CPA: Colorado Privacy Act

Colorado Attorney General

Comprehensive Colorado privacy law granting consumer rights, requiring data protection assessments, and mandating universal opt-out mechanisms.

6Citations
0Audited
6Reference only
Jun 2026Last amended
Official source ↗Effective July 1, 2023

CPA citations (6)

§ 6-1-1303Reference

Definitions

Provides definitions for core terms under the Colorado Privacy Act, including controller, processor, consumer, personal data, and consent.

Scope
§ 6-1-1304Reference

Applicability

Applies to controllers that conduct business in Colorado or intentionally target Colorado residents and that either control or process the personal data of 100,000+ consumers during a calendar year, or derive revenue or receive a discount on the price of goods or services from the sale of personal data and process or control the personal data of 25,000+ consumers. Since July 1, 2025 (HB 24-1130), a controller that controls or processes any amount of biometric identifiers or biometric data is also covered, whatever the volume; one covered only on that basis must comply only as to the biometric data it collects and processes. Since October 1, 2025 (SB 24-041), the minors' provisions (§§ 6-1-1305.5, 6-1-1308.5, and 6-1-1309.5) and §§ 6-1-1310 to 6-1-1313 (liability, enforcement, preemption, and rules) apply to any controller that conducts business in Colorado or targets Colorado residents, with no volume threshold. Colorado sets no minimum-revenue threshold.

Scope
§ 6-1-1306Reference

Consumer Rights

Grants consumers the right to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale of personal data, and profiling. Mandates honoring technical universal opt-out signals (like GPC) since July 1, 2024.

Consumer RightsOpt-OutGPC
§ 6-1-1308Reference

Duties of Controllers

Requires controllers to specify processing purposes, minimize data collection, implement data security, avoid processing sensitive data without consent, and provide transparent privacy notices. SB 25-276 (signed 2025-05-23) amended the sensitive-data duty in subsection (7) to read 'process or sell' (the Act already defined processing to include sale), so a controller may not process or sell a consumer's sensitive data (which now includes precise geolocation data) without first obtaining the consumer's consent or, for a known child, the consent of the child's parent or lawful guardian.

Privacy PolicyData CollectionConsentSensitive PI
§ 6-1-1309Reference

Data Protection Assessments

Mandates controllers to conduct data protection assessments for processing activities presenting a heightened risk of harm to consumers, such as targeted advertising, sale of personal data, or profiling.

Data Protection AssessmentOpt-Out
§ 6-1-1311Reference

Enforcement and Penalties

Grants the Colorado Attorney General and district attorneys exclusive authority to enforce the Act; there is no private right of action. Violations are deceptive trade practices under the Colorado Consumer Protection Act, carrying civil penalties of up to $20,000 per violation. The general 60-day right to cure (former subsection (1)(d)(I)) was repealed effective January 1, 2025, so for most violations the Attorney General may seek penalties without first offering a cure. For the minors' provisions added by SB 24-041 (§§ 6-1-1305.5, 6-1-1308.5, and 6-1-1309.5), however, subsection (1)(d)(II), in force since October 1, 2025, still requires a notice of violation and 60 days to cure, if a cure is deemed possible, before any enforcement action; that requirement is repealed effective December 31, 2026.

Enforcement

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit