Colorado Data Privacy Rights: CPA Guide for Data Broker Opt-Outs (2026)
Colorado Privacy Act guide covering universal opt-out signals, consumer rights, deletion requests, appeals, and data-broker obligations.
The Colorado Privacy Act (CPA) gives covered Colorado consumers rights that can include access, correction, deletion, portability, and opt-outs for certain processing. A data-broker request still depends on the business, data, purpose, verification, exemptions, and the exact route.
This guide is an evidence-first overview, not legal advice. Start with the Colorado Attorney General's CPA resources and official opt-out guidance before relying on a current rule or signal.
Quick answer
- A covered Colorado consumer may have a right to delete personal data, subject to the CPA's scope and exceptions.
- The Colorado AG's current universal-opt-out page lists Global Privacy Control (GPC) as the only mechanism it currently recognizes; that list can change. The mechanism applies to certain covered sale and targeted-advertising processing, not historical deletion.
- The Global Privacy Control (GPC) is a browser signal for an opt-out preference; it does not erase historical people-search profiles or public records.
- The CPA includes an appeal process when a covered request is denied. Preserve the denial and follow the provider's current appeal instructions.
- A Colorado request does not automatically cover every brand, source, search result, or downstream copy.
Rights under the CPA
Depending on the controller, consumer, data, and request, the CPA can provide rights to:
- access personal data;
- correct inaccuracies;
- delete personal data;
- obtain portability in some circumstances; and
- opt out of targeted advertising, sale of personal data, or certain profiling.
The statute and implementing rules contain thresholds, definitions, verification requirements, exceptions, and controller duties. Do not assume a public people-search page is within the same category as a covered controller without checking the facts.
Exercise your statutory data deletion rights
Review source-aware privacy-rights request drafts directly in your browser. Send or submit each request yourself after checking the provider route and applicable law.
GPC and universal opt-out signals
Colorado's official materials describe universal opt-out mechanisms. A browser sending GPC may communicate an opt-out preference to a covered business, but:
- the signal concerns activities such as sale, targeted advertising, or certain processing, not historical deletion;
- the controller and processing must fall within the applicable scope;
- browser configuration, extensions, and consent choices can affect whether the signal is sent; and
- a provider may still need a separate deletion or correction request for an existing profile.
Use the Colorado AG's current opt-out instructions and test the signal on the provider if the site supplies a way to confirm its status. Do not describe GPC as a universal deletion command.
How to make a Colorado request
1. Confirm the provider and record
Search your name, location, phone, email, and workplace. Save the exact provider URL and date, and verify the profile using multiple non-sensitive details.
2. Use the provider's current route
Read the privacy notice and select deletion, correction, access, opt-out, or appeal as appropriate. Provider routes can differ by product and brand.
3. Minimize the data submitted
Provide only identifiers reasonably needed for matching and verification. Treat government IDs, utility bills, full birth dates, and account credentials as sensitive. Ask for a less intrusive alternative if the requested document is unclear.
4. Preserve evidence
Keep the request, confirmation, response, verification, and dated source re-check. Do not treat an acknowledgement or dashboard status as proof that a live source changed.
5. Appeal a denial
If the provider denies a covered request, follow its current internal appeal route and keep the dates. If the issue remains unresolved, consult the Colorado AG's complaint or enforcement instructions.
Response and appeal timing
The CPA and its rules provide response and appeal requirements, but the clock, extension, verification, request type, and exception matter. The Colorado AG currently describes a 45-day response period for a request made through the method in the company's privacy notice, with a possible additional 45 days when reasonably necessary and with notice and reasons for the delay. That is a response period, not a deletion deadline. Check the current statutory text, rules, and provider notice instead of copying a fixed deadline into every request.
For your tracker, record:
| Event | Evidence |
|---|---|
| Request submitted | Date, route, and request type |
| Verification | Method and completion |
| Response | Provider answer and stated reason |
| Appeal | Date, grounds, and response |
| Source re-check | Exact URL and observed status |
What Colorado rights do not automatically do
A CPA request or GPC signal does not automatically:
- erase the original court, property, or government record;
- remove a search-engine result while the source remains live;
- cover a provider that is outside the statute's scope;
- force a related brand to use the same suppression list; or
- guarantee that an inferred or legally retained field will be deleted.
How OfflistMe fits
OfflistMe can show a recorded provider route and prepare a browser-local draft for user review and sending. Its public catalog contains 1,034 recorded workflow profiles within a 1,052-record research catalog. These are catalog and research counts, not Colorado legal coverage, live profile matches, or outcome rates.
You decide what to send, use the current provider route, complete verification, and keep the evidence. OfflistMe does not submit a GPC signal, determine CPA applicability, or guarantee provider action.
Frequently asked questions
Does GPC delete my data from Colorado data brokers?
No. It communicates a preference for certain ongoing processing. Use a separate deletion or correction request for an existing profile when appropriate.
Do all Colorado businesses have to honor GPC?
The CPA and current official guidance determine which covered businesses and processing activities are in scope. Check the AG's current materials and the provider's behavior; do not assume every website is covered.
What if a provider denies my deletion request?
Save the denial and use the provider's internal appeal process where the CPA requires one. Then consult the Colorado AG if the issue remains within its jurisdiction.
Is the CPA a nationwide law?
No. Colorado rights apply within their statutory scope. A provider may offer a broader voluntary process, but that is not the same as Colorado law.
How long does a Colorado request take?
Use the current law, rules, provider notice, and request record. Provider processing, response, source changes, and search indexing are separate clocks.
Sources
- Colorado Attorney General: Colorado Privacy Act
- Colorado Attorney General: Opt-out mechanisms
- Colorado Attorney General: CPA rulemaking and amendments
- Colorado General Assembly: 2026 Colorado Revised Statutes titles
- Global Privacy Control specification
Reviewed August 26, 2026. Verify the current Colorado rules, AG guidance, provider route, and GPC behavior before relying on this guide.
Example: separating a GPC signal from deletion
Suppose a Colorado resident visits a marketing site with GPC enabled and later finds an older people-search profile. The signal may communicate an opt-out preference for covered sale or targeted-advertising processing at the site. It does not establish that the older profile was deleted, that a separate publisher received the signal, or that the original public record changed. The resident should preserve the profile URL, read the publisher's privacy notice, and decide whether a separate deletion or correction request is appropriate.
This distinction is useful for audits: record the signal status, request status, provider response, and source re-check as separate evidence fields. Never mark a historical profile as removed merely because a browser sent GPC.
How to document a Colorado request
Use a private record with the provider name, exact profile URL, date, request type, jurisdictional basis, information submitted, verification step, response, appeal deadline if any, and the date of the next source check. Keep the record separate from public analytics and do not include unnecessary personal values in a shared document. If a provider asks for more information than appears reasonably necessary, pause and read its privacy notice and official request instructions before continuing.
When reviewing the result, distinguish a provider acknowledgement from a completed action. A confirmation email may show that a request entered a workflow; it does not by itself show that every copy, related brand, search result, or upstream record changed. Record what the provider actually said and what you could independently observe. This evidence makes an appeal or regulator inquiry more precise without overstating what Colorado law requires.
Related guides
Understand your privacy rights
Where a privacy right is relevant, these plain-English explainers show what each law covers and what to verify before making a request.
Take back your privacy today
Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.
Review Provider RoutesFree to review provider routes · Optional one-time unlock from $9.00 · No subscription
