Colorado
What Is the Colorado Privacy Act (CPA)?
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. How we verify our legal content

The Colorado Privacy Act (CPA), codified at through 6-1-1314, took effect on July 1, 2023, making Colorado the third state in the nation to enact a comprehensive consumer data privacy law. What sets it apart is not just the statute itself but the detailed implementing rules (4 CCR 904-3) the Attorney General adopted alongside it, including a first-in-the-nation requirement that covered businesses honor the Global Privacy Control browser signal as a legally recognized opt-out.
As of 2026, the Colorado Attorney General actively enforces the CPA. The general mandatory 60-day cure period that shielded businesses from immediate enforcement sunsetted on January 1, 2025, meaning the AG and district attorneys can now bring most enforcement actions without first issuing a cure notice. A separate 60-day cure notice requirement still applies to enforcement of the CPA's minors' data provisions through December 31, 2026.
What the Colorado Privacy Act is: statute, enactment, and background
The Colorado Privacy Act is Colorado's comprehensive consumer data privacy statute, codified at through 6-1-1314 as Part 13 of the Colorado Consumer Protection Act (Title 6, Article 1). Governor Jared Polis signed Senate Bill 21-190 on July 7, 2021, giving businesses nearly two years to prepare before the law took effect on July 1, 2023. That made Colorado the third state, after California and Virginia, to enact a broad consumer data privacy regime.
The CPA governs how covered businesses must collect, use, share, and safeguard the personal data of Colorado residents. Like Virginia's VCDPA, its architecture borrows significantly from the EU's General Data Protection Regulation (GDPR): it uses a controller-processor framework, mandates data protection assessments for high-risk processing activities, and requires affirmative opt-in consent for sensitive data rather than a mere opt-out mechanism. Unlike Virginia, however, Colorado went further by directing the Attorney General to promulgate detailed implementing rules, and those rules in turn established a public list of recognized Universal Opt-Out Mechanisms (UOOMs) that businesses must honor.
The companion regulations, the Colorado Privacy Act Rules (4 CCR 904-3), took effect on July 1, 2023, concurrent with the statute. The AG filed those final rules on March 15, 2023, making Colorado one of a small number of states where implementing regulations and the privacy statute launched together. Those rules add specificity to consent standards, data protection assessment content requirements, and the UOOM framework that the statute alone does not provide.
For the full compliance framework covering controller obligations, processor contracts, privacy notice requirements, and enforcement history, see the Colorado data privacy laws parent page.
Who the Colorado Privacy Act covers: thresholds, exemptions, and the nonprofit distinction
The CPA reaches any person, including corporations, individuals, and nonprofit organizations, that conducts business in Colorado or produces or delivers commercial products or services intentionally targeted to Colorado residents, and that meets either of two thresholds set out in C.R.S. § 6-1-1304(1).
The first threshold: the business controls or processes personal data of 100,000 or more Colorado consumers per calendar year. The second threshold: the business derives revenue or receives a discount on the price of goods or services from selling personal data and controls or processes the personal data of 25,000 or more consumers. That second prong contains a critical distinction from Virginia's VCDPA: Colorado requires only that a business derive any revenue from selling personal data, not that data sales represent more than 50% of gross revenue. A company that earns a small fraction of its income from data sales while processing 25,000 Colorado consumers' data is covered in Colorado but may not be covered in Virginia.
The CPA also covers nonprofit organizations that meet those thresholds, which is another meaningful contrast to Virginia and Texas. Both the VCDPA and the Texas Data Privacy and Security Act (TDPSA) exempt nonprofits entirely. Colorado does not.
Two 2024 amendments added coverage paths that do not depend on the consumer-count or revenue thresholds at all. Since July 1, 2025, a controller that processes any amount of biometric identifiers or biometric data is covered for that data, regardless of volume, under HB 24-1130. Since October 1, 2025, the CPA's minors' data provisions (C.R.S. §§ 6-1-1305.5, 6-1-1308.5, and 6-1-1309.5) apply to any controller that does business in or targets Colorado residents, with no consumer-count or revenue threshold at all, under SB 24-041.
Several categories of entities and data are exempt under C.R.S. § 6-1-1304(2) through (4):
- State and local government bodies
- Personal data used for purely noncommercial purposes by state institutions of higher education
- HIPAA-covered entities and business associates, for HIPAA-regulated data
- Financial institutions and data governed by the Gramm-Leach-Bliley Act (GLBA)
- Air carriers under federal aviation law
- Data regulated by the Fair Credit Reporting Act (FCRA), the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), and the Driver's Privacy Protection Act (DPPA)
These exemptions mean that health systems processing HIPAA-regulated data, banks and credit unions regulated by GLBA, and state universities operating for educational purposes are largely outside the CPA's reach even when they handle large volumes of resident data.
The five Colorado consumer rights under the CPA
The CPA grants Colorado residents five enumerated rights against covered controllers under (1):
- Right to access. A consumer may confirm whether a controller is processing their personal data and request a copy of that data in a readily usable format.
- Right to correct. A consumer may require a controller to correct inaccurate personal data, taking into account the nature and purposes of the processing.
- Right to delete. A consumer may request deletion of personal data the controller holds about them, whether the consumer provided it or the controller collected it from other sources.
- Right to portability. A consumer may obtain their personal data in a portable, readily usable format that allows transfer to another controller, provided the request is technically feasible.
- Right to opt out. A consumer may opt out of processing for three specific purposes: targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects on the consumer.
Controllers must respond to authenticated rights requests within 45 days of receipt. Under (2)(a), the response period may be extended once by an additional 45 days when reasonably necessary, but only if the controller notifies the consumer within the initial 45-day window and explains the reasons for the delay. The maximum response window is therefore 90 days with proper notice.
Controllers that deny a rights request must inform the consumer of the denial and explain how the consumer can appeal. C.R.S. § 6-1-1306(3)(a) requires the controller to establish an internal appeal process that is conspicuously available and as easy to use as the process for submitting the original request. Under § 6-1-1306(3)(b), the controller must tell the consumer what action it took on the appeal within 45 days, a period it may extend by 60 additional days where reasonably necessary. If the appeal is denied, § 6-1-1306(3)(c) requires the controller to inform the consumer of the consumer's ability to contact the Attorney General.
For a detailed walkthrough of how to submit requests and what businesses are required to do for each, see the Colorado consumer rights under the CPA spoke.

Sensitive data and the opt-in consent requirement
One of the CPA's defining features is its requirement that controllers obtain affirmative opt-in consent before processing any sensitive personal data. This is not a default-on setting with a way to opt out later: consent must be obtained before processing begins. Controllers that process sensitive data without prior consent are in violation of C.R.S. § 6-1-1308(7).
The CPA's current definition of sensitive data in C.R.S. § 6-1-1303 covers:
- Personal data revealing racial or ethnic origin
- Personal data revealing religious beliefs
- Mental or physical health condition or diagnosis
- Sex life or sexual orientation
- Citizenship or immigration status
- Genetic or biometric data processed to uniquely identify an individual
- Biological data, including neural data
- Personal data collected from a known child
- Precise geolocation data, since May 23, 2025 (added by SB 25-276)
Since May 23, 2025, when SB 25-276 took effect, precise geolocation data has also been classified as sensitive data under the CPA. SB 25-276, signed by Governor Polis on May 23, 2025, amended the definition of sensitive data in C.R.S. § 6-1-1303 to add precise location data, meaning that any controller who processes precise geolocation data must have obtained opt-in consent from Colorado consumers before processing it. Businesses that rely on location-based services or track device locations must now treat precise geolocation as sensitive data requiring opt-in consent.
The opt-in standard for sensitive data aligns Colorado more closely with GDPR Article 9's explicit-consent requirement for special-category data than with California's approach. The CCPA/CPRA uses an opt-out model for sensitive personal information: businesses may process it unless the consumer requests a limitation. Colorado flips that default: no processing until the consumer says yes.
Colorado's AG Rules (4 CCR 904-3) and the Universal Opt-Out Mechanism
Colorado stands apart from most U.S. state privacy laws for the specificity of its implementing regulations. The Attorney General filed the final Colorado Privacy Act Rules (4 CCR 904-3) on March 15, 2023, and they took effect on July 1, 2023, alongside the statute. While many states have enacted data privacy laws without detailed agency rules, Colorado's rules cover consent standards (4 CCR 904-3-7.02), data protection assessment content requirements (4 CCR 904-3-8.02 through 8.05), controller obligations for processing transparency, and the entire Universal Opt-Out Mechanism framework (4 CCR 904-3-5.03).
The UOOM framework is Colorado's most distinctive operational requirement. C.R.S. § 6-1-1313(2) required the Attorney General, by July 1, 2023, to adopt rules detailing the technical specifications for one or more universal opt-out mechanisms, which are browser or device signals that covered controllers must honor as a consumer's opt-out of targeted advertising and data sales. The public list itself comes from those rules rather than the statute: CPA Rule 5.07 (4 CCR 904-3) provides that the Department of Law maintains a public list of Universal Opt-Out Mechanisms that have been recognized, with the initial list due no later than January 1, 2024, and updated periodically.
The Global Privacy Control (GPC) is the first and currently the only mechanism the Colorado AG has recognized as a valid UOOM. The AG published the recognition of GPC on its Universal Opt-Out Mechanisms page. Beginning July 1, 2024, covered controllers have been required to honor GPC signals from Colorado consumers as valid opt-outs of targeted advertising and the sale of personal data. This is not aspirational: it is a current compliance obligation. A Colorado consumer who has GPC enabled in their browser does not need to navigate a website's privacy settings or submit a separate opt-out request. The signal is legally sufficient on its own.
The practical implication is significant. Businesses that run behavioral advertising programs or sell data to third-party data brokers must detect and honor GPC signals at the browser level, not just through a dedicated opt-out form on a privacy preference page. The 4 CCR 904-3 rules specify how a UOOM must be technically implemented, what disclosures controllers must provide when they recognize a UOOM, and what records must be kept.
Data protection assessments: when and why controllers must conduct them
The CPA requires covered controllers to complete a data protection assessment before beginning any processing activity that presents a heightened risk of harm to a consumer. C.R.S. § 6-1-1309 identifies four categories of processing that require an assessment:
- Processing personal data for targeted advertising
- Selling personal data
- Processing personal data for profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment, unlawful disparate impact, financial, physical, or reputational injury, intrusion on solitude, or other substantial injury to consumers
- Processing sensitive data
Controllers must document each assessment. The 4 CCR 904-3 rules (specifically Rules 8.02 through 8.05) specify thirteen minimum components that assessments must include: the categories of personal data processed, the purpose of the processing, the controller's legitimate interest in the processing, the categories of third parties who may receive the data, the expected benefits to the controller and consumers, the risks to consumer rights and interests, and the safeguards the controller will implement to mitigate those risks, among others. Colorado's requirements are more detailed than most comparable state laws.
The Attorney General may request to review data protection assessments during an investigation. A thorough, well-maintained assessment is not just a compliance checkbox: it is a primary line of defense if the AG begins examining a controller's practices. A controller that cannot produce a credible assessment for a covered processing activity has no effective response to an enforcement inquiry.

CPA enforcement: AG and district attorneys, up to $20,000 per violation, cure period sunset
The CPA is enforced exclusively by the Colorado Attorney General and district attorneys. There is no private right of action for consumers: an individual Colorado resident cannot sue a covered business directly for CPA violations, no matter how clear the breach of their rights. All enforcement authority runs through the AG's office and the state's district attorneys.
Violations of the CPA are classified as deceptive trade practices under the Colorado Consumer Protection Act (C.R.S. § 6-1-105). That classification carries civil penalties of up to $20,000 per violation under C.R.S. § 6-1-112(1)(a), rising to up to $50,000 per violation when the violation is committed against an elderly person, defined as a Colorado consumer age 60 or older, under C.R.S. § 6-1-112(1)(c) and § 6-1-102(4.4). That per-violation ceiling is notably higher than Virginia's VCDPA ($7,500 per violation) or Texas's TDPSA ($7,500 per violation, up to $25,000 per related series). A business that improperly denies thousands of consumer rights requests or fails to honor GPC signals at scale faces substantial exposure under Colorado law.
The CPA originally provided a safety valve: from the law's effective date of July 1, 2023 through January 1, 2025, the AG and district attorneys were required to provide covered businesses with a 60-day written cure notice before bringing an enforcement action, provided the violation was capable of being remedied. That general mandatory cure period sunsetted on January 1, 2025, under C.R.S. § 6-1-1311(1)(d)(I). As of that date, the AG may bring most enforcement actions immediately upon identifying a violation, without first giving the business an opportunity to fix the problem. Businesses that counted on receiving a cure notice before facing consequences no longer have that cushion for most violations. The exception: C.R.S. § 6-1-1311(1)(d)(II), added by SB 24-041, preserves a mandatory 60-day cure notice specifically for enforcement of the CPA's minors' data provisions (C.R.S. §§ 6-1-1305.5, 6-1-1308.5, and 6-1-1309.5), and that carve-out is not repealed until December 31, 2026.
The AG can also seek injunctive relief and, as part of any enforcement action, may recover reasonable investigative costs. The AG maintains a public CPA resource hub at coag.gov/resources/colorado-privacy-act/, which includes enforcement guidance and rulemaking updates.
For the full controller compliance checklist covering privacy notices, data processing agreements, consumer response workflows, and UOOM implementation steps, see the CPA compliance checklist.
Recent CPA amendments: biometrics, minors, and geolocation (2024 to 2026)
The CPA has been amended at least four times since its 2023 launch, each time adding new obligations in areas of heightened public concern.
HB 24-1058 (effective August 7, 2024): biological and neural data as sensitive data. Governor Polis signed this bill on April 17, 2024. It expanded the CPA's definition of sensitive data in C.R.S. § 6-1-1303 to include "biological data," which the act describes as data generated by the technological processing, measurement, or analysis of an individual's biological, genetic, biochemical, physiological, or neural properties, compositions, or activities, when that data is used for identification purposes. Because neural data falls inside that definition, Colorado became the first state to treat neural data as sensitive data requiring opt-in consent. This amendment is current law.
HB 24-1130 (effective July 1, 2025): biometric identifier protections. Governor Polis signed this bill on May 31, 2024. The amendment adds specific obligations for controllers that process biometric identifiers (fingerprints, face geometry, iris scans, and similar data) beyond the general sensitive-data consent requirement already in the CPA. Under HB 24-1130, covered controllers must: adopt and make publicly available a written retention and destruction schedule for biometric identifiers; obtain a consumer disclosure and written consent before collecting, purchasing, or otherwise obtaining biometric data; develop response protocols for security breaches involving biometric data; and limit when they may require employee consent to collect biometric identifiers as a condition of employment. That last duty is narrower than a flat ban. Under C.R.S. § 6-1-1314(6)(a), an employer may condition employment on an employee's or applicant's consent to collect a biometric identifier only to permit access to secure physical locations and secure electronic hardware and software applications; to record the start and end of a full work day, including meal and rest breaks over thirty minutes; to improve or monitor workplace safety or security; or to protect public safety in an emergency or crisis. For any other use, C.R.S. § 6-1-1314(6)(b) bars an employer from requiring consent as a condition of employment and from retaliating against an employee or applicant who declines. This amendment is current law.
SB 24-041 (effective October 1, 2025): minors' online data protections. Also signed May 31, 2024, SB 24-041 added C.R.S. § 6-1-1309.5, imposing heightened obligations whenever a controller knows or willfully disregards that a user is a minor. When that knowledge threshold is met, the controller must: exercise reasonable care to avoid heightened harm to the minor; conduct data protection assessments of any processing that may affect minors; and obtain consent before engaging in targeted advertising to minors, selling minors' personal data, profiling minors, or using design features intended to significantly extend minors' use of the service. Importantly, controllers are not required to implement age-verification systems under SB 24-041. This amendment is current law as of October 1, 2025.
SB 25-276 (in force since May 23, 2025): precise geolocation as sensitive data. Governor Polis signed SB 25-276 on May 23, 2025. The act carries a safety clause and took effect immediately on signing, so precise geolocation data has been added to the CPA's definition of sensitive data in C.R.S. § 6-1-1303. Controllers who process precise location data for Colorado consumers must obtain opt-in consent before doing so. SB 25-276 also restricts the sale of sensitive data without consumer consent more broadly. Businesses that use precise geolocation data (including mapping apps, delivery platforms, fleet management systems, or any service that tracks device location) must now treat precise geolocation as sensitive data requiring opt-in consent.
Colorado Privacy Act vs. CCPA: three key differences
The CPA and California's CCPA are the two most-discussed U.S. state privacy laws, and they share a common framework, but they differ in three ways that matter practically. Our state data privacy law comparison page covers the full multi-state picture, but here are the sharpest distinctions:
Consent standard for sensitive data. The CPA requires affirmative opt-in consent before a controller may process sensitive personal data (C.R.S. § 6-1-1308(7)). The CCPA/CPRA uses an opt-out model: businesses may process sensitive personal information under California's law unless and until the consumer submits a "Limit the Use of My Sensitive Personal Information" request under Cal. Civ. Code § 1798.121. In practical terms, opt-in means no processing without a prior yes; opt-out means processing continues unless the consumer objects.
Universal Opt-Out Mechanism. Colorado mandates that covered controllers honor GPC browser signals as a valid consumer opt-out of targeted advertising and data sales, with compliance required since July 1, 2024. California has a similar requirement under CPRA regulations for "opt-out preference signals," but Colorado's requirement is codified in both statute and detailed AG rules, with a public registry of recognized mechanisms that provides more operational specificity.
Applicability threshold. The CPA's secondary coverage prong requires only that a business derives any revenue from selling personal data while processing data of 25,000 or more Colorado consumers. The CCPA applies to businesses meeting at least one of three separate thresholds, one of which is annual gross revenues exceeding $25 million. A small business with no significant revenue but large data-processing volume may be covered in Colorado but not California.
Related guides
- Colorado Privacy Act Consumer Rights & How to Use Them
- Colorado Privacy Act Compliance Checklist (2026)
- Colorado Data Privacy Laws: CPA Consumer Rights Guide (2026)
- Colorado Biometric Privacy Laws: Collection, Consent & Penalties (2026)
- US State Privacy Laws Comparison Chart (2026)
More Colorado Laws
Frequently Asked Questions
What is the Colorado Privacy Act?
The Colorado Privacy Act (CPA) is Colorado's comprehensive consumer data privacy law, codified at C.R.S. §§ 6-1-1301 through 6-1-1314. Governor Jared Polis signed Senate Bill 21-190 on July 7, 2021, and the law took effect on July 1, 2023. It gives Colorado residents rights over their personal data and requires covered businesses to be transparent about collection, use, and processing. Colorado was the third state, after California and Virginia, to enact a law of this scope.
Who does the Colorado Privacy Act apply to?
The CPA applies to any person that does business in Colorado or targets Colorado residents and meets either of two thresholds: (1) processes personal data of 100,000 or more Colorado consumers per calendar year, or (2) processes data of 25,000 or more consumers while deriving any revenue from selling personal data. Unlike Virginia's VCDPA, there is no 50% revenue test. The CPA also covers nonprofits, which Virginia and Texas exempt. Government bodies, HIPAA-regulated entities, GLBA-regulated financial institutions, and data covered by FCRA, FERPA, COPPA, and DPPA are exempt.
What rights do Colorado consumers have under the CPA?
Colorado residents have five rights under C.R.S. § 6-1-1306(1): the right to access and confirm whether their data is being processed, the right to correct inaccurate data, the right to delete their personal data, the right to receive a portable copy of their data, and the right to opt out of targeted advertising, personal data sales, and profiling that produces a legal or similarly significant effect. Controllers must respond within 45 days, extendable by 45 more days with proper notice.
What is the penalty for violating the Colorado Privacy Act?
CPA violations are classified as deceptive trade practices under the Colorado Consumer Protection Act, carrying civil penalties of up to $20,000 per violation under C.R.S. § 6-1-112(1)(a), rising to up to $50,000 per violation when committed against a consumer age 60 or older under C.R.S. § 6-1-112(1)(c). This is higher than Virginia's $7,500 per violation. The Colorado AG and district attorneys can also seek injunctive relief. The general mandatory 60-day cure period that previously shielded businesses sunsetted on January 1, 2025, so most enforcement actions can now be brought without a prior cure opportunity, except for the CPA's minors' provisions, which still require a 60-day cure notice through December 31, 2026.
Does the Colorado Privacy Act have a private right of action?
No. Only the Colorado Attorney General and district attorneys can enforce the CPA under C.R.S. § 6-1-1311. Individual consumers cannot sue covered businesses directly for CPA violations. This is a key contrast with California's CCPA, which provides a limited private right of action for data breaches caused by inadequate security.
What is the Universal Opt-Out Mechanism under the Colorado Privacy Act?
A Universal Opt-Out Mechanism (UOOM) is a browser or device signal that tells covered businesses a consumer wants to opt out of targeted advertising and personal data sales. The Colorado AG maintains a public list of recognized UOOMs under CPA Rule 5.07 (4 CCR 904-3); the statute, C.R.S. § 6-1-1313(2), is what directed the AG to adopt the technical specifications those mechanisms must meet. The Global Privacy Control (GPC) is currently the only recognized UOOM. Controllers have been required to honor GPC signals from Colorado consumers since July 1, 2024. A consumer does not need to submit a separate opt-out form if their browser has GPC enabled.
What counts as sensitive data under the Colorado Privacy Act?
Current sensitive data categories under C.R.S. § 6-1-1303 include: personal data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life or sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify a person, biological data (including neural data), personal data collected from a known child, and precise geolocation data. Controllers must obtain opt-in consent before processing any of these categories. Precise geolocation became a sensitive-data category on May 23, 2025, when SB 25-276 was signed and took immediate effect under its safety clause.
Has the Colorado Privacy Act been amended since it was enacted?
Yes, at least four times. HB 24-1058 (effective August 7, 2024) added biological data, which includes neural data, to the sensitive-data definition, making Colorado the first state to require opt-in consent for neural data. HB 24-1130 (effective July 1, 2025) added biometric-identifier protections, including a public retention and destruction schedule requirement and limits on when an employer may condition employment on biometric consent. SB 24-041 (effective October 1, 2025) added heightened protections for minors, requiring consent before targeting or profiling known minors. SB 25-276 (signed May 23, 2025 and effective immediately under its safety clause) added precise geolocation data to the sensitive-data definition, requiring opt-in consent before processing.
Updates
Corrected the Colorado Privacy Act citation range to C.R.S. 6-1-1301 to 6-1-1314, fixed the SB 25-276 effective date to May 23, 2025, added the HB 24-1058 biological and neural data amendment, attributed the Universal Opt-Out Mechanism public list to CPA Rule 5.07 rather than the statute, and corrected the biometric employment-consent rule and the consumer appeal process to match the statutory text.
Updated this page to reflect that SB 25-276's precise-geolocation-as-sensitive-data amendment is now in force (effective August 12, 2026), added the enhanced $50,000-per-violation penalty for violations against consumers age 60 or older, clarified that a 60-day cure notice still applies to enforcement of the minors' provisions through December 31, 2026, added the threshold-free biometric and minors coverage paths, completed the sensitive-data list with genetic and biological (including neural) data, and removed an incorrect reference to a nonexistent Farm Credit Act exemption.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Re-pinned the 45-day response-extension rule to its correct statutory subsection, C.R.S. 6-1-1306(2)(a); the article had cited subsection (3), which is actually the CPA's internal-appeal provision.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Colorado Revised Statutes, Title 6: Consumer and Commercial Affairs
§ 6-1-1306Consumer personal data rightsIn forcecited in 3 of our articles
(1) Consumers may exercise the following rights by submitting a request using the methods specified by the controller in the privacy notice required under section 6-1-1308 (1)(a). The method must take into account the ways in which consumers normally interact with the controller, the need for secure and reliable communication relating to the request, and the ability of the controller to authenticate the identity of the consumer making the request. Controllers shall not require a consumer to create a new account in order to exercise consumer rights pursuant to this section but may require a consumer to use an existing account. A consumer may submit a request at any time to a controller specifying which of the following rights the consumer wishes to exercise: (a) Right to opt out. (I) A consumer has the right to opt out of the processing of personal data concerning the consumer for purposes of: (A) Targeted advertising; (B) The sale of personal data; or (C) Profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at olls.info
Also relied on in: Colorado Privacy Act Consumer Rights & How to Use Them, Colorado Data Privacy Laws: CPA Consumer Rights Guide (2026)
§ 6-1-1301Short titleIn forcecited in 4 of our articles
The short title of this part 13 is the Colorado Privacy Act.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at olls.info
Also relied on in: Colorado Signs Device-Level Age-Check Law (SB26-051), Colorado Smart Glasses Recording Laws 2026, Colorado Recording Laws (2026): One-Party Consent Rules
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- C.R.S. § 6-1-1301 et seq.: Colorado Privacy Act (SB21-190, full text)(leg.colorado.gov)
- 4 CCR 904-3: Colorado Privacy Act Rules (AG press release, filed March 15, 2023)(coag.gov)
- 4 CCR 904-3-2.02: Defined Terms (Law.Cornell.edu)(law.cornell.edu)
- 4 CCR 904-3-5.03: Notice and Choice for Universal Opt-Out Mechanisms (Law.Cornell.edu)(law.cornell.edu)
- 4 CCR 904-3-7.02: Required Consent (Law.Cornell.edu)(law.cornell.edu)
- 4 CCR 904-3-8.02: Data Protection Assessment Scope (Law.Cornell.edu)(law.cornell.edu)
- Colorado AG: Universal Opt-Out Mechanism (UOOM) Registry(coag.gov)
- Colorado AG: Global Privacy Control Recognition(coag.gov)
- Colorado AG: CPA Rulemaking (SB 24-041 and SB 25-276 rules)(coag.gov)
- HB 24-1130: Privacy of Biometric Identifiers and Data (signed May 31, 2024, eff. July 1, 2025)(leg.colorado.gov)
- SB 24-041: Privacy Protections for Children's Online Data (signed May 31, 2024, eff. Oct. 1, 2025)(leg.colorado.gov)
- SB 25-276: CPA Precise Geolocation Amendment (signed May 23, 2025, eff. Aug. 12, 2026)(leg.colorado.gov)
- Colorado AG: Privacy Laws Resource Hub(coag.gov)
- HB 24-1058: Protect Privacy of Biological Data (signed April 17, 2024, eff. Aug. 7, 2024)(leg.colorado.gov)
- C.R.S. Title 6, Article 1, Part 13: Colorado Privacy Act (2025 Colorado Revised Statutes, Office of Legislative Legal Services)(olls.info)