What CPA actually requires
Colorado's consumer privacy law, similar in shape to Virginia's VCDPA but with stricter rules around dark patterns and a clearer mandate to honour the Global Privacy Control. Enforced by the Colorado Attorney General and the Department of Law.
Key requirements
- Publish a privacy notice that describes categories of data and purposes
- Offer easy-to-find opt-outs of targeted advertising, sale of data, and profiling
- Honour the Global Privacy Control as a universal opt-out signal
- Avoid 'dark patterns' that nudge users toward consent
- Conduct data protection assessments for high-risk processing
- Process consumer rights requests (access, correction, deletion, portability) within 45 days
At a glance
Full name
Colorado Privacy Act
Region
Colorado, USA
Status
In force since July 2023
Who it affects
Controllers that conduct business in Colorado and either (a) process personal data of 100,000+ Coloradans per year, or (b) process data of 25,000+ Coloradans and derive revenue from selling personal data.
Penalties
Up to USD 20,000 per violation under the Colorado Consumer Protection Act, with potential injunctive relief on top. Each consumer or transaction can count as a separate violation.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
