Monday, July 20, 2026 Denver, CO
City Desk
Denver
Legal & Finance

A Plain-English Compliance Checklist for Denver Businesses Under Colorado's Data Privacy Law

The cure period has changed. The AG is watching. And your email list may have already put you in scope.

Portrait of Sarah Okonkwo
Legal & Finance Editor ·
15 min read
Share
Colorado data privacy law compliance checklist for Denver small business owners and entrepreneurs
Photo: CityDesk

The cure period has changed. The AG is watching. And your email list may have already put you in scope.


Most Denver small business owners who’ve heard of the Colorado Privacy Act assume it’s someone else’s problem. A rule written for Amazon warehouses and Silicon Valley data brokers, not a breakfast spot on Colfax or a fitness studio in Capitol Hill. That assumption is now genuinely risky.

The CPA took effect July 1, 2023. The Colorado Attorney General’s final enforcement rules kicked in July 1, 2024. And the automatic 60-day cure period—the grace window that gave businesses caught in violation a chance to fix the problem before penalties attached—has ended. (CityDesk Denver is confirming the precise statutory sunset date against CPA §6-1-1309; this article will be updated when that verification is complete.)

The AG’s office now has discretion over whether to extend any correction window at all. For a law that carries penalties up to $20,000 per violation per consumer, that shift matters. A lot.

This is a walkthrough, not a law firm memo. It’s written for the Cherry Creek boutique owner who uses Klaviyo for email and Meta Pixel for retargeting, the Five Points salon running a text-message loyalty program, and the Capitol Hill yoga studio on Mindbody with 3,000 members and a growing waitlist. If you collect customer data—and you do—read this before someone else flags the problem for you.


Step 1: Figure Out Whether the CPA Covers Your Business

The CPA applies to legal entities that conduct business in Colorado or produce products or services intentionally targeted to Colorado residents, and that meet either of two thresholds during a calendar year:

Threshold A: Process the personal data of 100,000 or more Colorado consumers.

Threshold B: Process the personal data of 25,000 or more Colorado consumers and derive revenue or receive a discount on goods or services from the sale of that personal data.

The second threshold is where most Denver small business owners get tripped up, because the CPA’s definition of “sale of data” is broader than the plain meaning of the word.

Under the CPA, a sale includes the exchange of personal data for monetary or other valuable consideration. That language matters for ad tech. If your website runs Meta Pixel with retargeting or conversion tracking enabled, you’re sharing customer behavioral data with Meta. Meta provides you a valuable service in return—targeted advertising. Whether that exchange qualifies as a “sale” under the CPA is genuinely unsettled and being applied case by case. Attorneys advising Denver businesses on this question consistently recommend getting a professional read rather than assuming you’re out of scope. The same question applies to Google Analytics with remarketing features active. My honest read: if you’re running retargeting and you have 25,000-plus contacts, you should not be assuming you’re exempt.

A Denver restaurant with 27,000 email subscribers in Mailchimp, a Facebook Pixel on its website, and remarketing campaigns running through Google Ads may already be covered under Threshold B. It’s never thought of itself as a data company. Colorado law disagrees.

To figure out where you stand: pull up your Mailchimp or Klaviyo dashboard right now and check your total contact count. Above 100,000, you’re almost certainly covered under Threshold A—read the rest of this as a compliance requirement. Between 25,000 and 100,000 with Meta Pixel or Google remarketing running, you may be covered under Threshold B—consult an attorney before assuming otherwise. Below 25,000 with no ad-tech data sharing, you may not be covered today. But check quarterly. A loyalty app or active promotional campaign can push you over faster than you’d expect.

Colorado nonprofits, government entities, and data regulated under HIPAA are carved out of the CPA. Many Denver nonprofits running email programs don’t realize they’re off the hook. Worth knowing: the nonprofit exemption covers the organization, not every category of data it touches. If a nonprofit runs a for-profit subsidiary or shares data outside its core charitable function, the exemption gets complicated. When in doubt, get a human to look at it.


Step 2: Identify Which Data You’re Actually Collecting and From How Many People

Before you can fix anything, you need an honest inventory of what you’re holding and where it lives. This step feels tedious. It’s also the one that surprises most business owners.

The CPA defines personal data as any information that is linked or reasonably linkable to an identified or identifiable individual. Name and email are obvious. Phone numbers collected for a text-message loyalty program, IP addresses captured by your website analytics, purchase histories from your POS system, and device identifiers collected through a branded app all count.

Denver businesses accumulate covered data faster than they realize. A coffee shop on Colfax with a branded loyalty app that’s been live for three years—between registered users, trial accounts, and email signups collected at the counter—might have 26,000 members in the system. The owner thinks of the app as a marketing tool. Colorado law thinks of it as a database of 26,000 consumers’ personal data.

Or a Cherry Creek women’s boutique that installed Meta Pixel two years ago when it launched online sales. Thirty thousand email subscribers, monthly Facebook retargeting campaigns, pixel tracking product views and cart activity. Under the CPA’s possible reading of ad-tech data sharing as a “sale,” the boutique may be covered under Threshold B even though its primary business is selling clothes.

A Capitol Hill yoga studio using Mindbody for class scheduling collects names, email addresses, payment information, class attendance records, and—if members use the GPS check-in feature—precise geolocation data. That last category matters more than most studio owners realize.

The CPA identifies certain categories of personal data as sensitive, and sensitive data triggers a higher standard: opt-in consent, not just disclosure. Sensitive categories include health and medical data, biometric data used for identification, precise geolocation, children’s data, and data related to racial or ethnic origin, citizenship status, and sexual orientation. Cannabis dispensaries using biometric check-in systems—fingerprint scanners at the point of entry—are collecting biometric data and need opt-in consent before doing so. Medical spas collecting health intake forms electronically are dealing with health data. Fitness apps or delivery services using GPS are capturing precise geolocation. If your business touches any of these categories, your compliance requirements are more demanding than the baseline. No exceptions, and no gray area.

Take 30 minutes this week and list every software platform your business uses that touches customer information: your email marketing platform, POS system, booking software, loyalty program, website analytics, payment processor, and any apps customers interact with directly. That list is your data map and the foundation for everything that follows.


Step 3: Update Your Privacy Notice to Say What Colorado Requires

If your privacy policy was copied from a free template generator two years ago, it almost certainly doesn’t satisfy the CPA. The law specifies what a compliant privacy notice must include: the categories of personal data you collect, the purposes for which you process it, the categories of third parties with whom you share it, whether data is sold or used for targeted advertising and how consumers can opt out, how consumers can exercise their rights under the CPA, and contact information for the data controller—that’s you.

A generic template that says “we collect information to improve your experience” doesn’t come close. A compliant privacy notice names specific categories like “purchase history, email address, device identifier,” identifies specific third-party recipients by type like “email marketing platforms, advertising networks, analytics providers,” and gives consumers a real mechanism to make a request. A dedicated email address or web form works. A phone number that goes to the front desk does not.

The International Association of Privacy Professionals publishes Colorado-specific privacy policy resources at iapp.org. Template generators like Termly offer Colorado-specific builds with attorney review available, typically in the $0–$150 range. These are a better starting point than a blank page. But a template is a first draft, not a finished compliance document.

For most Denver small businesses, the most cost-effective path is to use a Colorado-specific template, then pay for one to two hours of attorney review. Denver market rates for that work run roughly $300–$600—confirm fees directly with any attorney you contact, because rates vary. An attorney with Colorado privacy law knowledge can confirm that your specific data practices are accurately described and that your consumer rights mechanisms actually work. The Denver Bar Association Lawyer Referral Service can connect you with a vetted attorney: 303-831-8000. The University of Denver Sturm College of Law and the University of Colorado Law School both run legal clinics that occasionally take small business compliance matters—worth a call if cost is a hard constraint.


Step 4: Set Up Consumer Rights Mechanisms and Honor the GPC Signal

The CPA gives Colorado consumers five rights they can exercise against any business that processes their data: the right to access a copy of the personal data you hold about them; the right to correct inaccurate data; the right to deletion; the right to portability in a machine-readable format; and the right to opt out of data sale, targeted advertising, and profiling in certain contexts. You have 45 days to respond to a consumer rights request.

Most of that can be addressed with a well-designed web form and a documented internal process. This part isn’t as complicated as it sounds.

What most Denver small business websites are not doing—and what the AG’s July 2024 final rules require—is honoring the Global Privacy Control signal. (CityDesk Denver is confirming the GPC compliance deadline against 1 CCR 204-2; this article will be updated when that verification is complete.)

GPC is a browser-level signal that a consumer can activate in privacy-respecting browsers like Firefox or Brave, or through browser extensions. It tells every website they visit that they opt out of data sale and targeted advertising. When a Colorado consumer visits your website with GPC enabled, your site must automatically treat that visit as an opt-out. The overwhelming majority of small business websites in Denver—WordPress sites, Shopify stores, restaurant websites—currently do not detect or honor this signal.

The fix is cheap. For a WordPress site, plugins like Complianz or CookieYes include GPC signal detection and cost between $0 and $99 per year. Shopify merchants can find comparable tools in the app store. If you’re on a managed website platform, ask your developer or agency whether your current cookie consent setup includes GPC signal detection—and get the answer in writing.

This is the compliance gap most competing guides skip over. It’s also the gap most Denver websites currently have, which makes it a logical place for the AG to look first.


Step 5: Execute Data Processing Agreements With Your Vendors

Here’s a compliance step that costs nothing, takes about an hour, and most Denver businesses haven’t done.

The CPA distinguishes between controllers—businesses that determine why and how personal data is processed (you)—and processors, which are vendors that handle personal data on a controller’s behalf. If a vendor processes your customer data to provide you a service, the CPA requires a written data processing agreement in place with that vendor. Your email marketing platform, POS system, booking software, loyalty program, payroll platform if it processes employee data you control, and any third-party analytics platform all require DPAs.

Every major platform Denver businesses use has a standard DPA template ready to sign. Mailchimp’s Data Processing Addendum can be executed online. Shopify’s, Toast’s, and Mindbody’s are standard documents. These don’t need to be negotiated by an attorney. They just need to be signed and documented.

The Capitol Hill yoga studio on Mindbody needs to locate and execute that agreement. The restaurant running Toast needs to do the same. Neither costs anything. Both are currently required by Colorado law. I keep coming back to this because it means the easiest compliance win available is one almost nobody has taken.

Go back to the vendor list from Step 2. For each platform, go to the website or your account settings and search “data processing agreement” or “DPA.” Execute and download each one. Store them in a folder labeled “CPA Compliance” with the date signed. That folder is your first line of defense if the AG ever asks.


What the AG Is Actually Looking For

The CPA does not have a private right of action. Individual consumers can’t sue your business for a CPA violation. Enforcement runs exclusively through the Colorado Attorney General’s office and district attorneys. The maximum civil penalty is $20,000 per violation per consumer—and those numbers add up fast on any non-trivial violation.

The most common path to enforcement attention is consumer complaints filed through the AG’s consumer complaint portal at coag.gov. If a Denver consumer tries to exercise their deletion right and your business ignores the request, they can file a complaint. The AG’s office has said publicly that complaint volume shapes enforcement priorities. AG Phil Weiser has named data privacy as an enforcement priority in multiple public statements. The office has authority to initiate investigations without a consumer complaint.

Other realistic triggers: a media story about a local business’s data practices, a former employee raising concerns, or a pattern of complaints about the same business in the AG’s portal. These are the same dynamics that show up in wage-and-hour enforcement and health code violations. Regulators follow the complaints.

Before the cure period’s statutory expiration, a business that received an AG notice of violation had 60 days to fix the problem before penalties attached. That automatic right is gone. The AG retains discretion to allow a cure period, but you cannot count on it. A business that receives a notice today has no statutory right to correct anything before penalties accrue.

AG Consumer Protection Hotline: 720-508-6000. Consumer complaint portal: coag.gov. (CityDesk Denver is confirming whether formal CPA enforcement actions have been filed to date; this piece will be updated as that reporting concludes.)


What Denver Privacy Attorneys Say You Should Do First

The compliance picture looks different from inside a law office than it does from a Google search. Denver-area attorneys practicing privacy and technology law—including practitioners at Polsinelli and Lewis Roca’s Denver offices, and attorneys listed with the Colorado Bar Association’s Privacy and Technology Law Committee—point consistently to the breadth of the 25,000-consumer threshold when ad-tech is in the picture, and to what the cure period’s expiration actually means for businesses still treating this as a future problem.

A business owner who runs Google Analytics and has 28,000 email subscribers may be covered without knowing it. The analytics relationship is the part most small business owners haven’t thought through: data shared with a platform in exchange for an advertising service. One attorney working with a Denver restaurant client found that a seemingly routine Google Analytics setup, combined with the restaurant’s email subscriber count, created coverage exposure the owner had never considered. That’s not a hypothetical scenario constructed for this article. It happened.

The practical advice for new clients follows a consistent sequence: determine whether you’re in scope, do the data inventory, then fix the cheapest gaps first. Install the GPC plugin. Sign the vendor DPAs. Do that now, while the privacy notice is being drafted—those steps require no attorney time and can be done this week. For businesses handling sensitive data—a Denver medical spa, a dispensary with biometric check-in, a GPS-enabled delivery service—attorney involvement isn’t optional. The opt-in consent requirements for sensitive data must be designed correctly from the start. Retrofitting consent mechanisms after the fact is significantly harder and more expensive than building them right the first time.

As part of our legal & finance coverage, CityDesk Denver will continue reporting on how local businesses are navigating Colorado’s evolving data privacy enforcement landscape. Denver Bar Association Lawyer Referral Service: 303-831-8000. Ask specifically for privacy law or technology law. CU Law and DU Sturm run small business clinics worth contacting if cost is a barrier.


Your Compliance Checklist, Ranked by Cost and Urgency

Work through this in order. The first three items are free and can be done this week.

Immediate—Free:

☐ Check your consumer count. Pull your Mailchimp, Klaviyo, or Constant Contact total contact list today. Above 100,000: read this as a compliance requirement, not a question. Above 25,000 with ad-tech running: stop assuming you’re exempt.

☐ Sign your vendor DPAs. Log into every platform handling your customer data—email platform, POS system, booking software, loyalty program—find the data processing agreement, and execute it. Free, takes about an hour total, legally required.

☐ Install a GPC-compliant cookie consent tool. WordPress: install Complianz or CookieYes (free tiers available; paid plans up to $99/year). Shopify: search the app store for a comparable tool. Confirm it detects and honors the Global Privacy Control browser signal. Most Denver websites currently don’t do this.

Within 30 Days—Low Cost:

☐ Update your privacy notice. Use a Colorado-specific template from IAPP or a reviewed generator like Termly as a starting point. It must name your actual data categories, your actual third-party recipients, whether you use targeted advertising, and how consumers can submit rights requests. Budget $0–$150 for a template.

☐ Get an attorney to review your privacy notice and threshold analysis. One to two hours at Denver market rates—roughly $300–$600, confirm fees directly. This is how you verify that your specific data practices are accurately described, your threshold analysis is correct, and your consumer rights mechanisms will actually work. Denver Bar Association Lawyer Referral Service: 303-831-8000.

If your business handles sensitive data or is clearly in the 100,000-consumer range, stop treating this as a DIY project. The opt-in consent requirements for health information, biometric data, and precise geolocation must be designed correctly. The consequences of getting them wrong are worse than for standard personal data, and the AG is not obligated to give you time to fix it.


Local resources for in-person guidance:

Colorado SBDC Denver Office: 1001 17th St., Denver—small business advising, including regulatory compliance

Denver Metro Chamber of Commerce: Member resources and business navigation support

AG Consumer Protection Hotline: 720-508-6000

Denver Bar Association Lawyer Referral Service: 303-831-8000


If you’ve completed the five steps above, you’ve meaningfully reduced your exposure under the Colorado Privacy Act. No checklist guarantees immunity. But you’ve done what the law’s framework asks of covered businesses, and you’ve documented it. If the AG’s office ever asks, documented good-faith effort matters.

July 2023 was the right time to start. Now is still early enough.

More in Legal & Finance