{
 "jurisdiction_id": "US-CO",
 "jurisdiction": "United States – Colorado",
 "url": "https://dataprotection.gi/jurisdictions/united-states-colorado/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 44,
  "sub_modules": 57,
  "source_register": 28
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-colorado/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Mature, clearly-scoped statute with an active regulator and settled thresholds; no registration gap materially affects compliance certainty.",
   "claims": [
    {
     "statement": "The Colorado Attorney General is the primary regulator and enforcement authority for the Colorado Privacy Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/colorado",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Colorado Privacy Act (Senate Bill 21-190) was signed into law on July 7, 2021 and became effective July 1, 2023.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://dataguidance.com/resource/colorado-joins-us-privacy-landscape-new-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPA applies to controllers conducting business in or targeting Colorado residents that control or process the personal data of 100,000 or more consumers per calendar year, or that derive revenue from data sales and process the data of 25,000 or more consumers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/colorado-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPA applies to any controller that conducts business in Colorado or produces/delivers commercial products or services intentionally targeted to Colorado residents, regardless of the controller's own location.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/colorado-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-colorado/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Consent and sensitive-data rules are well defined in statute and implementing rules (4 CCR 904-3).",
   "claims": [
    {
     "statement": "Controllers are prohibited from processing sensitive data without first obtaining consumer consent, which must be freely given, specific, informed, and unambiguous.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/colorado-privacy-act-becomes-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where personal data concerns a known child, controllers must obtain consent from the child's parent or lawful guardian before processing sensitive data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/colorado-newly-approved-cpa-%E2%80%93-overview-key",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Colorado's definition of sensitive data includes racial and ethnic origin, religious beliefs, and genetic and biometric data, among other categories.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://dataguidance.com/resource/colorado-joins-us-privacy-landscape-new-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPA defines pseudonymous data as personal data that can no longer be attributed to a specific individual without additional information kept separately under technical and organizational safeguards.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/colorado-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-colorado/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights and deadlines are clearly codified and operative since 2023.",
   "claims": [
    {
     "statement": "Colorado consumers have the right to access personal data processed about them by a controller.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/colorado",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consumers have the right to correct inaccuracies in their personal data and to delete personal data held by a controller.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/colorado",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consumers may opt out of the processing of personal data for targeted advertising, sale, or profiling used for decisions that produce legal or similarly significant effects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/colorado-newly-approved-cpa-%E2%80%93-overview-key",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPA mandates that controllers provide a conspicuously available and easy-to-use appeal process when a consumer rights request is denied, and must inform the consumer of the ability to contact the Attorney General if the appeal is denied.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/colorado-privacy-act-becomes-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPA provides consumers a right to obtain a portable copy of their personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/colorado",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A business must respond to a consumer rights request within 45 days of receipt and may extend that deadline by an additional 45 days when reasonably necessary, notifying the consumer within the initial 45-day period.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/colorado-privacy-act-becomes-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-colorado/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability, security, and breach duties are robust and in force, but the absence of DPO/ROPA-equivalent obligations creates a structural gap relative to GDPR-style regimes.",
   "claims": [
    {
     "statement": "Controllers may not process personal data in a manner presenting a heightened risk of harm to a consumer without conducting and documenting a data protection assessment of that processing activity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/colorado-privacy-act-becomes-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Processing by a processor must be governed by a contract between the controller and processor establishing processing instructions, the nature and type of personal data, and the duration of processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/colorado-privacy-act-becomes-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPA imposes a duty of care requiring controllers to take security precautions appropriate to the volume, scope, and nature of the personal data processed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/colorado-privacy-act-becomes-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Colorado law requires notice to affected residents in the most expedient way and without unreasonable delay, but not later than 30 days after confirming a breach, and requires notice to the Colorado Attorney General within 30 days where the breach is reasonably believed to affect 500 or more residents.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/colorados-new-data-destruction-vendor-management-and-breach-notification-requirements",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "HB 24-1130 requires controllers to adopt a written policy establishing a retention schedule and destruction guidelines for biometric identifiers, extending the destruction period to 45 days.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colorado-bill-amending-cpa-address-biometric-0",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-colorado/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No comprehensive cross-border transfer regime exists at the US-CO state level; this is a legitimate structural gap, not a research omission.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-colorado/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial, health, and employment carve-outs are clear, but telecoms/ePrivacy, credit-scoring, and education overlays are not separately codified, leaving coverage partial.",
   "claims": [
    {
     "statement": "Entities regulated by the Gramm-Leach-Bliley Act are exempt at the entity level from Colorado Privacy Act obligations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/colorado-privacy-act-becomes-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Protected health information collected, stored, and processed by HIPAA-covered entities or their business associates is exempt from the Colorado Privacy Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/colorado-newly-approved-cpa-%E2%80%93-overview-key",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPA's definition of 'consumer' excludes an individual acting in a commercial or employment context, as a job applicant, or as a beneficiary of someone acting in an employment context.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/colorado-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Colorado enacted the Restrict Insurers' Use of External Consumer Data Act (SB 21-169), restricting insurers' use of external consumer data and algorithms in ways that could result in unfair discrimination.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/system/files/ftc_gov/pdf/commercial_surveillance_and_data_security_anpr.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "green",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-colorado/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "UOOM and dark-pattern rules are operative and well documented; gaps exist only in emerging areas like clean rooms.",
   "claims": [
    {
     "statement": "Under CPA Rules, any agreement obtained through dark patterns is not valid consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Colorado Department of Law",
     "source_url": "https://www.dataguidance.com/sites/default/files/colorado_privacy_act_draft_rules.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "From July 1, 2024, data controllers must allow consumers to exercise opt-out rights for targeted advertising or sale of personal data through a user-selected universal opt-out mechanism meeting AG technical specifications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/colorado-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Colorado currently considers the Global Privacy Control to be the only recognized valid universal opt-out mechanism under the CPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/there-s-no-opting-out-of-universal-opt-outs",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Colorado Department of Law maintains and publishes a public list of recognized universal opt-out mechanisms, with the initial list published no later than April 1, 2024.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/colorado-colorado-privacy-act-draft-rules-what-you-0",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-colorado/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric and profiling rules are settled, but the AI Act framework remains in active flux (major 2026 amendments, delayed effective date, pending litigation), creating material regulatory uncertainty.",
   "claims": [
    {
     "statement": "Consumers may opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/colorado-newly-approved-cpa-%E2%80%93-overview-key",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Senate Bill 189, deployers of covered AI systems must provide consumers with explicit disclosures regarding intended and harmful uses of automated decision-making technology, training-data categories, and deployer oversight instructions.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/amendments-move-colorado-ai-act-s-focus-from-risk-to-transparency",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Senate Bill 189 (2026) replaces the Colorado AI Act's original risk-based framework with disclosure and transparency requirements, removing the duty-of-care, risk-management-program, and impact-assessment obligations that had applied to deployers.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/amendments-move-colorado-ai-act-s-focus-from-risk-to-transparency",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "SB 189 moves the Colorado AI Act's principal effective date to January 1, 2027, superseding the prior June 30, 2026 date.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/amendments-move-colorado-ai-act-s-focus-from-risk-to-transparency",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "HB 24-1130 requires controllers to disclose and obtain consent before collecting biometric data and defines 'Biometric Identifiers' as data generated by technological processing of an individual's biological, physical, or behavioral characteristics.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colorado-bill-amending-cpa-address-biometric-0",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "HB 24-1130 expanded the Colorado Privacy Act's scope to protect neural data in addition to biometric identifiers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/colorado-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "green",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-colorado/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Minors' protections are now in force with clear obligations; only the pending age-attestation bill and dependent-adult gap temper the rating.",
   "claims": [
    {
     "statement": "Senate Bill 26-051 aims to establish a framework for age attestation on computing devices in Colorado, with penalties for non-compliance, but remains a pending bill as of this research pass.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Speculative",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/colorado",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "SB 24-041 amends the Colorado Privacy Act to include heightened protections for minors' online activity, effective October 1, 2025, mandating data controllers to exercise reasonable care to avoid risks to minors and to conduct data protection impact assessments for services posing heightened risk to minors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colorado-bill-amending-cpa-address-minors-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "SB 24-041 preserves a 60-day cure period specifically for violations of the minors' protection provisions through the end of 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colorado-bill-amending-cpa-address-minors-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "SB 24-041 prohibits processing a minor's personal data for purposes of targeted advertising without consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colorado-bill-amending-cpa-address-minors-protection",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-colorado/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement authority and general mechanics are clear, but the absence of a private right of action, unresolved penalty-figure conflicts, and active AI Act litigation introduce material uncertainty.",
   "claims": [
    {
     "statement": "The CPA assigns enforcement authority to the Colorado Attorney General and District Attorneys, who may investigate and bring actions treating CPA violations as deceptive trade practices under the Colorado Consumer Protection Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/colorado",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Civil penalties for CPA violations may reach up to $2,000 per violation, subject to a total maximum penalty of $500,000 for a related series of violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://dataguidance.com/resource/colorado-joins-us-privacy-landscape-new-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "An alternative secondary-source figure reports CPA noncompliance penalties of up to $20,000 per violation under the Colorado Consumer Protection Act; this figure conflicts with the $2,000/$500,000 figure reported elsewhere and requires primary statutory confirmation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/colorado-privacy-act-becomes-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Colorado Attorney General began CPA enforcement on July 12, 2023 with educational outreach letters focused on informing businesses of their obligations rather than immediate penalties.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colorado-ag-launches-cpa-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Colorado Privacy Act does not provide consumers with a private right of action for violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/colorado-privacy-act-passes-professionals-ponder-effects",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Colorado Attorney General's office is soliciting public comments on automated-decision-making-technology and chatbot-safety rulemaking through July 13, 2026.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/colorado",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "xAI and the U.S. Department of Justice are litigating to block enforcement of the Colorado AI Act on constitutional grounds.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colorado-xai-and-doj-seek-block-enforcement-ai-act",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}