US Privacy Law Colorado, USA

Colorado Privacy Act (CPA): Requirements and Enforcement

The Colorado Privacy Act explained: applicability, consumer rights, universal opt-out mandate, data protection assessments, and AG enforcement with $20,000 penalties.

Regulation

Colorado Privacy Act (SB 21-190), C.R.S. 6-1-1301 et seq., effective July 1, 2023

Max Penalty

Up to $20,000 per violation (Colorado Consumer Protection Act penalties)

Enforcing Authority

Colorado Attorney General and district attorneys

Official Source

coag.gov

Executive Summary

  • The CPA (effective July 1, 2023) applies to controllers doing business in Colorado that process personal data of 100,000+ consumers annually, or 25,000+ if they derive revenue or discounts from selling personal data, with no revenue floor.
  • Consumers get access, correction, deletion, portability, and opt-outs of targeted advertising, sale, and consequential profiling; sensitive data requires prior opt-in consent.
  • Colorado wrote the most detailed rulebook outside California: AG regulations covering consent, dark patterns (choice symmetry), data protection assessments, profiling, and biometric amendments effective 2025.
  • It was the first state to mandate universal opt-out mechanisms: since July 1, 2024, controllers must honor signals on the AG's recognized list, which includes GPC.
  • Penalties run through the Colorado Consumer Protection Act at up to $20,000 per violation, the highest per-violation ceiling among state privacy laws, and the 60-day cure period expired January 1, 2025.

Colorado runs the most regulator-shaped privacy law outside California: a Virginia-style statute upgraded by an Attorney General who wrote GDPR-grade rules and got the nation’s first universal opt-out mandate operating. The combination, opt-in consent for sensitive data, recognized UOOM signals, demandable risk assessments, and $20,000-per-violation penalties with no cure period since 2025, makes the CPA the compliance ceiling among the Virginia-lineage states: satisfy Colorado and most of the pack follows.

LawColorado Privacy Act, C.R.S. 6-1-1301 et seq.
EffectiveJuly 1, 2023 (UOOM mandate July 1, 2024; cure period ended Jan 1, 2025)
Max penalty$20,000 per violation (Colorado Consumer Protection Act)
RegulatorColorado AG
StatuteC.R.S. 6-1-1301 et seq.

The Colorado-specific work

Consent that meets the rules. Colorado’s regulations define valid consent and ban dark patterns with a symmetry principle (equal prominence for accept and decline). Consent obtained before the rules took effect for now-consent-requiring processing needed refreshing. Sensitive-data inference from browsing (health conditions, religion) counts, gate it or stop it.

UOOM plumbing. The recognized-signal list is published by the AG; honoring GPC is mandatory, and the signal must suppress both sale and targeted advertising. Implementation mirrors California’s, one consent state gating tags, server-side containers, and platform flags.

Assessments the AG can read. Colorado’s data protection assessment rules are the most detailed of any state; they double as your California risk assessments with modest supplementation. Version them and be ready for a 30-day production demand.

Biometrics from 2025. HB 24-1130 grafts BIPA-adjacent duties into the CPA: written consent for biometric identifiers, retention schedules, breach obligations, and strict employer limits, without a private right of action, but with the AG’s $20,000 hammer. Companies with Illinois BIPA programs can extend them.

Profiling opt-outs. Consumers can opt out of profiling in furtherance of decisions producing legal or similarly significant effects, and the rules add transparency duties about the logic involved, an early ADMT regime converging with automated decision-making rules elsewhere.

Colorado sits in the middle of the state comparison matrix in scope but at the top in enforcement machinery. Check the observable half of your Colorado exposure, trackers, targeted-ad flows, and signal handling, with a free scan.

Frequently Asked Questions

Who has to comply with the CPA?

Controllers that conduct business in Colorado or target Colorado residents and, during a calendar year, control or process personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving revenue or discounts from selling personal data. There is no revenue threshold, so high-traffic, low-revenue businesses are covered. Exemptions are mostly data-level (GLBA, HIPAA-regulated data) rather than entity-level, and employment/B2B data is out of scope (unlike California).

What makes Colorado's sensitive-data rule strict?

Processing sensitive data, racial or ethnic origin, religious beliefs, health condition or diagnosis, sex life or sexual orientation, citizenship status, genetic or biometric data, and data from a known child, requires prior opt-in consent meeting the rules' GDPR-style validity standard: freely given, specific, informed, unambiguous, and dark-pattern-free. The 2024 biometric amendments (HB 24-1130) added standalone duties for biometric identifiers, including employer limits, effective July 2025.

What is the universal opt-out obligation?

Since July 1, 2024, controllers processing for targeted advertising or sale must honor opt-out signals on the Colorado AG's public recognized-mechanism list; Global Privacy Control was the first approved entry. The signal counts as a valid consumer request: suppress the relevant processing, without requiring a Colorado-specific confirmation step. Authenticated consent can override a signal if logged and revocable.

When are data protection assessments required?

Before processing that presents a heightened risk of harm: targeted advertising, sale, sensitive-data processing, and profiling with foreseeable risks of unfair treatment or injury. The rules prescribe content in detail (purposes, benefits, risks, mitigations, stakeholder input where relevant), and the AG can demand assessments with 30 days' notice in investigations. GDPR DPIAs can satisfy the duty if they cover the required elements.

How is the CPA enforced and what is the real exposure?

The AG and district attorneys enforce through the Colorado Consumer Protection Act, where each violation carries up to $20,000 in civil penalties (per consumer, per violation in aggregation-friendly readings). The cure period sunset on January 1, 2025, so enforcement can begin without warning. The AG's office has prioritized universal opt-out compliance, sensitive-data consent, and assessment production in its public statements, and has run compliance-letter sweeps since the law took effect.

Regulatory Crosswalk

CCPAVirginia VCDPAConnecticut CTDPAGDPR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.