes of Targeted Advertising, Sale of Personal Data, or both purposes, as indicated by the mechanism, for the associated browser or device, and, if known, for the Consumer.

  1. After receiving a valid opt-out request through the use of a Universal Opt-Out Mechanism, a Controller shall continue to treat the browser, device, and Consumer as having exercised opt-out rights until the Consumer Consents to the Sale of Personal Data or Processing of Personal Data for Targeted Advertising, as specified in 4 CCR 904-3,

Rule 5.09.

  1. A Controller shall be capable of recognizing any Universal Opt-Out Mechanism reflected in the public list maintained by the Colorado Department of Law pursuant to subsection 4 CCR 904-3, Rule 5.07 provided the Controller has had at least six months’ notice of the addition of new mechanisms. For example, in the case of a recognized Universal Opt-Out Mechanism sent as a signal, the Controller must listen for the signal.

B. A Controller may also recognize Universal Opt-Out Mechanisms that are not reflected in the public list maintained by the Colorado Department of Law pursuant to subsection 4 CCR 904-3,

Rule 5.07.

C. Notwithstanding 4 CCR 904-3, Rule 5.08(A), a Controller may choose to honor an opt-out request received through a Universal Opt-Out Mechanism prior to July 1, 2024, pursuant to C.R.S. § 6-1- 1306(a)(IV)(A).

D. Unless a Controller is Authenticating a Consumer as permitted by C.R.S. § 6-1-1313(2)(f), a Controller may not require a Consumer to login or otherwise Authenticate themself as a condition of recognizing the Consumer’s use of a Universal Opt-Out Mechanism. A Controller may not subject a Consumer to undertake any authentication actions that are unnecessary or unnecessarily burdensome.

E. A Controller may display in a conspicuous manner if it has Processed the Consumer’s opt-out preference signal. For example, the Controller may display on its website “Opt-Out Preference Signal Honored” when a browser, device, or Consumer utilizing a Universal Opt-Out Mechanism visits the website.

F. Pursuant to C.R.S. § 6-1-1313(2)(f), a Controller may authenticate that the user sending an optout request through a Universal Opt-Out Mechanism is a Resident of Colorado, but they are not obligated to do so.

Rule 5.09 CONSENT AFTER UNIVERSAL OPT-OUT A. A Controller may enable a Consumer to Consent to Processing that the Consumer has opted-out of using a Universal Opt-Out mechanism, so long as the Controller’s request for Consent complies with the Consent requirements provided in C.R.S. § 6-1-1306(1)(a)(IV)(C), and 4 CCR 904-3, Rule 7.05.

B. A Controller shall not interpret the absence of a Universal Opt-Out Mechanism signal after the Consumer previously utilized a Universal Opt-Out Mechanism as Consent to opt back in.

PART 6 DUTIES OF CONTROLLERS

Rule 6.01 AUTHORITY AND PURPOSE A. The statutory authority for the rules in this Part 6 is C.R.S. §§ 6-1-108(1), 6-1-1308, 6-1-1313, and 6-1-1314. The purpose of the rules in this Part 6 is to provide clarity on the duties of Controllers concerning the Personal Data of Colorado Consumers.

Rule 6.02 PRIVACY NOTICE PRINCIPLES A. A privacy notice shall provide Consumers with a meaningful understanding and accurate expectations of how their Personal Data will be Processed. It shall also inform Consumers about their rights under the Colorado Privacy Act and provide any information necessary for Consumers to exercise those rights.

B. A Controller is not required to provide a separate Colorado-specific privacy notice or section of a privacy notice as long as the Controller’s privacy notice meets all requirements of this section and makes clear that Colorado Consumers are entitled to the rights provided by C.R.S. § 6-1-1306.

C. A privacy notice shall comply with all requirements for disclosures and communications to Consumers provided in 4 CCR 904-3, Rule 3.02.

D. A privacy notice must be clear. Information contained in a privacy notice shall be:

  1. Concrete and definitive, avoiding abstract or ambivalent terms that may lead to varying interpretations.

  2. Clearly labeled, such that Consumers seeking to understand a Controller’s Processing activities or how to exercise their Data Rights can easily access the section of the privacy notice containing relevant information.

E. A privacy notice must be easily accessible. A privacy notice must be:

  1. Posted online through a conspicuous link using the word “privacy” on the Controller’s website homepage or on a mobile application’s app store page or download page. A Controller that maintains an application on a mobile or other device shall also include a link to the privacy notice in the application’s settings menu.

a. A Controller that does not operate a website shall make the privacy notice conspicuously available to Consumers through a medium regularly used by the Controller to interact with Consumers. For instance, if a Controller interacts with a Consumer offline, an offline version of the privacy notice must be available to the Consumer.

F. A privacy notice must be specific. The level of specificity in a privacy notice should enable a Consumer to understand, in advance or at the time of the Processing, the scope of the Controller’s Processing operations, such that a Consumer should not be taken by surprise at a later point about Personal Data that has been collected and the ways in which Personal Data has been Processed.

Rule 6.03 PRIVACY NOTICE CONTENT A. A privacy notice must include the following information:

  1. A comprehensive description of the Controller’s online and offline Personal Data Processing practices, including but not limited to the following, linked in a way that gives Consumers a meaningful understanding of how each category of their Personal Data will be used when they provide that Personal Data to the Controller for a specified purpose:

a. The categories of Personal Data Processed, including, but not limited to, whether Personal Data of a Child or other Sensitive Data is Processed.

i. Categories shall be described in a level of detail that provides Consumers a meaningful understanding of the type of Personal Data Processed. For example, categories of Personal Data described at a sufficiently granular level of detail include, but are not limited to: "contact information,” “ government issued identification numbers,” “ payment information”, “Information from Cookies,” “ data revealing religious affiliation,” and “medical data.”

b. The Processing purpose described in a level of detail that gives Consumers a meaningful understanding of how each category of their Personal Data is used when provided for that Processing purpose.

c. Whether the Personal Data provided for a specific purpose will be sold or used for Targeted Advertising or Profiling in furtherance of Decisions that Produce Legal or Similarly Significant Effects Concerning a Consumer.

d. Categories of Personal Data that the Controller Sells to or shares with Third Parties, if any.

e. Categories of Third Parties to whom the Controller sells, or with whom the Controller shares Personal Data, if any. Categories of Third Parties must be described in a level of detail that gives Consumers a meaningful understanding of the type of, business model of, or processing conducted by the Third Party.

i. For example, categories of Third Parties described in a sufficiently granular level of detail include, but are not limited to: “analytics companies,” “ data brokers,” “ third-party advertisers,” “ payment processors,” “ lenders,” “ other merchants,” and “government agencies.”

  1. If a Controller’s Processing activity involves the Processing of Personal Data for the

purpose of Profiling in furtherance of Decisions that Produce Legal or Similarly Significant Effects Concerning a Consumer, all disclosures required by 4 CCR 904-3, Rule 9.03.

  1. A list of the Data Rights available.

  2. A description of the methods through which a Consumer may submit requests to exercise Data Rights, as required by C.R.S. § 6-1-1306(1) and 4 CCR 904-3, Rule 4.02, including:

a. Instructions on how to use each method.

b. Instructions on how an Authorized Agent may submit a request to opt out of the Processing of Consumer Personal Data on a Consumer’s behalf pursuant to C.R.S. § 6-1-1306(1)(a)(II).

c. A clear and conspicuous method to exercise the right to opt out of the Processing of Personal Data concerning the Consumer pursuant to C.R.S. § 6-1- 1306(1)(a)(I) and (1)(a)(III), or links to any online method, such as a webform or portal, consistent with 4 CCR 904-3, Rule 4.03.

d. A description of the commercially reasonable process the Controller uses to Authenticate the identity of a Consumer exercising a Data Right request or to Authenticate the authority of an Authorized Agent exercising the right to opt out on a Consumer’s behalf.

e. Effective July 1, 2024, an explanation of how requests to opt out using Universal Opt-Out Mechanisms will be processed.

  1. If a Controller will delete Sensitive Data Inferences within twenty-four (24) hours pursuant to 4 CCR 904-3, Rule 6.10, a description of the Sensitive Data Inferences subject to this provision and the retention and deletion timeline for such Sensitive Data Inferences.

  2. A Controller’s contact information.

  3. Instructions on how a Consumer may appeal a Controller’s action in response to the Consumer’s request, as contemplated by C.R.S. § 6-1-1306(3).

  4. The date the privacy notice was last updated.

Rule 6.04 CHANGES TO A PRIVACY NOTICE A. A Controller shall notify Consumers of material changes to a privacy notice. Such changes to a privacy notice shall be communicated to Consumers in a manner by which the Controller regularly interacts with Consumers.

  1. Material changes may include, but are not limited to, changes to: (1) categories of Personal Data Processed; (2) Processing purposes; (3) a Controller’s identity; (4) the act of sharing of Personal Data with Third Parties; (5) categories of Third Parties Personal Data is shared with; or (6) methods by which Consumers can exercise their Data Rights B. If a material change rises to the level of a secondary use, a Controller must obtain Consent from a Consumer pursuant to 4 CCR 904-3, Rules 7.02-7.05 in order to Process Personal Data that was collected before the change to the privacy notice for that Secondary Use.

Rule 6.05 LOYALTY PROGRAMS A. Pursuant to 6-1-1308(1)(d), a Controller is not prohibited from offering Bona Fide Loyalty Program Benefits to a Consumer based on the Consumer’s voluntary participation in a Bona Fide Loyalty Program.

B. If a Consumer exercises their right to delete Personal Data such that it is impossible for the Controller to provide a certain Bona Fide Loyalty Program Benefit to the Consumer, the Controller is no longer obligated to provide that Bona Fide Loyalty Benefit to the Consumer. However, the Controller shall provide any available Bona Fide Loyalty Program Benefit for which the deleted Personal Data is not necessary.

C. If a Consumer exercises their right to opt out of the Sale of Personal Data or Processing of Personal Data for Targeted Advertising, such that the exchange of Personal Data needed to obtain a Bona Fide Loyalty Program Benefit through a Bona Fide Loyalty Program Partner is no longer possible, the Controller is no longer obligated to provide that Bona Fide Loyalty Program Benefit to the Consumer.

  1. If the Controller’s Bona Fide Loyalty Program offers Bona Fide Loyalty Program Benefits that are unrelated to the exchange of Personal Data with a Bona Fide Loyalty Program Partner, the Controller shall continue to provide those Benefits to a Consumer who opts out of the Sale of Personal data or Processing of Personal Data for Targeted Advertising.

  2. The sale of Personal Data or Processing of Personal Data for Targeted Advertising that is unrelated to sharing of information with a Bona Fide Loyalty Program Partner is a Secondary Use that requires Consent pursuant to 4 CCR 904-3, Rule 6.08.

D. If a Consumer refuses to Consent to the Processing of Sensitive Data necessary for a personalized Bona Fide Loyalty Program Benefit, the Controller is no longer obligated to provide that personalized Bona Fide Loyalty Program Benefit. However, the Controller shall provide any available, non-personalized Bona Fide Loyalty Program Benefit for which the Sensitive Data is not necessary. A Controller may not condition a Consumer’s participation in a Bona Fide Loyalty Program on the Consumer’s Consent to Process Sensitive Data unless the Sensitive Data is required for all Bona Fide Loyalty Program Benefits.

E. If a Consumer’s decision to exercise a Data Right impacts the Consumer’s membership in a Bona Fide Loyalty Program, the Controller shall notify the Consumer of the impact of the Consumer’s decision in conformance with 4 CCR 904-3, Rule 3.02 and at least twenty-four (24) hours before discontinuing the Consumer’s Bona Fide Loyalty Program Benefit or membership, and must provide a reference or link to the information required by subparagraph F, below.

F. Loyalty Program Disclosures 1. In addition to all other disclosures required by 4 CCR 904-3, Rules 6.03 and 7.03, a Controller maintaining a Bona Fide Loyalty Program must provide the following disclosures at the point of program registration, either directly, or in the form of a link to the specific section of a privacy notice or terms and conditions containing such information:

a. The categories of Personal Data or Sensitive Data collected through the Bona Fide Loyalty Program that will be Sold or Processed for Targeted Advertising, if any;

b. Categories of Third Parties that will receive the Consumer’s Personal Data and Sensitive Data, provided in the level the detail described in 4 CCR 904-3, Rule 6.03(a)(1)(e), including whether Personal Data will be provided to Data Brokers;

c. A list of any Bona Fide Loyalty Program Partners, and the Bona Fide Loyalty Program Benefits provided by each Bona Fide Loyalty Program Partner.

d. If a Controller claims that a Consumer’s decision to delete Personal Data makes it impossible to provide a Bona Fide Loyalty Program Benefit, then the Controller shall provide an explanation of why the deletion of Personal Data makes it impossible to provide a Bona Fide Loyalty Program Benefit.

e. If a Controller claims that a Consumer’s Sensitive Data is required for a Bona Fide Loyalty Program Benefit, then the Controller shall provide an explanation of why the Sensitive Data is required for a Bona Fide Loyalty Program Benefit.

  1. Bona Fide Loyalty Program terms and requests for Consent to Process Sensitive Data or Personal Data in connection with the Bona Fide Loyalty Program shall also include a link to the Controller’s privacy notice.

G. Example: A Consumer joins a grocery store’s Bona Fide Loyalty Program that includes both personalized and non-personalized Bona Fide Loyalty Program Benefits. The grocery store asks the Consumer for Consent to collect Sensitive Data about the Consumer in order to provide personalized Bona Fide Loyalty Program Benefits. When the Consumer refuses Consent, the Controller gives timely notice to the Consumer that it will not provide the personalized Bona Fide Loyalty Program Benefits, but will continue to provide non-personalized Bona Fide Loyalty Program Benefits. Moving forward, the Controller provides only the non-personalized Bona Fide Loyalty Program Benefits following the Consumer’s decision to continue to refuse Consent to the collection of Sensitive Data. The Controller is not acting impermissibly because the grocery store is still providing all available non-personalized Bona Fide Loyalty Program Benefits and did not condition the Consumer’s participation in the Bona Fide Loyalty Program on the Consumers Consent to process Sensitive Data that is not required for personalized Bona Fide Loyalty Program Benefits.

H. Example: A Consumer joins a hotel chain’s Bona Fide Loyalty Program, which provides points that can be applied to obtain discounts for that hotel chain, and for a popular restaurant chain that is not otherwise affiliated with the hotel chain. The restaurant chain requires the hotel chain to provide the Personal Data of each Consumer who wishes to apply the hotel chain’s points to obtain restaurant discounts. When the Consumer opts out of the Sale of Personal Data and Processing of Personal Data for Targeted Advertising, the Controller is unable to provide the required information to the restaurant chain. The Controller may discontinue the Bona Fide Loyalty Program Benefit that allows Consumers to use points for discounts for the restaurant chain. However, the hotel chain must still provide all available Bona Fide Loyalty Benefits to be used at the hotel chain.

I. Example: A Consumer joins a retailer’s Bona Fide Loyalty Program that offers discounts on products based on the Consumer’s purchase history. The retailer wishes to fund the loyalty program, in part, by selling the Consumer’s purchase history to a Data Broker. The retailer must obtain the Consumer’s consent to Sell the Consumer’s Personal Data to the Data Broker because selling Personal Data obtained through a Bona Fide Loyalty Program to a Data Broker is a secondary use.

J. Example: A Consumer exercises their right to opt out of the Processing of Personal Data for Targeted Advertising. An online gaming company gives the Consumer fewer free games through the company’s service, arguing that the additional free games are for members of its loyalty program, which requires the use of Personal Data for Targeted Advertising. The company’s differential treatment is prohibited if the Processing of Personal Data is not necessary to provide the additional games. However, if the free games are provided by a Bona Fide Loyalty Program Partner that requires the Consumer data for Targeted Advertising through a co-marketing agreement with the Controller, the differential treatment may be appropriate.

Rule 6.06 PURPOSE SPECIFICATION A. Controllers shall specify the express purposes for which each category of Personal Data is collected and Processed in both external disclosures to Consumers, including privacy notices required by C.R.S. § 6-1-1308(1), as well as in any internal documentation required by this Part 6.

B. The express purpose must be described in a level of detail that gives Consumers a meaningful understanding of how each category of their Personal Data is used when provided for that Processing purpose.

C. If Personal Data is collected and Processed for more than one purpose, Controllers should specify each unrelated purpose with enough detail to allow Consumers to understand each individual, unrelated purpose.

  1. Controllers should not identify one broad purpose to justify numerous Processing activities that are only remotely related.

  2. Controllers should not specify one broad purpose to cover potential future Processing activities that are only remotely related.

  3. Controllers should not specify so many purposes for which Personal Data could potentially be processed to cover potential future processing activities that the purpose becomes unclear or uninformative.

D. If the Processing purpose has evolved beyond the original express purpose such that it becomes a distinct purpose that is no longer reasonably necessary to or compatible with the original express purpose, the Controller must review and update all related disclosures and documentation as necessary.

Rule 6.07 DATA MINIMIZATION A. To ensure all Personal Data collected is reasonably necessary for the specified purpose, Controllers shall carefully consider each Processing purpose and determine the minimum Personal Data that is necessary, adequate, or relevant for the express purpose or purposes.

B. Personal Data should only be kept in a form which allows identification of Consumers for as long as is necessary for the express Processing purpose(s). To ensure that the Personal Data are not kept longer than necessary, adequate, or relevant, Controllers shall set specific time limits for erasure or to conduct a periodic review.

  1. Any Personal Data determined to no longer be necessary, adequate, or relevant to the express Processing purpose(s) shall be deleted by the Controller and any Processors that the Controller has shared the Personal Data with.

  2. Biometric Identifiers, a digital or physical photograph of a person, an audio or voice recording containing the voice of a person, or any Personal Data generated from a digital or physical photograph or an audio or video recording held by a Controller shall be reviewed at least once a year to determine if its storage is still necessary, adequate, or relevant to the express Processing purpose. Such assessment shall be documented according to 4 CCR 904-3, Rule 6.11.

  3. Sensitive Data for which Controllers no longer have consent to Process, should be deleted or otherwise rendered permanently anonymized or inaccessible within a reasonable period of time after withdrawal of Consent.

C. A Controller shall not collect Personal Data other than those disclosed in its required privacy notice. If the Controller intends to collect additional Personal Data the Controller shall revise its privacy notice, and notify Consumers of the change to its privacy notice pursuant to 4 CCR 904-3,

Rule 6.04.

Rule 6.08 SECONDARY USE A. The specified Processing purpose is the purpose disclosed to Consumers at or before the time the Personal Data is collected or processed from Consumers. Such disclosure shall be included in any required privacy notice or Consent disclosure.

B. Before Processing Personal Data for purposes that are not reasonably necessary to or compatible with specified Processing purpose(s) disclosed on or after July 1, 2023, the Controller must obtain Consent consistent with C.R.S. § 6-1-1308 and 4 CCR 904-3, Rules 7.02-7.05.

C. When considering if the new Processing purpose is reasonably necessary to or compatible with the original specified purpose(s), Controllers may consider the following, as applicable:

  1. The reasonable expectation of an average Consumer concerning how their Personal Data would be Processed once it was collected;

  2. The link between the original specified purpose(s) for which the data was collected and the purpose(s) of further Processing;

  3. The relationship between the Consumer and the Controller and the context in which the Personal Data was collected;

  4. The type, nature, and amount of the Personal Data subject to the new Processing

purpose;

  1. The type and degree of possible consequence or impact to the Consumer of the new Processing purpose;

  2. The identity of the entity conducting the new Processing purposes, e.g., the same or different Controller, or a Third Party; and 7. The existence of additional safeguards for the Personal Data, such as encryption or pseudonymization.

Rule 6.09 DUTY OF CARE A. Personal Data must be Processed in a manner that ensures reasonable and appropriate administrative, technical, organizational, and physical safeguards of Personal Data collected, stored, and Processed.

B. When determining reasonable and appropriate safeguards, Controllers should consider:

  1. Applicable industry standards and frameworks;

  2. The nature, size, and complexity of the Controller’s organization;

  3. The sensitivity and amount of Personal Data;

  4. The original source of Personal Data;

  5. The risk of harm to Consumers resulting from unauthorized or unlawful access, use, or degradation of the Personal Data; and 6. The burden or cost of safeguards to protect Personal Data from harm assessed in 4 CCR 904-3, Rule 6.09(B)(5).

C. Reasonable and appropriate administrative, technical, organizational, and physical safeguards must be designed to:

  1. Protect against unauthorized or unlawful access to or use of Personal Data and the equipment used for the Processing and against accidental loss, destruction, or damage;

  2. Ensure the confidentiality, integrity, and availability of Personal Data collected, stored, and Processed;

  3. Identify and protect against reasonably anticipated threats to security or the integrity of information; and 4. Oversee compliance with data security policies by the Controller and Processors through reasonable requirements.

D. Reasonable and appropriate administrative, technical, organizational, and physical safeguards to secure Personal Data include but are not limited to those measures provided by C.R.S. § 6-1- 713.5 and C.R.S. § 24-73-102, as interpreted by state courts and administrative orders.

Rule 6.10 DUTY REGARDING SENSITIVE DATA A. Controllers must obtain Consent to Process Sensitive Data, including Sensitive Data Inferences, consistent with C.R.S. § 6-1-1308(7) and 4 CCR 904-3, Rules 7.02-7.05.

B. Controllers may be exempt from obtaining Consent to Process Sensitive Data Inferences from Consumers over the age of thirteen (13) only if:

  1. The Processing purpose of such Personal Data would be obvious to a reasonable Consumer based on the context of the collection and use of the Personal Data, and the relationship between the Controller and Consumer;

  2. Sensitive Data Inferences are permanently deleted within twenty-four (24) hours of collection or of the completion of the Processing activity, whichever comes first;

  3. Sensitive Data Inferences are not transferred, sold, or shared with any Processors, Affiliates, or Third-Parties; and 4. The Personal Data and any Sensitive Data Inferences are not Processed for any purpose other than the express purpose disclosed to the Consumer.

C. If a Controller will delete Sensitive Data Inferences within twenty-four (24) hours, pursuant to this

section, they must (1) include description of the Sensitive Data Inferences subject to this provision and the retention and deletion timeline for such Sensitive Data Inferences in its privacy notice, pursuant to 4 CCR 904-3, Rule 6.03, and (2) include the details of the deletion and verification process in the Controller’s Data Protection Assessment, pursuant to 4 CCR 904-3,

Rule 8.04.

Rule 6.11 DOCUMENTATION CONCERNING DUTIES OF CONTROLLERS A. Controllers shall maintain records of all Consumer Data Rights requests made pursuant to C.R.S. § 6-1-1306 for at least twenty-four (24) months. Such records shall include, at a minimum, each of the following:

  1. The date of request;

  2. The Consumer Data Rights request type;

  3. The date of the Controller’s response;

  4. The nature of the Controller’s response;

  5. The basis for the denial of the request if the request is denied in whole or in part; and 6. The existence and resolution of any Consumer appeal to a denied request.

B. Controllers shall maintain a record of all Data Rights requests made pursuant to C.R.S. § 6-1- 1306 with which the Controller has previously complied. Such records shall be retained for at least twenty-four (24) months and shall be made available at the completion of a merger, acquisition, bankruptcy, or other transaction in which a Third Party assumes control of Personal Data to ensure any new Controller continues to recognize the Consumer’s previously exercised Data Rights.

C. Controllers shall maintain documents sufficient to demonstrate compliance with 4 CCR 904-3, Rules 6.07, 6.08, and 7.06 for as long as the Processing activity continues, and for at least twenty-four (24) months after the conclusion of Processing activity.

D. Required records shall be maintained in a readable format, appropriate to the sophistication and size of the Controller’s business.

E. The Controller shall implement and maintain reasonable security procedures and practices, consistent with 4 CCR 904-3, Rule 6.09, in maintaining all required records.

F. Personal Data maintained pursuant to this 4 CCR 904-3, Rule 6.11, where that information is not used for any other purpose, shall not be subject to Data Rights requests.

G. Personal Data maintained for required documentation shall not be used for any other purpose except as reasonably necessary for the business to review and modify its processes for compliance with the Colorado Privacy Act, C.R.S. § 6-1-1301, et seq., and these rules. Personal Data maintained for required documentation shall not be shared with any Third Party except as necessary to comply with a legal obligation or as part of a merger, acquisition, bankruptcy, or other transaction in which a Third Party assumes control of Personal Data.

H. Other than as required by this subsection and 4 CCR 904-3, Rule 4.06, a Controller is not required to retain Personal Data solely for the purpose of fulfilling a Data Rights request made under the Colorado Privacy Act, C.R.S. § 6-1-1301, et seq.

Rule 6.12 BIOMETRIC IDENTIFIER NOTICE A. Controllers required to provide a Biometric Identifier Notice shall comply with all requirements for disclosures and communications to Consumers provided in 4 CCR 904-3, Rule 3.02.

B. The Biometric Identifier Notice shall occur at or before the initial collection or Processing of any Biometric Identifiers, or before a material change to the Processing purpose of a Biometric Identifier.

C. A Biometric Identifier Notice must be clear. Information contained in such notice shall be:

  1. Concrete and definitive, avoiding abstract or ambivalent terms that may lead to varying interpretations.

  2. If included in a privacy notice, clearly labeled, such that Consumers seeking to understand a Controller’s collection and use of Biometric Identifiers can easily access the

section of the privacy notice containing relevant information.

D. A Biometric Identifier Notice must be reasonably accessible. Such notice may be:

  1. A separate notice, or included within a general privacy notice if the privacy notice is clearly labeled as required by 4 CCR 904-3, Rule 6.12(C)(2); and 2. Made available in its entirety prior to the collection or Processing of Biometric Identifiers, or linked from a website’s homepage, and if applicable, a mobile application’s app store page or download page.

a. A link made available on the homepage of a website or on a mobile application’s app store page or download page must be conspicuous and must clearly indicate it relates to Biometric Identifiers in the link text. A Controller that Processes Biometric Identifiers and maintains an application on a mobile or other device shall also include a link to the Biometric Identifier Notice in the application’s settings menu.

b. If the link directs to a privacy notice, it must point the Consumer to the specific

section of the privacy notice that includes the Biometric Identifier Notice disclosures.

E. A Controller that does not operate a website shall make the Biometric Identifier Notice conspicuously available to Consumers through a medium regularly used by the Controller to interact with Consumers. For instance, if a Controller interacts with a Consumer offline, an offline version of the privacy notice must be available to the Consumer.

Rule 6.13 DUTY REGARDING MINOR DATA – KNOWLEDGE STANDARD A. The following factors may be considered when determining if a Controller willfully disregards that a Consumer is a Minor as contemplated in C.R.S. § 6-1-1308.5:

  1. If the Controller has directly received credible information from a parent or Consumer indicating that the Consumer is a Minor.

a. Example: A Controller requires or allows Consumers to provide their date of birth at sign up and the Consumer indicates they are a Minor.

b. Example: A Controller requires Consumers to provide their date of birth at sign up, which can be edited once registration is completed. A Consumer uses a fake birthdate to sign up and subsequently revises their birthdate after registration to indicate that they are a Minor.

c. Example: A Controller directly receives a credible report from a parent about a Minor using the service.

d. Example: A Consumer provides their age in the bio section of the profile on a Consumer’s service indicating that they are a Minor.

e. Example: A Consumer provides relevant indicia that they are a Minor, such as year of birth, in the profile or account set up of a service.

  1. If the Controller has intentionally directed the website or service to Minors, considering different factors such as marketing or promotional materials that refer to the intended audience as “minors” or “teens”, hosting or displaying advertisements that are directed to Minors, or empirical evidence demonstrating that the intended or actual audience is largely composed of Minors.

a. Example: A Controller creates and distributes marketing and promotional materials related to the website or service that specifically appeal to Minors.

b. Example: A Controller tells advertising partners that advertisements on its website or service will overwhelmingly reach an audience of Minors.

  1. If the Controller has categorized a Consumer as a Minor to serve advertising on the platform or service.

a. Example: A Controller uses Consumer data (such as user-generated content or data provided by a third party) to estimate a Consumer’s age, which indicates that they are a Minor, and the Controller serves ads to them based on that estimation.

B. In addition to the factors included in this part 4 CCR 904-3, Rule 6.13, Controllers may consider statutes, administrative rules, and administrative guidance concerning age knowledge standards from other jurisdictions when evaluating the appropriateness of treating a Consumer as a Minor as contemplated in C.R.S. § 6-1-1308.5.

C. The factors included in this part 4 CCR 904-3, Rule 6.13 are not exhaustive, and no one factor is dispositive when considering if a Controller willfully disregards that a Consumer is a Minor as contemplated in C.R.S. § 6-1-1308.5. The Attorney General shall consider a totality of the circumstances when evaluating if a Controller willfully disregards that a Consumer is a Minor as D. Consistent with C.R.S. § 6-1-1304(3)(f), nothing in this part shall require a Controller or Processor to implement a commercially reasonable age verification or age-gating system or otherwise affirmatively collect, retain, use, link, or combine personal data concerning a Consumer that it would not otherwise collect, retain, use, link, or combine in the ordinary course of business, including, for example, the age of consumers.

Rule 6.14 DUTY REGARDING MINOR DATA – SYSTEM DESIGN FEATURES A. The following factors may be considered when determining if a system design feature significantly increases, sustains, or extends a Minor’s use of an online service, product, or feature and is subject to the consent requirement as contemplated in C.R.S. § 6-1-1308.5:

  1. Whether the controller developed or deployed the system design feature primarily to significantly increase, sustain, or extend a Minor’s use of or engagement with an online service, product, or feature;

  2. Whether the system design feature has been shown by competent and reliable empirical evidence to cause harm due to increased use of or engagement with an online service, product, or feature;

  3. Whether the system design feature has the substantial effect of subverting or impairing Minor autonomy, decision making or choice, or unfairly, fraudulently, or deceptively manipulating or coercing a Minor.

B. A system design feature will likely not be found to significantly increase, sustain, or extend a Minor’s use of an online service, product, or feature:

  1. If the Minor expressly and unambiguously requested specific media or category of media, the Minor subscribed to specific media by the author, creator, or poster, or the Minor has subscribed to a page or group featuring specific media, provided that the media is not recommended, selected, or prioritized for display based, in whole or in part, on other information associated with the Minor or the Minor's device;

  2. If media are recommended, selected, or prioritized only in response to a specific search inquiry by the Minor, or is exclusively next in a pre-existing sequence from the same author, creator, poster, or source;

  3. If the system design feature is one that is necessary to the core functionality of an online service, product, or feature;

  4. If the system design feature is based on Personal Data that is not persistently associated with the Minor or the Minor’s device;

  5. If the system design feature does not consider the Minor’s previous interactions with media generated or shared by other Consumers;

  6. If the online service, product, or feature contains countervailing measures that could mitigate the harm or other negative effects of the system design feature, such as default time of day or time use limits, or required parental controls;

  7. If the system design feature’s primary function is to enhance the safety of the platform for Minors, remove spam, or filter out age-inappropriate content.

C. The fact that a system design feature is commonly used is not, alone, enough to demonstrate that any particular feature does not significantly increase, sustain, or extend a Minor’s use of an online service, product, or feature.

D. In addition to the factors included in this part 4 CCR 904-3, Rule 6.13, Controllers may consider statutes, administrative rules, and administrative guidance concerning system design features from other jurisdictions when evaluating the likelihood that a system design feature significantly increases, sustains, or extends a Minor’s use of an online service, product, or feature as E. The factors included in this part 4 CCR 904-3, Rule 6.14 are not exhaustive, and no one factor is dispositive when determining if a system design feature significantly increases, sustains, or extends a Minor’s use of an online service, product, or feature. The Attorney General shall consider a totality of the circumstances when evaluating if a system design feature significantly increases, sustains, or extends a Minor’s use of an online service, product, or feature as F. Consistent with C.R.S. § 6-1-1304(g), this Rule does not impose any obligation on a Controller or Processor that adversely affects the rights of any person to freedom of speech or the freedom of the press guaranteed by the First Amendment to the United States Constitution.

PART 7 CONSENT

Rule 7.01 AUTHORITY AND PURPOSE A. The statutory authority for the rules in this Part 7 is C.R.S. §§ 6-1-108(1), 6-1-1303(5), 6-1-1306, 6-1-1308, 6-1-1308.5 (eff. Oct. 1, 2025), 6-1-1313 and 6-1-1314(4) (eff. July 1, 2025). The

purpose of the rules in this Part 7 is to provide clarity on the requirements to obtain Consent when Consent is required under the statute, including the prohibition against obtaining agreement through the use of Dark Patterns.

Rule 7.02 REQUIRED CONSENT A. Pursuant to C.R.S. §§ 6-1-1303(5), 6-1-1306(1)(a)(IV)(C), 6-1-1308(4), 6-1-1308(7), 6-1-1308.5, and 6-1-1314(4) a Controller must obtain valid Consumer Consent prior to:

  1. Processing a Consumer’s Sensitive Data;

  2. Processing Personal Data concerning a known Child, in which case the Child’s parent or lawful guardian must provide Consent;

  3. Selling a Consumer’s Personal Data, Processing a Consumer’s Personal Data for Targeted Advertising, or Profiling in furtherance of Decisions that Produce Legal or Similarly Significant Effects Concerning a Consumer after the Consumer has exercised the right to opt out of the Processing for those purposes;

  4. Processing Personal Data for purposes that are not reasonably necessary to, or compatible with, the original specified purposes for which the Personal Data are Processed;

  5. Processing the Personal Data of a Consumer whom the Controller actually knows or willfully disregards is a Minor as contemplated in C.R.S. § 6-1-1308.5(2);

  6. Using any system design feature to significantly increase, sustain, or extend the use of an online service, product, or feature by a Consumer whom the Controller actually knows or willfully disregards is a Minor, as contemplated in C.R.S § 6-1-1308.5(2); and 7. Selling, leasing, trading, disclosing, redisclosing, or otherwise disseminating Biometric Identifiers, subject to the exceptions in 6-1-1314(4)(b).

B. Controllers may rely upon valid consent obtained prior to July 1, 2023, to continue to Process a Consumer’s previously collected Personal Data, including Sensitive Data, collected before July 1, 2023. Consent obtained before July 1, 2023, shall be considered valid only if it would comply with the requirements set forth in C.R.S. §§ 6-1-1303(5), 6-1-1306(1)(a)(IV)(C), 6-1-1308(4), and 6-1- 1308(7) and Part 7 of these rules.

  1. Controllers that do not obtain valid Consent prior to July 1, 2023 to continue to use, store, or otherwise Process Sensitive Data collected prior to this date must obtain valid Consent, as required by C.R.S. §§ 6-1-1303(5), 6-1-1306(1)(a)(IV)(C), 6-1-1308(4), and 6-1-1308(7) and Part 7 of these rules, by July 1, 2024 to continue to Process the previously collected Sensitive Data.

  2. If a Controller has collected Personal Data prior to July 1, 2023 and the Processing

purpose changes after July 1, 2023 such that it is considered a secondary use pursuant to C.R.S. § 6-1-1308(4) and 4 CCR 904-3, Rule 6.08, the Controller must obtain valid Consent, as required by C.R.S. §§ 6-1-1303(5), 6-1-1306(1)(a)(IV)(C), 6-1-1308(4), and 6-1-1308(7) and Part 7 of these rules, at the time the Processing purpose changes to continue to Process the previously collected Personal Data.

C. Notwithstanding the above, a Controller Processing Sensitive Data Inferences is not required to obtain Consent for the Processing activity if the Processing falls within the requirements of 4 CCR 904-3, Rule 6.10.

Rule 7.03 REQUIREMENTS FOR VALID CONSENT A. To be valid, a Consent must meet each of the following elements: (1) it must be obtained through the Consumer's clear, affirmative action; (2) it must be freely given by the Consumer; (3) it must be specific; (4) it must be informed; and (5) it must reflect the Consumer’s unambiguous agreement.

B. Consent must be obtained through the Consumer’s clear, affirmative action. For purposes of obtaining valid Consent:

  1. A “clear, affirmative action” means a Consumer’s Consent is communicated through either (a) deliberate and clear conduct, or (b) a statement that clearly indicates their acceptance of the proposed Processing of their Personal Data.

  2. A blanketed acceptance of general terms and conditions, silence, inactivity or in action, pre-ticked boxes, and other negative option opt-out constructions that require intervention from the Consumer to prevent agreement are not clear affirmative actions for the purposes of valid Consent.

  3. If a system design feature that significantly increases, sustains, or extends a Minor’s use of an online service, product, or feature is turned off by default or by the Minor, and the Minor turns on or enables the feature, such an act will be considered an affirmative action for the purpose of valid Consent as contemplated by C.R.S. § 6-1-1308.5.

C. Consent must be freely given. For purposes of obtaining valid Consent:

  1. Consent is freely given when Consumers may refuse Consent without detriment and withdraw Consent easily at any time.

  2. Consent is not freely given when:

a. It reflects acceptance of a general or broad terms of use or similar document that contains descriptions of Personal Data Processing along with other, unrelated information;

b. The performance of a contract is dependent on Consent to Process Personal Data that is not necessary to provide the goods or services contemplated by the contract; or c. The Controller denies goods, services, discounts, or promotions to a Consumer who chooses not to provide Consent, unless:

i. The Personal Data is necessary to the provision of those goods, services, discounts, or promotions, consistent with 4 CCR 904-3, Rule 6.05; or ii. The Consent is otherwise required in connection with a Consumer’s voluntary participation in a Bona Fide Loyalty Program, consistent with the requirements in 4 CCR 904-3, Rule 6.05.

  1. Example: An online dating application’s terms and conditions tells users that the application will disclose collected Personal Data, including Sensitive Data revealing sexual orientation, with similar applications for advertising purposes. Consent is required for the disclosure of Sensitive Data with similar applications for advertising purposes.

Since users cannot accept the required terms and conditions without the opportunity to separately provide or withhold Consent for sharing with similar applications, the Consent is not freely given.

D. Consent must be specific.

  1. When Controllers request Consent to Process Personal Data for more than one Processing purpose, and those Processing purposes are not reasonably necessary to or compatible with one another, Consumers must have the ability to separately Consent to each specific purpose.

a. Controllers may request Consent to Process Personal Data for multiple Processing purposes that are not reasonably necessary to or compatible with one another using a single Consent request as long there is also an option for more granular Consent within the same Consent interface.

  1. Consent to Process Personal Data for one specific purpose does not constitute valid Consent to Process Personal Data for other purposes that are not reasonably necessary to or compatible with that specific purpose.

  2. The Sale of Sensitive Data to one specific party is not necessary to or compatible with the Sale of Sensitive Data to a different party.

a. Example: A cosmetic retailer asks a customer for Consent to use Sensitive Data revealing the customer’s racial origin in order to provide first-party targeted offers to the customer and to Sell the customer’s racial origin information to Data Brokers. This Consent is not specific as there is no opportunity to provide separate Consent for the two separate Processing purposes. Therefore, Consent in this example would not be valid.

b. Example: In the example above, the Controller requests Consent only to Sell Sensitive Data revealing the customer’s racial origin with commercial partners.

The Controller lists “Fashion Co. #1” and “Make Up Co. #1” as commercial partners who will receive Sensitive Data. Consent would be deemed valid for only these two Third Parties because their identity was provided to the Consumer at the time that his or her Consent was collected. Consent would not be deemed valid for Selling with another Third Party whose identity has not been provided.

E. Consent must be informed.

  1. When requesting Consent, a Controller must provide the following information, at a minimum:

a. The Controller’s identity;

b. The plain-language reason that Consent is required;

c. The Processing purpose(s) for which Consent is sought;

d. The categories of Personal Data that the Controller shall Process to effectuate the Processing purpose(s);

e. Names of all Third Parties receiving the Sensitive Data through Sale, if applicable;

f. A description of the Consumer’s right to withdraw Consent for the identified Processing purpose at any time in accordance with 4 CCR 904-3, Rule 7.07 and details of how and where to do so; and g. Any disclosures required by 4 CCR 904-3, Rules 6.05 and 9.05.

F. Consent may not be obtained using Dark Patterns as defined in C.R.S § 6-1-1309(9) and prohibited by 4 CCR 904-3, Rule 7.09. Pursuant to C.R.S. § 6-1-1303(5)(c) and 4 CCR 904-3,

Rule 7.09, any agreement obtained through Dark Patterns is not valid Consent.

Rule 7.04 REQUESTS FOR CONSENT A. Controllers shall provide a simple form or mechanism to enable a Consumer to provide Consent when required, including Consent to Processing purposes from which the Consumer has previously opted out. Such a form or mechanism should be easy for a reasonable Consumer to locate and should comply with the other requirements set forth in Part 7 of these rules.

B. Requests for Consent shall be prominent, concise, and separate and distinct from other terms and conditions, and shall comply with all requirements for disclosures and communications to Consumers set forth in 4 CCR 904-3, Rule 3.02.

C. Any Consent request by a Controller must contain the disclosures required by 4 CCR 904-3, Rule 7.03(E)(1) either directly or through a link. Where possible, the request interface itself should contain the disclosures required by 4 CCR 904-3, Rule 7.03(E)(1)(a)-(d). Alternatively, the Controller may provide the Consumer with a link to a webpage containing the required Consent disclosures, provided the request clearly states the title and heading of the webpage section containing the relevant disclosures. If technically feasible, the request method must also link the Consumer directly to the relevant section of the disclosure.

D. Example: A mobile application requests Consent to Process Sensitive Data. The Consent request provides a link to the application’s privacy notice which contains the required Consent disclosures. However, the Consent request does not direct or bring the Consumer to the relevant

section of the privacy notice. Consent is not valid because the Consent request does not clearly indicate the title and section where the Consumer can find the required disclosures and did not link the Consumer directly to the relevant section of the privacy notice.

E. Example: Acme Toy Store collects customer email addresses in order to send customers information about product recalls, and maintains those email addresses in a recall email distribution list. Acme Toy Store wants to Sell the recall email distribution list to a Third Party partner to enable that partner to send those customers promotional materials. Acme Toy Store must obtain customer consent prior to Selling the recall email distribution list because Selling the recall email distribution list is not reasonably necessary to or compatible with providing product recall information. Acme Toy Store emails its customers attaching a revised privacy notice disclosing the new Processing purpose and asks customers to Consent to the new privacy notice, but does not state the new purpose in the email, and does not direct customers to the section of the privacy notice disclosing the secondary purpose. Consent is not valid because the email did not contain the required Consent disclosures or direct the customers to a document containing the required Consent disclosures.

  1. Example: Under the same circumstances, Acme Toy Store emails its customers on the recall distribution list informing those customers that Consent is required for the Acme Toy Store to Process email addresses for the secondary purpose of Selling the recall distribution list to a Third Party partner to enable that partner to send promotional materials, providing all other required disclosures and including a mechanism that enables the customers to provide Consent and to revoke Consent through the same user interface. Consent is valid because the email contained all required Consent disclosures in an acceptable form.

  2. Example: Under the same circumstances, Acme Toy Store emails the product recall email distribution list informing those customers that it would like to use their email addresses for the secondary purpose of Selling the recall distribution list to a Third Party partner as contemplated in section B.2.e. of its privacy notice, explains that it cannot use the customers’ email addresses for that secondary purpose without their consent, and requests the customers’ Consent to Process their email address for that secondary

purpose. It then provides a link directly to section B.2.e. of its privacy notice which explains that Acme Toy Store Sells customer email addresses, including those Processed for the purpose of product recall notifications, to marketing partners, in addition to all other disclosures. The email provides a Consent mechanism that enables the customers to provide or revoke consent through the same user interface. Consent is valid because the email and linked page together contained all required disclosures, the email provided the specific section of the relevant disclosures, and the link brought the customers directly to the relevant disclosures.

Rule 7.05 CONSENT AFTER OPT-OUT A. The Consumer’s decision to Consent to Processing activities from which the Consumer has previously opted-out using either a Universal Opt-Out Mechanism or directly with a particular Controller is subject to the requirements for Consent under 4 CCR 904-3, Rules 7.03 and 7.04.

B. A Controller that wishes to obtain Consent to Process Personal Data for an Opt-Out Purpose after the Consumer has opted out of Processing for that Purpose shall not request Consent using schemes that cause consent fatigue, such as interface dominating cookie banners, high frequency requests, cookie walls, pop-ups, or other any other interstitials that degrade or obstruct the Consumer’s experience on the Controller’s web page or application.

  1. A Controller may proactively request Consent to Process Personal Data for an Opt-Out

Purpose after the Consumer has opted out, by providing a link to a privacy settings page, menu, or similar interface, or comparable offline method, that enables the Consumer to Consent to the Controller Processing the Personal Data for the Opt-Out Purpose, so long as the request for Consent meets all other requirements for valid Consent under this Part 7.

  1. If a Controller has a reasonable belief that a Consumer intended to opt back into the Sale of Personal Data or Processing of Personal Data for Targeted Advertising, the Controller may proactively send a link to a privacy settings page or other method to enable the Consumer to Consent to the Controller Processing the Personal Data for the Opt-Out

Purpose directly to a Consumer.

C. If a Controller conspicuously displays the status of the Consumer’s opt-out choice on the website pursuant to 4 CCR 904-3, Rule 5.08(E), the link to provide Consent may appear beside or in conjunction with the Consumer’s opt-out status.

D. If a Consumer has opted-out of the Processing of Personal Data for the Opt-Out Purposes, and then initiates a transaction or attempts to use a product or service inconsistent with the request to opt-out, such as signing up for a Bona Fide Loyalty Program that also involves the Sale of Personal Data to a Bona Fide Loyalty Program Partner, the Controller may request the Consumer’s Consent to Process the Consumer’s Personal Data for that purpose, so long as the request for Consent complies with all provisions of 4 CCR 904-3, Rules 7.03 and 7.04.

E. Example: A Consumer opts out of the use of Personal Data for Sale or Targeted Advertising using a Universal Opt-Out Mechanism. The Consumer visits the website of a fashion retailer that routinely shares Consumer Personal Data for Targeted Advertising. The fashion retailer must obtain the Consumer’s consent because the Consumer has already opted out of Processing for that purpose. The fashion retailer’s website displays a pop-up banner seeking Consent to share the Consumer’s Personal Data for Targeted Advertising. This is not a valid request for Consumer Consent because the request is made through a pop-up banner that degrades or obstructs the Consumer’s experience on the Controller’s web page or application.

F. Example: A Consumer opts out of the use of Personal Data for Sale or Targeted Advertising using a Universal Opt-Out Mechanism. The Consumer visits a fashion retailer’s website. The fashion retailer’s homepage contains a message at the top of the webpage that displays the Consumer’s opt-out status, stating, “you have opted out of targeted advertising” next to a link that states “Opt-in to Data Use”. The linked webpage also meets all requirements of 4 CCR 904-3, Rules 7.03 and 7.04. Consent pursuant to this request is valid.

Rule 7.06 CONSENT FOR CHILDREN A. When a Controller engages in Processing activities involving the collection and Processing of Personal Data from a known Child or operates a website or business directed to Children or has actual knowledge that it is collecting or maintaining Personal Data from a Child, the Controller must obtain Consent from the parent or lawful guardian of that Child before collecting or Processing the Child’s Personal Data.

B. A Controller Processing the Personal Data of a Child must make reasonable efforts to obtain verifiable parental Consent, taking into consideration available technology. Any method to obtain verifiable parental Consent must be reasonably calculated, in light of available technology, to ensure that the person providing Consent is the Child's parent or lawful guardian.

C. Reasonably calculated methods for determining that a person Consenting to the Processing of a Child’s Personal Data is the parent or lawful guardian of that Child include, but are not limited to:

  1. Providing a Consent form to be signed by the parent or guardian under penalty of perjury and returned to the business by postal mail, facsimile, or electronic scan;

  2. Requiring a parent or guardian, in connection with a monetary transaction, to use a credit card, debit card, or other online payment system that provides notification of each discrete transaction to the primary account holder;

  3. Having a parent or guardian call a toll-free telephone number staffed by trained personnel;

  4. Having a parent or guardian connect to trained personnel via videoconference; and 5. Verifying a parent or guardian’s identity by checking a form of government-issued identification against databases of such information, as long as the parent or guardian’s identification is deleted by the business from its records promptly after such verification is complete.

D. Any Personal Data collected for purposes of verifying the identity of a parent or legal guardian may not be used for any reason other than Processing these verifications.

Rule 7.07 REFUSING OR WITHDRAWING CONSENT A. A Consumer shall be able to refuse or revoke Consent as easily and within a similar number of steps as Consent is affirmatively provided.

B. If Consent is obtained through an electronic interface, the Consumer shall be able to refuse or withdraw Consent through the same or similar electronic interface.

C. When using an electronic interface, and when feasible based on the Consumer’s relationship with the Controller, a Controller may allow Consumers to track what Processing activities they have Consented to or opted out of.

D. There shall be no detriment to a Consumer for refusing or withdrawing Consent, consistent with C.R.S. § 6-1-1308(1)(c)(II), and 4 CCR 904-3, Rule 6.05.

  1. Notwithstanding 4 CCR 904-3 Rule 7.07(D), if a Consumer refuses to Consent to, or withdraws consent for the Processing of Sensitive Data or Personal Data strictly necessary for a program, product or service, the Controller is no longer obligated to provide that program, product or service.

E. If a Consumer withdraws Consent for a Processing activity, subject to Consent under C.R.S. §§ 6-1-1306(1)(a)(IV)(C), 1308(4), and 1308(7), the Controller shall cease that Processing activity and, in the notice required by C.R.S. § 6-1-1306(2), provide the Consumer instructions on how to exercise the right to deletion, provide a link to exercise the right to deletion, or inform the Consumer that information regarding the right to delete their Personal Data can be found in the Controller’s privacy notice.

Rule 7.08 REFRESHING CONSENT A. When a Consumer has not interacted with a Controller in the prior twenty-four (24) months, the Controller must refresh Consent in compliance with all requirements of this Part 7 to:

  1. Continue Processing Sensitive Data pursuant to C.R.S. § 6-1-1308(7); or 2. Continue Processing Personal Data for a Secondary Use pursuant to C.R.S. § 13-8(4), if the Secondary Use involves Profiling for a decisions that results in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services.

B. Controllers are not required to refresh Consent under part A of this section where a Consumer has access and ability to update their opt-out preferences at any time through a user-controlled interface.

C. If a Processing purpose materially evolves such that the new purpose becomes a secondary use pursuant to C.R.S. § 6-1-1308(4), the Consumer’s original Consent is no longer valid, and the Controller must obtain new Consent pursuant to Part 7 of these rules.

D. Employers required to obtain Consent pursuant to C.R.S. § 6-1-1314(6)(b) are not required to refresh Consent under part A of this section.

  1. Employers required to obtain Consent pursuant to C.R.S. § 6-1-1314(6)(b) must refresh Consent in compliance with all requirements of this Part 7 when:

a. Processing additional categories of an Employee’s Biometric Identifier for which the Employee has not yet provided consent; and b. Processing an Employee’s Biometric Identifier for a Secondary Use.

  1. To comply with C.R.S. § 6-1-1314(6)(b), Consent must be obtained from an Employee.

Consent obtained from a prospective Employee during the hiring process is not sufficient to fulfill the requirements of C.R.S. § 6-1-1314(6)(b).

Rule 7.09 EMPLOYEE CONSENT TO COLLECT AND PROCESS BIOMETRIC IDENTIFIERS A. Employers may only require as a condition of employment that an Employee or a prospective Employee Consent to the collection and Processing of the Employee’s or prospective Employee’s Biometric Identifier consistent with C.R.S. § 6-1-1314(6).

B. Consent requested by an Employer to collect or Process an Employee’s or prospective Employee’s Biometric Identifier shall be consistent with all requirements for disclosures and communications to Consumers provided in 4 CCR 904-3, Rule 3.02(A).

C. Consent required by an Employer to collect or process an Employee’s or prospective Employee’s Biometric Identifier shall be consistent with the requirements for Consent provided in 4 CCR 904- 3, Rules 7.03-7.08:

Rule 7.10 USER INTERFACE DESIGN, CHOICE ARCHITECTURE, AND DARK PATTERNS A. The following principles should be considered when designing a user interface or a choice architecture used to obtain Consent when required under C.R.S. §§ 6-1-1303(5), 6-1- 1306(1)(a)(IV)(C), 6-1-1308(4), and 6-1-1308(7):

  1. Consent choice options should be presented to Consumers in a symmetrical way that does not impose unequal weight or focus on one available choice over another such that a Consumer’s ability to consent is impaired or subverted.

a. Example: One choice should not be presented with less prominent size, font, or styling than the other choice. Presenting an “I accept” button in a larger size than the “I do not accept” button would not be considered equal or symmetrical.

Presenting an “I do not accept” button in a greyed-out color while the “I accept” button is presented in a bright or obvious color would not be considered equal or symmetrical.

b. Example: If multiple choices are offered to a Consumer, it should be equally easy to accept or reject all options. Presenting the option to “accept all” when offering a Consumer the choice to Consent to the use of Sensitive Data for multiple purposes without an option to “reject all” would not be considered equal or symmetrical.

  1. Consent choice options should avoid the use of emotionally manipulative language or visuals to unfairly, fraudulently, or deceptively coerce or steer Consumer choice or Consent.

a. Example: One choice should not be presented in a way that creates unnecessary guilt or shames the user into selecting a specific choice. Presenting the choices “I accept, I want to help endangered species” vs “No, I don’t care about animals” may be considered unfairly emotionally manipulative.

b. Example: The explanation of the choice to Consumers should not include gratuitous information to emotionally manipulate Consumers. Explaining that a mobile application “helps save lives” when asking for Consent to collect Sensitive Data for Targeted Advertising may be considered deceptively emotionally manipulative if the Targeted Advertising is not critical to the lifesaving functionality of the application.

  1. A Consumer’s silence or failure to take an affirmative action should not be interpreted as acceptance or Consent.

a. Example: A Consumer closing a pop-up window which requests Consent without first affirmatively selecting the equivalent of an “I accept” button should not be interpreted as Consent.

b. Example: A Consumer navigating forward on a webpage after a Consent choice has been presented without selecting the equivalent of an “I accept” button should not be interpreted as affirmative Consent.

c. Example: A Consumer continuing to use a Smart TV without replying “I accept” or “I consent” in reply to a verbal request for Consent should not be interpreted as affirmative Consent.

  1. Consent choice options should not be presented with a preselected or default option.

a. Example: Checkboxes or radio buttons should not be selected automatically when presented to a Consumer.

  1. A Consumer should be able to select either Consent choice option within a similar number of steps. A Consumer’s ability to exercise a more privacy-protective option shall not be unduly longer, more difficult, or time-consuming than the path to exercise a less privacy-protective option.

a. Example: Consumers should be presented with all choices at the same time.

Presenting an "I accept” button next to a “Learn More” button which requires Consumers to take an extra step before they are given the option of an “I do not accept” button could be considered an unnecessary restriction.

b. Example: Describing the choice before Consumers and placing both the “I accept” and “I do not accept” buttons after a “select preferences” button would not be considered an unnecessary restriction.

  1. A Consumer’s expected interaction with a website, application, or product should not be unnecessarily interrupted or intruded upon to request Consent.

a. Example: Consumers should not be interrupted multiple times in one visit to a website to Consent if they have declined the Consent choice offered when they arrived at the page.

b. Example: Consumers should not be redirected away from the content or service they are attempting to interact with because they declined the Consent choice offered, unless Consent to process the requested data is strictly necessary to provide the website or application content or experience.

c. Example: Consumers should not be forced to navigate through multiple pop-ups which cover or otherwise disrupt the content or service they are attempting to interact with because they declined the Consent choice offered.

  1. Consent choice options should not include misleading statements, omissions, affirmative misstatements, or intentionally confusing language to obtain Consent.

a. Example: Choices should not be driven by a false sense of urgency. A countdown clock displayed next to a Consent choice option which states “time is running out to Consent to this data use and receive a limited discount” where the discount is not actually limited by time or availability would be considered creating a false sense of urgency.

b. Example: Choices should avoid the use of double negatives when describing Consent choice options to Consumers.

c. Example: Consent choice options should not be presented with confusing or unexpected syntax. “Please do not check this box if you wish to Consent to this data use” would be considered confusing syntax.

d. Example: The language used for choice options should logically follow the question presented to the Consumer. Offering the options of “Yes” or “No” to the question “Do you wish to provide or decline Consent for the described purposes” would be considered an illogical choice option. The choice options “provide” and “decline” would be considered to logically follow the same question.

  1. The vulnerabilities or unique characteristics of the target audience of a product, service, or website should be considered when deciding how to present Consent choice options.

a. Example: A website or service that primarily interacts with Consumers under the age of 18 should consider the simplicity of the language used to explain the choice options or the way in which cartoon imagery or endorsements might unduly influence their choice.

b. Example: A website or service that primarily interacts with the elderly should consider font size and space between buttons to ensure readability and ease of interaction with design elements.

  1. User interface design and Consent choice architecture should operate in a substantially similar manner when accessed through digital accessibility tools.

a. Example: If it takes two clicks for a Consumer to Consent through a website, it should take no more than two actions for a Consumer using a digital accessibility tool to complete the same Consent process.

B. In addition to the principles included in this part 4 CCR 904-3, Rule 7.09(A), Controllers may consider statutes, administrative rules, and administrative guidance concerning Dark Patterns from other jurisdictions when evaluating the appropriateness of the user interface or choice architecture used to obtain required Consent.

C. Controllers shall not use an interface design or choice architecture to obtain required Consent that has been designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision making or choice, or unfairly, fraudulently, or deceptively manipulating or coercing a Consumer into providing Consent.

  1. The principles outlined in 4 CCR 904-3, Rule 7.09(A) and (B) are factors to be considered when determining if a consent interface design or choice architecture has been designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision making or choice, or unfairly, fraudulently, or deceptively manipulating or coercing a Consumer into providing Consent.

D. Consent obtained in violation of this part 4 CCR 904-3, Rule 7.09(C) may be considered a Dark Pattern, as defined in C.R.S. § 6-1-1303(9).

E. The fact that a design or practice is commonly used is not, alone, enough to demonstrate that any particular design or practice is not a Dark Pattern.

F. Consent obtained through Dark Patterns does not constitute valid Consent in compliance with C.R.S. §§ 6-1-1303, 6-1-1306, and 6-1-1308.

PART 8 DATA PROTECTION ASSESSMENTS

Rule 8.01 AUTHORITY AND PURPOSE A. The statutory authority for the rules in this Part 8 is C.R.S. §§ 6-1-108(1), 6-1-1309, 6-1-1309.5, and 6-1-1313. The purpose of the rules in this Part 8 is to provide clarity on the requirements and timing of data protection assessments.

Rule 8.02 SCOPE A. A data protection assessment shall be a genuine, thoughtful analysis of each Personal Data Processing activity that presents a heightened risk of harm to a Consumer or to a Minor, pursuant to C.R.S. § 6-1-1309(3) and C.R.S. § 6-1-1309.5, that: 1) identifies and describes the risks to the rights of consumers associated with the processing; 2) documents measures considered and taken to address and offset those risks, including those duties required by C.R.S. § 6-1-1308; 3) contemplates the benefits of the Processing; 4) demonstrates that the benefits of the Processing outweigh the risks offset by safeguards in place; and 5) fulfills any additional obligations as required by C.R.S. § 6-1-1309.5.

B. If a Controller conducts a data protection assessment for the purpose of complying with another jurisdiction’s law or regulation, the assessment shall satisfy the requirements established in this

section if such data protection assessment is reasonably similar in scope and effect to the data protection assessment that would otherwise be conducted pursuant to this section.

  1. If a data protection assessment conducted for the purpose of complying with another jurisdiction’s law or regulation is not similar in scope and effect to a data protection assessment created pursuant to this section, a Controller may submit that assessment with a supplement that contains any additional information required by this jurisdiction.

C. The depth, level of detail, and scope of data protection assessments should take into account the scope of risk presented, the size of the Controller, amount and sensitivity of Personal Data Processed, Personal Data Processing activities subject to the assessment, and complexity of safeguards applied.

D. A “comparable set of Processing operations” that can be addressed by a single data protection assessment pursuant to C.R.S. § 6-1-1309(5) is a set of similar Processing operations including similar activities that present heightened risks of similar harm to a Consumer.

  1. Example: The ACME Toy Store chain is considering using in-store paper forms to collect names, mailing addresses, and birthdays from Children that visit their stores, and using that information to mail a coupon and list of age-appropriate toys to each child during the Child’s birth month and every November. ACME uses the same Processors and Processing systems for each category of mailings across all stores. ACME must conduct and document a data protection assessment because it is Processing Personal Data from known Children, which is Sensitive Data. ACME can use the same data protection assessment for Processing the Personal Data for the birthday mailing and November mailing across all stores because in each case it is collecting the same categories of Personal Data in the same way for the purpose of sending coupons and age-appropriate toy lists to Children.

Rule 8.03 STAKEHOLDER INVOLVEMENT A. A data protection assessment shall involve all relevant internal actors from across the Controller's organizational structure, and where appropriate, relevant external parties, to identify, assess and address the data protection risks.

Rule 8.04 DATA PROTECTION ASSESSMENT CONTENT A. At a minimum, a data protection assessment must include the following information:

  1. A short summary of the Processing activity;

  2. The categories of Personal Data to be Processed and whether they include Personal Data from a Minor if required by C.R.S. § 6-1-1309; or Sensitive Data, including Personal Data from a known Child as described in C.R.S. § 6-1-1303(24);

  3. The context of the Processing activity, including the relationship between the Controller and the Consumers whose Personal Data will be Processed, and the reasonable expectations of those Consumers;

  4. The nature and operational elements of the Processing activity. In determining the level of detail and specificity to provide pursuant to this section, the Controller shall consider the type, amount, and sensitivity of Personal Data Processed, the impacts that operational elements will have on the level of risk presented by the Processing activity, and any relevant unique relationships. Relevant operational elements may include:

a. Sources of Personal Data;

b. Technology or Processors to be used;

c. Names or categories of Personal Data recipients, including Third Parties, Affiliates, and Processors that will have access to the Personal Data, the processing purpose for which the Personal Data will be provided to those recipients, and categorical compliance processes that the Controller uses to evaluate that type of recipient;

d. Operational details about the Processing, including planned processes for Personal Data collection, use, storage, retention, and sharing;

e. Specific types of Personal Data to be processed.

  1. The core purposes of the Processing activity, as well as other benefits of the Processing that may flow, directly and indirectly to the Controller, Consumer, other expected stakeholders, and the public;

  2. The sources and nature of risks to the rights of Consumers associated with the Processing activity posed by the Processing activity, including the sources and nature of any heightened risk of harm to Minors that is a reasonable foreseeable result of offering an online service, product, or feature to Minors. The source and nature of the risks may differ based on the processing activity and type of Personal Data processed. Risks to the rights of Consumers that a Controller may consider in a data protection assessment include, for example, risks of:

a. Constitutional harms, such as speech harms or associational harms;

b. Intellectual privacy harms, such as the creation of negative inferences about an individual based on what an individual reads, learns, or debates;

c. Data security harms, such as unauthorized access or adversarial use;

d. Discrimination harms, such as a violation of federal antidiscrimination laws or antidiscrimination laws of any state or political subdivision thereof, or unlawful disparate impact;

e. Unfair, unconscionable, or deceptive treatment;

f. A negative outcome or decision with respect to an individual’s eligibility for a right, privilege, or benefit related to financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services;

g. Financial injury or economic harm;

h. Physical injury, harassment, or threat to an individual or property;

i. Privacy harms, such as physical or other intrusion upon the solitude or seclusion or the private affairs or concerns of Consumers, stigmatization or reputational injury;

j. Psychological harm, including anxiety, embarrassment, fear, and other mental trauma; or k. Other detrimental or negative consequences that affect an individual’s private life, private affairs, private family matters or similar concerns, including actions and communications within an individual’s home or similar physical, online, or digital location, where an individual has a reasonable expectation that Personal Data or other data will not be collected, observed, or used.

  1. Measures and safeguards the Controller will employ to reduce the risks identified by the Controller pursuant to 4 CCR 904-3, Rule 8.04(A)(6). Measures shall include the following, as applicable:

a. The use of De-identified Data;

b. Measures taken pursuant to the Controller duties in C.R.S. § 6-1-1308, including an overview of data security practices the Controller has implemented, any data security assessments that have been completed pursuant to C.R.S. § 6-1- 1308(5), and any measures taken to comply with the consent requirements of 4 CCR 904-3, Rule 7; and c. Measures taken to ensure that Consumers have access to the rights provided in C.R.S. § 6-1-1306.

  1. A description of how the benefits of the Processing outweigh the risks identified pursuant to 4 CCR 904-3, Rule 8.04(A)(6), as mitigated by the safeguards identified pursuant to 4 CCR 904-3, Rule 8.04(A)(7).

a. Contractual agreements in place to ensure that Personal Data in the possession of a Processor or other Third Party remains secure; or b. Any other practices, policies, or trainings intended to mitigate Processing risks.

  1. If a Controller is Processing Personal Data for Profiling as contemplated in C.R.S. § 6-1- 1309(2)(a), a data protection assessment of that Processing activity must also comply with 4 CCR 904-3, Rule 9.06;

  2. If a Controller is Processing Sensitive Data pursuant to the exception in section 4 CCR 904-3, Rule 6.10, the details of the process implemented to ensure that Personal Data and Sensitive Data Inferences are not transferred and are deleted within twenty-four (24) hours of the Personal Data Processing activity;

  3. Relevant internal actors and external parties contributing to the data protection assessment;

  4. Any internal or external audit conducted in relation to the data protection assessment, including, the name of the auditor, the names and positions of individuals involved in the review process, and the details of the audit process; and 13. Dates the data protection assessment was reviewed and approved, and names, positions, and signatures of the individuals responsible for the review and approval.

Rule 8.05 TIMING A. A Controller shall conduct and document a data protection assessment before initiating a Processing activity that Presents a Heightened Risk of Harm to a Consumer, as defined at C.R.S. § 6-1-1309(2).

B. A Controller shall review and update the data protection assessment as often as appropriate considering the type, amount, and sensitivity of Personal Data Processed and level of risk presented by the Processing, throughout the Processing activity’s lifecycle in order to: 1) monitor for harm caused by the Processing and adjust safeguards accordingly; and 2) ensure that data protection and privacy are considered as the Controller makes new decisions with respect to the Processing.

C. Data protection assessments containing Processing for Profiling in furtherance of Decisions that Produce Legal or Similarly Significant Effects Concerning a Consumer shall be reviewed and updated at least annually, and include an updated evaluation for fairness and disparate impact and the results of any such evaluation.

D. A new data Processing activity is generated when existing Processing activities are modified in a way that materially changes the level of risk presented. When a new data Processing activity is generated, a data protection assessment must reflect changes to the pre-existing activity and additional considerations and safeguards to offset the new risk level.

  1. Modifications that may materially change the level of risk of a Processing activity may include, without limitation, changes to any of the following:

a. The way that existing systems or Processes handle Personal Data;

b. Processing purpose;

c. Personal data Processed or sources of Personal Data;

d. Method of collection of Personal Data;

e. Personal Data recipients;

f. Processor roles or Processors;

g. Algorithm applied or algorithmic result; or h. Software or other systems used for Processing.

E. Data protection assessments, including prior versions which have been revised when a new data Processing activity is generated, shall be stored for as long as the Processing activity continues, and for at least three (3) years after the conclusion of the Processing activity. Data protection assessments shall be held in an electronic, transferable form.

F. Unless otherwise specified, data protection assessments shall be required for activities created or generated after July 1, 2023. This requirement is not retroactive.

G. Data protection assessments conducted pursuant to C.R.S. § 6-1-1309.5 shall be required for activities created or generated after October 1, 2025. This requirement is not retroactive.

Rule 8.06 ATTORNEY GENERAL REQUESTS A. A Controller shall make the data protection assessment available to the Attorney General within thirty (30) days of the Attorney General’s request.

PART 9 PROFILING

Rule 9.01 AUTHORITY AND PURPOSE A. The statutory authority for the rules in this Part 9 is C.R.S. §§ 6-1-108(1), 6-1-1302(1)(c)(II)(B), 6- 1- 1303, 6-1-1306, 6-1-1309, and 6-1-1313. The purpose of the rules in this Part 9 is to provide clarity on the duties and rights related to Profiling.

Rule 9.02 SCOPE A. Controllers have an affirmative obligation to provide clear, understandable, and transparent information to Consumers about how their Personal Data is used, including for Profiling, pursuant to C.R.S. § 6-1-1302(1)(c)(II)(B).

B. Consumers have the right to opt out of Profiling as defined in C.R.S. § 6-1-1303(20) and 4 CCR 904-3, Rule 2.02 when the Profiling is done in furtherance of a decision that results in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services, pursuant to C.R.S. §§ 6-1-1306(1)(a)(I).

C. Controllers must conduct and document a data protection assessment compliant with C.R.S. § 6- 1- 1309 and Parts 8 and 9 of these rules before Processing Personal Data for Profiling that presents specific, reasonably foreseeable risks contemplated in C.R.S. § 6-1-1309(2)(a).

Rule 9.03 PROFILING OPT-OUT TRANSPARENCY A. To ensure that Consumers understand how their Personal Data is used for Profiling in furtherance of Decisions that Produce Legal or Other Similarly Significant Effects Concerning a Consumer, Controllers that Process Personal Data for Profiling for a decision that results in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services and subject to C.R.S. § 6-1-1306(1)(a)(I) shall provide clear, understandable, and transparent information to Consumers in the required privacy notice, including at a minimum:

  1. What decision(s) is (are) subject to Profiling;

  2. The categories of Personal Data that were or will be Processed as part of the Profiling in Furtherance of Decisions that Produce Legal or Other Similarly Significant Effects;

  3. A non-technical, plain language explanation of the logic used in the Profiling process;

  4. A non-technical, plain language explanation of how Profiling is used in the decisionmaking process, including the role of human involvement, if any;

  5. If the system has been evaluated for accuracy, fairness, or bias, including the impact of the use of Sensitive Data, and the outcome of any such evaluation;

  6. The benefits and potential consequences of the decision based on the Profiling; and 7. Information about how a Consumer may exercise the right to opt out of the Processing of Personal Data concerning the Consumer for Profiling in Furtherance of Decisions that Produce Legal or Other Similarly Significant Effects.

B. Notwithstanding the requirements in 4 CCR 904-3, Rule 9.03(A), nothing in 4 CCR 904-3, Rule 9.03 shall be construed as requiring the Controller to provide information to a Consumer in a

Rule 9.04 OPTING OUT OF PROFILING IN FURTHERANCE OF DECISIONS THAT PRODUCE LEGAL OR SIMILARLY SIGNIFICANT EFFECTS CONCERNING A CONSUMER A. Consumers have the right to opt out of Profiling in furtherance of Decisions that Produce Legal or other Similarly Significant Effects Concerning a Consumer through the method specified by the Controller in the required privacy notice, pursuant to C.R.S. § 6-1-1306(1)(a) and 4 CCR 904-3,

Rule 4.03.

B. Requests to opt out of Profiling in furtherance of Decisions that Produce Legal or other Similarly Significant Effects Concerning a Consumer based on Solely Automated Processing or Human Reviewed Automated Processing shall be honored pursuant to C.R.S. § 6-1-1306(2).

C. A Controller may decide not to take action on a request to opt out of Profiling in furtherance of Decisions that Produce Legal or other Similarly Significant Effects Concerning a Consumer if the Profiling used is based on Human Involved Automated Processing. If a Controller does not take action based on this reason, the Controller shall inform the Consumer pursuant to C.R.S. § 6-1- 1306(2)(b) and include the following information, or share a link to such information if it is included in the Controller’s privacy notice:

  1. The decision subject to the Profiling;

  2. The categories of Personal Data that were or will be used as part of the Profiling used in Furtherance of Decisions that Produce Legal or Other Similarly Significant Effects;

  3. A non-technical, plain language explanation of the logic used in the Profiling process;

  4. A non-technical, plain language explanation of the role of meaningful human involvement in Profiling and the decision-making process;

  5. How Profiling is used in the decision-making process;

  6. The benefits and potential consequences of the decision based on the Profiling; and 7. An explanation of how Consumers can correct or delete the Personal Data used in the Profiling used in the decision-making process.

D. In order to ensure that Consumers have an opportunity to exercise their right to opt out of Profiling in furtherance of Decisions that Produce Legal or Other Similarly Significant Effects Concerning a Consumer, Controllers that Process Personal Data for Profiling covered by C.R.S. §§ 6-1-1303(10) and 6-1-1306(1)(a)(I) shall provide a method to exercise the right to opt out of Profiling in furtherance of Decision that Produce Legal or Other similarly Significant Effects Concerning a Consumer clearly and conspicuously at or before the time such Processing occurs.

E. Notwithstanding the requirements in 4 CCR 904-3, Rule 9.04(C), nothing in 4 CCR 904-3, Rule 9.04 shall be construed as requiring the Controller to provide information to a Consumer in a

Rule 9.05 CONSENT FOR PROFILING IN FURTHERANCE OF DECISIONS THAT PRODUCE LEGAL OR SIMILARLY SIGNIFICANT EFFECTS CONCERNING A CONSUMER A. When a Consumer has opted out of Profiling in furtherance of Decisions that Produce Legal or Similarly Significant Effects Concerning a Consumer as defined by C.R.S. § 6-1-1303(10), the Controller may request that a Consumer provide Consent after opting out subject to 4 CCR 904- 3, Rule 7.05.

B. If a Controller decides to begin Processing Personal Data for Profiling in furtherance of Decisions that Produce Legal or Similarly Significant Effects Concerning a Consumer and such Processing is not reasonably necessary to or compatible with the original specified purposes for which the Personal Data was Processed, the Controller shall request the Consumer provide Consent prior to such processing, subject to C.R.S. § 6-1-1308(4) and Part 7 of these rules.

C. Any request for Consent to Profiling in furtherance of Decisions that Produce Legal or Similarly Significant Effects Concerning a Consumer must include meaningful information about the Profiling that allows a Consumer to make an informed, freely given, and specific choice, including, at a minimum:

  1. The decision subject to the Profiling;

  2. The categories of Personal Data used in the Profiling;

  3. A non-technical, plain language explanation of the logic used in the Profiling, or a link to such information if it is included in the Controller’s privacy notice;

  4. How Profiling is used in the decision-making process, including the role of human involvement, if any;

  5. Why the Profiling is relevant to the decision-making process;

  6. Potential benefits and consequences of the decision based on the Profiling; and 7. Any applicable links to where Consumers can find any additional information about the Profiling and decision-making process and their associated rights.

D. Notwithstanding the requirements in 4 CCR 904-3, Rule 9.05(C), nothing in 4 CCR 904-3, Rule 9.05 shall be constructed as requiring the Controller to provide information to a Consumer in a

Rule 9.06 DATA PROTECTION ASSESSMENTS FOR PROFILING A. Controllers must conduct and document a data protection assessment compliant with C.R.S. § 6- 1- 1309 and 4 CCR 904-3, Part 8 before Processing Personal Data for Profiling if the Profiling presents a reasonably foreseeable risk of:

  1. Unfair or deceptive treatment of, or unlawful disparate impact on Consumers;

  2. Financial or physical injury to Consumers;

  3. A physical or other intrusion upon the solitude or seclusion, or private affairs or concerns, of Consumers if the intrusion would be offensive to a reasonable person; or 4. Other substantial injury to Consumers.

B. Profiling under C.R.S. § 6-1-1309(2)(a) and covered by required data protection assessment obligations includes Profiling using Solely Automated Processing, Human Reviewed Automated Processing, and Human Involved Automated Processing.

C. “Unfair or deceptive treatment” as used in C.R.S. § 6-1-1309 and 4 CCR 904-3, Rule 9.06 includes conduct or activity which violates state or federal laws that prohibit unfair and deceptive commercial practices.

D. “Unlawful disparate impact” as used in C.R.S. § 6-1-1309 and 4 CCR 904-3, Rule 9.06 includes conduct or activity which violates state or federal laws that prohibit unlawful discrimination against Consumers.

E. Controllers should consider both the type and degree of potential harm to Consumers when determining if Profiling presents a reasonably foreseeable risk of “other substantial injury” to Consumers as used in C.R.S. § 6-1-1309 and 4 CCR 904-3, Rule 9.06(A). For example, a small harm to a large number of Consumers. may constitute “other substantial injury”.

F. If a Controller is Processing Personal Data for Profiling under C.R.S. § 6-1-1309(2)(a), a data protection assessment of that Processing activity must include the elements listed at 4 CCR 904- 3, Rule 8.04 as well as each of the following as applicable to the assessed reasonably foreseeable risk:

  1. The specific types of Personal Data that were or will be used in the Profiling or decisionmaking process;

  2. The decision to be made using Profiling;

  3. The benefits of automated processing over manual processing for the stated purpose;

  4. A plain language explanation of why the Profiling directly and reasonably relates to the Controller’s goods and services;

  5. An explanation of the training data and logic used to create the Profiling system, including any statistics used in the analysis, either created by the Controller or provided by a Third Party which created the applicable Profiling system or software;

  6. If the Profiling is conducted by Third Party software purchased by the Controller, the name of the software and copies of any internal or external evaluations sufficient to show of the accuracy and reliability of the software where relevant to the risks described in C.R.S. § 6-1-1309(2)(a)(I)-(IV);

  7. A plain language description of the outputs secured from the Profiling process;

  8. A plain language description of how the outputs from the Profiling process are or will be used, including whether and how they are used to make a decision to provide or deny or substantially contribute to the provision or denial of financial or lending services, housing, insurance, education, enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services;

  9. If there is human involvement in the Profiling process, the degree and details of any human involvement;

  10. How the Profiling system is evaluated for fairness and disparate impact, and the results of any such evaluation;

  11. Safeguards used to reduce the risk of harms identified; and 12. Safeguards for any data sets produced by or derived from the Profiling.

G. If a Controller conducts a data protection assessment which includes an assessment of relevant Profiling for the purpose of complying with another jurisdiction’s law or regulation, the assessment shall satisfy the requirements established in this section if such data protection assessment is reasonably similar in scope and effect to the data protection assessment that would otherwise be conducted pursuant to this section. A Controller may also submit an assessment with a supplement that contains any additional information required by this regulation.

PART 10 INTERPRETIVE GUIDANCE AND OPINION LETTERS

Rule 10.01 AUTHORITY AND PURPOSE A. The statutory authority for the rules in this Part 10 is C.R.S. § 6-1-1313. The purpose of the rules in Part 10 is to create a process of issuing Opinion Letters to develop an operational framework for businesses that includes a good faith reliance defense, and to create a process of issuing statements of interpretive guidance to provide guidance to covered individuals and the general public.

Rule 10.02 SCOPE AND EFFECT OF OPINION LETTERS A. Opinion Letters are only issued in response to requests made pursuant to 4 CCR 904-3, Rule 10.03.

B. Opinion letters will contain the Attorney General’s opinion regarding the application of the Colorado Privacy Act to parties’ proposed activities, as described in requests made pursuant to 4 CCR 904-3, Rule 10.04.

C. The Attorney General shall determine, at the Attorney General’s discretion, whether to issue an Opinion Letter. In making this determination, the Attorney General may consider factors including, without limitation, whether:

  1. The Opinion Letter will terminate a controversy or remove one or more uncertainties as to the application of the law to the requestor's situation;

  2. The request involves a subject, question, or issue that concerns a formal or informal matter or investigation currently pending before the secretary or a court; and 3. The request seeks a ruling on a moot or hypothetical question.

D. Should the Department of Law file an enforcement action against a person or entity regarding the question presented in an Opinion Letter, the person or entity who is the subject of that Opinion Letter may legally rely upon the Opinion Letter in asserting a good faith reliance defense.

  1. The Attorney General will not normally investigate the underlying facts of the requestor’s situation and, as a result, an Opinion Letter may not be applicable to the requestor if the request for opinion does not contain all material facts and representations, or if the underlying facts of the requestor’s situation do not conform to the summary of material facts.

E. Except as otherwise provided in an Opinion Letter in the Attorney General’s sole determination, an Opinion Letter may not form the basis of a good faith reliance defense for persons or entities who were not the subject of that Opinion Letter as described in the Opinion Letter request.

F. The scope and terms of an Opinion Letter will be set out in the Opinion Letter itself and may deviate from the interpretation proposed by the requestor in its submission.

G. The Attorney General may decline any request to issue an Opinion Letter. The Attorney General may, when it is deemed appropriate, issue Interpretive Guidance calling attention to established principles under the Colorado Privacy Act, even when a request that was submitted was for an Opinion Letter.

Rule 10.03 REQUESTS FOR OPINION LETTERS A. A request for an Opinion Letter must be prospective in nature, pertaining to an activity that the requestor in good faith specifically plans to undertake. The plans may be contingent upon receiving a favorable Opinion Letter.

B. Requests presenting a general question of interpretation, positing a hypothetical situation, or regarding the activities of unrelated Persons or entities do not qualify as Opinion Letter requests.

C. A request for an Opinion Letter may only be submitted by a Person or entity that will be directly affected by the activity that is the subject of the request.

D. A request for an opinion letter must be submitted in writing using the process specified on the Attorney General’s website.

E. Each request for an Opinion Letter must be fact-specific and narrowly framed to the specific activity in question, and must set forth the facts underlying the request in as much detail as possible, including without limitation:

  1. The name, title, address, and daytime telephone number of a contact person who will be available to discuss the request for an Opinion Letter with the Attorney General on behalf of the requestor.

  2. The identities of the requestor and of all other actual and potential parties impacted by the activity that is subject to the request for an Opinion Letter.

  3. A complete and specific description containing all relevant information bearing on the activity for which an Opinion Letter is requested, including without limitation:

a. A complete and specific description of the activity, transaction or agreement that the requestor plans to undertake, or any Personal Data Processing that that will result from the activity, agreement or transaction that the requestor plans to pursue.

b. A description of the personal data involved, including whether the personal data is sensitive personal data, and the category of sensitive data;

c. A description of each of the parties that would have access to the Personal Data involved;

d. A description and draft of any disclosures relating the Personal Data involved that will be provided to consumers, and a description of the location and form in which the disclosure will be provided;

e. A copy of any data protection assessment conducted in anticipation of the contemplated Processing activity, if required by C.R.S. § 6-1-1309. Data protection assessments required by C.R.S. § 6-1-1309 are confidential and exempt from public inspection and copying under the Colorado Open records Act (CORA), Part 2 of Article 72 of Title 24. The disclosure of a data protection assessment in a request for an Opinion Letter does not constitute a waiver of any attorney-client privilege or work-product protection that might otherwise exist with respect to the assessment and any information contained in the assessment; and f. If applicable, a designation of trade secrets or confidential commercial or financial information. Such information will be protected to the extent permitted by CORA, Part 2 of Article 72 of Title 24.

F. The Attorney General may request additional information and documents from a person submitting a request for an Opinion Letter.

G. A request for an Opinion Letter is complete when the Attorney General has determined that no additional information is necessary to consider the request.

H. A request may be dismissed for failure to provide information requested by the Attorney General.

Rule 10.04 ISSUANCE OF OPINION LETTERS A. The Attorney General shall publish each issued Opinion Letter on the Attorney General’s Website after an opinion is issued. The published form of each Opinion Letter shall redact and protect information required by CORA, Part 2 of Article 72 of Title 24.

Rule 10.05 SCOPE AND EFFECT OFINTERPRETIVE GUIDANCE A. The Attorney General may, in its discretion, issue statements providing Interpretive Guidance to covered individuals and the general public where the nature of a request from an individual or organization suggests that it is seeking general information, where a request from an individual or organization does not meet all the requirements of 4 CCR 904-3, Rule 10.04 of these Rules, or when the Attorney General believes that such general information will assist an individual, organization, or the general public.

B. Interpretive Guidance issued by the Attorney General is informational only and is not binding on the Attorney General or Colorado Department of Law with respect to any particular factual situation.

C. Interpretive Guidance issued pursuant to this section is for informational purposes only, and may not serve as the basis for a good faith reliance defense.

D. Interpretive Guidance shall be published on the Attorney General website.

Rule 10.06 REQUESTS FOR INTERPRETIVE GUIDANCE A. Any Person affected directly or indirectly by the Colorado Privacy Act may request Interpretive Guidance from the Attorney General.

B. The Attorney General may, when it is deemed appropriate, issue Interpretive Guidance calling attention to principles under the Colorado Privacy Act, even when a request that was submitted was for an Opinion Letter. The Attorney General may issue Interpretive Guidance regarding the Colorado Privacy Act, C.R.S. the Colorado Privacy Act, C.R.S. § 6-1-1303 through 6-1-1314, sua sponte.

PART 11 ENFORCEMENT

Rule 11.01 AUTHORITY AND PURPOSE A. The statutory authority for the rules in this Part 11 is C.R.S. §§ 6-1-1310 and 6-1-1311. The

purpose of the rules in this Part 10 is to clarify enforcement considerations related to the Colorado Privacy Act, C.R.S. § 6-1-1303 through 6-1-1314, and these Colorado Privacy Act Rules, 4 CCR 904-3.

Rule 11.02 ENFORCEMENT CONSIDERATIONS A. Nothing in the Colorado Privacy Act, C.R.S. § 6-1-1303 through 6-1-1314, or these Colorado Privacy Act Rules, 4 CCR 904-3, provides the Colorado Attorney General or District Attorney, as applicable, with enforcement powers that would infringe upon rights protected by the United States Constitution or Colorado Constitution, including the right to freedom of speech or freedom of the press.

PART 12 MATERIALS INCORPORATED BY REFERENCE

Rule 12.01 AUTHORITY AND PURPOSE A. The statutory authority for the rules in this Part 12 is C.R.S. §§ 6-1-108(1) and 6-1-1313. The

purpose of the rules in this Part 12 is to incorporate by reference the guidelines that are referred to in 4 CCR 904-3, Rule 3.02(A)(2).

Rule 12.02 WEB CONTENT ACCESSIBILITY GUIDELINES A. The Web Content Accessibility Guidelines, version 2.1 of June 5, 2018, from the World Wide Web Consortium, are hereby incorporated into 4 CCR 904-3, Rule 3.02(A)(2) by reference pursuant to C.R.S. § 24-4-103(12.5), and do not include any later amendments.

B. Copies of the Web Content Accessibility Guidelines that are incorporated by reference into these rules may be obtained by sending a written request to the following address by U.S. mail:

Colorado Department of Law Ralph L. Carr Judicial Center 1300 Broadway, 9th Floor Denver, CO 80203 C. The Web Content Accessibility Guidelines published by the World Wide Web Consortium incorporated by reference into these rules are available at no cost in an electronic form online at https://www.w3.org/TR/WCAG21/.

D. The Colorado Department of Law also maintains a copy of the Web Content Accessibility Guidelines that are incorporated by reference into these rules that is available for public inspection at the Colorado Department of Law’s office during regular business hours. _________________________________________________________________________ Editor’s Notes

History New rule eff. 07/01/2023.

Rules 1.01, 1.03, 2.01, 2.02, 3.01, 3.02 A.1, 3.02 B, 4.01 A, 4.04 B-F, 6.01 A, 6.12, 7.01 A, 7.02 A-7.02 A.7, 7.08 D, 7.09-7.10, 8.01 A, 8.02 A, 8.04 A.2, 8.04 A.6, 8.05 F-G, 10.01 A, 10.02-10.06, 11.01- 11.02, 12.01-12.02 eff. 01/30/2025.

Rules 2.02, 6.13, 6.14, 7.03 B.3 eff. 12/01/2025.

4 CCR 904-4 Transferability of Training and Credentials Subject to Training Repayment Agreement Provisions {#sec-4-ccr-904-4 omnilex-key=us-co-regs-official--department-11--4 CCR 904-4}

Department of Law Attorney General-Consumer Protection Section TRANSFERABILITY OF TRAINING AND CREDENTIALS SUBJECT TO TRAINING REPAYMENT AGREEMENT PROVISIONS 4 CCR 904-4 [Editor’s Notes follow the text of the rules at the end of this CCR Document.]

A training or credential is transferable for the purposes of C.R.S. Section 8-2-113(3)(a) when it is engaged in voluntarily by the employee and directly results in either (a) an educational degree or certification from i. a private college or university authorized to operate in Colorado under C.R.S. Section 23-2-103.3;

ii. a private occupational school with a certificate of approval under C.R.S.

Section 23-64-115(1);

iii. a community or technical college identified in C.R.S. Section 23-60-205; or iv. a public institute of higher education as defined in C.R.S. Section 23-4.5- 102(7); or (b) a license i. as defined in C.R.S. Section 12-20-102(9);

ii. a commercial driver’s license as defined in C.R.S. Section 42-2-402(1);

iii. any license defined in Colorado law;

iv. a comparable license or credential defined in the law of any other state, territory, district, or federally recognized Indian Tribe; or v. a certificate or license granted by a federal government agency; or (c) a training or credential that is recognized by an industry or trade association, a union, or other organization representing employers or workers within the profession or occupation to which the training or credential is related.

Attorney General-Consumer Protection Section Editor’s Notes

History New rule eff. 04/30/2026.

4 CCR 904-5 Online Dating Safety Act Rules {#sec-4-ccr-904-5 omnilex-key=us-co-regs-official--department-11--4 CCR 904-5}

Colorado Department of Law ONLINE DATING SAFETY ACT RULES 4 CCR 904-5 [Editor’s Notes follow the text of the rules at the end of this CCR Document.]

PART 1 GENERAL APPLICABILITY

Rule 1.01 Authority The statutory authority for this Part 904-5 is sections C.R.S. §§ 6-1-108(1) and 6-1- 731.5(4.5).

Rule 1.02 Severability If any provision of these Online Dating Safety Act Rules, 4 CCR 904-5, is found to be invalid by a court of competent jurisdiction, the remaining provisions of the Rules shall remain in full force and effect.

PART 2 DEFINITIONS

Rule 2.01 Authority and Purpose The statutory authority for the rules in this Part 2 is C.R.S. §§ 6-1-108(1) and 6-1- 731.5(4.5). The purpose of these rules is to define certain undefined terms that are used throughout the Online Dating Safety Act, C.R.S. § 6-1-731.5, and these Online Dating Safety Act Rules, 4 CCR 904-5. The terms defined by this rule and C.R.S. § 6-1-731(1) are capitalized where they appear in the rules to let the reader know to refer to the definitions. When a term is used in a conventional sense, and is not intended to be a defined term, it is not capitalized.

Rule 2.01 Defined Terms “Annual Safety Report” means the annual report concerning Member safety and the Online Dating Service’s compliance with C.R.S. § 6-1-731.5 as required by C.R.S. § 6- 1- 731.5(4)(b).

PART 3 SAFETY POLICY

Rule 3.01 Authority and Purpose A. The statutory authority for the rules in this Part 3 is C.R.S. §§ 6-1-108(1) and 6-1- 731.5(4.5). The purpose of the rules in Part 3 is to ensure that Online Dating Services understand the process to submit to the attorney general's office the URL for its Safety Policy and that the Safety Policy is understandable to Members.

Rule 3.02 Process to Submit Safety Policy URL A. Pursuant to C.R.S. § 6-1-731.4(a), an Online Dating Service shall submit the URL for its Safety Policy posted on its website to the attorney general’s office within fifteen days after enacting the Safety Policy. If an Online Dating Service updates the URL for its Safety Policy, it shall submit the updated URL to the attorney general’s office within seven days after updating the URL.

B. An Online Dating Service shall submit the required Safety Policy URL to the attorney general’s office through the form available on the attorney general’s website, located at https://coag.gov/dating-safety/.

Rule 3.03 Requirements for Safety Policy A. The Safety Policy made available to Members pursuant to C.R.S. § 6-1-731.5(2) must be:

  1. Understandable and accessible to Members, considering the vulnerabilities or unique characteristics of the target audience of the Online Dating Service. For example, the Safety Policies shall use plain, straightforward language and avoid technical or legal jargon.

  2. Reasonably accessible to Members with Disabilities, including through the use of digital accessibility tools. For Safety Policies provided online, the Online Dating Service shall follow generally recognized industry standards, such as the Web Content Accessibility Guidelines, version 2.1 of June 5, 2018, from the World Wide Web Consortium, incorporated herein by reference as described at Rule 5.02. In other contexts, the Online Dating Service shall provide information on how a Member with a disability may access the disclosure or communication in an alternative format.

  3. Available in the languages in which the Online Dating Service in its ordinary course provides web pages, interfaces, contracts, disclaimers, sale announcements, and other information to Members.

  4. Readable on all devices through which Members interact with the Online Dating Service, including on smaller screens and through mobile applications, if applicable.

PART 4 ANNUAL REPORT

Rule 4.01 Authority and Purpose A. The statutory authority for the rules in this Part 4 is C.R.S. §§ 6-1-108(1), 6-1- 731.5(4)(b)-(c), (4.5). The purpose of the rules in Part 4 is to clarify the scope and content of the Online Dating Service Annual Safety Report required by C.R.S. § 6-1-731.5.

Rule 4.02 Scope A. An Online Dating Service shall create an Annual Safety Report as required by C.R.S. § 6-1-731.5. An Online Dating Service Annual Safety Report shall be a genuine, thoughtful analysis that:

  1. documents measures taken by the Online Dating Service to comply with C.R.S. § 6-1-731.5;

  2. describes the Online Dating Service policies to promote safer online and in-person dating experiences for Members; and 3. details the implementation of the Online Dating Service policies concerning Member safety.

B. If an Online Dating Service creates an Annual Safety Report for the purpose of complying with another jurisdiction’s law or regulation, the report for the other jurisdiction shall satisfy the requirements established in this section if that report is reasonably similar in scope and effect to the Annual Safety Report required by this Part 4.

C. If an Online Dating Service has internal documents which contain the same information required by the Annual Safety Report, the Service may provide those documents to fulfill the report requirements along with an appendix which references where the required information may be found in the documents.

Rule 4.03 Annual Safety Report Content A. At a minimum, the Annual Safety Report must include each of the following:

  1. The date the Online Dating Service most recently updated its Safety Policy;

  2. The date the Online Dating Service most recently submitted the URL for its Safety Policy to the attorney general’s office;

  3. Which of the following tiers the Online Dating Service belongs to:

a. Tier 1: Greater than 10 million monthly active users during the reporting period;

b. Tier 2: Between 5 million – 10 million monthly active users during the reporting period;

c. Tier 3: Between 1 million – 5 million monthly active users during the reporting period;

d. Tier 4: Between 500,000 – 1,000,000 monthly active users during the reporting period; or e. Tier 5: Less than 500,000 monthly active users during the reporting period.

  1. Information about the enforcement of the Online Dating Service Safety Policy during the reporting period, including:

a. Enforcement metrics based on violations of the Online Dating Service's Safety Policy within the reporting period, including the total number of Members or accounts subject to Remedial Action, the percentage of active users during the reporting period represented by those Members or accounts, the Safety Policy provisions violated, including violations involving Misconduct that Threatens Public or Personal Safety, the type of Remedial Action taken, and whether the Remedial Action resulted from a report from another Member or proactive review or moderation by the Service;

b. A summary of the process by which the Online Dating Service notifies other Members who interacted with Members removed from the Online Dating Service for violations of the Safety Policy, including information about the number of Members notified, disaggregated by type of reported content or conduct that resulted in removal.

c. A summary of the forms of proactive review or moderation utilized by the Online Dating Service, including what automation measures are used by the Online Dating Service for enforcing its Safety Policy, processing reports, or other measures taken to address Member safety;

d. A summary of the process the Online Dating Service uses to prevent individuals who have been removed or banned for violations of the Safety Policy from re-registering or creating new accounts;

e. The number of Members or accounts which, during the reporting period, were prevented from re-registering or creating new accounts on the Online Dating Platform after being removed or banned for violations of the Safety Policy, including the percentage of active users during the reporting period represented by these Members or accounts;

f. If an Online Dating Service is owned or operated by a parent company that owns or operates one or more additional Online Dating Services, a summary of the process in place to ensure that an individual who has been removed, suspended, or banned by an affiliated Online Dating Service for violations of its Safety Policy is subject to review before being permitted to create or maintain an account on a different, affiliated Online Dating Service; and g. The number of individuals who, during the reporting period, were prevented from creating or maintaining an account on the Online Dating Service after being removed, suspended, or banned violating the Safety of an affiliated Online Dating Service.

  1. Information about the enforcement of the Online Dating Service’s policy concerning criminal background screening during the reporting period, including, if applicable:

a. A summary of the Online Dating Service’s process regarding Member criminal background screening;

b. The number of criminal background checks conducted and the number of individuals excluded from the Online Dating Service based on the results of a background check;

c. Whether individuals are notified when a criminal background check results in their exclusion or suspension from the Online Dating Service, and whether they may appeal the decision, including a description of the appeal process and timeframes;

d. Whether and how the service conducts periodic further criminal background checks or ongoing monitoring of Members with existing accounts, and under what circumstances (e.g., following a report or periodically); and e. When and where the Online Dating Service provides disclosures regarding their criminal background check policies outside of the Safety Policy, and copies of or links to any such disclosures.

  1. Information on enforcement of the Online Dating Service Member identity verification and age verification policies during the reporting period, including, if applicable:

a. A summary of the Online Dating Service’s process regarding Member identity verification;

b. A summary of the Online Dating Service’s process regarding Member age verification;

c. The number of Members or accounts who were removed from the Online Dating Service and the number of individuals not allowed on the Service as result of identity verification conducted by the Online Dating Service or their parent company or affiliates; and d. The number of Members or accounts removed from the Online Dating Service and the number of individuals not allowed on the Service as a result of age verification conducted by the Online Dating Service or their parent company or affiliates.

  1. A high-level overview of the process and factors considered by the Online Dating Service when deciding whether to take Remedial Action on a Member report about prohibited content or conduct, and whether prior reports or prior Remedial Actions involving the reported Member are considered in that determination.

  2. Information on Member reporting and appeals during the reporting period, including:

a. The mechanism(s) for Members to report other Members for prohibited content or conduct, including where on the Online Dating Service the reporting forms are accessible;

b. What type of notice or communication reporting Members and reported Members receive throughout the reporting processing period, including through any appeal process and upon resolution;

c. The mechanism(s) for reported Members to appeal the report, if any, including where on the Online Dating Service the reported Member can submit an appeal and what information is required to submit an appeal;

d. The notices, communications, or limitations on an account or appealing Member can expect while an appeal is pending, including whether account restrictions remain in place until resolution;

e. The number of Members or accounts who were the subject of more than one Member report of prohibited content or conduct within the reporting period, specifying the numbers of reports for Misconduct that Threatens Public or Personal safety, and including whether Remedial Action was taken after the first, second, or subsequent report;

f. The number of reports of prohibited content or conduct the Online Dating Service identified as knowingly false, malicious, or submitted in bad faith, and whether any Remedial Actions were taken against the reporter in response; and g. The average and median time between when a report of prohibited content and conduct is received and when the Online Dating Service takes final action or closes the report.

  1. Information on safety resources for Members provided by the Online Dating Service, including:

a. The locations and methods by which the resources required by C.R.S. § 6-1-731.5(2)(i), are provided to Members;

b. Whether and which resources required by C.R.S. § 6-1-731.5(2)(i), have been developed in consultation with appropriate online safety or dating experts or advocacy organizations; and c. The total number of Members who have accessed the resources required by C.R.S. § 6-1-731.5(2)(i) during the reporting period.

  1. Information on the Online Dating Service’s policies and processes to promote safer online and in-person dating experiences for Members, including:

a. A description of the safety measures the Online Dating Service implemented as features of the Service to promote safer online and in-person dating experiences for Members as referenced in C.R.S. § 6-1-731.5(2)(j), including which safety measures are on by default and what risks the features were designed to address.

b. Of the safety measures implemented as outlined 10(a), what percentage of Members have engaged with those measures during the reporting period;

c. What, if any, controls Members have over the visibility of their personal information, discoverability of their profile, or ability to block other Members on the Online Dating Service;

d. How a Member’s geolocation is used, if at all, and if Members can control the use of or opt out of geolocation services;

e. A summary of platform-wide Trust & Safety resources and investments, including high-level information about the crossfunctional expertise that contributes to user safety;;

f. A summary of training relevant to Member safety the Online Dating Service trust and safety team receive, including but not limited to appropriate training to assist or refer Members who have made a genuine complaint or report to the appropriate support;

g. A summary of the Online Dating Services’ process for responding to requests for information from law enforcement; and h. A summary of when or under want circumstances the Online Dating Service proactively refers Members, Member activity, or Member complaints to law enforcement, i. The total number of Members referred to law enforcement during the reporting period.

  1. Dates the Annual Safety Report was reviewed and approved.

Rule 4.05 Process to Submit Annual Safety Report A. Pursuant to C.R.S. § 6-1-731.5(4)(b), an Online Dating Service shall submit an Annual Safety Report to the attorney general’s office on or before January 31, 2026, and on or before January 31 of each year thereafter.

  1. The first Annual Safety Report submitted to the attorney general's office Pursuant to C.R.S. 6-1-731.5(4)(b) must include at a minimum the information required in

Rule 4.03 subparts (A)(1-3). If all information required by Rule 4.03 is also included in this first report, no additional report is needed. If only the minimum required information is included, a supplemental report containing all information required by Rule 4.03 must be provided to the attorney general's office by August 31, 2026.

  1. All subsequent Annual Safety Reports must contain all information required in

Rule 4.03 on or before January 31 of each year thereafter.

B. An Online Dating Service shall submit the required Annual Safety Report to the attorney general’s office through the form available on the attorney general’s website, located at https://coag.gov/dating-safety/.

PART 5 MATERIALS INCORPORATED BY REFERENCE

Rule 5.01 Authority and purpose A. The statutory authority for the rules in this Part 5 is C.R.S. §§ 6-1-108(1) and 6-1- 731.5(4.5). The purpose of the rules in this Part 5 is to incorporate by reference the guidelines that are referred to in 4 CCR 904-5, Rule 3.03.

Rule 5.02 Web Content Accessibility Guidelines A. The Web Content Accessibility Guidelines, version 2.1 of June 5, 2018, from the World Wide Web Consortium, are hereby incorporated into 4 CCR 904-5, Rule 3.03 by reference pursuant to C.R.S. § 24-4-103(12.5), and do not include any later amendments.

B. Copies of the Web Content Accessibility Guidelines that are incorporated by reference into these rules may be obtained by sending a written request to the following address by U.S. mail:

Colorado Department of Law Ralph L. Carr Judicial Center 1300 Broadway, 9th Floor Denver, CO 80203 C. The Web Content Accessibility Guidelines published by the World Wide Web Consortium incorporated by reference into these rules are available at no cost in an electronic form online at https://www.w3.org/TR/WCAG21/.

D. The Colorado Department of Law also maintains a copy of the Web Content Accessibility Guidelines that are incorporated by reference into these rules that is available for public inspection at the Colorado Department of Law’s office during regular business hours.

Editor’s Notes

History New rule eff. 03/30/2026.

Continue your research in ChatGPT or Claude

Connect Omnilex to search the legal corpus from your AI assistant.