Loading
Home / Get your website ready for Colorado CPA compliance

Get your website ready for Colorado CPA compliance

Build clearer website privacy controls under the Colorado Privacy Act (CPA). Okito helps you identify tracking technologies, configure consent and opt-out choices, and keep visitor preferences organised in one platform.

Get Started
Powering we provide the latest solutions for website privacy compliance
garcia.png
suaryapi.png
blackstate.png
gulbenergen.png
reportage.png
sulax.png (1)
barbertrade.png
naksanyapi.png
byonhotels.png
atlastek.png
nexonya.png
uiduk.png
endemik.png
yediiklim.png
scotty.png
pehlivan.png
mintek.png
ader.png

Key Features of USA Laws CPA Compliance with Okito

Identify website technologies

Scan your website for cookies, pixels, tags and third-party scripts. Okito helps you organise detected technologies by provider, category and processing purpose.

Identify website technologies

Configure privacy choices

Create consent and opt-out controls that reflect how personal data is used. Manage website choices for sensitive data, targeted advertising and other relevant purposes.

Configure privacy choices

Keep settings and records organised

Bring detected technologies, consent activity and visitor preferences into one dashboard. Review your configuration when vendors, purposes or website integrations change.

Keep settings and records organised

Key website privacy controls under the Colorado CPA

Obtain valid consent for sensitive data

The Colorado CPA requires consent before sensitive data is collected or processed. Consent must be freely given, specific, informed and unambiguous, and obtained through a clear affirmative action.

  • Explain the data and processing purpose before requesting consent.

  • Avoid preselected choices, inactivity and deceptive interface designs.

  • Make withdrawing consent as accessible as giving it.

Sensitive data includes specified demographic, health, biometric, genetic, precise geolocation and children’s data. Additional requirements may apply when personal data belongs to a known child or minor.

Okito helps you configure granular privacy choices and connect recorded preferences with relevant website technologies.

Manage opt-out choices and privacy signals

Colorado consumers may opt out of personal data sales, targeted advertising and profiling used to make decisions with legal or similarly significant effects.

  • Provide a clear and accessible method for submitting opt-out choices.

  • Apply visitor preferences to the relevant configured technologies.

  • Explain how recognised universal opt-out mechanisms are processed.

Since July 1, 2024, covered controllers must recognise universal opt-out mechanisms accepted by the Colorado Department of Law for targeted advertising and personal data sales.

Okito supports website-level privacy choices by connecting visitor preferences with configured advertising and tracking services.

Keep privacy notices and consumer rights accessible

A Colorado CPA privacy notice should clearly explain what personal data is processed, why it is used and how consumers can exercise their rights.

  • Describe the categories and purposes of personal data processing.

  • Identify personal data shared with third parties and the categories of recipients.

  • Explain how consumers can access, correct, delete or obtain a portable copy of their data.

  • Clearly disclose personal data sales or targeted advertising and the available opt-out methods.

Controllers must also provide an internal appeal process when they refuse to act on a consumer request.

Okito’s technology inventory helps your team compare website activity with the information presented in privacy notices and preference interfaces.

Support assessments and ongoing accountability

The Colorado CPA requires data protection assessments for processing activities that may create heightened risks for consumers.

  • Assess targeted advertising, personal data sales and qualifying profiling activities.

  • Review sensitive data processing and other activities presenting heightened risks.

  • Document the benefits, potential harms and safeguards associated with the processing.

Controllers must also minimise unnecessary data collection, avoid incompatible secondary uses without consent and maintain reasonable security practices.

Okito’s technology inventory, provider details and preference records can support internal reviews. The controller remains responsible for completing and documenting the required assessment.

Simplify Your USA Laws CPA Compliance Today

1

Register

Create your agency profile to initiate the legal compliance process. Our expert team will review your application and provide instant access to our specialized USA Laws CPA management dashboard.

2

Configure

Set up customized "Opt-Out" mechanisms and data management preferences for your clients. Use Okito’s centralized tools to handle complex regulatory requirements through a simple, no-code interface.

3

Activate

Deploy CPA-compliant banners across all client websites. Automate data processing signals to protect your brands and ensure full security against regulatory audits and legal risks.

Please use an email address that is not associated with an existing Okito account.

What is the Colorado Privacy Act?

The Colorado Privacy Act (CPA) is a comprehensive state privacy law signed on July 7, 2021, and effective since July 1, 2023. It gives Colorado consumers rights over personal data and establishes obligations for covered controllers and processors.

The law addresses transparency, consumer requests, sensitive data consent, data minimisation, security, opt-out choices and data protection assessments. It is not solely a cookie law, but it may apply to personal data collected through cookies, pixels and similar website technologies.

Who does the Colorado CPA apply to?

The Colorado CPA applies to organisations that conduct business in Colorado or intentionally target commercial products or services to Colorado residents and meet either threshold:

  • Control or process personal data belonging to at least 100,000 consumers during a calendar year.

  • Derive revenue or receive a discount from selling personal data and process or control data belonging to at least 25,000 consumers.

A consumer is a Colorado resident acting in an individual or household context. Employment, job-applicant and commercial contexts are excluded. The CPA can apply to nonprofit organisations, although certain entities and regulated categories of data are exempt.

What are consumer rights under the Colorado CPA?

What are consumer rights under the Colorado CPA?

Colorado consumers have the right to:

  • Confirm whether their personal data is being processed and access it.

  • Correct inaccuracies in their personal data.

  • Delete personal data concerning them.

  • Obtain certain data in a portable and readily usable format.

  • Opt out of personal data sales, targeted advertising and qualifying profiling.

Consumers may also appeal when a controller refuses to act on a request. Covered controllers must recognise qualifying universal opt-out mechanisms for targeted advertising and personal data sales.

What is the penalty for Colorado CPA non-compliance?

The Colorado Attorney General and district attorneys have exclusive authority to enforce the CPA. The law does not give consumers a private right of action.

CPA violations are treated as deceptive trade practices under the Colorado Consumer Protection Act and may result in injunctions and civil penalties of up to $20,000 per violation. The CPA’s temporary mandatory 60-day cure period expired on January 1, 2025, so regulators are no longer generally required to provide that cure opportunity before enforcement.

FAQ

Frequently Asked Questions

Yes. The Colorado Privacy Act (CPA) is a comprehensive state privacy law that took effect on July 1, 2023. It gives Colorado residents control over certain uses of their personal data and requires covered controllers to provide transparent privacy notices, minimize data collection, protect personal data and respond to consumer requests.

The law applies to Colorado residents acting in an individual or household context. Employment, job-applicant and business-to-business contexts are generally outside its definition of a consumer.

Personal data is information linked or reasonably linkable to an identified or identifiable individual. Depending on the context, this may include names, email addresses, account details, online identifiers, device identifiers and browsing information.

De-identified data and information lawfully available from government records or intentionally made public by the consumer are excluded from the CPA definition.

The CPA does not require every website to display a cookie consent banner. The appropriate mechanism depends on how the website’s cookies, pixels and tracking technologies process personal data.

A covered controller may need consent when processing sensitive data or using personal data for certain secondary purposes. Websites that sell personal data or use it for targeted advertising must provide a clear opt-out method and honor applicable universal opt-out signals. A banner can support these requirements, but displaying one does not establish CPA compliance on its own.

Covered controllers that process personal data for targeted advertising or its sale have been required to recognize qualifying universal opt-out mechanisms since July 1, 2024.

Global Privacy Control (GPC) is currently the mechanism recognized by the Colorado Department of Law. When a valid GPC signal is received, it must be treated as an opt-out of targeted advertising and the sale of personal data, subject to the CPA’s applicable rules.

Yes. Controllers must conduct and document a data protection assessment before undertaking processing that presents a heightened risk of harm, including:

  • Processing personal data for targeted advertising.

  • Selling personal data.

  • Processing sensitive data.

  • Using qualifying profiling that creates a reasonably foreseeable risk of unfair treatment, financial or physical injury, an offensive intrusion into privacy or another substantial injury.

Assessments must weigh the processing benefits against potential consumer risks. They remain confidential but must be made available to the Colorado Attorney General when requested for a civil investigation.

Sensitive data is a protected subset of personal data. It includes:

  • Data revealing racial or ethnic origin, religious beliefs, health conditions or diagnoses, sex life, sexual orientation, citizenship or citizenship status.

  • Genetic or biometric data used or intended to uniquely identify an individual.

  • Biological data, including qualifying neural data.

  • Personal data belonging to a known child.

  • Precise geolocation data under the CPA’s current provisions.

Controllers generally must obtain valid consent before processing sensitive data. Processing a known child’s data also requires compliance with applicable parental-consent requirements.

There is no direct UK equivalent to the Colorado Privacy Act. General personal data processing in the UK is primarily regulated by the UK GDPR and the Data Protection Act 2018. PECR adds specific rules for cookies, similar technologies and electronic marketing.

The UK framework is broader than the Colorado CPA in several respects, including its lawful-basis requirements and application beyond businesses meeting specific consumer-volume thresholds. The Information Commissioner’s Office (ICO) is the UK’s independent data protection regulator.