Solutions / By Regulation

Colorado Privacy Act compliance — including Universal Opt-Out.

Honor Colorado's required Universal Opt-Out Mechanism, manage sensitive data consent, and run CPA-compliant Data Protection Assessments — all with one platform.

CO CPA at a glance
$20K
max civil penalty per violation (CO Consumer Protection Act)
100K
CO consumers triggers applicability
45 days
to respond to a consumer rights request
UOOM
required since July 1, 2024

What is CO CPA?

Overview

The Colorado Privacy Act (CPA), effective July 1, 2023, regulates how controllers process personal data of Colorado residents. Colorado was the first US state to require recognition of a Universal Opt-Out Mechanism (UOOM), such as Global Privacy Control. The Colorado AG and District Attorneys enforce the law and have issued detailed implementing regulations.

Who must comply

Typical applicability thresholds

  • Conduct business in Colorado or target CO residents, and
  • Control/process PD of 100,000+ Colorado consumers per year, or
  • Control/process PD of 25,000+ consumers and derive any revenue (or discount) from selling PD
  • Excludes employee and B2B data

Key requirements

What CO CPA expects from your organization.

Universal Opt-Out Mechanism

Recognize and honor approved UOOMs (e.g., Global Privacy Control) for sale and targeted advertising — required for controllers since July 1, 2024.

Sensitive data consent

Obtain affirmative opt-in consent before processing sensitive data, including data revealing racial/ethnic origin, religion, mental or physical health, sex life, sexual orientation, citizenship/immigration status, genetic/biometric data, and children's data.

Consumer rights

Provide access, correction, deletion, portability, and the right to opt out of sale, targeted advertising, and profiling in furtherance of decisions with legal/similarly significant effects.

Data Protection Assessments

Conduct DPAs for processing that presents heightened risk — sale, targeted ads, sensitive data, and certain profiling activities.

Duty of care & purpose limitation

Implement reasonable security, limit data collection to what's adequate, relevant, and limited to purposes disclosed.

Refresh consent

Re-prompt consent for sensitive data and certain processing at least every 24 months when the consumer has not interacted with the controller.

Penalties & enforcement

What's at stake

Violations of the CPA are deceptive trade practices under the Colorado Consumer Protection Act, with civil penalties of up to $20,000 per violation (and up to $50,000 for violations against elderly persons). The right-to-cure provision sunset on January 1, 2025.

How Clarip helps

Operationalize CO CPA on one platform.

Clarip unifies consent, data discovery, subject rights, and regulatory reporting — with workflows pre-configured for CO CPA.

UOOM & consent

  • Approved Universal Opt-Out handling
  • Sensitive data opt-in flows
  • 24-month consent refresh automation

Consumer rights

  • CPA-tuned rights portal
  • Identity verification
  • Appeals & SLA tracking

Data mapping

  • Auto-classify sensitive data
  • Purpose limitation tagging
  • Processor inventory

DPAs

  • CPA DPA templates
  • Risk vs. benefit analysis
  • Audit-ready evidence storage

Notices

  • Privacy notice generator
  • UOOM disclosure language
  • Profiling notice & opt-out

Multi-state reuse

  • Reuse controls across CCPA, VA, CT, UT
  • Unified data map
  • Centralized policy library
FAQ

CO CPA compliance, answered.

Quick answers to the questions privacy, legal, and engineering teams most often ask about CO CPA.

The CPA took effect on July 1, 2023. The requirement to recognize Universal Opt-Out Mechanisms became effective for controllers on July 1, 2024.

A user-enabled global signal — such as Global Privacy Control — that communicates a consumer's choice to opt out of sales of personal data and targeted advertising. Colorado publishes a list of approved mechanisms that controllers must honor.

Personal data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life or sexual orientation, citizenship or citizenship status; genetic or biometric data processed to uniquely identify an individual; and personal data from a known child. Processing requires opt-in consent.

Yes. DPAs are required before engaging in processing that presents a heightened risk of harm, including processing for targeted advertising, sale of personal data, processing sensitive data, and profiling that presents a reasonably foreseeable risk.

No. The CPA's right-to-cure provision sunset on January 1, 2025. The Colorado AG and District Attorneys may now enforce without first providing notice and opportunity to cure.

Clarip detects and honors approved Universal Opt-Out signals, manages sensitive data opt-in with 24-month consent refresh, runs a CPA-tuned consumer rights portal with appeals, and includes templated Data Protection Assessment workflows aligned to Colorado's regulations.

Get CO CPA-ready with Clarip.

Book a 30-minute walkthrough and a custom gap assessment against CO CPArequirements — mapped to the systems and vendors you already use.