Colorado Privacy Act: 2026 Information & Compliance Guide
Table of Contents
The Colorado Privacy Act (CPA) is Colorado's comprehensive consumer privacy law, in force since July 1, 2023. It gives local residents rights over their personal data, by establishing ground rules for businesses that process it.
The statute is C.R.S. § 6-1-1301 and following, with rules at 4 CCR 904-3. The attorney general publishes both as PDFs: the official text and the current rules.
Until January 1, 2025, a Colorado violation carried a warning: the attorney general had to give you 60 days to fix it before anything would cost money. That grace window is gone. The first letter you get can now carry penalties, and the law it enforces has grown three new sets of rules since 2023: biometrics, minors, and neural data.
That's the real story of the CPA in 2026. The statute you complied with at launch is not the statute in force today. This guide covers the current law: who it applies to, what it costs to ignore, what your website has to do to stay compliant, and every amendment with its deadline.
Our guide to U.S. state privacy laws has a broader overview of regulations across the United States.
Colorado was the third state to pass a comprehensive privacy law, after California and Virginia. It follows Virginia's general model, then sharpens it: mandatory universal opt-out signals, an active rulemaking program, and fines well above the state norm.
What businesses does the CPA apply to?
The Colorado Privacy Act covers businesses that process personal data from 100,000 or more consumers annually. That bar drops to 25,000 consumers for businesses that earn anything, either money or a rebate, from selling personal data.
A consumer here is a Colorado resident in a personal or household context, so employees and business contacts don't count toward the thresholds. You're also counting people, not traffic: one person visiting your site forty times is still one consumer.
In practice, estimate in good faith how many individual Coloradans appear across your customer records, email lists, and analytics in a year.
A worked example: an online retailer with customer accounts, order records, and an email list that reaches 120,000 Colorado residents in 2025 is covered under the first threshold, regardless of its revenue. A smaller shop with 30,000 Colorado customers that shares purchase data with an ad network in exchange for better rates is subject to the second.
The CPA requires opt-out for data sales, targeted advertising, and profiling. Processing sensitive data needs opt-in consent, and Global Privacy Control (GPC) signals must be honored. Violations run up to $20,000 each, counted per consumer, per incident.
Who's exempt from the CPA
The CPA exempt list is short: financial institutions regulated under GLBA, air carriers, public utilities, and state government bodies. Nonprofits are not exempt from the CPA. Some data types are also exempt wherever they sit, including FCRA-regulated credit data, employment records, and health records under specific federal programs. If you're not on that first list and you cross a threshold, assume you're covered.
CPA's HIPAA exemption, explained
The law does not apply to protected health information held by a HIPAA-covered entity or its business associates, codified at C.R.S. § 6-1-1304(2)(a). It also exempts HIPAA-compliance documents and properly de-identified health data.
Here's the trap: the organization itself stays covered. A clinic's patient records fall outside the CPA, but its website analytics, marketing lists, and ad pixels are ordinary personal data and don't benefit from the same exemption. If the clinic crosses a threshold, its non-PHI data operations must comply with the CPA like any other business's.
This trips up multi-state health businesses: Utah exempts HIPAA-covered entities entirely, and Connecticut does both, so the same organization can be exempt in one state and covered in the next..
Colorado Privacy Act penalties and enforcement
The Colorado Consumer Protection Act defines a CPA violation as a deceptive trade practice. It carries civil penalties of up to $20,000 per violation, or up to $50,000 per violation committed against an elderly person. Most state privacy laws stop at $7,500.
Enforcement belongs to the attorney general and Colorado's district attorneys; consumers cannot sue you under the CPA directly since there's no private right of action.
Here's the practical takeaway: A tracking pixel that fires before consent for 1,000 Colorado visitors is not one mistake; it is potentially 1,000 violations. The per-violation number adds up.
No enforcement actually runs the full multiplication since attorneys general settle. The math matters for a different reason: since the cure period ended in January 2025, there is no 60-day window to fix a violation before it can cost money.
Colorado does offer one mechanism no other state has built out the same way: businesses can request formal opinion letters from the attorney general, and good-faith reliance on one is a defense in later enforcement.
If you're genuinely confused, the Colorado attorney general is willing to help.
What the CPA requires from your website
Five obligations are critical for CPA compliance:
A privacy notice that says enough. The CPA sets the minimum contents: the purposes you process data for, the categories of personal data you collect, the categories you share, and the categories of third parties you share them with, plus how consumers exercise their rights. Transparency is a named duty under the law, not a formality.
An opt-out that works. Colorado consumers can opt out of the sale of personal data, targeted advertising, and certain profiling. Your banner or preference center has to actually stop the relevant scripts and pixels, not just record a preference.
GPC support, mandatory since July 1, 2024. Global Privacy Control is a browser signal that broadcasts a visitor's opt-out automatically, and Colorado requires you to honor the signals on the attorney general's approved list. If your consent setup ignores GPC, every GPC-enabled Colorado visitor you keep tracking is an opt-out you failed to honor.

Opt-in consent for sensitive data. Race or ethnicity, religion, health conditions, sex life or sexual orientation, citizenship status, genetic and biometric data, a known child's data, and, since August 2024, biological and neural data. Consent means a clear, affirmative act; the CPA's rules explicitly ban dark patterns, and pre-ticked boxes don't count.
Records you can produce. Colorado expects you to demonstrate compliance. Timestamped consent logs, versioned banner configurations, and a working intake for access, correction, deletion, and portability requests, generally answered within 45 days. Our DSAR guide covers the intake side.
How Enzuzo handles this: Enzuzo's consent management platform detects where a visitor is, applies Colorado's rules (including GPC signals), blocks trackers until the right consent state exists, and stores the records. Teams typically go live in one to three days. Book a demo to see it live and compare against your own site.
CPA deadlines: what changed and what's next
| Date | What changed | What you must do |
|---|---|---|
| Jul 1, 2023 | CPA + rules in force | Baseline compliance: notices, opt-outs, consent, DPAs |
| Jul 1, 2024 | Universal opt-out signals mandatory | Honor GPC and other approved signals |
| Aug 7, 2024 | Biological and neural data added to sensitive data (HB 24-1058) | Opt-in consent before processing these categories |
| Jan 1, 2025 | Cure period expired | No more free first strike; audit before the AG does |
| Jan 30, 2025 | Amended rules + opinion-letter process live | Optional: request AG guidance with reliance defense |
| Jul 1, 2025 | Biometric identifier rules (HB 24-1130), no size threshold | Consent before selling or sharing biometrics; annual retention review; employer carve-outs |
| Oct 1, 2025 | Minors' protections (SB 24-041), no size threshold | Consent before targeted ads, sale, or profiling of under-18s; no engagement-extending design features |
| Aug 12, 2026 | Sensitive-data sale ban + geolocation definitions (SB 25-276) | Selling sensitive data now requires consent, full stop |
| Pending | Minors implementing rules (filed Jul 2025, under review) | Watch the coag.gov rulemaking page |
Consumer rights under the CPA
Colorado residents hold six rights, each with an operational consequence for businesses:
1. Opt out of sale, targeted advertising, and profiling (your banner, your GPC handling)
2. Access their personal data (your DSAR intake)
3. Correct inaccuracies (your records tooling)
4. Delete their data (your deletion workflow, across processors too)
5. Portability: a usable copy (your export path)
6. Appeal a refused request, with escalation to the AG (your process documentation)
Obligations beyond the website
The CPA assigns duties by role: a controller decides why and how personal data gets processed, and a processor handles data on the controller's instructions. If it's your website and your customer list, you're the controller, and every processor touching that data needs a contract.
Beyond that, the CPA expects duties to reside in your operations rather than in your consent banner.
Collect only what you need for the purposes you disclosed, nothing beyond them. Keep it reasonably secure. Never penalize a consumer for exercising their rights. And before high-risk processing (targeted advertising, selling data, sensitive data, or profiling that risks harm to consumers), write a data protection assessment: a documented risk analysis whose required contents the rules spell out. If the attorney general asks, you have 30 days to hand it over.
CPA vs CCPA: how Colorado differs from California
| Point | Colorado (CPA) | California (CCPA/CPRA) |
|---|---|---|
| Who enforces | AG + district attorneys | Dedicated regulator (CPPA) + AG |
| Private lawsuits | No | Yes for data breaches |
| Fines | Up to $20,000/violation | $2,500–$7,500/violation |
| Revenue threshold | None | $25M+ (one of three triggers) |
| Sensitive data | Opt-in consent; sale banned without consent (2026) | Right to limit use |
| GPC | Mandatory | Mandatory |
FAQs
What is the Colorado Privacy Act?
The Colorado Privacy Act (CPA) is Colorado's comprehensive privacy law, effective July 1, 2023. It gives Colorado residents rights to access, correct, delete, and port their personal data, and to opt out of its sale, targeted advertising, and profiling. It's enforced by the attorney general and district attorneys, with fines up to $20,000 per violation.
Who must comply with the CPA?
Businesses operating in or targeting Colorado that process personal data from 100,000 or more Colorado consumers in a year. The threshold falls to 25,000 consumers for businesses earning any revenue or discount from selling personal data. There's no revenue floor. The biometrics and minors rules added in 2025 apply regardless of these thresholds.
What are the penalties for violating the CPA?
Up to $20,000 per violation ($50,000 if the violation targets an elderly person), enforced as deceptive trade practices under the Colorado Consumer Protection Act. Each affected consumer can count as a separate violation. The 60-day cure period expired January 1, 2025, so penalties can attach to a first enforcement letter.
Does the CPA have a private right of action?
No. Only the Colorado attorney general and district attorneys can enforce the CPA. Consumers cannot sue businesses directly under it, unlike California's breach provisions or Illinois BIPA.
Is there a HIPAA exemption in the CPA?
Yes, but it's data-level, not entity-level. Protected health information held by HIPAA covered entities and business associates is exempt; the organization itself is not. A covered entity's website analytics and marketing data remain subject to the CPA if it crosses a threshold.
Does Colorado require honoring Global Privacy Control?
Yes. Since July 1, 2024, controllers must honor universal opt-out mechanisms on the attorney general's approved list, and GPC is the flagship signal. A consent setup that ignores GPC signals is out of compliance for opted-out visitors.
When did the CPA take effect?
The core law took effect July 1, 2023. Key later dates: GPC became mandatory July 1, 2024; the cure period ended January 1, 2025; biometrics rules arrived July 1, 2025; minors' protections October 1, 2025; and sensitive-data sale restrictions August 12, 2026.
Where can I read the full text of the CPA?
The attorney general hosts the official statute PDF (SB 21-190, codified at C.R.S. § 6-1-1301 et seq.) and the current rules (4 CCR 904-3). The legislature's site tracks amendment bills.
How is the CPA different from the CCPA?
Colorado has higher per-violation fines ($20,000 vs $7,500), no revenue threshold, and opt-in consent for sensitive data. California has a dedicated regulator, a private right of action for breaches, and a right-to-limit model instead of sensitive-data opt-in. Both require honoring GPC.
Mate Prgin
Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.