Colorado
Colorado Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 9 primary sources cited on this page. How we verify our legal content

Colorado regulates biometric data through two overlapping laws: the Colorado Privacy Act (C.R.S. § 6-1-1301) classifies biometric data as sensitive data requiring affirmative consent, and HB24-1130 (C.R.S. § 6-1-1314), effective July 1, 2025, adds biometric-specific obligations covering written policies, retention timelines, and employer consent rules.
Colorado stands out among U.S. states for having two overlapping layers of biometric privacy protection. The Colorado Privacy Act (CPA) has treated biometric data as sensitive data since 2023, requiring affirmative consent before processing. Then in 2024, the legislature passed HB24-1130, creating a dedicated biometric privacy statute (C.R.S. § 6-1-1314) that took effect on July 1, 2025.
This dual framework gives Colorado one of the strongest biometric privacy regimes in the country. If your organization collects fingerprints, facial scans, voiceprints, or other biometric identifiers from Colorado residents, you need to comply with both the CPA's sensitive data rules and HB24-1130's biometric-specific requirements.
For a broader look at Colorado's privacy framework, see the parent guide: Colorado Data Privacy Laws.
What HB24-1130 Covers
Governor Jared Polis signed HB24-1130 on May 31, 2024. The bill drew broad bipartisan support: 34 representatives and 15 senators signed on as sponsors, and it cleared third reading without a no vote in either chamber (60-0 in the House, 33-0 in the Senate). It amends the CPA by adding Section 6-1-1314, which focuses exclusively on biometric identifiers and biometric data.
The law defines a biometric identifier as data generated by the technological processing, measurement, or analysis of a consumer's biological, physical, or behavioral characteristics that can be processed to uniquely identify an individual. Specific examples include:
- Fingerprints
- Voiceprints
- Retina or iris scans
- Facial maps, facial geometry, or facial templates
- Other unique biological, physical, or behavioral patterns or characteristics
Biometric data is defined as one or more biometric identifiers that are used or intended to be used, singly or in combination with other personal data, to identify an individual. The law explicitly excludes photographs, audio or video recordings, and data derived from them, unless that data is used for identification purposes.
One notable feature of HB24-1130 is its scope. The CPA generally applies only to entities processing data of 100,000 or more Colorado residents, or 25,000 or more residents if the entity earns revenue from data sales. HB24-1130 removes those numerical thresholds for most of its biometric duties, meaning any controller processing biometric identifiers from Colorado residents must obtain consent, provide notice, publish a written policy, and follow the retention and destruction schedule regardless of volume. There is one exception: the biometric right-to-access provision (C.R.S. § 6-1-1314(5)) applies only to a defined set of controllers. The main route in is volume based, covering an entity that does business in Colorado, collects biometric data, and either collects or processes the personal data of 100,000 or more individuals during a calendar year or collects and processes the personal data of 25,000 or more individuals while deriving revenue or a price discount from selling personal data. Note that the statute counts individuals, not Colorado residents. Two other categories in § 6-1-1314(5)(b) carry no volume test at all: a controller that controls or is controlled by another controller and shares common branding with it, and a joint venture or partnership of no more than two businesses that share consumers' personal data with each other.
Consent and Disclosure Requirements
HB24-1130 prohibits a controller from collecting a biometric identifier unless it first provides notice and obtains consent from the consumer. The notice must include:
- The specific purpose for collecting the biometric identifier
- The retention period for the biometric data
- Whether the controller will disclose the biometric identifier to any third party
This consent must be affirmative, freely given, specific, informed, and unambiguous. Broad terms-of-service acceptance does not qualify. The controller cannot bury consent in fine print or use deceptive design patterns to obtain it.

Controllers also face restrictions on what they can do with biometric identifiers once collected, and the statute treats selling and disclosing very differently. C.R.S. § 6-1-1314(4)(b)(I) flatly bars a controller that processes a consumer's biometric identifier from selling, leasing, or trading that identifier with any entity. No exception attaches to that ban, so a consumer cannot consent their way around it.
Disclosure is the narrower prohibition. Under § 6-1-1314(4)(b)(II), a controller cannot disclose, redisclose, or otherwise disseminate a biometric identifier unless the consumer or the consumer's legally authorized representative consents, the consumer requests or authorizes the disclosure for the purpose of completing a financial transaction, the disclosure is to a processor and is necessary for the purpose the consumer consented to, or state or federal law requires it.
Purchasing biometric identifiers from another party is also restricted. A controller cannot purchase biometric data unless it pays the consumer, obtains consent, and the purchase is unrelated to providing the controller's products or services.
Written Policy Requirements
Any controller that controls or processes biometric identifiers must adopt a written policy covering:
- Retention schedule: How long biometric identifiers and biometric data will be stored
- Security incident protocol: Steps for responding to a data breach that may compromise biometric information
- Deletion guidelines: When and how biometric identifiers will be permanently destroyed
Controllers must make this written policy publicly available. There are limited exceptions: policies that apply only to current employees or that contain internal incident response protocols do not need to be published.
These written policies are not optional. They must be in place before the controller begins collecting biometric identifiers. The Colorado Attorney General has rulemaking authority to set additional standards for what these policies must contain.
Retention and Destruction Timelines
HB24-1130 sets clear deadlines for destroying biometric identifiers. Controllers must permanently destroy a biometric identifier by the earliest of three dates:
- Purpose satisfied: The date when the initial purpose for collecting the biometric identifier has been fulfilled
- 24 months of inactivity: Twenty-four months after the consumer last interacted with the controller
- Earliest feasible date: No more than 45 days after a controller determines through an annual review that storing the biometric identifier is no longer necessary or relevant to the stated processing purpose
If the volume or complexity of biometric data makes the 45-day window impractical, the controller may extend it by up to 45 additional days. That means the absolute maximum extension is 90 days from the date the controller determines the data is no longer needed.
Controllers must conduct annual reviews to identify biometric identifiers eligible for deletion. This is not a suggestion. The statute requires it as part of the written policy.
Employer-Specific Protections
HB24-1130 contains some of the strongest employer-specific biometric protections in the country. The law draws a sharp line between what employers can and cannot require.
Permitted uses as a condition of employment:
An employer may require biometric consent as a condition of employment only for these limited purposes:
- Accessing a secure facility or secure hardware (excluding location tracking or monitoring application usage time)
- Recording the start and end times of the workday
- Improving workplace safety or security
- Protecting public safety during emergencies
Prohibited employer conduct:
For any biometric use outside those four categories, an employer cannot require an employee or prospective employee to consent as a condition of employment. Employers also cannot retaliate against any employee or job applicant who refuses to provide biometric consent.

The law broadly defines "employee" to include full-time, part-time, on-call workers, contractors, interns, and fellows. This is significant because the CPA's general provisions historically excluded employment-context personal data. HB24-1130 carves into that exemption to bring biometric protections into the workplace.
If an employer collects fingerprints for a time clock, that falls within the permitted uses. If the same employer wants to use facial recognition to track how long employees spend in certain areas of the building, that requires separate, voluntary consent and cannot be a condition of continued employment.
How HB24-1130 Interacts With the CPA
The Colorado Privacy Act and HB24-1130 work as layered protections, not alternatives. Here is how the two laws interact:
CPA baseline (effective July 1, 2023): Biometric data used to identify an individual qualifies as sensitive data under C.R.S. § 6-1-1303(24). Controllers must obtain affirmative consent before processing any sensitive data. Consumers have the right to access, correct, delete, and port their biometric data. Data protection assessments are required before processing sensitive data.
HB24-1130 additions (effective July 1, 2025): On top of the CPA baseline, controllers processing biometric identifiers must adopt written policies, follow specific retention and destruction schedules, meet heightened disclosure requirements before collection, comply with restrictions on selling or trading biometric data, and follow employer-specific consent rules.
A controller that processes biometric data in Colorado must comply with both sets of requirements simultaneously. The CPA provides the broad sensitive-data framework, and HB24-1130 adds biometric-specific detail.
Consumer Rights for Biometric Data
Colorado residents have several rights over their biometric information under the combined CPA and HB24-1130 framework:
- Right to know: Consumers can ask whether a controller collects their biometric data and what categories are collected
- Right to access: Consumers can request a copy of their biometric data, though this specific right under C.R.S. § 6-1-1314(5) reaches only certain controllers: those that collect or process the personal data of 100,000 or more individuals in a calendar year (or 25,000 or more while earning revenue from selling personal data), plus commonly branded affiliated controllers and two-business joint ventures that share consumer data, which face no volume test; other controllers still owe consent, notice, and retention duties
- Right to correct: Consumers can ask a controller to fix inaccurate biometric information
- Right to delete: Consumers can request deletion of their biometric identifiers
- Right to data portability: Consumers can download and transfer their biometric data in a portable format
- Right to opt out: The CPA gives consumers a general right to opt out of the sale of personal data and of targeted advertising. For biometric identifiers, the law goes further than an opt-out: § 6-1-1314(4)(b)(I) bars a controller from selling, leasing, or trading them at all
Controllers must respond to consumer rights requests and cannot discriminate against consumers who exercise these rights.
Penalties and Enforcement
HB24-1130 does not create a private right of action. Individual consumers cannot file lawsuits for violations of Colorado's biometric privacy laws. Enforcement authority rests exclusively with the Colorado Attorney General and district attorneys.
Violations of the CPA, including the biometric provisions, are treated as deceptive trade practices under C.R.S. § 6-1-112. Penalties include:
- Up to $20,000 per violation for standard violations
- Up to $50,000 per violation when the victim is 60 years of age or older
- No statutory cap on aggregate penalties. Colorado once capped a related series of violations at $500,000, but HB19-1289 struck that aggregate cap when it raised the per-violation maximums, effective May 23, 2019. The per-violation maximum above is now the only statutory ceiling.

An important enforcement change took effect on January 1, 2025: the 60-day cure period that previously gave businesses a chance to fix violations before facing penalties is no longer required. The Attorney General and district attorneys now have discretion to pursue enforcement actions immediately.
The AG also has rulemaking authority under HB24-1130 to issue rules implementing the biometric provisions. The Colorado Department of Law adopted amendments to the CPA Rules (4 CCR 904-3) in December 2024, with biometric-related rules taking effect alongside HB24-1130 on July 1, 2025. These rules require biometric notices to be "concrete and definitive," clearly labeled within privacy policies, and provided before collection or material processing changes.
How Colorado Compares to Illinois BIPA
Colorado's biometric privacy law is often compared to the Illinois Biometric Information Privacy Act (BIPA), the most aggressive biometric privacy statute in the country. The key differences:
| Feature | Colorado (HB24-1130 + CPA) | Illinois (BIPA) |
|---|---|---|
| Private right of action | No | Yes |
| Statutory damages | None (AG penalties only) | $1,000-$5,000 per violation |
| Consent required | Yes | Yes |
| Written policy required | Yes | Yes |
| Employer restrictions | Detailed, with specific permitted uses | General consent requirement |
| Retention timeline | 24 months or purpose satisfied | 3 years or purpose satisfied |
| Scope threshold | None for biometrics | None |
The lack of a private right of action is the most significant difference. Illinois BIPA has generated hundreds of class-action lawsuits. Colorado's enforcement-only model means the AG decides which cases to pursue.
However, Colorado's employer-specific protections are more detailed than Illinois BIPA's. The explicit list of permitted employment uses and the anti-retaliation provision give Colorado employees clearer protections in the workplace.

This article is for informational purposes only and does not constitute legal advice. Biometric privacy laws and enforcement interpretations change over time. Consult a licensed attorney in Colorado for advice about your specific situation. Last reviewed: March 2026.
More Colorado Laws
Frequently Asked Questions
When did Colorado's biometric privacy law take effect?
HB24-1130 took effect on July 1, 2025. The Colorado Privacy Act, which classifies biometric data as sensitive data, has been in effect since July 1, 2023. Both laws apply simultaneously to organizations processing biometric data from Colorado residents.
Can my employer require me to use a fingerprint scanner in Colorado?
It depends on the purpose. Under HB24-1130, employers may require biometric consent as a condition of employment only for secure facility access, recording work start and end times, workplace safety monitoring, or public safety emergencies. For any other biometric use, consent must be voluntary, and employers cannot retaliate against employees who refuse.
Does Colorado's biometric law allow individuals to sue for violations?
No. Colorado does not provide a private right of action for biometric privacy violations. Only the Colorado Attorney General and district attorneys can enforce the law. Penalties reach up to $20,000 per violation for standard cases and up to $50,000 per violation when the victim is 60 or older.
How long can a company keep my biometric data in Colorado?
A controller must permanently destroy biometric identifiers by the earliest of three dates: when the original collection purpose is satisfied, 24 months after your last interaction with the controller, or 45 days after the controller determines through an annual review that the data is no longer necessary. An extension of up to 45 additional days is allowed for complex deletions.
Who must comply with Colorado's biometric privacy requirements?
Any controller that processes biometric identifiers from Colorado residents must comply with HB24-1130's consent, notice, written-policy, and retention duties, regardless of the number of consumers whose data it handles. This is broader than the general CPA, which requires processing data of at least 100,000 Colorado residents. One right is an exception: the biometric-specific right to access under C.R.S. § 6-1-1314(5) reaches a narrower set of controllers, mainly those that collect or process the personal data of 100,000 or more individuals in a calendar year (or 25,000 or more while earning revenue from selling personal data), along with commonly branded affiliated controllers and two-business joint ventures that share consumer data, which face no volume test.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the biometric sale rule to reflect that Colorado bars selling, leasing, or trading biometric identifiers outright rather than permitting it with consent, fixed the bill and date credited with removing the $500,000 penalty cap, replaced an inaccurate description of the HB24-1130 vote, and clarified which controllers owe the biometric right of access.
Corrected the maximum civil-penalty figures for biometric privacy violations (removed a $500,000 aggregate cap that was repealed in 2023 and now has no ceiling) and clarified that HB24-1130's no-volume-threshold rule does not extend to the biometric right-to-access, which still requires a controller to meet Colorado's standard 100,000/25,000-resident thresholds.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Colorado Revised Statutes, Title 6: Consumer and Commercial Affairs
§ 6-1-1314Biometric data and biometric identifiers - controllers - duties and requirements - written policy - prohibited acts - right to correct biometric identifiers - right to access biometric identifiers - remedies and civil actions - rules - definitionsIn force
(1) As used in this section, unless the context otherwise requires: (a) Collect, collection, or collecting means to access, assemble, buy, rent, gather, procure, receive, capture, or otherwise obtain any biometric identifier or biometric data pertaining to a consumer by any means, online or offline, including: (I) Actively or passively receiving a biometric identifier or biometric data from the consumer or from a third party; and (II) Obtaining biometric data by observing the consumer's behavior. (b) Employee means an individual who is employed full-time, part-time, or on-call or who is hired as a contractor, subcontractor, intern, or fellow. (c) Legally authorized representative means a parent or legal guardian of a minor or a legal guardian of an adult. (2) Written policy required.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at olls.info
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- HB24-1130 Privacy of Biometric Identifiers & Data(leg.colorado.gov).gov
- Colorado Privacy Act (SB21-190)(leg.colorado.gov).gov
- Colorado Attorney General - Colorado Privacy Act(coag.gov).gov
- Colorado Attorney General - Consumer Data Protection Laws FAQ(coag.gov).gov
- 2025 Colorado Privacy Act Rulemaking(coag.gov).gov
- Colorado AG Launches CPA Enforcement(coag.gov).gov
- HB19-1289 Consumer Protection Act Penalties(leg.colorado.gov).gov
- Colorado CPA Final Rules (4 CCR 904-3)(coag.gov).gov
- 2024 Proposed Amendments to CPA Rules(coag.gov).gov
- Colorado HB24-1130 Enrolled Act (signed) - text of C.R.S. 6-1-1314(content.leg.colorado.gov)
- Colorado Revised Statutes 2025, Title 6 (Office of Legislative Legal Services)(olls.info)