Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Solutions / CPA · Colorado
COLORADO PRIVACY ACT · UNIVERSAL OPT-OUT

Colorado made the universal opt-out mandatory.

The Colorado Privacy Act requires covered controllers to recognize approved Universal Opt-Out Mechanisms, including Global Privacy Control, for the sale of personal data and targeted advertising. Colorado also requires affirmative consent for sensitive-data processing, consumer-rights and appeals workflows, data protection assessments for high-risk processing, and additional protections for biometric information and minors. Captain Compliance helps operationalize these requirements and document how privacy choices are applied.

Universal Opt-Out honoredOpt-in sensitive dataAG + DA enforcement

The state that made the signal compulsory.

$20,000
Per violation

CPA violations are enforced as deceptive trade practices under the Colorado Consumer Protection Act. Each affected consumer or transaction may constitute a separate violation. The Colorado Attorney General and district attorneys enforce the CPA; there is no private right of action, and the original generally applicable mandatory 60-day cure period expired January 1, 2025.

UOOM
Must be honored

Covered controllers have been required to honor recognized Universal Opt-Out Mechanisms since July 1, 2024. Global Privacy Control is currently the only mechanism on Colorado’s recognized list.

Opt-in
Sensitive data

Obtain affirmative, freely given, specific, informed, and unambiguous consent before processing sensitive data. For personal data from a known child under 13, obtain verifiable parental or legal-guardian consent.

Assessments
For high-risk processing

Data protection assessments are required before targeted advertising, the sale of personal data, sensitive-data processing, and qualifying profiling.

Honor the signal, document the rest.

Colorado’s distinctive requirement is the universal opt-out. We detect it, apply it, and support it with the consent, rights, and assessment workflow the CPA expects.

U

Universal opt-out

Detect and honor Global Privacy Control—currently Colorado’s only approved UOOM—for the sale of personal data and targeted advertising. Maintain the preference for the associated browser or device, and for the consumer when known, unless the consumer later provides valid consent.

C

Sensitive-data opt-in

Obtain affirmative, freely given, specific, informed, and unambiguous consent before processing sensitive data. For personal data from a known child under 13, obtain verifiable parental or legal-guardian consent.

D

Consumer rights

Confirmation, access, correction, deletion, portability, and opt-outs for sale, targeted advertising, and qualifying profiling—with authentication, appeal handling, and documented response deadlines. Controllers generally must respond within 45 days, with one additional 45-day extension when reasonably necessary. Denied requests include appeal instructions, and denied appeals include a way to contact the Colorado Attorney General.

A

Data protection assessments

Conduct and retain data protection assessments before processing activities that present a heightened risk of harm, including targeted advertising, the sale of personal data, sensitive-data processing, and qualifying profiling. Assessments should be updated when material changes alter the risk and retained for the life of the activity plus at least three years.

N

Privacy notice

Generate and maintain clear CPA disclosures covering data categories, processing purposes, third-party sharing, consumer rights, appeal instructions, opt-out methods, controller contact information, and the notice’s last-updated date. Supports the controller’s transparency obligations, including a clear and conspicuous opt-out method outside the notice where data is sold or used for targeted advertising.

R

Consent refresh

When a consumer has not interacted with the controller for 24 months, refresh consent before continuing sensitive-data processing or certain secondary-use profiling—unless the consumer has an always-available, user-controlled interface for updating the applicable preferences. Obtain new consent when the processing purpose materially changes into a secondary use.

M

Minor-data controls

For online services, products, or features offered to consumers known—or willfully disregarded—to be under 18, apply age-appropriate consent, data-minimization, retention, targeted-advertising, sale, profiling, precise-geolocation, and system-design controls. Colorado’s enhanced minor protections took effect October 1, 2025 and can apply regardless of the ordinary CPA thresholds; consent generally must come from the minor, or from a parent or legal guardian when the minor is under 13.

B

Biometric governance

Manage the policies, notices, consent records, and workflows required for biometric governance, including a documented retention schedule, deletion requirements, security-incident protocol, access and correction workflows, and restrictions on disclosure and sale. Colorado’s biometric provisions took effect July 1, 2025 and may apply to controllers processing even one biometric identifier, regardless of the ordinary CPA volume thresholds.

One signal framework, jurisdiction-specific execution.

Several state privacy laws require businesses to recognize browser-level opt-out preference signals, but their definitions, covered purposes, technical requirements, and effective dates differ. Captain Compliance detects signals such as GPC and applies the appropriate opt-out logic based on the consumer’s jurisdiction and the controller’s configured obligations.

Book a Colorado Privacy Act review
Illustrative rollout · timing varies by controller
  • Day 1 — GPC detection and Colorado opt-out handling configured
  • Week 1 — Sensitive-data and biometric consent workflows mapped
  • Week 2 — Consumer-rights, authentication, appeal, and 45-day response workflows deployed
  • Week 3 — High-risk processing and minor-data assessments documented
  • Ongoing — Consent status, rights-request records, processing changes, and Colorado’s UOOM list monitored

What changes when the CPA program is on.

Without a program
  • Browser opt-out signals ignored
  • Sensitive data processed with no consent
  • No assessments for targeted advertising, data sales, sensitive data, or qualifying profiling
  • Opt-out methods missing from the notice
  • Rights requests handled ad hoc
  • Rights denials have no appeal workflow
  • Minor-data protections are not operationalized
  • Biometric identifiers lack notice, consent, retention, and deletion controls
With Captain Compliance
  • UOOM / GPC recognized and applied
  • Opt-in captured before sensitive processing
  • Assessments completed, reviewed, approved, and retained for high-risk processing
  • Opt-out methods documented in the notice
  • 45-day rights workflow with receipts
  • Rights requests, denials, and appeals documented
  • Minor-data safeguards and assessments operationalized
  • Biometric notice, consent, retention, and deletion workflows maintained

Colorado Privacy Act, answered plainly.

What is the Universal Opt-Out Mechanism?+
A Universal Opt-Out Mechanism is a browser- or device-level method through which a consumer communicates an opt-out preference. Under the Colorado Privacy Act, a recognized UOOM may exercise the consumer’s rights to opt out of targeted advertising, the sale of personal data, or both. Covered controllers have been required to honor recognized mechanisms since July 1, 2024. Global Privacy Control is currently the only mechanism on Colorado’s recognized list.
How does the CPA differ from Virginia’s law?+
They’re close cousins, but Colorado mandates the universal opt-out mechanism and its rules are more detailed on consent and assessments. The AG also issued substantial rulemaking. The consent and rights engine is shared; we apply Colorado’s specifics on top.
What penalties does Colorado impose?+
CPA violations are enforced as deceptive trade practices under the Colorado Consumer Protection Act, with civil penalties of up to $20,000 per violation, and each affected consumer or transaction may count separately. The Colorado Attorney General and district attorneys enforce the CPA, which does not create a private right of action.
Do we need to re-collect consent periodically?+
Not for every processing activity. Colorado generally requires refreshed consent when a consumer has not interacted with the controller for 24 months and the controller wants to continue sensitive-data processing or certain secondary-use profiling. The refresh requirement does not apply in the same way when the consumer has an always-available, user-controlled interface for updating the applicable preferences. New consent is also required when a processing purpose materially evolves into a secondary use.
Who does the Colorado Privacy Act apply to?+
The CPA generally applies to controllers that conduct business in Colorado or intentionally target Colorado residents and either control or process the personal data of at least 100,000 Colorado consumers during a calendar year, or derive revenue or a discount on goods or services from selling personal data and control or process the personal data of at least 25,000 Colorado consumers. Nonprofits may be covered. Special provisions governing minors’ online data and biometric identifiers can apply regardless of these ordinary volume and revenue thresholds.
What counts as sensitive data under the CPA?+
Sensitive data includes personal data revealing racial or ethnic origin, religious beliefs, mental or physical health conditions or diagnoses, sex life or sexual orientation, citizenship or citizenship status, genetic or biometric data used to uniquely identify an individual, and personal data from a known child under 13.
Does the CPA apply to nonprofits?+
Yes. Unlike several other state privacy statutes, the Colorado Privacy Act does not broadly exempt nonprofit organizations. A nonprofit may be covered when it satisfies the law’s applicability requirements. Special biometric and minor-data provisions may also apply below the ordinary volume thresholds.
Does the CPA give consumers a private right of action?+
No. The Colorado Attorney General and Colorado district attorneys enforce the CPA. A CPA violation is treated as a deceptive trade practice, but the statute does not create a private right of action.
What changed in 2025?+
Colorado’s generally applicable mandatory 60-day cure period expired January 1, 2025. Expanded protections for biometric identifiers became effective July 1, 2025, and enhanced protections for the online data of minors became effective October 1, 2025. These newer provisions can apply even when a business does not meet the CPA’s ordinary consumer-volume thresholds.
Does GPC also opt a consumer out of profiling?+
Not automatically under Colorado’s UOOM requirement. Colorado requires recognized UOOMs to communicate opt-outs from targeted advertising, the sale of personal data, or both. Consumers separately have the right to opt out of profiling performed in furtherance of decisions producing legal or similarly significant effects.
Where can I find official Colorado resources?+
Colorado Attorney General — Colorado Privacy Act, Colorado Attorney General — Universal Opt-Out and GPC, Colorado Privacy Act Rules, 4 CCR 904-3, Colorado HB24-1130 — Biometric Identifiers and Data, and Colorado SB24-041 — Privacy Protections for Children’s Online Data. This page provides general information and does not constitute legal advice — applicability and compliance requirements depend on your organization’s data practices, business model, and circumstances.

Make the universal opt-out automatic.

Recognize UOOM and GPC, capture sensitive-data consent, and prove assessments. Start free.

Start free See pricing