Understanding Colorado Privacy Act (CPA) Compliance

From consumer rights to penalties for non-compliance, learn how businesses can stay on the right side of the Colorado Privacy Act. 

Trusted and used by 25,000+ websites and great companies across the world.

Monday.com
Semrush
Dealfront
Yotpo.com
Tixly.com
Cookie Preferences

What your business needs to know

As data privacy concerns escalate, US states are enacting their own privacy laws to safeguard consumers. The Colorado Privacy Act (CPA), which was signed into law in July 2021, reflects this trend, following similar legislation in California and Virginia. Designed to provide Colorado residents with greater control over their personal data, CPA requires businesses to adhere to specific privacy standards. As of July 1, 2023, the act was fully enforceable, with non-compliance resulting in substantial penalties. In this guide, we’ll outline CPA’s provisions, who it affects, and perhaps most importantly, how you can stay compliant.

What are the requirements under CPA?

CPA places several key demands on businesses. These include:

Who does CPA apply to?

The Act applies to businesses that meet at least one of the following criteria:

The Act also extends to service providers, contractors, and vendors responsible for managing data on behalf of these companies.

Consumer rights under CPA

The Act grants Colorado residents five key rights regarding their personal data:

Fully responsive

Right to Access

Consumers can request access to their personal data that a business has collected.

Fully responsive

Right to Deletion

They can demand the deletion of their personal data (with certain exceptions, such as data required for legal compliance).

Fully responsive

Right to Opt-Out

Consumers can opt out of specific types of data processing, such as targeted advertising or the sale of personal data.

Fully responsive

Right to Correction

Consumers can ask for corrections to inaccurate personal data.

When it comes to catering to these rights, businesses must have systems in place to process consumer requests within 45 days (although they may request a 45-day extension in some cases).

Why are cookies important for Colorado State compliance?

Cookies are small pieces of data stored on a user’s device that track their behavior, preferences, and interactions with a website. They play a key role in data collection for any number of businesses, especially when it comes to targeted advertising and website analytics. Under CPA, businesses need to be transparent about how they use cookies to collect personal data and offer consumers the ability to opt out of these data processing activities.

With cookies a central part of the State’s data privacy ethos, businesses need to manage cookie consent properly. This means obtaining clear authorization from users before collecting personal data via cookies and providing mechanisms for consumers to opt-out or withdraw consent at any time.

Penalties for
non-compliance

Businesses that fail to comply with the CPA can face steep penalties. The Colorado Attorney General and district attorneys are responsible for enforcing the law, and penalties can reach $20,000 per violation. With each violation referring to an individual instance where a consumer’s rights are infringed, fines can add up quickly.

That said, CPA provides a 60-day cure period, during which businesses can fix violations after being notified by the state without incurring penalties. However, this grace period will expire in January 2025—after that, violations could lead to immediate fines.

Unlike some other privacy laws, the CPA doesn’t grant a private right of action, meaning consumers can’t sue businesses directly for violations. Instead, enforcement is handled solely by state authorities.

How to comply with the CPA

To make sure that businesses remain CPA compliant, they should take the following steps:

How CookieHub can help

For businesses, managing cookie consent is one of the most important aspects of CPA compliance—fortunately, that’s where CookieHub can help. Our easy-to-use consent management solution simplifies the whole process by automating the obtaining, managing, and storing user consent.

With free options for sites with up to 5,000 sessions per month and paid plans starting at just €8 a month, CookieHub is the affordable way to stay compliant.

To find out more about CookieHub and how our consent management platform can keep your website compliant, contact us here.

Cookie Scanner

Are you compliant?

Sales & Support