Clym Logo

2026 Colorado Privacy Act Checklist: 11 Steps for Your Business

Published
AS
AuthorAdam Safar
7 min read

Colorado Privacy Act checklist 11 steps

An 11-step action checklist for CPA compliance efforts: scope, notices, opt-outs, GPC/UOOM, sensitive data, minors, biometric data, and DPAs.

Summarize full article with:

Use this checklist to review your business against the Colorado Privacy Act (CPA). Each step focuses on a specific action you can work through with your team or legal counsel.

For a deeper explanation of who the CPA applies to, what it requires, and how it compares with other state privacy laws, read Clym’s Colorado Privacy Act business guide first, then return to this checklist to put those requirements into practice.

Key takeaways
  • Start by checking whether the CPA applies to your business. There is no revenue threshold, and nonprofit status does not automatically place an organization outside the law’s scope.

  • The CPA no longer includes a cure period, so identified gaps should be addressed promptly rather than deferred.

  • Colorado requires businesses to recognize and honor qualifying universal opt-out mechanisms, including GPC. Test this functionality on your live site rather than assuming it is working correctly.

  • Processing sensitive data, including neural data, requires valid opt-in consent. Pre-checked boxes or similar passive consent methods are not sufficient.

  • The minors’ duty of care introduced by SB 24-041 applies separately from the CPA’s standard applicability thresholds, so review those requirements even if your business falls outside the main scope.

Quick CPA applicability check

The CPA likely applies if your business meets either of these thresholds:

  1. Do you control or process personal data from 100,000 or more Colorado residents in a calendar year?

  2. Do you control or process personal data from 25,000 or more Colorado residents, and derive revenue or a discount from selling that data?

If either threshold applies, continue through all 11 steps below. Even if neither applies, review Step 9 separately because the minors’ duty of care is not limited by these general thresholds.

Step 1: Confirm scope and document your basis

  • Record the date and threshold basis for your CPA determination

  • Confirm whether the CPA applies to your organization even if you are a nonprofit, as nonprofit status alone does not create an automatic exemption.

  • Check whether your organization qualifies for an entity-level exemption, such as those available to certain Colorado government bodies, air carriers, or financial institutions covered by the GLBA.

  • Separately confirm whether minors knowingly use your service, since Step 9 applies regardless of your threshold result

Step 2: Map your personal data and apply data minimization

  • Document the categories of personal data you collect, including any sensitive data and personal data relating to known children.

  • Document the purpose for collecting and processing each category

  • Document which third parties receive each category of personal data and the purpose for sharing it.

  • Cut any collection point that gathers more data than the stated purpose requires

Step 3: Update your privacy notice

  • Add the categories of personal data you process and the purposes for processing

  • Add the categories of personal data and third parties involved in any sharing

  • Add a clear explanation of consumer rights, including contact information

  • Add an appeal process for when a rights request is denied

A privacy and cookie policy solution can help keep this information organized as your data practices change.

Step 4: Set up opt-out mechanisms for sale, targeted advertising, and profiling

  • Implement an opt-out mechanism that is clearly visible and accessible before opt-out-eligible processing occurs.

  • Confirm the opt-out doesn’t require creating an account or navigating multiple pages

  • Confirm exercising the opt-out doesn’t reduce service quality or pricing for that consumer

  • Place a dedicated opt-out link in your website footer

A consent management solution that presents Colorado visitors with the correct options is the most common implementation approach.

Step 5: Honor GPC and other UOOM signals

  • Confirm your site detects Global Privacy Control (GPC) signals from Colorado visitors

  • Confirm a detected signal automatically suppresses sale and targeted-advertising processing, with no extra steps for the visitor

  • Test this on your live site rather than assuming your platform or vendor already handles it

See Clym’s guide on Colorado’s Universal Opt-Out Mechanism requirements for a deeper breakdown.

Step 6: Get opt-in consent before processing sensitive data

Confirm opt-in consent is required, not a pre-checked box or bundled consent, before processing any of the following:

  • Racial or ethnic origin

  • Religious or philosophical beliefs

  • Mental or physical health condition or diagnosis

  • Sex life or sexual orientation

  • Citizenship or immigration status

  • Genetic data that could uniquely identify a person

  • Biometric data processed for identification purposes

  • Neural data, added through attorney general rulemaking

  • Personal data from a known child

Step 7: Build a data subject rights process

  • Set up intake, identity verification, and tracking for consumer requests

  • Confirm you can respond within 45 days, with a documented process for the one-time 45-day extension

  • Confirm you have a working appeal mechanism for denied requests

A data subject request workflow helps track intake, deadlines, and documentation without manual spreadsheets.

Step 8: Complete data protection assessments for high-risk processing

  • Complete an assessment before using data for targeted advertising

  • Complete an assessment before selling personal data

  • Complete an assessment before processing sensitive personal data

  • Complete an assessment before profiling with legal or similarly significant effects

  • Store assessments somewhere your team can produce them within 30 days if the attorney general requests them

Step 9: Confirm your minors’ and biometric data practices

  • Identify whether your website, app, or product could reasonably be used by a Colorado teenager

  • If yes, confirm you restrict selling minors’ data or using it for targeted advertising without consent, per SB 24-041

  • If you collect facial geometry, voiceprints, fingerprints, or retina scans, confirm a written retention and destruction policy under HB 24-1130

  • Confirm opt-in consent for biometric data, plus parental consent if the data belongs to a minor

  • Complete this step regardless of whether you meet the standard consumer thresholds

Step 10: Review contracts with data processors

  • Confirm each processor contract states clear processing instructions, nature, and purpose

  • Confirm each contract requires appropriate technical and organizational security measures

  • Confirm subprocessors are bound by the same obligations, with advance notice before a new one is engaged

  • Confirm each contract requires the processor to delete or return data at the end of the engagement

  • Confirm you retain the right to conduct reasonable audits or inspections

Step 11: Review your enforcement readiness

  • Confirm your team knows the CPA no longer includes a cure period, so issues identified in Steps 1 through 10 should be addressed promptly.

  • Make sure relevant teams understand that penalties can reach $20,000 per violation, subject to the applicable cap for a related series of violations.

  • Confirm your team knows that the Colorado attorney general and district attorneys enforce the CPA and that the law does not provide a private right of action.

Common CPA checklist mistakes

  • Assuming the CPA does not apply because your business is a nonprofit or falls below the standard thresholds, without checking the minors’ provisions

  • Treating GPC and other UOOM signals as optional, especially now that no cure period is available

  • Missing the 2025 minors’ and biometric data updates because they were published after your last policy review

  • Running targeted advertising or selling data without a documented data protection assessment

  • Keeping data subject requests in manual spreadsheets without deadline tracking

How to stay on top of CPA changes

How Clym can support your CPA privacy program

  • Present location-appropriate consent and opt-out experiences to Colorado visitors using Clym’s geofencing and localization features

  • Automatically recognize and respond to GPC and other supported universal opt-out signals through Clym’s consent management platform

  • Manage data subject requests through a structured workflow for intake, tracking, response, and appeals

  • Keep privacy notices current as your data practices and regulatory obligations change

Clym does not guarantee compliance. Your obligations depend on your specific data practices, legal advice, and internal processes. The platform provides tools to support your privacy operations and help you work toward the CPA’s requirements.

Conclusion

Work through these 11 steps in order, starting with your thresholds. Since there is no cure period, treat anything you find as a priority rather than something to revisit later.

For the full explanation behind any of these requirements and how Colorado compares to other state privacy laws, go back to Clym’s Colorado Privacy Act business guide.

Review your website’s CPA readiness

Scan your website to identify cookies, trackers, and privacy workflows that may need review under Colorado and other state privacy laws.

Frequently asked questions

It’s an action checklist for working through Colorado Privacy Act requirements. Each step tells you what to check and do. For background on who the CPA applies to and why, see Clym’s Colorado Privacy Act business guide.

Any business that meets the CPA’s consumer thresholds, plus any business unsure whether minors use its service, since that duty applies regardless of thresholds.

Start with Step 1, then go straight to Step 9. Most gaps trace back to missing the minors’ and biometric data updates that took effect in 2025.

Racial or ethnic origin, religious beliefs, health diagnoses, sex life or sexual orientation, citizenship or immigration status, genetic data, biometric data used for identification, neural data, and personal data from a known child.

Yes, before targeted advertising, selling personal data, processing sensitive personal data, or profiling with legal or similarly significant effects. Keep it on file since the attorney general can request it within 30 days.

45 days, with one additional 45-day extension available for complex requests. If a request is denied, you must provide an appeal mechanism.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam