Artifact GuideUSCalifornia vs Colorado

CPRA vs Colorado Privacy Act

California and Colorado controls can share evidence, but the laws have different scope tests, actor names, sensitive-data rules, opt-outs, and enforcement routes.

Run both scope tests first, then compare the same data flow, purpose, recipient, consumer right, and control under each law.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
11

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The CCPA as amended by the CPRA applies to qualifying businesses doing business in California. The (CPA), effective July 1, 2023, applies to qualifying controllers that conduct business in Colorado or target commercial products or services to Colorado residents. One organization may be covered by both, one, or neither. Keep a separate legal finding for each state.

Side-by-side comparison

CPRA vs Colorado Privacy Act

Apply every row to the same entity and processing activity. Coverage under one law does not establish coverage under the other.

Review all sources
First framework
California CCPA as amended by CPRA

California regulates qualifying businesses and defines recipient roles, sale, sharing, consumer rights, and sensitive-personal-information limits within the CCPA.

Second framework
Colorado Privacy Act

Colorado regulates qualifying controllers and processors and has separate consent, opt-out, appeal, contract, and assessment rules.

Comparison row 1

Scope thresholds

California CCPA as amended by CPRA

A qualifying for-profit entity doing business in California is a business if it meets a statutory route: annual gross revenue above the adjusted threshold; buying, selling, or sharing personal information of 100,000 or more consumers or households; or deriving at least 50% of annual revenue from selling or sharing consumers' personal information. Other affiliate, joint-venture, and voluntary-certification routes can apply.

Colorado Privacy Act

The CPA covers a controller that conducts business in Colorado or targets commercial products or services to Colorado residents and controls or processes data of at least 100,000 Colorado consumers in a calendar year, or at least 25,000 consumers while receiving revenue or a discount from selling personal data. Since July 1, 2025, it also covers a controller that processes any amount of biometric identifiers or biometric data, limited to that processing if the controller does not meet a general threshold. Nonprofits can be covered.

Operational implication

Calculate each threshold from its own definitions and period, and test Colorado's separate biometric-data route. Colorado's lower general route does not require that 50% of revenue come from sales, and California's revenue route does not require a consumer count.

Comparison row 2

Who is a consumer

California CCPA as amended by CPRA

California's consumer definition is tied to California residency and is not limited to an individual acting only in a personal or household context. Specific statutory exemptions still require analysis.

Colorado Privacy Act

A Colorado consumer is a Colorado resident acting only in an individual or household context. The definition excludes a person acting in a commercial or employment context, and the CPA generally excludes data maintained for employment-record purposes. Separate biometric provisions nevertheless regulate specified employer processing of employee and prospective-employee biometric identifiers.

Operational implication

Do not exclude workforce or business-contact data from California merely because Colorado generally excludes that context, and assess Colorado's separate biometric rules where applicable.

Comparison row 3

Consumer rights and appeals

California CCPA as amended by CPRA

California provides rights to know or access, delete, correct, opt out of sale or sharing, limit certain uses and disclosures of sensitive personal information, and receive non-discriminatory treatment. Response and verification rules depend on the request.

Colorado Privacy Act

Colorado provides access, correction, deletion, portability, and opt-outs from sale, targeted advertising, and specified profiling. A controller must offer an internal appeal process when it refuses to act on a request.

Operational implication

A common request portal needs state-specific request types, exceptions, authentication steps, response text, and a Colorado appeal branch.

Comparison row 4

Sale, advertising, and opt-out signals

California CCPA as amended by CPRA

California sale includes specified disclosures for monetary or other valuable consideration. Sharing separately covers disclosures for cross-context behavioral advertising whether or not money or other valuable consideration is exchanged. Covered businesses must process applicable opt-out preference signals under the regulations.

Colorado Privacy Act

Colorado sale and targeted advertising are separate opt-out categories under Colorado definitions. Since July 1, 2024, controllers must accept recognized universal opt-out mechanisms for sale and targeted advertising.

Operational implication

Send a signal to each state's legal classifier. A disclosure that is not a Colorado sale may still be Colorado targeted advertising, California sharing, or a California sale.

Comparison row 5

Sensitive data

California CCPA as amended by CPRA

California defines sensitive personal information and lets consumers limit uses and disclosures outside specified permitted purposes. Sensitive personal information processed without the purpose of inferring characteristics is not subject to the right to limit, though other CCPA duties still apply.

Colorado Privacy Act

Colorado requires consent before processing sensitive data. Sensitive data includes specified revealing data, biometric data used for identification, and personal data from a known child; child data must be processed with parental consent as required by COPPA.

Operational implication

Do not use one blanket sensitive-data rule. Colorado asks whether consent is required before processing; California asks whether the category and purpose trigger the right to limit.

Comparison row 6

Contracts and assessments

California CCPA as amended by CPRA

California requires role-specific contract terms for disclosures to service providers, contractors, and third parties. Its risk-assessment and cybersecurity-audit regulations apply only when their separate triggers and phase-in rules are met.

Colorado Privacy Act

Colorado controller-processor contracts must govern processing instructions, purpose, data type, duration, rights and duties, confidentiality, deletion or return, audits, and subcontractors. Controllers must conduct data protection assessments for processing presenting a heightened risk of harm.

Operational implication

A shared vendor schedule or assessment can supply facts, but each state conclusion must identify its own trigger and required terms.

Comparison row 7

Enforcement

California CCPA as amended by CPRA

The California Privacy Protection Agency can bring administrative actions, and the California Attorney General can bring civil actions. California also has a limited private cause of action for specified security incidents, not for every statutory violation.

Colorado Privacy Act

The Colorado Attorney General and district attorneys enforce the CPA through the Colorado Consumer Protection Act. The CPA does not create a private right of action.

Operational implication

Keep regulator and incident-response paths state-specific. Consumer complaints and control failures may reach different authorities and remedies.

Practical decision rule

How to use the California-Colorado comparison

  • Make separate scope findings before designing a shared control.
  • Reuse inventories, vendors, request infrastructure, and testing evidence only after mapping both legal definitions.
  • Keep state-specific branches for sensitive data, appeals, opt-out mechanisms, recipient contracts, assessments, exemptions, and enforcement.
Section 1

What should a multistate team decide first?

Start with scope. California generally uses a for-profit business test with revenue, data-volume, and sale-or-sharing revenue routes. Colorado can cover nonprofits and has no standalone revenue threshold; its two general routes depend on the number of Colorado consumers whose data is controlled or processed, with a sale-related condition for the lower threshold. Since July 1, 2025, Colorado also covers a controller's processing of any amount of biometric identifiers or biometric data, limited to that processing if the controller does not meet a general threshold.

If both laws apply, classify the same processing under each law. California distinguishes sale from sharing for cross-context behavioral advertising. Colorado separately regulates sale and targeted advertising. The terms overlap, but their definitions and exceptions are not identical.

  • Count the people and households specified by each law; do not copy one state's threshold worksheet into the other.
  • Separate consumer data from employment and commercial-contact data because Colorado excludes those contexts from its consumer definition.
  • Classify the organization and each recipient under the correct roles: business, service provider, contractor, or third party in California; controller or processor in Colorado.
  • Map sale, sharing, targeted advertising, profiling, sensitive data, and secondary uses separately.
  • Record exemptions at the entity, data, and processing level instead of assuming one exemption has the same reach in both states.
Section 2

Which controls can be shared, and which need state-specific handling?

A single inventory, request portal, vendor register, assessment library, and opt-out service can support both laws. Reuse is defensible only when the control meets both legal definitions, deadlines, exceptions, and evidence requirements.

Keep state-specific branches where the laws diverge. Colorado requires consent before processing sensitive data and gives consumers an appeal route when a controller refuses a request. California instead provides a conditional right to limit certain uses and disclosures of sensitive personal information and uses its own request, opt-out-signal, and recipient-contract rules.

  • Rights workflow: support access, correction, deletion, portability, and opt-out, then add the Colorado appeal process and each state's verification or authentication rules.
  • Advertising workflow: honor California opt-out preference signals for sale or sharing and Colorado-recognized universal opt-out mechanisms for sale or targeted advertising.
  • Sensitive-data workflow: obtain Colorado consent where required; in California, determine whether the use triggers notice and the right to limit.
  • Contract workflow: maintain a common data-processing schedule, then include the terms required for the recipient's role under each statute and regulation.
  • Assessment workflow: keep processing-level facts reusable, but apply Colorado's data-protection-assessment triggers separately from California's risk-assessment rules.
  • Evidence: retain the legal classification, signal receipt, user-facing response, downstream propagation, exception, test result, owner, and review date.
Primary sources

References and citations

Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.