Colorado has a comprehensive consumer privacy statute, the Colorado Privacy Act (CPA). This page collects our coverage touching Colorado, alongside the federal rules that apply there. For the statute itself rather than the news, see our Colorado privacy law page.

Automated Decision-Making

Colorado's AI Act and the Consequential Decision: What the Reenacted Part 17 Says

September 7, 2026

Colorado's 2024 artificial intelligence statute was delayed once, then repealed and reenacted before it ever took effect. Senate Bill 26-189, signed May 14, 2026, replaced part 17 of article 1 of title 6 with a framework keyed to automated decision-making technology. Consequential decision survived as the trigger; the algorithmic discrimination duty did not.

Read more →
Adtech & Cookies

Cookie Consent Banner Requirements: What US State Law Actually Says

September 7, 2026

The banner that greets visitors to most American websites is not a creature of American statute. Neither the CCPA nor the Colorado Privacy Act requires one, and the California regulations mention banners chiefly to say when their design is unlawful. This sets out what each statute requires at the point of collection, and when each genuinely calls for consent.

Read more →
AI & Privacy

Automated Decision-Making Under Privacy Law: The Rules That Actually Bind

August 24, 2026

There is no general American law on algorithmic decisions. What exists is a set of narrow regimes reaching them from different directions: California ADMT rules attaching to decisions in named life domains, profiling opt-outs in the state comprehensive statutes, employment statutes imposing audits and notice, and an FTC remedy that reaches the model itself.

Read more →
Biometric Privacy

Biometric Privacy Statutes Outside Illinois, and Who Gets to Enforce Them

August 24, 2026

Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.

Read more →
Consent Management

Opt-Out Preference Signals: What the Law Requires of Consent Management

August 24, 2026

A universal opt-out signal moves the choice from the website to the browser: one setting, broadcast to every site, instead of a banner per visit. Several state statutes now require controllers to honour one. This guide sets out what those statutes and the California regulations say, the conditions on the mechanism, and what two enforcement actions establish about broken opt-out plumbing.

Read more →
Employee Privacy

Employee Privacy Under State Law, in the Order the Statutes Arrived

August 24, 2026

There is no single employee privacy statute in any state. What exists is a stack of laws written decades apart, each aimed at whatever the anxiety of its moment was — a paper file, a tape recorder, a Facebook password, a fingerprint scanner. Read in the order they arrived, the stack explains its own gaps. This guide takes them chronologically rather than by state.

Read more →