What to Know About New Data Privacy Laws in California and Colorado
California and Colorado have established two of the most influential state privacy frameworks in the United States. Their laws give residents greater control over personal information, limit certain forms of targeted advertising, and require businesses to explain how data is collected and used.
The rules matter beyond state borders. Companies that operate websites, mobile apps, online stores, advertising platforms, or cloud services may need to comply when they process information about California or Colorado residents, even if the business itself is located elsewhere.
For readers following technology news, these laws are part of a larger shift toward consumer privacy, data minimization, and stronger accountability for digital services. The details differ between the states, so businesses and consumers should understand where the protections overlap and where they do not.
The Main Laws And Their Timelines
California’s privacy framework began with the California Consumer Privacy Act, or CCPA, which took effect in 2020. The California Privacy Rights Act, commonly called the CPRA, expanded and amended those protections beginning in 2023. The framework is enforced by the California Privacy Protection Agency and the state attorney general.
Colorado’s law is the Colorado Privacy Act, or CPA. It took effect on July 1, 2023, with rules administered primarily by the Colorado attorney general. Colorado’s regulations provide detailed requirements for consent, universal opt-out signals, profiling, and data protection assessments.
Both laws apply to certain businesses that meet revenue, data-processing, or business-model thresholds. They do not automatically cover every small business, nonprofit, or public agency. However, a company may still be covered if it processes enough consumer data or earns significant income from selling or sharing personal information.
Who And What The Laws Protect
The California law protects “consumers,” generally meaning California residents acting in an individual or household context. It covers personal information that identifies, relates to, describes, or could reasonably be linked with a person or household. This can include browsing activity, purchase records, device identifiers, approximate location, and inferred interests.
Colorado uses the term “consumer” in a similar way, but its law generally excludes people acting in an employment or commercial context. The CPA applies to personal data connected to identified or identifiable individuals and recognizes that information can be collected directly or obtained from another source.
Both frameworks address sensitive information, though the categories and terminology are not identical. Health details, precise geolocation, biometric identifiers, racial or ethnic information, religious beliefs, and account credentials can receive heightened protection. Data about children and teenagers also triggers additional obligations.
Scientific and health-related data deserves particular attention because privacy risks can arise even when information is not obviously identifying. Research organizations and digital health companies should review guidance from reliable science coverage while assessing how data is collected, combined, and retained.
Consumer Rights At A Glance
California and Colorado residents can request access to personal data, ask for corrections, and seek deletion in many situations. Businesses must provide a method for submitting requests and generally must verify the requester’s identity without demanding unnecessary information.
California gives consumers the right to opt out of the sale or sharing of personal information. “Sharing” has a specific significance under the CCPA and can include using data for cross-context behavioral advertising. California also recognizes a right to limit certain uses of sensitive personal information.
Colorado gives consumers the right to opt out of targeted advertising, the sale of personal data, and certain profiling that produces legal or similarly significant effects. Both states restrict retaliation or discriminatory treatment when a person exercises privacy rights, although businesses may offer legitimate financial incentives under specific conditions.
| Area | California | Colorado |
|---|---|---|
| Core law | CCPA, as amended by CPRA | Colorado Privacy Act |
| Effective framework | 2020, with major CPRA changes in 2023 | July 1, 2023 |
| Key opt-outs | Sale, sharing, and some sensitive-data uses | Sale, targeted advertising, and certain profiling |
| Sensitive data | Sensitive personal information receives special controls | Sensitive data generally requires consent |
| Universal opt-out | Recognizes signals such as Global Privacy Control | Requires support for recognized universal opt-out mechanisms |
| Enforcement | California attorney general and California Privacy Protection Agency | Colorado attorney general |
| Access and deletion | Available, with statutory exceptions | Available, with statutory exceptions |
Business Duties And Compliance Controls
Covered companies need clear privacy notices that explain the categories of personal data collected, the purposes for processing, retention practices, and disclosures to service providers or other third parties. Notices should be understandable and updated when processing activities materially change.
Organizations must also establish procedures for handling consumer requests. California generally gives businesses 45 days to respond, with a possible extension in certain circumstances. Colorado generally uses a 45-day response period as well, with an additional extension when reasonably necessary. Companies should document verification, request handling, and appeal processes.
The laws also affect contracts with vendors, advertising partners, analytics providers, and cloud platforms. A business should know whether a provider acts as a service provider, contractor, or processor, and contracts should restrict the provider from using personal information for unrelated purposes.
Risk assessments are increasingly important. Companies handling health information, precise location, children’s data, profiling systems, or large-scale behavioral data should examine whether processing creates an unreasonable risk to individuals. Strong access controls, retention limits, encryption, and incident response plans support both compliance and sound cybersecurity.
Opt-Out Tools And Consent Requirements
California consumers may use an opt-out link or preference center to stop the sale or sharing of personal information. The state’s recognition of Global Privacy Control allows a browser or device signal to communicate a consumer’s opt-out choice. Businesses must avoid weakening that choice through confusing design or repeated requests.
Colorado also requires covered organizations to recognize a universal opt-out mechanism. The state’s rules provide detailed expectations for how businesses detect and honor such signals. A company cannot treat a valid opt-out as permission to continue targeted advertising through another technical route.
Consent is especially important for Colorado sensitive data. A business generally needs affirmative consent before processing sensitive data, and consent must be specific, informed, and freely given. Dark patterns, preselected boxes, and bundled choices can create legal risk.
California’s approach differs in some areas. Consumers can limit certain uses of sensitive personal information, while sale or sharing involving minors may require affirmative authorization. Businesses that serve children, teenagers, or families should use age-appropriate notices and carefully designed consent procedures.
What Consumers Should Watch For
People in both states should read privacy notices before joining loyalty programs, installing apps, or connecting accounts across services. A free service may rely on advertising, profiling, or data sharing, and the privacy notice should explain those practices in understandable terms.
Consumers can look for “Do Not Sell or Share My Personal Information” controls in California and privacy preference tools available to Colorado residents. Browser-based signals can also help communicate choices, although users should confirm that the setting is enabled and recognized by the websites they visit.
When submitting an access or deletion request, use the company’s official privacy channel and keep a copy of the request. Businesses may need to verify identity, and some records may be retained to meet legal, security, accounting, or transaction-related obligations.
Privacy rights are one part of a broader digital policy landscape covered across Ub24News. As more states adopt their own frameworks, residents may see different rights and procedures depending on where they live and which company handles their information.
Practical Steps For Businesses
- Map the personal and sensitive data collected through websites, apps, stores, and internal systems.
- Review whether revenue, data volume, advertising, or business activities trigger California or Colorado coverage.
- Add clear request, appeal, deletion, correction, and opt-out procedures to privacy operations.
- Update vendor agreements, retention schedules, consent flows, and universal opt-out signal handling.
- Train customer service, marketing, engineering, and security teams on privacy obligations.
The safest approach is to treat compliance as an ongoing program rather than a one-time website update. Businesses should monitor regulatory guidance, test privacy controls, review new products before launch, and preserve evidence showing how consumer requests and opt-out choices were handled.
Consumers can begin by checking account privacy settings, enabling an appropriate universal opt-out signal, and submitting requests directly to companies that hold their information. Staying informed through reliable current news coverage can also help track enforcement actions and future changes in state privacy policy.