Colorado CPA

Compliance The Web Exposure Company

Colorado CPA

Colorado Privacy Act

The Colorado Privacy Act grants residents the right to access, correct, delete, and port their personal data, and to opt out of its sale, targeted advertising, and profiling. It requires businesses to honor a universal opt-out mechanism, so non-compliance can mean both fines and lost trust. Security teams must confirm that all tags, trackers, and cookies recognize browser-based opt-out signals such as the Global Privacy Control.

Try for free
Colorado Privacy Act compliance monitoring

How Reflectiz Meets Every CPA Requirement

Requirement → Reflectiz Solution
Right to Opt-Out

Universal Opt-Out Recognition

Reflectiz validates that tags, trackers, and cookies actually honor browser-based opt-out signals such as the Global Privacy Control, and flags any that keep firing after opt-out.

Right to Access & Delete

Consumer Rights Fulfillment

A live inventory of data-collecting components lets teams pinpoint personal data to satisfy access, correction, deletion, and portability requests.

Right to Privacy

Sensitive Data Consent

The platform detects components handling sensitive data and verifies that consent was obtained before collection.

Right to Know

Privacy Notice Accuracy

Reflectiz highlights discrepancies between your published privacy notice and what your site’s code actually does, keeping disclosures truthful.

Reduces Regulatory Risk & Saves Time

Automated tracker detection dashboard Streamlined compliance operations Unified compliance management dashboard

Colorado CPA at a Glance

Key Facts
Key facts about the Colorado Privacy Act (CPA)
Full nameColorado Privacy Act, C.R.S. § 6-1-1301 et seq. Signed July 7, 2021, and in effect since July 1, 2023. Official guidance: Colorado Attorney General.
Who it applies toBusinesses that operate in Colorado or target Colorado residents and control or process personal data of at least 100,000 consumers a year, or of at least 25,000 consumers while earning revenue or discounts from selling personal data. There is no revenue threshold.
NonprofitsCovered. Unlike Virginia’s VCDPA, the CPA has no general nonprofit exemption.
ExemptionsFinancial institutions covered by the Gramm-Leach-Bliley Act, air carriers, national securities associations, and state institutions of higher education. Data governed by HIPAA, plus employee and business-to-business data, also fall outside the law.
Consumer rightsAccess, correct, delete, and get a portable copy of personal data. Opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. Businesses answer within 45 days, with one 45-day extension.
Universal opt-outRequired since July 1, 2024. Global Privacy Control is the only mechanism the Attorney General recognizes, and your privacy policy must explain how you process it.
Sensitive dataOpt-in consent comes first. Covers data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life or sexual orientation, or citizenship status; genetic, biometric, biological, and neural data; a known child’s data; and precise geolocation. Consent obtained through dark patterns does not count.
Precise geolocationSensitive data since a 2025 amendment (SB 25-276), defined as locating a device within 1,850 feet. Selling it requires prior opt-in consent.
MinorsSince October 1, 2025, a business that knows or willfully disregards that a user is under 18 needs consent before using that data for targeted advertising, sale, or profiling (SB 24-041).
BiometricsSince July 1, 2025, any business that collects biometric identifiers, whatever its size, needs notice, consent, a written retention policy, and deletion within 24 months of the last interaction (HB 24-1130).
EnforcementThe Colorado Attorney General and district attorneys, with no private right of action. The general 60-day cure period ended January 1, 2025.
PenaltiesUp to $20,000 per violation under the Colorado Consumer Protection Act, or $50,000 when the violation involves an elderly person.

Colorado CPA FAQ

Common Questions

What is the Colorado Privacy Act?

The Colorado Privacy Act (CPA) is Colorado’s comprehensive consumer privacy law, codified at C.R.S. § 6-1-1301 et seq. Signed on July 7, 2021, and in effect since July 1, 2023, it gives Colorado residents rights over their personal data, requires opt-in consent for sensitive data, and requires businesses to honor universal opt-out signals such as Global Privacy Control.

Who must comply with the Colorado Privacy Act?

Any business or nonprofit that operates in Colorado or targets Colorado residents and controls or processes personal data of at least 100,000 consumers a year, or of at least 25,000 consumers while earning revenue or discounts from selling personal data. There is no revenue threshold, and the biometric rules added in 2025 apply to any business that collects biometric identifiers, regardless of size.

Does the Colorado Privacy Act require honoring Global Privacy Control?

Yes. Since July 1, 2024, businesses covered by the CPA must honor opt-out requests sent through a recognized universal opt-out mechanism, and Global Privacy Control is the one the Attorney General recognizes. A Global Privacy Control signal opts the consumer out of targeted advertising and sale. In September 2025, Colorado joined California and Connecticut in a joint sweep of businesses that ignore it.

What counts as sensitive data under the Colorado Privacy Act?

Sensitive data includes personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life or sexual orientation, or citizenship status; genetic or biometric data used to identify a person; biological and neural data; a known child’s data; and, since 2025, precise geolocation. Businesses need opt-in consent before processing it, and consent obtained through dark patterns is invalid.

What are the penalties for violating the Colorado Privacy Act?

Violations count as deceptive trade practices under the Colorado Consumer Protection Act, with civil penalties of up to $20,000 per violation, or $50,000 when the violation involves an elderly person. The Attorney General and district attorneys enforce the law, and there is no private right of action. The general 60-day cure period expired on January 1, 2025, so regulators can act without offering a chance to fix violations first.

What has changed in the Colorado Privacy Act since 2024?

Four amendments expanded it. Biological and neural data became sensitive data in August 2024 (HB 24-1058). Biometric rules for businesses of any size took effect July 1, 2025 (HB 24-1130). Protections for users under 18 took effect October 1, 2025 (SB 24-041). Precise geolocation became sensitive data in 2025 (SB 25-276).

How does Reflectiz support Colorado Privacy Act compliance?

Reflectiz monitors your website remotely, with no code changes, and checks whether every tag, tracker, and cookie honors Global Privacy Control, flagging any that keep firing after opt-out. It detects components that collect sensitive data without consent, maps where personal data goes, and highlights gaps between your privacy notice and what your code does. Your privacy notice states the policy. Reflectiz shows what your site actually does.

Last reviewed September 2026. This page summarizes the Colorado Privacy Act for general information and is not legal advice. Related: CCPA, Texas TDPSA, Virginia VCDPA, Illinois BIPA, and the Reflectiz Privacy Hub.

Ready for the Colorado Privacy Act? Know Your Web Exposure.

See every script, tag, and tracker on your site, and whether it honors Global Privacy Control, in one continuous, agentless view.

Start Free