Colorado Privacy Act Rules
CPA Rules
Comprehensive privacy · Children · Biometric
The Attorney General's rules implementing the Colorado Privacy Act. They set detailed requirements for privacy notices, rights requests, universal opt-out mechanisms, valid consent and dark patterns, data protection assessments, profiling, and opinion letters. Amendments effective January 30, 2025 added biometric and opinion-letter rules, and amendments effective December 1, 2025 implemented the minors' (SB 24-041) and precise geolocation (SB 25-276) changes.
- Where
- Colorado
- Citation
- 4 CCR 904-3
- Status
- In force
- In force since
- 2023-07-01
- Last amended
- 2025-12-01
- Enforced by
- Colorado Attorney General (Department of Law, Consumer Protection Section)
- People can sue
- No
- Penalties
- Enforced through the Colorado Privacy Act and Colorado Consumer Protection Act penalties (up to $20,000 per violation).
- Applies to
- Controllers and processors subject to the Colorado Privacy Act (4 CCR 904-3, Rule 1.01, 1.04)
What a privacy notice must say
- Privacy notices must meet content and accessibility requirements (including WCAG 2.1 for disclosures) and consumers must be notified of material changes.4 CCR 904-3, Rules 3.02, 6.02-6.04, 12.02
- Provide a biometric identifier notice at or before collection or before a material change in purpose.4 CCR 904-3, Rule 6.12 · From 2025-07-01
- Explain profiling used for legally or similarly significant decisions and how to opt out.4 CCR 904-3, Rules 9.03-9.04
Rights it gives people
- Recognize universal opt-out mechanisms on the Department of Law's public list; a signal may be sent as an HTTP header or JavaScript object.4 CCR 904-3, Rules 5.06-5.08
Practices it requires
- Consent must be freely given, specific, informed, and unambiguous; agreement obtained through dark patterns is not valid consent.4 CCR 904-3, Rules 7.03, 7.10
- Refresh consent for sensitive data processing (and certain secondary-use profiling) when the consumer has not interacted with the controller in 24 months, unless a user-controlled preference interface is available.4 CCR 904-3, Rule 7.08
- Conduct data protection assessments before initiating heightened-risk processing, with specified content, and update them over the processing lifecycle.4 CCR 904-3, Rules 8.04-8.05
- Factors for deciding whether a controller willfully disregards that a consumer is a minor, and rules on system design features that extend minors' use.4 CCR 904-3, Rules 6.13-6.14 · From 2025-12-01
- Keep records of consumer rights requests and responses for at least 24 months.4 CCR 904-3, Rule 6.11
Sources
- Official text
- 4 CCR 904-3 rule history (Colorado Secretary of State, Code of Colorado Regulations)
- 4 CCR 904-3 current version effective 12/01/2025 (PDF, Secretary of State)
- 2025 Colorado Privacy Act rulemaking (Colorado Attorney General)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Research reference, not legal advice.