iQ Cookie State Law Series
Cookie & Privacy Law in Colorado
Educational purposes only — not legal advice. This guide is intended to help you understand Colorado’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.
The short version
Colorado was the third state to pass a comprehensive privacy law, and it has quietly become one of the most actively regulated. The Colorado Privacy Act (CPA) took effect July 1, 2023, and unlike most of its Virginia-model peers, Colorado followed up fast: a mandatory universal opt-out signal in 2024, new biometric and precise-geolocation categories in 2025, minors’ protections in 2025, and automated decision-making rules landing January 1, 2027. Few states have amended their privacy law this many times this quickly.
Colorado does not have a separate cookie law. Cookie compliance flows from the CPA itself — and specifically from its opt-out mechanism requirements, which are stricter than most states’ on the technical side.
Who does it apply to?
The CPA covers any entity — including nonprofits — that conducts business in Colorado or targets Colorado residents, and meets at least one of these thresholds:
Controls or processes personal data of 100,000 or more Colorado consumers during a calendar year.
Controls or processes data of 25,000 or more consumers AND derives revenue — or a discount on goods or services — from selling personal data.
Unlike most states, Colorado has no revenue floor and explicitly covers nonprofits. Exemptions include GLBA-regulated financial institutions, HIPAA-covered entities, and certain higher-education and government data.
Consumer rights
Colorado residents whose data is covered by the CPA have these rights:
Businesses must respond within 45 days, extendable by another 45 if reasonably necessary. There is no private right of action — only the Attorney General and district attorneys can enforce.
What makes Colorado different
Server-side opt-out recognition is mandatory. Since July 1, 2024, businesses must honor universal opt-out mechanisms like Global Privacy Control — and Colorado requires it be recognized server-side, not just in front-end JavaScript. The signal must also propagate to downstream processors within 15 days.
No cure period. Colorado’s original 60-day cure window sunset January 1, 2025. The Attorney General now has full discretion to enforce without offering a chance to fix violations first.
Biometric and precise-geolocation data are now sensitive. Two 2025 amendments (HB 24-1130 and SB 25-276) added unique biometric identifiers and geolocation within roughly 1,850 feet to the sensitive data category, requiring opt-in consent.
Minors 13–17 get opt-in protection. SB 24-041 (effective October 1, 2025) requires opt-in consent before targeted advertising or selling the data of anyone aged 13–17, plus mandatory data protection assessments for services likely to be used by minors.
ADMT rules arrive January 1, 2027. SB 26-189 will require documentation, consumer notices, and human review for automated decision-making that materially affects education, employment, housing, credit, insurance, or healthcare decisions. Get your consent stack solid now — this is the next compliance wave.
Sensitive data & children
Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:
For children under 13, COPPA-compliant parental consent satisfies the CPA. For ages 13–17, businesses need opt-in consent before selling that person’s data or using it for targeted advertising or certain profiling — and must complete a data protection assessment if the service is reasonably likely to be used by minors.
What this means for your cookies
| Cookie type | Requirement | What to do |
|---|---|---|
| Sensitive data cookies (precise geolocation, biometric) | Opt-in required | Gate these behind affirmative consent before they fire. |
| Targeted advertising cookies | Opt-out required | Provide a clear opt-out mechanism, and honor it fast. |
| GPC / universal opt-out signal | Required, server-side | Client-side-only detection is not sufficient in Colorado. Confirm your consent tool processes the signal server-side. |
| Any cookies — users 13–17 | Opt-in required | No targeted advertising or sale without affirmative consent for known minors. |
| Analytics & functional cookies | No specific requirement | Disclose in your privacy policy. Confirm they are not building profiles that count as "sale." |
Enforcement
The Colorado Attorney General and local district attorneys share enforcement authority, with penalties calculated under the state’s Consumer Protection Act — up to $20,000 per violation. With the cure period gone, Colorado has moved from warnings to real settlements: a $250,000 penalty against an ad-tech firm in 2025 for ignoring opt-out signals, and a $300,000 consent decree against a health app for collecting sensitive data without consent.
Your action checklist
The law is in effect now, with no cure period — here is what to check today:
Check your thresholds. Do you process data on 100,000+ Colorado consumers, or 25,000+ while profiting from data sales? Nonprofits are not exempt — check regardless of your tax status.
Verify server-side GPC recognition. Test with a GPC-enabled browser and confirm the signal is honored on the server, not just suppressed client-side. This is Colorado’s top enforcement target.
Audit sensitive data cookies. Precise geolocation and biometric identifiers now require opt-in — confirm any location or biometric-based cookies are gated correctly.
Flag users aged 13–17. If your site could reach minors, block targeted advertising and data sales until you have opt-in consent.
Update your privacy policy. Cover data categories, purposes, consumer rights including appeal, and whether data is sold or used for targeted advertising.
Watch the ADMT deadline. If you use automated tools for consequential decisions — lending, hiring, housing — start building documentation and notice processes ahead of January 1, 2027.
Review vendor contracts. Any processor handling Colorado resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.
iQ Cookie scans your site, verifies server-side GPC recognition, and deploys a lightweight US-built consent banner.
iQ Cookie State Law Series · Guide 4 of 25 · Next: Connecticut →