Privacy
Colorado Privacy Act (CPA)
The CPA applies to a controller that conducts business in Colorado or produces or delivers commercial products or services intentionally targeted to Colorado residents and that either controls or processes the personal data of 100,000 or more consumers in a calendar year, or derives revenue or receives a discount from selling personal data and processes or controls the personal data of 25,000 or more consumers. A controller that processes any amount of biometric identifiers or biometric data is covered for that data regardless of volume. The minors' protections in §§ 6-1-1305.5, 6-1-1308.5 and 6-1-1309.5 apply to any controller doing business in Colorado regardless of volume or revenue. Nonprofits are covered.
What the website needs
- A controller must provide a reasonably accessible, clear and meaningful privacy notice listing the categories of personal data collected or processed, the purposes, how consumers can exercise their rights and appeal a decision with the controller's contact information, the categories of personal data shared with third parties, and the categories of those third parties (C.R.S. § 6-1-1308(1)(a)).
- A controller that sells personal data or uses it for targeted advertising must clearly and conspicuously disclose that processing and how to opt out (C.R.S. § 6-1-1308(1)(b)).
- The opt-out method must appear clearly and conspicuously in the privacy notice and in a clear, conspicuous and readily accessible location outside the privacy notice (C.R.S. § 6-1-1306(1)(a)(III)).
- A controller may not process sensitive data without first obtaining the consumer's consent, and for a known child it must obtain a parent's or guardian's consent (C.R.S. § 6-1-1308(7)).


