Other Developments
Colorado's data protection regime centers on the Colorado Privacy Act, signed into law on July 7, 2021 and effective July 1, 2023, for which the Colorado Attorney General serves as the primary regulator and enforcement authority, with District Attorneys co-enforcing. The Act applies to controllers meeting a 100,000-consumer processing threshold or a 25,000-consumer-plus-data-sale-revenue threshold, and it applies extraterritorially to any controller conducting business in or targeting Colorado residents, regardless of controller location. This cycle corrects a named-entity misattribution: the CPA's sensitive-data definition is understood to have been expanded to include biological data and neural data by HB 24-1058, signed April 17, 2024 and effective August 7, 2024, rather than by HB 24-1130, which is limited to requiring controllers to adopt a written retention schedule and destroy biometric identifiers within 45 days of the retention purpose being satisfied. HB 24-1058 is now understood to sit alongside SB 24-041 and HB 24-1130 on the list of instruments amending the CPA.
Colorado consumers hold rights to access personal data held about them, to correct inaccuracies and delete their data, and to obtain a portable copy of it in a readily usable format. They may also opt out of processing for targeted advertising, for sale, or for profiling that produces legal or similarly significant effects, and controllers denying a rights request must provide a conspicuous appeal process that names a route to Attorney General contact. Controllers must respond to rights requests within 45 days, extendable by a further 45 days when reasonably necessary, with notice given in the initial period. Processing of sensitive or special-category data requires freely-given, specific, informed, and unambiguous opt-in consent, and processing a known child's sensitive data requires parental or guardian consent; the sensitive-data category itself spans racial and ethnic origin, religious beliefs, and genetic and biometric data, among other categories.
Controllers must conduct and document a data protection assessment before engaging in heightened-risk processing, must govern processor relationships through contracts specifying processing instructions, data type, and duration, and are held to a duty of care requiring security precautions appropriate to the volume, scope, and nature of the data processed. Under a separate breach-notification statute, affected residents must be notified within 30 days of a confirmed breach, with Attorney General notice required within the same window where 500 or more residents are affected. HB 24-1130 separately requires controllers to adopt a written retention schedule and destroy biometric identifiers within 45 days once the retention purpose is satisfied.
GLBA-regulated financial institutions and HIPAA-covered protected health information are exempt from the Act at the entity and data-category level respectively, and the statute's consumer definition excludes individuals acting in a commercial or employment context, including job applicants. Reports suggest a separate 2021 statute, SB 21-169, may restrict insurers' use of external consumer data and algorithms that could produce unfair discrimination, though this citation has not been independently verified and is flagged for primary-source follow-up. Under CPA rules, any agreement obtained through dark patterns is not valid consent, and since July 1, 2024 controllers must honor a user-selected universal opt-out mechanism meeting Attorney General technical specifications for targeted-advertising and sale opt-outs. The Global Privacy Control signal is understood to currently be the only mechanism recognized as valid under that regime, and the Colorado Department of Law maintains a public list of recognized mechanisms, with the initial list published by April 1, 2024.
SB 24-041, effective October 1, 2025, requires reasonable care to avoid risks to minors and data protection assessments for services posing heightened risk to minors, and it prohibits processing a minor's personal data for targeted advertising without consent. A 60-day cure period preserved for minors'-provision violations is set to sunset at the end of 2026. Third-party commentary attributes to Senate Bill 26-051 a proposed age-attestation framework for computing devices with non-compliance penalties, although no enactment has occurred and no primary evidence of a scheduled vote has surfaced.
The Attorney General and District Attorneys hold authority to treat CPA violations as deceptive trade practices under the Colorado Consumer Protection Act, and the Act does not provide consumers a private right of action. One line of reporting is understood to place civil penalties at up to $2,000 per violation subject to a $500,000 aggregate cap for a related series of violations, while another source reports a conflicting figure of up to $20,000 per violation that requires primary statutory confirmation. The Attorney General's enforcement is understood to have begun on July 12, 2023 through educational outreach letters rather than immediate penalties, and no confirmed post-2023 CPA-specific monetary penalty has surfaced this cycle. The Attorney General's office is separately soliciting public comment, through July 13, 2026, on rulemaking addressing automated decision-making technology and chatbot safety.
Cross-Monitor Connections
The entity-level exemption for GLBA-regulated financial institutions from Colorado Privacy Act obligations carries anti-money-laundering and payments data-sharing implications that fall outside this monitor's scope; readers tracking that dimension should consult financial-integrity and world-payments coverage. SB 189's overhaul of the Colorado AI Act — including its shift to a disclosure-based framework, its delayed effective date, and the associated litigation brought by xAI and the Department of Justice — is being tracked primarily as an artificial-intelligence development; this monitor retains only the data-protection framing of automated-decision-making transparency and profiling opt-outs, with the fuller regulatory analysis directed to the artificial-intelligence monitor.
Outlook
Two forward-dated milestones anchor the near-term Colorado calendar: the AI Act's SB 189-delayed effective date of January 1, 2027, and the sunset of the minors'-provisions 60-day cure period at the end of 2026. Both developments narrow the window in which controllers can rely on cure opportunities or on the original risk-based AI Act model before disclosure obligations and cure-free enforcement take hold. The unresolved civil-penalty figure and the pending litigation over the AI Act's enforceability leave open questions about the actual cost and shape of noncompliance that the next research cycle will need to track.