Last updated
Who this affects: This page tracks Colorado’s CPA, which governs controllers and processors.
Who it applies to: Entities that do business in Colorado or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and any revenue or discount from selling personal data; other entities are covered regardless of this test (see below); some provisions apply under a separate test (see below).
Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.The law, in plain English
CPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.
These are the highlights we judge most important, not everything CPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.
The comprehensive law
CPA (SB21-190) is Colorado’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.
What the law gives consumers
Who the law governs
Exemptions
Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.
Timeline
Drag the handle or use ← → to step through the milestones. The marker shows where today falls.
Source: primary citation