Skip to main content
CPA Penalties Started January 1, 2025: What ChangedLaws and Regulations
4 min readFor Privacy Officers

CPA Penalties Started January 1, 2025: What Changed

The Colorado Privacy Act (CPA) stopped offering second chances on January 1, 2025. The 60-day cure period that allowed businesses to fix violations before facing fines is gone. Now, every enforcement letter from the Colorado Attorney General can include penalties from the first contact.

This change is significant. Combined with three major rule expansions since the CPA launched in July 2023, Colorado now has a privacy regime that punishes non-compliance more severely than most states while expanding what counts as a violation.

Key Changes Since the CPA Launched

The grace period ended. Before January 1, 2025, the Attorney General had to warn you and give you 60 days to fix a violation before imposing fines. That cushion is gone. The first letter you receive can include penalties.

Three rule expansions went live. Colorado added sensitive data categories and new protected populations quickly:

  • August 7, 2024: Biological and neural data joined the sensitive data list under HB 24-1058, requiring opt-in consent before processing.
  • July 1, 2025: Biometric identifier rules took effect under HB 24-1130, requiring consent before selling or sharing biometrics and annual retention reviews. These rules apply to all businesses, regardless of size.
  • October 1, 2025: Minors' protections under SB 24-041 banned targeted advertising, sale, and profiling of under-18s without consent, and prohibited engagement-extending design features. No size threshold applies.

GPC became mandatory. Global Privacy Control signals have been required since July 1, 2024. If your Consent Management Platform doesn't detect and honor GPC, every GPC-enabled Colorado visitor you track after they've signaled opt-out is a violation you're accumulating.

A sensitive data sale ban is coming. Starting August 12, 2026, selling sensitive data will require consent under all circumstances, not just when you're the original collector. SB 25-276 closes the resale loophole.

Key Findings

Violations now carry immediate financial exposure. The CPA allows civil penalties up to $20,000 per violation, or up to $50,000 if the violation targets an elderly person. Without a cure period, there's no warning shot. A misconfigured tracking pixel that fires before consent for 1,000 Colorado visitors isn't one mistake; it's potentially 1,000 violations at $20,000 each.

The thresholds haven't changed, but the rules underneath them have. You're still covered if you process personal data from 100,000 or more Colorado consumers annually, or 25,000 if you derive revenue from selling personal data. What's different: the biometrics and minors rules apply regardless of those thresholds, and the sensitive data list now includes categories that didn't exist when the CPA launched.

GPC compliance is testable and auditable. Unlike vague "reasonable security" obligations, GPC support is binary: your CMP either honors the signal or it doesn't. The Attorney General can test it with a browser extension. If your banner keeps loading ad pixels after a GPC signal fires, you're non-compliant in a way that's easy to prove.

Opinion letters offer a unique compliance path. Colorado allows businesses to request formal guidance from the Attorney General. Good-faith reliance on an opinion letter is an affirmative defense in enforcement. No other state has built out this mechanism at the same scale.

Consent records are now your first line of defense. Since you can't rely on a cure period to patch violations after the fact, your ability to demonstrate compliance depends on timestamped consent logs, versioned banner configurations, and documented GPC handling. The CPA explicitly requires controllers to demonstrate compliance.

What This Means for Your Team

Your compliance posture needs to shift from reactive to preventive. The cure period allowed you to treat the first enforcement letter as a free audit; you could fix what the Attorney General flagged and walk away. That safety net is gone.

You're now operating in a regime where every Colorado visitor who doesn't receive Valid Consent handling is a potential $20,000 liability. The math scales badly: a tracking pixel misconfiguration that affects 5,000 Colorado visitors in a month is a $100 million exposure on paper. Enforcement doesn't run the full multiplication in practice, but settlements still hurt, and the per-violation count gives the Attorney General leverage.

The biometrics and minors rules add complexity because they apply universally. Even if you're below the 100,000-consumer threshold, if you're processing biometric identifiers or targeting ads to minors, you're covered for those specific activities.

GPC creates a bright-line test. Your banner either honors the signal or it doesn't. There's no gray area, and testing it requires nothing more than a browser extension and a network inspector. If you're ignoring GPC, assume the Attorney General can prove it.

Action Items by Priority

1. Audit your GPC implementation immediately. Test with a GPC-enabled browser. Verify that third-party scripts and pixels don't fire after the signal is detected. If your CMP doesn't support GPC, replace it. This is the easiest violation to prove and the hardest to defend.

2. Review your sensitive data inventory. Biological and neural data are now on the list. If you're processing health metrics, genetic data, or biometric identifiers, confirm you're collecting opt-in consent before processing starts. Document the consent flow.

3. Examine your minors' data handling. If your site attracts users under 18, verify you're not serving them Behavioural Advertising, selling their data, or using engagement-extending design features without consent. The minors rules carry no size threshold.

4. Document your consent records. You need timestamped logs, versioned banner configurations, and a working intake for data subject requests. The CPA gives you 45 days to respond to access, correction, deletion, and portability requests. If you can't produce records, you can't demonstrate compliance.

5. Consider requesting an opinion letter if you're uncertain. Colorado's opinion letter process is live as of January 30, 2025. If you're genuinely unclear whether a practice complies, ask. Good-faith reliance is a defense.

Colorado Privacy Act text

You Might Also Like