Does Colorado require businesses to honor Global Privacy Control?
Yes. Since July 1, 2024, businesses within the Colorado Privacy Act's thresholds must let consumers opt out of the sale of personal data and targeted advertising through a universal opt-out mechanism. Global Privacy Control is currently the only mechanism the Colorado Department of Law recognizes as valid.
Applies to: Businesses that meet the Colorado Privacy Act's applicability thresholds and either sell personal data or process it for targeted advertising, which must accept opt-out signals sent by a recognized universal opt-out mechanism.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanColorado made the browser signal mandatory before most states did, and it named a specific mechanism. That combination makes this one of the easier obligations to test and one of the easier ones to fail silently.
The obligation
The Colorado Privacy Act gives consumers the right to opt out of the sale of their personal data and out of the use of their personal data for targeted advertising. They can do that directly with a business, or through a universal opt-out mechanism.
The Colorado Department of Law puts the compliance date plainly: beginning July 1, 2024, businesses falling within the CPA's application thresholds must allow consumers to opt out of the sale of their personal data or use of their personal data for targeted advertising using GPC, citing C.R.S. section 6-1-1306(1)(a)(IV).
Two purposes, then. Sale, and targeted advertising. A signal that you honor for cookie-based advertising but not for a data sale is only half-implemented.
GPC is the list
Under CPA Rule 5.07 the Attorney General maintains a public list of universal opt-out mechanisms that have been recognized to meet the standards of the rules. That list was due no later than January 1, 2024 and is updated periodically.
Global Privacy Control was the first mechanism recognized, and the Department states that GPC is currently the only UOOM it considers valid. The Department is careful to add that the list does not exclude other mechanisms from qualifying later, and that the published list represents what it will prioritize for enforcement.
The practical reading: implement GPC now, and treat the list as something to re-check rather than a settled fact.
What GPC actually is
It is a signal sent by a user's browser, as a browser setting or extension, telling businesses the user's privacy preference. The consumer turns it on once per browser or device and it then travels with every site they visit, which is exactly why it is more demanding than a per-site opt-out link: you cannot wait for a request that arrives through your own form.
The Department recognizes GPC insofar as the mechanism or its authorized implementations meet the requirements of C.R.S. section 6-1-1313 and Part 5 of the CPA Rules, and points businesses to the published technical specification for implementation.
The disclosure most teams forget
Honoring the signal is not the whole obligation. Businesses must also include, in their privacy policy, an explanation of how requests made using universal opt-out mechanisms including GPC will be processed. That requirement sits at Rule 6.03(4)(e) of the CPA Rules.
This is the part that shows up in a document review, because it is visible from outside your systems. A regulator or a prospective customer can read your privacy policy and see immediately whether you have addressed universal opt-outs at all.
Where this fits with other states
Colorado is not alone in requiring a browser signal, but the rules are not interchangeable. California has its own treatment of opt-out preference signals, and Texas built a different route again through authorized agents. Building for one state does not automatically satisfy another, and the differences sit in which purposes the signal covers and what you must publish about it.
Next step
Universal opt-out only matters if the CPA reaches you in the first place, and Colorado's thresholds are their own test. The free 2-minute Obligation Scan checks which US state privacy laws apply to your business and what each requires. See the Colorado Privacy Act overview for the applicability thresholds, CCPA and Global Privacy Control for how California treats the same signal, and Texas browser opt-out signals for the Texas route.
Compliance checklist
- Detect the GPC signal on every page a Colorado consumer can reach, not only on your privacy or cookie pages.
- Treat a received signal as an opt-out from both the sale of personal data and targeted advertising, which are the two purposes named in C.R.S. 6-1-1306(1)(a)(IV).
- Add an explanation to your privacy policy of how you process universal opt-out requests, as Rule 6.03(4)(e) of the CPA Rules requires.
- Do not require the consumer to create an account or verify their identity to have a universal opt-out honored; the point of the mechanism is that it works without an individual request to each controller.
- Watch the Department of Law's published UOOM list rather than assuming GPC is permanently the only entry, because Rule 5.07 commits the Department to updating it periodically.
- Check the other states separately, since Texas and California run their own browser-signal rules on different terms.
Sources
- Universal Opt-Out and the Colorado Privacy Act, Colorado Attorney General (Colorado Department of Law)
- Colorado Privacy Act resource page, Colorado Attorney General
- Colorado Privacy Act Rules (official adopted text), Colorado Department of Law, Consumer Protection Section
Last verified: 2026-08-23
Informational, not legal advice.