Colorado
Colorado Privacy Act Compliance Checklist (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 9 primary sources cited on this page. How we verify our legal content

Businesses that process the personal data of Colorado residents face one of the most detailed and enforcer-friendly controller-duty stacks in the country under the Colorado Privacy Act (CPA), C.R.S. sections 6-1-1301 through 6-1-1314, and the Attorney General's implementing rules at 4 CCR 904-3. Two features make the CPA genuinely different from most other state privacy laws: nonprofits are NOT broadly exempt, and since July 1, 2024, controllers must automatically honor Global Privacy Control browser signals as valid opt-outs. The 60-day cure period that once softened enforcement sunsetted on January 1, 2025. This nine-step checklist walks every required compliance obligation so you can identify gaps before an enforcement investigation begins.
For a plain-language overview of the Colorado Privacy Act and how it fits the national state-privacy landscape, see the Colorado data privacy law overview.
Step 1: Run the Applicability Self-Test
You are a covered controller under the CPA's general obligations if you conduct business in Colorado or target products or services to Colorado residents AND you meet either of two data-volume thresholds. The first is processing the personal data of at least 100,000 Colorado consumers during a calendar year. The second is processing data of at least 25,000 consumers while also deriving revenue, or receiving any discount on goods or services, from the sale of personal data. C.R.S. section 6-1-1304(1)(a).
Two narrower obligations apply even if you clear neither threshold. Under C.R.S. section 6-1-1304(1)(a)(II), added by HB 24-1130, a controller that processes any amount of biometric identifiers or biometric data owes CPA duties for that biometric data specifically, with no volume floor. Under C.R.S. section 6-1-1304(1)(b), added by SB 24-041, the minors' duty-of-care (6-1-1308.5) and minors' data protection assessment (6-1-1309.5) requirements apply to any controller conducting business in or targeting Colorado that knowingly offers an online service, product, or feature to a minor, again regardless of volume. A small business that fails both general thresholds can still owe these two narrower sets of duties.
The second threshold is significantly broader than Virginia's equivalent prong. Virginia requires that more than 50 percent of gross revenue come from data sales. Colorado requires only that the controller derives any revenue or receives any discount from data sales. A company that earns even a nominal amount from selling data and processes 25,000 or more consumer records is within scope.
"Consumer" under the CPA means a Colorado resident acting in an individual or household capacity. Business-to-business interactions and employer-employee data are not included in the consumer count. "Sale" means exchange of personal data for monetary consideration or other valuable consideration to a third party.
Key questions to ask
- How many unique Colorado residents appear in your systems across all products, services, and website traffic during the calendar year?
- Do you exchange personal data with any third party for money or other valuable consideration? If so, how many consumers does that data cover?
- Do you conduct business in Colorado or offer products or services directed at Colorado residents, even if headquartered elsewhere?
If you cross 100,000 consumer records, or if you sell data at all and cross 25,000 records, continue through this checklist. If neither threshold applies, confirm you also fall outside the threshold-free biometric and minors triggers described above before concluding you have no CPA exposure, then document that conclusion and revisit it annually as your data footprint grows.
Step 2: Check Entity and Data Exemptions, Including the Nonprofit Trap
Even if you clear both thresholds, the CPA exempts certain entities entirely. Entity-level exemptions under C.R.S. section 6-1-1304 include: financial institutions and their affiliates subject to the Gramm-Leach-Bliley Act; air carriers subject to Federal Aviation Administration regulation; national securities associations registered under the Securities Exchange Act; and Colorado state and local governments and state institutions of higher education.
What the CPA does NOT include in its entity-level exemptions is nonprofits. This is one of the most consequential structural differences between the CPA and Virginia's VCDPA, Texas's TDPSA, and several other state privacy laws that blanket-exempt nonprofit organizations. A 501(c)(3), trade association, or advocacy nonprofit that conducts business in Colorado and meets either data threshold is a covered controller under the CPA. SB 24-129, passed in 2024, is a separate statute limiting public agencies from collecting or compelling disclosure of nonprofit membership and donor data; it does not amend the CPA. The no-blanket-nonprofit-exemption conclusion above comes from the CPA's own entity-exemption list at C.R.S. section 6-1-1304, which does not include nonprofits, not from SB 24-129.
The CPA also carves out specific categories of data at the data level, regardless of what entity holds them. These data-category exemptions under C.R.S. section 6-1-1304 include: HIPAA-protected health information; consumer credit data regulated by the Fair Credit Reporting Act; FERPA-protected education records; personal data of children regulated under COPPA; personal data processed in the context of employment; and data covered by the Driver's Privacy Protection Act.
How to apply the dual-check
The entity and data exemptions operate independently. A GLBA-regulated bank is exempt as an entity across the board. A technology company that is not GLBA-covered may still hold some data streams that are exempt at the data level, such as HIPAA-regulated health records processed on behalf of covered entities. But that same company owes full CPA obligations for all non-exempt data it processes.
Work through each data category in your systems: (a) Is our entity exempt? (b) Even if not, is this specific data stream exempt? Apply both questions before treating any data type as CPA-regulated.
Step 3: Post a Compliant Privacy Notice
Controllers must provide consumers with a reasonably accessible, clear, and meaningful privacy notice on all interfaces through which consumers regularly interact, including mobile applications. (1) specifies five required disclosures:
- The categories of personal data collected or processed by the controller or its processors
- The purposes for which each category of personal data is processed
- How and where consumers may exercise their five rights under the CPA, and how to appeal a denial
- The categories of personal data shared with third parties
- The categories of third parties with whom personal data is shared
If you sell personal data or process it for targeted advertising, the notice must also include a clear and conspicuous disclosure of that practice and the mechanism consumers can use to opt out.
Beyond the notice content, imposes seven affirmative duties, each codified in its own subsection: transparency (subsection (1)), purpose specification ((2)), data minimization ((3)), avoiding secondary use that is not reasonably necessary to or compatible with the specified purposes ((4)), care, meaning reasonable security measures ((5)), avoiding processing that violates state or federal anti-discrimination laws ((6)), and the sensitive-data duty barring the processing or sale of sensitive data without consent ((7)). These duties apply regardless of whether a consumer submits a request.
Privacy notice checklist
| Required element | Covered? |
|---|---|
| Categories of personal data collected or processed | |
| Purposes of processing for each category | |
| How to submit a consumer rights request | |
| How to appeal a denied request | |
| Categories of data shared with third parties | |
| Categories of third parties receiving data | |
| Sale or targeted-advertising disclosure (if applicable) | |
| Opt-out mechanism for sale and targeted advertising (if applicable) | |
| Explanation of how UOOM and GPC signals are handled (Rule 6.03(4)(e)) |
The AG's Rules at 4 CCR 904-3 require plain, straightforward language. A layered notice approach is acceptable for complex data practices, but core disclosures must be surfaced in the first layer.

Step 4: Honor the Universal Opt-Out Mechanism and Global Privacy Control
This is the compliance obligation most often overlooked by controllers who have otherwise implemented strong privacy programs. Since July 1, 2024, the CPA requires controllers to recognize and honor approved Universal Opt-Out Mechanisms (UOOMs). C.R.S. section 6-1-1306(1)(a)(IV)(B).
The Colorado Attorney General currently recognizes one UOOM: Global Privacy Control (GPC). GPC is a browser-level privacy signal built into certain browsers and extensions that allows users to express a persistent, site-independent opt-out of data sale and targeted advertising. When a consumer with GPC enabled visits your website or uses your application, you must treat that signal as a valid opt-out request automatically, without requiring the consumer to separately click a "Do Not Sell" link.
Colorado is the only state to impose this UOOM obligation through a formal, AG-maintained public registry. The current list of recognized UOOMs is published at coag.gov/opt-out/. Controllers must monitor the registry, because the AG may recognize additional mechanisms in the future.
Under 4 CCR 904-3, Rule 6.03(4)(e), your privacy policy must include an explanation of how UOOM requests, including GPC signals, will be processed. The AG has made clear that a privacy policy that does not address GPC is deficient even if the underlying technical implementation is in place.
Technical implementation steps
- Implement server-side or client-side detection of the
Sec-GPC: 1HTTP header and thenavigator.globalPrivacyControlJavaScript property. - Map detected GPC signals to your existing opt-out data pipeline for data sale and targeted advertising.
- Confirm that GPC opt-outs persist across sessions and devices where technically feasible.
- Add a paragraph to your privacy policy explaining that you recognize GPC as a valid UOOM and describing how the signal triggers an opt-out.
Step 5: Obtain Opt-In Consent for Sensitive Data
Before processing any sensitive data, the CPA requires affirmative opt-IN consent. "Consent" under C.R.S. section 6-1-1303(5) means a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement to the processing. Pre-ticked boxes, bundled consent buried in terms of service, and inferred agreement from continued use of a service do not satisfy this standard.
Sensitive data is defined in C.R.S. section 6-1-1303(24) as five categories:
- Personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life or sexual orientation, or citizenship or citizenship status
- Genetic or biometric data that may be processed for the purpose of uniquely identifying an individual
- Personal data from a known child
- Biological data, meaning data generated by the technological processing of an individual's biological, genetic, biochemical, physiological, or neural properties and used for identification purposes, which includes neural data
- Precise geolocation data
The precise geolocation category covers data that identifies the specific location of a person within a radius that could reveal a home address or other sensitive location. Any application that collects GPS coordinates, or any analytics platform that processes precise device-location data, likely triggers this requirement.
For children under 13 on online platforms (effective October 1, 2025 under SB 24-041), you must obtain verifiable consent from the child's parent or legal guardian before processing; for minors age 13 to 17, who are not "children" under the CPA, the minor's own consent is sufficient instead. SB 24-041 also requires controllers offering online services to known minors to use reasonable care to avoid heightened risk of harm and to conduct data protection assessments whenever that heightened risk is present.
Sensitive data consent design
A compliant opt-in for sensitive data must be: (a) presented before processing begins, not retroactively; (b) specific to the sensitive data category and its processing purpose; (c) not conditioned on access to the core service to the extent possible; and (d) easily revocable by the consumer. Review all onboarding flows, health questionnaires, account creation screens, and location permission requests against these requirements.
Note also the biometric-specific layer added by HB 24-1130, effective July 1, 2025 and codified at C.R.S. section 6-1-1314. Controllers processing biometric identifiers must adopt and publish a written retention and deletion schedule and store biometric data using the industry standard of care. Employers are governed by a narrower rule. Under C.R.S. section 6-1-1314(6)(a), an employer may require biometric consent as a condition of employment only for four enumerated purposes: permitting access to secure physical locations and secure electronic hardware and software applications; recording the commencement and conclusion of the employee's full work day, including meal and rest breaks in excess of thirty minutes; improving or monitoring workplace safety or security; and improving or monitoring the safety or security of the public in an emergency or crisis situation. For any use outside that list, section 6-1-1314(6)(b) still requires consent but bars the employer from making it a condition of employment or retaliating against a worker who declines.
Step 6: Conduct Data Protection Assessments
Written data protection assessments (DPAs) are mandatory before initiating any processing activity that presents a heightened risk of harm to a consumer. C.R.S. section 6-1-1309(1) states the general bar: no processing that presents a heightened risk of harm, involving personal data acquired on or after July 1, 2023, without a conducted and documented assessment. Subsection (2) then lists three categories of heightened-risk processing:
- Processing personal data for purposes of targeted advertising, or for profiling where the profiling presents a reasonably foreseeable risk of unfair or deceptive treatment or unlawful disparate impact, financial or physical injury, an intrusion upon solitude or seclusion that would be offensive to a reasonable person, or other substantial injury. C.R.S. section 6-1-1309(2)(a)
- Selling personal data. C.R.S. section 6-1-1309(2)(b)
- Processing sensitive data as defined in C.R.S. section 6-1-1303(24). C.R.S. section 6-1-1309(2)(c)
Targeted advertising, data sales, and sensitive-data processing trigger the assessment requirement on their own. Profiling triggers it only where one of the reasonably foreseeable risks listed above is present.
Each DPA must: identify the processing activity; document the benefits that flow from the processing to the controller, consumers, and the public; identify the potential risks to consumer rights and freedoms; describe the safeguards and technical or organizational measures in place to offset those risks; and weigh benefits against residual risks after safeguards are applied, factoring in the use of de-identified data, the reasonable expectations of consumers, the context of the processing, and the relationship between the controller and the consumer. C.R.S. section 6-1-1309(3).
A single assessment may cover a set of comparable processing operations rather than requiring a separate document per campaign or vendor relationship. However, materially new or modified processing activities require a new or updated assessment.
The retroactivity rule
DPA requirements are expressly not retroactive. Under C.R.S. section 6-1-1309(6), they apply only to processing activities created or generated after July 1, 2023. Existing processing operations that predate that cutoff do not require a retroactive assessment, but any new or materially modified processing since that date does. "Materially modified" should be interpreted conservatively: a new data-sharing partner, a new processing purpose for existing data, or a new algorithmic profiling use case all likely require a fresh assessment.
AG demand authority
The Attorney General may request completed assessments through a civil investigative demand. C.R.S. section 6-1-1309(4). Assessments disclosed to the AG are confidential under the Colorado Open Records Act and retain applicable attorney-client privilege or work-product protections. Treat all DPAs as potentially discoverable enforcement documents from the moment they are drafted, and involve legal counsel in their preparation.

Step 7: Execute Processor Contracts
Every vendor, service provider, or other third party that processes personal data on your behalf must be governed by a binding written controller-processor contract before processing begins. C.R.S. section 6-1-1305(2)-(6).
The contract must specify: the instructions for processing personal data; the nature and purpose of processing; the type and categories of personal data subject to processing; and the duration of the processing engagement. Those scope elements define the outer boundary of the processor's authorized activities.
Mandatory contract provisions
Beyond the scope elements, the CPA's processor contract must require the processor to:
- Maintain confidentiality: All personnel who access or handle personal data must be bound by confidentiality obligations.
- Delete or return data: Upon termination or on the controller's request, the processor must delete or return all personal data to the controller.
- Demonstrate compliance: The processor must provide the controller with all information necessary to demonstrate compliance with CPA obligations.
- Cooperate with audits: The processor must submit to and cooperate with audits or independent assessments requested by the controller or the AG.
- Flow down to sub-processors: The processor must bind any sub-processors it engages in a written contract imposing equivalent obligations.
Vendor inventory
Build a complete data-flow inventory before auditing contracts. List every third party that touches personal data you control: cloud infrastructure providers, advertising platforms, analytics vendors, CRM and marketing automation tools, payment processors, HR platforms, and any SaaS application that receives data from your systems. Determine whether each relationship is a processor relationship (the third party acts under your instructions) or a separate controller relationship (the third party determines its own processing purposes). Processor relationships require a CPA-compliant contract. Third-party controller relationships require a different instrument, typically a data-sharing agreement with representations about independent compliance.
Step 8: Build Consumer Rights Response Workflows
Colorado consumers have five rights under the CPA: access, correction, deletion, portability, and opt-out (of data sale, targeted advertising, and certain profiling). C.R.S. section 6-1-1306.
Controllers must respond to authenticated consumer requests within 45 days of receipt. One extension of up to an additional 45 days is available if the consumer is notified within the original 45-day window of the need for more time and the reason for the extension. The controller must provide the information free of charge, except that it may charge for a second or subsequent request within a twelve-month period. C.R.S. section 6-1-1306(2), including (2)(c) on charges.
The appeal requirement
If you deny a consumer request in whole or in part, you must: (a) inform the consumer of the reasons within 45 days, together with instructions for how to appeal; (b) establish an internal appeal process that is conspicuously available and as easy to use as the process for submitting the original request; and (c) inform the consumer of any action taken or not taken on the appeal within 45 days of receipt, with a written explanation of the reasons, extendable by 60 additional days where reasonably necessary. You must also inform the consumer of the consumer's ability to contact the Colorado Attorney General if the consumer has concerns about the result of the appeal. C.R.S. section 6-1-1306(2)(b) and (3).
Record retention
Maintain records of all consumer rights requests, the actions taken or basis for denial, and any appeal resolutions for at least 24 months. These records are the primary evidence that will be examined if the AG opens an investigation. A generic log saying "request received and denied" is insufficient. Document the specific claim raised, the legal basis for any refusal, and the date and substance of any communication sent to the consumer.
For a full overview of Colorado's privacy framework, including how consumer rights fit within the broader CPA structure, see the Colorado data privacy law overview.
Step 9: Understand Enforcement: No Cure Period, No Private Suit, $20,000 to $50,000 Per Violation
The CPA is enforced exclusively by the Colorado Attorney General and district attorneys. There is no private right of action for consumers. C.R.S. section 6-1-1310 states expressly that "THIS PART 13 DOES NOT AUTHORIZE A PRIVATE RIGHT OF ACTION FOR A VIOLATION OF THIS PART 13." No individual, plaintiff's firm, or class action can sue for a CPA violation. C.R.S. section 6-1-1311.
CPA violations are treated as deceptive trade practices under the Colorado Consumer Protection Act. Civil penalties under C.R.S. section 6-1-112(1)(a) are up to $20,000 per violation, rising to up to $50,000 per violation under C.R.S. section 6-1-112(1)(c) where the violation was committed against an elderly person (a consumer age 60 or older), with each elderly person involved counted as a separate violation. The AG may also seek injunctive relief and recover investigative costs including attorney fees.
The cure-period sunset
The original CPA included a 60-day cure period requiring the AG or a district attorney to give a controller written notice of an alleged violation before filing suit. That provision was effective only through January 1, 2025, and it sunsetted on that date. Beginning January 1, 2025, the AG and district attorneys may bring enforcement actions against noncompliant controllers without first issuing a cure notice. There is no grace period, no required warning letter, and no right to cure the violation before penalties accrue.
One limited exception: under SB 24-041's child-data provisions added in C.R.S. sections 6-1-1305.5, 6-1-1308.5, and 6-1-1309.5, a separate 60-day cure notice is still required before enforcement of those specific children's-data sections. That child-data cure provision is itself scheduled to expire on December 31, 2026.
SB 25-276: Precise Geolocation Data Is Now Sensitive Data (Already in Force)
SB 25-276 was signed May 23, 2025 and, under its safety clause, took effect immediately on signature. It is primarily an immigration civil-rights act; its CPA amendments add "precise geolocation data" (location data accurate to within roughly 1,850 feet) as a standalone sensitive-data category and bar a controller from processing or selling a consumer's sensitive data without consent. This is current law now, not an upcoming change. Confirm your sensitive-data consent flows, data protection assessments, and privacy notice already cover precise geolocation collection.
Compliance program elements
- Designate a named internal owner for CPA compliance with documented authority and budget.
- Maintain a compliance calendar: annual applicability threshold review, privacy notice audit, DPA review for new processing activities, UOOM registry check, and processor contract audit.
- Train customer-service, engineering, and marketing staff on the consumer request workflow, the GPC detection requirement, and the sensitive-data consent rules.
- Keep all DPAs, processor contracts, consent records, and consumer request logs in a documented, retrievable system. The AG's civil investigative demand authority means you need to be able to produce these documents on a short timeline.
For the full Colorado data privacy law overview, including how the CPA fits into the broader national state-privacy-law landscape, see the parent page.
Related guides
-
Colorado Data Privacy Laws: CPA Consumer Rights Guide (2026)
-
Colorado Biometric Privacy Laws: Collection, Consent & Penalties (2026)
More Colorado Laws
Frequently Asked Questions
Does the Colorado Privacy Act apply to nonprofits?
Yes. Unlike Virginia's VCDPA, Texas's TDPSA, and most other state privacy laws, the CPA does not include a blanket entity-level exemption for nonprofits. A nonprofit that conducts business in Colorado and meets either applicability threshold (100,000 consumers, or 25,000 consumers with any revenue from selling personal data) is a covered controller with the full stack of CPA obligations. SB 24-129 is a separate statute restricting public agencies from collecting or compelling disclosure of nonprofit membership data; it does not amend the CPA or create a nonprofit exemption.
What is Global Privacy Control (GPC) and why does it matter for Colorado compliance?
Global Privacy Control is a browser-level privacy signal that lets users opt out of data sale and targeted advertising across all sites they visit in a single persistent setting. Since July 1, 2024, the Colorado AG has formally recognized GPC as the only qualifying Universal Opt-Out Mechanism under the CPA. Controllers must detect GPC signals automatically and treat them as a valid opt-out of data sale and targeted advertising without requiring the consumer to take any additional step. Controllers must also describe their GPC handling in their privacy policy under 4 CCR 904-3, Rule 6.03(4)(e).
Is there still a cure period under the Colorado Privacy Act?
Not for most violations. The original 60-day cure period sunsetted January 1, 2025. The AG and district attorneys may now bring enforcement actions immediately upon identifying a violation, without first issuing a notice and opportunity to cure. A limited cure provision still applies to the children's data sections added by SB 24-041 (C.R.S. sections 6-1-1305.5, 6-1-1308.5, and 6-1-1309.5), but that child-data cure period is also scheduled to expire December 31, 2026.
When does the CPA require opt-in consent versus opt-out?
Opt-IN affirmative consent is required before processing sensitive data under C.R.S. section 6-1-1308(7). Sensitive data is defined at C.R.S. section 6-1-1303(24) as personal data revealing racial or ethnic origin, religious beliefs, a health condition or diagnosis, sex life or sexual orientation, or citizenship status; genetic or biometric data processed to uniquely identify an individual; personal data from a known child; biological data, including neural data; and precise geolocation data. Opt-OUT rights apply to data sale, targeted advertising, and high-risk profiling. For all other standard processing, neither opt-in nor opt-out consent is required provided processing is consistent with disclosed purposes.
Do data protection assessment requirements apply retroactively under the CPA?
No. C.R.S. section 6-1-1309 requires DPAs only for processing activities created or generated after July 1, 2023. Processing that was fully established before that date is not subject to a retroactive DPA requirement. However, new processing activities, new data-sharing relationships, and materially modified existing operations since that date all require a documented assessment, and the AG can compel production through a civil investigative demand.
What is the maximum penalty for a Colorado Privacy Act violation?
Up to $20,000 per violation under C.R.S. section 6-1-112(1)(a), which governs civil penalties for deceptive trade practices under the Colorado Consumer Protection Act. That cap rises to up to $50,000 per violation under C.R.S. section 6-1-112(1)(c) where the violation was committed against an elderly person, defined as a consumer age 60 or older, with each elderly person involved counted as a separate violation. The AG may also seek injunctive relief and recover investigative costs and attorney fees. There is no private right of action; only the AG and district attorneys can bring enforcement actions.
How is Colorado's second applicability threshold different from Virginia's?
Colorado's second prong covers any controller that derives any revenue or receives any discount from selling personal data AND processes data of 25,000 or more consumers. Virginia requires that more than 50 percent of gross revenue come from data sales to trigger the lower-threshold coverage. Colorado's standard is materially broader: even a small or incidental revenue stream from data sales can trigger CPA coverage for a controller processing 25,000 or more Colorado consumer records.
What biometric-specific obligations does Colorado impose separately from the general CPA?
HB 24-1130, effective July 1, 2025, adds standalone biometric data requirements beyond what the CPA's sensitive-data framework already imposes. Controllers that collect or process biometric identifiers must: adopt and publish a written retention and deletion policy; store, transmit, and protect biometric data using the industry standard of care; and obtain affirmative consent before collecting biometric data. Employers are treated separately under C.R.S. section 6-1-1314(6). An employer may require biometric consent as a condition of employment only for four enumerated purposes: access to secure physical locations and secure hardware and software; recording the commencement and conclusion of the full work day, including meal and rest breaks over thirty minutes; workplace safety or security; and public safety in an emergency or crisis. For any use outside that list, the employer may not require consent as a condition of employment and may not retaliate against a worker who declines.
Updates
Corrected the Colorado Privacy Act statute citations throughout and fixed two substantive errors: the sensitive data definition has five statutory categories (not eight, and the previously listed financial account number category is not in the law), and Colorado does allow an employer to require biometric consent as a condition of employment for four specific purposes, which the page had described as prohibited outright.
Corrected several Colorado Privacy Act compliance details: SB 25-276's precise-geolocation amendment has been in force since May 23, 2025 (it was previously described as a future August 2026 change); added two threshold-free CPA triggers for biometric data and minors' online services; corrected the under-13 parental-consent requirement from a dual child-plus-parent test to the correct parent-or-guardian-consent standard; added the $50,000 enhanced penalty tier for violations against consumers age 60 or older; corrected a mischaracterized citation to SB 24-129; and fixed a statutory pincite for the universal opt-out mechanism mandate.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Colorado Revised Statutes, Title 6: Consumer and Commercial Affairs
§ 6-1-1308Duties of controllersIn force
(1) Duty of transparency. (a) A controller shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes: (I) The categories of personal data collected or processed by the controller or a processor; (II) The purposes for which the categories of personal data are processed; (III) How and where consumers may exercise the rights pursuant to section 6-1-1306, including the controller's contact information and how a consumer may appeal a controller's action with regard to the consumer's request; (IV) The categories of personal data that the controller shares with third parties, if any; and (V) The categories of third parties, if any, with whom the controller shares personal data. (b) If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose the sale or processing, as well as the manner in which a consumer may exercise the right to opt out of the sale or processing.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at olls.info
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- C.R.S. sections 6-1-1301 through 6-1-1313 (Colorado Privacy Act), SB21-190(leg.colorado.gov).gov
- 4 CCR 904-3 (Colorado Privacy Act Rules, finalized March 15, 2023)(coag.gov).gov
- SB 24-041: Privacy Protections for Children's Online Data (effective October 1, 2025)(leg.colorado.gov).gov
- HB 24-1130: Privacy of Biometric Identifiers and Data (effective July 1, 2025)(leg.colorado.gov).gov
- SB24-129: Nonprofit Member Data Privacy and Public Agencies(leg.colorado.gov).gov
- SB 25-276: Precise Geolocation Data Added to CPA Sensitive-Data List (signed May 23, 2025, in force via safety clause)(leg.colorado.gov).gov
- Colorado AG Universal Opt-Out Mechanism Registry(coag.gov).gov
- Colorado AG CPA Resource Page(coag.gov).gov
- Colorado AG FAQ: Data Protection Laws for Businesses(coag.gov).gov
- Colorado Revised Statutes Title 6, Part 13 (Colorado Privacy Act), sections 6-1-1301 to 6-1-1314, 2025 edition(olls.info)
- Senate Bill 21-190 (enrolled), the Colorado Privacy Act as enacted, including 6-1-1308 duties and 6-1-1309 data protection assessments(content.leg.colorado.gov)
- House Bill 24-1130 (enrolled), biometric identifiers and biometric data, codified at C.R.S. 6-1-1314 including the employer consent rule at (6)(content.leg.colorado.gov)
- Senate Bill 25-276 (enrolled), amending the C.R.S. 6-1-1303(24) sensitive data definition and the 6-1-1308(7) sensitive data duty(content.leg.colorado.gov)
- Colorado Attorney General list of recognized Universal Opt-Out Mechanisms(coag.gov)
- Colorado Privacy Act Rules, 4 CCR 904-3, Colorado Department of Law(coag.gov)