Colorado — Comprehensive Law

Colorado Privacy Law

Colorado has done more to extend the reach of a comprehensive privacy statute since enactment than any state except California. Three amendments in successive sessions added biological data — expressly defined to include neural data — to the categories of sensitive data, wrote a standalone biometric chapter at § 6-1-1314 that binds controllers of any volume of biometric identifiers regardless of the Act’s ordinary thresholds, and added a minors’ regime effective October 1, 2025. Colorado was also the first state to require honouring a browser-level opt-out signal, and the Department of Law publishes the list of mechanisms that qualify: as of now it contains one entry. Underneath all of that sits an unusually short breach clock — thirty days to residents and thirty days to the Attorney General — and a penalty schedule that reaches $50,000 per violation where the person harmed is elderly.

The Colorado Privacy Act (CPA)

Part 13 of article 1 of title 6 was added by SB 21-190 and took effect July 1, 2023. Its rights are set out at § 6-1-1306: opt-out of targeted advertising, of the sale of personal data, and of profiling in furtherance of decisions producing legal or similarly significant effects, exercisable through an authorized agent or through a technology indicating the consumer’s intent. Section 6-1-1306(1)(a)(IV)(B) has required since July 1, 2024 that controllers processing personal data for targeted advertising or sale honour a user-selected universal opt-out mechanism meeting the technical specifications the Attorney General adopts under § 6-1-1313. The definition of sensitive data at § 6-1-1303 now reaches four categories, the last of which no other early comprehensive law contained: data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life or sexual orientation, or citizenship status; genetic or biometric data processed to uniquely identify an individual; personal data from a known child; and biological data. Biological data is defined at § 6-1-1303(2.2) as data generated by the technological processing, measurement or analysis of an individual’s biological, genetic, biochemical, physiological or neural properties, compositions or activities, or of the body or bodily functions, used or intended to be used for identification purposes — and the definition states that it “includes neural data”, which § 6-1-1303(16.7) defines as information generated by measuring the activity of an individual’s central or peripheral nervous systems that can be processed by or with the assistance of a device.

Effective dateJuly 1, 2023
CitationC.R.S. § 6-1-1301 et seq. (art. 1, pt. 13)
Enforced byColorado Attorney General and district attorneys
Maximum penaltyUp to $20,000 per violation under C.R.S. § 6-1-112(1)(a), counted separately per consumer or transaction, rising to $50,000 where the violation was committed against an elderly person
Private right of actionNo, enforcement by the state only
Right to cure60 days, repealed January 1, 2025 for the Act generally; a separate 60-day cure for the minors’ sections runs until December 31, 2026

Who Must Comply

The CPA reaches a business that controls or processes the personal data of at least 100,000 Colorado consumers during a calendar year, or derives revenue or receives a discount on goods or services from selling personal data and controls or processes the data of at least 25,000 consumers, and for biometric identifiers or biometric data, any amount — the ordinary numeric thresholds do not gate § 6-1-1314.

Section 6-1-1311(1)(c) makes a CPA violation a deceptive trade practice for enforcement purposes only, which imports the article 1 penalty schedule at § 6-1-112 rather than creating a bespoke one — hence the $20,000 figure, the per-consumer counting rule, and the $50,000 elderly-person tier. Section 6-1-1312 preempts local privacy ordinances outright

Consumer Rights Under the CPA

Residents of Colorado can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Colorado

Biometric identifiers and biometric data (C.R.S. § 6-1-1314)

Section 6-1-1314, added by HB 24-1130 and effective July 1, 2025, applies to a controller that controls or processes any amount of biometric identifiers or biometric data, regardless of volume — the CPA’s 100,000- and 25,000-consumer thresholds do not gate it. “Collect” is defined broadly at subsection (1)(a) to include accessing, assembling, buying, renting, gathering, procuring, receiving or capturing a biometric identifier by any means, online or offline, whether actively or passively received from the consumer or a third party, and including obtaining biometric data by observing the consumer’s behavior. A “biometric identifier” at § 6-1-1303(2.5) is data generated by technological processing, measurement or analysis of a consumer’s biological, physical or behavioral characteristics that can be processed to uniquely identify an individual, and the definition lists a fingerprint, a voiceprint, a scan or record of an eye retina or iris, a facial map, facial geometry or facial template, and other unique biological, physical or behavioral patterns. Subsection (2) requires a written policy establishing a retention schedule, a protocol for responding to a data security incident that may compromise biometric identifiers including a process for notifying consumers under § 6-1-716, and deletion guidelines requiring deletion on or before the earliest of: the date the initial collection purpose has been satisfied; twenty-four months after the consumer last interacted with the controller; or the earliest reasonably feasible date, no more than forty-five days after the controller determines through an at-least-annual review that storage is no longer necessary, adequate or relevant — extendable by up to forty-five further days where complexity and volume make that reasonably necessary. The policy is made public, except where it applies only to current employees, is used solely by employees and agents for the controller’s operation, or is the internal incident-response protocol. Subsection (3) puts a parallel incident-response protocol duty on processors of biometric identifiers, including a process for notifying the controller. “Employee” is defined to include contractors, subcontractors, interns and fellows, so the section’s limits on employer-obtained consent reach beyond payroll staff.

Colorado Consumer Protection Act penalties (C.R.S. § 6-1-112)

Article 1 of title 6 is Colorado’s unfair-practices statute, and § 6-1-112 supplies the penalties that both the CPA and the breach statute borrow. Subsection (1)(a) authorises the Attorney General or a district attorney to seek a civil penalty of not more than $20,000 for each violation, payable to the state general fund, and provides that a violation constitutes a separate violation with respect to each consumer or transaction involved — a counting rule that scales the exposure with the size of the affected population rather than the number of statutory provisions breached. Subsection (1)(b) sets not more than $10,000 for each violation of a court order or injunction, with the issuing court retaining jurisdiction. Subsection (1)(c) raises the ceiling to not more than $50,000 for each violation committed against an elderly person, again counted separately per elderly person involved.

Universal opt-out mechanism rules (4 CCR 904-3, pts. 5 and 6)

Section 6-1-1313(2) directed the Attorney General to adopt, by July 1, 2023, rules detailing the technical specifications for one or more universal opt-out mechanisms that clearly communicate a consumer’s affirmative, freely given and unambiguous choice to opt out of processing for targeted advertising or sale. Those rules are at 4 CCR 904-3, part 5, and rule 5.07 requires the Department of Law to maintain a public list of recognised mechanisms. The Department published the list on January 1, 2024, and controllers within the CPA’s scope have had to honour a listed mechanism since July 1, 2024. Global Privacy Control is currently the only mechanism on it. Rule 6.03(4)(e) governs the corresponding privacy-notice disclosure. The Department states that the list does not preclude other mechanisms from qualifying later and will be updated periodically.

Data Breach Notification in Colorado

Section 6-1-716 runs both clocks at thirty days — to affected residents and, separately, to the Attorney General — and both run from the “determination that a security breach occurred”, which subsection (1)(c) defines as the point at which there is sufficient evidence to conclude that a breach has taken place. The Attorney General duty attaches where the breach is reasonably believed to have affected 500 Colorado residents or more, unless the investigation determines that misuse has not occurred and is not reasonably likely to occur. The definition of personal information at subsection (1)(g) is in three parts. The first is a name plus an unencrypted, unredacted data element, and the list is broader than most: Social Security number; student, military, or passport identification number; driver’s licence or identification card number; medical information; health insurance identification number; or biometric data. The second and third parts drop the name requirement entirely — a username or e-mail address with a password or security question and answer permitting access to an online account, and an account number or card number with the security code, access code or password permitting access. “Biometric data” is defined narrowly for this section, at subsection (1)(a), as unique biometric data generated from measurements or analysis of human body characteristics for the purpose of authenticating an individual when accessing an online account. Substitute notice becomes available where the cost of notice exceeds $250,000, the affected class exceeds 250,000 Colorado residents, or contact information is insufficient. Subsection (5) is unusual: on receipt of a breach notice the Attorney General is given authority to prosecute any criminal violations in the district where a case could be brought.

Residents must be notified in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred. Notify the Colorado Attorney General within thirty days where the breach is reasonably believed to have affected 500 Colorado residents or more. Complaints are taken by the Colorado Attorney General, which enforces the statute.

How the CPA Is Enforced

Two enforcers, and the penalty comes from the consumer-protection article. Section 6-1-1311(1)(a) gives the Attorney General and district attorneys exclusive authority to enforce part 13, by an action in the name of the state or as parens patriae on behalf of persons residing in the state, including an injunction. Subsection (1)(c) then provides that, for purposes of enforcement by those officials only, a violation of part 13 is a deceptive trade practice. That framing is what supplies the remedy: rather than a bespoke schedule, the Act borrows § 6-1-112, with its $20,000-per-violation ceiling, its rule that each consumer or transaction is a separate violation, its $10,000 penalty for violating an injunction, and its $50,000 tier for violations committed against an elderly person. Subsection (2) directs the state treasurer to credit receipts from CPA civil penalties under § 24-31-108.

The office opened with education rather than penalties. On July 12, 2023, days after the Act took effect, the Attorney General announced that the office had sent a series of letters to businesses. The office characterised them as informational rather than as notices of violation — intended to inform businesses of their obligations and direct them to resources — and stated the enforcement posture in the release: “Our enforcement of this important law will not seek to make life challenging for organizations that are complying with the law, but rather will seek to support such efforts”, with a warning that the office would act against organisations flouting the law or refusing to comply.

Recent Enforcement in Colorado

Impact MHC — $25,000 over a ten-month notification delay. On June 14, 2021 the Attorney General announced a settlement with Impact MHC, a Colorado mobile home park management company, over a phishing compromise of employee e-mail accounts that began in October 2018 and to which criminals retained access until July 2019, exposing Social Security numbers and financial details. Of more than 15,000 people affected, 719 were Coloradans. The office alleged both a failure to properly safeguard the information and a failure to notify consumers in time: the company took ten months to notify, against Colorado’s thirty-day requirement. The company paid $25,000 to the Attorney General’s office, with a further $30,000 payable if it fails to implement the required measures, and agreed to create a written information-disposal policy, develop a comprehensive cybersecurity program, and establish an incident response plan.

23andMe — $394,324 to Colorado in the multistate genetic data settlement. On July 14, 2026 the Attorney General announced a multistate settlement of bankruptcy claims against 23andMe over the October 2023 genetic data breach. Colorado’s share of the $18 million multistate payment is $394,324, on behalf of 140,517 affected Coloradans; a separate class-action settlement accounted for $46.75 million. The office framed the matter against the Colorado Privacy Act’s enhanced protections for biometric data, under which companies cannot sell or disclose biometric data without affirmative consumer consent.

Pending Privacy Legislation

Colorado has amended the Privacy Act in three consecutive sessions rather than leaving it as enacted. HB 24-1130, “Privacy of Biometric Identifiers & Data”, sponsored by Representatives Daugherty and Lynch and Senators Hansen and Lundeen, passed the House 60-0 on February 20, 2024 and the Senate 33-0 on April 19, 2024, cleared concurrence 60-2 on April 22, was signed on May 31, 2024, and took effect July 1, 2025; it added § 6-1-1314 and the biometric definitions. SB 24-041, on children’s online data, added § 6-1-1305.5 and companion sections and applies to conduct occurring on or after October 1, 2025; it also introduced the minors-specific 60-day cure at § 6-1-1311(1)(d)(II), which is repealed effective December 31, 2026. The definitions of “biological data” and “neural data” that brought brain-activity measurements inside the sensitive-data category sit at § 6-1-1303(2.2) and (16.7). The Department of Law has stated it is considering further amendments to the Colorado Privacy Act Rules to implement SB 24-041.

Federal Privacy Laws That Apply in Colorado

Federal privacy law applies in Colorado by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The CPA sits alongside those rules rather than displacing them: the Colorado Attorney General and district attorneys enforce the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Colorado Consumer Protection Act penalties (C.R.S. § 6-1-112), which the Colorado Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Colorado Privacy Law FAQ

Does Colorado treat brain data as sensitive data?
Yes, and it says so in terms. Section 6-1-1303 lists “biological data” as a category of sensitive data, defines it at subsection (2.2) as data generated by the technological processing, measurement or analysis of an individual’s biological, genetic, biochemical, physiological or neural properties, compositions or activities, or of the body or bodily functions, used or intended for identification purposes — and states expressly that biological data “includes neural data”. Subsection (16.7) defines neural data as information generated by measuring the activity of an individual’s central or peripheral nervous systems that can be processed by or with the assistance of a device. Because sensitive data requires consent, that places neural data inside the CPA’s opt-in regime.
How long may a Colorado controller retain a biometric identifier?
Section 6-1-1314(2)(a)(III) requires the written policy to mandate deletion on or before the earliest of three dates: the date the initial purpose for collecting the identifier has been satisfied; twenty-four months after the consumer last interacted with the controller; or the earliest reasonably feasible date, which must be no more than forty-five days after the controller determines, through a review conducted at least annually, that storage is no longer necessary, adequate or relevant to the express processing purpose. That forty-five-day period may be extended by up to forty-five additional days where the extension is reasonably necessary given the complexity and number of identifiers to be deleted.
Which universal opt-out signals does Colorado recognise?
One, at present. Rule 5.07 of 4 CCR 904-3 requires the Department of Law to maintain a public list of universal opt-out mechanisms that meet the standards of the Colorado Privacy Act; the Department published it on January 1, 2024 and Global Privacy Control is the only entry. Controllers within the Act’s scope have had to allow consumers to opt out of sale and targeted advertising through a listed mechanism since July 1, 2024. The Department states the list does not preclude other mechanisms from qualifying and will be updated periodically as further mechanisms are evaluated.
Did Colorado’s right to cure expire?
Twice over, and on two different schedules. The original 60-day cure at § 6-1-1311(1)(d) was repealed effective January 1, 2025. SB 24-041 amended subsection (1)(d) effective October 1, 2025, but the editor’s note records that the amendment to (1)(d)(I) never took effect because that provision had already been repealed. What did take effect is subsection (1)(d)(II), a separate 60-day cure that applies only before an enforcement action to enforce §§ 6-1-1305.5, 6-1-1308.5 or 6-1-1309.5 — the minors’ provisions — and that subsection is itself repealed effective December 31, 2026.
What is the maximum penalty under the Colorado Privacy Act?
$20,000 per violation, counted per consumer. Section 6-1-1311(1)(c) makes a CPA violation a deceptive trade practice for enforcement purposes, which imports § 6-1-112. Subsection (1)(a) of that section sets not more than $20,000 for each violation and provides that a violation constitutes a separate violation with respect to each consumer or transaction involved. Subsection (1)(c) raises the ceiling to not more than $50,000 for each violation committed against an elderly person, counted separately per elderly person. Violating a court order or injunction carries a further penalty of not more than $10,000 per violation under subsection (1)(b).
How fast is Colorado’s breach clock?
Thirty days on both legs, which is among the shortest in the country. Section 6-1-716 requires notice to affected Colorado residents in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred, and requires notice to the Attorney General on the same thirty-day standard where the breach is reasonably believed to have affected 500 Colorado residents or more. “Determination that a security breach occurred” is defined as the point at which there is sufficient evidence to conclude that a breach has taken place.
Does Colorado’s breach law reach data without a name attached?
Yes, in two of the three limbs of the definition. Section 6-1-716(1)(g)(I)(A) is the conventional name-plus-element formulation, listing Social Security number, student, military or passport identification number, driver’s licence or identification card number, medical information, health insurance identification number, or biometric data. But subparagraph (B) covers a Colorado resident’s username or e-mail address in combination with a password or security questions and answers permitting access to an online account, and subparagraph (C) covers an account number or credit or debit card number with any required security code, access code or password — neither of which requires a name.
Can a Coloradan sue under the Colorado Privacy Act?
No. Section 6-1-1311(1)(b) provides that nothing in part 13 shall be construed as providing the basis for, or being subject to, a private right of action for violations of the part or any other law, and subsection (1)(a) gives the Attorney General and district attorneys exclusive authority to enforce it, by an action in the name of the state or as parens patriae on behalf of residents. Section 6-1-1312 separately preempts any privacy ordinance a municipality, county, or city and county might adopt regarding the processing of personal data by controllers or processors.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.