Colorado biometric law: does it apply to you?
Colorado's biometric provisions, added by HB 24-1130 and effective 1 July 2025, apply to any controller that collects, uses, or stores biometric identifiers of Colorado residents. This is a data-type trigger with no revenue or consumer-count threshold, so it reaches organizations that fall below the general Colorado Privacy Act thresholds.
Applies to: Controllers that collect, use, or store biometric identifiers or biometric data of Colorado residents.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
Biometric rules catch a lot of businesses by surprise because they do not follow the usual size logic. You can be far too small for the general Colorado Privacy Act and still owe the full set of biometric duties the moment you scan a fingerprint or a face. This page explains the trigger and the obligations that come with it.
Who the biometric provisions cover
Colorado's biometric provisions, added by HB 24-1130 and effective 1 July 2025, apply to controllers that collect, use, or store biometric identifiers or biometric data of Colorado residents. This is a pure data-type trigger. There is no revenue floor and no consumer-count threshold. If biometric identifiers pass through your systems and belong to Colorado residents, you are in scope, whatever your size. That is what makes these provisions reach organizations sitting well below the general Colorado Privacy Act thresholds.
Notice and consent come before collection
The central rule is timing. You must give specific notice and obtain affirmative consent before collecting biometric identifiers, not after the fact. Consent bolted on later does not cure a collection that already happened. If you plan to roll out face recognition for building access, fingerprint time clocks, or voiceprints in a product, the notice and consent step has to be in place first.
Written policy, retention, and deletion
Beyond consent, you must maintain a written biometric policy covering retention, security-incident response, and deletion. Apply retention limits and deletion deadlines, and review the policy on a schedule rather than treating it as a one-time document. You may not sell, lease, or trade biometric identifiers at all. Consumers hold the right to access the biometric data held about them and to opt in through specific notice and affirmative consent before collection.
Employees are specifically covered
The provisions include specific consent protections for employees and prospective employees, which matters because biometric tools often appear first in the workplace through time-and-attendance or access-control systems. Do not assume workforce use is outside the rules; follow the employee consent path deliberately.
How this fits the wider picture
These duties sit alongside, not inside, the general Colorado Privacy Act, and sensitive-data handling also features in laws like the Connecticut Data Privacy Act. See the US state privacy laws hub for how data-type triggers differ from the revenue and volume tests elsewhere.
Next step
If you use any biometric technology and touch Colorado residents, the free 2-minute Obligation Scan checks whether the biometric trigger applies and lists the notice, consent, retention, and deletion steps you owe, so nothing slips through because you assumed you were too small.
Compliance checklist
- Map where you collect, use, or store biometric identifiers of Colorado residents.
- Give specific notice and obtain affirmative consent before collection.
- Maintain a written biometric policy covering retention, security-incident response, and deletion.
- Apply retention limits and deletion deadlines, and review the policy on a schedule.
- Do not sell, lease, or trade biometric identifiers, and follow the specific consent rules for employees and prospective employees.
Sources
Last verified: 2026-07-16
Informational, not legal advice.