State Guide
Colorado Privacy & Data Security Laws
Every statute below can apply to a business handling Colorado residents' data, depending on your revenue, the number of Colorado consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Applies at 100,000+ Colorado consumers, or 25,000+ if you derive revenue (or a discount on goods/services) from selling personal data. Unlike most peer states, Colorado does NOT exempt nonprofits generally. Biometric-specific amendments (written retention/destruction policy, consent gate) apply regardless of these thresholds. Colorado's HIPAA exemption (C.R.S. § 6-1-1304(2)) is data-level only (PHI collected/processed by a covered entity), not a whole-entity exemption. Its GLBA exemption is a genuine entity-level carve-out. The higher-education exemption is narrower than it sounds — limited to state (public) institutions, and only for data processed for noncommercial purposes; a private university or a public university's commercial activities aren't covered.
Data Security & Breach Notification · 1
Requires reasonable security procedures and practices proportionate to the sensitivity of the data. Applies regardless of company size whenever you hold covered personal information about a resident of this state.
Student Data Privacy · 1
Restricts ed-tech vendors from selling student data or using it for advertising; requires security and breach notification specific to student data.