Key Takeaways
- The Colorado Privacy Act applies to businesses processing 100,000+ Colorado consumers' data per year, or 25,000+ if the business also earns revenue from selling that data. There's no revenue threshold on its own.
- Violations are penalized at up to $20,000 per violation, not $5,000 as some guides claim, since CPA violations are enforced as deceptive trade practices under Colorado's broader Consumer Protection Act.
- The CPA's 60-day cure period expired on January 1, 2025 and was never renewed. Businesses facing enforcement today get no advance notice-and-fix window.
- There is no private right of action under the CPA. Only Colorado's Attorney General and district attorneys can bring an enforcement action; individuals cannot sue directly under this law.
- Colorado requires businesses to honor a universal opt-out mechanism, letting a consumer opt out of sale and targeted advertising across every site at once, not just through a single site's own preference center.
- Two recent amendments add real obligations: SB 24-041 (effective October 1, 2025) restricts collecting minors' precise geolocation and addictive design features, and SB 25-276 (2025) added precise geolocation to the sensitive-data category for everyone, requiring opt-in consent to collect it.
The Colorado Privacy Act (CPA) applies once a business processes 100,000 or more Colorado consumers' personal data in a year, or 25,000 or more if it also earns revenue from selling that data, and violations carry a penalty of up to $20,000 each. Most compliance guides get at least one of the CPA's specifics wrong, whether that's the actual penalty figure, whether a cure period still exists, or which businesses are exempt entirely. Below: exactly who's in scope, what rights Colorado consumers actually have, and what enforcement looks like now that the law's grace period has expired.
Secure Privacy is a cookie and consent management platform that generates CPA-compliant consent flows, including the opt-out mechanisms Colorado requires, alongside GDPR, CCPA, and 55+ other privacy laws.
Who Does the Colorado Privacy Act Apply To?
The CPA applies to any business that conducts business in Colorado, or produces or delivers commercial products or services intentionally targeted to Colorado residents, and that meets one of two thresholds: controlling or processing the personal data of 100,000 or more Colorado consumers in a calendar year, or controlling or processing the data of 25,000 or more Colorado consumers while also deriving revenue (or a discount on goods or services) from selling personal data. Unlike some other state privacy laws, the CPA sets no separate revenue threshold of its own, so a small business can fall in scope purely on consumer-count grounds if it processes enough data.
A specific set of entities and data types sit outside the CPA regardless of scale: entities already regulated under COPPA, FERPA, GLBA, HIPAA, or the FCRA, and higher-education institutions, are exempt from CPA obligations for the data those other frameworks already govern. That exemption list is easy to get wrong by omission, since some summaries drop the higher-education carve-out entirely. One exemption that doesn't exist is also worth stating directly: unlike the CCPA's approach in California, the CPA does not generally exempt nonprofit organizations, so a nonprofit meeting the consumer-count thresholds is in scope the same as a for-profit business.
What Rights Do Colorado Consumers Have?
Colorado consumers can know what personal data a business holds about them, access it, correct inaccuracies, delete it, and obtain a portable copy, the last of which they can exercise up to twice a year at no cost. They can also opt out of targeted advertising, the sale of their data, and profiling that produces legal or similarly significant effects, such as decisions about credit, employment, or housing.
Businesses have 45 days to respond to a consumer rights request, with one 45-day extension available for complex or numerous requests. Since July 1, 2024, businesses subject to the CPA also have to honor a universal opt-out mechanism: a browser- or device-level signal a consumer sets once, which then has to be treated as a valid opt-out request across every site that consumer visits, rather than requiring them to click through a separate preference center on each one.
What Changed in 2024 and 2025?
Two amendments added real, current obligations that a lot of "complete guides" still don't reflect. SB 24-041, signed May 31, 2024 and effective October 1, 2025, added children's-privacy protections: businesses can't collect a minor's precise geolocation data except in narrow circumstances, can't use system-design features built to significantly increase, sustain, or extend a minor's use of a product, and face new age-appropriate design obligations for consumers 13 to 17. SB 25-276, signed in May 2025, went further for the general population: it added precise geolocation data to the CPA's sensitive-data category outright, which means collecting it now requires the same opt-in consent standard sensitive data already carried, not just a disclosure.
Sensitive data generally, precise geolocation now included, requires opt-in consent before collection, a higher bar than the opt-out standard that governs ordinary personal data and targeted advertising. Businesses also have to practice data minimization: collecting only what's reasonably necessary for the disclosed purpose and not retaining it longer than that purpose requires, and any contract with a data processor has to include specific terms (a data processing agreement) covering the processor's obligations, confidentiality, and how data gets deleted or returned at the end of the relationship.
When Is a Data Protection Impact Assessment (DPIA) Required?
The CPA requires a DPIA before starting any processing activity that presents a heightened risk of harm to consumers, which includes processing for targeted advertising, selling personal data, certain profiling, and processing sensitive data categories like precise geolocation, biometric data, or data revealing racial or ethnic origin, religious beliefs, or health status. A DPIA has to weigh the benefits of the processing against its risks to consumers, factoring in safeguards already in place, and the assessment has to exist before the processing starts, not be written up afterward to justify something already underway.
What Are the Penalties for Violating the CPA?
CPA violations are enforced as deceptive trade practices under the broader Colorado Consumer Protection Act, which caps civil penalties at $20,000 per violation, with each affected consumer or transaction typically counted separately. Only the Colorado Attorney General and district attorneys can bring an enforcement action; the CPA does not create a private right of action, so an individual consumer cannot sue a business directly under this law, regardless of what a demand letter might imply.
One detail changed recently enough that older content gets it wrong by omission: the CPA originally gave businesses a 60-day cure period, a window to fix a violation after notice before a fine could be imposed. That provision included its own sunset clause and expired on January 1, 2025. It was never renewed. A business facing a CPA enforcement action today doesn't get that advance notice-and-fix opportunity the way an early CPA violator might have in 2023 or 2024.
How Does the CPA Compare to Other State Privacy Laws?
The CPA sits in the same general family as the CCPA/CPRA, Virginia's VCDPA, and similar state laws: opt-out based rather than opt-in based for general processing, with heightened requirements (explicit consent, DPIAs) layered on top for sensitive data and high-risk processing specifically. The practical difference that trips up multi-state compliance programs is the threshold math: Colorado's 100,000-consumer bar is lower than some other states', which means a business that's out of scope for a neighboring state's law can still be squarely in scope for Colorado's.
A consent management platform built to handle multiple state frameworks at once, rather than a single-state patchwork of separate banners and opt-out flows, is what actually makes a universal opt-out signal workable across Colorado, California, and every other state a business operates in simultaneously. Secure Privacy covers the CPA alongside CCPA/CPRA and other state frameworks from a single consent record, so a Colorado opt-out and a California opt-out don't have to be built, tested, and maintained as two separate systems.
FAQ
Does the Colorado Privacy Act apply to small businesses?
It can. The CPA has no separate revenue threshold, so a business processing 100,000 or more Colorado consumers' data in a year, or 25,000 or more while selling that data, is in scope regardless of company size or revenue.
What is the penalty for violating the Colorado Privacy Act?
Up to $20,000 per violation, enforced under the Colorado Consumer Protection Act's civil penalty provision, since CPA violations are treated as deceptive trade practices. Only the Attorney General and district attorneys can bring these actions.
Can individuals sue under the Colorado Privacy Act?
No. The CPA does not create a private right of action. Enforcement is exclusively handled by Colorado's Attorney General and district attorneys.
Does Colorado still give businesses a chance to fix a violation before being fined?
No, not anymore. The CPA's 60-day cure period expired on January 1, 2025, under its own built-in sunset clause and was never renewed.
What is a universal opt-out mechanism under the CPA?
A signal, typically set once at the browser or device level, that a business must honor as a valid opt-out of data sale and targeted advertising across every site the consumer visits, rather than requiring a separate opt-out action on each individual site. This has been mandatory since July 1, 2024.
Are higher-education institutions exempt from the CPA?
Yes, along with entities already regulated under COPPA, FERPA, GLBA, HIPAA, or the FCRA, for the data those frameworks already cover.
Are nonprofits exempt from the Colorado Privacy Act?
No. Unlike California's CCPA, the CPA does not generally exempt nonprofit organizations. A nonprofit that meets the consumer-count thresholds is in scope the same as any for-profit business.
What did SB 24-041 and SB 25-276 change?
SB 24-041 (effective October 1, 2025) added minors-specific protections: restrictions on collecting a minor's precise geolocation and a ban on addictive design features aimed at extending a minor's use. SB 25-276 (2025) separately added precise geolocation data to the CPA's sensitive-data category for all consumers, requiring opt-in consent to collect it.




