Understanding how Colorado privacy laws change your marketing measurement
Marketers need more than a legal summary of the Colorado Privacy Act. Here's what it means for your ad targeting, audience building, and measurement strategy.
Linnea Zielinski · 11 min read
Every time you cross a state line while driving, the speed limit changes, but nobody hands you a new rulebook at the border. That's roughly where marketers find themselves with state data privacy laws right now, and Colorado is one of the states where the "speed limit" changed in ways that directly touch how you collect personal data, build audiences, and measure performance.
For marketing teams, how you build your retargeting pools, what personal data you're allowed to act on, and how much you can trust your platform-reported numbers all depend on staying ahead of laws like the Colorado Privacy Act, both in Colorado and in the growing list of other states following its lead.
Key takeaways
- The Colorado Privacy Act applies to businesses that process the personal data of at least 100,000 Colorado residents a year, or at least 25,000 Colorado residents if they sell personal data or use it for targeted advertising, regardless of where the business itself is headquartered.
- Colorado residents can access personal data, correct personal data, delete personal data, and request a portable copy of the personal data collected about them, plus opt out of the sale of personal data, targeted advertising, and certain automated profiling.
- Sensitive data, including health, biometric, genetic, racial or ethnic, religious, and sexual orientation data, requires opt-in consent before a business can process it.
- Businesses have had to honor universal opt-out mechanisms like Global Privacy Control since July 1, 2024, which means some of your prospecting and retargeting audiences have already shrunk automatically as more browsers and extensions send that universal opt-out signal.
- Standard ad tech practices, like third-party pixel tracking and audience list matching, can count as a sale of personal data under the Colorado Privacy Act's broad definition, even when no money changes hands.
- Colorado is one of roughly 20 states with comprehensive data privacy legislation on the books, so a compliance and targeting strategy built for just one state won't hold up for long as more data privacy laws pass.
- The Colorado Attorney General's office enforces the law, and as platform-level tracking gets more restricted, marketing measurement that doesn't depend on the personal data these laws regulate becomes more reliable, not less.
What is the Colorado Privacy Act?
The Colorado Privacy Act took effect on July 1, 2023, and it's enforced by the Colorado Attorney General's office along with district attorneys around the state, under the broader umbrella of the Colorado Consumer Protection Act. The Colorado Attorney General's office also publishes rules and guidance that spell out how the law applies in practice. The Colorado Privacy Act applies to any business that conducts business in Colorado, or that markets and delivers commercial products or services to Colorado residents, and meets one of two thresholds:
- processing the personal data of at least 100,000 Colorado residents in a calendar year, or
- processing the personal data of at least 25,000 Colorado residents while also deriving revenue, or getting a discount on goods or services, from selling personal data.
That second threshold catches a lot of mid-sized brands off guard. You don't need to be a massive company for the Colorado Privacy Act to apply to you. If your business derives revenue from selling personal data or leans on targeted advertising, and you conduct business that reaches Colorado residents, the lower consumer threshold probably applies, and the Colorado Attorney General can still bring an enforcement action against you.
A few categories of businesses are exempt outright. Financial institutions and lending services already regulated under the Gramm-Leach-Bliley Act don't have to separately comply with the Colorado Privacy Act's data processing rules, and the same goes for entities covered under HIPAA. Employment records and personal data tied to a job applicant also generally fall outside the law, since that personal data gets regulated in an employment context rather than a consumer one.
Consumer rights under the Colorado Privacy Act
Colorado residents get a specific set of rights over their own personal data, and businesses need a real process in place to handle consumer requests when they come in. Here's what the Colorado Privacy Act grants:
- Access: Colorado residents can request that a business provide the personal data it has collected about them.
- Correction: Colorado residents can correct personal data that's inaccurate.
- Deletion: Colorado residents can delete personal data a business holds on them.
- Portability: Colorado residents can request their personal data in a format they can actually use elsewhere. This is the data portability right, and it means the personal data collected about a consumer has to be provided in a readily usable form instead of locked in a proprietary format.
- Opt-out: Colorado residents can opt out of the sale of personal data, targeted advertising, and profiling that has legal or similarly significant effects on them.
Businesses generally have 45 days to respond to a verified consumer request, with a possible 45-day extension for more complex cases. If you're collecting the personal data of Colorado residents at any real scale, it's worth having a documented process for exactly how each of these consumer requests gets routed and fulfilled, especially opt-out requests tied to the sale of personal data or targeted advertising.
What the Colorado Privacy Act requires of businesses
Beyond consumer rights, the Colorado Privacy Act puts a handful of operational requirements directly on the businesses collecting and processing personal data. A meaningful privacy notice needs to clearly explain what personal data you collect and why, which ties back to a principle called purpose specification: you can't collect personal data for one stated reason and then use it for something else entirely. Businesses also need to practice data minimization, meaning they only collect the personal data they actually need, and they have to maintain reasonable security measures to protect against unauthorized access, physical or other intrusion, or unintended disclosure.
For higher-risk data processing activities, like targeted advertising, selling personal data, or processing sensitive data, businesses have to conduct data protection assessments before they start that data processing. Think of a data protection assessment as a formal check on whether the benefit of a given use of personal data outweighs the heightened risk of harm to the consumer, whether that's a privacy harm, a financial or physical injury, or something more reputational. The Colorado Attorney General can request to see these data protection assessments, and businesses that process personal data without one for high-risk data processing activities are exposed if an investigation happens. Data protection assessments generally need to be updated whenever the underlying data processing changes in a meaningful way, not filed once and forgotten.
Sensitive data gets a higher bar
Some categories of personal data need opt-in consent before a business can process them at all, not just an opt-out option. That list includes:
- Racial or ethnic origin and religious beliefs
- Sexual orientation and citizenship status
- Mental or physical health condition, including sex life or sexual behavior
- Genetic or biometric data used to uniquely identify a person
- Personal data belonging to a known child
If your marketing touches any of these categories, even indirectly, you need explicit opt-in consent before processing sensitive data. Brand should take note if their targeting logic tries to predict personal aspects of a consumer, like health or lifestyle interests, from behavior that looks unrelated on the surface. Any data processing activity that starts collecting or processing sensitive data on a wider scale should also trigger a fresh data protection assessment.
Universal opt-out mechanisms, explained
The Colorado Privacy Act also requires businesses to honor universal opt-out mechanisms, and that requirement has been in effect since July 1, 2024. A universal opt-out mechanism, like Global Privacy Control, is a signal a consumer's browser or browser extension sends automatically to every site the consumer visits, telling each one not to sell their personal data or use it for targeted advertising. Once a business detects one of these universal opt-out mechanisms, it has to treat that signal the same as an opt-out request submitted directly. The consumer doesn't have to find your privacy notice at whatever readily accessible location it lives on your site and click an opt-out link. The signal does it for them, everywhere they go.
For marketers, that means some portion of your audience is opting out passively, in the background, without you ever seeing a direct interaction. Your addressable audience for targeted advertising can shrink over time even if nobody visits your privacy policy page.
What counts as a "sale" or "targeted advertising" under the Colorado Privacy Act
This is the part that trips up a lot of marketing teams, because both terms are defined more broadly than most people assume.
Under the Colorado Privacy Act, a sale of personal data isn't limited to a direct cash transaction. A sale of personal data is defined as sharing personal data with a third party in exchange for any valuable consideration, which can include things like ad platform access, audience insights, or other non-monetary benefits. That definition is broad enough to sweep in a lot of standard ad tech, including third-party pixel tracking and certain kinds of audience list matching, even when your team never thought of it as a sale of personal data in the traditional sense.
Targeted advertising is defined similarly broadly. It covers ads displayed to a consumer based on personal data obtained from that consumer's activity over time and across non-affiliated websites or apps, used to predict consumer preferences or personal aspects like an identifiable individual's economic situation, health, or interests. Contextual advertising, meaning ads based only on the content a consumer is currently viewing, isn't included. But most retargeting and lookalike audience strategies rely on exactly the kind of cross-site behavioral data the law is describing.
De-identified data, where a business has removed anything that could reasonably identify a specific person or an identified or identifiable individual, falls outside most of these restrictions. That's one reason aggregated, statistical approaches to marketing data hold up better under laws like this one than approaches built on identifying individuals through unique technical specifications like device or advertising IDs.
How the Colorado Privacy Act affects your ad targeting and audience building
A few practical shifts follow directly from the definitions above:
- Rebuild, don't just react. Retargeting and lookalike audiences built on personal data collected before a consumer opted out may need to be refreshed and rebuilt, not just paused.
- Expect gradual shrinkage. As more browsers and extensions send universal opt-out mechanisms by default, some prospecting pools will shrink over time without any single dramatic drop-off. It's worth checking with your ad tech vendors on how they detect and honor universal opt-out mechanisms today, since not every platform handles this data processing the same way.
- Watch your list-matching vendors. If a vendor is matching your customer list against a platform's user base to build audiences, confirm how that exchange of personal data is being classified, since it may count as a sale of personal data under the Colorado Privacy Act.
- Be careful with inference. If your targeting logic infers anything from sensitive categories, like assuming a health or beauty interest from purchase history, that inference can trigger the opt-in consent requirement even if you never directly collected sensitive data.
- Know your context. The Colorado Privacy Act governs personal data collected in a commercial or individual or household context. Personal data tied to an employment context, like employment records or a job applicant's information, isn't covered by these same consumer rights.
None of this means targeted advertising is off the table in Colorado. It means the audiences you build need a clearer paper trail behind them.
What the Colorado Privacy Act means for your marketing measurement
There's no comprehensive federal law governing personal data privacy yet, so state data privacy laws like the Colorado Privacy Act are setting the pace, and more states are expected to pass their own data privacy laws. That matters for measurement, not just targeting.
Click-based, user-level attribution depends on the exact kind of cross-site data processing these laws restrict. As opt-out rates climb and more consumers rely on universal opt-out mechanisms, the personal data feeding platform-reported conversions gets less complete. Measurement approaches that work at an aggregated, statistical level rather than tracking an identifiable individual don't carry that same exposure, since they're not built on the personal data these data privacy laws regulate in the first place. This is a big part of the reason marketing mix modeling has owned more of the measurement conversation as state privacy laws keep expanding.
Colorado isn't the only state you need to track
If your brand markets nationally, Colorado is just one piece of a much bigger puzzle. Roughly 20 states now have their own comprehensive data privacy legislation, each with its own thresholds, exemptions, and consumer rights. California's law, originally the CCPA and later expanded by the California Privacy Rights Act, was first and remains the most well-known, but Colorado, Virginia, Connecticut, and a growing list of others have each written their own version, and the details don't always match.
A few practical exemptions are worth knowing across most of these laws. Entities already regulated under federal laws like the Gramm-Leach-Bliley Act, which covers financial or lending services, are typically exempt from state data privacy laws like the Colorado Privacy Act, and the same goes for personal data covered under HIPAA. Employment records and job applicant data usually fall outside these consumer privacy laws entirely, since that personal data gets regulated separately.
The bigger point for marketers is that a state-by-state compliance and targeting strategy doesn't scale well. If you're building your approach around individual state rules, you'll always be catching up to whichever state passes something new next.
Where Prescient comes in
As more states pass laws like the Colorado Privacy Act, the personal data marketers have relied on for targeting and measurement keeps getting harder to collect and less complete once you have it. Prescient's marketing mix modeling doesn't depend on the kind of individually identifiable personal data these laws restrict. Instead, it works with your aggregated spend and performance data to show you what's actually driving revenue across your marketing mix.
That means your measurement doesn't break every time a new state passes a privacy law or a browser update expands opt-out defaults. If you want to see how that works, book a demo and we'll walk you through it, or you can check out our latest release here.
FAQs
Does the Colorado Privacy Act apply to businesses outside Colorado?
Yes. The Colorado Privacy Act applies based on whether a business conducts business in Colorado, or markets and delivers commercial products to Colorado residents, not where the business itself is headquartered. A company based anywhere in the country can fall under the law if it meets the consumer thresholds and reaches Colorado residents.
What's the difference between the Colorado Privacy Act and the California Consumer Privacy Act?
Both laws give consumers similar rights, like the ability to access personal data, delete personal data, correct personal data, and opt out of the sale of personal data and targeted advertising, but the thresholds, exemptions, and enforcement mechanisms differ. California's law also gives consumers a private right of action in certain data breach cases, while Colorado's law is enforced solely by the state Attorney General and district attorneys.
What happens if a business doesn't comply with the Colorado Privacy Act?
The Colorado Attorney General's office and district attorneys can investigate and bring enforcement actions, with penalties that can reach up to $20,000 per violation. The Colorado Attorney General has already shown willingness to look closely at how businesses handle sensitive data and universal opt-out mechanisms specifically. Businesses previously had a 60-day cure period to fix violations before facing enforcement, but that cure period expired at the start of 2025, so businesses can now face enforcement from the Colorado Attorney General without a chance to correct the issue first.
Do small businesses have to comply with the Colorado Privacy Act?
It depends on how much personal data they process, not their overall size or revenue. A small business that processes the personal data of at least 25,000 Colorado consumers while selling personal data or using it for targeted advertising can still fall under the law, even if it has a small team and modest revenue.
The Halo
Exclusive insights, every week.
Subscribe to The Halo for sharper marketing thinking.
You're subscribed to The Halo!
Quick question (optional): How familiar are you with MMM?
Thanks for sharing! Enjoy The Halo.
Keep reading
View allWhat is a tracking pixel audit (and how do you run one)?
Read articlePixels vs. cookies: What they are, how they differ, and what's changing
Read article
What California's data privacy law means for your marketing data
Read article
What is privacy-preserving ad measurement?
Read articleBest identity graph for cross-device tracking in martech
Read article
What cross-device attribution is and why it matters
Read article