| Scope thresholds | A qualifying for-profit entity doing business in California is a business if it meets a statutory route: annual gross revenue above the adjusted threshold; buying, selling, or sharing personal information of 100,000 or more consumers or households; or deriving at least 50% of annual revenue from selling or sharing consumers' personal information. Other affiliate, joint-venture, and voluntary-certification routes can apply. | The CPA covers a controller that conducts business in Colorado or targets commercial products or services to Colorado residents and controls or processes data of at least 100,000 Colorado consumers in a calendar year, or at least 25,000 consumers while receiving revenue or a discount from selling personal data. Since July 1, 2025, it also covers a controller that processes any amount of biometric identifiers or biometric data, limited to that processing if the controller does not meet a general threshold. Nonprofits can be covered. | Calculate each threshold from its own definitions and period, and test Colorado's separate biometric-data route. Colorado's lower general route does not require that 50% of revenue come from sales, and California's revenue route does not require a consumer count. |
|---|
| Who is a consumer | California's consumer definition is tied to California residency and is not limited to an individual acting only in a personal or household context. Specific statutory exemptions still require analysis. | A Colorado consumer is a Colorado resident acting only in an individual or household context. The definition excludes a person acting in a commercial or employment context, and the CPA generally excludes data maintained for employment-record purposes. Separate biometric provisions nevertheless regulate specified employer processing of employee and prospective-employee biometric identifiers. | Do not exclude workforce or business-contact data from California merely because Colorado generally excludes that context, and assess Colorado's separate biometric rules where applicable. |
|---|
| Consumer rights and appeals | California provides rights to know or access, delete, correct, opt out of sale or sharing, limit certain uses and disclosures of sensitive personal information, and receive non-discriminatory treatment. Response and verification rules depend on the request. | Colorado provides access, correction, deletion, portability, and opt-outs from sale, targeted advertising, and specified profiling. A controller must offer an internal appeal process when it refuses to act on a request. | A common request portal needs state-specific request types, exceptions, authentication steps, response text, and a Colorado appeal branch. |
|---|
| Sale, advertising, and opt-out signals | California sale includes specified disclosures for monetary or other valuable consideration. Sharing separately covers disclosures for cross-context behavioral advertising whether or not money or other valuable consideration is exchanged. Covered businesses must process applicable opt-out preference signals under the regulations. | Colorado sale and targeted advertising are separate opt-out categories under Colorado definitions. Since July 1, 2024, controllers must accept recognized universal opt-out mechanisms for sale and targeted advertising. | Send a signal to each state's legal classifier. A disclosure that is not a Colorado sale may still be Colorado targeted advertising, California sharing, or a California sale. |
|---|
| Sensitive data | California defines sensitive personal information and lets consumers limit uses and disclosures outside specified permitted purposes. Sensitive personal information processed without the purpose of inferring characteristics is not subject to the right to limit, though other CCPA duties still apply. | Colorado requires consent before processing sensitive data. Sensitive data includes specified revealing data, biometric data used for identification, and personal data from a known child; child data must be processed with parental consent as required by COPPA. | Do not use one blanket sensitive-data rule. Colorado asks whether consent is required before processing; California asks whether the category and purpose trigger the right to limit. |
|---|
| Contracts and assessments | California requires role-specific contract terms for disclosures to service providers, contractors, and third parties. Its risk-assessment and cybersecurity-audit regulations apply only when their separate triggers and phase-in rules are met. | Colorado controller-processor contracts must govern processing instructions, purpose, data type, duration, rights and duties, confidentiality, deletion or return, audits, and subcontractors. Controllers must conduct data protection assessments for processing presenting a heightened risk of harm. | A shared vendor schedule or assessment can supply facts, but each state conclusion must identify its own trigger and required terms. |
|---|
| Enforcement | The California Privacy Protection Agency can bring administrative actions, and the California Attorney General can bring civil actions. California also has a limited private cause of action for specified security incidents, not for every statutory violation. | The Colorado Attorney General and district attorneys enforce the CPA through the Colorado Consumer Protection Act. The CPA does not create a private right of action. | Keep regulator and incident-response paths state-specific. Consumer complaints and control failures may reach different authorities and remedies. |
|---|