Colorado Privacy Act (CPA)
The Colorado Privacy Act, as amended by SB23-316 (effective July 1, 2024), provides comprehensive consumer privacy rights for Colorado residents. It applies to controllers conducting business in Colorado or producing products/services targeted to Colorado residents that control or process personal data of 100,000+ consumers annually, excluding certain entities and de-identified data.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (21)
Consumer Rights
| Code | Title |
|---|---|
| CPA-CR-1 | Right to Access |
| CPA-CR-2 | Right to Correction |
| CPA-CR-3 | Right to Deletion |
| CPA-CR-4 | Right to Data Portability |
| CPA-CR-5 | Right to Opt Out |
| CPA-V2-2 | Consumer Right of Access |
| CPA-V2-3 | Right to Correction |
| CPA-V2-4 | Right to Deletion |
| CTDPA-3 | Right to Access (Section 4) |
| CTDPA-4 | Right to Correction and Deletion |
| CTDPA-5 | Right to Portability |
| CTDPA-6 | Right to Opt Out |
| FDBR-705 | Consumer Rights (§501.705) |
| FDBR-706 | Controller Response Requirements (§501.706) |
| RIDTPPA-6 | Right to Confirm and Access |
| RIDTPPA-7 | Right to Correct and Delete |
| RIDTPPA-8 | Right to Opt Out |
| TIPA-3 | Right to Access and Confirm |
| TIPA-4 | Right to Delete |
| TIPA-5 | Right to Opt Out |
| WDPA-3 | Right to Access and Confirm |
| WDPA-4 | Right to Portability |
| WDPA-5 | Right to Correction and Deletion |
| WDPA-6 | Right to Opt Out |
| s.6(1) | Right to Deletion |
| s.6(2) | Deletion Request Processing |
| s.6(3) | Right to Withdraw Consent |
| s.7(1) | Data Security Obligations |
Consumer Rights
| Code | Title |
|---|---|
| CPA-CR-1 | Right to Access |
| CPA-CR-2 | Right to Correction |
| CPA-CR-3 | Right to Deletion |
| CPA-CR-4 | Right to Data Portability |
| CPA-CR-5 | Right to Opt Out |
| CPA-V2-2 | Consumer Right of Access |
| CPA-V2-3 | Right to Correction |
| CPA-V2-4 | Right to Deletion |
| CTDPA-3 | Right to Access (Section 4) |
| CTDPA-4 | Right to Correction and Deletion |
| CTDPA-5 | Right to Portability |
| CTDPA-6 | Right to Opt Out |
| FDBR-705 | Consumer Rights (§501.705) |
| FDBR-706 | Controller Response Requirements (§501.706) |
| RIDTPPA-6 | Right to Confirm and Access |
| RIDTPPA-7 | Right to Correct and Delete |
| RIDTPPA-8 | Right to Opt Out |
| TIPA-3 | Right to Access and Confirm |
| TIPA-4 | Right to Delete |
| TIPA-5 | Right to Opt Out |
| WDPA-3 | Right to Access and Confirm |
| WDPA-4 | Right to Portability |
| WDPA-5 | Right to Correction and Deletion |
| WDPA-6 | Right to Opt Out |
| s.6(1) | Right to Deletion |
| s.6(2) | Deletion Request Processing |
| s.6(3) | Right to Withdraw Consent |
| s.7(1) | Data Security Obligations |
Controller Obligations
| Code | Title |
|---|---|
| CPA-CO-1 | Privacy Notice Requirements |
| CPA-CO-2 | Purpose Limitation |
| CPA-CO-3 | Data Minimization |
| CPA-CO-4 | Data Security |
| CTDPA-10 | Privacy Notice |
| CTDPA-7 | Data Minimization |
| CTDPA-8 | Security Practices |
| CTDPA-9 | Consent for Sensitive Data |
| LEB-14 | Registration and Licensing |
| LEB-15 | Penalties and Enforcement |
| TIPA-6 | Purpose Limitation |
| TIPA-7 | Privacy Notice |
| TIPA-8 | Sensitive Data Consent |
| TIPA-9 | Response Timeline |
| WDPA-10 | Non-Discrimination |
| WDPA-7 | Data Minimization |
| WDPA-8 | Security Practices |
| WDPA-9 | Privacy Notice |
DPIA
| Code | Title |
|---|---|
| CPA-V2-13 | Data Protection Assessments |
Data Protection Assessments
| Code | Title |
|---|---|
| CPA-DPA-1 | Assessment Requirement |
| CPA-DPA-2 | Targeted Advertising Assessment |
| CPA-DPA-3 | Profiling Risk Assessment |
| CTDPA-11 | DPA Requirements |
| CTDPA-12 | AG Review of DPAs |
Enforcement
| Code | Title |
|---|---|
| CPA-V2-19 | Cure Period and Enforcement |
Governance
| Code | Title |
|---|---|
| CPA-V2-21 | Cross-Functional Privacy Governance |
Minors
| Code | Title |
|---|---|
| CPA-V2-17 | Children Under 13 Special Rules |
Opt Out
| Code | Title |
|---|---|
| CPA-V2-5 | Right to Opt Out of Sale, Targeted Advertising, Profiling |
| CPA-V2-6 | Universal Opt-Out Mechanism Recognition |
Pricing
| Code | Title |
|---|---|
| CPA-V2-20 | Loyalty Program Bona Fide Test |
Principles
| Code | Title |
|---|---|
| CPA-V2-10 | Secondary Use Restrictions |
| CPA-V2-9 | Purpose Limitation and Data Minimization |
Profiling
| Code | Title |
|---|---|
| CPA-V2-14 | Profiling Decisions Disclosure |
Records
| Code | Title |
|---|---|
| CPA-V2-18 | Recordkeeping for Compliance |
Rights
| Code | Title |
|---|---|
| CPA-V2-12 | Anti-Discrimination in Rights Exercise |
| CPA-V2-16 | Authenticated Appeal Process |
Scope
| Code | Title |
|---|---|
| CPA-V2-1 | Applicability Threshold Determination |
Security
| Code | Title |
|---|---|
| CPA-V2-11 | Reasonable Security Practices |
Sensitive Data
| Code | Title |
|---|---|
| CPA-V2-7 | Consent for Sensitive Data Processing |
Sensitive Data and Consent
| Code | Title |
|---|---|
| AICDA-3.1 | Consent for Sensitive Data |
| AICDA-3.2 | Children's Data Protections |
| AICDA-3.3 | Age-Appropriate Design Code |
| AICDA-3.4 | Prohibition on Dark Patterns |
| CPA-SD-1 | Sensitive Data Consent |
| CPA-SD-2 | Children's Data Protection |
| CPA-SD-3 | Secondary Use Consent |
Third Party
| Code | Title |
|---|---|
| CPA-V2-15 | Processor Contracts |
Transparency
| Code | Title |
|---|---|
| CPA-V2-8 | Privacy Notice Content |
Universal Opt-Out and Enforcement
| Code | Title |
|---|---|
| CPA-UO-1 | Universal Opt-Out Mechanism |
| CPA-UO-2 | Automated Decision-Making Regulations |
| CPA-UO-3 | Attorney General Enforcement |
| CPA-UO-4 | Cure Period |
Your Compliance Coverage
If you comply with Colorado Privacy Act (CPA), you already cover:
FAA Cybersecurity Framework for Aviation
26%
21 controls mapped
Compare →Connecticut Data Privacy Act (CTDPA)
25%
20 controls mapped
Compare →Azure Security Benchmark
24%
19 controls mapped
Compare →+ 587 more: TISAX — Trusted Information Security Assessment Exchange (24%), CSA STAR (Security, Trust, Assurance, and Risk) (24%)
See all 590 mapped frameworks ↓Maps to 590 other frameworks
Frequently Asked Questions
What is Colorado Privacy Act (CPA)?
Colorado Privacy Act (CPA) is a compliance framework from United States — Colorado with 21 domains and 80 controls. The Colorado Privacy Act, as amended by SB23-316 (effective July 1, 2024), provides comprehensive consumer privacy rights for Colorado residents. It applies to controllers conducting business in Colorado or producing products/services targeted to Colorado residents that control or process personal data of 100,000+ consumers annually, excluding certain entities and de-identified data. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Colorado Privacy Act (CPA) have?
Colorado Privacy Act (CPA) has 80 controls organised across 21 domains. The largest domains are Consumer Rights (25 controls), Controller Obligations (18 controls), Sensitive Data and Consent (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Colorado Privacy Act (CPA) map to?
Colorado Privacy Act (CPA) maps to 590 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (26% coverage), Connecticut Data Privacy Act (CTDPA) (25% coverage), Azure Security Benchmark (24% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Colorado Privacy Act (CPA) compliance?
Start your Colorado Privacy Act (CPA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Colorado Privacy Act (CPA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 80 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required