close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Colorado Privacy Law

CO

Colorado (CPA)

Last updated

CPA Enacted, in effect

Who this affects: This page tracks Colorado’s CPA, which governs controllers and processors.

Who it applies to: Entities that do business in Colorado or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and any revenue or discount from selling personal data; other entities are covered regardless of this test (see below); some provisions apply under a separate test (see below).

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
July 1, 2023
Effective ↗
AG and DAs
Enforced by ↗
$20,000
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

CPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Respond to access, correction, and deletion requests within forty-five days, with reasons and appeal instructions if you decline. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CO-6-1-1306 “A consumer has the right to confirm whether a controller is processing personal data concerning the consumer and to access the consumer's personal data.” Read the statute CO-6-1-1306 “A consumer has the right to correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data.” Read the statute CO-6-1-1306 “A consumer has the right to delete personal data concerning the consumer.” Read the statute CO-6-1-1306 “A controller shall inform a consumer of any action taken on a request under subsection (1) of this section without undue delay and, in any event, within forty-five days after receipt of the request” Read the statute CO-6-1-1306 “the controller shall inform the consumer, without undue delay and, at the latest, within forty-five days after receipt of the request, of the reasons for not taking action and instructions for how to appeal the decision with the controller” Read the statute
  • If you sell data or target ads, post a conspicuous opt-out method and honor universal opt-out mechanisms meeting AG specs. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CO-6-1-1306 “Effective July 1, 2024, a controller that processes personal data for purposes of targeted advertising or the sale of personal data shall allow consumers to exercise the right to opt out of the processing of personal data concerning the consumer for purposes of targeted advertising or the sale of personal data pursuant to subsections (1)(a)(I)(A) and (1)(a)(I)(B) of this section by controllers through a user-selected universal opt-out mechanism that meets the technical specifications established by the attorney general pursuant to section 6-1-1313.” Read the statute CO-6-1-1306 “The controller shall provide the opt-out method clearly and conspicuously in any privacy notice required to be provided to consumers under this part 13, and in a clear, conspicuous, and readily accessible location outside the privacy notice.” Read the statute
  • Set up an appeal process, answer appeals in writing within forty-five days, and note consumers can contact the attorney general. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CO-6-1-1306 “A controller shall establish an internal process whereby consumers may appeal a refusal to take action on a request to exercise any of the rights under subsection (1) of this section” Read the statute CO-6-1-1306 “Within forty-five days after receipt of an appeal, a controller shall inform the consumer of any action taken or not taken in response to the appeal, along with a written explanation of the reasons in support of the response” Read the statute CO-6-1-1306 “The controller shall inform the consumer of the consumer's ability to contact the attorney general if the consumer has concerns about the result of the appeal” Read the statute

Can't

  • Process or sell sensitive data without the consumer's consent or, for a known child, a parent or lawful guardian's consent. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CO-6-1-1308 “A controller shall not process or sell a consumer's sensitive data without first obtaining the consumer's consent or, in the case of the processing of personal data concerning a known child, without first obtaining consent from the child's parent or lawful guardian” Read the statute
  • Conduct heightened-risk processing of data acquired on or after July 1, 2023 without a documented data protection assessment. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CO-6-1-1309 “A controller shall not conduct processing that presents a heightened risk of harm to a consumer without conducting and documenting a data protection assessment of each of its processing activities that involve personal data acquired on or after July 1, 2023, that present a heightened risk of harm to a consumer” Read the statute
  • Sell, lease, or trade biometric identifiers, or deny service to those declining biometric consent unless necessary to provide it. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CO-6-1-1314 “Sell, lease, or trade the biometric identifier with any entity” Read the statute CO-6-1-1314 “Refuse to provide a good or service to a consumer based on the consumer's refusal to consent to the controller's collection, use, disclosure, transfer, sale, retention, or processing of a biometric identifier unless the collection, use, disclosure, transfer, sale, retention, or processing of the biometric identifier is necessary to provide the good or service” Read the statute

Should

  • Bind processors by contract setting instructions, purpose, data type, and duration; processors must also allow reasonable audits. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CO-6-1-1305 “Processing by a processor must be governed by a contract between the controller and the processor that is binding on both parties and that sets out: (a) The processing instructions to which the processor is bound, including the nature and purpose of the processing; (b) The type of personal data subject to the processing, and the duration of the processing” Read the statute CO-6-1-1305 “The processor shall allow for, and contribute to, reasonable audits and inspections by the controller or the controller's designated auditor” Read the statute
  • Specify express purposes for collecting data, collect only what is reasonably necessary, and get consent for incompatible uses. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CO-6-1-1308 “A controller shall specify the express purposes for which personal data are collected and processed” Read the statute CO-6-1-1308 “A controller's collection of personal data must be adequate, relevant, and limited to what is reasonably necessary in relation to the specified purposes for which the data are processed” Read the statute CO-6-1-1308 “A controller shall not process personal data for purposes that are not reasonably necessary to or compatible with the specified purposes for which the personal data are processed, unless the controller first obtains the consumer's consent” Read the statute
  • If you process biometric identifiers, adopt a written retention, incident, and deletion policy and get consent before collecting. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. CO-6-1-1314 “A controller that controls or processes one or more biometric identifiers shall adopt a written policy that: (I) Establishes a retention schedule for biometric identifiers and biometric data; (II) Includes a protocol for responding to a data security incident that may compromise the security of biometric identifiers or biometric data, including a process for notifying a consumer when the security of the consumer's biometric identifier or biometric data has been breached, pursuant to section 6-1-716; and (III) Includes guidelines that require the deletion of a biometric identifier on or before the earliest of the following dates: (A) The date upon which the initial purpose for collecting the biometric identifier has been satisfied; (B) Twenty-four months after the consumer last interacted with the controller; or (C) The earliest reasonably feasible date, which date must be no more than forty-five days after a controller determines that storage of the biometric identifier is no longer necessary, adequate, or relevant to the express processing purpose identified by a review conducted by the controller at least once annually.” Read the statute CO-6-1-1314 “A controller shall obtain consent from a consumer or from the consumer's legally authorized representative before collecting the consumer's biometric data” Read the statute

These are the highlights we judge most important, not everything CPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Colorado Privacy Act

CPA (SB21-190) is Colorado’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read 6-1-1301. Short title. The short title of this part 13 is the "Colorado Privacy Act". Source: L. 2021: Entire part added, (SB 21-190), ch. 483, p. 3445, § 1, effective July 1, 2023. Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
Effective
July 1, 2023
Archived excerpt — the text we read 6-1-1301. Short title. The short title of this part 13 is the "Colorado Privacy Act". Source: L. 2021: Entire part added, (SB 21-190), ch. 483, p. 3445, § 1, effective July 1, 2023. Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
Signed
July 7, 2021
“07/07/2021 Governor Governor Signed” View the source
Enforced by
Attorney General and District Attorneys
Colorado Attorney General and District Attorneys Archived excerpt — the text we read 6-1-1311. Enforcement - penalties - repeal. (1) (a) Notwithstanding any other provision of this article 1, the attorney general and district attorneys have exclusive authority to enforce this part 13 by bringing an action in the name of the state or as parens patriae on behalf of persons residing in the state to enforce this part 13 as provided in this article 1, including seeking an injunction to enjoin a violation of this part 13. (b) Notwithstanding any other provision of this article 1, nothing in this part 13 shall be c… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
Maximum penalty per violation
$20,000; up to $50,000 (elderly)
Deemed a deceptive trade practice; 6-1-112 counts each consumer or transaction as a separate violation, with no cap. Source for each figure$20,000 · CO-6-1-112 $10,000 · CO-6-1-112 $50,000 · CO-6-1-112 “a civil penalty of not more than twenty thousand dollars for each violation. For purposes of this subsection (1)(a), a violation of any provision constitutes a separate violation with respect to each consumer or transaction involved” View the statute
Right to cure
60 days, minors' provisions only (until Dec 31, 2026)
General cure repealed Jan 1, 2025. A 60-day cure still applies to the minors' provisions until Dec 31, 2026. Archived excerpt — the text we read …ns of this part 13 or any other law. (c) For purposes only of enforcement of this part 13 by the attorney general or a district attorney, a violation of this part 13 is a deceptive trade practice. (d) (I) Repealed. (II) Prior to any enforcement action pursuant to subsection (1)(a) of this section to enforce section 6-1-1305.5, 6-1-1308.5, or 6-1-1309.5, the attorney general or district attorney must issue a notice of violation to the controller if a cure is deemed possible. If the controller fails to cure the violation within sixty days after receipt of the notice of violation, an action may be brought pursuant to this section. This subsection (1)(d)(II) is repealed, effective December 31, 2026. (2) The state treasurer shall credit all receipts from the imposition of civil penalties under this part 13 pursuant to section 24-31-108. … Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read …f of persons residing in the state to enforce this part 13 as provided in this article 1, including seeking an injunction to enjoin a violation of this part 13. (b) Notwithstanding any other provision of this article 1, nothing in this part 13 shall be construed as providing the basis for, or being subject to, a private right of action for violations of this part 13 or any other law. (c) For purposes only of enforcement of this part 13 by the attorney general or a district attorney, a violation of this part 13 is a deceptive trade practice. (d) (I) Repealed. (II) Prior to any enforcement action pur… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
Universal opt-out signal
Required
Archived excerpt — the text we read …od clearly and conspicuously in any privacy notice required to be provided to consumers under this part 13, and in a clear, conspicuous, and readily accessible location outside the privacy notice. (IV) (A) Repealed. (B) Effective July 1, 2024, a controller that processes personal data for purposes of targeted advertising or the sale of personal data shall allow consumers to exercise the right to opt out of the processing of personal data concerning the consumer for purposes of targeted advertising or the sale of personal data pursuant to subsections (1)(a)(I)(A) and (1)(a)(I)(B) of this section by controllers through a user-selected universal opt-out mechanism that meets the technical specifications established by the attorney general pursuant to section 6-1-1313. (C) Notwithstanding a consumer's decision to exercise the right to opt out of the processing of personal data through a universal opt-out mechanism pursuant to subsection (1)(a)(IV)(B) of this section, a controller may … Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source

Who it applies to

Entities that do business in Colorado or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and any revenue or discount from selling personal data; other entities are covered regardless of this test (see full text); some provisions apply under a separate test (see full text)

What the law gives consumers

  • Right to opt out of sale Archived excerpt — the text we read …it a request at any time to a controller specifying which of the following rights the consumer wishes to exercise: (a) Right to opt out. (I) A consumer has the right to opt out of the processing of personal data concerning the consumer for purposes of: (A) Targeted advertising; (B) The sale of personal data; or (C) Profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer. (II) A consumer may authorize another person, acting on the consumer's behalf, to opt out of the p… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read …it a request at any time to a controller specifying which of the following rights the consumer wishes to exercise: (a) Right to opt out. (I) A consumer has the right to opt out of the processing of personal data concerning the consumer for purposes of: (A) Targeted advertising; (B) The sale of personal data; or (C) Profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer. (II) A consumer may authorize another person, acting on the consume… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Right to opt out of profiling for significant decisions Archived excerpt — the text we read … (a) Right to opt out. (I) A consumer has the right to opt out of the processing of personal data concerning the consumer for purposes of: (A) Targeted advertising; (B) The sale of personal data; or (C) Profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer. (II) A consumer may authorize another person, acting on the consumer's behalf, to opt out of the processing of the consumer's personal data for one or more of the purposes specified in subsection (1)(a)(I) of this sect… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Right to access Archived excerpt — the text we read …mer's consent to process personal data for purposes of targeted advertising or the sale of personal data must also allow the consumer to revoke the consent as easily as it is affirmatively provided. (b) Right of access. A consumer has the right to confirm whether a controller is processing personal data concerning the consumer and to access the consumer's personal data. (c) Right to correction. A consumer has the right to correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's persona… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Right to correct Archived excerpt — the text we read …irmatively provided. (b) Right of access. A consumer has the right to confirm whether a controller is processing personal data concerning the consumer and to access the consumer's personal data. (c) Right to correction. A consumer has the right to correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. (d) Right to deletion. A consumer has the right to delete personal data concerning the consumer. (e) Right to data portability. When exercising the right to access personal data pursuant to subsection (1)(b) of this sec… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Right to delete Archived excerpt — the text we read …sumer has the right to correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. (d) Right to deletion. A consumer has the right to delete personal data concerning the consumer. (e) Right to data portability. When exercising the right to access personal data pursuant to subsection (1)(b) of this section, a consumer has the right to obtain the personal data in a portable and, to the extent techn… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Right to data portability Exercised with the right of access; no more than two times per calendar year; trade secrets need not be disclosed (6-1-1306(1)(e)). Archived excerpt — the text we read …re of the personal data and the purposes of the processing of the consumer's personal data. (d) Right to deletion. A consumer has the right to delete personal data concerning the consumer. (e) Right to data portability. When exercising the right to access personal data pursuant to subsection (1)(b) of this section, a consumer has the right to obtain the personal data in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another entity without hindrance. A consumer may exercise this right no more than two times per calendar year. Nothing in this subsection (1)(e) requires a controller to provide the data to the consumer in a manner that would disclose the controller's trade secrets. (2) Responding to consumer requests. (a) A controller shall inf… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Right to appeal Archived excerpt — the text we read …ler is unable to authenticate the request using commercially reasonable efforts, in which case the controller may request the provision of additional information reasonably necessary to authenticate the request. (3) (a) A controller shall establish an internal process whereby consumers may appeal a refusal to take action on a request to exercise any of the rights under subsection (1) of this section within a reasonable period after the consumer's receipt of the notice sent by the controller under subsection (2)(b) of this section. The appeal process must be conspicuously available and as easy to use as the process … Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Right against discrimination Archived excerpt — the text we read …ng, as well as the manner in which a consumer may exercise the right to opt out of the sale or processing. (c) A controller shall not: (I) Require a consumer to create a new account in order to exercise a right; or (II) Based solely on the exercise of a right and unrelated to feasibility or the value of a service, increase the cost of, or decrease the availability of, the product or service. (d) Nothing in this part 13 shall be construed to require a controller to provide a product or service that requires the personal data of a consumer that the controller does not collect or maintain or to prohibit a con… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Sensitive data: opt-in consent required Archived excerpt — the text we read …. (6) Duty to avoid unlawful discrimination. A controller shall not process personal data in violation of state or federal laws that prohibit unlawful discrimination against consumers. (7) Duty regarding sensitive data. A controller shall not process or sell a consumer's sensitive data without first obtaining the consumer's consent or, in the case of the processing of personal data concerning a known child, without first obtaining consent from the child's parent or lawful guardian. Source: L. 2021: Entire part added, (SB 21-190), ch. 483, p. 3460… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read …f of persons residing in the state to enforce this part 13 as provided in this article 1, including seeking an injunction to enjoin a violation of this part 13. (b) Notwithstanding any other provision of this article 1, nothing in this part 13 shall be construed as providing the basis for, or being subject to, a private right of action for violations of this part 13 or any other law. (c) For purposes only of enforcement of this part 13 by the attorney general or a district attorney, a violation of this part 13 is a deceptive trade practice. (d) (I) Repealed. (II) Prior to any enforcement action pur… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read …ng only in an individual or household context; and (b) Does not include an individual acting in a commercial or employment context, as a job applicant, or as a beneficiary of someone acting in an employment context. (7) "Controller" means a person that, alone or jointly with others, determines the purposes for and means of processing personal data. (8) "Covered entity" has the meaning established in 45 CFR 160.103. (9) "Dark pattern" means a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Processors Archived excerpt — the text we read …s" or "processing" means the collection, use, sale, storage, disclosure, analysis, deletion, or modification of personal data and includes the actions of a controller directing a processor to process personal data. (19) "Processor" means a person that processes personal data on behalf of a controller. (20) "Profiling" means any form of automated processing of personal data to evaluate, analyze, or predict personal aspects concerning an identified or identifiable individual's economic situation, health, personal prefe… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source

Exemptions

  • HIPAA protected health information Data-level Protected health information collected, stored and processed by a HIPAA covered entity or business associate (data-level). Archived excerpt — the text we read …1-1309.5 to 6-1-1313 apply to a controller that conducts business in Colorado or delivers commercial products or services that are intentionally targeted to residents of Colorado. (2) This part 13 does not apply to: (a) Protected health information that is collected, stored, and processed by a covered entity or its business associates; (b) Health-care information that is governed by part 8 of article 1 of title 25 solely for the purpose of access to medical records; (c) Patient identifying information, as defined in 42 CFR 2.11, that are governed by … Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Health-care information for medical-records access Health-care information governed by part 8 of article 1 of title 25, solely for the purpose of access to medical records. Archived excerpt — the text we read …that are intentionally targeted to residents of Colorado. (2) This part 13 does not apply to: (a) Protected health information that is collected, stored, and processed by a covered entity or its business associates; (b) Health-care information that is governed by part 8 of article 1 of title 25 solely for the purpose of access to medical records; (c) Patient identifying information, as defined in 42 CFR 2.11, that are governed by and collected and processed pursuant to 42 CFR 2, established pursuant to 42 U.S.C. sec. 290dd-2; (d) Identifiable private informatio… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Patient identifying information under 42 CFR 2 Archived excerpt — the text we read …s collected, stored, and processed by a covered entity or its business associates; (b) Health-care information that is governed by part 8 of article 1 of title 25 solely for the purpose of access to medical records; (c) Patient identifying information, as defined in 42 CFR 2.11, that are governed by and collected and processed pursuant to 42 CFR 2, established pursuant to 42 U.S.C. sec. 290dd-2; (d) Identifiable private information, as defined in 45 CFR 46.102, for purposes of the federal policy for the protection of human subjects pursuant to 45 CFR 46; identifiable private information that is collected as pa… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Human subjects research information Archived excerpt — the text we read …se of access to medical records; (c) Patient identifying information, as defined in 42 CFR 2.11, that are governed by and collected and processed pursuant to 42 CFR 2, established pursuant to 42 U.S.C. sec. 290dd-2; (d) Identifiable private information, as defined in 45 CFR 46.102, for purposes of the federal policy for the protection of human subjects pursuant to 45 CFR 46; identifiable private information that is collected as part of human subjects research pursuant to the ICH E6 Good Clinical Practice Guideline issued by the International Council for Harmonisation of Technical Requireme… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Information created for HIPAA compliance Archived excerpt — the text we read …s for Human Use or the protection of human subjects under 21 CFR 50 and 56; or personal data used or shared in research conducted in accordance with one or more of the categories set forth in this subsection (2)(d); (e) Information and documents created by a covered entity for purposes of complying with HIPAA and its implementing regulations; (f) Patient safety work product, as defined in 42 CFR 3.20, that is created for purposes of patient safety improvement pursuant to 42 CFR 3… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Patient safety work product Archived excerpt — the text we read …(2)(d); (e) Information and documents created by a covered entity for purposes of complying with HIPAA and its implementing regulations; (f) Patient safety work product, as defined in 42 CFR 3.20, that is created for purposes of patient safety improvement pursuant to 42 CFR 3, established pursuant to 42 U.S.C. secs. 299b-21 to 299b-26; (g) Information that is: (I) De-identified in accordance with the requirements for de-identification set forth in 45 CFR 164; and (II) Derived from any of the health-care-related information described in this section; … Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • De-identified health-care-related information under 45 CFR 164 Archived excerpt — the text we read …t safety work product, as defined in 42 CFR 3.20, that is created for purposes of patient safety improvement pursuant to 42 CFR 3, established pursuant to 42 U.S.C. secs. 299b-21 to 299b-26; (g) Information that is: (I) De-identified in accordance with the requirements for de-identification set forth in 45 CFR 164; and (II) Derived from any of the health-care-related information described in this section; (h) Information maintained in the same manner as information under subsections (2)(a) to (2)(g) of this section by: (I) A cove… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Health-entity data maintained like exempt health information Data-level Information maintained in the same manner as the exempt health information in (2)(a) to (2)(g), by covered entities or business associates, health-care facilities or providers, or qualified service organization programs. Archived excerpt — the text we read …) Information that is: (I) De-identified in accordance with the requirements for de-identification set forth in 45 CFR 164; and (II) Derived from any of the health-care-related information described in this section; (h) Information maintained in the same manner as information under subsections (2)(a) to (2)(g) of this section by: (I) A covered entity or business associate; (II) A health-care facility or health-care provider; or (III) A program of a qualified service organization as defined in 42 CFR 2.11; (i) (I) Except as provided in subsectio… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • FCRA consumer-report activity Data-level Consumer-report activity (creditworthiness data) by consumer reporting agencies, furnishers and users of consumer reports, only to the extent regulated by the FCRA and used only as the FCRA authorizes. Archived excerpt — the text we read …mation as set forth in 15 U.S.C. sec. 1681s-2 that provides information for use in a consumer report, as defined in 15 U.S.C. sec. 1681a (d); or (C) A user of a consumer report as set forth in 15 U.S.C. sec. 1681b. (II) This subsection (2)(i) applies only to the extent that the activity is regulated by the federal "Fair Credit Reporting Act", 15 U.S.C. sec. 1681 et seq., as amended, and the personal data are not collected, maintained, disclosed, sold, communicated, or used except as authorized by the federal "Fair Credit Reporting Act", as amended. (j) Personal data: (I) Collected and maintained for purposes of article 22 of title 10; (II) Collected, processed, sold, or disclosed pursuant to the federal "Gramm-Leach-Bliley Act", 15 U.S.C. sec. 6801 et seq., as ame… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Colorado Health Benefit Exchange data Data-level Personal data collected and maintained for purposes of the Colorado Health Benefit Exchange Act (C.R.S. title 10, article 22). Archived excerpt — the text we read …. 1681 et seq., as amended, and the personal data are not collected, maintained, disclosed, sold, communicated, or used except as authorized by the federal "Fair Credit Reporting Act", as amended. (j) Personal data: (I) Collected and maintained for purposes of article 22 of title 10; (II) Collected, processed, sold, or disclosed pursuant to the federal "Gramm-Leach-Bliley Act", 15 U.S.C. sec. 6801 et seq., as amended, and implementing regulations, if the collection, processing, sale, or disclosure … Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Data processed under GLBA Title V, if in compliance Data-level Archived excerpt — the text we read …aintained, disclosed, sold, communicated, or used except as authorized by the federal "Fair Credit Reporting Act", as amended. (j) Personal data: (I) Collected and maintained for purposes of article 22 of title 10; (II) Collected, processed, sold, or disclosed pursuant to the federal "Gramm-Leach-Bliley Act", 15 U.S.C. sec. 6801 et seq., as amended, and implementing regulations, if the collection, processing, sale, or disclosure is in compliance with that law; (III) Collected, processed, sold, or disclosed pursuant to the federal "Driver's Privacy Protection Act of 1994", 18 U.S.C. sec. 2721 et seq., as amended, if the collection, processing, … Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read …disclosed pursuant to the federal "Gramm-Leach-Bliley Act", 15 U.S.C. sec. 6801 et seq., as amended, and implementing regulations, if the collection, processing, sale, or disclosure is in compliance with that law; (III) Collected, processed, sold, or disclosed pursuant to the federal "Driver's Privacy Protection Act of 1994", 18 U.S.C. sec. 2721 et seq., as amended, if the collection, processing, sale, or disclosure is regulated by that law, including implementing rules, regulations, or exemptions; (IV) Regulated by the federal "Children's Online Privacy Protection Act of 1998", 15 U.S.C. secs. 6501 to 6506, as amended, if collected, processed, and maintai… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • COPPA-regulated data Archived excerpt — the text we read … if the collection, processing, sale, or disclosure is regulated by that law, including implementing rules, regulations, or exemptions; (IV) Regulated by the federal "Children's Online Privacy Protection Act of 1998", 15 U.S.C. secs. 6501 to 6506, as amended, if collected, processed, and maintained in compliance with that law; or (V) Regulated by the federal "Family Educational Rights and Privacy Act of 1974", 20 U.S.C. sec. 1232g et seq., as amended, and its implementing regulations; (k) Data maintained for employment records purposes; (l) … Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read …ons, or exemptions; (IV) Regulated by the federal "Children's Online Privacy Protection Act of 1998", 15 U.S.C. secs. 6501 to 6506, as amended, if collected, processed, and maintained in compliance with that law; or (V) Regulated by the federal "Family Educational Rights and Privacy Act of 1974", 20 U.S.C. sec. 1232g et seq., as amended, and its implementing regulations; (k) Data maintained for employment records purposes; (l) An air carrier as defined in and regulated under 49 U.S.C. sec. 40101 et seq., as amended, and 49 U.S.C. sec. 41713, as amended; (m) A national securities associ… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Employment records data Archived excerpt — the text we read …processed, and maintained in compliance with that law; or (V) Regulated by the federal "Family Educational Rights and Privacy Act of 1974", 20 U.S.C. sec. 1232g et seq., as amended, and its implementing regulations; (k) Data maintained for employment records purposes; (l) An air carrier as defined in and regulated under 49 U.S.C. sec. 40101 et seq., as amended, and 49 U.S.C. sec. 41713, as amended; (m) A national securities association registered pursuant to the federal "Securities … Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Air carriers Archived excerpt — the text we read …; or (V) Regulated by the federal "Family Educational Rights and Privacy Act of 1974", 20 U.S.C. sec. 1232g et seq., as amended, and its implementing regulations; (k) Data maintained for employment records purposes; (l) An air carrier as defined in and regulated under 49 U.S.C. sec. 40101 et seq., as amended, and 49 U.S.C. sec. 41713, as amended; (m) A national securities association registered pursuant to the federal "Securities Exchange Act of 1934", 15 U.S.C. sec. 78o-3, as amended, or implementing regulations; (n) Customer data maintained by a public utilit… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • National securities associations Archived excerpt — the text we read …its implementing regulations; (k) Data maintained for employment records purposes; (l) An air carrier as defined in and regulated under 49 U.S.C. sec. 40101 et seq., as amended, and 49 U.S.C. sec. 41713, as amended; (m) A national securities association registered pursuant to the federal "Securities Exchange Act of 1934", 15 U.S.C. sec. 78o-3, as amended, or implementing regulations; (n) Customer data maintained by a public utility as defined in section 40-1-103 (1)(a)(I) or an authority as defined in section 43-4-503 (1), if the data are not collected, maintained, disclosed, sold, communicated, or… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Public utility customer data If not collected, maintained, disclosed, sold, communicated, or used except as authorized by state and federal law. Archived excerpt — the text we read …ended, and 49 U.S.C. sec. 41713, as amended; (m) A national securities association registered pursuant to the federal "Securities Exchange Act of 1934", 15 U.S.C. sec. 78o-3, as amended, or implementing regulations; (n) Customer data maintained by a public utility as defined in section 40-1-103 (1)(a)(I) or an authority as defined in section 43-4-503 (1), if the data are not collected, maintained, disclosed, sold, communicated, or used except as authorized by state and federal law; (o) Data maintained by a state institution of higher education, as defined in section 23-18-102 (10), the state, the judicial department of the state, or a county, city and county, or municipality if the data is collec… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • State and local government/higher education data Only if used as authorized by state and federal law for noncommercial purposes. Archived excerpt — the text we read …ined in section 40-1-103 (1)(a)(I) or an authority as defined in section 43-4-503 (1), if the data are not collected, maintained, disclosed, sold, communicated, or used except as authorized by state and federal law; (o) Data maintained by a state institution of higher education, as defined in section 23-18-102 (10), the state, the judicial department of the state, or a county, city and county, or municipality if the data is collected, maintained, disclosed, communicated, and used as authorized by state and federal law for noncommercial purposes. This subsection (2)(o) does not effect any other exemption available under this part 13. (p) Information used and disclosed in compliance with 45 CFR 164.512; or (q) A financial institution or an affiliate of a financia… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Information disclosed in compliance with 45 CFR 164.512 Archived excerpt — the text we read …is collected, maintained, disclosed, communicated, and used as authorized by state and federal law for noncommercial purposes. This subsection (2)(o) does not effect any other exemption available under this part 13. (p) Information used and disclosed in compliance with 45 CFR 164.512; or (q) A financial institution or an affiliate of a financial institution as defined by and that is subject to the federal "Gramm-Leach-Bliley Act", 15 U.S.C. sec. 6801 et seq., as amended, and implementing regulations… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Financial institutions under GLBA Archived excerpt — the text we read … by state and federal law for noncommercial purposes. This subsection (2)(o) does not effect any other exemption available under this part 13. (p) Information used and disclosed in compliance with 45 CFR 164.512; or (q) A financial institution or an affiliate of a financial institution as defined by and that is subject to the federal "Gramm-Leach-Bliley Act", 15 U.S.C. sec. 6801 et seq., as amended, and implementing regulations, including Regulation P, 12 CFR 1016. (3) The obligations imposed on controllers or processors under this part 13 do not: (a) Restrict a controller's or processor's ability to: (I) Comply with federal, state, or local laws, rules, or regulations; (II) Comp… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Purely personal or household activity Archived excerpt — the text we read …nder Colorado law as part of a privileged communication; (d) Apply to information made available by a third party that the controller has a reasonable basis to believe is protected speech pursuant to applicable law; (e) Apply to the processing of personal data by an individual in the course of a purely personal or household activity; (f) Require a controller or processor to implement an age verification or age-gating system or otherwise affirmatively collect the age of consumers, but a controller that chooses to conduct … Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Evidentiary privilege (compliance would violate a Colorado evidentiary privilege) Archived excerpt — the text we read …B) Is under the responsibility of a professional subject to confidentiality obligations under federal, state, or local law; or (XII) Assist another person with any of the activities set forth in this subsection (3); (b) Apply where compliance by the controller or processor with this part 13 would violate an evidentiary privilege under Colorado law; (c) Prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under Colorado law as part of a privileged communication; (d) Apply to informatio… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …sist another person with any of the activities set forth in this subsection (3); (b) Apply where compliance by the controller or processor with this part 13 would violate an evidentiary privilege under Colorado law; (c) Prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under Colorado law as part of a privileged communication; (d) Apply to information made available by a third party that the controller has a reasonable basis to believe is protected speech pursuant to applicable law; (e) Apply to the processing of personal data by an individu… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Third-party information reasonably believed to be protected speech Archived excerpt — the text we read … under Colorado law; (c) Prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under Colorado law as part of a privileged communication; (d) Apply to information made available by a third party that the controller has a reasonable basis to believe is protected speech pursuant to applicable law; (e) Apply to the processing of personal data by an individual in the course of a purely personal or household activity; (f) Require a controller or processor to implement an age verification or age-gating system or oth… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • No age-verification or age-gating obligation Archived excerpt — the text we read …he controller has a reasonable basis to believe is protected speech pursuant to applicable law; (e) Apply to the processing of personal data by an individual in the course of a purely personal or household activity; (f) Require a controller or processor to implement an age verification or age-gating system or otherwise affirmatively collect the age of consumers, but a controller that chooses to conduct commercially reasonable age estimation to determine which consumers are minors is not liable for an erroneous age estimation; and (g) Impose any obligation on a controller or processor that adversely affects the rights of any person to freedom of speech or freedom of the press guaranteed by the first amendment to the United States constitutio… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • First Amendment free speech and press rights Archived excerpt — the text we read …onduct commercially reasonable age estimation to determine which consumers are minors is not liable for an erroneous age estimation; and (g) Impose any obligation on a controller or processor that adversely affects the rights of any person to freedom of speech or freedom of the press guaranteed by the first amendment to the United States constitution. (4) Personal data that are processed by a controller pursuant to an exception provided by this section: (a) Shall not be processed for any purpose other than a purpose expressly listed in this section or as otherwise a… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Human subjects research information Data-level Human subjects research information under the ICH E6 Good Clinical Practice Guideline or 21 CFR parts 50 and 56. Archived excerpt — the text we read …42 CFR 2, established pursuant to 42 U.S.C. sec. 290dd-2; (d) Identifiable private information, as defined in 45 CFR 46.102, for purposes of the federal policy for the protection of human subjects pursuant to 45 CFR 46; identifiable private information that is collected as part of human subjects research pursuant to the ICH E6 Good Clinical Practice Guideline issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use or the protection of human subjects under 21 CFR 50 and 56; or personal data used or shared in research conducted in accordance with one or more of the categories set forth in this subsection (2)(d); (e) Information and documents created by a covered entity for purposes of comp… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Personal data used or shared in research conducted under those categories Data-level Archived excerpt — the text we read …he ICH E6 Good Clinical Practice Guideline issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use or the protection of human subjects under 21 CFR 50 and 56; or personal data used or shared in research conducted in accordance with one or more of the categories set forth in this subsection (2)(d); (e) Information and documents created by a covered entity for purposes of complying with HIPAA and its implementing regulations; (f) Patien… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source
  • Individuals acting in a commercial (B2B) or employment context, and others Data-level Individuals acting in a commercial (B2B) or employment context, job applicants, and beneficiaries of someone acting in an employment context. Outside the definition of consumer. Archived excerpt — the text we read … that contains descriptions of personal data processing along with other, unrelated information; (b) Hovering over, muting, pausing, or closing a given piece of content; and (c) Agreement obtained through dark patterns. (6) "Consumer": (a) Means an individual who is a Colorado resident acting only in an individual or household context; and (b) Does not include an individual acting in a commercial or employment context, as a job applicant, or as a beneficiary of someone acting in an employment context. (7) "Controller" means a person that, alone or jointly with others, determines the purposes for and means of processing personal data. (8) "Covered entity" has the meaning established in 45 CFR 160.103. (9) "Dark patter… Archived from source — captured 2026-09-29 · snapshot c11da60f Verify at the source

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

CPA milestones

Drag the handle or use ← → to step through the milestones. The marker shows where today falls.

Done Upcoming Today
You are here
Completed October 1, 2025

Duties toward minors took effect (SB 24-041)

Source: primary citation

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 29, 2026