🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-CO v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing28 sources retrieved model claude-sonnet-5 · 2026-08-04

Colorado, USA

US-CO schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 44 claims · 44 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
6Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 12 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Colorado enacted SB26-189 this cycle, repealing and replacing the original Colorado AI Act (SB24-205) with a new Automated Decision-Making Technology (ADMT) framework. The new law requires deployers of covered ADMT to provide disclosures before use, explain adverse outcomes within 30 days, and offer a path to meaningful human review, effective January 1, 2027. This represents a structural shift in Colorado's algorithmic-governance approach: away from the duty-of-care and risk-management/impact-assessment model of the original AI Act, toward a transparency, disclosure and consumer-rights model centered on individual notice and recourse.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Mature, clearly-scoped statute with an active regulator and settled thresholds; no registration gap materially affects compliance certainty.

Primary frameworkColorado Privacy Act, Colo. Rev. Stat. §§ 6-1-1301 to 6-1-1313
Traffic-light rationale — GreenMature, clearly-scoped statute with an active regulator and settled thresholds; no registration gap materially affects compliance certainty.

Sub-modules (5)

Regulator And AuthorityGreen

The Colorado AG (Department of Law) is the primary CPA regulator; District Attorneys share enforcement authority.

Claims (1):

  • The Colorado Attorney General is the primary regulator and enforcement authority for the Colorado Privacy Act.

Act And InstrumentsGreen

Primary instrument is SB 21-190 (CPA), in force since July 1, 2023, subsequently amended by SB 24-041 and HB 24-1130.

Claims (1):

  • The Colorado Privacy Act (Senate Bill 21-190) was signed into law on July 7, 2021 and became effective July 1, 2023.

Material ScopeGreen

Applies to controllers meeting a 100,000-consumer threshold or a 25,000-consumer-plus-data-sale-revenue threshold, over personal data of Colorado residents.

Claims (1):

  • The CPA applies to controllers conducting business in or targeting Colorado residents that control or process the personal data of 100,000 or more consumers per calendar year, or that derive revenue from data sales and process the data of 25,000 or more consumers.

Territorial ScopeGreen

Extraterritorial application to any controller conducting business in or targeting Colorado residents, irrespective of controller location.

Claims (1):

  • The CPA applies to any controller that conducts business in Colorado or produces/delivers commercial products or services intentionally targeted to Colorado residents, regardless of the controller's own location.

Regulator Registration And FilingAmber

No general controller registration or filing obligation exists under the CPA; the AG instead relies on rulemaking and complaint/enforcement mechanisms.

Absence provenance: unavailable. Searched: Colorado Privacy Act registration requirement, Colorado AG controller filing CPA.

Category narrative65 words

Colorado is governed by the Colorado Privacy Act (CPA), a comprehensive consumer-privacy statute enforced exclusively by the Colorado Attorney General (with District Attorney co-enforcement authority), layered over federal sectoral statutes (HIPAA, GLBA, COPPA, FCRA) that carve out entity- and data-level exemptions. The CPA applies extraterritorially to any controller targeting Colorado residents that meets defined processing-volume or data-sale-revenue thresholds; there is no separate controller registration/filing regime.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedOneTrust DataGuidance — The Colorado Attorney General is the primary regulator and enforcement authority for the Colorado Privacy Act.observed
  2. ConfirmedOneTrust DataGuidance — The Colorado Privacy Act (Senate Bill 21-190) was signed into law on July 7, 2021 and became effective July 1, 2023.observed
  3. ConfirmedOneTrust DataGuidance — The CPA applies to controllers conducting business in or targeting Colorado residents that control or process the personal data of 100,000 or more consumers per calendar year, or that derive revenue from data sales and process the data of 25,000 or more consumers.observed
  4. ConfirmedOneTrust DataGuidance — The CPA applies to any controller that conducts business in Colorado or produces/delivers commercial products or services intentionally targeted to Colorado residents, regardless of the controller's own location.observed

#

Consent and sensitive-data rules are well defined in statute and implementing rules (4 CCR 904-3).

Primary frameworkColorado Privacy Act, Colo. Rev. Stat. § 6-1-1303; CPA Rules 4 CCR 904-3
Traffic-light rationale — GreenConsent and sensitive-data rules are well defined in statute and implementing rules (4 CCR 904-3).

Sub-modules (4)

Lawful BasesGreen

CPA uses an opt-out consent model for standard processing rather than enumerated lawful bases; opt-in consent is mandatory for sensitive data.

Claims (1):

  • Controllers are prohibited from processing sensitive data without first obtaining consumer consent, which must be freely given, specific, informed, and unambiguous.

Special CategoriesGreen

Sensitive data categories include racial/ethnic origin, religious beliefs, mental/physical health, sexual orientation, citizenship status, genetic and biometric data, and neural data (post-HB24-1130).

Claims (1):

  • Colorado's definition of sensitive data includes racial and ethnic origin, religious beliefs, and genetic and biometric data, among other categories.

Pseudonymisation And AnonymisationGreen

The CPA defines pseudonymous data as data that cannot be attributed to a specific individual absent separately-held additional information under technical/organizational safeguards; de-identified data is excluded from personal-data scope entirely.

Claims (1):

  • The CPA defines pseudonymous data as personal data that can no longer be attributed to a specific individual without additional information kept separately under technical and organizational safeguards.
Category narrative57 words

The CPA does not use a GDPR-style enumerated lawful-basis model; instead it relies on an opt-out consent architecture supplemented by mandatory opt-in consent for sensitive/sensitive-inference data and for processing a known child's data. Sensitive categories include racial/ethnic origin, religious beliefs, mental/physical health, sex life/orientation, citizenship status, genetic and biometric data, and (as of HB 24-1130) neural data.

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

Colorado law prohibits collection of biometric identifiers unless the controller obtains consumer consent, and separately prohibits the sale, lease or trade of biometric data outright. These protections, effective July 1, 2025, establish biometric identifiers as a form of special-category data subject to heightened lawful-basis requirements beyond the general Colorado Privacy Act consent and notice framework. This creates a materially higher bar for any Colorado-facing business processing biometric identifiers, such as facial-recognition or fingerprint-based authentication systems, since consent must be affirmatively obtained before collection, and the data cannot enter commercial secondary markets through sale, lease or trade under any circumstance, regardless of consent status for that further transfer.

The consent requirement for biometric collection sits alongside Colorado's broader special-categories framework, which also separately designates precise geolocation data as covered Sensitive Data following SB25-276's May 2025 amendment to CPA Part 13, though that amendment is a stable, previously established baseline feature this cycle rather than a new development.

The biometric-consent finding here is corroborated at Tier-3 practitioner-analysis level and cross-referenced against the effective date of the underlying biometric statute (understood to be HB24-1130), giving it Confirmed-tier confidence despite the absence this cycle of a direct Tier-1 statutory text retrieval.

Outlook

Colorado-facing controllers processing biometric identifiers should ensure consent-capture mechanisms are in place ahead of any collection activity, and should audit any existing data-sharing arrangements involving biometric data to confirm none constitute a prohibited sale, lease or trade under the current framework.

1 earlier distinct update(s)
Periodic update · new data 2026-09-05

Lawful Processing & Special Data

Colorado's rules on sensitive and specially-regulated data categories expanded materially this cycle through two distinct amendments to the Colorado Privacy Act. SB25-276 added precise geolocation data as a category of sensitive data, meaning controllers must now obtain a consumer's prior opt-in consent before processing precise geolocation data, placing it alongside racial or ethnic origin, health data, and biometric data as categories requiring heightened consent under the Act. SB25-276 also clarifies that controllers may not sell precise geolocation data without that same prior opt-in consent, closing a potential gap where consent obtained for processing might otherwise have been read to extend to sale as a downstream use.

Separately, HB24-1130 imposes a distinct lawful-processing-adjacent duty specific to biometric identifiers and biometric data: controllers of such data must adopt a written policy that includes a retention schedule and a data-security-incident-response protocol, effective 2025-07-01. This obligation extends beyond the consumer context into the employment relationship, meaning Colorado employers that collect biometric identifiers, such as fingerprint or facial-recognition data used for workplace access control, fall within the statute's reach even though the underlying data may never be processed for a consumer-facing purpose.

The geolocation and biometric amendments also interact with the Colorado Privacy Act's existing data protection assessment requirement. Processing of sensitive data, including now precise geolocation data, already triggers the requirement to conduct a data protection assessment weighing the benefits of processing against the risks to consumers; controllers that begin treating geolocation data as sensitive under SB25-276 must fold that category into their existing data-protection-assessment practice. Biometric data was already treated as sensitive data under the Colorado Privacy Act prior to this cycle, so HB24-1130's contribution is to layer an additional, freestanding documentation duty on top of the assessment obligation that already applied.

Read together, these two amendments reflect a pattern of category-specific tightening rather than a wholesale rewrite of the Colorado Privacy Act's lawful-processing architecture: the Act's core lawful-basis structure remains unchanged, but the population of data categories requiring heightened consent, and the population of controllers subject to category-specific documentation duties, has both grown. For multistate controllers, the geolocation expansion is notable because it moves Colorado's sensitive-data definition further from a lowest-common-denominator baseline shared uniformly across US state privacy laws.

Outlook

Controllers should expect continued category-specific tightening of Colorado's sensitive-data regime as a plausible pattern going forward, given that this cycle's SB25-276 and HB24-1130 amendments both followed this template rather than reopening the Act's foundational lawful-processing structure. The practical compliance question for the coming cycle is whether the Attorney General's office treats the geolocation opt-in requirement and the biometric retention-and-incident-response policy as areas of active enforcement focus.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy Professionals — Controllers are prohibited from processing sensitive data without first obtaining consumer consent, which must be freely given, specific, informed, and unambiguous.observed
  2. ConfirmedOneTrust DataGuidance — Where personal data concerns a known child, controllers must obtain consent from the child's parent or lawful guardian before processing sensitive data.observed
  3. ConfirmedOneTrust DataGuidance — Colorado's definition of sensitive data includes racial and ethnic origin, religious beliefs, and genetic and biometric data, among other categories.observed
  4. ConfirmedOneTrust DataGuidance — The CPA defines pseudonymous data as personal data that can no longer be attributed to a specific individual without additional information kept separately under technical and organizational safeguards.observed

#

Rights and deadlines are clearly codified and operative since 2023.

Primary frameworkColorado Privacy Act, Colo. Rev. Stat. § 6-1-1306
Traffic-light rationale — GreenRights and deadlines are clearly codified and operative since 2023.

Sub-modules (5)

Access RightGreen

Consumers have a statutory right to access personal data held by a controller.

Claims (1):

  • Colorado consumers have the right to access personal data processed about them by a controller.

Rectification And ErasureGreen

Consumers may correct inaccuracies and request deletion of their personal data.

Claims (1):

  • Consumers have the right to correct inaccuracies in their personal data and to delete personal data held by a controller.

Restriction And ObjectionGreen

Consumers may object to/opt out of profiling used for decisions with legal or similarly significant effects, and may appeal a controller's denial of a rights request.

Claims (2):

  • Consumers may opt out of the processing of personal data for targeted advertising, sale, or profiling used for decisions that produce legal or similarly significant effects.
  • The CPA mandates that controllers provide a conspicuously available and easy-to-use appeal process when a consumer rights request is denied, and must inform the consumer of the ability to contact the Attorney General if the appeal is denied.

Data PortabilityGreen

The CPA includes a right to obtain a portable copy of personal data in a readily usable format.

Claims (1):

  • The CPA provides consumers a right to obtain a portable copy of their personal data.

Deadlines And Response WindowsGreen

Controllers must respond to consumer requests within 45 days, extendable by an additional 45 days when reasonably necessary, with notice to the consumer within the initial period.

Claims (1):

  • A business must respond to a consumer rights request within 45 days of receipt and may extend that deadline by an additional 45 days when reasonably necessary, notifying the consumer within the initial 45-day period.
Category narrative37 words

Colorado consumers hold access, correction, deletion, portability, and opt-out rights (targeted advertising, sale, and consequential-effect profiling), plus a mandatory appeal right against controller denials. Statutory response deadlines mirror the Virginia/Connecticut model (45 days, extendable by 45 days).

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidance — Colorado consumers have the right to access personal data processed about them by a controller.observed
  2. ConfirmedOneTrust DataGuidance — Consumers have the right to correct inaccuracies in their personal data and to delete personal data held by a controller.observed
  3. ConfirmedOneTrust DataGuidance — Consumers may opt out of the processing of personal data for targeted advertising, sale, or profiling used for decisions that produce legal or similarly significant effects.observed
  4. ConfirmedInternational Association of Privacy Professionals — The CPA mandates that controllers provide a conspicuously available and easy-to-use appeal process when a consumer rights request is denied, and must inform the consumer of the ability to contact the Attorney General if the appeal is denied.observed
  5. ConfirmedOneTrust DataGuidance — The CPA provides consumers a right to obtain a portable copy of their personal data.observed
  6. ConfirmedInternational Association of Privacy Professionals — A business must respond to a consumer rights request within 45 days of receipt and may extend that deadline by an additional 45 days when reasonably necessary, notifying the consumer within the initial 45-day period.observed

#

Core accountability, security, and breach duties are robust and in force, but the absence of DPO/ROPA-equivalent obligations creates a structural gap relative to GDPR-style regimes.

Primary frameworkColorado Privacy Act, Colo. Rev. Stat. §§ 6-1-1305, 6-1-1308; Colo. Rev. Stat. § 6-1-716 (breach notification); HB 24-1130
Traffic-light rationale — AmberCore accountability, security, and breach duties are robust and in force, but the absence of DPO/ROPA-equivalent obligations creates a structural gap relative to GDPR-style regimes.

Sub-modules (7)

Accountability And DpiaGreen

Controllers must conduct and document a data protection assessment before engaging in processing that presents a heightened risk of harm to consumers.

Claims (1):

  • Controllers may not process personal data in a manner presenting a heightened risk of harm to a consumer without conducting and documenting a data protection assessment of that processing activity.

Dpo RequirementsRed

No GDPR-style DPO appointment or independence mandate was identified in the CPA, CPA Rules, or secondary commentary.

Absence provenance: unavailable. Searched: Colorado Privacy Act data protection officer requirement, CPA Rules DPO appointment.

Ropa RequirementsAmber

No standalone, continuous records-of-processing-activities obligation analogous to GDPR Art. 30 was identified; the per-activity data protection assessment is the closest functional analog.

Absence provenance: unavailable. Searched: Colorado Privacy Act records of processing activities, CPA ROPA requirement.

Joint Controller ArrangementsGreen

Processing by a processor on behalf of a controller must be governed by a contract specifying processing instructions, nature, type of data, and duration.

Claims (1):

  • Processing by a processor must be governed by a contract between the controller and processor establishing processing instructions, the nature and type of personal data, and the duration of processing.

Security MeasuresGreen

Controllers must take security precautions appropriate to the volume, scope, and nature of the personal data processed (duty of care).

Claims (1):

  • The CPA imposes a duty of care requiring controllers to take security precautions appropriate to the volume, scope, and nature of the personal data processed.

Breach NotificationGreen

Colorado's breach law requires notice to affected residents without unreasonable delay and no later than 30 days after confirming a breach, plus AG notice within 30 days where 500+ residents are affected.

Claims (1):

  • Colorado law requires notice to affected residents in the most expedient way and without unreasonable delay, but not later than 30 days after confirming a breach, and requires notice to the Colorado Attorney General within 30 days where the breach is reasonably believed to affect 500 or more residents.

Retention And DisposalGreen

HB 24-1130 requires controllers to adopt a written biometric-data retention schedule and to permanently destroy biometric identifiers within 45 days of the retention purpose being satisfied.

Claims (1):

  • HB 24-1130 requires controllers to adopt a written policy establishing a retention schedule and destruction guidelines for biometric identifiers, extending the destruction period to 45 days.
Category narrative87 words

Controllers must conduct and document data protection assessments (DPAs) for heightened-risk processing, exercise a duty of care over security proportionate to the volume/scope/nature of data, and govern processor relationships by contract. Colorado's breach-notification law (independent of the CPA) requires consumer notice within 30 days and AG notice within 30 days for breaches affecting 500+ residents. HB 24-1130 layers biometric-specific retention/destruction duties (45-day destruction window). The CPA has no standalone DPO-appointment mandate or continuous ROPA obligation analogous to GDPR Arts. 30/37-39; the DPA functions as the closest analog.

Periodic update · new data 2026-09-05

Controller/Processor Duties

Colorado added a new, category-specific controller duty this cycle through HB24-1130, effective 2025-07-01. Controllers of biometric identifiers and biometric data must adopt a written policy that includes a retention schedule and a data-security-incident-response protocol. This is a documentation-and-governance duty distinct from the Colorado Privacy Act's general controller obligations: it requires an affirmative, written artifact specific to biometric data, rather than a generalized practice or policy covering personal data as a whole.

The retention-schedule component requires controllers to specify a defined period for which biometric identifiers and biometric data will be retained, rather than relying on an open-ended or purpose-based retention standard. The incident-response-protocol component requires controllers to have a defined process for responding to a data-security incident involving biometric data specifically, which may need to be integrated with, but is not necessarily identical to, a controller's general data-security-incident-response plan.

Notably, this duty extends into the employment relationship: Colorado employers collecting biometric identifiers from employees, for example for workplace access-control systems using fingerprint or facial-recognition technology, are captured by this obligation even where the employer's broader Colorado Privacy Act exposure is otherwise limited to consumer-facing processing. This development should also be read alongside the broader tightening pattern evident across this cycle's Colorado privacy amendments: HB24-1130's controller-duty addition arrives in the same legislative and enforcement environment as SB25-276's sensitive-data expansion and the Attorney General's active post-cure-period enforcement posture.

Outlook

The near-term compliance question for controllers is whether existing biometric-data-handling practices, if any, already satisfy the written-policy, retention-schedule, and incident-response-protocol requirements, or whether a freestanding policy document must now be created. Employers using biometric access-control systems in Colorado are a population particularly likely to face this compliance question for the first time.

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy Professionals — Controllers may not process personal data in a manner presenting a heightened risk of harm to a consumer without conducting and documenting a data protection assessment of that processing activity.observed
  2. ConfirmedInternational Association of Privacy Professionals — Processing by a processor must be governed by a contract between the controller and processor establishing processing instructions, the nature and type of personal data, and the duration of processing.observed
  3. ConfirmedInternational Association of Privacy Professionals — The CPA imposes a duty of care requiring controllers to take security precautions appropriate to the volume, scope, and nature of the personal data processed.observed
  4. ConfirmedInternational Association of Privacy Professionals — Colorado law requires notice to affected residents in the most expedient way and without unreasonable delay, but not later than 30 days after confirming a breach, and requires notice to the Colorado Attorney General within 30 days where the breach is reasonably believed to affect 500 or more residents.observed
  5. ConfirmedOneTrust DataGuidance — HB 24-1130 requires controllers to adopt a written policy establishing a retention schedule and destruction guidelines for biometric identifiers, extending the destruction period to 45 days.observed

#

No comprehensive cross-border transfer regime exists at the US-CO state level; this is a legitimate structural gap, not a research omission.

Traffic-light rationale — Not assessedNo comprehensive cross-border transfer regime exists at the US-CO state level; this is a legitimate structural gap, not a research omission.

Sub-modules (6)

Transfer MechanismsRed

No CPA-specific transfer mechanism exists.

Absence provenance: unavailable. Searched: Colorado Privacy Act cross-border data transfer, CPA international data transfer mechanism.

Adequacy ReceivedRed

Not applicable; Colorado does not participate in a national/international adequacy framework.

Absence provenance: unavailable. Searched: Colorado adequacy decision received.

Adequacy GrantedRed

Not applicable.

Absence provenance: unavailable. Searched: Colorado adequacy decision granted.

Sccs And BcrsRed

No SCC/BCR concept exists under the CPA.

Absence provenance: unavailable. Searched: Colorado Privacy Act standard contractual clauses, CPA binding corporate rules.

Transfer Impact AssessmentRed

No TIA requirement exists under the CPA; the general data protection assessment does not extend to cross-border transfer risk analysis.

Absence provenance: unavailable. Searched: Colorado Privacy Act transfer impact assessment.

Data LocalisationRed

No data localisation mandate exists under Colorado law.

Absence provenance: unavailable. Searched: Colorado data localisation requirement.

Category narrative47 words

The Colorado Privacy Act is a US state consumer-privacy statute and contains no international-transfer mechanism, adequacy-decision framework, SCC/BCR regime, transfer-impact-assessment requirement, or data-localisation mandate. Cross-border data flows are governed, if at all, by federal law (e.g., GLBA, HIPAA) or general contract law, not by the CPA itself.

#

Financial, health, and employment carve-outs are clear, but telecoms/ePrivacy, credit-scoring, and education overlays are not separately codified, leaving coverage partial.

Primary frameworkColorado Privacy Act (exemptions); Restrict Insurers' Use of External Consumer Data Act, SB 21-169
Traffic-light rationale — AmberFinancial, health, and employment carve-outs are clear, but telecoms/ePrivacy, credit-scoring, and education overlays are not separately codified, leaving coverage partial.

Sub-modules (7)

Financial Sector OverlayGreen

Entities regulated by the Gramm-Leach-Bliley Act are exempt at the entity level from CPA obligations.

Claims (1):

  • Entities regulated by the Gramm-Leach-Bliley Act are exempt at the entity level from Colorado Privacy Act obligations.

Health Sector OverlayGreen

Protected health information collected/processed by HIPAA-covered entities or business associates is exempt from the CPA.

Claims (1):

  • Protected health information collected, stored, and processed by HIPAA-covered entities or their business associates is exempt from the Colorado Privacy Act.

Telecoms And EprivacyAmber

No dedicated Colorado telecoms/ePrivacy overlay distinct from the CPA's general cookie/UOOM rules was identified.

Absence provenance: unavailable. Searched: Colorado telecoms privacy law, Colorado ePrivacy cookie law.

Employment DataGreen

The CPA's definition of 'consumer' excludes individuals acting in a commercial or employment context, including job applicants and employment-context beneficiaries.

Claims (1):

  • The CPA's definition of 'consumer' excludes an individual acting in a commercial or employment context, as a job applicant, or as a beneficiary of someone acting in an employment context.

Credit And ScoringAmber

No Colorado-specific credit-scoring overlay beyond federal FCRA exemption was identified.

Absence provenance: unavailable. Searched: Colorado credit scoring privacy law.

EducationAmber

No dedicated Colorado education-sector data-privacy overlay distinct from federal FERPA/COPPA was identified in this research pass.

Absence provenance: unavailable. Searched: Colorado education data privacy law, Colorado student data privacy CPA.

InsuranceAmber

Colorado's Restrict Insurers' Use of External Consumer Data Act (SB 21-169) restricts insurers' use of external consumer data and algorithms that could produce unfair discrimination.

Claims (1):

  • Colorado enacted the Restrict Insurers' Use of External Consumer Data Act (SB 21-169), restricting insurers' use of external consumer data and algorithms in ways that could result in unfair discrimination.
Category narrative69 words

The CPA carves out entity-level exemptions for GLBA-regulated financial institutions and data-level exemptions for HIPAA-covered PHI, COPPA-regulated data, and employment-context data (the CPA's 'consumer' definition excludes employees, job applicants, and employment beneficiaries). Colorado separately regulates insurers' use of external consumer data and algorithms via the Restrict Insurers' Use of External Consumer Data Act (SB 21-169). No dedicated telecoms/ePrivacy, credit-scoring, or education-sector overlay distinct from the CPA/federal baseline was identified.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy Professionals — Entities regulated by the Gramm-Leach-Bliley Act are exempt at the entity level from Colorado Privacy Act obligations.observed
  2. ConfirmedOneTrust DataGuidance — Protected health information collected, stored, and processed by HIPAA-covered entities or their business associates is exempt from the Colorado Privacy Act.observed
  3. ConfirmedOneTrust DataGuidance — The CPA's definition of 'consumer' excludes an individual acting in a commercial or employment context, as a job applicant, or as a beneficiary of someone acting in an employment context.observed
  4. UncertainFederal Trade Commission — Colorado enacted the Restrict Insurers' Use of External Consumer Data Act (SB 21-169), restricting insurers' use of external consumer data and algorithms in ways that could result in unfair discrimination.observed

#

UOOM and dark-pattern rules are operative and well documented; gaps exist only in emerging areas like clean rooms.

Primary frameworkColorado Privacy Act Rules, 4 CCR 904-3, Part 5
Traffic-light rationale — GreenUOOM and dark-pattern rules are operative and well documented; gaps exist only in emerging areas like clean rooms.

Sub-modules (6)

Cookies And TrackersAmber

The CPA governs tracking primarily through its sale/targeted-advertising opt-out and UOOM regime rather than a dedicated cookie-consent-banner law.

Absence provenance: unavailable. Searched: Colorado cookie consent law.

Dark PatternsGreen

CPA Rules provide that any agreement obtained through dark patterns is not valid consent.

Claims (1):

  • Under CPA Rules, any agreement obtained through dark patterns is not valid consent.

Opt Out SignalsGreen

From July 1, 2024, controllers must honor a user-selected universal opt-out mechanism meeting AG technical specifications; Colorado currently recognizes GPC as the only valid UOOM, and the AG publishes a public UOOM list (initial list by April 1, 2024).

Claims (3):

  • From July 1, 2024, data controllers must allow consumers to exercise opt-out rights for targeted advertising or sale of personal data through a user-selected universal opt-out mechanism meeting AG technical specifications.
  • Colorado currently considers the Global Privacy Control to be the only recognized valid universal opt-out mechanism under the CPA.
  • The Colorado Department of Law maintains and publishes a public list of recognized universal opt-out mechanisms, with the initial list published no later than April 1, 2024.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific provisions were identified under the CPA.

Absence provenance: unavailable. Searched: Colorado Privacy Act clean room data collaboration.

Cross Context AdvertisingAmber

The CPA's 'sale' definition (exchange of data for monetary or other valuable consideration) and targeted-advertising opt-out function as Colorado's analog to CPRA-style cross-context advertising restrictions.

Absence provenance: unavailable. Searched: Colorado Privacy Act cross-context advertising 'share'.

Direct MarketingAmber

No CPA provision specifically dedicated to direct-marketing suppression lists was identified beyond the general targeted-advertising opt-out.

Absence provenance: unavailable. Searched: Colorado Privacy Act direct marketing consent.

Category narrative57 words

Colorado requires recognition of a universal opt-out mechanism (UOOM) for targeted-advertising and sale opt-outs since July 1, 2024, and currently recognizes the Global Privacy Control (GPC) as the sole valid UOOM signal. The AG maintains and publishes a public list of recognized UOOMs. CPA Rules invalidate consent obtained through dark patterns. No dedicated clean-room/data-collaboration-room regime was identified.

Periodic update · new data 2026-09-05

AdTech & Commercial Privacy

Colorado's adtech enforcement posture became concrete this cycle with the disclosure of the Attorney General's first reported Colorado Privacy Act enforcement action following the cure period's sunset. The Attorney General publicly disclosed a 250,000 dollar penalty against an adtech company in April 2025, arising from compliance sweeps focused on universal opt-out mechanisms and Global Privacy Control compliance. This is reported to be the first disclosed enforcement action taken without the 60-day cure opportunity that characterized the law's earlier enforcement years, and it specifically targets a compliance failure, non-recognition or non-honoring of opt-out signals, that sits at the center of the Colorado Privacy Act's commercial-privacy and targeted-advertising provisions.

The action signals that Colorado's Attorney General is treating universal opt-out and Global Privacy Control compliance as an active enforcement priority for adtech and commercial-privacy practices, rather than a technical requirement enforced only reactively. For adtech companies and any controller relying on third-party advertising technology, the practical implication is that opt-out-signal recognition, and the ability to demonstrate that recognition operationally, is now understood to carry direct financial-penalty risk. Commercial-privacy stakeholders should also note that this action arrives amid a broader tightening of Colorado's sensitive-data and enforcement architecture this cycle, suggesting that adtech-focused enforcement is one strand of a wider regulatory tightening rather than an isolated sectoral action.

Outlook

Given that this is reported as the first disclosed post-cure-period action, further adtech-sector enforcement activity focused on opt-out-signal compliance is a plausible near-term development, though no specific additional action has been identified this cycle. Sourcing note: the 250,000 dollar figure relies on secondary reporting rather than an independently retrieved primary enforcement order this cycle, a gap worth tracking as the underlying enforcement-posture shift is otherwise treated as reliably established.

Sources and claims (4)
  1. ConfirmedColorado Department of Law — Under CPA Rules, any agreement obtained through dark patterns is not valid consent.observed
  2. ConfirmedOneTrust DataGuidance — From July 1, 2024, data controllers must allow consumers to exercise opt-out rights for targeted advertising or sale of personal data through a user-selected universal opt-out mechanism meeting AG technical specifications.observed
  3. ProbableInternational Association of Privacy Professionals — Colorado currently considers the Global Privacy Control to be the only recognized valid universal opt-out mechanism under the CPA.observed
  4. ConfirmedOneTrust DataGuidance — The Colorado Department of Law maintains and publishes a public list of recognized universal opt-out mechanisms, with the initial list published no later than April 1, 2024.observed

#

Biometric and profiling rules are settled, but the AI Act framework remains in active flux (major 2026 amendments, delayed effective date, pending litigation), creating material regulatory uncertainty.

Primary frameworkColorado Privacy Act Rules, 4 CCR 904-3; Colorado Artificial Intelligence Act, SB 24-205 (as amended by SB 189, 2026)
Traffic-light rationale — AmberBiometric and profiling rules are settled, but the AI Act framework remains in active flux (major 2026 amendments, delayed effective date, pending litigation), creating material regulatory uncertainty.

Sub-modules (6)

Profiling RestrictionsGreen

Consumers may opt out of profiling used for decisions producing legal or similarly significant effects.

Claims (1):

  • Consumers may opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.

Automated Decision Making TransparencyAmber

Under SB 189, deployers must provide consumers explicit disclosures on intended/harmful uses of ADMT, training-data categories, and deployer oversight instructions when the AI Act takes effect January 1, 2027.

Claims (1):

  • Under Senate Bill 189, deployers of covered AI systems must provide consumers with explicit disclosures regarding intended and harmful uses of automated decision-making technology, training-data categories, and deployer oversight instructions.

Ai Risk AssessmentsAmber

SB 189 (2026) replaces the AI Act's original duty-of-care/risk-management-program/impact-assessment obligations with a disclosure-based framework and delays the principal effective date to January 1, 2027.

Claims (2):

  • Senate Bill 189 (2026) replaces the Colorado AI Act's original risk-based framework with disclosure and transparency requirements, removing the duty-of-care, risk-management-program, and impact-assessment obligations that had applied to deployers.
  • SB 189 moves the Colorado AI Act's principal effective date to January 1, 2027, superseding the prior June 30, 2026 date.

Biometric RegimeGreen

CPA Rules define 'Biometric Identifiers' and 'Biometric Data'; HB 24-1130 mandates disclosure and consent before collection, retention scheduling, and 45-day destruction timelines.

Claims (1):

  • HB 24-1130 requires controllers to disclose and obtain consent before collecting biometric data and defines 'Biometric Identifiers' as data generated by technological processing of an individual's biological, physical, or behavioral characteristics.

Genetic DataAmber

HB 24-1130 expanded CPA sensitive-data protections to cover neural data alongside biometric identifiers; no separate freestanding genetic-data statute was identified.

Claims (1):

  • HB 24-1130 expanded the Colorado Privacy Act's scope to protect neural data in addition to biometric identifiers.

State Surveillance CarveoutsRed

No Colorado-specific state-surveillance carve-out or national-security exemption analysis distinct from general law-enforcement exceptions was identified in this research pass.

Absence provenance: unavailable. Searched: Colorado Privacy Act national security exemption, Colorado AI Act law enforcement carve-out.

Category narrative39 words

Colorado repealed and replaced its 2024 AI Act (SB24-205) with SB26-189, the Automated Decision-Making Technology Act, signed May 14, 2026, effective January 1, 2027. SB26-189 shifts the framework from broad algorithmic-discrimination risk governance to transparency, notice, and consumer-recourse duties.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

Colorado enacted SB26-189, which repeals and replaces the original Colorado AI Act (SB24-205) with a new Automated Decision-Making Technology (ADMT) framework, effective January 1, 2027. The new law requires deployers of covered ADMT to provide pre-use disclosures to affected consumers, to explain adverse outcomes within 30 days of a request, and to offer a path for meaningful human review of automated decisions. This is a structural realignment of Colorado's algorithmic-governance approach: the original AI Act had centered on a duty-of-care standard implemented through risk-management programs and pre-deployment impact assessments, whereas SB26-189 shifts the regulatory center of gravity to individual-facing transparency, disclosure and a consumer right to contest or seek review of an automated outcome.

This is an enacted-but-not-yet-effective instrument: SB26-189 has passed but its substantive obligations do not bind deployers until January 1, 2027, giving covered entities a defined runway to build the required disclosure, adverse-outcome-explanation and human-review infrastructure. The repeal-and-replace nature of this legislation means that entities that had begun building compliance programs around the original AI Act's risk-management and impact-assessment model will need to reorient toward the new transparency-and-disclosure model rather than simply continuing prior compliance work.

The practical effect for ADMT deployers operating in or serving Colorado consumers is a shift in compliance architecture: rather than documenting internal risk assessments primarily for regulator-facing accountability, deployers will need consumer-facing disclosure content, a working adverse-outcome explanation process capable of responding within a 30-day window, and an operational human-review pathway that a consumer can actually invoke.

Outlook

The SB26-189 framework takes effect January 1, 2027. Whether the Colorado Attorney General issues implementing guidance or rules ahead of that date, and whether any enforcement action or interpretive opinion emerges regarding the scope of covered ADMT prior to the effective date, are the key items to watch in the run-up to implementation.

1 earlier distinct update(s)
Periodic update · new data 2026-09-05

Algorithmic, Biometric & Surveillance Governance

Colorado undertook a significant restructuring of its algorithmic-governance framework this cycle. SB26-189, signed 2026-05-14, repeals and reenacts Colorado's 2024 high-risk-AI provisions as an Automated Decision-Making Technology law. The new framework imposes ADMT-specific duties for consequential decisions, including a developer-documentation obligation, with these duties taking effect 2027-01-01. This is a repeal-and-reenactment rather than an amendment: the prior 2024 high-risk-AI framework is replaced wholesale by the new ADMT structure rather than modified in place, which is itself a significant governance signal, indicating that the legislature judged the original 2024 framework to require structural replacement rather than incremental correction.

The distinction between enacted and in-force status is important here: SB26-189 is enacted law as of its 2026-05-14 signature, but its consequential-decision and developer-documentation duties are not yet in force, with an effective date of 2027-01-01. This gives covered developers and deployers of automated decision-making technology a defined compliance runway before the substantive duties become enforceable, and it also means that any implementing guidance issued in the interim would be addressing an enacted-but-not-yet-effective framework rather than a currently binding one.

Outlook

The 2027-01-01 effective date is the single most consequential date on Colorado's algorithmic-governance horizon. Developers and deployers of automated decision-making technology operating in Colorado should treat the intervening period as the primary window for compliance-program development. Whether implementing rules or guidance will further clarify the scope of consequential decision or the specific content of the developer-documentation obligation ahead of that date remains an open question this cycle.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidance — Consumers may opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.observed
  2. ConfirmedInternational Association of Privacy Professionals — Under Senate Bill 189, deployers of covered AI systems must provide consumers with explicit disclosures regarding intended and harmful uses of automated decision-making technology, training-data categories, and deployer oversight instructions.observed
  3. ConfirmedInternational Association of Privacy Professionals — Senate Bill 189 (2026) replaces the Colorado AI Act's original risk-based framework with disclosure and transparency requirements, removing the duty-of-care, risk-management-program, and impact-assessment obligations that had applied to deployers.observed
  4. ConfirmedInternational Association of Privacy Professionals — SB 189 moves the Colorado AI Act's principal effective date to January 1, 2027, superseding the prior June 30, 2026 date.observed
  5. ConfirmedOneTrust DataGuidance — HB 24-1130 requires controllers to disclose and obtain consent before collecting biometric data and defines 'Biometric Identifiers' as data generated by technological processing of an individual's biological, physical, or behavioral characteristics.observed
  6. ProbableOneTrust DataGuidance — HB 24-1130 expanded the Colorado Privacy Act's scope to protect neural data in addition to biometric identifiers.observed

#

Minors' protections are now in force with clear obligations; only the pending age-attestation bill and dependent-adult gap temper the rating.

Primary frameworkColorado Privacy Act as amended by SB 24-041
Traffic-light rationale — GreenMinors' protections are now in force with clear obligations; only the pending age-attestation bill and dependent-adult gap temper the rating.

Sub-modules (5)

Age VerificationAmber

Senate Bill 26-051 would establish an age-attestation framework for computing devices with non-compliance penalties, but remained a pending bill as of this research pass.

Claims (1):

  • Senate Bill 26-051 aims to establish a framework for age attestation on computing devices in Colorado, with penalties for non-compliance, but remains a pending bill as of this research pass.

Minor Profiling BansGreen

SB 24-041 prohibits processing a minor's personal data for targeted advertising absent consent.

Claims (1):

  • SB 24-041 prohibits processing a minor's personal data for purposes of targeted advertising without consent.

Education SettingsAmber

No education-setting-specific minors' data provisions distinct from SB 24-041's general minors' framework were identified.

Absence provenance: unavailable. Searched: Colorado student data privacy minors CPA.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) data-protection provisions were identified under the CPA.

Absence provenance: unavailable. Searched: Colorado Privacy Act dependent adults protections, Colorado elderly consumer data privacy.

Category narrative80 words

SB 24-041, effective October 1, 2025, amended the CPA to prohibit processing minors' data for targeted advertising without consent, require reasonable care to avoid risks to minors, and mandate data protection impact assessments for services posing heightened risk to minors, with a 60-day cure period preserved through the end of 2026 specifically for minors' provisions. Senate Bill 26-051, proposing an age-attestation framework for computing devices, remains a pending bill as of this research pass. No dedicated dependent-adult protections were identified.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

SB24-041 amends the Colorado Privacy Act to add enhanced protections applicable when a minor's data is processed and there is a heightened risk of harm to minors, effective October 1, 2025. This heightened-risk-of-harm standard establishes a distinct, more protective processing tier for minors' data beyond the CPA's general consumer-data framework, though the specific substantive obligations that attach once the heightened-risk threshold is met sit within the broader CPA amendment rather than being enumerated as a standalone claim this cycle.

A notice-and-cure period applicable to enforcement of the minors' and biometric-data provisions is scheduled to sunset December 31, 2026. During the current cure period, the Colorado Attorney General's Office must generally afford a 60-day opportunity to cure before pursuing enforcement for violations of these specific provisions; after the sunset date, that mandatory cure opportunity will no longer apply, materially increasing the immediate enforcement exposure for non-compliant processing of minors' data.

This represents a tightening trajectory: the combination of the heightened-risk-of-harm standard taking effect in October 2025 and the cure-period protection lapsing at the end of 2026 means that the practical compliance runway for minors'-data processors to identify and remediate non-compliant practices without facing direct enforcement is time-limited and closing.

Outlook

Controllers processing minors' data in a manner that could trigger the heightened-risk-of-harm standard should treat the December 31, 2026 cure-period sunset as a hard compliance deadline: remediation identified after that date will not benefit from the current 60-day cure opportunity, and enforcement exposure increases correspondingly.

1 earlier distinct update(s)
Periodic update · new data 2026-09-05

Children & Vulnerable Groups

Colorado expanded its protections for minors under the Colorado Privacy Act this cycle through SB24-041, effective 2025-10-01. The statute requires controllers to use reasonable care to avoid heightened risks of harm to minors, and to conduct data protection assessments for online services, products, or features used by minors. This is a population-based trigger for the data-protection-assessment requirement, distinct from the Act's more familiar processing-based triggers, such as processing of sensitive data or use of personal data for targeted advertising, profiling, or sale.

The reasonable-care-to-avoid-heightened-risk-of-harm standard introduces a duty-of-care concept into Colorado's privacy framework specifically in relation to minors, which is analytically distinct from the Act's general lawful-processing and controller-obligation architecture: it is a harm-avoidance standard rather than a consent-or-lawful-basis standard, meaning a controller could in principle satisfy the Act's general consent and lawful-processing requirements while still falling short of the heightened-care standard specifically owed to minors.

Outlook

Whether the Colorado Department of Law finalized proposed Colorado Privacy Act rule amendments addressing minors' protections ahead of an anticipated 2026-07-01 effective date, without material change from the proposed text, remains unconfirmed this cycle and is a gap worth tracking. Controllers operating online services, products, or features reasonably likely to be accessed by minors should treat the data-protection-assessment requirement introduced by SB24-041 as a standing, population-based compliance obligation distinct from their existing sensitive-data and targeted-advertising assessment triggers.

Sources and claims (4)
  1. SpeculativeOneTrust DataGuidance — Senate Bill 26-051 aims to establish a framework for age attestation on computing devices in Colorado, with penalties for non-compliance, but remains a pending bill as of this research pass.observed
  2. ConfirmedOneTrust DataGuidance — SB 24-041 amends the Colorado Privacy Act to include heightened protections for minors' online activity, effective October 1, 2025, mandating data controllers to exercise reasonable care to avoid risks to minors and to conduct data protection impact assessments for services posing heightened risk to minors.observed
  3. ConfirmedOneTrust DataGuidance — SB 24-041 preserves a 60-day cure period specifically for violations of the minors' protection provisions through the end of 2026.observed
  4. ConfirmedOneTrust DataGuidance — SB 24-041 prohibits processing a minor's personal data for purposes of targeted advertising without consent.observed

#

Enforcement authority and general mechanics are clear, but the absence of a private right of action, unresolved penalty-figure conflicts, and active AI Act litigation introduce material uncertainty.

Primary frameworkColorado Privacy Act, Colo. Rev. Stat. § 6-1-1311; Colorado Consumer Protection Act, Colo. Rev. Stat. Title 6, Article 1
Traffic-light rationale — AmberEnforcement authority and general mechanics are clear, but the absence of a private right of action, unresolved penalty-figure conflicts, and active AI Act litigation introduce material uncertainty.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The AG and DAs may investigate and bring enforcement actions treating CPA violations as deceptive trade practices; maximum-penalty figures reported in secondary sources conflict and require primary-source confirmation.

Claims (3):

  • The CPA assigns enforcement authority to the Colorado Attorney General and District Attorneys, who may investigate and bring actions treating CPA violations as deceptive trade practices under the Colorado Consumer Protection Act.
  • Civil penalties for CPA violations may reach up to $2,000 per violation, subject to a total maximum penalty of $500,000 for a related series of violations.
  • An alternative secondary-source figure reports CPA noncompliance penalties of up to $20,000 per violation under the Colorado Consumer Protection Act; this figure conflicts with the $2,000/$500,000 figure reported elsewhere and requires primary statutory confirmation.

Enforcement Activity IndexAmber

The AG's initial CPA enforcement posture (from July 2023) was educational/letter-based rather than punitive; no independently verified list of subsequent CPA-specific monetary penalties was located in this research pass.

Absence provenance: unavailable. Searched: Colorado Privacy Act enforcement action fine 2025, Colorado AG CPA settlement 2026.

Claims (1):

  • The Colorado Attorney General began CPA enforcement on July 12, 2023 with educational outreach letters focused on informing businesses of their obligations rather than immediate penalties.

Regulator Funding And CapacityRed

No specific budget/headcount data for the Colorado AG's privacy enforcement unit was identified.

Absence provenance: unavailable. Searched: Colorado Attorney General privacy unit budget headcount.

Collective Redress And Class ActionsRed

No CPA-specific collective-redress or class-action mechanism distinct from general Colorado civil procedure was identified.

Absence provenance: unavailable. Searched: Colorado Privacy Act class action mechanism.

Private Right Of ActionAmber

The CPA does not grant consumers a private right of action; enforcement is confined to the AG and District Attorneys.

Claims (1):

  • The Colorado Privacy Act does not provide consumers with a private right of action for violations.

Recent Developments 180DAmber

Within the past 180 days: the AG solicited public comment on ADMT/chatbot-safety rulemaking (through July 13, 2026); SB 189 substantially overhauled the AI Act's framework and delayed its effective date to January 1, 2027; and xAI and the U.S. DOJ initiated litigation to block AI Act enforcement.

Claims (2):

  • The Colorado Attorney General's office is soliciting public comments on automated-decision-making-technology and chatbot-safety rulemaking through July 13, 2026.
  • xAI and the U.S. Department of Justice are litigating to block enforcement of the Colorado AI Act on constitutional grounds.
Category narrative35 words

CPA penalties can reach $20,000 per violation. The notice-and-60-day-cure requirement for newly-added minors'/biometric provisions sunsets December 31, 2026; after that date the AG may proceed to enforcement without a mandatory cure opportunity for those provisions.

Periodic update · new data 2026-09-28

Enforcement & Redress

Enforcement of the Colorado Privacy Act rests exclusively with the Colorado Attorney General's Office and District Attorneys; no private right of action exists under the CPA, meaning individual consumers cannot bring their own lawsuits to enforce CPA rights directly. This centralized public-enforcement model is a stable, standing feature of Colorado's privacy-enforcement architecture and was not a new development this cycle, but it is the essential backdrop against which this cycle's enforcement-relevant development should be read.

That development is the scheduled sunset, on December 31, 2026, of the mandatory 60-day notice-and-cure period that currently applies to enforcement of the minors'- and biometric-data provisions. Under the current cure-period protection, the Attorney General's Office must generally provide covered entities a 60-day window to remediate a violation before pursuing enforcement action in these specific categories. Once that cure period sunsets, the Attorney General would be positioned to pursue enforcement action for minors'- and biometric-data violations without first affording that remediation opportunity, representing a genuine escalation in enforcement exposure for entities processing these data categories, distinct from any change to the underlying substantive obligations themselves.

Whether the Attorney General has issued any enforcement action or opinion letter regarding the forthcoming SB26-189 ADMT framework ahead of its January 1, 2027 effective date remains unresolved and was not established this cycle.

Outlook

The December 31, 2026 cure-period sunset is the key near-term date for enforcement exposure: entities processing minors' or biometric data should treat any known compliance gaps as urgent to remediate before that date, since the current 60-day cure protection will no longer be available in these categories thereafter.

1 earlier distinct update(s)
Periodic update · new data 2026-09-05

Enforcement & Redress

The most structurally significant enforcement development in Colorado's privacy regime this cycle is one of standing posture rather than a single new action: the Colorado Privacy Act's original 60-day cure period sunset on 2025-01-01, after which the Colorado Attorney General has full discretion to enforce the Act without offering a cure opportunity to violators. Per-violation penalties under this enforcement authority can reach 20,000 dollars. This structural shift is the backdrop against which the Attorney General's disclosed 250,000 dollar penalty against an adtech company, arising from an April 2025 universal-opt-out and Global Privacy Control compliance sweep, should be read: it is understood to be the first disclosed Colorado Privacy Act enforcement action taken after the cure period's sunset.

The removal of the cure-period requirement is significant because it changes the practical risk calculus for controllers and processors: prior to 2025-01-01, a violation identified by the Attorney General's office would typically first generate a cure notice, giving the violator 60 days to correct the deficiency before facing a penalty; after the sunset, the office may proceed directly to enforcement and penalty assessment, without that intervening correction opportunity, for at least some class of violations.

Outlook

Given the disclosed adtech action and the removal of the cure-period backstop, continued and potentially expanding enforcement activity is a plausible trajectory for Colorado's privacy regime going forward, though the evidence available this cycle does not identify any further specific enforcement action beyond the disclosed adtech penalty. A sourcing gap exists around the specific penalty figures: no Tier 1 source was independently retrieved this cycle confirming the 250,000 dollar penalty or the 20,000-dollar-per-violation ceiling; both rely on secondary reporting, a point worth flagging even as the underlying enforcement-posture shift is otherwise treated as reliably established.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidance — The CPA assigns enforcement authority to the Colorado Attorney General and District Attorneys, who may investigate and bring actions treating CPA violations as deceptive trade practices under the Colorado Consumer Protection Act.observed
  2. ProbableOneTrust DataGuidance — Civil penalties for CPA violations may reach up to $2,000 per violation, subject to a total maximum penalty of $500,000 for a related series of violations.observed
  3. UncertainInternational Association of Privacy Professionals — An alternative secondary-source figure reports CPA noncompliance penalties of up to $20,000 per violation under the Colorado Consumer Protection Act; this figure conflicts with the $2,000/$500,000 figure reported elsewhere and requires primary statutory confirmation.observed
  4. ConfirmedOneTrust DataGuidance — The Colorado Attorney General began CPA enforcement on July 12, 2023 with educational outreach letters focused on informing businesses of their obligations rather than immediate penalties.observed
  5. ConfirmedInternational Association of Privacy Professionals — The Colorado Privacy Act does not provide consumers with a private right of action for violations.observed
  6. ConfirmedOneTrust DataGuidance — The Colorado Attorney General's office is soliciting public comments on automated-decision-making-technology and chatbot-safety rulemaking through July 13, 2026.observed
  7. ProbableOneTrust DataGuidance — xAI and the U.S. Department of Justice are litigating to block enforcement of the Colorado AI Act on constitutional grounds.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct16.22
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Colorado, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s) (44 category placement(s)), 44 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacytransfer mechanisms
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressprivate right of action
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, adtech_and_commercial_privacy, and children_and_vulnerable_groups rest on T1 statutory/rule text (CPA, 4 CCR 904-3) cross-checked against multiple T3 secondary analyses (IAPP, DataGuidance), yielding high confidence. controller_processor_duties and algorithmic_biometric_and_surveillance_governance mix T1 rule text with T3 reporting on the fast-moving Colorado AI Act (SB 24-205/SB 189), yielding Probable/Confirmed mixed confidence given the law's active 2026 amendment cycle. cross_border_and_adequacy is a legitimate empty module (no CPA transfer regime exists) supported by explicit absent_field_provenance. sectoral_watch and enforcement_and_redress rely predominantly on T3 secondary sources with one T2 federal source (FTC ANPR) and one T1 CRS excerpt; the exact CPA civil-penalty figure (competing $2,000/$500,000 vs. $20,000 reports) could not be conclusively resolved from the CRS excerpt retrieved and is flagged Uncertain pending primary-source (CRS §6-1-112/6-1-1311) confirmation.

Unresolved questions (5):

  • What is the definitive, currently-effective maximum per-violation civil penalty for CPA violations under Colorado Consumer Protection Act enforcement — $2,000/$500,000 aggregate, or a $20,000 figure reported in older secondary commentary?
  • Has SB 189 (2026 Colorado AI Act amendments) received the Governor's formal signature and been codified, and what is the finalized text of the 'materially influences' definition left to AG rulemaking?
  • What is the current status and precise effective date of House Bill 1210 (limiting use of intimate personal data for financial decisions), reported with an effective date of August 12, 2026?
  • Does Colorado impose any DPO-equivalent or continuous ROPA-equivalent obligation not captured in publicly available CPA Rules text?
  • What is the current, detailed operative status of SB 21-169 (Restrict Insurers' Use of External Consumer Data Act) relative to the CPA?

Escalate to primary-source review: yes