Consumer Data Privacy

Colorado Consumer Data Privacy Law: Thresholds, Consumer Rights & Deadlines

What Colorado’s consumer data privacy law requires, maintained by Stauss PLLC. Last reviewed July 2026.

What You Need to Know

Colorado was the third state to pass a consumer data privacy law, and the first to require controllers to recognize universal opt-out mechanisms and to decline to exempt nonprofits and HIPAA-covered entities. The law required the Colorado Attorney General's office to promulgate interpretive rules, which are important to review when analyzing the law's requirements. The law has been amended several times. Of note, it was amended to add biometric privacy provisions that, in some circumstances, extend to employee data, and to add heightened protections for minors, including a duty of care.

Official law text
Who the law applies to
ThresholdRequirement
Main Provisions
Annual gross revenueN/A
Consumers whose data is processed100,000 consumers 1.72% of state's 5.8 million population
Revenue from sale of personal dataDerives revenue or receives a discount on the price of goods or services from the sale of personal data and processes or controls the personal data of 25,000 or more consumers.
Biometric Privacy Provisions
Annual gross revenue
Consumers whose data is processed
Revenue from sale of personal data
Other conditions
  • Controllers that control or process any amount of biometric identifiers or data, except that controllers who do not meet CPA thresholds shall comply with CPA only for the purposes of a biometric identifier or data that controller collects and processes. Right to access only applies to a sole proprietorship, partnership, LLC, corporation, association, or another legal entity that (1) conducts business in Colorado or produces or delivers commercial products or services that are marketed to Colorado residents; (2) collects biometric data or has biometric data collected on its behalf; and (3) either collects or processes the personal data of 100,000 or more individuals (not consumers) during a calendar year or collects and processes the personal data of 25,000 or more individuals and derives revenue from, or receives a discount on the price of goods or services from, the sale of data.
Children's Privacy Provisions
Annual gross revenue
Consumers whose data is processed
Revenue from sale of personal data
Other conditions
  • Controllers that conduct business in Colorado or deliver commercial products or services that are intentionally targeted to Colorado residents and that offer an online service, product, or feature to consumers whom the entity actually knows or willfully disregards are minors.
Consumer rights under Colorado's law15
RightProvided?
KnowYes
AccessYes
Obtain list of third parties to which personal data was disclosedNo
Data portabilityYes
DeleteYes
Correct inaccuraciesYes
Not be discriminated against for exercising rightsYes
Opt-out of saleYes
Opt-out of targeted advertising/sharingYes
Opt-out of certain types of profilingYes
Opt-out of ADMTNo
Recognize opt-out signalsYes
Revoke consent
noteRight provided through rulemaking.
Yes
Not process data in discriminatory mannerNo
AppealYes

Tracking Colorado’s privacy law? We write about it as the law changes.

Subscribe →
Categories treated as sensitive data11
  • Racial or ethnic origin
  • Religious beliefs
  • Mental or physical health diagnosis
  • Mental or physical health condition
  • Sexual orientation
  • Sex life
  • Citizenship or citizenship status
  • Genetic or biometric data for purposes of uniquely identifying an individual
  • Personal data of known child
  • Precise geolocation
    noteConnecticut, Maryland, Oregon, and Virginia ban the sale of precise geolocation data.
  • Biological data (including neural data)
    note“Biological data” means data generated by the technological processing, measurement, or analysis of an individual's biological, genetic, biochemical, physiological, or neural properties, compositions, or activities or of an individual's body or bodily functions, which data is used or intended to be used, singly or in combination with other personal data, for identification purposes. “Biological data” includes neural data.
How sensitive data must be treated4
  • Obtain Consent to Process
    notePursuant to Colorado Privacy Act Rule 7.08, controllers must refresh consent for consumers who have not interacted with the controller within the prior 24 months.
  • Obtain Consent to Process Sensitive Data Inferences
    notePursuant to Colorado Privacy Act Rule 6.10, controllers must obtain consent to process sensitive data inferences, which are inferences made by a controller based on personal data, alone or in combination with other data, which are used to indicate an individual's racial or ethnic origin; religious beliefs; mental or physical health condition or diagnosis; sex life or sexual orientation; or citizenship or citizenship status.
  • Must Obtain Consent to Sell Sensitive Data
  • Conduct Data Protection or Risk Assessment
Requirements for minors' data4
  • Process personal data of children under 13 in accordance with COPPA or parental/legal guardian consent
  • Opt-in to sell personal data, engage in targeted advertising, or profile for consequential decisions for children under 18
  • Creates requirements for collection of precise geolocation of children under 18
  • Duty of care to avoid heightened risk of harm to children under 18 years of age
Activities that trigger a risk or impact assessment6
  • Targeted advertising (“sharing”)
  • Sale of personal data
  • Processing of sensitive data
  • Processing personal data for purposes of profiling where it presents reasonably foreseeable risk of unfair or deceptive treatment of, or unlawful disparate impact on, consumers; financial, physical, or reputational injury to consumers; physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where such intrusion would be offensive to a reasonable person; other subject injury to consumers
    noteColorado and New Jersey’s law do not include “reputational” injury.
  • Any processing activities involving personal data that present a heightened risk of harm to consumers
  • Processing personal data of minors (under 18 years of age) in a manner that presents reasonably foreseeable risk that could cause: (1) unfair or deceptive treatment of, or unlawful disparate impact on, minors; (2) financial, physical, or reputational injury to minors; (3) unauthorized disclosure of personal data of minors as result of security breach, as defined in state law; or (4) physical or other intrusion upon solitude or seclusion, or private affairs or concerns, of minors if intrusion would be offensive to reasonable person
Other notable provisions11
  • Definition of “Sale” Includes “Other Valuable Consideration”
  • Opt-out Request Can Be Verified
  • Applies to Nonprofits
  • Data Processing Agreements
  • Privacy Policy
  • Duty of Purpose Specification
  • Implement Reasonable Data Security Measures
  • Duty to Avoid Secondary Use
  • Data Minimization
  • Attorney General Enforcement
  • Rulemaking
Key dates2
DateWhat happens
July 1, 2023Colorado's consumer data privacy law takes effect
December 31, 2026Right to cure for Colorado's children's privacy law amendments expires

Questions about Colorado’s privacy law?

Stauss PLLC advises companies on state privacy, AI, and data broker compliance.

Contact Stauss PLLC

Follow Colorado’s privacy law

Our analysis, by email, as the law moves.

Subscribe

This page is provided for general informational purposes only, is not legal advice, and does not create an attorney-client relationship. State laws change frequently; coverage reflects this tool’s most recent update. Contact Stauss PLLC to confirm how these requirements apply to your organization.