Privacy Law Library

Colorado Privacy Act Rules

CPA Rules

Comprehensive privacy · Children · Biometric

The Attorney General's rules implementing the Colorado Privacy Act. They set detailed requirements for privacy notices, rights requests, universal opt-out mechanisms, valid consent and dark patterns, data protection assessments, profiling, and opinion letters. Amendments effective January 30, 2025 added biometric and opinion-letter rules, and amendments effective December 1, 2025 implemented the minors' (SB 24-041) and precise geolocation (SB 25-276) changes.

Where
Colorado
Citation
4 CCR 904-3
Status
In force
In force since
2023-07-01
Last amended
2025-12-01
Enforced by
Colorado Attorney General (Department of Law, Consumer Protection Section)
People can sue
No
Penalties
Enforced through the Colorado Privacy Act and Colorado Consumer Protection Act penalties (up to $20,000 per violation).
Applies to
  • Controllers and processors subject to the Colorado Privacy Act (4 CCR 904-3, Rule 1.01, 1.04)

What a privacy notice must say

  • Privacy notices must meet content and accessibility requirements (including WCAG 2.1 for disclosures) and consumers must be notified of material changes.4 CCR 904-3, Rules 3.02, 6.02-6.04, 12.02
  • Provide a biometric identifier notice at or before collection or before a material change in purpose.4 CCR 904-3, Rule 6.12 · From 2025-07-01
  • Explain profiling used for legally or similarly significant decisions and how to opt out.4 CCR 904-3, Rules 9.03-9.04

Rights it gives people

  • Recognize universal opt-out mechanisms on the Department of Law's public list; a signal may be sent as an HTTP header or JavaScript object.4 CCR 904-3, Rules 5.06-5.08

Practices it requires

  • Consent must be freely given, specific, informed, and unambiguous; agreement obtained through dark patterns is not valid consent.4 CCR 904-3, Rules 7.03, 7.10
  • Refresh consent for sensitive data processing (and certain secondary-use profiling) when the consumer has not interacted with the controller in 24 months, unless a user-controlled preference interface is available.4 CCR 904-3, Rule 7.08
  • Conduct data protection assessments before initiating heightened-risk processing, with specified content, and update them over the processing lifecycle.4 CCR 904-3, Rules 8.04-8.05
  • Factors for deciding whether a controller willfully disregards that a consumer is a minor, and rules on system design features that extend minors' use.4 CCR 904-3, Rules 6.13-6.14 · From 2025-12-01
  • Keep records of consumer rights requests and responses for at least 24 months.4 CCR 904-3, Rule 6.11

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.