EnglishEspañol
Colorado flag

Colorado

Colorado Privacy Act Compliance Checklist (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 9 primary sources cited on this page. How we verify our legal content

Colorado Privacy Act Compliance Checklist (2026)

Frequently Asked Questions

Does the Colorado Privacy Act apply to nonprofits?

Yes. Unlike Virginia's VCDPA, Texas's TDPSA, and most other state privacy laws, the CPA does not include a blanket entity-level exemption for nonprofits. A nonprofit that conducts business in Colorado and meets either applicability threshold (100,000 consumers, or 25,000 consumers with any revenue from selling personal data) is a covered controller with the full stack of CPA obligations. SB 24-129 is a separate statute restricting public agencies from collecting or compelling disclosure of nonprofit membership data; it does not amend the CPA or create a nonprofit exemption.

What is Global Privacy Control (GPC) and why does it matter for Colorado compliance?

Global Privacy Control is a browser-level privacy signal that lets users opt out of data sale and targeted advertising across all sites they visit in a single persistent setting. Since July 1, 2024, the Colorado AG has formally recognized GPC as the only qualifying Universal Opt-Out Mechanism under the CPA. Controllers must detect GPC signals automatically and treat them as a valid opt-out of data sale and targeted advertising without requiring the consumer to take any additional step. Controllers must also describe their GPC handling in their privacy policy under 4 CCR 904-3, Rule 6.03(4)(e).

Is there still a cure period under the Colorado Privacy Act?

Not for most violations. The original 60-day cure period sunsetted January 1, 2025. The AG and district attorneys may now bring enforcement actions immediately upon identifying a violation, without first issuing a notice and opportunity to cure. A limited cure provision still applies to the children's data sections added by SB 24-041 (C.R.S. sections 6-1-1305.5, 6-1-1308.5, and 6-1-1309.5), but that child-data cure period is also scheduled to expire December 31, 2026.

When does the CPA require opt-in consent versus opt-out?

Opt-IN affirmative consent is required before processing sensitive data under C.R.S. section 6-1-1308(7). Sensitive data is defined at C.R.S. section 6-1-1303(24) as personal data revealing racial or ethnic origin, religious beliefs, a health condition or diagnosis, sex life or sexual orientation, or citizenship status; genetic or biometric data processed to uniquely identify an individual; personal data from a known child; biological data, including neural data; and precise geolocation data. Opt-OUT rights apply to data sale, targeted advertising, and high-risk profiling. For all other standard processing, neither opt-in nor opt-out consent is required provided processing is consistent with disclosed purposes.

Do data protection assessment requirements apply retroactively under the CPA?

No. C.R.S. section 6-1-1309 requires DPAs only for processing activities created or generated after July 1, 2023. Processing that was fully established before that date is not subject to a retroactive DPA requirement. However, new processing activities, new data-sharing relationships, and materially modified existing operations since that date all require a documented assessment, and the AG can compel production through a civil investigative demand.

What is the maximum penalty for a Colorado Privacy Act violation?

Up to $20,000 per violation under C.R.S. section 6-1-112(1)(a), which governs civil penalties for deceptive trade practices under the Colorado Consumer Protection Act. That cap rises to up to $50,000 per violation under C.R.S. section 6-1-112(1)(c) where the violation was committed against an elderly person, defined as a consumer age 60 or older, with each elderly person involved counted as a separate violation. The AG may also seek injunctive relief and recover investigative costs and attorney fees. There is no private right of action; only the AG and district attorneys can bring enforcement actions.

How is Colorado's second applicability threshold different from Virginia's?

Colorado's second prong covers any controller that derives any revenue or receives any discount from selling personal data AND processes data of 25,000 or more consumers. Virginia requires that more than 50 percent of gross revenue come from data sales to trigger the lower-threshold coverage. Colorado's standard is materially broader: even a small or incidental revenue stream from data sales can trigger CPA coverage for a controller processing 25,000 or more Colorado consumer records.

What biometric-specific obligations does Colorado impose separately from the general CPA?

HB 24-1130, effective July 1, 2025, adds standalone biometric data requirements beyond what the CPA's sensitive-data framework already imposes. Controllers that collect or process biometric identifiers must: adopt and publish a written retention and deletion policy; store, transmit, and protect biometric data using the industry standard of care; and obtain affirmative consent before collecting biometric data. Employers are treated separately under C.R.S. section 6-1-1314(6). An employer may require biometric consent as a condition of employment only for four enumerated purposes: access to secure physical locations and secure hardware and software; recording the commencement and conclusion of the full work day, including meal and rest breaks over thirty minutes; workplace safety or security; and public safety in an emergency or crisis. For any use outside that list, the employer may not require consent as a condition of employment and may not retaliate against a worker who declines.

Updates

Corrected the Colorado Privacy Act statute citations throughout and fixed two substantive errors: the sensitive data definition has five statutory categories (not eight, and the previously listed financial account number category is not in the law), and Colorado does allow an employer to require biometric consent as a condition of employment for four specific purposes, which the page had described as prohibited outright.

Corrected several Colorado Privacy Act compliance details: SB 25-276's precise-geolocation amendment has been in force since May 23, 2025 (it was previously described as a future August 2026 change); added two threshold-free CPA triggers for biometric data and minors' online services; corrected the under-13 parental-consent requirement from a dual child-plus-parent test to the correct parent-or-guardian-consent standard; added the $50,000 enhanced penalty tier for violations against consumers age 60 or older; corrected a mischaracterized citation to SB 24-129; and fixed a statutory pincite for the universal opt-out mechanism mandate.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. C.R.S. sections 6-1-1301 through 6-1-1313 (Colorado Privacy Act), SB21-190(leg.colorado.gov).gov
  2. 4 CCR 904-3 (Colorado Privacy Act Rules, finalized March 15, 2023)(coag.gov).gov
  3. SB 24-041: Privacy Protections for Children's Online Data (effective October 1, 2025)(leg.colorado.gov).gov
  4. HB 24-1130: Privacy of Biometric Identifiers and Data (effective July 1, 2025)(leg.colorado.gov).gov
  5. SB24-129: Nonprofit Member Data Privacy and Public Agencies(leg.colorado.gov).gov
  6. SB 25-276: Precise Geolocation Data Added to CPA Sensitive-Data List (signed May 23, 2025, in force via safety clause)(leg.colorado.gov).gov
  7. Colorado AG Universal Opt-Out Mechanism Registry(coag.gov).gov
  8. Colorado AG CPA Resource Page(coag.gov).gov
  9. Colorado AG FAQ: Data Protection Laws for Businesses(coag.gov).gov
  10. Colorado Revised Statutes Title 6, Part 13 (Colorado Privacy Act), sections 6-1-1301 to 6-1-1314, 2025 edition(olls.info)
  11. Senate Bill 21-190 (enrolled), the Colorado Privacy Act as enacted, including 6-1-1308 duties and 6-1-1309 data protection assessments(content.leg.colorado.gov)
  12. House Bill 24-1130 (enrolled), biometric identifiers and biometric data, codified at C.R.S. 6-1-1314 including the employer consent rule at (6)(content.leg.colorado.gov)
  13. Senate Bill 25-276 (enrolled), amending the C.R.S. 6-1-1303(24) sensitive data definition and the 6-1-1308(7) sensitive data duty(content.leg.colorado.gov)
  14. Colorado Attorney General list of recognized Universal Opt-Out Mechanisms(coag.gov)
  15. Colorado Privacy Act Rules, 4 CCR 904-3, Colorado Department of Law(coag.gov)
Share: