iQ Cookie  State Law Series

State 4 of 25 · Colorado

Cookie & Privacy Law in Colorado

Published August 2026
Law in effect
Since July 1, 2023

Educational purposes only — not legal advice. This guide is intended to help you understand Colorado’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
CPA
SB 21-190
SIGNED
Jul 7, 2021
Gov. Jared Polis
EFFECTIVE
Jul 1, 2023
In effect 3+ years
STATE RANK
#3
To enact a law

The short version

Colorado was the third state to pass a comprehensive privacy law, and it has quietly become one of the most actively regulated. The Colorado Privacy Act (CPA) took effect July 1, 2023, and unlike most of its Virginia-model peers, Colorado followed up fast: a mandatory universal opt-out signal in 2024, new biometric and precise-geolocation categories in 2025, minors’ protections in 2025, and automated decision-making rules landing January 1, 2027. Few states have amended their privacy law this many times this quickly.

Colorado does not have a separate cookie law. Cookie compliance flows from the CPA itself — and specifically from its opt-out mechanism requirements, which are stricter than most states’ on the technical side.

Colorado Attorney General — Official Resource
Colorado Privacy Act, SB 21-190 — C.R.S. § 6-1-1303 et seq.

Who does it apply to?

The CPA covers any entity — including nonprofits — that conducts business in Colorado or targets Colorado residents, and meets at least one of these thresholds:

THRESHOLD 1

Controls or processes personal data of 100,000 or more Colorado consumers during a calendar year.

THRESHOLD 2

Controls or processes data of 25,000 or more consumers AND derives revenue — or a discount on goods or services — from selling personal data.

Unlike most states, Colorado has no revenue floor and explicitly covers nonprofits. Exemptions include GLBA-regulated financial institutions, HIPAA-covered entities, and certain higher-education and government data.

Consumer rights

Colorado residents whose data is covered by the CPA have these rights:

Access
Confirm whether their data is being processed and receive a copy
Correct
Fix inaccurate personal data
Delete
Request removal of personal data
Portability
Receive data in a usable, portable format
Opt out
Targeted ads, data sales, and profiling
Appeal
Challenge a controller’s decision

Businesses must respond within 45 days, extendable by another 45 if reasonably necessary. There is no private right of action — only the Attorney General and district attorneys can enforce.

What makes Colorado different

Server-side opt-out recognition is mandatory. Since July 1, 2024, businesses must honor universal opt-out mechanisms like Global Privacy Control — and Colorado requires it be recognized server-side, not just in front-end JavaScript. The signal must also propagate to downstream processors within 15 days.

Colorado has already fined an ad-tech firm $250,000 for ignoring GPC signals from 500,000+ users.

No cure period. Colorado’s original 60-day cure window sunset January 1, 2025. The Attorney General now has full discretion to enforce without offering a chance to fix violations first.

Biometric and precise-geolocation data are now sensitive. Two 2025 amendments (HB 24-1130 and SB 25-276) added unique biometric identifiers and geolocation within roughly 1,850 feet to the sensitive data category, requiring opt-in consent.

Minors 13–17 get opt-in protection. SB 24-041 (effective October 1, 2025) requires opt-in consent before targeted advertising or selling the data of anyone aged 13–17, plus mandatory data protection assessments for services likely to be used by minors.

ADMT rules arrive January 1, 2027. SB 26-189 will require documentation, consumer notices, and human review for automated decision-making that materially affects education, employment, housing, credit, insurance, or healthcare decisions. Get your consent stack solid now — this is the next compliance wave.

Sensitive data & children

Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Mental / physical health
Sex life / orientation
Citizenship / immigration status
Biometric identifiers
Genetic data
Precise geolocation (≈1,850 ft)
Children’s data (under 13)

For children under 13, COPPA-compliant parental consent satisfies the CPA. For ages 13–17, businesses need opt-in consent before selling that person’s data or using it for targeted advertising or certain profiling — and must complete a data protection assessment if the service is reasonably likely to be used by minors.

What this means for your cookies

Cookie typeRequirementWhat to do
Sensitive data cookies (precise geolocation, biometric)Opt-in requiredGate these behind affirmative consent before they fire.
Targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism, and honor it fast.
GPC / universal opt-out signalRequired, server-sideClient-side-only detection is not sufficient in Colorado. Confirm your consent tool processes the signal server-side.
Any cookies — users 13–17Opt-in requiredNo targeted advertising or sale without affirmative consent for known minors.
Analytics & functional cookiesNo specific requirementDisclose in your privacy policy. Confirm they are not building profiles that count as "sale."

Enforcement

$20,000
Max penalty per violation
None
Cure period sunset Jan 1, 2025
AG + DAs
No private right of action

The Colorado Attorney General and local district attorneys share enforcement authority, with penalties calculated under the state’s Consumer Protection Act — up to $20,000 per violation. With the cure period gone, Colorado has moved from warnings to real settlements: a $250,000 penalty against an ad-tech firm in 2025 for ignoring opt-out signals, and a $300,000 consent decree against a health app for collecting sensitive data without consent.

Your action checklist

The law is in effect now, with no cure period — here is what to check today:

1

Check your thresholds. Do you process data on 100,000+ Colorado consumers, or 25,000+ while profiting from data sales? Nonprofits are not exempt — check regardless of your tax status.

2

Verify server-side GPC recognition. Test with a GPC-enabled browser and confirm the signal is honored on the server, not just suppressed client-side. This is Colorado’s top enforcement target.

3

Audit sensitive data cookies. Precise geolocation and biometric identifiers now require opt-in — confirm any location or biometric-based cookies are gated correctly.

4

Flag users aged 13–17. If your site could reach minors, block targeted advertising and data sales until you have opt-in consent.

5

Update your privacy policy. Cover data categories, purposes, consumer rights including appeal, and whether data is sold or used for targeted advertising.

6

Watch the ADMT deadline. If you use automated tools for consequential decisions — lending, hiring, housing — start building documentation and notice processes ahead of January 1, 2027.

7

Review vendor contracts. Any processor handling Colorado resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.

Not sure where your site stands with Colorado?

iQ Cookie scans your site, verifies server-side GPC recognition, and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 4 of 25  ·  Next: Connecticut →