EnglishEspañol
Colorado flag

Colorado

Colorado Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 9 primary sources cited on this page. How we verify our legal content

Colorado Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

When did Colorado's biometric privacy law take effect?

HB24-1130 took effect on July 1, 2025. The Colorado Privacy Act, which classifies biometric data as sensitive data, has been in effect since July 1, 2023. Both laws apply simultaneously to organizations processing biometric data from Colorado residents.

Can my employer require me to use a fingerprint scanner in Colorado?

It depends on the purpose. Under HB24-1130, employers may require biometric consent as a condition of employment only for secure facility access, recording work start and end times, workplace safety monitoring, or public safety emergencies. For any other biometric use, consent must be voluntary, and employers cannot retaliate against employees who refuse.

Does Colorado's biometric law allow individuals to sue for violations?

No. Colorado does not provide a private right of action for biometric privacy violations. Only the Colorado Attorney General and district attorneys can enforce the law. Penalties reach up to $20,000 per violation for standard cases and up to $50,000 per violation when the victim is 60 or older.

How long can a company keep my biometric data in Colorado?

A controller must permanently destroy biometric identifiers by the earliest of three dates: when the original collection purpose is satisfied, 24 months after your last interaction with the controller, or 45 days after the controller determines through an annual review that the data is no longer necessary. An extension of up to 45 additional days is allowed for complex deletions.

Who must comply with Colorado's biometric privacy requirements?

Any controller that processes biometric identifiers from Colorado residents must comply with HB24-1130's consent, notice, written-policy, and retention duties, regardless of the number of consumers whose data it handles. This is broader than the general CPA, which requires processing data of at least 100,000 Colorado residents. One right is an exception: the biometric-specific right to access under C.R.S. § 6-1-1314(5) reaches a narrower set of controllers, mainly those that collect or process the personal data of 100,000 or more individuals in a calendar year (or 25,000 or more while earning revenue from selling personal data), along with commonly branded affiliated controllers and two-business joint ventures that share consumer data, which face no volume test.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the biometric sale rule to reflect that Colorado bars selling, leasing, or trading biometric identifiers outright rather than permitting it with consent, fixed the bill and date credited with removing the $500,000 penalty cap, replaced an inaccurate description of the HB24-1130 vote, and clarified which controllers owe the biometric right of access.

Corrected the maximum civil-penalty figures for biometric privacy violations (removed a $500,000 aggregate cap that was repealed in 2023 and now has no ceiling) and clarified that HB24-1130's no-volume-threshold rule does not extend to the biometric right-to-access, which still requires a controller to meet Colorado's standard 100,000/25,000-resident thresholds.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. HB24-1130 Privacy of Biometric Identifiers & Data(leg.colorado.gov).gov
  2. Colorado Privacy Act (SB21-190)(leg.colorado.gov).gov
  3. Colorado Attorney General - Colorado Privacy Act(coag.gov).gov
  4. Colorado Attorney General - Consumer Data Protection Laws FAQ(coag.gov).gov
  5. 2025 Colorado Privacy Act Rulemaking(coag.gov).gov
  6. Colorado AG Launches CPA Enforcement(coag.gov).gov
  7. HB19-1289 Consumer Protection Act Penalties(leg.colorado.gov).gov
  8. Colorado CPA Final Rules (4 CCR 904-3)(coag.gov).gov
  9. 2024 Proposed Amendments to CPA Rules(coag.gov).gov
  10. Colorado HB24-1130 Enrolled Act (signed) - text of C.R.S. 6-1-1314(content.leg.colorado.gov)
  11. Colorado Revised Statutes 2025, Title 6 (Office of Legislative Legal Services)(olls.info)
Share: