Colorado Privacy Act
The Colorado Privacy Act (CPA) is a Colorado state law that gives Colorado residents more control over how businesses collect and use their personal data. It grants consumers rights such as accessing, correcting, and deleting their personal data, and it places obligations on the organizations that handle that data. This entry covers the law's general purpose and does not address enforcement penalties, cross-border transfer mechanics, or detailed retention rules.
The Colorado Privacy Act (CPA) is a Colorado data protection and privacy statute that grants Colorado consumers rights over their personal data and imposes obligations on data controllers and processors, following the controller/processor distinction familiar from other privacy regimes. Consumer rights under the CPA include the right to access, delete, and correct personal data. The CPA also requires that a privacy notice provide consumers with a meaningful understanding and accurate expectations of how their personal data will be processed. Note that the CPA is a distinct instrument and should not be treated as interchangeable with other US state privacy laws (such as the CCPA/CPRA) or with the EU or UK GDPR; obligations, definitions, and thresholds differ. This entry is limited to the law's scope, consumer rights, and core controller/processor and notice obligations; it does not describe applicability thresholds, enforcement mechanisms, penalty amounts, statutory article citations, or the specifics of any assessment or transfer requirements, which should be confirmed against the statute and its implementing regulations.
Why it matters
The Colorado Privacy Act (CPA) is part of the growing patchwork of US state privacy laws that organizations must navigate individually rather than as a single, harmonized regime. For compliance and privacy teams, the CPA matters because it adopts the controller/processor distinction familiar from other frameworks while remaining a distinct instrument: its consumer rights, notice obligations, and definitions cannot be assumed to match the CCPA/CPRA or the EU or UK GDPR. Treating these regimes as interchangeable is a common and consequential error, because obligations and thresholds differ across each statute.
For Colorado residents, the CPA is significant because it grants rights to access, delete, and correct their personal data, giving them more control over how businesses collect and use it. For the organizations that process that data, the law creates accountability obligations that fall on both controllers and processors depending on their role in the processing. Demonstrable compliance, not merely stated intent, is the operative standard under governance frameworks generally, so mapping which party bears which obligation is a practical necessity rather than a paperwork exercise.
The CPA also imposes a substantive transparency requirement: a privacy notice must provide consumers with a meaningful understanding and accurate expectations of how their personal data will be processed. This raises the bar beyond boilerplate disclosures and requires organizations to align their stated practices with their actual data handling. This entry does not address applicability thresholds, enforcement mechanisms, penalty amounts, retention rules, or cross-border transfer mechanics, which must be confirmed against the statute and its implementing regulations.
Who it's relevant to
Inside CPA
Common questions
Answers to the questions practitioners most commonly ask about CPA.