🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-CO · run data-protection-2026-08-04 v13-gdpri-1.0.0
content: ai_generated 28 sources retrieved model claude-sonnet-5 ·

United States – Colorado

US-CO schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 44 claims · 28 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Lead Signal

Colorado's SB 189, enacted in 2026, overhauls the state's AI Act by replacing its original risk-based duty-of-care framework with a disclosure and transparency model, and pushes back the law's principal effective date from June 30, 2026 to January 1, 2027. The amendment requires deployers of covered automated decision-making systems to disclose intended and potentially harmful uses of the technology, the categories of data used to train it, and the oversight instructions given to it. xAI and the U.S. Department of Justice are understood to be seeking to block enforcement of the Colorado AI Act on constitutional grounds.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Mature, clearly-scoped statute with an active regulator and settled thresholds; no registration gap materially affects compliance certainty.

Primary frameworkColorado Privacy Act, Colo. Rev. Stat. §§ 6-1-1301 to 6-1-1313
Traffic-light rationale — GreenMature, clearly-scoped statute with an active regulator and settled thresholds; no registration gap materially affects compliance certainty.

Sub-modules (5)

Regulator And AuthorityGreen

The Colorado AG (Department of Law) is the primary CPA regulator; District Attorneys share enforcement authority.

Claims: CLM-US-CO-1a2b3c4d

Act And InstrumentsGreen

Primary instrument is SB 21-190 (CPA), in force since July 1, 2023, subsequently amended by SB 24-041 and HB 24-1130.

Claims: CLM-US-CO-2b3c4d5e

Material ScopeGreen

Applies to controllers meeting a 100,000-consumer threshold or a 25,000-consumer-plus-data-sale-revenue threshold, over personal data of Colorado residents.

Claims: CLM-US-CO-3c4d5e6f

Territorial ScopeGreen

Extraterritorial application to any controller conducting business in or targeting Colorado residents, irrespective of controller location.

Claims: CLM-US-CO-4d5e6f7a

Regulator Registration And FilingAmber

No general controller registration or filing obligation exists under the CPA; the AG instead relies on rulemaking and complaint/enforcement mechanisms.

Absence provenance: not recorded. Searched: Colorado Privacy Act registration requirement, Colorado AG controller filing CPA.

Category narrative65 words

Colorado is governed by the Colorado Privacy Act (CPA), a comprehensive consumer-privacy statute enforced exclusively by the Colorado Attorney General (with District Attorney co-enforcement authority), layered over federal sectoral statutes (HIPAA, GLBA, COPPA, FCRA) that carve out entity- and data-level exemptions. The CPA applies extraterritorially to any controller targeting Colorado residents that meets defined processing-volume or data-sale-revenue thresholds; there is no separate controller registration/filing regime.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedOneTrust DataGuidanceThe Colorado Attorney General is the primary regulator and enforcement authority for the Colorado Privacy Act.
  2. ConfirmedOneTrust DataGuidanceThe Colorado Privacy Act (Senate Bill 21-190) was signed into law on July 7, 2021 and became effective July 1, 2023.
  3. ConfirmedOneTrust DataGuidanceThe CPA applies to controllers conducting business in or targeting Colorado residents that control or process the personal data of 100,000 or more consumers per calendar year, or that derive revenue from data sales and process the data of 25,000 or more consumers.
  4. ConfirmedOneTrust DataGuidanceThe CPA applies to any controller that conducts business in Colorado or produces/delivers commercial products or services intentionally targeted to Colorado residents, regardless of the controller's own location.

#

Consent and sensitive-data rules are well defined in statute and implementing rules (4 CCR 904-3).

Primary frameworkColorado Privacy Act, Colo. Rev. Stat. § 6-1-1303; CPA Rules 4 CCR 904-3
Traffic-light rationale — GreenConsent and sensitive-data rules are well defined in statute and implementing rules (4 CCR 904-3).

Sub-modules (4)

Lawful BasesGreen

CPA uses an opt-out consent model for standard processing rather than enumerated lawful bases; opt-in consent is mandatory for sensitive data.

Claims: CLM-US-CO-5e6f7a8b

Special CategoriesGreen

Sensitive data categories include racial/ethnic origin, religious beliefs, mental/physical health, sexual orientation, citizenship status, genetic and biometric data, and neural data (post-HB24-1130).

Claims: CLM-US-CO-7a8b9c0d

Pseudonymisation And AnonymisationGreen

The CPA defines pseudonymous data as data that cannot be attributed to a specific individual absent separately-held additional information under technical/organizational safeguards; de-identified data is excluded from personal-data scope entirely.

Claims: CLM-US-CO-8b9c0d1e

Category narrative57 words

The CPA does not use a GDPR-style enumerated lawful-basis model; instead it relies on an opt-out consent architecture supplemented by mandatory opt-in consent for sensitive/sensitive-inference data and for processing a known child's data. Sensitive categories include racial/ethnic origin, religious beliefs, mental/physical health, sex life/orientation, citizenship status, genetic and biometric data, and (as of HB 24-1130) neural data.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsControllers are prohibited from processing sensitive data without first obtaining consumer consent, which must be freely given, specific, informed, and unambiguous.
  2. ConfirmedOneTrust DataGuidanceWhere personal data concerns a known child, controllers must obtain consent from the child's parent or lawful guardian before processing sensitive data.
  3. ConfirmedOneTrust DataGuidanceColorado's definition of sensitive data includes racial and ethnic origin, religious beliefs, and genetic and biometric data, among other categories.
  4. ConfirmedOneTrust DataGuidanceThe CPA defines pseudonymous data as personal data that can no longer be attributed to a specific individual without additional information kept separately under technical and organizational safeguards.

#

Rights and deadlines are clearly codified and operative since 2023.

Primary frameworkColorado Privacy Act, Colo. Rev. Stat. § 6-1-1306
Traffic-light rationale — GreenRights and deadlines are clearly codified and operative since 2023.

Sub-modules (5)

Access RightGreen

Consumers have a statutory right to access personal data held by a controller.

Claims: CLM-US-CO-9c0d1e2f

Rectification And ErasureGreen

Consumers may correct inaccuracies and request deletion of their personal data.

Claims: CLM-US-CO-0d1e2f3a

Restriction And ObjectionGreen

Consumers may object to/opt out of profiling used for decisions with legal or similarly significant effects, and may appeal a controller's denial of a rights request.

Claims: CLM-US-CO-1e2f3a4b, CLM-US-CO-2f3a4b5c

Data PortabilityGreen

The CPA includes a right to obtain a portable copy of personal data in a readily usable format.

Claims: CLM-US-CO-3a4b5c6d

Deadlines And Response WindowsGreen

Controllers must respond to consumer requests within 45 days, extendable by an additional 45 days when reasonably necessary, with notice to the consumer within the initial period.

Claims: CLM-US-CO-4b5c6d7e

Category narrative37 words

Colorado consumers hold access, correction, deletion, portability, and opt-out rights (targeted advertising, sale, and consequential-effect profiling), plus a mandatory appeal right against controller denials. Statutory response deadlines mirror the Virginia/Connecticut model (45 days, extendable by 45 days).

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidanceColorado consumers have the right to access personal data processed about them by a controller.
  2. ConfirmedOneTrust DataGuidanceConsumers have the right to correct inaccuracies in their personal data and to delete personal data held by a controller.
  3. ConfirmedOneTrust DataGuidanceConsumers may opt out of the processing of personal data for targeted advertising, sale, or profiling used for decisions that produce legal or similarly significant effects.
  4. ConfirmedInternational Association of Privacy ProfessionalsThe CPA mandates that controllers provide a conspicuously available and easy-to-use appeal process when a consumer rights request is denied, and must inform the consumer of the ability to contact the Attorney General if the appeal is denied.
  5. ConfirmedOneTrust DataGuidanceThe CPA provides consumers a right to obtain a portable copy of their personal data.
  6. ConfirmedInternational Association of Privacy ProfessionalsA business must respond to a consumer rights request within 45 days of receipt and may extend that deadline by an additional 45 days when reasonably necessary, notifying the consumer within the initial 45-day period.

#

Core accountability, security, and breach duties are robust and in force, but the absence of DPO/ROPA-equivalent obligations creates a structural gap relative to GDPR-style regimes.

Primary frameworkColorado Privacy Act, Colo. Rev. Stat. §§ 6-1-1305, 6-1-1308; Colo. Rev. Stat. § 6-1-716 (breach notification); HB 24-1130
Traffic-light rationale — AmberCore accountability, security, and breach duties are robust and in force, but the absence of DPO/ROPA-equivalent obligations creates a structural gap relative to GDPR-style regimes.

Sub-modules (7)

Accountability And DpiaGreen

Controllers must conduct and document a data protection assessment before engaging in processing that presents a heightened risk of harm to consumers.

Claims: CLM-US-CO-5c6d7e8f

Dpo RequirementsRed

No GDPR-style DPO appointment or independence mandate was identified in the CPA, CPA Rules, or secondary commentary.

Absence provenance: not recorded. Searched: Colorado Privacy Act data protection officer requirement, CPA Rules DPO appointment.

Ropa RequirementsAmber

No standalone, continuous records-of-processing-activities obligation analogous to GDPR Art. 30 was identified; the per-activity data protection assessment is the closest functional analog.

Absence provenance: not recorded. Searched: Colorado Privacy Act records of processing activities, CPA ROPA requirement.

Joint Controller ArrangementsGreen

Processing by a processor on behalf of a controller must be governed by a contract specifying processing instructions, nature, type of data, and duration.

Claims: CLM-US-CO-6d7e8f9a

Security MeasuresGreen

Controllers must take security precautions appropriate to the volume, scope, and nature of the personal data processed (duty of care).

Claims: CLM-US-CO-7e8f9a0b

Breach NotificationGreen

Colorado's breach law requires notice to affected residents without unreasonable delay and no later than 30 days after confirming a breach, plus AG notice within 30 days where 500+ residents are affected.

Claims: CLM-US-CO-8f9a0b1c

Retention And DisposalGreen

HB 24-1130 requires controllers to adopt a written biometric-data retention schedule and to permanently destroy biometric identifiers within 45 days of the retention purpose being satisfied.

Claims: CLM-US-CO-9a0b1c2d

Category narrative87 words

Controllers must conduct and document data protection assessments (DPAs) for heightened-risk processing, exercise a duty of care over security proportionate to the volume/scope/nature of data, and govern processor relationships by contract. Colorado's breach-notification law (independent of the CPA) requires consumer notice within 30 days and AG notice within 30 days for breaches affecting 500+ residents. HB 24-1130 layers biometric-specific retention/destruction duties (45-day destruction window). The CPA has no standalone DPO-appointment mandate or continuous ROPA obligation analogous to GDPR Arts. 30/37-39; the DPA functions as the closest analog.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy ProfessionalsControllers may not process personal data in a manner presenting a heightened risk of harm to a consumer without conducting and documenting a data protection assessment of that processing activity.
  2. ConfirmedInternational Association of Privacy ProfessionalsProcessing by a processor must be governed by a contract between the controller and processor establishing processing instructions, the nature and type of personal data, and the duration of processing.
  3. ConfirmedInternational Association of Privacy ProfessionalsThe CPA imposes a duty of care requiring controllers to take security precautions appropriate to the volume, scope, and nature of the personal data processed.
  4. ConfirmedInternational Association of Privacy ProfessionalsColorado law requires notice to affected residents in the most expedient way and without unreasonable delay, but not later than 30 days after confirming a breach, and requires notice to the Colorado Attorney General within 30 days where the breach is reasonably believed to affect 500 or more residents.
  5. ConfirmedOneTrust DataGuidanceHB 24-1130 requires controllers to adopt a written policy establishing a retention schedule and destruction guidelines for biometric identifiers, extending the destruction period to 45 days.

#

No comprehensive cross-border transfer regime exists at the US-CO state level; this is a legitimate structural gap, not a research omission.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists at the US-CO state level; this is a legitimate structural gap, not a research omission.

Sub-modules (6)

Transfer MechanismsRed

No CPA-specific transfer mechanism exists.

Absence provenance: not recorded. Searched: Colorado Privacy Act cross-border data transfer, CPA international data transfer mechanism.

Adequacy ReceivedRed

Not applicable; Colorado does not participate in a national/international adequacy framework.

Absence provenance: not recorded. Searched: Colorado adequacy decision received.

Adequacy GrantedRed

Not applicable.

Absence provenance: not recorded. Searched: Colorado adequacy decision granted.

Sccs And BcrsRed

No SCC/BCR concept exists under the CPA.

Absence provenance: not recorded. Searched: Colorado Privacy Act standard contractual clauses, CPA binding corporate rules.

Transfer Impact AssessmentRed

No TIA requirement exists under the CPA; the general data protection assessment does not extend to cross-border transfer risk analysis.

Absence provenance: not recorded. Searched: Colorado Privacy Act transfer impact assessment.

Data LocalisationRed

No data localisation mandate exists under Colorado law.

Absence provenance: not recorded. Searched: Colorado data localisation requirement.

Category narrative47 words

The Colorado Privacy Act is a US state consumer-privacy statute and contains no international-transfer mechanism, adequacy-decision framework, SCC/BCR regime, transfer-impact-assessment requirement, or data-localisation mandate. Cross-border data flows are governed, if at all, by federal law (e.g., GLBA, HIPAA) or general contract law, not by the CPA itself.

#

Financial, health, and employment carve-outs are clear, but telecoms/ePrivacy, credit-scoring, and education overlays are not separately codified, leaving coverage partial.

Primary frameworkColorado Privacy Act (exemptions); Restrict Insurers' Use of External Consumer Data Act, SB 21-169
Traffic-light rationale — AmberFinancial, health, and employment carve-outs are clear, but telecoms/ePrivacy, credit-scoring, and education overlays are not separately codified, leaving coverage partial.

Sub-modules (7)

Financial Sector OverlayGreen

Entities regulated by the Gramm-Leach-Bliley Act are exempt at the entity level from CPA obligations.

Claims: CLM-US-CO-0b1c2d3e

Health Sector OverlayGreen

Protected health information collected/processed by HIPAA-covered entities or business associates is exempt from the CPA.

Claims: CLM-US-CO-1c2d3e4f

Telecoms And EprivacyAmber

No dedicated Colorado telecoms/ePrivacy overlay distinct from the CPA's general cookie/UOOM rules was identified.

Absence provenance: not recorded. Searched: Colorado telecoms privacy law, Colorado ePrivacy cookie law.

Employment DataGreen

The CPA's definition of 'consumer' excludes individuals acting in a commercial or employment context, including job applicants and employment-context beneficiaries.

Claims: CLM-US-CO-2d3e4f5a

Credit And ScoringAmber

No Colorado-specific credit-scoring overlay beyond federal FCRA exemption was identified.

Absence provenance: not recorded. Searched: Colorado credit scoring privacy law.

EducationAmber

No dedicated Colorado education-sector data-privacy overlay distinct from federal FERPA/COPPA was identified in this research pass.

Absence provenance: not recorded. Searched: Colorado education data privacy law, Colorado student data privacy CPA.

InsuranceAmber

Colorado's Restrict Insurers' Use of External Consumer Data Act (SB 21-169) restricts insurers' use of external consumer data and algorithms that could produce unfair discrimination.

Claims: CLM-US-CO-3e4f5a6b

Category narrative69 words

The CPA carves out entity-level exemptions for GLBA-regulated financial institutions and data-level exemptions for HIPAA-covered PHI, COPPA-regulated data, and employment-context data (the CPA's 'consumer' definition excludes employees, job applicants, and employment beneficiaries). Colorado separately regulates insurers' use of external consumer data and algorithms via the Restrict Insurers' Use of External Consumer Data Act (SB 21-169). No dedicated telecoms/ePrivacy, credit-scoring, or education-sector overlay distinct from the CPA/federal baseline was identified.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsEntities regulated by the Gramm-Leach-Bliley Act are exempt at the entity level from Colorado Privacy Act obligations.
  2. ConfirmedOneTrust DataGuidanceProtected health information collected, stored, and processed by HIPAA-covered entities or their business associates is exempt from the Colorado Privacy Act.
  3. ConfirmedOneTrust DataGuidanceThe CPA's definition of 'consumer' excludes an individual acting in a commercial or employment context, as a job applicant, or as a beneficiary of someone acting in an employment context.
  4. UncertainFederal Trade CommissionColorado enacted the Restrict Insurers' Use of External Consumer Data Act (SB 21-169), restricting insurers' use of external consumer data and algorithms in ways that could result in unfair discrimination.

#

UOOM and dark-pattern rules are operative and well documented; gaps exist only in emerging areas like clean rooms.

Primary frameworkColorado Privacy Act Rules, 4 CCR 904-3, Part 5
Traffic-light rationale — GreenUOOM and dark-pattern rules are operative and well documented; gaps exist only in emerging areas like clean rooms.

Sub-modules (6)

Cookies And TrackersAmber

The CPA governs tracking primarily through its sale/targeted-advertising opt-out and UOOM regime rather than a dedicated cookie-consent-banner law.

Absence provenance: not recorded. Searched: Colorado cookie consent law.

Dark PatternsGreen

CPA Rules provide that any agreement obtained through dark patterns is not valid consent.

Claims: CLM-US-CO-4f5a6b7c

Opt Out SignalsGreen

From July 1, 2024, controllers must honor a user-selected universal opt-out mechanism meeting AG technical specifications; Colorado currently recognizes GPC as the only valid UOOM, and the AG publishes a public UOOM list (initial list by April 1, 2024).

Claims: CLM-US-CO-5a6b7c8d, CLM-US-CO-6b7c8d9e, CLM-US-CO-7c8d9e0f

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific provisions were identified under the CPA.

Absence provenance: not recorded. Searched: Colorado Privacy Act clean room data collaboration.

Cross Context AdvertisingAmber

The CPA's 'sale' definition (exchange of data for monetary or other valuable consideration) and targeted-advertising opt-out function as Colorado's analog to CPRA-style cross-context advertising restrictions.

Absence provenance: not recorded. Searched: Colorado Privacy Act cross-context advertising 'share'.

Direct MarketingAmber

No CPA provision specifically dedicated to direct-marketing suppression lists was identified beyond the general targeted-advertising opt-out.

Absence provenance: not recorded. Searched: Colorado Privacy Act direct marketing consent.

Category narrative57 words

Colorado requires recognition of a universal opt-out mechanism (UOOM) for targeted-advertising and sale opt-outs since July 1, 2024, and currently recognizes the Global Privacy Control (GPC) as the sole valid UOOM signal. The AG maintains and publishes a public list of recognized UOOMs. CPA Rules invalidate consent obtained through dark patterns. No dedicated clean-room/data-collaboration-room regime was identified.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedColorado Department of LawUnder CPA Rules, any agreement obtained through dark patterns is not valid consent.
  2. ConfirmedOneTrust DataGuidanceFrom July 1, 2024, data controllers must allow consumers to exercise opt-out rights for targeted advertising or sale of personal data through a user-selected universal opt-out mechanism meeting AG technical specifications.
  3. ProbableInternational Association of Privacy ProfessionalsColorado currently considers the Global Privacy Control to be the only recognized valid universal opt-out mechanism under the CPA.
  4. ConfirmedOneTrust DataGuidanceThe Colorado Department of Law maintains and publishes a public list of recognized universal opt-out mechanisms, with the initial list published no later than April 1, 2024.

#

Biometric and profiling rules are settled, but the AI Act framework remains in active flux (major 2026 amendments, delayed effective date, pending litigation), creating material regulatory uncertainty.

Primary frameworkColorado Privacy Act Rules, 4 CCR 904-3; Colorado Artificial Intelligence Act, SB 24-205 (as amended by SB 189, 2026)
Traffic-light rationale — AmberBiometric and profiling rules are settled, but the AI Act framework remains in active flux (major 2026 amendments, delayed effective date, pending litigation), creating material regulatory uncertainty.

Sub-modules (6)

Profiling RestrictionsGreen

Consumers may opt out of profiling used for decisions producing legal or similarly significant effects.

Claims: CLM-US-CO-8d9e0f1a

Automated Decision Making TransparencyAmber

Under SB 189, deployers must provide consumers explicit disclosures on intended/harmful uses of ADMT, training-data categories, and deployer oversight instructions when the AI Act takes effect January 1, 2027.

Claims: CLM-US-CO-9e0f1a2b

Ai Risk AssessmentsAmber

SB 189 (2026) replaces the AI Act's original duty-of-care/risk-management-program/impact-assessment obligations with a disclosure-based framework and delays the principal effective date to January 1, 2027.

Claims: CLM-US-CO-0f1a2b3c, CLM-US-CO-1a2b3c4e

Biometric RegimeGreen

CPA Rules define 'Biometric Identifiers' and 'Biometric Data'; HB 24-1130 mandates disclosure and consent before collection, retention scheduling, and 45-day destruction timelines.

Claims: CLM-US-CO-2b3c4e5f

Genetic DataAmber

HB 24-1130 expanded CPA sensitive-data protections to cover neural data alongside biometric identifiers; no separate freestanding genetic-data statute was identified.

Claims: CLM-US-CO-3c4e5f6a

State Surveillance CarveoutsRed

No Colorado-specific state-surveillance carve-out or national-security exemption analysis distinct from general law-enforcement exceptions was identified in this research pass.

Absence provenance: not recorded. Searched: Colorado Privacy Act national security exemption, Colorado AI Act law enforcement carve-out.

Category narrative89 words

The CPA grants a profiling opt-out for decisions with legal or similarly significant effects. Colorado's separate AI Act (SB 24-205), as substantially amended by 2026's SB 189, moves from a risk-based framework (duty of care, risk-management programs, impact assessments) to a disclosure/transparency-based framework, with a principal effective date pushed to January 1, 2027. Biometric identifiers are separately regulated (definitions and consent duties under CPA Rules and HB 24-1130, which also extended coverage to neural data). Litigation (xAI/DOJ) challenges the AI Act's constitutionality. No dedicated state-surveillance carve-out analysis was identified.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidanceConsumers may opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.
  2. ConfirmedInternational Association of Privacy ProfessionalsUnder Senate Bill 189, deployers of covered AI systems must provide consumers with explicit disclosures regarding intended and harmful uses of automated decision-making technology, training-data categories, and deployer oversight instructions.
  3. ConfirmedInternational Association of Privacy ProfessionalsSenate Bill 189 (2026) replaces the Colorado AI Act's original risk-based framework with disclosure and transparency requirements, removing the duty-of-care, risk-management-program, and impact-assessment obligations that had applied to deployers.
  4. ConfirmedInternational Association of Privacy ProfessionalsSB 189 moves the Colorado AI Act's principal effective date to January 1, 2027, superseding the prior June 30, 2026 date.
  5. ConfirmedOneTrust DataGuidanceHB 24-1130 requires controllers to disclose and obtain consent before collecting biometric data and defines 'Biometric Identifiers' as data generated by technological processing of an individual's biological, physical, or behavioral characteristics.
  6. ProbableOneTrust DataGuidanceHB 24-1130 expanded the Colorado Privacy Act's scope to protect neural data in addition to biometric identifiers.

#

Minors' protections are now in force with clear obligations; only the pending age-attestation bill and dependent-adult gap temper the rating.

Primary frameworkColorado Privacy Act as amended by SB 24-041
Traffic-light rationale — GreenMinors' protections are now in force with clear obligations; only the pending age-attestation bill and dependent-adult gap temper the rating.

Sub-modules (5)

Age VerificationAmber

Senate Bill 26-051 would establish an age-attestation framework for computing devices with non-compliance penalties, but remained a pending bill as of this research pass.

Claims: CLM-US-CO-4e5f6a7b

Minor Profiling BansGreen

SB 24-041 prohibits processing a minor's personal data for targeted advertising absent consent.

Claims: CLM-US-CO-7b8c9d0e

Education SettingsAmber

No education-setting-specific minors' data provisions distinct from SB 24-041's general minors' framework were identified.

Absence provenance: not recorded. Searched: Colorado student data privacy minors CPA.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) data-protection provisions were identified under the CPA.

Absence provenance: not recorded. Searched: Colorado Privacy Act dependent adults protections, Colorado elderly consumer data privacy.

Category narrative80 words

SB 24-041, effective October 1, 2025, amended the CPA to prohibit processing minors' data for targeted advertising without consent, require reasonable care to avoid risks to minors, and mandate data protection impact assessments for services posing heightened risk to minors, with a 60-day cure period preserved through the end of 2026 specifically for minors' provisions. Senate Bill 26-051, proposing an age-attestation framework for computing devices, remains a pending bill as of this research pass. No dedicated dependent-adult protections were identified.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. SpeculativeOneTrust DataGuidanceSenate Bill 26-051 aims to establish a framework for age attestation on computing devices in Colorado, with penalties for non-compliance, but remains a pending bill as of this research pass.
  2. ConfirmedOneTrust DataGuidanceSB 24-041 amends the Colorado Privacy Act to include heightened protections for minors' online activity, effective October 1, 2025, mandating data controllers to exercise reasonable care to avoid risks to minors and to conduct data protection impact assessments for services posing heightened risk to minors.
  3. ConfirmedOneTrust DataGuidanceSB 24-041 preserves a 60-day cure period specifically for violations of the minors' protection provisions through the end of 2026.
  4. ConfirmedOneTrust DataGuidanceSB 24-041 prohibits processing a minor's personal data for purposes of targeted advertising without consent.

#

Enforcement authority and general mechanics are clear, but the absence of a private right of action, unresolved penalty-figure conflicts, and active AI Act litigation introduce material uncertainty.

Primary frameworkColorado Privacy Act, Colo. Rev. Stat. § 6-1-1311; Colorado Consumer Protection Act, Colo. Rev. Stat. Title 6, Article 1
Traffic-light rationale — AmberEnforcement authority and general mechanics are clear, but the absence of a private right of action, unresolved penalty-figure conflicts, and active AI Act litigation introduce material uncertainty.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The AG and DAs may investigate and bring enforcement actions treating CPA violations as deceptive trade practices; maximum-penalty figures reported in secondary sources conflict and require primary-source confirmation.

Claims: CLM-US-CO-8c9d0e1f, CLM-US-CO-9d0e1f2a, CLM-US-CO-0e1f2a3b

Enforcement Activity IndexAmber

The AG's initial CPA enforcement posture (from July 2023) was educational/letter-based rather than punitive; no independently verified list of subsequent CPA-specific monetary penalties was located in this research pass.

Absence provenance: not recorded. Searched: Colorado Privacy Act enforcement action fine 2025, Colorado AG CPA settlement 2026.

Claims: CLM-US-CO-1f2a3b4c

Regulator Funding And CapacityRed

No specific budget/headcount data for the Colorado AG's privacy enforcement unit was identified.

Absence provenance: not recorded. Searched: Colorado Attorney General privacy unit budget headcount.

Collective Redress And Class ActionsRed

No CPA-specific collective-redress or class-action mechanism distinct from general Colorado civil procedure was identified.

Absence provenance: not recorded. Searched: Colorado Privacy Act class action mechanism.

Private Right Of ActionAmber

The CPA does not grant consumers a private right of action; enforcement is confined to the AG and District Attorneys.

Claims: CLM-US-CO-2a3b4c5d

Recent Developments 180DAmber

Within the past 180 days: the AG solicited public comment on ADMT/chatbot-safety rulemaking (through July 13, 2026); SB 189 substantially overhauled the AI Act's framework and delayed its effective date to January 1, 2027; and xAI and the U.S. DOJ initiated litigation to block AI Act enforcement.

Claims: CLM-US-CO-3b4c5d6e, CLM-US-CO-4c5d6e7f

Category narrative113 words

CPA enforcement rests exclusively with the Colorado Attorney General and District Attorneys; a CPA violation is treated as a deceptive trade practice under the Colorado Consumer Protection Act. Secondary sources report conflicting maximum-penalty figures ($20,000 per violation versus $2,000 per violation with a $500,000 aggregate cap), which requires primary-source (CRS Title 6) confirmation. The CPA provides no private right of action. The statutory 60-day right-to-cure sunset on January 1, 2025 for general violations (preserved through 2026 for minors' provisions). Recent developments include AG rulemaking on ADMT/chatbot safety (comment period through July 13, 2026), the SB 189 AI Act overhaul, and ongoing litigation by xAI and the U.S. DOJ challenging the AI Act's enforceability.

No periodic updates recorded against this sub-brief.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidanceThe CPA assigns enforcement authority to the Colorado Attorney General and District Attorneys, who may investigate and bring actions treating CPA violations as deceptive trade practices under the Colorado Consumer Protection Act.
  2. ProbableOneTrust DataGuidanceCivil penalties for CPA violations may reach up to $2,000 per violation, subject to a total maximum penalty of $500,000 for a related series of violations.
  3. UncertainInternational Association of Privacy ProfessionalsAn alternative secondary-source figure reports CPA noncompliance penalties of up to $20,000 per violation under the Colorado Consumer Protection Act; this figure conflicts with the $2,000/$500,000 figure reported elsewhere and requires primary statutory confirmation.
  4. ConfirmedOneTrust DataGuidanceThe Colorado Attorney General began CPA enforcement on July 12, 2023 with educational outreach letters focused on informing businesses of their obligations rather than immediate penalties.
  5. ConfirmedInternational Association of Privacy ProfessionalsThe Colorado Privacy Act does not provide consumers with a private right of action for violations.
  6. ConfirmedOneTrust DataGuidanceThe Colorado Attorney General's office is soliciting public comments on automated-decision-making-technology and chatbot-safety rulemaking through July 13, 2026.
  7. ProbableOneTrust DataGuidancexAI and the U.S. Department of Justice are litigating to block enforcement of the Colorado AI Act on constitutional grounds.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Colorado
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s), 28 source(s) in the cumulative register.