Colorado Privacy Act (CPA) Compliance: Handle Data Subject Requests on the 45-Day Deadline
The Colorado Privacy Act gives Colorado residents the right to access, correct, delete, and port their personal data, opt out of its sale and targeted advertising, and appeal a denial. A verified request starts a 45-day clock, and the data is usually spread across your systems. Obtainer finds where a person's data lives, compiles one reviewable manifest, drafts the response, and tracks the deadline so it does not slip.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The Colorado Privacy Act (CPA) took effect on July 1, 2023, and applies to a controller that conducts business in Colorado or targets Colorado residents and meets either threshold in a calendar year: it controls or processes the personal data of 100,000 or more consumers, or it derives revenue or a discount from selling personal data and controls or processes the data of 25,000 or more consumers. Colorado consumers can access, correct, delete, and obtain a portable copy of their personal data, opt out of the sale of their data, targeted advertising, and certain profiling, and appeal if you deny a request. You generally must respond within 45 days, extendable once by another 45 days with notice. Since July 1, 2024, controllers must honor a universal opt-out mechanism such as Global Privacy Control. The Colorado Attorney General and district attorneys enforce the law, with penalties of up to $20,000 per violation under the Colorado Consumer Protection Act; the 60-day cure period ended on January 1, 2025, so the Attorney General now has discretion to enforce without offering a chance to fix the problem first. Obtainer handles the operational side of a CPA request: it intakes the request, discovers where the person's data lives across your systems, compiles a source-system manifest, drafts a deadline-safe response, and tracks the 45-day clock. Nothing is disclosed automatically; a human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so whether the CPA applies to you and how you handle appeals stay with your team. Self-serve from $49/mo.
Why it fits
Colorado businesses, plus out-of-state SaaS, ecommerce, adtech, and B2B firms that target Colorado residents at the CPA thresholds, that want discovery, drafting, appeal handling, and 45-day deadline tracking for a Colorado Privacy Act request in one place.
Know if the thresholds pull you in
The CPA uses OR logic: you are covered if you process the data of 100,000 or more Colorado consumers in a year, or if you sell personal data and process the data of 25,000 or more. There is no revenue floor. If you run analytics, targeted ads, or a sizeable consumer product in Colorado, assume you should be ready to answer a request.
45 days to respond, plus an appeal path
Colorado residents can access, correct, delete, and port their data, and opt out of sale, targeted advertising, and profiling. If you deny a request, they can appeal, and you must have a process for it. You have 45 days from a verified request, extendable once by 45 days. Obtainer starts the countdown, finds the data, and drafts the reply so both the response and any appeal stay on schedule.
Discovery across your stack, priced for you
A single consumer's data is spread across your production database, warehouse, Stripe, support desk, and email. Obtainer surfaces where it lives and compiles one manifest, and it captures universal opt-out signals in the intake so honoring them is not a manual step. Self-serve from $49/mo, with no five-figure floor before your first request.
More use cases
Related features
Questions
Common questions about this
Who must comply with the Colorado Privacy Act?
A controller that conducts business in Colorado or targets Colorado residents and meets either threshold in a calendar year: it processes the personal data of 100,000 or more consumers, or it sells personal data and processes the data of 25,000 or more consumers. There is no revenue threshold. Certain entities and data governed by other laws, such as HIPAA-covered data, are exempt.
What are the consumer rights under the Colorado Privacy Act?
Colorado residents can confirm whether you process their personal data and access it, correct inaccuracies, delete it, and obtain a portable copy. They can opt out of the sale of their data, targeted advertising, and certain profiling, and they can appeal if you deny a request. You must respond within 45 days and provide a clear way to appeal a refusal.
What is the penalty for violating the Colorado Privacy Act?
Violations are enforced by the Colorado Attorney General and district attorneys as deceptive trade practices under the Colorado Consumer Protection Act, with penalties of up to $20,000 per violation. The 60-day cure period ended on January 1, 2025, so the Attorney General now has discretion to pursue penalties without first offering a chance to fix the issue. There is no private right of action.
Does the Colorado Privacy Act require honoring universal opt-out signals?
Yes. Since July 1, 2024, controllers must honor a recognized universal opt-out mechanism, such as Global Privacy Control, as a valid request to opt out of the sale of personal data and targeted advertising. That means a browser-level signal counts as an opt-out, and your intake process needs to detect and act on it rather than wait for a form submission.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.