Skip to main content
Privacy Law & Rights
7 min read

Colorado Data Privacy Rights: CPA Guide for Data Broker Opt-Outs (2026)

Colorado Privacy Act guide covering universal opt-out signals, consumer rights, deletion requests, appeals, and data-broker obligations.

Rahul Kandoriya
Written byRahul Kandoriya·Last updated August 26, 2026
Colorado Data Privacy Rights: CPA Guide for Data Broker Opt-Outs (2026)
Colorado Data Privacy Rights: CPA Guide for Data Broker Opt-Outs (2026)
Coverage scope: The OfflistMe catalog currently records 1,000+data-broker workflows. Paid access lets you select workflows at once; you review and send or submit the generated requests, while provider eligibility and outcomes remain outside OfflistMe's control.

The Colorado Privacy Act (CPA) gives covered Colorado consumers rights that can include access, correction, deletion, portability, and opt-outs for certain processing. A data-broker request still depends on the business, data, purpose, verification, exemptions, and the exact route.

This guide is an evidence-first overview, not legal advice. Start with the Colorado Attorney General's CPA resources and official opt-out guidance before relying on a current rule or signal.

Quick answer

  • A covered Colorado consumer may have a right to delete personal data, subject to the CPA's scope and exceptions.
  • The Colorado AG's current universal-opt-out page lists Global Privacy Control (GPC) as the only mechanism it currently recognizes; that list can change. The mechanism applies to certain covered sale and targeted-advertising processing, not historical deletion.
  • The Global Privacy Control (GPC) is a browser signal for an opt-out preference; it does not erase historical people-search profiles or public records.
  • The CPA includes an appeal process when a covered request is denied. Preserve the denial and follow the provider's current appeal instructions.
  • A Colorado request does not automatically cover every brand, source, search result, or downstream copy.

Rights under the CPA

Depending on the controller, consumer, data, and request, the CPA can provide rights to:

  • access personal data;
  • correct inaccuracies;
  • delete personal data;
  • obtain portability in some circumstances; and
  • opt out of targeted advertising, sale of personal data, or certain profiling.

The statute and implementing rules contain thresholds, definitions, verification requirements, exceptions, and controller duties. Do not assume a public people-search page is within the same category as a covered controller without checking the facts.

Request Drafting

Exercise your statutory data deletion rights

Review source-aware privacy-rights request drafts directly in your browser. Send or submit each request yourself after checking the provider route and applicable law.

Start Free Statutory Opt-Out Free for selected workflows · No opt-out profile stored · No card needed

GPC and universal opt-out signals

Colorado's official materials describe universal opt-out mechanisms. A browser sending GPC may communicate an opt-out preference to a covered business, but:

  • the signal concerns activities such as sale, targeted advertising, or certain processing, not historical deletion;
  • the controller and processing must fall within the applicable scope;
  • browser configuration, extensions, and consent choices can affect whether the signal is sent; and
  • a provider may still need a separate deletion or correction request for an existing profile.

Use the Colorado AG's current opt-out instructions and test the signal on the provider if the site supplies a way to confirm its status. Do not describe GPC as a universal deletion command.

How to make a Colorado request

1. Confirm the provider and record

Search your name, location, phone, email, and workplace. Save the exact provider URL and date, and verify the profile using multiple non-sensitive details.

2. Use the provider's current route

Read the privacy notice and select deletion, correction, access, opt-out, or appeal as appropriate. Provider routes can differ by product and brand.

3. Minimize the data submitted

Provide only identifiers reasonably needed for matching and verification. Treat government IDs, utility bills, full birth dates, and account credentials as sensitive. Ask for a less intrusive alternative if the requested document is unclear.

4. Preserve evidence

Keep the request, confirmation, response, verification, and dated source re-check. Do not treat an acknowledgement or dashboard status as proof that a live source changed.

5. Appeal a denial

If the provider denies a covered request, follow its current internal appeal route and keep the dates. If the issue remains unresolved, consult the Colorado AG's complaint or enforcement instructions.

Response and appeal timing

The CPA and its rules provide response and appeal requirements, but the clock, extension, verification, request type, and exception matter. The Colorado AG currently describes a 45-day response period for a request made through the method in the company's privacy notice, with a possible additional 45 days when reasonably necessary and with notice and reasons for the delay. That is a response period, not a deletion deadline. Check the current statutory text, rules, and provider notice instead of copying a fixed deadline into every request.

For your tracker, record:

EventEvidence
Request submittedDate, route, and request type
VerificationMethod and completion
ResponseProvider answer and stated reason
AppealDate, grounds, and response
Source re-checkExact URL and observed status

What Colorado rights do not automatically do

A CPA request or GPC signal does not automatically:

  • erase the original court, property, or government record;
  • remove a search-engine result while the source remains live;
  • cover a provider that is outside the statute's scope;
  • force a related brand to use the same suppression list; or
  • guarantee that an inferred or legally retained field will be deleted.

How OfflistMe fits

OfflistMe can show a recorded provider route and prepare a browser-local draft for user review and sending. Its public catalog contains 1,034 recorded workflow profiles within a 1,052-record research catalog. These are catalog and research counts, not Colorado legal coverage, live profile matches, or outcome rates.

You decide what to send, use the current provider route, complete verification, and keep the evidence. OfflistMe does not submit a GPC signal, determine CPA applicability, or guarantee provider action.

Review the directory →

Frequently asked questions

Does GPC delete my data from Colorado data brokers?

No. It communicates a preference for certain ongoing processing. Use a separate deletion or correction request for an existing profile when appropriate.

Do all Colorado businesses have to honor GPC?

The CPA and current official guidance determine which covered businesses and processing activities are in scope. Check the AG's current materials and the provider's behavior; do not assume every website is covered.

What if a provider denies my deletion request?

Save the denial and use the provider's internal appeal process where the CPA requires one. Then consult the Colorado AG if the issue remains within its jurisdiction.

Is the CPA a nationwide law?

No. Colorado rights apply within their statutory scope. A provider may offer a broader voluntary process, but that is not the same as Colorado law.

How long does a Colorado request take?

Use the current law, rules, provider notice, and request record. Provider processing, response, source changes, and search indexing are separate clocks.

Sources

Reviewed August 26, 2026. Verify the current Colorado rules, AG guidance, provider route, and GPC behavior before relying on this guide.

Example: separating a GPC signal from deletion

Suppose a Colorado resident visits a marketing site with GPC enabled and later finds an older people-search profile. The signal may communicate an opt-out preference for covered sale or targeted-advertising processing at the site. It does not establish that the older profile was deleted, that a separate publisher received the signal, or that the original public record changed. The resident should preserve the profile URL, read the publisher's privacy notice, and decide whether a separate deletion or correction request is appropriate.

This distinction is useful for audits: record the signal status, request status, provider response, and source re-check as separate evidence fields. Never mark a historical profile as removed merely because a browser sent GPC.

How to document a Colorado request

Use a private record with the provider name, exact profile URL, date, request type, jurisdictional basis, information submitted, verification step, response, appeal deadline if any, and the date of the next source check. Keep the record separate from public analytics and do not include unnecessary personal values in a shared document. If a provider asks for more information than appears reasonably necessary, pause and read its privacy notice and official request instructions before continuing.

When reviewing the result, distinguish a provider acknowledgement from a completed action. A confirmation email may show that a request entered a workflow; it does not by itself show that every copy, related brand, search result, or upstream record changed. Record what the provider actually said and what you could independently observe. This evidence makes an appeal or regulator inquiry more precise without overstating what Colorado law requires.

Related guides

Take back your privacy today

Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.

Review Provider Routes

Free to review provider routes · Optional one-time unlock from $9.00 · No subscription