The Colorado Privacy Act (CPA) has a set of rules for the Privacy Portal that goes beyond the statute. The Attorney General promulgated the Colorado Privacy Act Rules (4 CCR 904-3), which specify exactly how each aspect of the DSAR process must work, including the minimum content of each request record, the record-keeping deadline, and how to handle authorized agents.
This page covers one piece of the picture. For the full scope of the CPA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the CPA and cookies.
This article covers all of it: what a DSAR is under the CPA, the five guaranteed rights, the law's specific deadlines, the Universal Opt-Out Mechanism, and what the regulations require from the process.
DSAR stands for Data Subject Access Request, or Data Rights request in the language of the CPA. It is any formal request from a Colorado consumer to exercise the rights the law grants over their own data.
Under C.R.S. § 6-1-1306(1), the consumer may submit a request at any time using the methods specified by the controller in the privacy notice.
If you are already familiar with the GDPR data subject rights framework, the structure is familiar. The CPA adds the Universal Opt-Out Mechanism as an alternative channel for exercising opt-out of targeted advertising and data sale.
Under C.R.S. § 6-1-1306(1), Colorado residents have five rights:
The consumer may refuse the processing of their personal data for three purposes (C.R.S. § 6-1-1306(1)(a)):
Targeted advertising.
Sale of personal data.
Profiling in furtherance of decisions with legal or similarly significant effects (access to financial or lending services, housing, insurance, education, criminal justice, employment, healthcare, or essential goods).
The consumer may also exercise the opt-out through an authorized agent, including via UOM (such as the GPC), when the controller can authenticate the consumer's identity and the agent's authority with commercially reasonable effort (C.R.S. § 6-1-1306(1)(a)(II)).
The regulations (4 CCR 904-3, Rule 4.03(A)(1)(b)) detail: if the opt-out is submitted online and the controller cannot identify the consumer to cease processing of connected offline data, it may request additional information. And if a consumer submitted multiple DSARs, the opt-out must be processed first.
The consumer may confirm whether the controller processes their data and access the personal data (C.R.S. § 6-1-1306(1)(b)).
The regulations (4 CCR 904-3, Rule 4.04(A)(1)) clarify that "specific pieces of personal data" include final profiling decisions, inferences, derivative data, marketing profiles, and any other personal data created by the controller linked to the consumer.
The response must be provided in a common, accessible electronic format, in the language the consumer uses to interact with the controller, without incomprehensible internal codes.
The controller does not need to disclose in response to an access request: government-issued identification numbers, financial account numbers, biometric data or biometric identifiers. But must inform the consumer that it holds these types of data (e.g., "We collect unique biometric data including fingerprint scan" without revealing the actual scan).
The consumer may request correction of inaccuracies in personal data, taking into account the nature and purposes of processing (C.R.S. § 6-1-1306(1)(c)).
The regulations (4 CCR 904-3, Rule 4.05) detail:
The controller corrects in active systems but may delay for archive or backup systems until they are restored or accessed.
If the correction can be made by the consumer through account settings, the controller may provide instructions, provided the process is not unduly burdensome.
The controller may request documentation to verify data accuracy.
If the controller did not receive the data directly from the consumer and has no supporting documentation, the consumer's assertion of inaccuracy is sufficient to establish that the data is inaccurate.
The consumer may request deletion of personal data (C.R.S. § 6-1-1306(1)(d)).
The regulations (4 CCR 904-3, Rule 4.06) detail:
The controller permanently and completely erases from active systems, or de-identifies so it cannot reasonably be linked to the individual.
Also instructs processors to delete.
May delay for archive or backup systems until they are restored.
For data obtained from third parties (not directly from the consumer), may comply by retaining only the deletion request record and the minimum necessary to ensure the data remains deleted, or opting the consumer out of all processing.
If partial retention is justified by a legal exception, must inform the consumer of which categories were not deleted and which exception applies.
When exercising the right of access, the consumer may obtain data in a portable and, where technically feasible, readily usable format that allows transmission to another entity without hindrance (C.R.S. § 6-1-1306(1)(e)).
Portability may be exercised no more than twice per calendar year. This differs from other US state privacy laws that do not impose this limit on the right to portability.
The controller is not required to provide data in a manner that discloses trade secrets. But must provide as much data as possible in portable format without disclosing the secret.
The CPA's deadlines have a specific structure.
45 days from receipt of the request to respond (C.R.S. § 6-1-1306(2)(a)).
The deadline may be extended by another 45 days when reasonably necessary, considering complexity and number of requests, as long as the consumer is notified within the initial period with the reason.
For appeals: 45 days to respond, extendable by another 60 days in cases of complexity or large number of requests (C.R.S. § 6-1-1306(3)(b)).
The first request is free. For subsequent requests within the same 12-month period, the business may charge a fee calculated under C.R.S. § 24-72-205(5)(a).
The CPA has a very specific appeal process (C.R.S. § 6-1-1306(3)):
The controller must establish an internal appeal process that is conspicuously available and as easy to use as the original request submission process.
The process must be actionable within a reasonable period after the consumer receives the denial notice.
The appeal response must include the decision and the written justification.
If the appeal is denied, the controller must inform the consumer of the ability to contact the Attorney General (C.R.S. § 6-1-1306(3)(c)).
The regulations (4 CCR 904-3, Rule 4.02(B)) detail the requirements:
Online-only businesses with a direct consumer relationship: a single email address is sufficient.
Other businesses: two or more designated methods, and if the business maintains a website, application, or digital presence, one method must be through that digital presence (web form).
Businesses that interact in person: must consider an in-person method (printed form, tablet/computer portal, or telephone for a toll-free call).
The method must:
Consider how consumers normally interact with the controller.
Enable the consumer to submit the request at any time.
Use reasonable data security measures.
Be easy to execute, with a minimal number of steps.
Not require creating a new account (but may require using an existing password-protected account).
The regulations (4 CCR 904-3, Rule 4.08) are specific:
The controller must use a commercially reasonable method to authenticate each request. To determine what is reasonable, consider:
The right being exercised, the type, sensitivity, value, and volume of data involved.
The level of possible harm from improper access.
The cost of authentication to the controller.
The controller should avoid requesting additional personal data if it can authenticate using data it already has.
The controller cannot charge an authentication fee to the consumer (e.g., cannot require notarization without compensating the consumer for the cost).
If unable to authenticate with reasonable effort, the controller is not required to comply. But must inform the consumer that their identity could not be authenticated and how to remedy deficiencies.
The regulations (4 CCR 904-3, Rule 6.11(A)) require records of all DSARs to be maintained for at least 24 months. Each record must include at minimum:
The date of the request.
The type of request.
The date of the controller's response.
The nature of the response.
The basis for denial if the request was denied in whole or in part.
The existence and resolution of any appeal.
Records of DSARs already complied with must also be maintained for 24 months and made available to any new controller in a merger, acquisition, or other transaction where a third party assumes control of personal data.
The UOM (including the GPC) does not replace the Privacy Portal, but covers the opt-out for targeted advertising and data sale.
When the consumer sends a valid UOM signal, the controller must:
Cease processing for the indicated purposes as soon as feasibly possible, without undue delay (4 CCR 904-3, Rule 4.03(A)(1)).
Maintain a record of the opt-out (4 CCR 904-3, Rule 4.03(A)(2)).
Continue treating the browser, device, and consumer as having exercised opt-out until the consumer consents again (4 CCR 904-3, Rule 5.08(A)(2)).
If the consumer wants to opt out of profiling with significant effects, this still requires submission through the Privacy Portal, since the UOM covers only targeted advertising and data sale.
C.R.S. § 6-1-1308(1)(c)(II) prohibits the controller from, based solely on the exercise of a right and unrelated to feasibility or the value of a service, increasing the cost or decreasing the availability of the product or service.
The exception is loyalty programs, rewards, premium features, discounts, or club card programs (C.R.S. § 6-1-1308(1)(d)). The regulations (4 CCR 904-3, Rule 6.05) detail extensively the obligations related to loyalty programs.
The CPA is enforced by the Attorney General and District Attorneys of Colorado (C.R.S. § 6-1-1311). There is no private right of action.
From January 1, 2025, the 60-day cure period was repealed. AG and DAs have discretion to act without a guaranteed prior correction period.
AdOpt logs every consent and opt-out interaction with a timestamp and unique identifier, maintaining documentation for 24 months as required by the regulations.
The GPC and other UOMs are detected and honored automatically. When the consumer exercises opt-out via Portal or via UOM, the system updates the corresponding trackers. The auditable log serves as evidence for the AG or District Attorneys.
Over 60,000 websites already run with AdOpt.
Privacy is not a banner. It is a position.
Want to build a Privacy Portal for your site that complies with the Colorado CPA? Talk to our team.
Two or more submission methods for non-online-only businesses, including a digital channel if the business has digital presence (4 CCR 904-3, Rule 4.02(B)(1)(b)).
Email only for online-only businesses with a direct consumer relationship (4 CCR 904-3, Rule 4.02(B)(1)(a)).
Coverage of 5 rights: opt-out, access, correction, deletion, portability.
Portability limited to 2x per calendar year (C.R.S. § 6-1-1306(1)(e)).
Universal Opt-Out Mechanism honored automatically from July 2024 (C.R.S. § 6-1-1306(1)(a)(IV)(B)).
Conspicuously available appeal process as easy as the original submission process.
Deadlines: 45 days for response (+45 ext.); 45 days for appeals (+60 ext.).
Information to consumer on how to contact the AG in case of denied appeal.
Authentication with commercially reasonable effort, no fee charged, no unnecessary data requested.
Records maintained for 24 months with the 6 mandatory fields (4 CCR 904-3, Rule 6.11(A)).
Free first request; second may be charged under C.R.S. § 24-72-205(5)(a).
Consent refresh configured for 24 months of consumer inactivity.
Notification to processors when a deletion or correction is fulfilled.
| Request type | Response deadline | Extension possible |
|---|---|---|
| Opt-out, access, correction, deletion | 45 days | +45 days with notification |
| Portability (max 2x/year) | 45 days | +45 days with notification |
| Appeal of a decision | 45 days | +60 days with notification |
| Cure period (general violations) | Discretionary (2025) | No guarantee |
1. Does the CPA require a dedicated Privacy Portal or is an email address sufficient?
It depends on the type of business. Online-only businesses with a direct consumer relationship only need an email address (4 CCR 904-3, Rule 4.02(B)(1)(a)). Others need two or more methods, and a business with a website must offer a digital option (web form). A dedicated Privacy Portal is the most organized approach, but it is not the name the law requires.
2. How does the twice-per-year limit on portability work?
The right to portability under the CPA may be exercised no more than twice per calendar year (C.R.S. § 6-1-1306(1)(e)). This is a limit exclusive to the CPA among US state privacy laws. The right of access (without portable format) does not have this explicit limit in the statute, although the first request is free and subsequent ones may be charged.
3. What must the controller do when a consumer has not interacted for 24 months?
The regulations (4 CCR 904-3, Rule 7.08) require the controller to refresh consent for processing sensitive data and for secondary purposes involving profiling with significant effects, when the consumer has not interacted in the past 24 months. This means the Privacy Portal and consent management systems need to track the consumer's last interaction and trigger consent refresh flows.
4. What happens after a denied appeal under the CPA?
C.R.S. § 6-1-1306(3)(c) requires the controller to inform the consumer of the ability to contact the Attorney General. This differs from other laws that require specific instructions on how to contact the authority. The CPA is more open: the controller must communicate that this option exists. The consumer can then file a complaint with the AG or the District Attorney of the relevant jurisdiction.
5. Does the CPA have specific obligations about data found during an access request that the controller cannot disclose?
Yes. The regulations (4 CCR 904-3, Rule 4.04(D)) list categories of data the controller does not need to disclose in the access response: government-issued identification numbers, financial account numbers, health insurance or medical identification numbers, passwords, security questions, biometric data, and biometric identifiers. But the controller must inform the consumer that it holds these types of data, with sufficient particularity (e.g., "We collect unique biometric data including a fingerprint scan") without revealing the actual data.
Ready to build a Privacy Portal for your site that complies with the Colorado CPA? Talk to our team.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.
Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Here is a step-by-step explanation of how consent registration works in AdOpt.
The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.
In the end, our goal has never been to predict doom for companies or to be part of the LGPD's Apocalypse Cavalry. But, since we've been in the market for some time, these kinds of issues always catch our attention when we start data mapping and having conversations with colleagues.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
With the data mapping we have a clear understanding of the 5 stages that every data goes through in a company.
Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
The Data Protection Officer, or DPO, is a new position that emerged all over the globe with the new privacy regulations, and more recently at the LGPD. Although it already existed in other international legislations, such as the EU's GDPR, it is still a novelty here since 2020. Along with it comes the possibility of outsourcing, known as DPO as a Service (DPOaaS).
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.
Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!
What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.
Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.
Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.
Learn what your TIPA Privacy Policy must include to comply with the Tennessee Information Protection Act from consumer rights and targeted advertising disclosures to the NIST affirmative defense, appeal mechanisms, and how to keep your notice aligned with your operational program.
What the Utah UCPA requires from your Privacy Policy: five mandatory elements, opt-out model for sensitive data, no retention periods required, no active contact channel mandate, and the guaranteed 30-day cure period.
Brazilian LGPD - General Data Protection Law brought with it several acronyms and specific terms. Many of them are imported from other countries and regulations. One of them is ROPA (Record Of Processing Activities), adapted in Brazil to Registros das Atividades de Tratamento. An essential document for any DPO, Data Processor.
Everything about the California CCPA and CPRA: who must comply, the $25M threshold, 7 consumer rights, CCPA vs CPRA explained, the Do Not Sell link, CPPA enforcement, and cookies.
Surely you've already seen the predictions of fines and sanctions, processes. But, what does it mean to your company?
All the important information about the General Data Protection Law - LGPD: what it is, why it exists, how it works, when it came into force, who it applies to, potential fines, steps for compliance, and its legal principles.
Discover what the New Hampshire Privacy Act (NHDPA) means for your business. Learn about compliance steps, consumer rights, penalties, and how to simplify it all with AdOpt, a Google-certified CMP.
What the Virginia VCDPA requires from your Cookies Policy: targeted advertising disclosure, consent standards, tracker categories, opt-out mechanisms, and the 30-day cure period explained.
Iowa ICDPA explained: the longest response deadline of all US state privacy laws (90 days), 90-day cure period, opt-out for sensitive data, limited deletion scope, no right to correct, and how it compares to UCPA, VCDPA, and OCPA.
Ignoring Terms of Use and their significance within a website, particularly now with LGPD, is a common mistake that both consumers and website owners frequently commit.
Learn about how to apply Montana MTCDPA Cookies Policy in your site
09 Jun 2026
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications