{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/colorado",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/colorado.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/colorado",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/colorado/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/colorado/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "colorado",
    "frontmatter": {
      "title": "Colorado Consumer Privacy Law (CPA)",
      "description": "The Colorado Privacy Act gives Colorado consumers rights over their personal data and imposes notice, universal-opt-out, contracting, and consent duties on controllers above defined thresholds — it reaches nonprofits, is enforced by the Attorney General and district attorneys, has no cure period, and provides no private right of action.",
      "state": "Colorado",
      "lastReviewed": "2026-06-04",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Colo. Rev. Stat. §§ 6-1-1301 et seq. (Colorado Privacy Act)",
        "appliesTo": "Controllers doing business in Colorado (or targeting Coloradans) that control or process the data of 100,000+ consumers a year, 25,000+ while deriving revenue from selling data, or any amount of biometric identifiers or biometric data — nonprofits included; no revenue floor",
        "privacyPolicyRequired": "Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents",
        "privateRightOfAction": "No — the statute bars any private right of action",
        "regulator": "Colorado Attorney General and district attorneys",
        "bottomLine": "If you do business in Colorado and meet the 100,000-consumer, 25,000 plus data-sale, or biometric-data threshold — nonprofits included — the CPA requires applicable privacy safeguards, enforced by the Attorney General with no consumer lawsuits and no cure period.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "no",
        "sensitiveDataConsent": "optIn",
        "universalOptOutSignal": "required"
      },
      "about": [
        "Colorado Privacy Act CPA",
        "Colorado privacy policy requirements",
        "Colorado privacy notice contents",
        "CPA applicability thresholds nonprofits",
        "Colorado universal opt-out mechanism",
        "CPA processor contract requirements",
        "Colorado Attorney General privacy enforcement",
        "CPA no private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-cpa-apply",
        "label": "Does the Colorado Privacy Act apply to your business?",
        "heading": "Does the Colorado Privacy Act apply to your business?",
        "answerText": "It depends on data volume, not a general revenue floor — and unlike most states, nonprofits are not exempt. The CPA applies to a controller that does business in Colorado or targets Colorado residents and meets one of three thresholds: controlling or processing the personal data of 100,000 or more consumers in a year; controlling or processing 25,000 or more consumers' data while deriving revenue (or a discount) from selling personal data; or controlling or processing any amount of biometric identifiers or biometric data. A controller that qualifies only through the biometric trigger must comply only for the biometric identifiers or biometric data it collects and processes.",
        "sources": [
          {
            "id": "stat-1304-apply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Colo. Rev. Stat. § 6-1-1304",
            "citation": "Colo. Rev. Stat. § 6-1-1304(1).",
            "url": "https://olls.info/crs/crs2025-title-06.pdf",
            "proposition": "The CPA applies to a controller that conducts business in Colorado or targets Colorado residents and meets a 100,000-consumer threshold, a 25,000-consumer threshold while deriving revenue from selling personal data, or a biometric-data threshold; biometric-only controllers have correspondingly limited duties.",
            "verbatimQuote": "This part 13, other than sections 6-1-1305.5, 6-1-1308.5, and 6-1-1309.5, applies to a controller that: (I) (A) Conducts business in Colorado or produces or delivers commercial products or services that are intentionally targeted to residents of Colorado; and (B) Satisfies one or both of the following thresholds: controls or processes the personal data of one hundred thousand consumers or more during a calendar year; or derives revenue or receives a discount on the price of goods or services from the sale of personal data and processes or controls the personal data of twenty-five thousand consumers or more; or (II) Controls or processes any amount of biometric identifiers or biometric data regardless of the amount of biometric identifiers or biometric data controlled or processed annually; except that a controller that meets the qualifications of this subsection (1)(b) but does not meet the qualifications of subsection (1)(a) of this section shall comply with this part 13 only for the purposes of a biometric identifier or biometric data that the controller collects and processes;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/colorado#src-stat-1304-apply"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Colorado privacy policy contain?",
        "heading": "What must your Colorado privacy policy contain?",
        "answerText": "The CPA imposes a duty of transparency: a controller must give consumers a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed, the purposes of processing, how to exercise and appeal consumer rights, the categories shared with third parties, and the categories of third parties.",
        "sources": [
          {
            "id": "stat-1308-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Colo. Rev. Stat. § 6-1-1308",
            "citation": "Colo. Rev. Stat. § 6-1-1308(1)(a).",
            "url": "https://olls.info/crs/crs2025-title-06.pdf",
            "proposition": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed, the purposes of processing, how consumers may exercise and appeal their rights, the categories of personal data shared with third parties, and the categories of those third parties.",
            "verbatimQuote": "A controller shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes: (I) The categories of personal data collected or processed by the controller or a processor; (II) The purposes for which the categories of personal data are processed; (III) How and where consumers may exercise the rights pursuant to section 6-1-1306, including the controller's contact information and how a consumer may appeal a controller's action with regard to the consumer's request;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/colorado#src-stat-1308-notice"
          },
          {
            "id": "stat-1308-optout-disclosure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Colo. Rev. Stat. § 6-1-1308",
            "citation": "Colo. Rev. Stat. § 6-1-1308(1)(b).",
            "url": "https://content.leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf",
            "proposition": "If a controller sells personal data or processes it for targeted advertising, the privacy notice must clearly and conspicuously disclose that sale or processing and the manner in which a consumer may opt out.",
            "verbatimQuote": "If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose the sale or processing, as well as the manner in which a consumer may exercise the right to opt out of the sale or processing.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/colorado#src-stat-1308-optout-disclosure"
          },
          {
            "id": "stat-1308-sensitive-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Colo. Rev. Stat. § 6-1-1308",
            "citation": "Colo. Rev. Stat. § 6-1-1308(7).",
            "url": "https://content.leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf",
            "proposition": "A controller may not process a consumer's sensitive data without first obtaining consent, or, for the personal data of a known child, consent from the child's parent or lawful guardian.",
            "verbatimQuote": "A controller shall not process a consumer's sensitive data without first obtaining the consumer's consent or, in the case of the processing of personal data concerning a known child, without first obtaining consent from the child's parent or lawful guardian.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/colorado#src-stat-1308-sensitive-consent"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with processors say?",
        "heading": "What must your contracts with processors say?",
        "answerText": "Processing by a processor must be governed by a binding contract between the controller and the processor — so a data processing agreement is a statutory requirement. The contract must set out the processing instructions, including the nature and purpose of the processing.",
        "sources": [
          {
            "id": "stat-1305-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Colo. Rev. Stat. § 6-1-1305",
            "citation": "Colo. Rev. Stat. § 6-1-1305(5).",
            "url": "https://content.leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf",
            "proposition": "Processing by a processor must be governed by a binding contract that sets out the processing instructions; the type of personal data and duration of processing; the statutory requirements imposed on the processor; a duty to delete or return the data at the controller's direction; a duty to make available information needed to demonstrate compliance; and a right to reasonable audits, or, alternatively, an annual independent audit report.",
            "verbatimQuote": "Processing by a processor must be governed by a contract between the controller and the processor that is binding on both parties and that sets out: (a) The processing instructions to which the processor is bound, including the nature and purpose of the processing; (b) The type of personal data subject to the processing, and the duration of the processing; (c) The requirements imposed by this subsection (5) and subsections (3) and (4) of this section; and (d) The following requirements: (I) At the choice of the controller, the processor shall delete or return all personal data to the controller as requested at the end of the provision of services, unless retention of the personal data is required by law; (II) (A) The processor shall make available to the controller all information necessary to demonstrate compliance with the obligations in this part 13; and (B) The processor shall allow for, and contribute to, reasonable audits and inspections by the controller or the controller's designated auditor. Alternatively, the processor may, with the controller's consent, arrange for a qualified and independent auditor to conduct, at least annually and at the processor's expense, an audit of the processor's policies and technical and organizational measures in support of the obligations under this part 13 using an appropriate and accepted control standard or framework and audit procedure for the audits as applicable. The processor shall provide a report of the audit to the controller upon request.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/colorado#src-stat-1305-contract"
          }
        ]
      },
      {
        "slug": "universal-opt-out",
        "label": "Must you honor a universal opt-out signal?",
        "heading": "Must you honor a universal opt-out signal?",
        "answerText": "Yes. This is where Colorado is stricter than many states: since July 1, 2024, a controller that processes personal data for targeted advertising or sells it must let consumers opt out through a user-selected universal opt-out mechanism that meets the technical specifications the Attorney General has adopted.",
        "sources": [
          {
            "id": "stat-1306-uoom",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Colo. Rev. Stat. § 6-1-1306",
            "citation": "Colo. Rev. Stat. § 6-1-1306(1)(a)(IV)(B).",
            "url": "https://content.leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf",
            "proposition": "Since July 1, 2024, a controller that processes personal data for targeted advertising or sells it must allow consumers to opt out through a user-selected universal opt-out mechanism meeting the Attorney General's technical specifications.",
            "verbatimQuote": "a controller that processes personal data for purposes of targeted advertising or the sale of personal data shall allow consumers to exercise the right to opt out of the processing of personal data concerning the consumer for purposes of targeted advertising or the sale of personal data pursuant to subsections (1)(a)(I)(A) and (1)(a)(I)(B) of this section by controllers through a user-selected universal opt-out mechanism that meets the technical specifications established by the attorney general pursuant to section 6-1-1313.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/colorado#src-stat-1306-uoom"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business under the CPA?",
        "heading": "Can a consumer sue your business under the CPA?",
        "answerText": "No. The CPA states that nothing in it provides a basis for a private right of action, so consumers cannot sue under it. Enforcement belongs exclusively to the Colorado Attorney General and district attorneys.",
        "sources": [
          {
            "id": "stat-1311-nopra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Colo. Rev. Stat. § 6-1-1311",
            "citation": "Colo. Rev. Stat. § 6-1-1311(1)(b).",
            "url": "https://content.leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf",
            "proposition": "The CPA bars any private right of action for its violation.",
            "verbatimQuote": "nothing in this part 13 shall be construed as providing the basis for, or being subject to, a private right of action for violations of this part 13 or any other law.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/colorado#src-stat-1311-nopra"
          },
          {
            "id": "stat-1311-enforce",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Colo. Rev. Stat. § 6-1-1311",
            "citation": "Colo. Rev. Stat. § 6-1-1311(1)(a).",
            "url": "https://content.leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf",
            "proposition": "The Attorney General and district attorneys have exclusive authority to enforce the CPA.",
            "verbatimQuote": "the attorney general and district attorneys have exclusive authority to enforce this part 13 by bringing an action in the name of the state or as parens patriae on behalf of persons residing in the state to enforce this part 13 as provided in this article 1, including seeking an injunction to enjoin a violation of this part 13.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/colorado#src-stat-1311-enforce"
          }
        ]
      }
    ]
  }
}
