Back to Blog
Law UpdatesMarch 29, 202616 min readReviewed by the PrivacyLawMap editorial teamLast reviewed June 14, 2026

Colorado Privacy Act (CPA) 2026 Compliance Checklist

Share:
Turn This Guide Into a Working Privacy SetupSponsored

Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.

Start Free with Termly

Quick answer

As of June 14, 2026, the Colorado Privacy Act has six practical compliance triggers: the 100,000-consumer threshold, the 25,000-consumer-plus-data-sale threshold, universal opt-out recognition, opt-in consent for sensitive data including precise geolocation, minor-data safeguards, and data protection assessments for high-risk processing. Covered controllers must also maintain 45-day consumer-rights workflows and operate without the former 60-day cure period.

Colorado Privacy Act Compliance Requirements for 2026

The Colorado Privacy Act (CPA) was signed into law on July 7, 2021, and took effect on July 1, 2023, making Colorado the third state in the nation (after California and Virginia) to enact a comprehensive consumer data privacy law. Since then, the CPA has undergone significant amendments that have strengthened its protections and eliminated its cure period, establishing Colorado as one of the most consumer-friendly state privacy regimes.

If your business operates in Colorado or serves Colorado residents, use our Privacy Law Calculator to determine your compliance obligations across all state privacy laws.

Who Must Comply with the CPA?

The CPA applies to entities that conduct business in Colorado or produce products or services intentionally targeted to Colorado residents, AND meet either of these thresholds:

  • Control or process personal data of 100,000 or more Colorado consumers during a calendar year, OR
  • Control or process personal data of 25,000 or more Colorado consumers AND derive revenue or receive a discount from the sale of personal data

Unlike some other state privacy laws, the CPA does not include a revenue threshold. The focus is purely on the volume of consumer data processed and whether data is sold for revenue.

Exemptions

The CPA exempts several categories:

  • Entity exemptions: Government bodies, institutions of higher education, financial institutions and affiliates subject to GLBA, air carriers, national securities associations, and nonprofits (with some exceptions)
  • Data exemptions: HIPAA-regulated PHI collected, stored, and processed by a covered entity or business associate; certain Colorado medical-records access data; 42 CFR Part 2 patient-identifying information; FCRA, FERPA, DPPA, COPPA, GLBA-regulated data, and certain employment and B2B contact data — see our state privacy law vs. HIPAA guide for how Colorado’s carve-out compares with other states
  • HIPAA note: Colorado uses a data-level health-data carve-out, not a blanket HIPAA entity exemption. A hospital, insurer, or health app may still need to apply the CPA to non-PHI consumer data such as web analytics, marketing audiences, loyalty data, or app telemetry.
  • Special note: The CPA applies to both for-profit and “all” commercial entities, though most true nonprofits are exempt unless they process data for commercial purposes

Colorado CPA 2026 Trigger Worksheet

Use this worksheet before building a Colorado privacy program. The base CPA thresholds decide whether the general controller duties apply, but two 2025 amendments can create narrower obligations even when the business is mainly worried about a specific data practice: minor online services under SB 24-041 and sensitive-data sales or precise geolocation under SB 25-276.

Trigger When it fires 2026 compliance action
Base CPA coverage Business targets Colorado residents and either processes 100,000+ Colorado consumers, or processes 25,000+ consumers while deriving revenue or receiving a discount from personal-data sales. Publish a CPA privacy notice, build rights intake, verify requests, handle appeals, and update processor contracts.
Universal opt-out The controller sells personal data or processes it for targeted advertising. Recognize Global Privacy Control and any Colorado-recognized universal opt-out mechanism automatically, without forcing the consumer through another step.
Sensitive data and geolocation The business processes or sells sensitive data, now including precise geolocation data added by SB 25-276. Collect clear opt-in consent before processing or sale; map app, SDK, advertising, analytics, delivery, and location-personalization flows separately.
Minor online service The controller actually knows or willfully disregards that a Colorado consumer is a minor and the online product can create heightened risk of harm. Use reasonable care, run and retain a minor-focused data protection assessment, and obtain consent before targeted advertising, sale, profiling for significant decisions, or addictive-design features.
High-risk processing Targeted advertising, sale of personal data, profiling with legal or similarly significant effects, sensitive-data processing, or minor-data processing with heightened risk. Document a data protection assessment before launch and be ready to provide it to the Colorado Attorney General on request.
Consumer-rights workflow A Colorado resident exercises access, correction, deletion, portability, opt-out, or appeal rights. Respond within 45 days, use the one 45-day extension only when reasonably necessary, and preserve the appeal path for denied requests.

Source check: Last verified June 27, 2026 against the Colorado Attorney General’s CPA overview and rules page, C.R.S. § 6-1-1304, the Colorado AG’s 2025 proposed-rulemaking notice, the Colorado General Assembly SB 24-041 enacted bill page, and the Colorado General Assembly SB 25-276 enacted bill page (date_retrieved: 2026-06-27).

Consumer Rights Under the CPA

The CPA grants Colorado residents a robust set of privacy rights:

  • Right to access — Confirm whether a controller is processing personal data and access that data
  • Right to correction — Request correction of inaccurate personal data
  • Right to deletion — Request deletion of personal data
  • Right to data portability — Obtain a copy of personal data in a portable, readily usable format
  • Right to opt out of data sale — Opt out of the sale of personal data
  • Right to opt out of targeted advertising — Opt out of processing for targeted advertising purposes
  • Right to opt out of profiling — Opt out of profiling that produces legal or similarly significant effects
  • Right to appeal — Appeal a controller’s refusal to act on a rights request

Controllers must respond to consumer rights requests within 45 days, with one 45-day extension if reasonably necessary.

Universal Opt-Out Mechanism (GPC) Requirement

Colorado was one of the first states to mandate that businesses honor universal opt-out mechanisms such as Global Privacy Control (GPC). This requirement went into effect on July 1, 2024.

The Colorado Attorney General has published technical specifications and a list of approved universal opt-out mechanisms. Businesses must:

  • Detect and honor GPC browser signals automatically
  • Treat a GPC signal as an opt-out of both data sales and targeted advertising
  • Not require additional action from the consumer beyond enabling GPC
  • Provide clear instructions in their privacy notice about how consumers can use universal opt-out mechanisms

Colorado joins California, Connecticut, Texas, Montana, Delaware, Oregon, and Maryland in requiring universal opt-out recognition. Check your GPC obligations across all states with our GPC Compliance Checker.

Key 2025–2026 Changes

The CPA has undergone several important updates:

Cure Period Eliminated (January 1, 2025)

The CPA’s original 60-day cure period sunset on January 1, 2025. The Colorado Attorney General now has full enforcement discretion and can proceed directly to enforcement without offering businesses a chance to fix violations first. This places Colorado alongside California in having the most aggressive enforcement posture among state privacy laws.

SB 25-276: Precise Geolocation Data as Sensitive Data (2025)

Signed in May 2025, SB 25-276 added precise geolocation data as a new category of sensitive data under the CPA. This means businesses must now obtain opt-in consent before collecting or processing precise geolocation data of Colorado consumers. This aligns Colorado with Oregon and Maryland in providing elevated protections for location data.

SB 24-041: Age-Appropriate Design Code (October 1, 2025)

SB 24-041 introduced significant new requirements for services likely to be accessed by minors:

  • Age-appropriate design code: Online services must implement design practices that protect children’s and teens’ privacy
  • Opt-in consent for minors 13–17: Targeted advertising and data sales involving minors aged 13–17 now require opt-in consent
  • COPPA requirements for under-13: Verifiable parental consent is required for children under 13

Continued CPA Rulemaking (2025–2026)

The Colorado Department of Law filed proposed amendments to CPA rules in July 2025 to clarify the implementation of SB 24-041 and SB 25-276, accepted comments through September 10, 2025, and continues to point businesses to the CPA rulemaking page for implementation updates. Treat the rulemaking docket as a live compliance watch item: if your service handles minors’ data, precise geolocation, sensitive-data sales, or universal opt-out signals, re-check the AG page before each release.

Sensitive Data Under the CPA

The CPA requires opt-in consent before processing sensitive personal data. As of 2026, sensitive data categories include:

  • Racial or ethnic origin
  • Religious beliefs
  • Mental or physical health condition or diagnosis
  • Sex life or sexual orientation
  • Citizenship or immigration status
  • Biometric data for identification purposes
  • Precise geolocation data (added by SB 25-276)

The addition of precise geolocation data means that businesses collecting location information (such as mobile apps, mapping services, or delivery platforms) must obtain explicit consumer consent before processing this data for Colorado residents.

Data Protection Assessments

The CPA requires controllers to conduct and document data protection assessments (DPAs) before engaging in processing that presents a heightened risk to consumers. Required assessments include:

  • Processing personal data for targeted advertising
  • Sale of personal data
  • Processing for profiling with legal or similarly significant effects
  • Processing sensitive personal data
  • New: Processing involving automated profiling that produces legal or similarly significant effects (added by SB 24-041)

DPAs must weigh the benefits of the processing against the potential risks to consumer rights and be made available to the Attorney General upon request.

Enforcement and Penalties

The CPA is enforced by the Colorado Attorney General and District Attorneys. There is no private right of action.

  • Penalties: Up to $20,000 per violation
  • Additional penalties: Up to $50,000 for violations involving deceptive trade practices
  • Cure period: None (sunset January 1, 2025)

The $20,000 per-violation maximum makes the CPA one of the stricter state privacy laws. The absence of a cure period since January 2025 means the AG can act swiftly. View all state enforcement actions on our Enforcement Tracker.

How Colorado Compares to Other State Privacy Laws

  • GPC pioneer: Colorado was among the first states (alongside California and Connecticut) to mandate universal opt-out mechanism recognition
  • No cure period: The 60-day cure period sunset on January 1, 2025 — Colorado joins California, Maryland, and Oregon in this strict approach
  • High penalties: $20,000 per violation is among the highest flat rates — exceeded only by Maryland ($10K/$25K escalating) and Florida ($50K)
  • Precise geolocation as sensitive data: SB 25-276 aligns Colorado with the emerging trend of treating location data as a special category
  • Age-appropriate design code: SB 24-041 places Colorado alongside California in having specific design requirements for services accessed by minors
  • Active AG rulemaking: Colorado’s AG has been among the most active in developing detailed implementation rules, providing clearer compliance guidance than most states

Use our State Comparison Tool to see how Colorado stacks up against all 20+ state privacy laws.

8-Step CPA Compliance Plan

  1. Assess applicability — Determine if your organization processes data of 100,000+ Colorado consumers, or 25,000+ while deriving revenue from data sales. Use the Privacy Law Calculator.
  2. Implement GPC recognition — Ensure your website and apps recognize and honor Global Privacy Control and other approved universal opt-out mechanisms. This has been required since July 1, 2024.
  3. Audit geolocation data collection — Obtain opt-in consent before collecting or processing precise geolocation data from Colorado consumers (required by SB 25-276).
  4. Review minor data practices — Implement age-appropriate design practices. Obtain opt-in consent for targeted advertising and data sales involving consumers aged 13–17. Ensure COPPA compliance for children under 13.
  5. Update privacy notices — Include all CPA-required disclosures, including categories of data, purposes, third-party sharing, consumer rights, and universal opt-out instructions.
  6. Build consumer rights processes — Create intake, verification, fulfillment, and appeals workflows for all eight consumer rights. Configure 45-day response timelines.
  7. Conduct data protection assessments — Document DPAs for all high-risk processing activities including targeted advertising, data sales, profiling, sensitive data processing, and automated decision-making.
  8. Review processor contracts — Ensure all data processor agreements include CPA-mandated provisions governing scope, purpose, confidentiality, and data return or deletion.

For a detailed walkthrough, visit our Colorado Compliance Checklist.

Frequently Asked Questions

What is the Colorado Privacy Act (CPA)?

The Colorado Privacy Act (CPA) is Colorado’s comprehensive consumer data privacy law. Signed July 7, 2021 and effective July 1, 2023, it made Colorado the third state with a comprehensive privacy law (after California and Virginia). The CPA is codified at Colo. Rev. Stat. §§ 6-1-1301 to 6-1-1313 and gives Colorado residents eight consumer rights. It applies to controllers that process data of 100,000+ Colorado consumers, or 25,000+ consumers while deriving any revenue from data sales. It has been amended by SB 24-041 (age-appropriate design code) and SB 25-276 (precise geolocation as sensitive data).

What are the penalties for violating the Colorado Privacy Act?

The Colorado Privacy Act imposes some of the steepest state-privacy fines in the country: up to $20,000 per violation, plus up to $50,000 per violation if the conduct also amounts to a deceptive trade practice under Colorado’s Consumer Protection Act. The 60-day cure period sunset on January 1, 2025, so the Colorado AG and District Attorneys can pursue enforcement immediately, without first offering an opportunity to cure. There is no private right of action — consumers cannot sue directly, only file complaints with the AG.

Does the Colorado Privacy Act require Global Privacy Control (GPC)?

Yes. Since July 1, 2024, controllers covered by the CPA must recognize and honor universal opt-out mechanisms, including Global Privacy Control (GPC), as valid opt-outs from the sale of personal data and processing for targeted advertising. The Colorado Attorney General publishes the official list of approved universal opt-out mechanisms; controllers cannot require any additional consumer action beyond enabling GPC. Verify your implementation with our free GPC Compliance Checker.

When did the Colorado Privacy Act take effect?

The base CPA took effect on July 1, 2023. Universal opt-out (GPC) requirements took effect July 1, 2024. The 60-day cure period sunset on January 1, 2025 — from that date forward the AG can enforce immediately. Major amendments effective in 2025: SB 24-041 (age-appropriate design code, October 1, 2025) and SB 25-276 (precise geolocation as sensitive data, signed May 2025).

Where can I find the full text of the Colorado Privacy Act?

The Colorado Privacy Act is codified at Colo. Rev. Stat. §§ 6-1-1301 to 6-1-1313. The full text and the Colorado AG’s implementing rules are available at coag.gov/resources/colorado-privacy-act. The Colorado General Assembly maintains the original SB 21-190 enrolled text at leg.colorado.gov. The most recent amendments — SB 24-041 and SB 25-276 — are available via the same Colorado General Assembly bill-lookup interface.

Source check: Last verified June 14, 2026 against the Colorado Attorney General’s CPA overview, rules, and universal opt-out page, the Colorado AG’s 2025 proposed-rulemaking notice, and the Colorado General Assembly SB 25-276 enacted bill page (date_retrieved: 2026-06-14).

What are the Colorado Privacy Act compliance requirements for 2026?

The 2026 CPA compliance requirements are: (1) determine applicability against the 100K / 25K-plus-data-sales thresholds; (2) implement GPC recognition (live since July 2024); (3) obtain opt-in consent before collecting precise geolocation data (SB 25-276); (4) implement age-appropriate design and opt-in consent for minors aged 13–17 (SB 24-041, effective October 2025); (5) publish a CPA-compliant privacy notice; (6) build the eight consumer-rights workflows with a 45-day response window and appeals; (7) document data protection assessments for high-risk processing; (8) tighten processor contracts with the CPA-mandated provisions. The 8-step plan above walks through each.

What is the Colorado CPA compliance checklist for 2026?

The practical 2026 checklist is: confirm whether the 100,000-consumer or 25,000-consumer-plus-data-sale threshold applies; inventory sensitive data and precise geolocation; configure GPC and other Colorado-recognized universal opt-out mechanisms; write a Colorado privacy notice; set 45-day rights and appeal workflows; complete DPAs for targeted advertising, sale, profiling, sensitive data, and minor-data risk; update processor contracts; and keep a rulemaking watch for SB 24-041 and SB 25-276 implementation guidance.

This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Published: March 29, 2026. Last verified: June 14, 2026.

Put This Guide Into PracticeSponsored

Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.

Start Free with Termly