Back to Frameworks

Colorado Privacy Act

United States - Colorado
v2023 (effective date) or 2021 (enactment year)
5 domains
22 controls

The Colorado Privacy Act (CPA) grants Colorado residents rights over their personal data, including the right to access, correct, delete, and opt‑out of processing for targeted advertising, profiling, or other discriminatory purposes. It applies to controllers and processors that (a) conduct business in Colorado or target Colorado residents, (b) process personal data of at least 100,000 Colorado residents annually, or (c) derive revenue of $25 million or more from the personal data of Colorado residents. The CPA also requires covered entities to implement data minimization, purpose limitation, reasonable security measures, and to appoint a data protection officer (or designate a responsible individual).

Verified

Colorado Privacy Act is a compliance framework from United States - Colorado with 5 domains and 22 controls that map to 2 other frameworks. The largest domains are Colorado Privacy Act: Controller Duties (6-1-1308) (8 controls), Colorado Privacy Act: Consumer Rights (6-1-1306) (6 controls), Colorado Privacy Act: Enforcement and Rules (6-1-1310 to 1313) (3 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Colorado Privacy Act: Consumer Rights (6-1-1306)

6 controls
Controls in the Colorado Privacy Act: Consumer Rights (6-1-1306) domain of Colorado Privacy Act6 controls
CodeTitle
COPA-1306-ACCESSRight of Access
COPA-1306-APPEALRight to Appeal
COPA-1306-CORRECTRight to Correction
COPA-1306-DELETERight to Deletion
COPA-1306-OPTOUTRight to Opt Out
COPA-1306-PORTABILITYRight to Data Portability

Colorado Privacy Act: Controller Duties (6-1-1308)

8 controls
Controls in the Colorado Privacy Act: Controller Duties (6-1-1308) domain of Colorado Privacy Act8 controls
CodeTitle
COPA-1308-CAREDuty of Care (Security)
COPA-1308-CONSENTValid Consent and Dark Patterns
COPA-1308-MINIMIZATIONDuty of Data Minimization
COPA-1308-NONDISCRIMDuty to Avoid Unlawful Discrimination
COPA-1308-PURPOSEDuty of Purpose Specification
COPA-1308-SECONDARYDuty to Avoid Secondary Use
COPA-1308-SENSITIVEDuty Regarding Sensitive Data
COPA-1308-TRANSPARENCYDuty of Transparency (Privacy Notice)

Colorado Privacy Act: Enforcement and Rules (6-1-1310 to 1313)

3 controls
Controls in the Colorado Privacy Act: Enforcement and Rules (6-1-1310 to 1313) domain of Colorado Privacy Act3 controls
CodeTitle
COPA-1310-LIABILITYLiability and Processor Allocation
COPA-1311-ENFORCEEnforcement by the Attorney General and District Attorneys
COPA-1313-RULESRules and Universal Opt-Out Mechanism

Colorado Privacy Act: Processor and Assessments (6-1-1305/1309)

2 controls
Controls in the Colorado Privacy Act: Processor and Assessments (6-1-1305/1309) domain of Colorado Privacy Act2 controls
CodeTitle
COPA-1305-PROCESSORProcessor Contracts and Role Responsibility
COPA-1309-DPAData Protection Assessments

Colorado Privacy Act: Scope and Definitions (6-1-1303/1304/1307)

3 controls
Controls in the Colorado Privacy Act: Scope and Definitions (6-1-1303/1304/1307) domain of Colorado Privacy Act2 controls
CodeTitle
COPA-1304-SCOPEApplicability and Thresholds
COPA-1307-DEIDENTDe-identified and Pseudonymous Data

Maps to 2 other frameworks

21 total controls
GDPR
13 source controls mapped|11 target controls covered
62%
CCPA/CPRA
5 source controls mapped|5 target controls covered
24%

What is Colorado Privacy Act and who does it apply to?

Colorado Privacy Act is a compliance framework from United States - Colorado with 5 domains and 22 controls. The Colorado Privacy Act (CPA) grants Colorado residents rights over their personal data, including the right to access, correct, delete, and opt‑out of processing for targeted advertising, profiling, or other discriminatory purposes. It applies to controllers and processors that (a) conduct business in Colorado or target Colorado residents, (b) process personal data of at least 100,000 Colorado residents annually, or (c) derive revenue of $25 million or more from the personal data of Colorado residents. The CPA also requires covered entities to implement data minimization, purpose limitation, reasonable security measures, and to appoint a data protection officer (or designate a responsible individual). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Colorado Privacy Act actually require?

Colorado Privacy Act has 22 controls organised across 5 domains. The largest domains are Colorado Privacy Act: Controller Duties (6-1-1308) (8 controls), Colorado Privacy Act: Consumer Rights (6-1-1306) (6 controls), Colorado Privacy Act: Enforcement and Rules (6-1-1310 to 1313) (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Colorado Privacy Act do I already cover?

Colorado Privacy Act maps to 2 other compliance frameworks. The top mapping partners are GDPR (62% coverage), CCPA/CPRA (24% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Colorado Privacy Act?

Start your Colorado Privacy Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Colorado Privacy Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required