Colorado Privacy Act (C.R.S. 6-1-1301 et seq.)
Below is what the official text of Colorado Privacy Act (C.R.S. 6-1-1301 et seq.) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Colorado and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in Colorado: Not triggered by these answers.
- A US business with no users in Colorado: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Protects personal data of Colorado consumers and binds controllers that conduct business in Colorado or intentionally target Colorado residents and meet the thresholds.Official wording6-1-1304. Applicability of part. (1) EXCEPT AS SPECIFIED IN SUBSECTION (2) OF THIS SECTION, THIS PART 13 APPLIES TO A CONTROLLER THAT: | coag.gov read 2026-10-06 |
| When it applies to a business | Applies to a controller that conducts business in Colorado or produces or delivers commercial products or services intentionally targeted to Colorado residents and that controls or processes personal data of 100,000 consumers or more in a calendar year, or derives revenue or receives a discount on the price of goods or services from the sale of personal data and processes or controls personal data of 25,000 consumers or more. Conditions to check: The second threshold (sale of personal data AND 25,000 consumers or more) is not tested here: it has no revenue-share minimum and 'sale' differs from our question on selling or sharing data, so a business with 25,000 or more Colorado consumers that sells personal data can be covered even if the condition above is false. The enacted text lists exemptions for categories of data (HIPAA protected health information, GLBA data, FCRA, FERPA, employment records etc.) in 6-1-1304(2); no blanket exemption for nonprofits was found in this text, but entity-level exemptions elsewhere or in later amendments were not checked. 'Consumers' means Colorado residents (definition not quoted). 'Intentionally targeted' is not defined in the quote. Official wording(a) CONDUCTS BUSINESS IN COLORADO OR PRODUCES OR DELIVERS COMMERCIAL PRODUCTS OR SERVICES THAT ARE INTENTIONALLY TARGETED TO RESIDENTS OF COLORADO; AND (b) SATISFIES ONE OR BOTH OF THE FOLLOWING THRESHOLDS: (I) CONTROLS OR PROCESSES THE PERSONAL DATA OF ONE HUNDRED THOUSAND CONSUMERS OR MORE DURING A CALENDAR YEAR; | coag.gov read 2026-10-06 |
| In force from | 2023-07-01 SB 21-190 section 7: act takes effect July 1, 2023 (subject to a referendum clause); some provisions have later dates in the text, e.g. rules by July 1, 2025. Official wording(1) This act takes effect July 1, 2023; except that, if a referendum petition is filed pursuant to section 1 (3) of article V of the state constitution against this act | coag.gov read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text read does not say whether a data protection officer or privacy officer must be appointed | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here