Back to the hub

How much can a Colorado Privacy Act violation cost?

A Colorado Privacy Act violation is treated as a deceptive trade practice, so the penalty comes from C.R.S. Section 6-1-112: up to $20,000 for each violation. Each consumer or transaction involved counts as a separate violation, and only the attorney general and district attorneys can enforce.

Applies to: Controllers and processors subject to the Colorado Privacy Act, C.R.S. Part 13 of Article 1 of Title 6, which the attorney general and district attorneys enforce exclusively.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Colorado does not print a penalty figure in its Privacy Act. It does something more consequential: it declares a privacy violation to be a deceptive trade practice, which imports the penalty from Colorado's general consumer protection law. The number that comes back is $20,000, and the way it multiplies is the part worth understanding.

Where the number actually comes from

C.R.S. Section 6-1-1311(1)(c) provides that, for purposes only of enforcement of Part 13 by the attorney general or a district attorney, a violation of Part 13 is a deceptive trade practice.

That single sentence hands the case to Section 6-1-112, the civil penalty provision of the Colorado Consumer Protection Act. Section 6-1-112(1)(a) provides that any person who violates or causes another to violate any provision of the article shall forfeit and pay to the general fund of the state a civil penalty of not more than twenty thousand dollars for each violation.

If you go looking for "$20,000" inside the Colorado Privacy Act itself, you will not find it. It is one cross-reference away.

The multiplier is per consumer

The second sentence of Section 6-1-112(1)(a) is the one that decides the size of a Colorado matter: for purposes of this subsection, a violation of any provision constitutes a separate violation with respect to each consumer or transaction involved.

That is written into the statute rather than left to a regulator's discretion. So the arithmetic is not one defect equals $20,000. It is one defect, multiplied by the number of Colorado consumers it touched, at up to $20,000 each.

Most real privacy failures are systemic. An opt-out link that does not work, a privacy notice missing a required disclosure, a universal opt-out signal that is received but not honored: none of these affect one person. They affect everyone who visited. A per-consumer multiplier turns a configuration error into a population-sized number, which is why Colorado exposure should be modeled off your Colorado user count rather than off the headline figure.

The general cure period is gone

This is the point where a lot of published guidance, including material still on the attorney general's own site, has not caught up.

When the Colorado Privacy Act was enacted, Section 6-1-1311(1)(d) required the attorney general or a district attorney to issue a notice of violation and allow 60 days to cure before bringing an action. That subsection carried its own repeal date. In the current statute, Section 6-1-1311(1)(d)(I) is shown simply as "Repealed."

The statutory history is unusually tangled and worth stating precisely. SB 24-041 amended subsection (1)(d) effective October 1, 2025. But the editor's note to the section records that those amendments to subsection (1)(d)(I) never took effect, because (1)(d)(I) had already been repealed. The net effect is the same either way: there is no general right to cure a Colorado Privacy Act violation before enforcement.

One narrow cure right survives, and not for long

Section 6-1-1311(1)(d)(II) keeps a cure right alive, but only for three sections: 6-1-1305.5, 6-1-1308.5 and 6-1-1309.5. Those are the minors provisions added by SB 24-041, covering responsibility for processing the data of minors, the duty of care with its rebuttable presumption, and data protection assessments for a heightened risk of harm to minors.

For those three, and only those three, the attorney general or district attorney must issue a notice of violation if a cure is deemed possible, and an action may be brought if the controller fails to cure within 60 days after receipt.

Section 6-1-1311(1)(d)(II) states that it is repealed effective December 31, 2026. So the last cure right in the Colorado Privacy Act has a stated end date, and it is close.

Who can sue, and who cannot

Section 6-1-1311(1)(a) gives the attorney general and district attorneys exclusive authority to enforce Part 13, by bringing an action in the name of the state or as parens patriae on behalf of persons residing in the state, including seeking an injunction.

Two things follow. District attorneys are real enforcement actors here, not a formality, so the risk is not concentrated in a single statewide office. And under Section 6-1-1311(1)(b), nothing in Part 13 provides the basis for a private right of action. Colorado consumers cannot sue you directly under this statute, which is a meaningful contrast with California's limited breach-based private right of action.

Section 6-1-112(1)(b) adds a further penalty of not more than ten thousand dollars for each violation of a court order or injunction issued under the article, and Section 6-1-1311(2) directs the state treasurer to credit penalty receipts under Section 24-31-108.

What this means in practice

Colorado is now a no-warning regime with a per-consumer multiplier. Compare that with Texas, where the penalty is $7,500 per violation and a 30-day notice-and-cure step still stands between you and an action. Same category of law, materially different risk shape.

Planning that assumes you will get a letter first is planning on a provision that no longer exists.

Next step

The free 2-minute Obligation Scan checks your business against every US state privacy law and GDPR at once and tells you whether Colorado reaches you before a district attorney does. For the applicability test, see the Colorado Privacy Act overview; for the deadlines that generate most violations, see the Colorado response deadline; and for the opt-out mechanism Colorado requires, see universal opt-out signals.

Compliance checklist

  • Model exposure per consumer, not per incident, because Section 6-1-112(1)(a) states that a violation constitutes a separate violation with respect to each consumer or transaction involved.
  • Do not plan around a cure period: the general cure right in Section 6-1-1311(1)(d)(I) is repealed, so the attorney general can act without giving notice first.
  • If you process the personal data of minors, note that the surviving cure right in Section 6-1-1311(1)(d)(II) covers only Sections 6-1-1305.5, 6-1-1308.5 and 6-1-1309.5, and expires on December 31, 2026.
  • Remember that district attorneys, not only the attorney general, can bring an action under Section 6-1-1311(1)(a), including as parens patriae on behalf of Colorado residents.
  • Do not treat a court order as the end of exposure: Section 6-1-112(1)(b) adds a penalty of up to ten thousand dollars for each violation of an injunction issued under the article.
  • Fix systemic defects first, since a single misconfigured opt-out or notice repeats across your whole Colorado user base and multiplies under the per-consumer rule.

Sources

Last verified: 2026-08-28

Informational, not legal advice.