Home
Colorado CPA: Cookies Policy

Colorado CPA: Cookies Policy

3 months ago
João Bruno Soares
15 minutes

Colorado has a requirement that changes the equation for any site with users in the state.

This page covers one piece of the picture. For the full scope of the CPA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the CPA and cookies.

From July 1, 2024, if your site processes personal data for targeted advertising or sells personal data, it must automatically detect and honor the Universal Opt-Out Mechanism (UOM). This includes the Global Privacy Control (GPC) and other mechanisms recognized by the Colorado Department of Law.

This is not optional. It is not a recommended best practice. It is a legal obligation under the Colorado Privacy Act (CPA, C.R.S. § 6-1-1301 et seq.), complemented by the Colorado Privacy Act Rules (4 CCR 904-3).

This article focuses exclusively on what the CPA and its regulations require from a Cookies Policy: what the document must contain, how consent and opt-out must work, and what the Universal Opt-Out Mechanism means for each tracker on your site.

Cookies Policy vs. cookie banner: the necessary distinction

The cookie banner is the visual interface. It is what the visitor sees when they access the site and where they make choices.

The Cookies Policy is the detailed document. It is where the user finds complete information about every technology operating on the site.

Both need to exist. Both need to be aligned. And the Cookies Policy must be accessible from a link within the consent notice itself.

What the CPA specifically requires for cookies

Specific purpose for each category

C.R.S. § 6-1-1308(1)(a)(II) requires the privacy notice to describe the purposes for which each category of data is processed. The regulations (4 CCR 904-3, Rule 6.06) require specificity.

For cookies, each category needs a purpose description the consumer can actually understand.

What does not work: "cookies to improve your experience." That is not a purpose.

What works: "Analytics cookies: collect browsing behavior data including pages visited, traffic source, and session duration. Used to identify content improvement opportunities. Data is processed by our internal systems and is not sold or used for targeted advertising."

"Advertising cookies: collect behavioral identifiers that are shared with advertising platforms for targeted advertising on other non-affiliated sites and applications. Include pixels from Meta Ads, Google Ads. Consumers may exercise opt-out through the link in our Privacy Policy or via Universal Opt-Out Mechanism."

Cookie categories present on the site

The Policy must list tracker categories:

Necessary cookies: essential for basic functionality. Do not constitute targeted advertising or data sale. Must be documented.

Analytics cookies: depends on configuration. If data stays internal, generally does not constitute targeted advertising. If sent to third parties for targeting on other sites, it may.

Advertising cookies: almost always constitute targeted advertising under the CPA, which defines it as ads based on data "obtained or inferred over time from the consumer's activities across nonaffiliated websites, applications, or online services" (C.R.S. § 6-1-1303(25)(a)).

Functional cookies: remember preferences. Generally do not constitute targeted advertising or data sale.

Third-party cookies: fired by external services. Correct tag categorization is what makes it possible to document each one accurately.

Targeted advertising: the CPA's definition

The CPA defines targeted advertising (C.R.S. § 6-1-1303(25)(a)) as displaying an advertisement selected based on personal data obtained or inferred over time from the consumer's activities across nonaffiliated websites, applications, or online services.

What does not constitute targeted advertising:

Advertising in response to a specific consumer request.

Advertisements based on activities within the controller's own websites or applications.

Advertisements based on the context of the current search query, website visit, or online application.

Processing personal data solely for measuring or reporting advertising performance, reach, or frequency.

Sale of personal data

The CPA defines sale (C.R.S. § 6-1-1303(23)(a)) as the exchange of personal data for monetary or other valuable consideration from a controller to a third party.

The second threshold criterion of the CPA already signals this breadth: it includes "receiving a discount on the price of goods or services" from the sale of data. Agreements where the controller exchanges data for indirect economic benefits may constitute a sale.

Who receives data via cookies

The notice must identify the categories of third parties receiving data via cookies (C.R.S. § 6-1-1308(1)(a)(V)), at a level of detail giving the consumer understanding of the type, business model of, or processing by those third parties (4 CCR 904-3, Rule 6.03(A)(1)(e)).

This means it is not enough to say "advertising partners." The notice should describe, for example: "digital advertising platforms that use the data for cross-context behavioral advertising," "data brokers," "analytics platforms that process browsing behavior data."

The Universal Opt-Out Mechanism and cookies

This is the most important CPA requirement for the cookies context. From July 1, 2024, a controller that processes personal data for targeted advertising or sells data must accept opt-outs via UOM (C.R.S. § 6-1-1306(1)(a)(IV)(B)).

In practical terms for cookies: when a user visits the site with the GPC activated in their browser, the site must interpret that signal as an opt-out of targeted advertising and data sale, and automatically block the corresponding trackers.

The regulations (4 CCR 904-3, Rule 5.08(A)) detail:

After receiving a valid opt-out via UOM, the controller must continue treating the browser, device, and consumer as having exercised opt-out until the consumer consents again.

The controller cannot require the consumer to log in as a condition for recognizing the UOM.

The controller may display conspicuously when the opt-out signal has been honored (e.g., "Opt-Out Preference Signal Honored").

The Cookies Policy must describe how the UOM is processed and what happens when a consumer sends this signal.

Retention period for each category

The duty of data minimization (C.R.S. § 6-1-1308(3)) and the regulations (4 CCR 904-3, Rule 6.07) require data to be kept only for as long as necessary for the specified purpose.

For cookies: document how long each cookie category stays active on the device and how long collected data stays in the business's systems. Biometric data and stored photographs must be reviewed at least once a year to verify the storage is still necessary (4 CCR 904-3, Rule 6.07(B)(2)).

What constitutes valid consent for cookies under the CPA

C.R.S. § 6-1-1303(5) defines consent as a clear, affirmative act that is freely given, specific, informed, and unambiguous.

The correct standard: non-essential cookies off by default. The user chooses what to enable.

What is not valid consent: accepting general terms with data processing descriptions mixed with unrelated information, hovering over or closing content, and any agreement through dark patterns.

Dark patterns: Colorado's detailed prohibition

Colorado's regulations have the most detailed description of dark patterns among all US state privacy laws (4 CCR 904-3, Rule 7.09). Prohibited:

Presenting consent choice options with unequal weight or focus ("accept" button larger, in a more prominent color, or more visible than "decline").

Emotionally manipulative language or visuals to steer choices (e.g., "Yes, I want to help endangered species" vs "No, I don't care about animals").

Silence or inaction interpreted as consent (closing a window is not consent).

Pre-selected default options.

A longer or more difficult path to exercise the more privacy-protective option than to accept.

Repeatedly interrupting the consumer experience to request consent after refusal.

Misleading language, double negatives, or confusing syntax in choice options.

Protection for children's data via cookies

The CPA defines "child" as an individual under 13 years of age (C.R.S. § 6-1-1303(4)). Data from known children is sensitive data and requires parental consent before processing (C.R.S. § 6-1-1308(7)).

The regulations (4 CCR 904-3, Rule 7.06) detail verifiable parental consent methods, including: signed forms returned by mail or fax, financial transaction with account holder notification, toll-free telephone call with trained staff, or videoconference.

If the site may have users under 13, the Cookies Policy must describe how cookies are blocked for this audience.

When to update the Cookies Policy

The regulations (4 CCR 904-3, Rule 6.04) require notifying consumers of material changes. For cookies, situations requiring an update:

Adding a new advertising pixel or third-party tracker.

New analytics tool.

New partner receiving behavioral data.

Change in the use of cookie data for new purposes.

Addition of a newly recognized UOM to the Colorado Department of Law's public list (which requires the site to begin recognizing it within 6 months).

Continuous data mapping is what keeps the cookie inventory synchronized with the document.

Enforcement: AG and District Attorneys

CPA violations are treated as deceptive trade practices by the Attorney General and District Attorneys of Colorado. There is no private right of action (C.R.S. § 6-1-1310).

The 60-day cure period was repealed on January 1, 2025. From 2025 onward, the AG and DAs may act without a guaranteed prior correction period.

How AdOpt helps with the Cookies Policy under the CPA

AdOpt's automatic scan identifies all active technologies, feeding the list of categories that must appear in the Cookies Policy.

The cookie notice configured through AdOpt blocks non-essential trackers before acceptance, automatically detects and honors the GPC and other UOMs, offers real choice options without dark patterns, and logs every interaction for 24 months.

Over 60,000 websites already run with AdOpt.

Privacy is not a banner. It is a position.

Want to build a Cookies Policy for your site that complies with the Colorado CPA? Talk to our team.

Checklist: what your Cookies Policy needs for the CPA

Visible link in the footer and within the cookie banner.

Listing of cookie categories with a specific description of each.

Specific purpose for each category, without vague descriptions.

Indication of whether data is sold or used for targeted advertising (4 CCR 904-3, Rule 6.03(A)(1)(c)).

Categories of third parties receiving data, with detail on type/business model.

Clear and conspicuous opt-out method within and outside the notice (4 CCR 904-3, Rule 4.03(B)).

Universal Opt-Out Mechanism recognized: description of how GPC and other UOMs are processed (mandatory since July 2024).

Retention period for each cookie category.

Non-essential cookies disabled by default, without dark patterns (4 CCR 904-3, Rule 7.09).

Protection for children under 13 with tracker blocking without parental consent.

Date of last update of the document.

Accessible language, without legal jargon.

No cookie walls.

FAQ: CPA and Cookies Policy

1. What is the Universal Opt-Out Mechanism and why is it mandatory in Colorado?
The UOM is a mechanism (like the GPC) that allows the consumer to automatically communicate their opt-out choice for targeted advertising and data sale to multiple controllers simultaneously. From July 2024, C.R.S. § 6-1-1306(1)(a)(IV)(B) made it mandatory for controllers processing data for targeted advertising or data sale to accept and honor these signals. Colorado was the first US state to require this by law.

2. How should I configure the site to recognize the GPC as a UOM?
The regulations (4 CCR 904-3, Rule 5.08) require that when a valid UOM signal is received, the controller must immediately cease processing for the indicated opt-out purposes. The controller cannot require login to recognize the signal, cannot collect data beyond what is strictly necessary to authenticate the consumer as a Colorado resident, and may display on screen when the signal has been honored. A consent management platform integrates this recognition automatically.

3. What happens if the consumer sends the GPC and the site continues tracking for advertising?
It is a direct violation of C.R.S. § 6-1-1306(1)(a)(IV)(B). The AG or District Attorney may investigate and, from 2025, act without a guaranteed cure period. The regulations (4 CCR 904-3, Rule 5.08(A)(2)) clarify that the controller must continue treating the browser and consumer as having exercised opt-out until the consumer voluntarily consents again.

4. Do analytics cookies require opt-out under the CPA?
It depends on how the data is used. If analytics data stays internal and is not sent to third parties for targeting on other sites, it generally does not constitute targeted advertising. But if the analytics tool sends data to the provider for use on other sites, it may. The CPA's criterion is "activities across nonaffiliated websites" (C.R.S. § 6-1-1303(25)(a)).

5. How does Colorado's dark pattern prohibition apply to cookie banners?
The regulations (4 CCR 904-3, Rule 7.09) are detailed: "accept" and "decline" buttons must have equal visual weight (size, color, position). The path to decline cannot be longer or more difficult. Pre-selected options are prohibited. Reappearing repeatedly after the consumer declines is prohibited. Cookie walls blocking content until acceptance may be prohibited if consent is not strictly necessary for the service.

Ready to build a Cookies Policy for your site that complies with the Colorado CPA? Talk to our team.

Tags

Colorado CPA
Controller and Operator
Cookies
Cookie Banner
Data Mapping
CMP

Related posts

AdOpt post

Connecticut CTDPA: Cookies Policy

What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.

AdOpt post

5 Signs Your Website Needs an Cookie Consent Strategy

How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.

AdOpt post

How long can we ignore LGPD?

LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?

AdOpt post

LGPD: An Opportunity for Digital Marketing Agencies!

Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.

AdOpt post

Why Give Consent on Every Website I Visit?

Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.

AdOpt post

New Hampshire NHDPA: Privacy Policy

Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.

AdOpt post

The Impact of Cookie Banners on Your E-commerce - LGPD

Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.

AdOpt post

California CPRA and Cookies: All you need to know

California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.

AdOpt post

MTCDPA Montana and Cookies: All you need to know

Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana

AdOpt post

IOWA ICDPA: DSAR and Privacy Portal

Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.

AdOpt post

Utah UCPA: DSAR and Privacy Portal

Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.

AdOpt post

How does a cookie banner operate?

Here is a step-by-step explanation of how consent registration works in AdOpt.

AdOpt post

Tenesse TIPA: Cookies Policy

Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.

AdOpt post

Data Mapping or Data Inventory - a life jacket for the DPO!

With the data mapping we have a clear understanding of the 5 stages that every data goes through in a company.

AdOpt post

Tenesse TIPA: DSAR Privacy Portal

Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.

AdOpt post

Colorado CPA and Cookies: All You Need to Know

The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?

AdOpt post

Florida FDBR: Privacy Policy

What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.

AdOpt post

California CCPA: Privacy Policy

What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.

AdOpt post

Connecticut CTDPA: Privacy Policy

What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.

AdOpt post

Colorado CPA: Privacy Policy

What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.

AdOpt post

Utah UCPA and Cookies: All you need to know

Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.

AdOpt post

Oregon OCPA: Cookies Policy

What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.

AdOpt post

Texas TDPSA and Cookies: All You Need to Know

Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.

AdOpt post

Outsourcing the DPO (DPOaaS), Is It a Good Idea?

The Data Protection Officer, or DPO, is a new position that emerged all over the globe with the new privacy regulations, and more recently at the LGPD. Although it already existed in other international legislations, such as the EU's GDPR, it is still a novelty here since 2020. Along with it comes the possibility of outsourcing, known as DPO as a Service (DPOaaS).

AdOpt post

Virginia VCDPA: DSAR Privacy Portal

How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.

AdOpt post

Florida FDBR: DSAR Privacy Portal

How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.

AdOpt post

Best practices in tag categorization

It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.

AdOpt post

What is the difference between cookies, local storage, and session storage?

Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!

AdOpt post

California CPRA: Cookies Policy

What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.

AdOpt post

New Hampshire NHDPA: Cookies Policy

Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.

AdOpt post

Virginia VCDPA and Cookies: All you need to know

Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.

AdOpt post

Tenesse TIPA: Privacy Policy

Learn what your TIPA Privacy Policy must include to comply with the Tennessee Information Protection Act from consumer rights and targeted advertising disclosures to the NIST affirmative defense, appeal mechanisms, and how to keep your notice aligned with your operational program.

AdOpt post

Utah UCPA: Privacy Policy

What the Utah UCPA requires from your Privacy Policy: five mandatory elements, opt-out model for sensitive data, no retention periods required, no active contact channel mandate, and the guaranteed 30-day cure period.

AdOpt post

California CCPA and Cookies: All You Need to Know

Everything about the California CCPA and CPRA: who must comply, the $25M threshold, 7 consumer rights, CCPA vs CPRA explained, the Do Not Sell link, CPPA enforcement, and cookies.

AdOpt post

New Hampshire NHDPA and Cookies: All you need to know

Discover what the New Hampshire Privacy Act (NHDPA) means for your business. Learn about compliance steps, consumer rights, penalties, and how to simplify it all with AdOpt, a Google-certified CMP.

AdOpt post

Virginia VCDPA: Cookies Policy

What the Virginia VCDPA requires from your Cookies Policy: targeted advertising disclosure, consent standards, tracker categories, opt-out mechanisms, and the 30-day cure period explained.

AdOpt post

Colorado CPA: DSAR Privacy Portal

How to handle DSARs under the Colorado CPA: 5 consumer rights, portability limited to twice per year, Universal Opt-Out Mechanism, 24-month record retention, and District Attorney enforcement.

AdOpt post

IOWA ICDPA and Cookies: All you need to Know

Iowa ICDPA explained: the longest response deadline of all US state privacy laws (90 days), 90-day cure period, opt-out for sensitive data, limited deletion scope, no right to correct, and how it compares to UCPA, VCDPA, and OCPA.

AdOpt post

What are Terms of Use and their importance for the LGPD?

Ignoring Terms of Use and their significance within a website, particularly now with LGPD, is a common mistake that both consumers and website owners frequently commit.

AdOpt post

Montana MTCDPA: Cookies Policy

Learn about how to apply Montana MTCDPA Cookies Policy in your site

AdOpt post

Cookies and the TDPSA

If your website uses cookies and serves users in Texas, the Texas Data Privacy and Security Act (TDPSA) applies to you. This article breaks down exactly how cookies are treated under the law—and what your business must do to remain compliant and build user trust.

AdOpt post

GDPR and Cookies all you need to know

Understanding the General Data Protection Regulation (GDPR) and its impact on cookies is essential. So, let's break it down, step by step.

AdOpt post

Virginia VCDPA: Privacy Policy

What the Virginia VCDPA requires from your Privacy Policy: the 5 mandatory content categories, sensitive data obligations, targeted advertising disclosure, and the appeal process explained.

5 Common Cookie Consent Mistakes Hurting Your Compliance

Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.

AdOpt post

The Differences Between Data Controller and Data Processor - LGPD

Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.

AdOpt logoAdOpt logo

Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819

15 Rue du Général Campredon, 34000 Montpellier, France

207 Rue de Bercy, 75012 Paris, France

EIN: 86-3965064

Phone: +1 (407) 768-3792

AdOpt

Resources

Product

Certifications

Google CMP PartnerIAB Europe TCF Registered Vendor

© GO ADOPT, LLC since 2020 - Made by people who love🍪