Colorado Privacy Act checklist 11 steps
An 11-step action checklist for CPA compliance efforts: scope, notices, opt-outs, GPC/UOOM, sensitive data, minors, biometric data, and DPAs.
An 11-step action checklist for CPA compliance efforts: scope, notices, opt-outs, GPC/UOOM, sensitive data, minors, biometric data, and DPAs.
Use this checklist to review your business against the Colorado Privacy Act (CPA). Each step focuses on a specific action you can work through with your team or legal counsel.
For a deeper explanation of who the CPA applies to, what it requires, and how it compares with other state privacy laws, read Clym’s Colorado Privacy Act business guide first, then return to this checklist to put those requirements into practice.
Start by checking whether the CPA applies to your business. There is no revenue threshold, and nonprofit status does not automatically place an organization outside the law’s scope.
The CPA no longer includes a cure period, so identified gaps should be addressed promptly rather than deferred.
Colorado requires businesses to recognize and honor qualifying universal opt-out mechanisms, including GPC. Test this functionality on your live site rather than assuming it is working correctly.
Processing sensitive data, including neural data, requires valid opt-in consent. Pre-checked boxes or similar passive consent methods are not sufficient.
The minors’ duty of care introduced by SB 24-041 applies separately from the CPA’s standard applicability thresholds, so review those requirements even if your business falls outside the main scope.
The CPA likely applies if your business meets either of these thresholds:
Do you control or process personal data from 100,000 or more Colorado residents in a calendar year?
Do you control or process personal data from 25,000 or more Colorado residents, and derive revenue or a discount from selling that data?
If either threshold applies, continue through all 11 steps below. Even if neither applies, review Step 9 separately because the minors’ duty of care is not limited by these general thresholds.
Record the date and threshold basis for your CPA determination
Confirm whether the CPA applies to your organization even if you are a nonprofit, as nonprofit status alone does not create an automatic exemption.
Check whether your organization qualifies for an entity-level exemption, such as those available to certain Colorado government bodies, air carriers, or financial institutions covered by the GLBA.
Separately confirm whether minors knowingly use your service, since Step 9 applies regardless of your threshold result
Document the categories of personal data you collect, including any sensitive data and personal data relating to known children.
Document the purpose for collecting and processing each category
Document which third parties receive each category of personal data and the purpose for sharing it.
Cut any collection point that gathers more data than the stated purpose requires
Add the categories of personal data you process and the purposes for processing
Add the categories of personal data and third parties involved in any sharing
Add a clear explanation of consumer rights, including contact information
Add an appeal process for when a rights request is denied
A privacy and cookie policy solution can help keep this information organized as your data practices change.
Implement an opt-out mechanism that is clearly visible and accessible before opt-out-eligible processing occurs.
Confirm the opt-out doesn’t require creating an account or navigating multiple pages
Confirm exercising the opt-out doesn’t reduce service quality or pricing for that consumer
Place a dedicated opt-out link in your website footer
A consent management solution that presents Colorado visitors with the correct options is the most common implementation approach.
Confirm your site detects Global Privacy Control (GPC) signals from Colorado visitors
Confirm a detected signal automatically suppresses sale and targeted-advertising processing, with no extra steps for the visitor
Test this on your live site rather than assuming your platform or vendor already handles it
See Clym’s guide on Colorado’s Universal Opt-Out Mechanism requirements for a deeper breakdown.
Confirm opt-in consent is required, not a pre-checked box or bundled consent, before processing any of the following:
Racial or ethnic origin
Religious or philosophical beliefs
Mental or physical health condition or diagnosis
Sex life or sexual orientation
Citizenship or immigration status
Genetic data that could uniquely identify a person
Biometric data processed for identification purposes
Neural data, added through attorney general rulemaking
Personal data from a known child
Set up intake, identity verification, and tracking for consumer requests
Confirm you can respond within 45 days, with a documented process for the one-time 45-day extension
Confirm you have a working appeal mechanism for denied requests
A data subject request workflow helps track intake, deadlines, and documentation without manual spreadsheets.
Complete an assessment before using data for targeted advertising
Complete an assessment before selling personal data
Complete an assessment before processing sensitive personal data
Complete an assessment before profiling with legal or similarly significant effects
Store assessments somewhere your team can produce them within 30 days if the attorney general requests them
Identify whether your website, app, or product could reasonably be used by a Colorado teenager
If yes, confirm you restrict selling minors’ data or using it for targeted advertising without consent, per SB 24-041
If you collect facial geometry, voiceprints, fingerprints, or retina scans, confirm a written retention and destruction policy under HB 24-1130
Confirm opt-in consent for biometric data, plus parental consent if the data belongs to a minor
Complete this step regardless of whether you meet the standard consumer thresholds
Confirm each processor contract states clear processing instructions, nature, and purpose
Confirm each contract requires appropriate technical and organizational security measures
Confirm subprocessors are bound by the same obligations, with advance notice before a new one is engaged
Confirm each contract requires the processor to delete or return data at the end of the engagement
Confirm you retain the right to conduct reasonable audits or inspections
Confirm your team knows the CPA no longer includes a cure period, so issues identified in Steps 1 through 10 should be addressed promptly.
Make sure relevant teams understand that penalties can reach $20,000 per violation, subject to the applicable cap for a related series of violations.
Confirm your team knows that the Colorado attorney general and district attorneys enforce the CPA and that the law does not provide a private right of action.
Assuming the CPA does not apply because your business is a nonprofit or falls below the standard thresholds, without checking the minors’ provisions
Treating GPC and other UOOM signals as optional, especially now that no cure period is available
Missing the 2025 minors’ and biometric data updates because they were published after your last policy review
Running targeted advertising or selling data without a documented data protection assessment
Keeping data subject requests in manual spreadsheets without deadline tracking
Review your privacy notice and data practices at least once a year and whenever your processing activities change materially
Monitor Colorado AG guidance and enforcement actions for how enforcement is being applied
Update your data map whenever you add new vendors, tools, or data collection methods
If you operate across multiple states, Clym’s U.S. state privacy law comparison guide covers thresholds, cure periods, and enforcement side by side
Present location-appropriate consent and opt-out experiences to Colorado visitors using Clym’s geofencing and localization features
Automatically recognize and respond to GPC and other supported universal opt-out signals through Clym’s consent management platform
Manage data subject requests through a structured workflow for intake, tracking, response, and appeals
Keep privacy notices current as your data practices and regulatory obligations change
Clym does not guarantee compliance. Your obligations depend on your specific data practices, legal advice, and internal processes. The platform provides tools to support your privacy operations and help you work toward the CPA’s requirements.
Work through these 11 steps in order, starting with your thresholds. Since there is no cure period, treat anything you find as a priority rather than something to revisit later.
For the full explanation behind any of these requirements and how Colorado compares to other state privacy laws, go back to Clym’s Colorado Privacy Act business guide.
Scan your website to identify cookies, trackers, and privacy workflows that may need review under Colorado and other state privacy laws.
It’s an action checklist for working through Colorado Privacy Act requirements. Each step tells you what to check and do. For background on who the CPA applies to and why, see Clym’s Colorado Privacy Act business guide.
Any business that meets the CPA’s consumer thresholds, plus any business unsure whether minors use its service, since that duty applies regardless of thresholds.
Start with Step 1, then go straight to Step 9. Most gaps trace back to missing the minors’ and biometric data updates that took effect in 2025.
Racial or ethnic origin, religious beliefs, health diagnoses, sex life or sexual orientation, citizenship or immigration status, genetic data, biometric data used for identification, neural data, and personal data from a known child.
Yes, before targeted advertising, selling personal data, processing sensitive personal data, or profiling with legal or similarly significant effects. Keep it on file since the attorney general can request it within 30 days.
45 days, with one additional 45-day extension available for complex requests. If a request is denied, you must provide an appeal mechanism.