Colorado made the universal opt-out mandatory.
The Colorado Privacy Act requires covered controllers to recognize approved Universal Opt-Out Mechanisms, including Global Privacy Control, for the sale of personal data and targeted advertising. Colorado also requires affirmative consent for sensitive-data processing, consumer-rights and appeals workflows, data protection assessments for high-risk processing, and additional protections for biometric information and minors. Captain Compliance helps operationalize these requirements and document how privacy choices are applied.
The state that made the signal compulsory.
CPA violations are enforced as deceptive trade practices under the Colorado Consumer Protection Act. Each affected consumer or transaction may constitute a separate violation. The Colorado Attorney General and district attorneys enforce the CPA; there is no private right of action, and the original generally applicable mandatory 60-day cure period expired January 1, 2025.
Covered controllers have been required to honor recognized Universal Opt-Out Mechanisms since July 1, 2024. Global Privacy Control is currently the only mechanism on Colorado’s recognized list.
Obtain affirmative, freely given, specific, informed, and unambiguous consent before processing sensitive data. For personal data from a known child under 13, obtain verifiable parental or legal-guardian consent.
Data protection assessments are required before targeted advertising, the sale of personal data, sensitive-data processing, and qualifying profiling.
Honor the signal, document the rest.
Colorado’s distinctive requirement is the universal opt-out. We detect it, apply it, and support it with the consent, rights, and assessment workflow the CPA expects.
Universal opt-out
Detect and honor Global Privacy Control—currently Colorado’s only approved UOOM—for the sale of personal data and targeted advertising. Maintain the preference for the associated browser or device, and for the consumer when known, unless the consumer later provides valid consent.
Sensitive-data opt-in
Obtain affirmative, freely given, specific, informed, and unambiguous consent before processing sensitive data. For personal data from a known child under 13, obtain verifiable parental or legal-guardian consent.
Consumer rights
Confirmation, access, correction, deletion, portability, and opt-outs for sale, targeted advertising, and qualifying profiling—with authentication, appeal handling, and documented response deadlines. Controllers generally must respond within 45 days, with one additional 45-day extension when reasonably necessary. Denied requests include appeal instructions, and denied appeals include a way to contact the Colorado Attorney General.
Data protection assessments
Conduct and retain data protection assessments before processing activities that present a heightened risk of harm, including targeted advertising, the sale of personal data, sensitive-data processing, and qualifying profiling. Assessments should be updated when material changes alter the risk and retained for the life of the activity plus at least three years.
Privacy notice
Generate and maintain clear CPA disclosures covering data categories, processing purposes, third-party sharing, consumer rights, appeal instructions, opt-out methods, controller contact information, and the notice’s last-updated date. Supports the controller’s transparency obligations, including a clear and conspicuous opt-out method outside the notice where data is sold or used for targeted advertising.
Consent refresh
When a consumer has not interacted with the controller for 24 months, refresh consent before continuing sensitive-data processing or certain secondary-use profiling—unless the consumer has an always-available, user-controlled interface for updating the applicable preferences. Obtain new consent when the processing purpose materially changes into a secondary use.
Minor-data controls
For online services, products, or features offered to consumers known—or willfully disregarded—to be under 18, apply age-appropriate consent, data-minimization, retention, targeted-advertising, sale, profiling, precise-geolocation, and system-design controls. Colorado’s enhanced minor protections took effect October 1, 2025 and can apply regardless of the ordinary CPA thresholds; consent generally must come from the minor, or from a parent or legal guardian when the minor is under 13.
Biometric governance
Manage the policies, notices, consent records, and workflows required for biometric governance, including a documented retention schedule, deletion requirements, security-incident protocol, access and correction workflows, and restrictions on disclosure and sale. Colorado’s biometric provisions took effect July 1, 2025 and may apply to controllers processing even one biometric identifier, regardless of the ordinary CPA volume thresholds.
One signal framework, jurisdiction-specific execution.
Several state privacy laws require businesses to recognize browser-level opt-out preference signals, but their definitions, covered purposes, technical requirements, and effective dates differ. Captain Compliance detects signals such as GPC and applies the appropriate opt-out logic based on the consumer’s jurisdiction and the controller’s configured obligations.
Book a Colorado Privacy Act review- Day 1 — GPC detection and Colorado opt-out handling configured
- Week 1 — Sensitive-data and biometric consent workflows mapped
- Week 2 — Consumer-rights, authentication, appeal, and 45-day response workflows deployed
- Week 3 — High-risk processing and minor-data assessments documented
- Ongoing — Consent status, rights-request records, processing changes, and Colorado’s UOOM list monitored
What changes when the CPA program is on.
- Browser opt-out signals ignored
- Sensitive data processed with no consent
- No assessments for targeted advertising, data sales, sensitive data, or qualifying profiling
- Opt-out methods missing from the notice
- Rights requests handled ad hoc
- Rights denials have no appeal workflow
- Minor-data protections are not operationalized
- Biometric identifiers lack notice, consent, retention, and deletion controls
- UOOM / GPC recognized and applied
- Opt-in captured before sensitive processing
- Assessments completed, reviewed, approved, and retained for high-risk processing
- Opt-out methods documented in the notice
- 45-day rights workflow with receipts
- Rights requests, denials, and appeals documented
- Minor-data safeguards and assessments operationalized
- Biometric notice, consent, retention, and deletion workflows maintained
Colorado Privacy Act, answered plainly.
What is the Universal Opt-Out Mechanism?+
How does the CPA differ from Virginia’s law?+
What penalties does Colorado impose?+
Do we need to re-collect consent periodically?+
Who does the Colorado Privacy Act apply to?+
What counts as sensitive data under the CPA?+
Does the CPA apply to nonprofits?+
Does the CPA give consumers a private right of action?+
What changed in 2025?+
Does GPC also opt a consumer out of profiling?+
Where can I find official Colorado resources?+
Make the universal opt-out automatic.
Recognize UOOM and GPC, capture sensitive-data consent, and prove assessments. Start free.
Start free See pricing