1
Determine CPA applicability: assess whether your organization processes personal data of 100,000+ Colorado consumers annually, OR 25,000+ consumers while deriving any revenue or receiving any discount from data sales (OR logic — either threshold triggers compliance). There is no standalone revenue threshold, so small businesses that hit the consumer-count line are fully in scope. Check exemptions carefully: HIPAA-covered entities are exempt ONLY for PHI (not for consumer data collected outside the HIPAA context), GLBA-regulated financial data is exempt at the data level (not entity level), FCRA-regulated consumer report data is exempt, nonprofits and higher education institutions have limited exemptions, and employee/job applicant data has a temporary exemption that has been repeatedly extended
2
Conduct a comprehensive data inventory: identify all personal data collected from Colorado consumers, map data flows including third-party sharing, categorize sensitive data (racial/ethnic origin, religious beliefs, mental or physical health condition, sex life/sexual orientation, citizenship/immigration status, biometric identifiers under HB 24-1130, and precise geolocation within 1,850 feet per SB 25-276), and document all processing purposes. Special attention to minors' data (13-17) and any covered automated decision-making technology subject to SB 26-189
3
Implement server-side technical mechanisms to detect and honor universal opt-out signals (GPC and other AG-recognized mechanisms). The Colorado AG explicitly requires server-side recognition — client-side-only JavaScript processing is insufficient. Test GPC signal detection across all consumer-facing web properties and all major browsers (Chrome, Firefox, Safari, Edge, Brave), ensure opt-out propagates to all downstream data processors within 15 days (as required by the CPA Rules), and maintain a GPC hit log for at least 24 months for audit defense. The AG's Consumer Protection Section treats GPC as its top enforcement priority
4
Update privacy notices to include all CPA-required disclosures: categories of personal data collected, purposes of processing, categories of third parties receiving data, consumer rights and how to exercise them, instructions for using universal opt-out mechanisms (with a plain-English link/description), whether data is sold or used for targeted advertising, and a dated "Last Updated" field. Under the July 1, 2026 rule amendments, notices must also disclose any use of personal data to train AI models for services that might reasonably be considered minor-facing
5
Build consumer rights request intake and fulfillment processes: respond to verified requests within 45 days (one 45-day extension permitted with notice), support access, correction, deletion, and portability requests, implement a documented internal appeals process for denied requests with a 45-day response window, designate a privacy officer or point of contact for AG inquiries, and maintain records of all requests and responses for at least 24 months
6
Obtain affirmative opt-in consent before processing any sensitive personal data, including precise geolocation data within 1,850 feet (added by SB 25-276) and biometric identifiers used for unique identification (added by HB 24-1130). Consent must be freely given, specific, informed, and unambiguous — pre-checked boxes, bundled consent, dark patterns, and cookie-banner "Accept All" defaults that do not also offer a genuinely equivalent "Reject All" are insufficient. Maintain a consent log that documents the specific language presented to each consumer and the timestamp of consent
7
Comply with age-appropriate design code requirements (SB 24-041, effective October 1, 2025): conduct DPIAs for any online service, product, or feature likely accessed by minors; default to the highest privacy settings for minor users (no targeted advertising, no data sale, no profiling); prohibit using personal data in ways reasonably foreseeable to harm minors; obtain opt-in consent for targeted advertising and data sales involving consumers aged 13-17; provide clear privacy notices written in age-appropriate language; and do NOT use dark patterns, nudges, or engagement-maximizing features (autoplay, infinite scroll, streak rewards) in minor-facing services
8
Prepare for Colorado SB 26-189 compliance before the January 1, 2027 effective date: determine whether any automated decision-making technology materially influences consequential decisions in education, employment, housing, financial or lending services, insurance, healthcare, essential government services, or public benefits; if a developer, prepare technical documentation on intended uses, training data categories, limitations, appropriate use, and human review; if a deployer, build clear point-of-interaction notices, post-adverse-outcome explanations, correction workflows, and meaningful human review/reconsideration. These ADMT obligations stack on top of CPA profiling and DPIA requirements — do not treat them as separate workstreams
9
Conduct and document data protection assessments (DPIAs) for: targeted advertising, sale of personal data, profiling with a reasonably foreseeable risk of unfair or deceptive treatment, processing sensitive data, any processing presenting a heightened risk of harm, and any processing of minors' data under SB 24-041. Assessments must weigh benefits against potential risks to consumer rights, be made available to the AG upon request within 30 days of demand, and be retained for at least 3 years after the processing activity ends
10
Review and update all data processing agreements with third-party processors to include CPA-required terms: clear processing instructions, confidentiality obligations, subprocessor management (processor must obtain controller permission or maintain a public list), cooperation with consumer rights requests, data return or deletion upon contract termination, audit rights, and propagation of opt-out signals within 15 days. Any contract signed before July 1, 2023 that has not been refreshed is likely noncompliant
11
Implement data minimization practices: collect only personal data that is adequate, relevant, and reasonably necessary for the disclosed processing purposes. The CPA's data minimization requirement is stricter than some other state laws and applies to both collection and retention — document purpose specification, retention schedules, and periodic deletion review cycles. Be prepared to justify retention beyond 12 months in a DPIA
12
Prepare for July 1, 2026 CPA rule amendments: review updated technical specifications for universal opt-out mechanisms, updated DPIA requirements for minor-facing services under SB 24-041, clarified sensitive data consent requirements for precise geolocation under SB 25-276, and finalized biometric data provisions under HB 24-1130. The July 2026 rules are expected to add explicit examples of noncompliant cookie-banner dark patterns and a safe-harbor cookie-banner template
13
Establish an ongoing compliance monitoring program: monthly automated GPC signal tests across all browsers, quarterly consent-mechanism audits, annual DPIA refresh, documented employee training on CPA obligations (at minimum for marketing, product, engineering, and customer-service teams), a public-facing complaint intake channel, and a monthly review of Colorado AG enforcement actions and guidance for evolving compliance expectations
14
Develop an AG-inquiry response playbook for the post-cure-period environment: because the 60-day cure period sunset on January 1, 2025, any notice of violation or civil investigative demand from the Consumer Protection Section should be treated as litigation-ready. The playbook should include immediate document preservation, designation of outside privacy counsel, internal compliance audit, remediation plan, and response within the AG's stated deadline (typically 20-30 days). Even voluntary remediation no longer guarantees enforcement discretion
15
Map multi-state compliance overlap: if already compliant with California CCPA, Virginia VCDPA, or Connecticut CTDPA, identify the Colorado-specific delta. Highest-risk delta items are (1) server-side GPC enforcement (stricter than most states), (2) the 1,850-foot precise geolocation threshold (stricter than CCPA's GPS-derived standard), (3) narrower HIPAA/GLBA exemptions (data-level, not entity-level), (4) AADC requirements under SB 24-041, and (5) SB 26-189 covered-ADMT duties for consequential decisions