Colorado's Privacy Law Has a Feature Most States Don't: Automatic Browser Opt-Out
Colorado's privacy law shares a lot of structure with Virginia's, same consumer-count threshold, same core rights. But it adds one requirement that catches sellers off guard: your store has to detect and honor a browser-level opt-out signal automatically, without the consumer clicking anything on your site at all.
Who the Colorado Privacy Act Applies To
The threshold mirrors Virginia's closely: businesses that control or process personal data for 100,000 or more Colorado consumers annually, or that control or process data for 25,000 or more consumers while deriving revenue from the sale of personal data. Like Virginia, there is no revenue-only trigger. Consumer volume is what matters.
The Universal Opt-Out Requirement
This is the detail that actually separates Colorado from most of its peers. Colorado law requires businesses to recognize universal opt-out mechanisms, browser or device-level signals that automatically communicate a consumer's opt-out preference to every website they visit.
In practice, this means a Colorado resident could enable a signal once in their browser settings and have it apply across every site they visit afterward, including yours, without ever finding or clicking your opt-out link. If your store's compliance approach is "we have a link in the footer," that alone isn't enough under Colorado's law. Your systems need to actually detect and act on the incoming signal.
Consumer Rights
Colorado grants the same core set found in Virginia's law: confirmation of processing and access, correction, deletion, data portability, and opt-out of targeted advertising, sale of data, and significant-effect profiling. Sensitive data again requires opt-in consent before processing.
Active Enforcement
The Colorado Attorney General enforces this law and has been described as taking a genuinely active posture compared to some other states' AG offices. There is no private right of action. A cure period exists but is more limited than in many other states, worth confirming current terms directly rather than assuming a long grace period.
What This Means for Your Store's Technical Setup
If you sell into Colorado and haven't specifically checked whether your cookie consent or privacy tooling recognizes signals like Global Privacy Control, that's the concrete first thing worth verifying, separate from anything about your written privacy policy. A policy that reads perfectly can still leave you non-compliant if the underlying technical detection isn't actually in place.
Check Your Colorado Exposure
All information in this article is sourced from the Colorado Privacy Act (Colo. Rev. Stat. § 6-1-1301 et seq.) and the Colorado Attorney General's published compliance guidance. Regulens is informational only and this article is not legal advice. Speak to a licensed privacy attorney about your specific compliance situation.
Regulens tracks Colorado as part of its ongoing state-by-state privacy coverage. Your store's readiness is calculated based on your actual inputs and current policy documents.
Free to check, takes three minutes, no credit card needed. Not legal advice. Informational only.
Check your store's Colorado privacy readiness at getregulens.com
Further Reading
Does Your Store Need to Detect a Browser Signal? A State-by-State Guide
Some states require your store to automatically recognize a consumer's opt-out preference through their browser settings, with no click required on your site at all. Here's exactly which states require it.
Four More States Are About to Get Privacy Laws — Here's Your Advance Notice
Alabama, Oklahoma, Louisiana, and Vermont have all signed comprehensive privacy laws into effect between 2027 and 2028. None are enforceable yet, but each is worth understanding well before its clock starts.