The CPA took effect on July 1, 2023. The requirement to recognize Universal Opt-Out Mechanisms became effective for controllers on July 1, 2024.
Solutions / By Regulation
Honor Colorado's required Universal Opt-Out Mechanism, manage sensitive data consent, and run CPA-compliant Data Protection Assessments — all with one platform.
What is CO CPA?
The Colorado Privacy Act (CPA), effective July 1, 2023, regulates how controllers process personal data of Colorado residents. Colorado was the first US state to require recognition of a Universal Opt-Out Mechanism (UOOM), such as Global Privacy Control. The Colorado AG and District Attorneys enforce the law and have issued detailed implementing regulations.
Typical applicability thresholds
Key requirements
Recognize and honor approved UOOMs (e.g., Global Privacy Control) for sale and targeted advertising — required for controllers since July 1, 2024.
Obtain affirmative opt-in consent before processing sensitive data, including data revealing racial/ethnic origin, religion, mental or physical health, sex life, sexual orientation, citizenship/immigration status, genetic/biometric data, and children's data.
Provide access, correction, deletion, portability, and the right to opt out of sale, targeted advertising, and profiling in furtherance of decisions with legal/similarly significant effects.
Conduct DPAs for processing that presents heightened risk — sale, targeted ads, sensitive data, and certain profiling activities.
Implement reasonable security, limit data collection to what's adequate, relevant, and limited to purposes disclosed.
Re-prompt consent for sensitive data and certain processing at least every 24 months when the consumer has not interacted with the controller.
Penalties & enforcement
Violations of the CPA are deceptive trade practices under the Colorado Consumer Protection Act, with civil penalties of up to $20,000 per violation (and up to $50,000 for violations against elderly persons). The right-to-cure provision sunset on January 1, 2025.
How Clarip helps
Clarip unifies consent, data discovery, subject rights, and regulatory reporting — with workflows pre-configured for CO CPA.
Quick answers to the questions privacy, legal, and engineering teams most often ask about CO CPA.
The CPA took effect on July 1, 2023. The requirement to recognize Universal Opt-Out Mechanisms became effective for controllers on July 1, 2024.
A user-enabled global signal — such as Global Privacy Control — that communicates a consumer's choice to opt out of sales of personal data and targeted advertising. Colorado publishes a list of approved mechanisms that controllers must honor.
Personal data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life or sexual orientation, citizenship or citizenship status; genetic or biometric data processed to uniquely identify an individual; and personal data from a known child. Processing requires opt-in consent.
Yes. DPAs are required before engaging in processing that presents a heightened risk of harm, including processing for targeted advertising, sale of personal data, processing sensitive data, and profiling that presents a reasonably foreseeable risk.
No. The CPA's right-to-cure provision sunset on January 1, 2025. The Colorado AG and District Attorneys may now enforce without first providing notice and opportunity to cure.
Clarip detects and honors approved Universal Opt-Out signals, manages sensitive data opt-in with 24-month consent refresh, runs a CPA-tuned consumer rights portal with appeals, and includes templated Data Protection Assessment workflows aligned to Colorado's regulations.
Book a 30-minute walkthrough and a custom gap assessment against CO CPArequirements — mapped to the systems and vendors you already use.