Colorado Privacy Act biometric amendments (Privacy of Biometric Identifiers and Data)
CPA biometric (HB 24-1130)
Biometric · Employees
HB 24-1130 added biometric-specific duties to the Colorado Privacy Act, reaching any controller that handles biometric identifiers regardless of size and covering employees. Controllers need a public written retention and deletion policy, advance notice, consent, and may not sell biometric identifiers. Employers may require consent only for listed purposes such as secure access, timekeeping, and safety.
- Where
- Colorado
- Citation
- C.R.S. 6-1-1314; 6-1-1303(2.4), (2.5); 6-1-1304(1)(a)(II)
- Status
- In force
- In force since
- 2025-07-01
- Enforced by
- Colorado Attorney General and district attorneys
- People can sue
- No
- Penalties
- Enforced as a Colorado Privacy Act violation: deceptive trade practice, up to $20,000 per violation (6-1-1311; 6-1-112).
- Applies to
- Any controller that controls or processes biometric identifiers or biometric data, regardless of volume, as to those data (6-1-1304(1)(a)(II))
- Employers collecting biometric identifiers of employees and prospective employees, including contractors, interns, and fellows (6-1-1314(1)(b), (6))
- The right to access biometric data applies to larger controllers (100,000 / 25,000-plus-sale thresholds), commonly branded affiliates, and small joint ventures (6-1-1314(5)(b))
What a privacy notice must say
- Before collecting a biometric identifier, inform the consumer that it is being collected, the specific purpose, the retention period, and any disclosure to processors.C.R.S. 6-1-1314(4)(a)
Rights it gives people
- On request, disclose free of charge the source, purpose, third-party recipients, and categories of biometric data disclosed.C.R.S. 6-1-1314(5) · Only if: Applies to controllers meeting 6-1-1314(5)(b)
Practices it requires
- Do not sell, lease, or trade biometric identifiers, and disclose them only with consent, for a requested financial transaction, to a processor for the consented purpose, or as required by law.C.R.S. 6-1-1314(4)(b)
- Do not refuse service or charge different prices because a consumer declines biometric collection unless the biometric is necessary to provide the service.C.R.S. 6-1-1314(4)(c)
- Adopt a written policy with a retention schedule, an incident-response protocol, and deletion by the earliest of purpose satisfied, 24 months after last interaction, or 45 days after storage is found unnecessary; make it public (with exceptions for employee-only policies).C.R.S. 6-1-1314(2)
- Employers may condition employment on biometric consent only for secure access, recording the work day, workplace safety or security, or public emergencies; other uses need voluntary consent without retaliation.C.R.S. 6-1-1314(6)
- Obtain consent before collecting biometric data (sensitive data).C.R.S. 6-1-1314(4)(e); 6-1-1308(7)
Security duties
- Store, transmit, and protect biometric identifiers using the industry standard of care; processors need a breach-response protocol that notifies the controller.C.R.S. 6-1-1314(3), (4)(d)
Sources
- Official text
- Colorado Revised Statutes 2024, Title 6 (Office of Legislative Legal Services, leg.colorado.gov)
- HB24-1130 bill page: Privacy of Biometric Identifiers & Data (Colorado General Assembly)
- HB24-1130 session law, Privacy of Biometric Identifiers & Data (Colorado General Assembly)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Research reference, not legal advice.