EnglishEspañol
Colorado flag

Colorado

What Is the Colorado Privacy Act (CPA)?

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. How we verify our legal content

What Is the Colorado Privacy Act (CPA)?

Frequently Asked Questions

What is the Colorado Privacy Act?

The Colorado Privacy Act (CPA) is Colorado's comprehensive consumer data privacy law, codified at C.R.S. §§ 6-1-1301 through 6-1-1314. Governor Jared Polis signed Senate Bill 21-190 on July 7, 2021, and the law took effect on July 1, 2023. It gives Colorado residents rights over their personal data and requires covered businesses to be transparent about collection, use, and processing. Colorado was the third state, after California and Virginia, to enact a law of this scope.

Who does the Colorado Privacy Act apply to?

The CPA applies to any person that does business in Colorado or targets Colorado residents and meets either of two thresholds: (1) processes personal data of 100,000 or more Colorado consumers per calendar year, or (2) processes data of 25,000 or more consumers while deriving any revenue from selling personal data. Unlike Virginia's VCDPA, there is no 50% revenue test. The CPA also covers nonprofits, which Virginia and Texas exempt. Government bodies, HIPAA-regulated entities, GLBA-regulated financial institutions, and data covered by FCRA, FERPA, COPPA, and DPPA are exempt.

What rights do Colorado consumers have under the CPA?

Colorado residents have five rights under C.R.S. § 6-1-1306(1): the right to access and confirm whether their data is being processed, the right to correct inaccurate data, the right to delete their personal data, the right to receive a portable copy of their data, and the right to opt out of targeted advertising, personal data sales, and profiling that produces a legal or similarly significant effect. Controllers must respond within 45 days, extendable by 45 more days with proper notice.

What is the penalty for violating the Colorado Privacy Act?

CPA violations are classified as deceptive trade practices under the Colorado Consumer Protection Act, carrying civil penalties of up to $20,000 per violation under C.R.S. § 6-1-112(1)(a), rising to up to $50,000 per violation when committed against a consumer age 60 or older under C.R.S. § 6-1-112(1)(c). This is higher than Virginia's $7,500 per violation. The Colorado AG and district attorneys can also seek injunctive relief. The general mandatory 60-day cure period that previously shielded businesses sunsetted on January 1, 2025, so most enforcement actions can now be brought without a prior cure opportunity, except for the CPA's minors' provisions, which still require a 60-day cure notice through December 31, 2026.

Does the Colorado Privacy Act have a private right of action?

No. Only the Colorado Attorney General and district attorneys can enforce the CPA under C.R.S. § 6-1-1311. Individual consumers cannot sue covered businesses directly for CPA violations. This is a key contrast with California's CCPA, which provides a limited private right of action for data breaches caused by inadequate security.

What is the Universal Opt-Out Mechanism under the Colorado Privacy Act?

A Universal Opt-Out Mechanism (UOOM) is a browser or device signal that tells covered businesses a consumer wants to opt out of targeted advertising and personal data sales. The Colorado AG maintains a public list of recognized UOOMs under CPA Rule 5.07 (4 CCR 904-3); the statute, C.R.S. § 6-1-1313(2), is what directed the AG to adopt the technical specifications those mechanisms must meet. The Global Privacy Control (GPC) is currently the only recognized UOOM. Controllers have been required to honor GPC signals from Colorado consumers since July 1, 2024. A consumer does not need to submit a separate opt-out form if their browser has GPC enabled.

What counts as sensitive data under the Colorado Privacy Act?

Current sensitive data categories under C.R.S. § 6-1-1303 include: personal data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life or sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify a person, biological data (including neural data), personal data collected from a known child, and precise geolocation data. Controllers must obtain opt-in consent before processing any of these categories. Precise geolocation became a sensitive-data category on May 23, 2025, when SB 25-276 was signed and took immediate effect under its safety clause.

Has the Colorado Privacy Act been amended since it was enacted?

Yes, at least four times. HB 24-1058 (effective August 7, 2024) added biological data, which includes neural data, to the sensitive-data definition, making Colorado the first state to require opt-in consent for neural data. HB 24-1130 (effective July 1, 2025) added biometric-identifier protections, including a public retention and destruction schedule requirement and limits on when an employer may condition employment on biometric consent. SB 24-041 (effective October 1, 2025) added heightened protections for minors, requiring consent before targeting or profiling known minors. SB 25-276 (signed May 23, 2025 and effective immediately under its safety clause) added precise geolocation data to the sensitive-data definition, requiring opt-in consent before processing.

Updates

Corrected the Colorado Privacy Act citation range to C.R.S. 6-1-1301 to 6-1-1314, fixed the SB 25-276 effective date to May 23, 2025, added the HB 24-1058 biological and neural data amendment, attributed the Universal Opt-Out Mechanism public list to CPA Rule 5.07 rather than the statute, and corrected the biometric employment-consent rule and the consumer appeal process to match the statutory text.

Updated this page to reflect that SB 25-276's precise-geolocation-as-sensitive-data amendment is now in force (effective August 12, 2026), added the enhanced $50,000-per-violation penalty for violations against consumers age 60 or older, clarified that a 60-day cure notice still applies to enforcement of the minors' provisions through December 31, 2026, added the threshold-free biometric and minors coverage paths, completed the sensitive-data list with genetic and biological (including neural) data, and removed an incorrect reference to a nonexistent Farm Credit Act exemption.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Re-pinned the 45-day response-extension rule to its correct statutory subsection, C.R.S. 6-1-1306(2)(a); the article had cited subsection (3), which is actually the CPA's internal-appeal provision.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. C.R.S. § 6-1-1301 et seq.: Colorado Privacy Act (SB21-190, full text)(leg.colorado.gov)
  2. 4 CCR 904-3: Colorado Privacy Act Rules (AG press release, filed March 15, 2023)(coag.gov)
  3. 4 CCR 904-3-2.02: Defined Terms (Law.Cornell.edu)(law.cornell.edu)
  4. 4 CCR 904-3-5.03: Notice and Choice for Universal Opt-Out Mechanisms (Law.Cornell.edu)(law.cornell.edu)
  5. 4 CCR 904-3-7.02: Required Consent (Law.Cornell.edu)(law.cornell.edu)
  6. 4 CCR 904-3-8.02: Data Protection Assessment Scope (Law.Cornell.edu)(law.cornell.edu)
  7. Colorado AG: Universal Opt-Out Mechanism (UOOM) Registry(coag.gov)
  8. Colorado AG: Global Privacy Control Recognition(coag.gov)
  9. Colorado AG: CPA Rulemaking (SB 24-041 and SB 25-276 rules)(coag.gov)
  10. HB 24-1130: Privacy of Biometric Identifiers and Data (signed May 31, 2024, eff. July 1, 2025)(leg.colorado.gov)
  11. SB 24-041: Privacy Protections for Children's Online Data (signed May 31, 2024, eff. Oct. 1, 2025)(leg.colorado.gov)
  12. SB 25-276: CPA Precise Geolocation Amendment (signed May 23, 2025, eff. Aug. 12, 2026)(leg.colorado.gov)
  13. Colorado AG: Privacy Laws Resource Hub(coag.gov)
  14. HB 24-1058: Protect Privacy of Biological Data (signed April 17, 2024, eff. Aug. 7, 2024)(leg.colorado.gov)
  15. C.R.S. Title 6, Article 1, Part 13: Colorado Privacy Act (2025 Colorado Revised Statutes, Office of Legislative Legal Services)(olls.info)
Share: