{"id":5864,"date":"2023-01-04T14:22:33","date_gmt":"2023-01-04T13:22:33","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=5864"},"modified":"2026-05-28T14:53:34","modified_gmt":"2026-05-28T12:53:34","slug":"cpa-colorado-privacy-act","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/us\/cpa-colorado-privacy-act\/","title":{"rendered":"Colorado Privacy Act (CPA): U.S. Business Compliance Guide"},"content":{"rendered":"\n<p>Colorado enacted the Colorado Privacy Act (CPA) in July 2021, and the law came into force on July 1, 2023. It made Colorado the third U.S. state to enact a comprehensive consumer data privacy law after California and Virginia. As one of the earliest modern U.S. state privacy laws, it has gone through several amendments.<\/p>\n\n\n\n<p>The CPA grants Colorado residents, who are referred to in the law as \u201cconsumers\u201d, a set of enforceable rights over their personal data, and it places binding obligations on businesses that collect or process that data.<\/p>\n\n\n\n<p>For U.S. companies operating websites, apps, or digital services that reach Colorado users, the CPA is a live compliance requirement, not a future consideration. Even businesses headquartered elsewhere must comply if they process Colorado residents\u2019 personal data and meet the law\u2019s coverage thresholds.&nbsp;<\/p>\n\n\n\n<p>This guide explains exactly what the CPA requires, how it compares to other state privacy laws, and what practical steps your organization needs to take to remain compliant.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-at-a-glance\">At a Glance<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Effective date:<\/strong> July 1, 2023 (Colorado was the third U.S. state to enact a comprehensive consumer data privacy law; significantly amended in 2024 and 2025)<\/li>\n\n\n\n<li><strong>Scope:<\/strong> Applies to businesses conducting business in Colorado, or targeting goods or services to Colorado residents, that either process personal data from at least 100,000 consumers per year, or process data from at least 25,000 consumers per year while deriving revenue from the sale of personal data. No minimum annual revenue threshold.<\/li>\n\n\n\n<li><strong>Consent model:<\/strong> Opt-out, so businesses may generally collect and process personal data without prior consent, but must notify consumers and honor opt-out requests for targeted advertising, data sales, and profiling. Opt-in consent is required for sensitive data, children\u2019s data, and secondary uses.<\/li>\n\n\n\n<li><strong>Consumer rights:<\/strong> Opt-out, access, correction, deletion, and data portability; consumers also have the right to appeal a controller\u2019s denial of a request.<\/li>\n\n\n\n<li><strong>Enforcement:<\/strong> Colorado Attorney General and District Attorneys have exclusive enforcement authority; fines from USD 2,000 to USD 20,000 per violation (USD 10,000 to USD 50,000 for violations against elderly persons); no private right of action; no cure period.<\/li>\n\n\n\n<li><strong>Key 2025 updates:<\/strong> Biometric data obligations expanded (effective July 1, 2025); minor protections requiring consent for under-18 data processing added (effective October 1, 2025); precise geolocation classified as sensitive data (effective May 23, 2025).<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-colorado-privacy-act-cpa\">What is the Colorado Privacy Act (CPA)?<\/h2>\n\n\n\n<p>The Colorado Privacy Act is a state-level consumer data privacy statute encoded in the <a href=\"https:\/\/law.justia.com\/codes\/colorado\/title-6\/fair-trade-and-restraint-of-trade\/article-1\/part-13\/\" target=\"_blank\" rel=\"noreferrer noopener\">Colorado Revised Statutes, Title 6, Article 1, Part 13<\/a>. It followed closely on the passage of <a href=\"https:\/\/www.cookiebot.com\/us\/virginia-vcdpa\/\">Virginia\u2019s Consumer Data Protection Act<\/a> earlier that year.<\/p>\n\n\n\n<p>The CPA\u2019s core purpose is to give Colorado residents meaningful control over how their personal data is collected, used, and shared by businesses.&nbsp;<\/p>\n\n\n\n<p>Rather than requiring consent before all data collection as the EU\u2019s General Data Protection Regulation (GDPR) does, the CPA adopts an opt-out framework, meaning businesses may generally process consumer data without prior consent, unless the data is sensitive, belongs to a child, or is being used for secondary purposes not previously disclosed.<\/p>\n\n\n\n<p>The Colorado Attorney General\u2019s Office is responsible for enforcement, and it finalized implementing rules on March 15, 2023, covering universal opt-out mechanisms, privacy notice requirements, accessibility standards, and biometric data retention.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-key-definitions-under-the-colorado-privacy-act\">Key Definitions Under the Colorado Privacy Act<\/h2>\n\n\n\n<p>Understanding the CPA requires clarity on how the law defines several foundational terms.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-personal-data\">Personal Data<\/h3>\n\n\n\n<p>Personal data under the CPA means any information that is linked or reasonably linkable to an identified or identifiable individual. The definition excludes data that has been de-identified and information that is publicly available, for example, government records or content a consumer has voluntarily made public.<\/p>\n\n\n\n<p>The law does not enumerate specific categories of personal data, but common examples collected by websites and apps include names, email addresses, phone numbers, IP addresses, device identifiers, and browsing history.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-sensitive-data\">Sensitive Data<\/h3>\n\n\n\n<p>A distinct subset of personal data, sensitive data triggers stronger protections under the CPA and requires explicit, opt-in consent before a controller may collect or process it. The CPA classifies the following as sensitive data:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Data revealing racial or ethnic origin<\/li>\n\n\n\n<li>Data revealing religious beliefs<\/li>\n\n\n\n<li>Data revealing mental or physical health conditions or diagnoses<\/li>\n\n\n\n<li>Data concerning sex life or sexual orientation<\/li>\n\n\n\n<li>Data revealing citizenship or immigration status<\/li>\n\n\n\n<li>Genetic data<\/li>\n\n\n\n<li>Biometric data processed for the purpose of uniquely identifying an individual<\/li>\n\n\n\n<li>Personal data belonging to a known child<\/li>\n<\/ul>\n\n\n\n<p>As of July 1, 2025, biometric data protections were significantly strengthened by <a href=\"https:\/\/leg.colorado.gov\/bills\/hb24-1130\" target=\"_blank\" rel=\"noreferrer noopener\">HB 24-1130<\/a>, which imposed new consent, notice, retention, and deletion obligations on entities \u2014 including employers \u2014 that collect biometric identifiers from individuals in Colorado.<\/p>\n\n\n\n<p>As of May 23, 2025, precise geolocation data has been added to the category of sensitive data under the CPA. Collecting precise geolocation must now be justified by necessity and proportionality.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.cookiebot.com\/us\/wp-content\/uploads\/sites\/8\/2025\/04\/cb_blog_900x450_What-is-sensitive-data-under-the-CPA_.svg\" alt=\"\" class=\"wp-image-16807\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-controller-and-processor\">Controller and Processor<\/h3>\n\n\n\n<p>A controller is any person or organization that determines the purposes and means of processing personal data. A processor is a person that processes personal data on behalf of the controller. Processors must follow controllers\u2019 instructions and support their compliance obligations.&nbsp;<\/p>\n\n\n\n<p>Before processing begins, controllers must enter into written contracts with processors that detail processing instructions, data security obligations, the conditions for engaging subcontractors, and requirements for deletion or return of data at the end of the contract.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-consent\">Consent<\/h3>\n\n\n\n<p>The CPA defines consent as a clear, affirmative act signifying a consumer\u2019s freely given, specific, informed, and unambiguous agreement to the processing of their personal data. Acceptance of broad terms of service, hovering over or closing content, and consent obtained through <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/dark-patterns-and-how-they-affect-consent\/\" target=\"_blank\" rel=\"noreferrer noopener\">dark patterns<\/a> do not meet this standard.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-sale-of-personal-data\">Sale of Personal Data<\/h3>\n\n\n\n<p id=\"h-sale-of-personal-dataa-sale-under-the-cpa-is-broadly-defined-as-the-exchange-of-personal-data-for-monetary-or-other-valuable-consideration-by-a-controller-to-a-third-party-sharing-data-with-processors-affiliates-or-third-parties-in-the-course-of-providing-a-requested-product-or-service-is-not-considered-a-sale-under-the-law\">A sale under the CPA is broadly defined as the exchange of personal data for monetary or other valuable consideration by a controller to a third party. Sharing data with processors, affiliates, or third parties in the course of providing a requested product or service is not considered a sale under the law.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-targeted-advertising\">Targeted Advertising<\/h3>\n\n\n\n<p>The CPA defines targeted advertising as displaying ads to a consumer based on personal data obtained or inferred over time from the consumer\u2019s activities across unaffiliated websites, applications, or services, used to predict preferences or interests. Contextual advertising based on a consumer\u2019s current search query or website visit does not fall within this definition.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-must-comply-with-the-colorado-privacy-act\">Who Must Comply with the Colorado Privacy Act?<\/h2>\n\n\n\n<p>The CPA applies to any person or business that conducts business in Colorado or targets commercial products or services to Colorado residents, and that meets one or both of the following thresholds:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Controls or processes the personal data of 100,000 or more consumers in a calendar year<\/li>\n\n\n\n<li>Controls or processes the personal data of at least 25,000 consumers per year, and derives revenue or receives a discount on goods or services from the sale of that data<\/li>\n<\/ul>\n\n\n\n<p>Businesses that collect or process biometric data or the personal data of minors are subject to CPA obligations now regardless of whether they meet these thresholds.<\/p>\n\n\n\n<p>Colorado does not require a minimum annual revenue figure for compliance, which distinguishes it from California\u2019s CCPA. A business need not have a physical presence in Colorado for the CPA to apply; operating a website or app that is intentionally targeted at Colorado residents is sufficient.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-cpa-exemptions\">CPA Exemptions<\/h3>\n\n\n\n<p>Certain categories of organizations and data are exempt from CPA requirements. Exempt businesses include:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Airlines<\/li>\n\n\n\n<li>Public utilities<\/li>\n\n\n\n<li>National securities associations<\/li>\n\n\n\n<li>Higher education institutions<\/li>\n\n\n\n<li>Health care facilities and providers<\/li>\n\n\n\n<li>Consumer reporting agencies<\/li>\n\n\n\n<li>Financial institutions subject to the <a href=\"https:\/\/www.cookiebot.com\/us\/gramm-leach-bliley-act-glba\/\">Gramm-Leach-Bliley Act (GLBA)<\/a><\/li>\n<\/ul>\n\n\n\n<p>Exempt categories of data include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/usercentrics.com\/knowledge-hub\/health-insurance-portability-and-accountability-act-hipaa\/\" target=\"_blank\" rel=\"noreferrer noopener\">HIPAA<\/a>-regulated data<\/li>\n\n\n\n<li>Employment records&nbsp;<\/li>\n\n\n\n<li>Research data<\/li>\n\n\n\n<li>De-identified data<\/li>\n\n\n\n<li>Data regulated under laws, including FERPA, FCRA, COPPA, and the DPPA.<\/li>\n<\/ul>\n\n\n\n<p>Notably, nonprofit organizations and small businesses are not categorically exempt. If they meet the coverage thresholds and do not otherwise qualify for an enumerated exemption, they must comply.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-consumer-rights-under-the-colorado-privacy-act\">Consumer Rights Under the Colorado Privacy Act<\/h2>\n\n\n\n<p>ThColorado residents have five core rights under the CPA, which controllers must be equipped to honor.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Right of access:<\/strong> Consumers may request confirmation of whether a controller is processing their data, and may obtain a copy of that data.<\/li>\n\n\n\n<li><strong>Right to correction:<\/strong> Consumers may request that a controller correct inaccuracies in their personal data, taking into account the purpose of the processing.<\/li>\n\n\n\n<li><strong>Right to deletion:<\/strong> Consumers may request deletion of their personal data, subject to certain exceptions.<\/li>\n\n\n\n<li><strong>Right to data portability:<\/strong> Consumers may request their personal data in a portable, readily usable format that allows them to transmit it to another entity.<\/li>\n\n\n\n<li><strong>Right to opt out:<\/strong> Consumers may opt out of the processing of their personal data for purposes of targeted advertising, sale, or profiling that produces legal or similarly significant effects.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.cookiebot.com\/us\/wp-content\/uploads\/sites\/8\/2025\/04\/cb_blog_900x450_Consumer-rights-under-the-Colorado-Privacy-Act.svg\" alt=\"\" class=\"wp-image-16808\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-handling-consumer-rights-requests-under-the-cpa\">Handling Consumer Rights Requests Under the CPA<\/h3>\n\n\n\n<p>The CPA also gives consumers the right to appeal a controller\u2019s denial of a request. Controllers must respond to an authenticated consumer request within 45 days, with an option to extend by an additional 45 days where reasonably necessary. If a request is denied, the controller must inform the consumer of the available appeals process and of their right to contact the Attorney General.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-the-colorado-privacy-act-means-for-cookies-and-website-tracking\">What the Colorado Privacy Act Means for Cookies and Website Tracking<\/h2>\n\n\n\n<p>The CPA does not address cookies or tracking technologies by name, but its definition of personal data encompasses the types of identifiers, such as IP addresses, device IDs, browser fingerprints, and behavioral profiles, that tracking cookies and pixels routinely collect.<\/p>\n\n\n\n<p>Because the CPA requires controllers to provide users with the ability to opt out of data processing for targeted advertising and sale, any cookie or tracker on your website that collects personal data for these purposes must be brought under the user\u2019s control.&nbsp;<\/p>\n\n\n\n<p>In practical terms, this means deploying a consent management solution that presents Colorado users with a clear opt-out mechanism, honors <a href=\"https:\/\/www.cookiebot.com\/us\/global-privacy-control\/\">Global Privacy Control (GPC)<\/a> signals \u2014 which the CPA expressly requires controllers to recognize as valid opt-out signals \u2014 and maintains records of user preferences.&nbsp;<\/p>\n\n\n\n<p>Your privacy notice must also disclose the categories of personal data collected through cookies and trackers, the purposes for which that data is processed, and the categories of third parties with whom it is shared.&nbsp;<\/p>\n\n\n\n<p>If your marketing stack includes advertising pixels, session replay tools, or behavioral analytics trackers, each constitutes a data processing activity that requires transparency and, where the data is sensitive or the purpose constitutes a secondary use, opt-in consent.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-manage-colorado-privacy-act-compliance-with-cookiebot-by-usercentrics\">Manage Colorado Privacy Act Compliance with Cookiebot by Usercentrics<\/h2>\n\n\n\n<p><a href=\"https:\/\/www.cookiebot.com\/us\/cookie-consent-solution\/\">Cookiebot by Usercentrics<\/a> automatically scans your website for cookies and trackers, generates a cookie declaration to support compliance, and delivers a customizable consent banner that enables Colorado users to exercise their opt-out rights.&nbsp;<\/p>\n\n\n\n<p>The platform supports Global Privacy Control recognition (opt-out mechanisms are now required by a number of states), granular consent logging, and automated updates as privacy laws evolve.<\/p>\n\n\n<div class=\"cta-block cta-block--size-s cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h4\">\n                        Manage data collection, notice, and opt-out requirements with Cookiebot                    <\/h2>\n                                                    <div class=\"cta-block__description like-text-md\">\n                        <p><span style=\"font-weight: 400;\">In 5 minutes you can customize your cookie banner for your brand and relevant regulations. Then start your 14-day trial to see it in action.<\/span><\/p>\n                    <\/div>\n                                                                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"e575bccc-03ea-49fc-b33d-872bbfe3fbb6\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"https:\/\/www.cookiebot.com\/us\/create-cookie-banner-in-minutes\/\" target=\"\">\n<span>Try It Now<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                                                <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-controllers-obligations-under-the-colorado-privacy-act\">Controllers\u2019 Obligations Under the Colorado Privacy Act<\/h2>\n\n\n\n<p>Beyond honoring consumer rights requests, the CPA imposes seven affirmative duties on data controllers.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-duty-of-transparency\">Duty of Transparency<\/h3>\n\n\n\n<p>Controllers must publish a privacy notice that is reasonably accessible, clear, and meaningful. The notice must identify:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Categories of personal data collected<\/li>\n\n\n\n<li>Purposes of processing<\/li>\n\n\n\n<li>Categories of third parties with whom data is shared<\/li>\n\n\n\n<li>Mechanism through which consumers can exercise their rights<\/li>\n<\/ul>\n\n\n\n<p>For businesses operating apps, the notice must also be posted on download pages and in the app\u2019s settings menu. Per the <a href=\"https:\/\/www.sos.state.co.us\/CCR\/DisplayRule.do?action=ruleinfo&amp;ruleId=3396&amp;deptID=11&amp;agencyID=11&amp;deptName=Department+of+Law&amp;agencyName=Attorney+General-Consumer+Protection+Section&amp;seriesNum=4+CCR+904-3\" target=\"_blank\" rel=\"noreferrer noopener\">2023 CPA Rules<\/a>, the link to the notice must include the word \u201cprivacy,\u201d and the notice must be accessible to users with disabilities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-duty-of-purpose-specification-and-data-minimization\">Duty of Purpose Specification and Data Minimization<\/h3>\n\n\n\n<p>CControllers must specify the purposes for which personal data is collected, and they may only collect data that is adequate, relevant, and limited to what is reasonably necessary for those stated purposes.&nbsp;<\/p>\n\n\n\n<p>This <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/data-minimization\/\" target=\"_blank\" rel=\"noreferrer noopener\">data minimization<\/a> requirement differs from California\u2019s CCPA, the original version of which did not include a data minimization requirement. This was added by the California Privacy Rights Act (CPRA), which took effect in January 2023.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-duty-to-avoid-secondary-use\">Duty to Avoid Secondary Use<\/h3>\n\n\n\n<p>Personal data collected for one stated purpose may not be processed for a materially different purpose without first notifying the consumer of the new purpose and obtaining their consent. This is the secondary use prohibition.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-duty-of-care-and-data-security\">Duty of Care and Data Security<\/h3>\n\n\n\n<p>Controllers must implement reasonable security measures appropriate to the volume, scope, and sensitivity of the personal data processed. The CPA does not specify minimum technical controls, but enforcement guidance from the Attorney General\u2019s office indicates that the greater the volume and sensitivity of data, the more robust the required security posture.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-duty-to-avoid-unlawful-discrimination\">Duty to Avoid Unlawful Discrimination<\/h3>\n\n\n\n<p>Controllers may not process personal data in a manner that violates state or federal anti-discrimination laws.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-data-protection-impact-assessments-dpias\">Data Protection Impact Assessments (DPIAs)<\/h3>\n\n\n\n<p>Controllers must conduct and document <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/data-protection-impact-assessment-dpia\/\">Data Protection Impact Assessments (DPIAs)<\/a> for processing activities that present a heightened risk of consumer harm. These activities include targeted advertising, the sale of personal data, the processing of sensitive data, and profiling that could produce decisions with legal or similarly significant effects.&nbsp;<\/p>\n\n\n\n<p>DPIAs must be made available to the Attorney General upon request. Under the October 2025 amendments, controllers offering online services to known or reasonably identifiable minors must conduct DPIAs where those services present a heightened risk of harm to minors, and must retain assessment documentation for at least three years.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-consent-for-sensitive-data-children-and-secondary-use\">Consent for Sensitive Data, Children, and Secondary Use<\/h3>\n\n\n\n<p>The CPA\u2019s opt-out default shifts to an opt-in requirement in three situations:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Processing sensitive data<\/li>\n\n\n\n<li>Processing personal data of a known child under 13 (for which parental or guardian consent is required)<\/li>\n\n\n\n<li>Processing data for secondary purposes<\/li>\n<\/ul>\n\n\n\n<p>As of October 1, 2025, the standard expanded further: controllers must obtain consent from any consumer under 18 before processing their personal data for targeted advertising, sale, or profiling purposes, provided the controller knew or willfully disregarded that the consumer was a minor.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-universal-opt-out-and-the-global-privacy-control\">Universal Opt-Out and the Global Privacy Control<\/h2>\n\n\n\n<p>The CPA was among the first U.S. state privacy laws to explicitly require controllers to recognize universal opt-out mechanisms. As of 2026, 12 states now require this. Colorado is one of three states \u2014 along with California and Connecticut \u2014 to explicitly require respecting Global Privacy Control signals. The GPC is a browser-level signal that transmits a user\u2019s opt-out preference across all sites they visit.<\/p>\n\n\n\n<p>Controllers must honor valid GPC signals from Colorado users and may not configure their consent management platforms to treat a device\u2019s default setting as an affirmative opt-out choice; the signal must reflect a deliberate user action.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-2025-cpa-updates-biometrics-minors-and-geolocation\">2025 CPA Updates: Biometrics, Minors, and Geolocation<\/h2>\n\n\n\n<p>The Colorado Privacy Act has been actively amended since going into effect. Businesses subject to the CPA should note the following changes, and stay up to date on future amendments and other relevant legislation that affects personal data and privacy, such as that targeting AI governance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-biometric-data\">Biometric Data<\/h3>\n\n\n\n<p>HB 24-1130 substantially expanded the CPA\u2019s treatment of biometric data. Under the biometric amendment, controllers \u2014 including employers collecting biometric identifiers from employees and job applicants \u2014 must provide advance notice of biometric data collection, obtain consent before collection in most circumstances, maintain a written retention and destruction schedule, and implement an incident-response protocol for biometric data breaches.&nbsp;<\/p>\n\n\n\n<p>The amendment imposes obligations that apply regardless of whether the individuals involved qualify as \u201cconsumers\u201d under the base CPA.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-minor-protections\">Minor Protections<\/h3>\n\n\n\n<p>SB 24-041 added a broader set of online safety obligations for businesses whose services are directed at or knowingly used by minors. The obligations, which came into effect on October 1, 2025, require controllers to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use reasonable care to avoid heightened risks of harm to minors<\/li>\n\n\n\n<li>Obtain consent before processing a minor\u2019s data for targeted advertising, sale, or profiling<\/li>\n\n\n\n<li>Refrain from using design features that significantly increase, sustain, or extend a minor\u2019s use of a service<\/li>\n\n\n\n<li>Obtain parental or guardian consent before collecting precise geolocation data of users under 13&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>In October 2025, the Colorado Department of Law finalized rules implementing these amendments, clarifying the \u201cwillful disregard\u201d standard and the definition of addictive design features.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-precise-geolocation-as-sensitive-data\">Precise Geolocation as Sensitive Data<\/h3>\n\n\n\n<p>SB 25-276 amended the CPA to classify precise geolocation data as a category of sensitive data. Controllers must now justify the collection of precise geolocation on the basis of necessity and proportionality, consistent with the civil rights protections the bill was enacted to reinforce.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-colorado-ai-act\">Colorado AI Act<\/h3>\n\n\n\n<p>Controllers must enter into contracts with processors before data processing begins. These contracts, while not explicitly referred to as \"data processing agreements\" under the CPA, serve a similar puColorado has also enacted what is expected to become the first comprehensive state law regulating artificial intelligence systems used in consequential decisions with <a href=\"https:\/\/leg.colorado.gov\/bills\/sb24-205\" target=\"_blank\" rel=\"noreferrer noopener\">SB 24-205<\/a>. Originally passed in 2024, the Colorado AI Act was designed to regulate AI systems used in high-stakes decisions covering areas such as employment, housing, loans, and healthcare.<\/p>\n\n\n\n<p>Its initial effective date of February 1, 2026 was subsequently delayed: on August 28, 2025, Governor Jared Polis signed SB 25B-004, pushing the operative date to June 30, 2026.<\/p>\n\n\n\n<p>The law imposes obligations on both developers and deployers of high-risk AI systems, including requirements to create developer documentation and public statements, implement deployer risk management programs and impact assessments, and issue consumer disclosures when AI contributes to consequential decisions.<\/p>\n\n\n\n<p>Enforcement authority rests with the Colorado Attorney General, and violations are actionable as deceptive trade practices under the Colorado Consumer Protection Act, which is the same enforcement framework that governs CPA violations.<\/p>\n\n\n\n<p>Substantive amendments remain under consideration during the 2026 regular legislative session, and the law's final form is not yet settled. Businesses that use automated or AI-assisted decision-making in Colorado \u2014 particularly in employment, lending, or healthcare contexts \u2014 should monitor developments and begin assessing whether their systems fall within the Act's definition of a high-risk AI system ahead of the June 30, 2026 effective date.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-colorado-privacy-act-enforcement-and-penalties\">Colorado Privacy Act Enforcement and Penalties<\/h2>\n\n\n\n<p>The Colorado Attorney General and District Attorneys share exclusive enforcement authority under the CPA. Colorado residents have no private right of action, meaning they cannot file lawsuits directly against companies for CPA violations.<\/p>\n\n\n\n<p>Violations of the CPA are classified as deceptive trade practices under the <a href=\"https:\/\/leg.colorado.gov\/sites\/default\/files\/images\/olls\/crs2024-title-06.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Colorado Consumer Protection Act<\/a>, which governs the penalty structure. Fines range from USD 2,000 to USD 20,000 per violation in standard cases, and from USD 10,000 to USD 50,000 per violation when the affected party is an elderly individual. Penalties are capped at USD 500,000 in aggregate for a related series of violations.<\/p>\n\n\n\n<p>The CPA originally required the Attorney General or District Attorney to issue a notice of violation and allow 60 days to cure before initiating enforcement. That provision \u2014 which was double the 30-day cure period found in several other state privacy laws \u2014 sunsetted on January 1, 2025.&nbsp;<\/p>\n\n\n\n<p>The Colorado AG may now pursue enforcement action without first offering a cure opportunity, placing Colorado alongside Connecticut in an enforcement posture that permits immediate penalties.<\/p>\n\n\n\n<p>Because CPA violations fall under the Consumer Protection Act, they can also result in criminal charges in extreme cases, which is an unusual feature among U.S. state privacy laws.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.cookiebot.com\/us\/wp-content\/uploads\/sites\/8\/2025\/04\/cb_blog_900x450_Colorado-Privacy-Act-penalties-and-enforcement.svg\" alt=\"\" class=\"wp-image-16809\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-the-cpa-compares-to-other-privacy-laws\">How the CPA Compares to Other Privacy Laws<\/h2>\n\n\n\n<p>The CPA shares significant structural DNA with Virginia's Consumer Data Protection Act, including the same five core consumer rights, data minimization and purpose limitation obligations, data protection assessment requirements, and enforcement exclusively through the Attorney General with no private right of action.&nbsp;<\/p>\n\n\n\n<p>Virginia's framework has since become the template for a number of state privacy laws enacted since 2023. Practically speaking, businesses already managing VCDPA compliance will find considerable overlap with CPA requirements, though Colorado's more detailed rulemaking, biometric provisions, and minor protections represent meaningful additions.<\/p>\n\n\n\n<p>Against California, the most significant structural difference remains the absence of a revenue-based compliance threshold in Colorado: the CPA triggers solely on data volume and whether revenue derives from data sales.&nbsp;<\/p>\n\n\n\n<p>Colorado imposes higher maximum penalties \u2014 up to USD 20,000 per violation compared to California's USD 7,500.&nbsp;<\/p>\n\n\n\n<p>On universal opt-out, Colorado is now one of 12 states requiring businesses to honor opt-out preference signals such as the Global Privacy Control, with GPC enforcement already the subject of coordinated multi-state investigative sweeps involving California, Colorado, and Connecticut.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/usercentrics.com\/knowledge-hub\/maryland-online-data-privacy-act-modpa\/\">Maryland's Online Data Privacy Act (MODPA)<\/a> is worth noting as a point of comparison for businesses assessing where state law is heading: it imposes the most restrictive data minimization standard currently in force in the U.S. MODPA limits collection to what is necessary for the specific product or service requested and prohibits the sale of sensitive personal data outright, going further than Colorado's opt-in consent requirement.<\/p>\n\n\n\n<p>Against the GDPR, the fundamental structural difference remains: Colorado operates on an opt-out default, whereas European law requires affirmative consent before most data processing.&nbsp;<\/p>\n\n\n\n<p>For businesses subject to both regimes, the CPA's consent requirements for sensitive data, secondary use, children's data, and biometric identifiers meaningfully narrow the operational gap, but the baseline default represents an irreconcilable structural distinction that cannot be harmonized through policy alone.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-to-comply-with-the-colorado-privacy-act-seven-steps\">How to Comply with the Colorado Privacy Act: Seven Steps<\/h2>\n\n\n\n<p>Businesses that meet the CPA\u2019s coverage thresholds should work through the following compliance steps.<\/p>\n\n\n\n<div class=\"cb-article-list-timeline   cb-ctx--base\" style=\"\" data-manual-enabling=\"false\" style=\"--items-count: 7\">\n            <div class=\"cb-article-list-timeline__header\">\n                                        <figure class=\"cb-article-list-timeline__header-image\">\n                    <img decoding=\"async\" class=\"cb-article-list-timeline__header-image-element\"\n                         src=\"https:\/\/www.cookiebot.com\/us\/wp-content\/uploads\/sites\/8\/2023\/01\/Checklist_with_a_shield_representing_privacy_compliance_verification-1.svg?v=9945bae901ece5af\"\n                         alt=\"Checklist icon\">\n                <\/figure>\n                    <\/div>\n        <div class=\"cb-article-list-timeline__list\">\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                            <h3 class=\"cb-article-list-timeline__item-title\">                        Audit your data flows                        <\/h3>                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p><span style=\"font-weight: 400;\">Identify all personal data your organization collects, the sources and purposes, the processors involved, and the third parties with whom data is shared.<\/span><\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                            <h3 class=\"cb-article-list-timeline__item-title\">                        Publish a compliant privacy notice                        <\/h3>                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p><span style=\"font-weight: 400;\">Ensure that your notice identifies the categories of data collected, purposes of processing, third-party data sharing, and the method for consumers to exercise their rights. Post it prominently on your website and on any app download or settings page and keep it updated.<\/span><\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                            <h3 class=\"cb-article-list-timeline__item-title\">                        Implement an opt-out mechanism                        <\/h3>                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p><span style=\"font-weight: 400;\">Provide consumers with a clear means to opt out of targeted advertising, data sales, and profiling. Honor Global Privacy Control signals automatically.<\/span><\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                            <h3 class=\"cb-article-list-timeline__item-title\">                        Obtain consent where required                        <\/h3>                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p><span style=\"font-weight: 400;\">Deploy a consent management solution to collect valid opt-in consent for sensitive data processing, secondary uses, and data belonging to children under 13. For users under 18, obtain consent before processing their data for advertising, sale, or profiling purposes.<\/span><\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                            <h3 class=\"cb-article-list-timeline__item-title\">                        Enter into data processing agreements                        <\/h3>                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p><span style=\"font-weight: 400;\">Execute written contracts with all processors before processing begins, covering the specific requirements set out in the CPA.<\/span><\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                            <h3 class=\"cb-article-list-timeline__item-title\">                        Build a consumer request process                        <\/h3>                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p><span style=\"font-weight: 400;\">Establish a documented system for receiving, authenticating, and responding to consumer rights requests within 45 days, with an appeals pathway.<\/span><\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item cb-article-list-timeline__item--last\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                            <h3 class=\"cb-article-list-timeline__item-title\">                        Conduct and document DPIAs                        <\/h3>                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p><span style=\"font-weight: 400;\">Complete Data Protection Impact Assessments for high-risk processing activities and retain documentation for at least three years.<\/span><\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <\/div>\n<\/div>\n\n\n<div class=\"cta-block cta-block--size-s cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h4\">\n                        Federal, state, and industry rules. Which ones apply to you?                    <\/h2>\n                                                    <div class=\"cta-block__description like-text-md\">\n                        <p><span style=\"font-weight: 400;\">Many businesses have obligations under multiple overlapping regulations. Find out exactly which ones apply to your business. No signup required, takes less than 2 minutes.<\/span><\/p>\n                    <\/div>\n                                                                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"21e89734-4600-486a-b1c2-7770820ef65b\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"https:\/\/www.cookiebot.com\/en\/regulations-finder\/\" target=\"\">\n<span>Find My Regulations<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                                                <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Colorado Privacy Act (CPA) is a comprehensive state privacy law that grants Colorado residents meaningful rights over their personal data and imposes clear obligations on businesses that collect or process it. This guide covers who must comply, what the law requires, and how to meet your obligations.<\/p>\n","protected":false},"author":10,"featured_media":16806,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":true,"inline_featured_image":false,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5864","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/us\/wp-content\/uploads\/sites\/8\/2023\/01\/cb_some_colorado_cpa_091524_blue.jpg","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts\/5864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/comments?post=5864"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/posts\/5864\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/media\/16806"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/media?parent=5864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/categories?post=5864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/us\/wp-json\/wp\/v2\/tags?post=5864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}