The Colorado Privacy Act applies to businesses that process personal data of at least 100,000 Colorado consumers a year, or 25,000 consumers if the business derives revenue from selling personal data. It was the first state law to make recognition of universal opt-out mechanisms mandatory.
What the Colorado Privacy Act Requires
Covered controllers must post a privacy notice, honor rights to access, correct, delete, and port personal data, offer opt-outs for targeted advertising, sale, and significant profiling, get opt-in consent for sensitive data, and run data protection assessments for higher-risk processing. Since July 1, 2024, covered sites must treat signals like the Global Privacy Control as a valid opt-out from targeted advertising and sale.
Enforcement and Penalties
Violations are deceptive trade practices enforced by the Attorney General and district attorneys, with penalties up to $20,000 per violation. The right-to-cure period expired January 1, 2025, so enforcers no longer have to offer businesses a chance to fix problems before bringing an action.
Source: Colorado General Assembly: SB 21-190, C.R.S. 6-1-1301 et seq.
Report a violation: If you believe a business is violating this law, you can file a complaint with the Colorado Attorney General Consumer Protection Section.