Colorado can fine a business up to $20,000 per violation under the Colorado Privacy Act, and there is no cap on how high the total penalty can climb, according to Colorado Revised Statutes 6-1-112 as amended in 2019. That per-violation maximum is the highest among the major comprehensive state privacy laws, and it sits inside a law that has added a new compliance deadline roughly every six months since mid-2023. Below is the full set of thresholds, penalty figures, and dates that matter for any business handling Colorado residents' personal data.

Colorado Privacy Act penalties can reach 20,000 dollars per violation $20K per violation under the CPA,with no cap on the total

What are the Colorado Privacy Act's applicability thresholds?

A business must meet one of two thresholds to fall under the CPA: controlling or processing the personal data of 100,000 or more Colorado consumers in a calendar year, or controlling or processing the data of 25,000 or more consumers while deriving revenue, or a discount on goods or services, from selling personal data. Both thresholds count Colorado residents acting in a personal or household capacity only, and both exclude data collected in an employment or business-to-business context.

Neither threshold looks at where a business is headquartered. A retailer based in Texas or an app publisher based overseas is just as covered as a Denver-based company the moment either count is crossed, because the CPA, like every comprehensive state privacy law, applies based on whose data is processed rather than where the processor sits. That makes the threshold test the first question any compliance review should answer, well before looking at what the law actually requires a covered business to disclose or offer consumers.

Small businesses sometimes assume a low overall customer count keeps them out of scope entirely, and for most that assumption holds. It stops holding the moment any meaningful share of revenue comes from selling contact records, audience segments, or other personal data to a third party, since the 25,000-consumer threshold sits far below what many data-driven small businesses already process in a single year.

Figure 1: The Colorado Privacy Act's two-track applicability test, plus the separate biometric-data carve-out that applies regardless of size. Source: Colorado Attorney General CPA guidance, HB24-1130.

The lower 25,000-consumer threshold exists specifically to catch data brokers and ad-tech firms whose business model depends on selling personal data, even if their total consumer count is modest. A local retailer with 40,000 Colorado customers and no data-sale revenue falls outside the law entirely, while a smaller data broker with 26,000 records for sale falls squarely inside it.

How much can a Colorado Privacy Act violation actually cost?

Up to $20,000 per violation, and Colorado law counts each affected consumer or transaction as a separate violation, with no ceiling on the combined total since HB19-1289 removed the previous $500,000 aggregate cap in 2019. Violations targeting an elderly consumer carry an even higher $50,000-per-violation maximum. That structure means the size of a CPA penalty scales directly with how many people a single violation touches, not with a fixed statutory ceiling.

Figure 2: Colorado's per-violation maximum is more than double Virginia's and roughly 7.5 times California's standard rate. Sources: Colorado Revised Statutes 6-1-112, Code of Virginia 59.1-584, Connecticut General Statutes 42-110o, California Privacy Protection Agency 2025 inflation adjustment.

Because each affected consumer counts separately, the theoretical exposure for a violation touching every consumer at the CPA's own 100,000-consumer coverage threshold works out to $2 billion, a figure no actual Colorado enforcement action has come close to and one that exists purely to illustrate how the per-violation structure scales, not as a projection of a real case. Sites that handle sensitive data or run targeted advertising at any real scale can generate a Colorado-compliant privacy policy that keeps disclosure obligations, sale opt-outs, and sensitive-data consent current with the statute rather than relying on a generic multi-state template.

Colorado is not alone in ratcheting up its privacy penalty exposure. Our roundup of state privacy laws now in effect nationwide tracks how 20 states now share this same broad enforcement structure, even though the dollar figures and cure-period rules differ state by state.

What happened when Colorado's right-to-cure period ended?

The CPA's mandatory 60-day right-to-cure period sunset on January 1, 2025, roughly 18 months after the law's July 1, 2023 effective date. Before that date, a business that received a violation notice from the Colorado Attorney General had 60 days to fix the problem and avoid any enforcement action. After it, the Attorney General and Colorado's district attorneys can pursue enforcement immediately, with no guaranteed warning first.

Figure 3: Nine compliance milestones across four years, none of them optional. Source: Colorado Attorney General press releases and rulemaking pages, Colorado General Assembly bill records.

On September 9, 2025, the Attorneys General of Colorado, California, and Connecticut, working with the California Privacy Protection Agency, announced a joint investigative sweep of businesses that appeared not to be honoring Global Privacy Control opt-out signals, the same mechanism Colorado's own July 2024 deadline required. The three-state coordination signals that Colorado's opt-out enforcement is no longer an isolated state effort but part of a shared, cross-border enforcement posture among the states with the most active privacy regulators.

How has the number of active CPA compliance obligations grown since 2023?

A business that only had to worry about the base CPA disclosure and opt-out rules in mid-2023 now has five distinct, independently effective sets of obligations layered on top of one another, each triggered by its own statute and its own deadline rather than arriving as a single update.

Figure 4: Each milestone adds a new, still-active obligation rather than replacing the one before it. Source: Colorado Attorney General rulemaking pages, Colorado General Assembly bill records for HB24-1130 and SB24-041.

The fifth layer, Colorado's automated decision-making law under SB26-189, does not take effect until January 1, 2027, so it is not yet part of the active count above, but businesses using algorithmic tools for hiring, lending, or similar consequential decisions about Colorado residents should treat it as the next confirmed addition to this stack; our coverage of Colorado's AI Act repeal and replacement covers what that law will require in more detail.

Which states require honoring an opt-out signal like Colorado's?

Colorado was among the earlier states to formally recognize Global Privacy Control as a valid universal opt-out mechanism, but it is no longer unusual. Twelve of the 20 states with a comprehensive privacy law in effect as of 2026 now require businesses to honor an opt-out preference signal such as GPC, according to tracking compiled from state attorney general guidance and legislative text across the current privacy law landscape.

Figure 5: Colorado sits in the 12-state majority that has moved from opt-out links to machine-readable opt-out signals. Source: state attorney general guidance and enacted privacy statutes, compiled 2026.

For a business already honoring GPC in Colorado, extending the same technical handling to California, Connecticut, and the other nine states on this list is largely a configuration exercise rather than new engineering work, since GPC is a single browser-level signal rather than a state-specific format.

How does Colorado's cure period and penalty structure compare to neighboring state laws?

LawMax penalty per violationConsumer thresholdCure period status (2026)
Colorado Privacy Act$20,000100,000, or 25,000 with data salesSunset January 1, 2025
Virginia CDPA$7,500100,000, or 25,000 with 50%+ revenue from salesPermanent 30-day cure
Connecticut CTDPA$5,000100,000, or 25,000 with data salesDiscretionary as of 2025
California CCPA/CPRA$2,663 standard, $7,988 intentional or minorsRevenue or volume-based, not a flat consumer countNo mandatory cure period

Sources: Colorado Revised Statutes 6-1-112, Code of Virginia 59.1-584, Connecticut General Statutes 42-110o, California Privacy Protection Agency 2025 inflation adjustment announcement.

Virginia is the outlier here, since it kept a permanent 30-day cure period rather than letting one sunset the way Colorado and Connecticut did. That difference matters operationally: a Virginia-only business still gets a guaranteed chance to fix a violation before facing a penalty, while a Colorado-only business as of 2025 does not.

The Bottom Line

Colorado's $20,000-per-violation, no-aggregate-cap penalty structure makes it the strictest comprehensive state privacy law on paper, and the sunset of its 60-day cure period on January 1, 2025 means that structure is no longer theoretical. Five distinct compliance obligations, base disclosures, the July 2024 opt-out signal requirement, the July 2025 biometric amendment, the October 2025 minors' protections, and the coming 2027 automated decision-making law, are now stacked on top of each other rather than replacing one another, and Colorado's participation in a multistate GPC enforcement sweep alongside California and Connecticut shows regulators are actively checking for gaps rather than waiting for complaints. For any business meeting the 100,000 or 25,000-consumer threshold, treating the CPA as a one-time compliance project rather than a rolling set of deadlines is the single biggest risk this data points to.

Frequently Asked Questions

What are the Colorado Privacy Act's applicability thresholds? A business must either control or process the personal data of 100,000 or more Colorado consumers in a calendar year, or process the data of 25,000 or more consumers while deriving revenue or a discount from selling personal data, according to the Colorado Attorney General's official CPA guidance.

How much can a Colorado Privacy Act violation cost? Up to $20,000 per violation, with each affected consumer or transaction counted as a separate violation and no cap on the total penalty, under Colorado Revised Statutes 6-1-112 as amended by HB19-1289 in 2019. That is the highest per-violation maximum among the major comprehensive state privacy laws.

When did the Colorado Privacy Act's right-to-cure period end? The mandatory 60-day cure period sunset on January 1, 2025, roughly 18 months after the law took effect on July 1, 2023. Since that date, the Colorado Attorney General and district attorneys can pursue enforcement immediately, without first offering a chance to fix the violation.

What is the deadline for Colorado's minors' data protections? October 1, 2025, when Senate Bill 24-041 took effect, requiring parental consent before processing a minor's data for targeted advertising, sale, or profiling, and adding a duty of reasonable care for any online service a business knows is used by minors under 18.

Where the Numbers Come From

  1. Colorado Attorney General. "Colorado Privacy Act (CPA)." Applicability thresholds, enforcement authority, and general CPA guidance.
  2. Justia, Colorado Revised Statutes. Section 6-1-112, "Civil penalties." $20,000 standard maximum, $50,000 for violations against elderly consumers, no aggregate cap since the 2019 amendment.
  3. Colorado General Assembly. "HB19-1289, Consumer Protection Act." Raised the per-violation maximum from $2,000 to $20,000 and removed the prior $500,000 aggregate cap, effective May 23, 2019.
  4. Colorado Attorney General. "Universal Opt-Out and the Colorado Privacy Act." Global Privacy Control recognized as the sole valid universal opt-out mechanism, requirement effective July 1, 2024.
  5. Colorado Attorney General. "2025 Colorado Privacy Act rulemaking." Updated CPA rules finalized December 5, 2024, effective January 30, 2025.
  6. Colorado General Assembly. "HB24-1130, Privacy of Biometric Identifiers and Data." Amendment effective July 1, 2025, applying to any amount of biometric data regardless of the CPA's standard consumer-count thresholds.
  7. Colorado General Assembly. "SB24-041, Protections for Minors." Parental consent and heightened-risk-assessment requirements effective October 1, 2025.
  8. California Department of Justice. "Attorney General Bonta Announces Joint Investigative Privacy Sweep, CO, CT, and CA." Multistate Global Privacy Control enforcement sweep announced September 9, 2025.
  9. California Privacy Protection Agency. "California Privacy Protection Agency Announces 2025 Increases for CCPA Fines and Penalties." Standard maximum $2,663, intentional or minors' violations $7,988, effective January 1, 2025.

Note: All figures verified as of August 2026. Colorado's automated decision-making law, SB26-189, does not take effect until January 1, 2027, and is included here as a confirmed upcoming deadline rather than a currently active obligation. This post's figures are refreshed at least twice a year as Colorado's Attorney General publishes new rulemaking and enforcement updates.