Skip to main content
Category: Privacy Regulations

Colorado Privacy Act

Also known as: CPA, Colorado Privacy Act (CPA)
Simply put

The Colorado Privacy Act (CPA) is a Colorado state law that gives Colorado residents more control over how businesses collect and use their personal data. It grants consumers rights such as accessing, correcting, and deleting their personal data, and it places obligations on the organizations that handle that data. This entry covers the law's general purpose and does not address enforcement penalties, cross-border transfer mechanics, or detailed retention rules.

Formal definition

The Colorado Privacy Act (CPA) is a Colorado data protection and privacy statute that grants Colorado consumers rights over their personal data and imposes obligations on data controllers and processors, following the controller/processor distinction familiar from other privacy regimes. Consumer rights under the CPA include the right to access, delete, and correct personal data. The CPA also requires that a privacy notice provide consumers with a meaningful understanding and accurate expectations of how their personal data will be processed. Note that the CPA is a distinct instrument and should not be treated as interchangeable with other US state privacy laws (such as the CCPA/CPRA) or with the EU or UK GDPR; obligations, definitions, and thresholds differ. This entry is limited to the law's scope, consumer rights, and core controller/processor and notice obligations; it does not describe applicability thresholds, enforcement mechanisms, penalty amounts, statutory article citations, or the specifics of any assessment or transfer requirements, which should be confirmed against the statute and its implementing regulations.

Why it matters

The Colorado Privacy Act (CPA) is part of the growing patchwork of US state privacy laws that organizations must navigate individually rather than as a single, harmonized regime. For compliance and privacy teams, the CPA matters because it adopts the controller/processor distinction familiar from other frameworks while remaining a distinct instrument: its consumer rights, notice obligations, and definitions cannot be assumed to match the CCPA/CPRA or the EU or UK GDPR. Treating these regimes as interchangeable is a common and consequential error, because obligations and thresholds differ across each statute.

For Colorado residents, the CPA is significant because it grants rights to access, delete, and correct their personal data, giving them more control over how businesses collect and use it. For the organizations that process that data, the law creates accountability obligations that fall on both controllers and processors depending on their role in the processing. Demonstrable compliance, not merely stated intent, is the operative standard under governance frameworks generally, so mapping which party bears which obligation is a practical necessity rather than a paperwork exercise.

The CPA also imposes a substantive transparency requirement: a privacy notice must provide consumers with a meaningful understanding and accurate expectations of how their personal data will be processed. This raises the bar beyond boilerplate disclosures and requires organizations to align their stated practices with their actual data handling. This entry does not address applicability thresholds, enforcement mechanisms, penalty amounts, retention rules, or cross-border transfer mechanics, which must be confirmed against the statute and its implementing regulations.

Who it's relevant to

Compliance and privacy officers
Teams responsible for multi-state privacy compliance need to treat the CPA as a distinct instrument and map its consumer rights and controller/processor obligations separately from those under the CCPA/CPRA or the EU and UK GDPR. Because obligations, definitions, and thresholds differ across regimes, assuming interchangeability is a common expert-level mistake to avoid.
Data controllers operating in Colorado
Organizations that determine the purposes and means of processing Colorado consumers' personal data generally bear primary accountability under the CPA, including responsibility for honoring access, deletion, and correction rights and for maintaining a privacy notice that gives consumers a meaningful and accurate understanding of processing. Accountability requires demonstrable evidence, not merely stated intent.
Data processors
Parties that process personal data on a controller's behalf carry obligations under the CPA that differ from those of controllers. The precise allocation of duties between the two roles should be confirmed against the statute and its implementing regulations rather than assumed from other frameworks.
Legal and governance teams
Legal counsel and information governance leads supporting Colorado-facing businesses should verify applicability thresholds, enforcement mechanisms, retention rules, and any assessment or transfer requirements directly against the CPA and its implementing regulations, as these are outside the scope of this general overview.

Inside CPA

Scope and Applicability Thresholds
The Colorado Privacy Act (CPA) is a US state-level comprehensive privacy statute that generally applies to entities conducting business in Colorado or targeting Colorado residents that meet defined processing-volume or revenue-linked thresholds. Applicability is determined by these criteria rather than being universal, and the precise threshold figures should be confirmed against the current statutory text rather than assumed.
Controller and Processor Roles
The CPA distinguishes between controllers, who determine the purposes and means of processing and bear the primary compliance obligations, and processors, who process on a controller's behalf under contractual instructions. This role distinction governs who owes which duties; the two should not be treated as interchangeable, and processor obligations are typically anchored in the controller-processor contract.
Consumer Rights
The CPA grants Colorado consumers a set of rights that generally include access, correction, deletion, portability, and the ability to opt out of certain processing such as targeted advertising, the sale of personal data, and certain profiling. The exact contours and any exemptions should be read from the statute and its implementing rules; this entry does not enumerate procedural response deadlines.
Opt-Out and Universal Opt-Out Mechanism
The CPA contemplates an opt-out model for specified processing activities and provides for recognition of a universal opt-out signal. This differs from an opt-in consent model and is a state-specific mechanism; its operation should not be assumed identical to opt-out or consent approaches in other US states or non-US regimes.
Sensitive Data Handling
The CPA treats certain categories as sensitive data and generally requires a heightened basis, such as consent, before processing them. Sensitive data under the CPA is a narrower designation than personal data broadly and should not be conflated with the EU or UK GDPR concept of special category data, which is defined under a separate regime with different categories and conditions.
Data Protection Assessments
The CPA requires controllers to conduct data protection assessments for processing that presents a heightened risk of harm, such as certain profiling, targeted advertising, or sensitive-data processing. This is a risk-triggered obligation and is not required for every processing activity; it is a distinct instrument from the EU/UK GDPR data protection impact assessment, though conceptually related.
Enforcement and Regulatory Authority
Enforcement of the CPA is generally vested in state authority rather than a private right of action. This entry does not state specific penalty amounts, cure-period mechanics, or effective dates, which should be verified against current statutory and regulatory sources.

Common questions

Answers to the questions practitioners most commonly ask about CPA.

Does complying with the EU GDPR mean an organization automatically complies with the Colorado Privacy Act (CPA)?
No. While the CPA shares conceptual overlap with the EU GDPR, such as recognizing consumer rights and imposing duties on those who determine the purposes and means of processing, the two are distinct legal instruments with different scoping, terminology, thresholds, and obligations. The CPA is a US state statute and uses its own definitions of covered entities and personal data, while the EU GDPR applies under its own territorial scope. A GDPR compliance program can provide a useful foundation, but each CPA requirement must be assessed against the Colorado statute itself rather than assumed to be satisfied. This answer does not address whether other US state laws or the EU GDPR apply to a given organization.
Is consent the default or required basis for processing under the CPA in the way lawful bases operate under the GDPR?
No, and it is a common error to map CPA obligations directly onto the EU GDPR's lawful basis framework. The CPA does not use the GDPR's structure of enumerated lawful bases such as legitimate interests or contractual necessity. Instead, it centers on consumer rights and opt-out mechanisms for certain processing, with consent required in specific defined circumstances rather than as a general precondition for all processing. Treating consent as the universal foundation for processing under the CPA misrepresents how the statute is structured. Whether consent is required in a particular scenario depends on the nature of the processing and must be evaluated against the statute's specific triggers; this answer does not enumerate those triggers.
How should an organization determine whether the CPA applies to it?
Applicability under the CPA turns on statutory scoping criteria, which typically include factors such as whether an entity conducts business in or targets consumers in the state and whether it meets defined processing thresholds. An organization should map its consumer data flows, the volume and categories of Colorado consumer personal data it processes, and any activities that may fall within the statute's scope. Because thresholds and exemptions are set by the statute and can be interpreted alongside regulatory guidance, this determination should be documented and reviewed by qualified counsel. This answer does not state specific numeric thresholds or exemption categories, which must be confirmed against the current text of the Act.
What role do data protection assessments play in a CPA implementation program?
The CPA contemplates assessments for processing that presents a heightened risk to consumers, and these assessments serve as documented, evidence-based evaluations rather than a mere statement of intent. As a practical matter, an organization should establish a repeatable process to identify processing activities that may trigger an assessment obligation, conduct and record the analysis, and retain that documentation as demonstrable evidence of accountability. It is a mistake to assume an assessment is required for every processing activity; the obligation generally attaches to defined higher-risk categories. This answer does not enumerate which processing categories trigger an assessment, which should be confirmed against the statute and applicable rules.
How should an organization operationalize consumer rights requests under the CPA?
Operationalizing consumer rights typically involves establishing intake channels for requests, a process to verify the identity of the requesting consumer where appropriate, workflows to locate and act on the relevant personal data, and a mechanism to respond within the timeframes and constraints set by the statute. Because the CPA provides for opt-out rights in certain contexts, organizations should also implement the technical means to honor opt-out signals as required. Accountability generally requires retaining records that demonstrate requests were received and handled. This answer does not specify response deadlines, appeal procedures, or the precise catalog of rights, which must be drawn from the current statutory text.
What contractual or vendor governance steps support CPA compliance?
Where an organization engages a party that processes personal data on its behalf, the CPA generally expects contractual terms that govern the scope, purpose, and handling of that processing. Practically, this involves inventorying vendors that process Colorado consumer personal data, ensuring contracts reflect the required processing terms, and maintaining oversight of how those vendors meet their obligations. This is a governance and accountability activity that produces demonstrable evidence, and it should be coordinated with, but not treated as identical to, information security control requirements for those vendors. This answer does not specify the exact contractual clauses the statute requires, which should be confirmed against the current text and any implementing rules.

Common misconceptions

The CPA works the same way as the EU or UK GDPR, so a GDPR-compliant program automatically satisfies it.
The CPA is a distinct US state statute with its own applicability thresholds, consumer rights, opt-out mechanics, and sensitive data definitions. While it shares some conceptual language such as controller and processor, its scope and obligations differ from the EU GDPR and UK GDPR, and compliance with one does not guarantee compliance with the other. Cross-mapping should be validated against each instrument.
The CPA's sensitive data category is equivalent to GDPR special category data.
Sensitive data under the CPA is a US state-specific designation defined within that statute. It should not be treated as identical to the EU/UK GDPR special category data concept, which sits in a different regime with its own categories and lawful conditions for processing. The heightened treatment is analogous in spirit but not interchangeable in scope.
A data protection assessment is required for all processing under the CPA.
The CPA's assessment obligation is generally triggered by processing that presents a heightened risk of harm, such as certain profiling, targeted advertising, or sensitive-data processing. It is not a blanket requirement for every activity, and it should not be assumed to be always mandatory or identical to a GDPR data protection impact assessment.

Best practices

Confirm applicability against the current CPA statutory thresholds before assuming the law applies, and re-assess as processing volume or business activity changes rather than relying on a one-time determination.
Classify your role as controller or processor for each processing activity, and ensure controller-processor relationships are documented in contracts that reflect the responsibilities each party bears under the CPA.
Maintain a defensible record of data protection assessments for heightened-risk processing, treating the assessment as risk-triggered rather than universal and retaining demonstrable evidence rather than stated intent.
Implement and test mechanisms to honor consumer rights requests and opt-out signals, including recognition of a universal opt-out mechanism, and validate that they function as configured rather than assuming coverage.
Identify sensitive data under the CPA's specific definition and apply the heightened basis it requires, without assuming the same categories or conditions as GDPR special category data.
Do not treat a GDPR, CCPA/CPRA, or other program as automatically satisfying the CPA; map obligations to the CPA text specifically and reconcile differences, recognizing that compliance depends on jurisdiction and implementation.