Law / United States / Colorado

Colorado

United States law applies in Colorado Colorado is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Colorado, described on this page below, applies here too.

All 17 named instruments researched to a stage, across five of the six areas of law we track: 12 in force, 3 enacted but not yet in force and 2 repealed, withdrawn or blocked. As of 12 September 2026.

When they take effect16 of 17 carry a date, 1 does not. Earlier is before 2016.
Before 2016: 1 instrument (1 in force) earlier 2016: 0 instruments 2017: 0 instruments 2018: 3 instruments (3 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 1 instrument (1 in force) 2023: 1 instrument (1 in force) 2024: 2 instruments (2 in force) 2025: 4 instruments (4 in force) ’25 2026: 1 instrument (1 repealed, withdrawn or blocked) 2027: 2 instruments (2 enacted but not yet in force) 2028: 1 instrument (1 enacted but not yet in force) ’28 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 4
  2. Privacy law 5
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 3
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law4 instruments, 1 in force, 2 enacted but not yet in force, 1 repealed, withdrawn or blocked

Research summary (234 words)

Colorado's landmark Colorado AI Act (SB 24-205, 2024) never took effect.

Its operative date slipped from 1 February 2026 to 30 June 2026 under SB 25B-004 (2025 Special Session B), a federal court stayed its enforcement in April 2026 in litigation brought by xAI and joined by the U.S. Department of Justice, and before the June date arrived, the legislature repealed and re-enacted its Part 17 of Title 6 wholesale as SB 26-189 (signed 14 May 2026), replacing the risk-management framework with a narrower automated-decision-making-technology disclosure regime whose consumer-facing duty does not take effect until 1 January 2027.

SB 25B-004, officially titled "Increase Transparency for Algorithmic Systems" and sometimes called the Colorado AI Sunshine Act, only extended SB 24-205's effective date and created no independent disclosure duty of its own, so it is described here only as part of SB 24-205's history, not as a standalone instrument. Separately and unaffected by any of this, Colorado's candidate election-deepfake disclosure statute, HB 24-1147, has been in force since 1 July 2024.

A fourth instrument, HB 26-1263 (2026), Chapter 208, adds Part 17 duties for operators of conversational AI services (chatbots): age estimation, minor-specific safety and disclosure requirements, a suicide and self-harm response protocol, a ban on claiming professional credentials for the service's output, and annual reporting to the Attorney General, with its consumer-facing duties taking effect 1 January 2027 and its reporting duty 1 July 2027.

AI transparency

HB 24-1147, Candidate Election Deepfake Disclosures

C.R.S. 1-46-103official signed act text, Colorado General Assembly

In force since 1 July 2024. Binds public and private bodies.

What this law does

No person may distribute, publish, broadcast, or display a communication about a candidate for elective office that includes a deepfake within 60 days of a primary or 90 days of a general election, unless the communication carries a specified clear and conspicuous disclosure that it has been edited and falsely appears authentic. This binds any distributing party, not only the AI system's provider or deployer, and is unaffected by the litigation and repeal touching SB 24-205 and SB 26-189.

What it requires

HB 26-1263 (2026), Conversational AI Service Operator Requirements

C.R.S. 6-1-1708official session-law chapter text, Chapter 208 (2026), Colorado General Assembly

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

An operator that develops and makes publicly available, or offers to a consumer, a conversational artificial intelligence service must use commercially reasonable or generally accepted methods to estimate a user's age, and must not willfully disregard clear and convincing information that an account holder or user is a minor.

Starting January 1, 2027, if an operator knows an account holder or user is a minor, the operator must disclose that the service is artificial intelligence, withhold unpredictable-interval engagement rewards from the minor, prevent the service from producing explicit sexual content, intimate digital depictions, or statements simulating romantic companionship or emotional dependence with the minor, and give the minor and a parent or guardian tools to manage privacy and account settings.

Starting January 1, 2027, an operator must also disclose to every user, not only minors, that the service is artificial intelligence, run a suicide and self-harm response protocol that refers a user to a crisis service provider rather than law enforcement, and not represent the service's output as coming from a licensed health-care, legal, or mental-health professional or a qualified dietitian; starting July 1, 2027, it must report annually to the Attorney General on crisis referrals and self-harm safeguards without including user-identifying information.

Signed May 29, 2026 as Chapter 208 and added to Part 17 of Title 6 alongside SB 24-205 and SB 26-189, a violation of this duty is a deceptive trade practice under the Colorado Consumer Protection Act enforced by the Colorado Attorney General, subject to a 60-day right to cure before an enforcement action, and creates no new private right of action.

What it requires

SB 24-205 (2024), Colorado AI Act, original enactment

C.R.S. 6-1-1701 et seq., as originally enactedofficial signed act text, Colorado General Assembly

Repealed: no longer in force. Binds private bodies.

What this law does

As originally enacted, this disclosure duty (6-1-1704) required a deployer or developer that made an artificial intelligence system available to interact with consumers to ensure disclosure to each consumer that they were interacting with an artificial intelligence system, unless it would be obvious to a reasonable person, and sat alongside a broader high-risk-system duty to avoid algorithmic discrimination in consequential decisions elsewhere in Part 17, outside this topic's scope.

The operative date slipped twice: first to 1 February 2026 as originally enacted, then to 30 June 2026 under SB 25B-004 (2025 Special Session B, Chapter 3), which extended the effective date of SB 24-205's requirements and added no independent disclosure duty of its own; enforcement was then stayed by a federal court on 27 April 2026 in X.AI LLC v. Weiser (a stipulated stay on joint motion of xAI and the state, not a merits ruling) after xAI sued and the United States intervened.

Before the delayed date arrived, SB 26-189 (signed 14 May 2026) repealed and re-enacted the same Part 17 with a successor framework, effective 1 January 2027; the Colorado General Assembly's own bill summary describes this action as repealing and reenacting Part 17, and multiple law firm summaries of the signed act likewise describe SB 24-205 as repealed.

Because it never reached its own operative date before being repealed, this statute was never in force at any point, and is recorded here as repealed.

What it requires

SB 26-189 (2026), Automated Decision-Making Technology Act

C.R.S. 6-1-1704official enrolled act text, Colorado General Assembly

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Prior to using a covered automated decision-making technology that materially influences a consequential decision (education, employment, housing, financial or lending services, insurance, health care, or essential government services), a deployer must provide a clear and conspicuous notice that it used or will use covered ADMT in that decision, satisfiable by a prominent public notice at points of consumer interaction.

If the ADMT produces an adverse outcome, the deployer must, within 30 days, provide a plain-language description of the decision and the technology's role, plus an explanation of the consumer's rights. Signed 14 May 2026; the consumer disclosure duty itself takes effect 1 January 2027, so it is enacted, not yet in force, as of the date shown. The Colorado General Assembly's own bill status page confirms the 14 May 2026 signature date.

What it requires

Privacy law5 instruments, 5 in force

Research summary (311 words)

Colorado's comprehensive privacy regime is the Colorado Privacy Act (CPA, C.R.S. 6-1-1301 et seq., enacted by SB 21-190), in effect since July 1, 2023, binding a controller that conducts business in or intentionally targets Colorado residents and meets a 100,000-consumer, or a 25,000-consumer-plus-sale-revenue, processing threshold.

No express government-entity exemption clause was located in the text reviewed; the private-sector coding here rests on the act's business-facing definitions and its placement inside the Colorado Consumer Protection Act, not on a located carve-out. Three 2024-session amendments extend the CPA on staggered effective dates. HB 24-1058 (7 August 2024) added biological and neural data as sensitive-data categories.

HB 24-1130 (1 July 2025) added a dedicated biometric-identifier regime, naming voiceprint and facial map, geometry, or template explicitly, that binds a controller processing any amount of biometric data with no volume threshold, requiring pre-collection notice and consent and a written retention-and-destruction schedule.

SB 24-041 (1 October 2025) layered a duty of care and consent-gated processing limits onto a minor's data, and kept its own 60-day cure period in force through December 31, 2026 after the CPA's general cure period sunset on January 1, 2025. The Department of Law also retains open rulemaking authority for biometric security standards under C.R.S. 6-1-1314(7).

A standalone statute, C.R.S. 6-1-716, requires a private entity to notify affected Colorado residents of a security breach within 30 days of determination, with Attorney General notice once 500 or more residents are affected and consumer-reporting-agency notice at 1,000 or more; a separate statute, C.R.S. 24-73-103, covers a governmental entity's own breach-notification duty.

Enforcement of the CPA is exclusive to the Attorney General and district attorneys, with no private right of action anywhere in the act. Civil penalties apply under the Colorado Consumer Protection Act's general penalty provision, C.R.S. 6-1-112; specific per-violation dollar figures are reported by compliance trackers, not independently confirmed against that provision's primary text.

Biometric privacy

HB 24-1130, Privacy of Biometric Identifiers and Data

C.R.S. sections 6-1-1303(2.2)-(2.4), 6-1-1314 (2024 Colo. Sess. Laws ch. 313)official legislature bill status page for HB 24-1130 (bill history and staff summary)

In force since 1 July 2025. Binds private bodies.

What this law does

Amends the Colorado Privacy Act to define biometric identifier (a fingerprint, a voiceprint, a scan or record of an eye retina or iris, a facial map, facial geometry, or facial template, or another unique biological, physical, or behavioral pattern) and biometric data, and adds C.R.S. 6-1-1314, which requires any controller that controls or processes a biometric identifier, regardless of the CPA's general size thresholds, to give notice and obtain consent before collection, adopt a written retention and destruction policy, maintain a data-security-incident response protocol, and refrain from selling, leasing, or trading a biometric identifier absent consent or a listed exception.

Consumers may request the source, purpose, and third-party disclosures of their biometric data. The biometric-data definition excludes a photograph and an audio or video recording, and data generated from either, but only conditionally: the exclusion drops away the moment that data is used for identification purposes, so a voiceprint or faceprint extracted from a recording specifically to identify someone remains covered.

What it requires

Breach notification

C.R.S. 6-1-716, Notification of Security Breach

C.R.S. section 6-1-716Colorado Attorney General official data-protection-laws resource page

In force since 1 September 2018. Binds private bodies.

What this law does

Requires a person or commercial entity that maintains computerized personal identifying information of Colorado residents to notify affected residents of a security breach in the most expedient time possible, without unreasonable delay, and within 30 days of determining a breach occurred, subject to a delay while a law-enforcement investigation is pending.

A breach affecting 500 or more residents must also be reported to the Colorado Attorney General; one affecting more than 1,000 residents must also be reported to nationwide consumer reporting agencies. A separate statute, C.R.S. 24-73-103, covers a governmental entity's own breach-notification duty. HB 24-1130 cross-references this section for the biometric-specific breach-response protocol a controller's written policy must include.

What it requires

Comprehensive regime

SB 21-190, Colorado Privacy Act (CPA)

C.R.S. sections 6-1-1301 et seq.Official session law text (2021 Colo. Sess. Laws ch. 483, enrolled SB 21-190) and the Colorado General Assembly's official bill page

In force since 1 July 2023. Binds private bodies.

What this law does

Colorado's omnibus data-privacy statute requires a controller that conducts business in or intentionally targets Colorado residents, and meets a 100,000-consumer or a 25,000-consumer-plus-sale-revenue threshold, to give consumers notice, minimize collection, obtain affirmative opt-in consent before processing sensitive data or resuming processing after an opt-out, and honor rights to access, correct, delete, and port personal data.

Processors must follow controller instructions and assist with compliance, and a controller must complete a data protection assessment before processing that presents a heightened risk of harm.

What it requires

Sensitive categories

HB 24-1058, Protect Privacy of Biological Data

C.R.S. sections 6-1-1303(2.5), 6-1-1303(16.7), 6-1-1303(24)(b)-(d) (2024 Colo. Sess. Laws ch. 68)Colorado General Assembly official bill page for HB24-1058

In force since 7 August 2024. Binds private bodies.

What this law does

Amends the Colorado Privacy Act's sensitive-data definition to add biological data (data from technological processing, measurement, or analysis of an individual's biological, genetic, biochemical, physiological, or neural properties, used or intended for identification) and neural data (information generated by measuring central or peripheral nervous system activity, processed by or with a device).

Extends the CPA's opt-in consent duty for sensitive data to both categories, the first such extension to neural data in a US comprehensive privacy statute.

What it requires

SB 24-041, Protecting Minors' Online Data

C.R.S. sections 6-1-1305.5, 6-1-1308.5, 6-1-1309.5, 6-1-1311(1)(d)(II) (2024 Colo. Sess. Laws ch. 296)Official enrolled act text, 2024 Colo. Sess. Laws ch. 296 (SB 24-041), and the Colorado General Assembly's official bill page

In force 12 months, effective 1 October 2025. Binds private bodies.

What this law does

Amends the Colorado Privacy Act to add a duty of care: a controller that offers an online service, product, or feature to a consumer it actually knows or willfully disregards is a minor must use reasonable care to avoid a heightened risk of harm to that minor, and must complete a data protection assessment where that risk exists.

Absent opt-in consent (from the minor, or a parent or guardian for a minor under 13), the controller may not process a minor's personal data for targeted advertising, sale, or profiling with legal or similarly significant effects, use a system design feature meant to significantly increase, sustain, or extend a minor's use of the service, or collect a minor's precise geolocation data beyond what is necessary to provide the service.

The minors' provisions keep their own 60-day cure notice requirement in force through December 31, 2026, after the CPA's general cure period sunset on January 1, 2025.

What it requires

Scraping law3 instruments, 3 in force

Research summary (210 words)

Colorado diverges from federal scraping law only in the personal_data family, and more narrowly than California. Its cybercrime statute tracks the federal Computer Fraud and Abuse Act (CFAA)'s without authorization and exceeds authorized access language almost verbatim, unlike California's broader without permission standard, and no Colorado court has construed it in a scraping context, so how it would apply to public-page access is unsettled as a matter of Colorado law specifically.

The Colorado Privacy Act's publicly-available-information exemption has only two prongs, both keyed to a government record or the consumer's own act, with no California-style third widely-distributed-media catch-all and no prong for a third party's unrestricted disclosure; personal data a scraper pulls from an aggregator or re-hosted directory falls outside the exemption.

A 2024 amendment separately defines biometric data (excluding a bare photo, video, or audio recording unless used for identification) and the distinct term biometric identifier (the underlying raw category, such as a fingerprint or facial geometry); processing a scraped photo or voice clip into an identification template converts it into sensitive data requiring opt-in consent.

No Colorado-specific scraping case law was found for any dimension, so several access-context questions remain textually plausible but judicially untested. Copyright, database rights, and ToS enforceability add nothing beyond the federal position already covered in the national document.

Computer misuse

Colorado Cybercrime statute (unauthorized access, tracking the federal CFAA)

C.R.S. § 18-5.5-102official text, Colorado Revised Statutes, Office of Legislative Legal Services (leg.colorado.gov)

In force since 1 July 2000. Binds public and private bodies.

What this law does

Subsection (1)(a) makes it a cybercrime for a person to knowingly access a computer without authorization, exceed authorized access, or use a computer without authorization or in excess of authorized access, language that tracks the federal Computer Fraud and Abuse Act (CFAA)'s structure almost verbatim rather than California's broader without permission standard.

No Colorado court has construed this language in a scraping context, so whether Colorado would follow the narrow, gates-based reading the US Supreme Court gave the federal statute in Van Buren v. United States (593 U.S. 374, 2021) is unsettled as a matter of Colorado law.

A 2018 act (HB 18-1200, session law chapter 379, confirmed against the official signed act) renamed the section from computer crime to cybercrime and added the current subsections (1)(h) through (1)(j) and an escalated penalty tier; a 2023 act (HB 23-1293, confirmed against the official signed act) amended only the repeat-offender penalty clause at (3)(b), not the underlying conduct definition at (1)(a).

The underlying text is confirmed directly against the official Colorado Revised Statutes (leg.colorado.gov): the section's own source note shows the article was entire added in 1979, subsection (1) was amended in 1983, and the entire section was reenacted in 2000; no amendment since 2000 has touched subsection (1)(a) itself, so the currently codified without-authorization or exceeds-authorized-access language traces to that 2000 reenactment rather than to the 1979 original.

What it requires

Personal data

Colorado Privacy Act, publicly-available-information exemption and biometric data (as amended by HB 24-1130)

C.R.S. §§ 6-1-1301 et seq., 6-1-1303(2.2), (2.4), (17), (24)official signed act PDFs, Colorado General Assembly (content.leg.colorado.gov and leg.colorado.gov)

In force since 1 July 2025. Binds private bodies.

What this law does

Section 6-1-1303(17) excludes publicly available information from personal data, defined with only two prongs: information lawfully made available from a federal, state, or local government record, and information the controller has a reasonable basis to believe the consumer has lawfully made available to the general public.

Unlike California's CCPA, there is no third widely-distributed-media catch-all and no prong for information a third party disclosed without restricting the audience, so personal data a scraper pulls from a source that is neither a government record nor the data subject's own post, such as an aggregator or people-search broker, falls outside the exemption and inside the Act's reach for a qualifying collector.

HB 24-1130 (2024), effective July 1, 2025, added Section 6-1-1303(2.2), defining biometric data as one or more biometric identifiers used for identification purposes and excluding a bare digital or physical photograph, an audio or video recording, or data generated from one, unless used for identification; and (2.4), a separate term, biometric identifier, meaning data generated by measuring a person's unique biological, physical, or behavioral characteristics, such as a fingerprint, voiceprint, retina or iris scan, or facial geometry.

Biometric or genetic data processed to uniquely identify an individual is sensitive data under Section 6-1-1303(24)(b), triggering opt-in consent; scraping a raw photo or voice clip is not itself scraping biometric data, but processing it into an identification template is.

What it requires

Unfair competition

Colorado Consumer Protection Act, unfair or deceptive trade practices

C.R.S. § 6-1-105(1)(rrr)official text, Colorado Revised Statutes, Office of Legislative Legal Services (leg.colorado.gov)

In force since 1 October 2022. Binds private bodies.

What this law does

Section 6-1-105 lists specific deceptive trade practices, and paragraph (1)(rrr) reaches anyone who knowingly or recklessly engages in any unfair, unconscionable, deceptive, deliberately misleading, false, or fraudulent act or practice, broad language structurally comparable to California's UCL.

No Colorado scraping case has ever been brought under this statute, and no Colorado case applies common-law trespass to chattels to a scraping fact pattern either, so whether Colorado would require actual system harm, as California does post-Hamidi, or a lower showing, is unsettled. Paragraph (1)(rrr) is a 2022 addition, confirmed against the official Colorado Revised Statutes: HB 22-1287 repealed the former paragraph (1)(kkk) and added the current (1)(rrr) in its place.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (554 words)

Colorado's security posture rests on two enacted state statutes added and amended together by HB 18-1128 (2018 Colo. Sess. Laws ch. 266, signed May 29, 2018, effective September 1, 2018): C.R.S. 6-1-713.5, requiring a covered entity that maintains, owns, or licenses the personal identifying information of a Colorado resident to implement and maintain reasonable security procedures and practices appropriate to the nature of that information and the nature and size of the business, and its disposal-of-documents sibling, C.R.S. 6-1-713, requiring a written policy to destroy or dispose of paper and electronic documents containing personal identifying information by shredding, erasing, or otherwise rendering it unreadable once no longer needed.

Both duties bind only a private person or commercial entity; a governmental entity's parallel duties sit at C.R.S. 24-73-102 (protection) and 24-73-103 (breach notice), outside this profile's private-sector scope.

No enacted Colorado statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's or Oregon's connected-device statutes; a search for a Colorado IoT or product-security bill returned only the state's general data-protection statutes, so this is treated as a researched absence rather than a gap in coverage.

No Colorado statute or regulation setting a sector-specific cyber-resilience regime for a software or technology provider, comparable to New York's 23 NYCRR Part 500, was located; the Colorado Division of Insurance may separately regulate insurer cybersecurity, but no citable text was located to support a row.

The Colorado Privacy Act carries its own security-of-processing clause, C.R.S. 6-1-1308(5)'s duty of care, requiring a controller to take reasonable measures to secure personal data during storage and use from unauthorized acquisition, appropriate to the volume, scope, and nature of the personal data and the nature of the business; because that duty is a section of Colorado's comprehensive data-protection act rather than a standalone security statute, it is this jurisdiction's privacy row, not a second row here.

Colorado's breach-notification duty, C.R.S. 6-1-716, is likewise already this jurisdiction's privacy row: a person or commercial entity that experiences unauthorized acquisition of unencrypted computerized personal identifying information must notify affected Colorado residents within 30 days of determination, the Attorney General once 500 or more residents are affected, and nationwide consumer reporting agencies once more than 1,000 are affected.

Enforcement of both security-topic statutes runs through C.R.S. 6-1-716(4), which lets the Attorney General bring an action in law or equity to address a violation of section 6-1-716, 6-1-713, or 6-1-713.5, either to compel compliance or to recover direct economic damages, and states that this route is not exclusive of other applicable law.

Because 6-1-713 and 6-1-713.5 sit in part 7 of the Colorado Consumer Protection Act, a violation of either is also a deceptive trade practice under C.R.S. 6-1-105(1)(x) (violating part 7 of the article), which reaches the article's general civil penalty of up to $20,000 per violation under C.R.S. 6-1-112(1)(a) (up to $50,000 per violation against an elderly person), enforced by the Attorney General or a district attorney, and a private right of action under C.R.S. 6-1-113 for actual damages (with prejudgment interest), a $500 statutory minimum, treble damages on clear and convincing evidence of bad faith, and attorney fees.

This is a broader private remedy than New York's SHIELD Act safeguards duty, which creates no private right of action at all.

Security baseline statutes

Disposal of personal identifying information, written policy duty

C.R.S. 6-1-713 (amended by HB 18-1128, 2018 Colo. Sess. Laws ch. 266, section 1)Colorado Revised Statutes Title 6, Consumer and Commercial Affairs, as compiled by FindLaw

In force since 1 September 2018. Binds private bodies.

What this law does

A covered entity that maintains paper or electronic documents containing personal identifying information during the course of business must develop a written policy for the destruction or proper disposal of those documents. Once the documents are no longer needed, the covered entity must destroy or arrange for their destruction by shredding, erasing, or otherwise modifying the personal identifying information to make it unreadable or indecipherable through any means.

"Covered entity" and "personal identifying information" carry the same definitions this section shares with the reasonable-security-procedures duty at C.R.S. 6-1-713.5, and a covered entity already regulated by state or federal law and following that regulator's own disposal procedures is deemed compliant.

Unless an entity specifically contracts with a recycler or disposal firm for destruction, the recycler or disposal firm has no duty to verify that the documents it receives were properly destroyed.

What it requires

Protection of personal identifying information, reasonable security procedures duty

C.R.S. 6-1-713.5 (added by HB 18-1128, 2018 Colo. Sess. Laws ch. 266, section 2)Colorado Revised Statutes Title 6, Consumer and Commercial Affairs, as compiled by FindLaw

In force since 1 September 2018. Binds private bodies.

What this law does

A covered entity, a person that maintains, owns, or licenses personal identifying information of a Colorado resident in the course of its business, vocation, or occupation, must implement and maintain reasonable security procedures and practices, appropriate to the nature of the information and the nature and size of the business, to protect personal identifying information from unauthorized access, use, modification, disclosure, or destruction.

Personal identifying information is defined narrowly: a Social Security number, a personal identification number, a password or pass code, a state driver's license or identification card number, a government passport number, biometric data, an employer, student, or military identification number, or a financial transaction device.

Where a covered entity discloses that information to a third-party service provider, it must require the provider to implement and maintain its own reasonable security procedures, unless the covered entity retains primary responsibility and implements technical controls that protect the information. A covered entity already regulated by state or federal law and following that regulator's own data-security procedures is deemed compliant.

This duty binds a private person or commercial entity; a governmental entity's parallel duty sits at C.R.S. 24-73-102, outside this profile's private-sector scope.

What it requires

Age gating law3 instruments, 1 in force, 1 enacted but not yet in force, 1 repealed, withdrawn or blocked

Research summary (187 words)

Colorado has enacted laws in three of the four age-gating families but has not passed a social media minor access or adult content age verification statute. Senate Bill 24-041 amended the Colorado Privacy Act, effective October 1, 2025, to impose a duty of care, data protection assessments, and consent requirements before minors' data is used for targeted advertising, sale, profiling, or engagement extending design features.

House Bill 24-1136 required social media platforms to show pop-up warnings to users under 18 after an hour of daily use and at night starting January 1, 2026, but a federal court preliminarily enjoined it on First Amendment grounds in November 2025. Senate Bill 26-051, the Age Attestation on Computing Devices Act, requires operating system providers to collect a birth date, age, or age bracket at device setup and share an age signal with app developers, effective July 1, 2028.

Several 2025 and 2026 proposals on adult content age verification (SB 25-201), social media transparency and age verification (SB 24-158), and youth privacy design requirements (HB 25-1287, HB 26-1148) all failed to advance past committee or died when their legislative sessions ended.

Age-appropriate design code

SB 24-041 (2024), Privacy Protections for Children's Online Data

Colo. Rev. Stat. §§ 6-1-1305.5, 6-1-1308.5, 6-1-1309.5 (amending the Colorado Privacy Act)official signed act text, Colorado General Assembly

In force 12 months, effective 1 October 2025. Binds private bodies.

What this law does

Requires a controller offering an online service, product, or feature to a consumer it actually knows or willfully disregards is a minor (under 18) to use reasonable care to avoid a heightened risk of harm to minors and to conduct data protection assessments.

Without consent (the minor's, or a parent's for a child under 13), the controller may not process a minor's data for targeted advertising, sale, or significant profiling, use a system design feature to significantly increase, sustain, or extend the minor's use, or collect precise geolocation except as specified. Signed May 31, 2024.

Note and primary source

App store age verification (AV)

SB 26-051 (2026), Age Attestation on Computing Devices Act

Colo. Rev. Stat. §§ 6-30-101 to 6-30-105 (2026 Colo. Sess. Laws ch. 343)official session law chapter text, Colorado General Assembly

In force in 647 days, effective 1 July 2028. Binds private bodies.

What this law does

Requires operating system providers and covered application stores to let an account holder indicate a birth date, age, or age bracket at device setup and to share a real time age signal (under 13, 13 to under 16, 16 to under 18, or 18 and older) with application developers, who must treat the signal as the primary indicator of a user's age range unless they have clear and convincing information otherwise. Signed June 3, 2026; codified as article 30 of title 6 (Age Attestation for Online Users).

Note and primary source

Social media and minors

HB 24-1136 (2024), Healthier Social Media Use by Youth

Colo. Rev. Stat. § 6-1-1601 (and § 22-2-127.8)official signed act text, Colorado General Assembly

Enjoined: enforcement paused by a court, effective 1 January 2026. Binds private bodies.

What this law does

Requires a social media platform with more than 100,000 active Colorado users to give users under 18 information on how social media affects the developing brain and youth mental and physical health, and to display a notification every 30 minutes once a minor has spent one hour on the platform in a 24 hour period or is using it between 10 p.m. and 6 a.m. Signed June 6, 2024, with the platform requirement set for January 1, 2026, but preliminarily enjoined before that date.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.