Colorado Privacy Act (CPA)

· About Colorado Privacy Act (CPA)

Key Takeaways

  • The Colorado Privacy Act (CPA) applies to controllers doing business in Colorado or targeting Colorado residents that process data for 100,000 consumers in a year, or that process 25,000 consumers and derive revenue from sale of personal data.[1]
  • The CPA has applied since 1 July 2023, and Colorado’s Attorney General says the law is actively enforced, with rulemaking and amendments continuing through 2026.[1][10]
  • Colorado added heightened protections for minors effective 1 October 2025, including restrictions on targeted advertising, sale, and consequential profiling when a minor’s data is processed.[4][5]
  • Colorado also adopted biometric-data duties effective 1 July 2025, including written policies, retention limits, limits on sale/disclosure, and access rights for biometric data.[4]
  • Colorado’s Department of Law adopted rule amendments effective 1 July 2026, including updated universal opt-out technical requirements and clarifications tied to later statutory amendments.[2][11]
  • Violations are enforced under Colorado consumer protection law; the CPA is subject to Attorney General and district attorney enforcement and can carry significant civil penalties under Colorado’s general enforcement framework.[1][10]

What It Is

The Colorado Privacy Act is Colorado’s comprehensive consumer privacy law governing controllers’ collection, use, disclosure, sale, and profiling of personal data belonging to Colorado residents.[1] It is enforced by the Colorado Attorney General and district attorneys, with interpretive rules issued by the Colorado Department of Law.[1][11]

The CPA was enacted by SB21-190 and took effect on 1 July 2023.[8][15] Colorado then added major follow-on obligations through amendments covering biometric data in HB 24-1130 and minors’ online data in SB 24-041.[4][5]

Key phase-in milestones now relevant for compliance include 1 July 2025 for biometric-data duties, 1 October 2025 for minors’ protections, and 1 July 2026 for the latest rule amendments.[4][5][2] Colorado’s public enforcement materials reflect the law as currently operative rather than a deferred or paused regime.[1][10]

Who Must Comply

The CPA applies to a controller that conducts business in Colorado or targets Colorado residents and either processes personal data of at least 100,000 Colorado consumers in a calendar year, or derives revenue or receives a discount from the sale of personal data and processes or controls personal data of at least 25,000 Colorado consumers.[1]

The law has extraterritorial reach because it applies to businesses outside Colorado if they target Colorado residents and meet the statutory thresholds.[1] This makes it a practical compliance obligation for many U.S. and non-U.S. digital businesses, especially adtech, SaaS, consumer apps, and platforms with Colorado users.

Exemptions remain important. The CPA contains entity-level and data-level exemptions typical of U.S. state privacy laws, including certain regulated-sector and data-type carveouts, but the exact scope depends on the activity and the record set at issue.[1] For regulated organizations, the CPA often still applies to non-exempt processing even where some data or operations are carved out.

Core Requirements

  1. Notice and transparency — Controllers must provide a privacy notice describing the categories of personal data processed, purposes, categories of third parties, consumer rights, and how to exercise them.[1]
  1. Consumer rights operations — Controllers must honor rights requests for access, correction, deletion, portability, and objection to processing, and they must provide a mechanism to appeal denied requests.[1]
  1. Universal opt-out support — Controllers must recognize universal opt-out mechanisms for targeted advertising, sale of personal data, and certain profiling, consistent with Colorado’s rules and technical specifications.[2][11]
  1. Sensitive-data consent — Controllers need consent before processing sensitive data, with heightened treatment for minors’ data, biometric data, and precise geolocation under the later amendments.[1][4][5]
  1. Purpose limitation and minimization — Controllers must limit collection to what is adequate, relevant, and reasonably necessary in relation to the disclosed purposes.[1]
  1. Data protection assessments — Controllers must conduct and document assessments for high-risk processing, including targeted advertising, sale, profiling, sensitive data processing, and certain other activities.[1]
  1. Contracting with processors — Controllers must use written agreements with processors that include required processing instructions, confidentiality, deletion/return, audit, and assistance terms.[1]
  1. Children’s and biometric safeguards — For minors and biometric data, controllers must implement the additional safeguards added by Colorado’s later amendments, including restrictions on targeted advertising, sale, profiling, retention, and disclosure.[4][5]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | CPA effective date | 1 July 2023 | Core consumer privacy rights, controller duties, enforcement framework.[8][15] | | Biometric-data amendments | 1 July 2025 | Written policies, retention limits, access rights, and other biometric obligations.[4] | | Minor-protection amendments | 1 October 2025 | Enhanced protections for minors, including opt-in/processing restrictions.[4][5] | | Latest rule amendments | 1 July 2026 | Updated Colorado Department of Law rules, including opt-out technical updates.[2][11] |

Colorado enforces the CPA through the Attorney General and district attorneys under the state’s consumer protection enforcement structure.[1][10] The CPA does not create a private right of action, but violations can still lead to injunctions and civil penalties through public enforcement.[1][10]

Maximum penalties are governed by Colorado’s general civil-penalty framework for consumer protection enforcement, which can be substantial per violation and may increase with repeated or continuing conduct.[10] In practice, the largest exposure often comes from the volume of affected consumers, the persistence of noncompliance, and the parallel risk of injunctive relief and mandated remediation.[10]

How to Comply

  1. Map applicability and data flows — Identify whether Colorado thresholds are met, including consumer counts, sale-related revenue, targeted advertising, and whether minors’ or biometric data is processed.[1][4]
  1. Build a data inventory and processing register — Align records of processing with purpose limitation, retention, disclosure, and transfer mapping; ISO 27001 is a strong fit for control ownership and asset management.
  1. Operationalize rights handling — Create workflows for access, correction, deletion, portability, objection, appeals, and universal opt-out signals; NIST CSF 2.0 helps structure governance, identify, protect, detect, respond, and recover functions.
  1. Review consent and notice mechanics — Rewrite privacy notices and consent flows for sensitive data, minors’ data, biometric data, and precise geolocation; ensure consent is specific and auditable.
  1. Assess high-risk processing — Maintain data protection assessments for targeted advertising, sale, profiling, and sensitive-data uses, and refresh them when the processing changes.
  1. Harden vendor contracting — Update controller-processor agreements for mandatory instructions, deletion/return, assistance, confidentiality, and audit support.
  1. Implement technical opt-out support — Confirm recognition of Colorado universal opt-out mechanisms and test interoperability with browsers or devices sending those signals.
  1. Run an AI governance overlay — Where profiling, automated decisioning, or model training affects Colorado residents, use ISO 42001 to formalize AI risk controls, accountability, and lifecycle governance.

Related Regulations

The California Consumer Privacy Act / CPRA overlaps heavily on consumer rights, sensitive data, and opt-out concepts, but California’s regime differs on definitions, enforcement, and the treatment of certain automated decision-making rules.

The Connecticut Data Privacy Act is similar in structure and is useful as a comparator for cross-state privacy programs, though Colorado’s universal opt-out and minors’/biometric amendments are distinctive.

The EU GDPR conflicts mainly on transfer and lawful-basis architecture: Colorado uses a U.S.-state consumer-rights model, while GDPR uses controller- and processor-level lawful grounds and broader cross-border transfer rules.

The Virginia Consumer Data Protection Act is another overlapping state law with similar controller obligations, but its opt-out and assessment architecture are not identical to Colorado’s, so a single U.S. privacy program still needs state-specific tuning.

FAQ

Does the Colorado Privacy Act apply to companies outside Colorado?

Yes, if the company conducts business in Colorado or targets Colorado residents and meets the statutory processing thresholds.[1] Physical presence in Colorado is not required. This makes the CPA relevant to national and global digital services with Colorado users.[1]

Does the CPA require opt-in consent for all advertising?

No. The CPA generally requires an opt-out for targeted advertising, sale of personal data, and certain profiling, but later amendments add stricter consent rules for minors’ data and certain sensitive-data processing.[1][4][5] A company must distinguish ordinary adtech from processing that involves minors, biometric data, or other sensitive categories.[4][5]

Does the CPA cover AI profiling and automated decisions?

Yes, when profiling or other automated processing is used in ways covered by the law, especially where it relates to targeted advertising, sales, or consumer rights.[1] Colorado’s requirements do not mirror the EU AI Act, but they do create privacy obligations for automated processing that affects consumers.[1]

Is there still a cure period under the CPA?

No active cure period should be assumed for ongoing compliance planning in 2026. Colorado’s enforcement posture has shifted to active enforcement, so remediation must be built into ordinary operations rather than relied on as a safe harbor.[10]

What changed in 2025 and 2026?

Colorado added biometric-data obligations effective 1 July 2025, minors’ protections effective 1 October 2025, and updated Department of Law rules effective 1 July 2026.[4][5][2] These changes materially increased the number of companies that need consent, stronger notices, and more detailed data governance.

Sources

Put it into practice

More compliance guides