Home
Colorado CPA: Privacy Policy

Colorado CPA: Privacy Policy

3 months ago
João Bruno Soares
17 minutes

The Colorado Privacy Act (CPA, C.R.S. § 6-1-1301 et seq.) has one of the most detailed sets of privacy notice requirements among all US state privacy laws.

This page covers one piece of the picture. For the full scope of the CPA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the CPA and cookies.

This happens because Colorado went beyond the statute: the Attorney General promulgated the Colorado Privacy Act Rules (4 CCR 904-3), a complete set of regulations that precisely specify what each element of the privacy notice must contain, how it must be presented, in what languages, and which changes require immediate update.

This article focuses exclusively on what the CPA and its regulations require from the Privacy Policy, based on the official text of both documents.

What the CPA calls a Privacy Notice

The law uses the term "privacy notice." In practice, it is the Privacy Policy.

C.R.S. § 6-1-1308(1) requires the controller to provide consumers with a privacy notice that is "reasonably accessible, clear, and meaningful."

The regulations (4 CCR 904-3, Rule 6.02) expand this standard: the notice must give the consumer a meaningful understanding and accurate expectations of how their personal data will be processed. It must be clear, easily accessible, specific, and available in all languages the controller regularly uses to interact with consumers.

What must be in the Privacy Policy under the CPA

1. Categories of personal data processed

The notice must list the categories of personal data collected or processed by the controller or a processor (C.R.S. § 6-1-1308(1)(a)(I)).

The regulations (4 CCR 904-3, Rule 6.03(A)(1)(a)) require categories to be described at a sufficient level of detail for the consumer to understand the type of data. Examples of categories with adequate granularity: "contact information," "government-issued identification numbers," "payment information," "data from cookies," "data revealing religious affiliation," "medical data."

The notice must also specifically indicate whether sensitive data or children's data is processed.

2. The purposes for which the data is processed

The notice must explain what the data of each category is used for (C.R.S. § 6-1-1308(1)(a)(II)).

The regulations (4 CCR 904-3, Rule 6.06) require the purpose to be described at a level of detail that gives the consumer a meaningful understanding of how the data is used. Vague purposes are not permitted. If data will be used for targeted advertising, profiling, or sale, this must be stated explicitly for each category.

3. How consumers exercise their rights and file appeals

The notice must describe how and where consumers can exercise the rights guaranteed by the CPA, including the controller's contact information and how to appeal a decision (C.R.S. § 6-1-1308(1)(a)(III)).

The regulations (4 CCR 904-3, Rule 6.03(A)(4)) detail what must be in the notice:

Instructions on how to use each available submission method.

Instructions on how an authorized agent may submit opt-outs on behalf of a consumer.

A clear and conspicuous method to exercise opt-out of targeted advertising and data sale.

The description of the commercially reasonable identity authentication process.

Effective July 2024: explanation of how requests via Universal Opt-Out Mechanism will be processed.

4. Categories of personal data shared with third parties

If the controller shares data with third parties, the notice must identify the categories of data shared (C.R.S. § 6-1-1308(1)(a)(IV)).

The regulations (4 CCR 904-3, Rule 6.03(A)(1)(d)) also require the notice to indicate whether each category of data will be sold, used for targeted advertising, or for profiling with significant effects on the consumer.

5. Categories of third parties with whom data is shared

In addition to the categories of data, the notice must identify the categories of third parties that receive them (C.R.S. § 6-1-1308(1)(a)(V)).

The regulations (4 CCR 904-3, Rule 6.03(A)(1)(e)) require categories of third parties to be described at a level of detail that gives the consumer a meaningful understanding of the type, business model of, or processing conducted by those third parties. Examples: "analytics companies," "data brokers," "third-party advertisers," "payment processors," "lenders," "government agencies."

6. The date of last update

The regulations (4 CCR 904-3, Rule 6.03(A)(8)) require the notice to include the date it was last updated.

The opt-out mechanism must be in the notice

C.R.S. § 6-1-1308(1)(b) requires that if the controller sells personal data or processes for targeted advertising, it must disclose this clearly and conspicuously, along with the method to exercise the opt-out.

The regulations (4 CCR 904-3, Rule 4.03(B)) detail: the opt-out method must appear in the privacy notice AND in a clear, conspicuous, and readily accessible location outside the notice. A direct link to the opt-out method is required.

From July 2024, the notice must also describe how requests via Universal Opt-Out Mechanism (including the GPC) will be processed.

Sensitive data: additional requirements

If the controller processes sensitive data, the notice must reflect this explicitly.

Sensitive data under the CPA (C.R.S. § 6-1-1303(24)) includes: racial or ethnic origin, religious beliefs, physical or mental health, sex life or sexual orientation, citizenship status, genetic or biometric data for identification, and known children's data.

The regulations (4 CCR 904-3, Rule 6.10) add an important nuance: inferences made by the controller that indicate these sensitive categories ("Sensitive Data Inferences") are also sensitive data and require consent to be processed, except in specific situations where they can be deleted within 24 hours.

If the controller uses this 24-hour inference exception, the notice must describe the inferences subject to this provision and the retention and deletion timeline.

The duty of purpose specification

The CPA explicitly names the duty of purpose specification as an autonomous controller obligation (C.R.S. § 6-1-1308(2)): the controller must specify the express purposes for which personal data are collected and processed.

The regulations (4 CCR 904-3, Rule 6.06) detail what this means:

The purpose must be described at a level of detail that gives the consumer a meaningful understanding of how the data is used.

If data is collected for more than one purpose, each unrelated purpose must be specified separately.

It is not permitted to identify a broad purpose to justify numerous processing activities that are only remotely related.

It is not permitted to specify so many purposes that the purposes become unclear or uninformative.

The duty to avoid secondary use

The CPA also names the duty to avoid secondary use (C.R.S. § 6-1-1308(4)): the controller must not process personal data for purposes not reasonably necessary or compatible with the specified purposes, except with consumer consent.

The regulations (4 CCR 904-3, Rule 6.08) detail: if the controller collected data before July 2023 and the processing purpose changes after that date in a way incompatible with the original, new consent must be obtained.

The 24-month consent refresh requirement

This is a requirement exclusive to Colorado's regulations that does not exist in other US state privacy laws.

Under 4 CCR 904-3, Rule 7.08: when a consumer has not interacted with the controller in the past 24 months, the controller must refresh consent to:

Continue processing sensitive data.

Continue processing personal data for secondary purposes involving profiling with significant effects.

The exception is for cases where the consumer has permanent access and ability to update their opt-out preferences through a consumer-controlled interface.

The Privacy Policy must describe when and how this consent will be refreshed.

Material changes: mandatory notification

The regulations (4 CCR 904-3, Rule 6.04) require the controller to notify consumers of material changes to the privacy notice, communicated in a manner by which the controller regularly interacts with consumers.

Material changes include: categories of personal data processed, processing purposes, the controller's identity, the act of sharing personal data with third parties, categories of third parties, and methods for exercising rights.

If a material change constitutes a secondary use, the controller must obtain consumer consent.

Enforcement and penalties

CPA violations are treated as deceptive trade practices under the Colorado Consumer Protection Act (C.R.S. § 6-1-1311(1)(c)).

Enforcement is shared between the Attorney General and District Attorneys of Colorado. There is no private right of action (C.R.S. § 6-1-1310).

Before 2025, there was a guaranteed 60-day cure period. From 2025 onward, the cure period is discretionary.

How AdOpt supports CPA compliance

AdOpt ensures that what is written in the Policy has real correspondence with what actually happens on the site.

The automatic scan identifies all active technologies, feeding the list of data categories and third parties. The consent management platform ensures that the Universal Opt-Out Mechanism is honored automatically and the consent mechanism works as described.

Every interaction is logged for 24 months as required by the regulations.

Over 60,000 websites already run with AdOpt.

Privacy is not a banner. It is a position.

Want to build a Privacy Policy for your site that complies with the Colorado CPA? Talk to our team.

Checklist: what the Privacy Policy must contain for the CPA

Visible and accessible link on all pages, using the word "privacy" (4 CCR 904-3, Rule 6.02(E)).

Available in all languages used by the controller to interact with consumers (4 CCR 904-3, Rule 3.02(A)(3)).

Accessible for people with disabilities, following WCAG 2.1 (4 CCR 904-3, Rule 3.02(A)(2)).

Categories of personal data processed, with sufficient granularity (C.R.S. § 6-1-1308(1)(a)(I)).

Purpose for each category, without vague descriptions (C.R.S. § 6-1-1308(1)(a)(II)).

Whether data will be sold, used for targeted advertising, or profiling (4 CCR 904-3, Rule 6.03(A)(1)(c)).

How to exercise all rights guaranteed by the CPA, with processes and timelines (C.R.S. § 6-1-1308(1)(a)(III)).

Appeal process described with 45+60 day deadlines.

Categories of personal data shared with third parties (C.R.S. § 6-1-1308(1)(a)(IV)).

Categories of third parties with detail on type/business model (C.R.S. § 6-1-1308(1)(a)(V)).

Opt-out method clearly within and outside the notice (C.R.S. § 6-1-1308(1)(b)).

Universal Opt-Out Mechanism processing explained (4 CCR 904-3, Rule 6.03(A)(4)(e)).

Sensitive data and sensitive data inferences identified with how consent is obtained.

Consent refresh policy after 24 months of consumer inactivity (4 CCR 904-3, Rule 7.08).

Date of last update (4 CCR 904-3, Rule 6.03(A)(8)).

Controller contact information.

Authentication process described.

FAQ: CPA and Privacy Policy

1. Does the CPA require a Colorado-specific privacy notice?
No. The regulations (4 CCR 904-3, Rule 6.02(B)) confirm that the controller does not need a separate Colorado notice, as long as the existing notice meets all CPA requirements and makes clear that Colorado consumers have the rights provided by C.R.S. § 6-1-1306.

2. In how many languages must the privacy notice be available?
The notice must be available in all languages in which the controller ordinarily provides web pages, interfaces, contracts, and other information to consumers (4 CCR 904-3, Rule 3.02(A)(3)). Communications sent directly to the consumer must be in the language the consumer ordinarily uses to interact with the controller.

3. What are "Sensitive Data Inferences" and how do they affect the Privacy Policy?
They are inferences made by the controller based on personal data indicating racial or ethnic origin, religious beliefs, health condition, sex life or sexual orientation, or citizenship status (4 CCR 904-3, Rule 2.02). Like the underlying sensitive data, these inferences require consent to be processed. If the controller uses the 24-hour deletion exception, the Policy must describe the inferences subject to this provision and the retention timeline.

4. What is the 24-month consent refresh requirement?
The regulations (4 CCR 904-3, Rule 7.08) require that when a consumer has not interacted with the controller in the past 24 months, consent for processing sensitive data or for secondary purposes involving significant profiling effects must be refreshed. This requirement is exclusive to Colorado and does not exist in other US state privacy laws.

5. What changed in CPA enforcement from 2025?
Before 2025, C.R.S. § 6-1-1311(1)(d) guaranteed 60 days to cure before legal action. From January 1, 2025, this provision was repealed. The Attorney General and District Attorneys now have discretion to investigate and act without any obligation to grant a prior correction period.

Ready to build a Privacy Policy for your site that complies with the Colorado CPA? Talk to our team.

Tags

Colorado CPA
Cookie Banner
Cookies
Privacy Policy

Related posts

5 Common Cookie Consent Mistakes Hurting Your Compliance

Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.

AdOpt post

Connecticut CTDPA: Cookies Policy

What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.

AdOpt post

7 Steps to GDPR-Compliant Cookie Banners in 2025

Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.

AdOpt post

5 Signs Your Website Needs an Cookie Consent Strategy

How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.

AdOpt post

How long can we ignore LGPD?

LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?

AdOpt post

California CCPA: DSAR Privacy Portal

How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.

AdOpt post

LGPD: An Opportunity for Digital Marketing Agencies!

Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.

AdOpt post

Why Give Consent on Every Website I Visit?

Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.

AdOpt post

New Hampshire NHDPA: Privacy Policy

Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.

AdOpt post

The Impact of Cookie Banners on Your E-commerce - LGPD

Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.

AdOpt post

California CPRA and Cookies: All you need to know

California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.

AdOpt post

MTCDPA Montana and Cookies: All you need to know

Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana

AdOpt post

IOWA ICDPA: DSAR and Privacy Portal

Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.

AdOpt post

Utah UCPA: DSAR and Privacy Portal

Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.

AdOpt post

Montana MTCDPA: Privacy Policy

Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.

AdOpt post

What is a privacy policy?

A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.

AdOpt post

How does a cookie banner operate?

Here is a step-by-step explanation of how consent registration works in AdOpt.

AdOpt post

Texas TDPSA: Privacy Policy

The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.

AdOpt post

New Hampshire NHDPA: DSAR Privacy Portal

What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.

AdOpt post

Tenesse TIPA: Cookies Policy

Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.

AdOpt post

Connecticut CTDPA and Cookies: All You Need to Know

The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.

AdOpt post

Florida FDBR and Cookies: All You Need to Know

Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.

AdOpt post

Colorado CPA: Cookies Policy

What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.

AdOpt post

Oregon OCPA and Cookies: All You Need to Know

Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.

AdOpt post

LGPD and Cookies all do you need to know?

In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.

AdOpt post

California CPRA: Privacy Policy

What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.

AdOpt post

Florida FDBR: Cookies Policy

What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.

AdOpt post

Google Consent Mode: Beginner to Advanced Guide.

Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.

AdOpt post

Tenesse TIPA: DSAR Privacy Portal

Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.

AdOpt post

Colorado CPA and Cookies: All You Need to Know

The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?

AdOpt post

Florida FDBR: Privacy Policy

What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.

AdOpt post

California CCPA: Privacy Policy

What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.

AdOpt post

Connecticut CTDPA: Privacy Policy

What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.

AdOpt post

Utah UCPA and Cookies: All you need to know

Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.

AdOpt post

Oregon OCPA: Cookies Policy

What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.

AdOpt post

California CPRA: DSAR and Privacy Portal

California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.

AdOpt post

Texas TDPSA and Cookies: All You Need to Know

Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.

AdOpt post

Virginia VCDPA: DSAR Privacy Portal

How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.

AdOpt post

GDPR Legal Basis: An Introduction

In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.

AdOpt post

Florida FDBR: DSAR Privacy Portal

How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.

AdOpt post

IOWA ICDPA: Cookies Policy

What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.

AdOpt post

Montana MTCDPA: DSAR Policy

Rights, Policy and how to understand about the DSAR Montana MTCDPA

AdOpt post

What is the difference between cookies, local storage, and session storage?

Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!

AdOpt post

California CPRA: Cookies Policy

What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.

AdOpt post

How to choose a Cookie Banner for your website

What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!

AdOpt logoAdOpt logo

Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819

15 Rue du Général Campredon, 34000 Montpellier, France

207 Rue de Bercy, 75012 Paris, France

EIN: 86-3965064

Phone: +1 (407) 768-3792

AdOpt

Resources

Product

Certifications

Google CMP PartnerIAB Europe TCF Registered Vendor

© GO ADOPT, LLC since 2020 - Made by people who love🍪