CO

Colorado Privacy Law

Colorado Privacy Act

Effective: July 1, 2023ActiveReviewed by PrivacyLawMap editorial teamLast verified: June 6, 2026

Overview

The Colorado Privacy Act (CPA) — codified at Colo. Rev. Stat. §§ 6-1-1301 to 6-1-1313 — was signed into law by Governor Jared Polis on July 7, 2021, and took effect on July 1, 2023. Colorado was the third state to enact a comprehensive consumer privacy law, following California and Virginia, and the first state to make its universal opt-out requirement enforceable at the technical level. Its framework closely mirrors the Virginia VCDPA structure (access/correction/deletion/portability/opt-out, controller/processor distinction, no private right of action), but layers on several uniquely consumer-protective provisions: mandatory honoring of universal opt-out mechanisms since July 1, 2024; some of the most detailed implementing rules of any state privacy law (the Colorado AG issued the first comprehensive CPA Rules in March 2023, later amended in 2025); data protection assessment (DPIA) obligations with explicit AG audit rights; and an age-appropriate design code (SB 24-041) modeled on California's AADC. Enforcement is handled by the Colorado Attorney General's Consumer Protection Section and by District Attorneys, with penalties calculated under the Colorado Consumer Protection Act (CCPA — not to be confused with California's CCPA) at up to $20,000 per violation per consumer.

The CPA provides Colorado residents with rights to access, correct, delete, and obtain a portable copy of their personal data. Consumers also have the right to opt out of the sale of personal data, targeted advertising, and certain profiling activities that produce legal or similarly significant effects. Controllers must respond to verified consumer requests within 45 days (extendable once by another 45 days for complex requests) and must provide a documented appeals process with a final response within 45 days of the appeal. Colorado was one of the first states to mandate that businesses recognize universal opt-out signals such as Global Privacy Control (GPC), which went into effect July 1, 2024. The Colorado AG maintains a public list of recognized universal opt-out mechanisms and has published detailed technical specifications — including the requirement that recognition be server-side (not merely JavaScript/client-side) and that the signal be propagated to all downstream processors — making Colorado's GPC regime materially stricter than most other state laws.

The law applies to controllers that conduct business in Colorado or target Colorado residents and that (a) process personal data of 100,000 or more consumers annually, or (b) process personal data of 25,000 or more consumers while deriving any revenue or receiving a discount from the sale of personal data. Unlike the Utah UCPA (which uses AND logic requiring both revenue and volume thresholds), the CPA uses OR logic — meeting either threshold triggers compliance obligations. There is no standalone revenue threshold, so small businesses that cross the consumer-count line are fully in scope regardless of company size. The CPA exempts certain entities and data types, including HIPAA-covered entities and business associates (for PHI only, not for other consumer data), GLBA-regulated financial data, FCRA-regulated consumer report data, employee and job applicant data (through a temporary exemption that has been repeatedly extended), and nonprofit organizations — though these exemptions are narrower than in some other states. Notably, Colorado does not entity-exempt insurance institutions or educational institutions the way several other states do, which has pulled a number of mid-market organizations into scope unexpectedly.

The CPA originally included a 60-day cure period, which sunset on January 1, 2025 — the AG now has full discretion in enforcement. Attorney General Phil Weiser's Consumer Protection Section has made Colorado one of the most active state privacy enforcers in the country since the sunset. In 2025, two major amendments strengthened the CPA: SB 25-276 (signed May 2025) added precise geolocation data as a new category of sensitive data requiring opt-in consent, and SB 24-041 (effective October 1, 2025) added age-appropriate design code requirements and strengthened minor protections for consumers aged 13-17. Colorado replaced the 2024 Colorado Artificial Intelligence Act framework with SB 26-189, the Automated Decision-Making Technology law signed May 14, 2026. Per the Colorado Attorney General rulemaking page, SB 26-189 repeals and reenacts the earlier high-risk-AI provisions with ADMT-specific duties for consequential decisions that take effect January 1, 2027, including developer documentation, deployer notices, post-adverse-outcome explanations, record retention, and rights to correction plus meaningful human review. The Colorado Department of Law filed proposed amendments to the CPA rules in July 2025, clarifying requirements from SB 25-276 and SB 24-041; these rule amendments take effect July 1, 2026. Penalties can reach $20,000 per violation, making the CPA one of the stricter state privacy laws. Colorado's early enforcement has focused on universal opt-out/GPC compliance, with the AG conducting enforcement sweeps targeting non-compliant businesses and publicly disclosing a $250,000 penalty against an adtech company in April 2025 as the first post-cure-period CPA enforcement action.

Applicability Thresholds

Conditions are joined by OR meeting ANY one triggers applicability.

100,000+
Colorado consumers' data processed
25,000+ consumers
AND 50%+ revenue from data sales

Consumer Rights

Right to Access
Right to Delete
Right to Correct
Data Portability
Opt-Out of Sale
Opt-Out of Targeted Ads
Opt-Out of Profiling
Limit Sensitive Data Use
Right to Appeal
Private Right of Action

Key Changes in 2025-2026

  • The 60-day cure period sunset on January 1, 2025 — AG now has full enforcement discretion with no obligation to offer cure opportunities before filing suit or issuing notices of violation
  • SB 25-276 (signed May 2025) added precise geolocation data (within 1,850 feet / ~564 meters) as a new category of sensitive data requiring opt-in consent, aligning Colorado with Maryland MODPA, Oregon, Connecticut, and most other comprehensive state privacy laws
  • SB 24-041 (effective October 1, 2025) added age-appropriate design code requirements modeled after California's AADC, strengthening minor protections including DPIA requirements for minor-facing services and opt-in consent for targeted advertising and data sales involving consumers aged 13-17
  • SB 26-189 (signed May 14, 2026) replaced Colorado's 2024 high-risk-AI framework with an Automated Decision-Making Technology law effective January 1, 2027; developers and deployers of covered ADMT must prepare documentation, consumer notices, post-adverse-outcome explanations, 3-year compliance records, and meaningful human review workflows
  • Department of Law CPA rule amendments take effect July 1, 2026, clarifying SB 24-041 and SB 25-276 requirements, updating universal opt-out technical specifications, and finalizing biometric data provisions added by HB 24-1130
  • HB 24-1130 (signed May 31, 2024, effective July 1, 2025) expanded the CPA's definition of sensitive data to include biometric identifiers processed for the purpose of uniquely identifying an individual, and added biometric-specific notice and consent requirements
  • AG enforcement activity accelerating — first post-cure-period enforcement action resulted in $250,000 penalty against an AdTech company for ignoring GPC signals from 500,000+ Colorado users
  • AG conducted proactive GPC enforcement sweep with 15+ companies receiving non-compliance notices during 2025, signaling that universal opt-out enforcement remains the Consumer Protection Section's top priority heading into 2026
  • Health data processing enforcement increasing — $300,000 consent decree against a national health app for collecting mental health and reproductive health data without opt-in consent, the first formal CPA consent decree targeting sensitive-data violations
  • Colorado remains one of only two states (alongside California) to require server-side (not merely client-side) recognition of GPC signals, meaning CCPA-only GPC implementations are insufficient for Colorado compliance

Enforcement Details

Enforced By
Colorado Attorney General and District Attorneys
Penalty Per Violation
$20,000
Cure Period
None — immediate enforcement
Private Right of Action
No — AG enforcement only

Notable Enforcement Actions

Undisclosed (AdTech Company)

CPA · Notable enforcement action

$250,000

Colorado AG's first CPA enforcement action after the cure period sunset. An advertising technology company failed to honor universal opt-out signals (GPC) and continued processing Colorado consumers' data for targeted advertising. The AG found the company had received and ignored GPC signals from over 500,000 Colorado users.

April 22, 2025

Multiple Companies (GPC Enforcement Sweep)

CPA · Notable enforcement action

Cure notices — 15+ companies notified

Colorado AG launched a proactive enforcement sweep focused on universal opt-out/GPC compliance. Over 15 companies received notices of non-compliance for failing to recognize or honor GPC signals. Companies had 60 days to cure (before sunset) or face penalties up to $20,000 per violation.

January 15, 2025

National Health App Provider

CPA · Notable enforcement action

$300,000 (consent decree)

Health and wellness app collected sensitive health data including mental health conditions and reproductive health information without obtaining opt-in consent as required for sensitive data categories under the CPA. The company was also found to lack required data protection assessments.

November 3, 2025

Sensitive Data Categories

Consent model: opt-in

Racial or ethnic originReligious beliefsMental or physical health condition or diagnosisSex life or sexual orientationCitizenship or immigration statusBiometric data for identificationPrecise geolocation data

Universal Opt-Out / GPC Requirements

GPC / Universal Opt-Out Required

As of July 1, 2024, businesses must recognize and honor universal opt-out mechanisms such as Global Privacy Control (GPC). The Colorado AG has published technical specifications for compliance with this requirement.

Effective: July 1, 2024

Minor / Child Protections

The CPA requires opt-in consent before processing sensitive data, which includes data of known children. Businesses must obtain verifiable parental consent for children under 13, consistent with COPPA. SB 24-041 (effective October 1, 2025) added age-appropriate design code requirements and strengthened protections for minors aged 13-17, including opt-in consent for targeted advertising and data sales.

Compliance Checklist

  1. 1Determine CPA applicability: assess whether your organization processes personal data of 100,000+ Colorado consumers annually, OR 25,000+ consumers while deriving any revenue or receiving any discount from data sales (OR logic — either threshold triggers compliance). There is no standalone revenue threshold, so small businesses that hit the consumer-count line are fully in scope. Check exemptions carefully: HIPAA-covered entities are exempt ONLY for PHI (not for consumer data collected outside the HIPAA context), GLBA-regulated financial data is exempt at the data level (not entity level), FCRA-regulated consumer report data is exempt, nonprofits and higher education institutions have limited exemptions, and employee/job applicant data has a temporary exemption that has been repeatedly extended
  2. 2Conduct a comprehensive data inventory: identify all personal data collected from Colorado consumers, map data flows including third-party sharing, categorize sensitive data (racial/ethnic origin, religious beliefs, mental or physical health condition, sex life/sexual orientation, citizenship/immigration status, biometric identifiers under HB 24-1130, and precise geolocation within 1,850 feet per SB 25-276), and document all processing purposes. Special attention to minors' data (13-17) and any covered automated decision-making technology subject to SB 26-189
  3. 3Implement server-side technical mechanisms to detect and honor universal opt-out signals (GPC and other AG-recognized mechanisms). The Colorado AG explicitly requires server-side recognition — client-side-only JavaScript processing is insufficient. Test GPC signal detection across all consumer-facing web properties and all major browsers (Chrome, Firefox, Safari, Edge, Brave), ensure opt-out propagates to all downstream data processors within 15 days (as required by the CPA Rules), and maintain a GPC hit log for at least 24 months for audit defense. The AG's Consumer Protection Section treats GPC as its top enforcement priority
  4. 4Update privacy notices to include all CPA-required disclosures: categories of personal data collected, purposes of processing, categories of third parties receiving data, consumer rights and how to exercise them, instructions for using universal opt-out mechanisms (with a plain-English link/description), whether data is sold or used for targeted advertising, and a dated "Last Updated" field. Under the July 1, 2026 rule amendments, notices must also disclose any use of personal data to train AI models for services that might reasonably be considered minor-facing
  5. 5Build consumer rights request intake and fulfillment processes: respond to verified requests within 45 days (one 45-day extension permitted with notice), support access, correction, deletion, and portability requests, implement a documented internal appeals process for denied requests with a 45-day response window, designate a privacy officer or point of contact for AG inquiries, and maintain records of all requests and responses for at least 24 months
  6. 6Obtain affirmative opt-in consent before processing any sensitive personal data, including precise geolocation data within 1,850 feet (added by SB 25-276) and biometric identifiers used for unique identification (added by HB 24-1130). Consent must be freely given, specific, informed, and unambiguous — pre-checked boxes, bundled consent, dark patterns, and cookie-banner "Accept All" defaults that do not also offer a genuinely equivalent "Reject All" are insufficient. Maintain a consent log that documents the specific language presented to each consumer and the timestamp of consent
  7. 7Comply with age-appropriate design code requirements (SB 24-041, effective October 1, 2025): conduct DPIAs for any online service, product, or feature likely accessed by minors; default to the highest privacy settings for minor users (no targeted advertising, no data sale, no profiling); prohibit using personal data in ways reasonably foreseeable to harm minors; obtain opt-in consent for targeted advertising and data sales involving consumers aged 13-17; provide clear privacy notices written in age-appropriate language; and do NOT use dark patterns, nudges, or engagement-maximizing features (autoplay, infinite scroll, streak rewards) in minor-facing services
  8. 8Prepare for Colorado SB 26-189 compliance before the January 1, 2027 effective date: determine whether any automated decision-making technology materially influences consequential decisions in education, employment, housing, financial or lending services, insurance, healthcare, essential government services, or public benefits; if a developer, prepare technical documentation on intended uses, training data categories, limitations, appropriate use, and human review; if a deployer, build clear point-of-interaction notices, post-adverse-outcome explanations, correction workflows, and meaningful human review/reconsideration. These ADMT obligations stack on top of CPA profiling and DPIA requirements — do not treat them as separate workstreams
  9. 9Conduct and document data protection assessments (DPIAs) for: targeted advertising, sale of personal data, profiling with a reasonably foreseeable risk of unfair or deceptive treatment, processing sensitive data, any processing presenting a heightened risk of harm, and any processing of minors' data under SB 24-041. Assessments must weigh benefits against potential risks to consumer rights, be made available to the AG upon request within 30 days of demand, and be retained for at least 3 years after the processing activity ends
  10. 10Review and update all data processing agreements with third-party processors to include CPA-required terms: clear processing instructions, confidentiality obligations, subprocessor management (processor must obtain controller permission or maintain a public list), cooperation with consumer rights requests, data return or deletion upon contract termination, audit rights, and propagation of opt-out signals within 15 days. Any contract signed before July 1, 2023 that has not been refreshed is likely noncompliant
  11. 11Implement data minimization practices: collect only personal data that is adequate, relevant, and reasonably necessary for the disclosed processing purposes. The CPA's data minimization requirement is stricter than some other state laws and applies to both collection and retention — document purpose specification, retention schedules, and periodic deletion review cycles. Be prepared to justify retention beyond 12 months in a DPIA
  12. 12Prepare for July 1, 2026 CPA rule amendments: review updated technical specifications for universal opt-out mechanisms, updated DPIA requirements for minor-facing services under SB 24-041, clarified sensitive data consent requirements for precise geolocation under SB 25-276, and finalized biometric data provisions under HB 24-1130. The July 2026 rules are expected to add explicit examples of noncompliant cookie-banner dark patterns and a safe-harbor cookie-banner template
  13. 13Establish an ongoing compliance monitoring program: monthly automated GPC signal tests across all browsers, quarterly consent-mechanism audits, annual DPIA refresh, documented employee training on CPA obligations (at minimum for marketing, product, engineering, and customer-service teams), a public-facing complaint intake channel, and a monthly review of Colorado AG enforcement actions and guidance for evolving compliance expectations
  14. 14Develop an AG-inquiry response playbook for the post-cure-period environment: because the 60-day cure period sunset on January 1, 2025, any notice of violation or civil investigative demand from the Consumer Protection Section should be treated as litigation-ready. The playbook should include immediate document preservation, designation of outside privacy counsel, internal compliance audit, remediation plan, and response within the AG's stated deadline (typically 20-30 days). Even voluntary remediation no longer guarantees enforcement discretion
  15. 15Map multi-state compliance overlap: if already compliant with California CCPA, Virginia VCDPA, or Connecticut CTDPA, identify the Colorado-specific delta. Highest-risk delta items are (1) server-side GPC enforcement (stricter than most states), (2) the 1,850-foot precise geolocation threshold (stricter than CCPA's GPS-derived standard), (3) narrower HIPAA/GLBA exemptions (data-level, not entity-level), (4) AADC requirements under SB 24-041, and (5) SB 26-189 covered-ADMT duties for consequential decisions
Put CPA Into Practice on Your SiteSponsored

Termly builds and maintains a Colorado-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests CPA grants.

Start Free with Termly

Colorado Privacy Law FAQ

Official Resources