Skip to content

Colorado Privacy Act: A Privacy Compliance Overview

Colorado landscape with CPA badge
Resources / Blog / Colorado Privacy Act: A Privacy Compliance Overview
Summary
  • The Colorado Privacy Act (CPA) went into effect July 1, 2023 and applies to businesses processing personal data of 100,000+ Colorado residents annually, or 25,000+ if they profit from selling that data.
  • The mandatory 60-day cure period ended January 1, 2025, so the Colorado Attorney General can pursue enforcement without warning in most cases.
  • Consumers can opt out of sale, targeted advertising, and profiling, and can access, correct, delete, or port their personal data.
  • Colorado requires businesses to honor Global Privacy Control (GPC) as an approved universal opt-out signal.
  • 2025 amendments added precise geolocation as sensitive data requiring opt-in consent, plus new protections for consumers aged 13 to 17.
  • Violations can bring civil penalties of up to $20,000 per violation, or $50,000 against an elderly consumer.

Colorado was the third U.S. state to pass privacy legislation. While it was certainly influenced by and shares content from California and Virginia’s state laws, the Colorado Privacy Act also shows the rapid evolution of legal thought and consumer rights expectations around privacy.

While a federal U.S. privacy law is still nowhere on the horizon, we’ll outline what businesses operating in Colorado need to know for compliance.

What Is the Colorado Privacy Act?

The Colorado Privacy Act (CPA) was signed into law on July 8th, 2021, and went into effect on July 1st, 2023. It protects the privacy rights of Colorado residents and applies responsibilities to companies doing business in the state. Among these is mandated adherence to standards for controlling, storing, processing, and maintaining personally identifiable information (PII).

Consumers, Controllers, and Processors Under the Colorado Privacy Act

The Colorado Privacy Act is designed to protect the consumer, defined in the Act as: “an individual who is a Colorado resident acting only in an individual or household context; and does not include an individual acting in a commercial or employment context, as a job applicant, or as a beneficiary of someone acting in an employment context”.

The Colorado Privacy Act is particularly intended to protect consumers in their online activities. It gives them certain rights over their personal data, including making inquiries or requests to data controllers or data processors about it.

Under the Act a data controller is “a person that, alone or jointly with others, determines the purposes for and means of processing personal data”. So it could be a company, but isn’t explicitly limited to commercial enterprises.

The Act defines a data processor as “a person that processes personal data on behalf of a controller”. Again, likely often a corporate entity, but not always. It can also be a third party that’s not part of the same entity that qualifies as the controller.

“Processing” with regards to data doesn’t explicitly refer to its sale, and the CPA defines that as “collection, use, sale, storage, disclosure, analysis, deletion, or modification of personal data and includes the actions of a controller directing a processor to process personal data”.

Consumer Rights Under the Colorado Privacy Act

Consumers have five specific rights under the Colorado Privacy Act:

CPA Consumer Rights

CPA Consumer Rights
1
right to opt-out of data processing

For targeted advertising, sale or profiling using their personal data.

2
Right to access

Any data that a company has collected about them.

3
Right to have any data corrected

That has been collected about them and is incorrect or outdated.

4
Right to deletion

For any data collected about them.

5
Right to data portability

The ability for a consumer to receive their data in a portable format to transfer to another entity.

Data controllers must respond to an authenticated consumer request within 45 days of receiving it. Where “reasonably necessary” the controller can request an additional 45 days to complete the request, but must communicate the reason for the delay.

The Colorado Privacy Act also requires data controllers to establish a process for consumers to appeal a denial of their request, and communicate that they can contact the Attorney General if they have concerns about the denial of the request. This is not a part of other states’ privacy laws. Requests can be denied if the person making the request can’t be reasonably authenticated and the person making the request fails to provide adequate additional authentication documentation.

Controllers are exempt from some aspects of requesting consent or responding to consumer requests about PII if the data in question has been de-identified. However, regular and identifiable PII that has been requested must be provided free of charge if the request is reasonable and authenticated.

Unlike the CCPA, the CPA does not provide consumers with private right of action, i.e. the ability to sue companies for damages or injury in the event of an alleged violation.

Personally Identifiable Information

Personally identifiable information is among the types of data protected by the Colorado Privacy Act. The term refers to information that is “linked or reasonably linkable to an identified or identifiable individual”. Both physical and digital data and records are protected.

The following types of data are considered PII and are protected:

  • Biometric information
  • Credit and debit card numbers
  • Drivers’ license and license plate numbers
  • Email addresses
  • Employment information
  • Financial data
  • Healthcare and insurance information
  • Mailing addresses
  • Military ID numbers
  • Passport ID numbers
  • Passwords
  • Physical addresses
  • Social Security Numbers
  • Student ID numbers
  • Telephone numbers
  • Usernames

The definition of personal information excludes data that has been de-identified or that is publicly available. (Learn more: Data Anonymization: The What, Why, and How of Data Anonymization). Public availability would include records from any level of government or information that the consumer has themself made public. (So keep an eye on those social media privacy settings.)

Sensitive Personal Information

As is common to other privacy laws, the Colorado Privacy Act also specifies “sensitive data” that requires specific consent and handling. It includes data that could reveal:

  • Racial or ethnic origin
  • Religious beliefs
  • Mental or physical health condition or diagnosis
  • Sex life or sexual orientation
  • Citizenship or citizenship status
  • Genetic or biometric data that may be processed for the purpose of uniquely identifying an individual
  • A known child

The Colorado Privacy Act, like the other state-level laws adopted in the U.S. to date, uses an opt-out model, which means that in most cases data controllers do not need to get consumers’ consent before collecting their personal information. The exception to this is if it’s sensitive personal information that is being collected, if the data is to be processed for purposes other than the ones previously specified (and potentially consented to), aka “secondary use”, or if the data is that of a known child (in which case parental or guardian consent is required).

Colorado was also the first state to require businesses to honor a browser-based universal opt-out signal. Since July 1, 2024, controllers must recognize Global Privacy Control (GPC) as an approved mechanism for consumers to exercise their opt-out rights automatically, without needing to submit a separate request to each business.

Other privacy laws, like the European Union’s General Data Protection Regulation (GDPR), use an opt-in model, where consent must be obtained before personal data can be collected at all. In the United States, there are indications that newer privacy legislation is starting to favor a hybrid model that specifies more granularly when and for what consumer consent must be obtained and when/how it can be rescinded.

Are you staying ahead of CPA changes?

Usercentrics CMP automates updates, so you stay ahead of your privacy compliance requirements as the law changes. Try it free for 14 days.

Who Has to Comply with the Colorado Privacy Act?

In addition to doing business in Colorado and/or processing the data of Colorado residents, the Colorado Privacy Act applies to businesses that:

  • Process personal data of 100,000 or more residents annually, or
  • Process personal data from at least 25,000 residents annually and derive revenue or receive a discount on goods/services as the result of the sale of that data

These stipulations are similar to those in the CCPA and Virginia’s Consumer Data Protection Act (CDPA), which make compliance easier on smaller businesses.

Conducting business in Colorado does not imply that a company has a physical presence or is headquartered in the state. Companies meeting the requirements and doing business via website or app are also required to comply.

Exemptions to Colorado Privacy Act Compliance Requirements

Not all companies are required to comply with the Colorado Privacy Act. As noted, businesses that don’t meet the number of residents whose data is processed annually, or the revenue threshold, are exempt. Additionally, these types of organizations are also exempt:

There is, unsurprisingly, some consternation among privacy professionals over the extensive number of exemptions, especially among commercial entities. Also, in a departure from other states’ laws, the Colorado Privacy Act will apply to charitable organizations and nonprofits that meet the aforementioned thresholds.

Companies’ Obligations Under the Colorado Privacy Act

On the other side of the scale from consumers’ rights under the CPA, businesses have responsibilities regarding collecting and use of data.

CPA Obligations

CPA Obligations
Duty of transparency

Must provide a “reasonably accessible, clear, and meaningful privacy notice.”

Duty of purpose specification

What data is being collected and for what specific purposes.

Duty of data minimization

Adequate, relevant, and limited to what is reasonably necessary to fulfill the communicated purpose

Duty to avoid secondary use

Wo not process personal data for purposes that are not reasonable or necessary to the communicated purpose.

Duty of care

Reasonable measures to secure data from unauthorized access must be taken for storage and use.

Duty to avoid unlawful discrimination

Do not process personal data in violation of state or federal laws prohibiting unlawful discrimination against consumers.

Duty regarding sensitive data

Do not process consumers’ sensitive data without obtaining explicit and informed consent, or, in the case of a known child, without obtaining consent from the parent or guardian.

Transparency Requirements for Privacy Notices

Further to the duty of transparency, the privacy notice must include:

  • Categories of personal data collected or processed by the controller or processor
  • Purposes for which the categories of data are processed
  • Categories of personal data that the controller shares with third parties, if any
  • Categories of third parties with which the controller shares personal data, if any
  • Clear and conspicuous disclosure of the sale or processing of personal data if the controller sells it to third parties or processes it for targeted advertising, as well as how consumers can exercise their right to opt out of sale or processing
  • How and where consumers can exercise their rights under the Act, including contact information for the controller and information about appealing a controller’s action with regards to consumer requests (though consumers cannot be required to create a new account to make or appeal the response to a request)

Entities are also required to conduct and document data protection assessments that have a “heightened risk of harm” before engaging in that data processing.

Companies do have to respond to consumer requests within 45 days, with some exceptions and with the possibility of extending that in some cases. They must also explain the reason for the need for an extension, or the reason for denial of fulfilling a request.

Common reasons that a company might deny a request would be if the consumer is mistaken and the company does not have any data about them, or if the consumer cannot be reasonably authenticated for security before revealing the personal information. It is also generally considered reasonable to deny an excessive number of requests that are received in a short period of time, especially if the data is not a type that changes frequently.

2024–2026 Amendments to the Colorado Privacy Act

The CPA has been amended repeatedly since 2023, and several of these changes are now in force. Businesses should be compliant with all of the following:”

  • Biometric data (effective July 1, 2025, under HB 24-1130): controllers, including employers, must provide advance notice before collecting biometric data. This can be folded into a general privacy notice. New retention, deletion, and “consent refresh” rules apply for employer use of biometric data.
  • Minors under 18: controllers must obtain prior consent before processing personal data belonging to a consumer they know or willfully ignore is under 18.
  • Age-appropriate protections (effective October 1, 2025, under SB 24-041): additional safeguards apply specifically for consumers aged 13 to 17, building on the general minors’ consent rule above.
  • Precise geolocation (effective under SB 25-276, signed May 2025): geolocation data is now classified as sensitive data, requiring opt-in consent before processing.
  • Attorney General contact methods: new channels exist for businesses seeking compliance guidance from the Colorado AG. Submitting a data protection assessment or seeking an opinion letter does not waive attorney-client privilege, and assessments submitted to the AG are exempt from public inspection under the Colorado Open Records Act.
  • Implementing rules: the Colorado Department of Law’s rule amendments clarifying the geolocation and minors’ provisions above took effect July 1, 2026.

Colorado Privacy Act Enforcement and Penalties

The Colorado Attorney General’s Office will enforce the Colorado Privacy Act. If a CPA violation is alleged and appears reasonable or provable, the Attorney General’s office will send a notice to the organization in question with an option to correct the problem.

Businesses previously had 60 days to cure a violation before enforcement, which was double the period allowed under the CCPA and CDPA. That mandatory cure period sunset on January 1, 2025, however, so the Attorney General and district attorneys can now pursue enforcement without first offering a chance to correct the issue. There was still a 60-day cure notice for violations involving minors’ data, but that sunset December 31, 2026.

Interestingly, the CPA does not specify fines for violations. A Colorado Privacy Act violation is considered to be a deceptive trade practice. Penalties for that are governed by the Colorado Consumer Protection Act (confusingly, also CCPA), and can be from USD 2,000 to USD 20,000 per violation, or between USD 10,000 to USD 50,000 per violation against an elderly person. That Act also used to have a cap for damages of USD 500,000 for a series of violations, but that was removed in 2019.

As a result of Consumer Protection Act oversight, Colorado Privacy Act violations can also lead to criminal charges. Criminal penalties are not common in privacy law internationally, but are not unheard of. Violations of South Africa’s Protection of Personal Information Act (POPIA) can result in prison sentences of up to 10 years in some instances.

What Does the Colorado Privacy Act Mean for Websites?

The CPA has been in effect since July 1, 2023, so any organization meeting the applicability thresholds needs to already be compliant. Entities already compliant with the CCPA/CPRA, CDPA, or GDPR will typically have covered most of the same ground, but Colorado’s more recent additions, including GPC recognition, geolocation as sensitive data, and minors’ protections, may call for a fresh review even for otherwise-compliant programs.

That said, regular data audits, risk assessments and reviews of privacy policies and operations are highly recommended, as is consulting with qualified legal counsel, and appointing a data protection officer, where possible.

Companies also need to make it reasonably easy for consumers to contact them, and to be able to respond to and comply with consumer requests in a timely manner. Such requests could be resource-intensive and time-consuming to smaller organizations, especially if not automated, and if the companies’ data is stored in multiple locations.

Companies engaging in digital marketing, ecommerce and other online activities should look into a consent management platform for their web and app properties to support the collection of consumers’ consents where required, as well as storing them securely, and in case of an audit or allegation of privacy violation.

In practice, this means configuring a consent management platform to recognize GPC signals automatically, keep records of consent choices, and route opt-out requests without manual intervention.

Ongoing Support for the CPA

The CPA is acknowledged to be a work in progress, and will likely change and evolve over time. Its contents are not a significant departure from California’s and Virginia’s laws, so prior compliance with other state-level or international privacy law will have done most of the heavy lifting for CPA compliance. As always, we recommend consulting qualified legal counsel for companies’ specific data privacy compliance needs.

Do you know what your site is tracking?

Usercentrics’ free compliance scanner can help identify gaps in your current cookie and consent setup. See what cookies and trackers are active on your site and get your customized compliance report in minutes.

William Newmark
Senior Legal Counsel, Usercentrics
Stay in the loop

Join our growing community of data privacy enthusiasts now. Subscribe to the Usercentrics newsletter and get the latest updates right in your inbox.