Orange textured background

US state law

CPA and browser fingerprinting

How the Colorado Privacy Act and its 4 CCR 904-3 rules treat device fingerprinting, the Universal Opt-Out Mechanism the AG actively enforces, and where Colorado is the strictest US state law that follows the Virginia template.

Reviewed

RegionColorado, USA
RegulatorColorado Attorney General + District Attorneys
Effective1 July 2023
Max penaltyUp to $20,000 per violation in civil penalties (C.R.S. §6-1-112)
Status in-force

What CPA says about fingerprinting

The Colorado Privacy Act took effect on 1 July 2023 and is codified at C.R.S. §6-1-1301 through §6-1-1313. Like every state law in the 'Virginia cluster', it does not mention 'fingerprinting' by name, but C.R.S. §6-1-1303(17) defines personal data as 'information that is linked or reasonably linkable to an identified or identifiable individual'. A browser or device fingerprint hash satisfies that test the moment a controller uses it to recognise a returning Colorado consumer.

What sets Colorado apart is what came after the statute: the Colorado AG published implementing rules at 4 CCR 904-3 in March 2023, then revised them substantively in 2024 and 2025. The rules are unusually specific. Rule 2.02 explicitly names 'browser-level signals' as personal data. Rule 5.07 makes the Universal Opt-Out Mechanism the operational backbone of the opt-out right. Rule 8.01 to 8.06 spells out exactly what a Data Protection Assessment must contain. Where VCDPA leaves controllers to interpret statutory language, CPA tells them in regulator-published prose.

The practical consequence: fingerprinting compliance in Colorado is less about reading the statute and more about reading the rules. Any Benny deployment intended to serve Colorado consumers should be architected to the 4 CCR 904-3 specifications, not to the C.R.S. §6-1-1300 statutory text alone.

When CPA applies to you

Section 6-1-1304 applies the statute to controllers that conduct business in Colorado or produce products or services intentionally targeted to Colorado residents, and either (a) control or process the personal data of 100,000 or more Colorado consumers in a calendar year, or (b) derive revenue or receive a discount from the sale of personal data AND process the personal data of 25,000 or more Colorado consumers.

The second leg is where Colorado is broader than Virginia. VCDPA's 25,000-consumer leg requires more than 50% of gross revenue from selling personal data. CPA only requires any revenue from sale. A small ad-tech vendor that earns 5% of its revenue from selling fingerprint-derived audiences and processes 30,000 Colorado consumers falls inside CPA but outside VCDPA.

Consumer is defined at C.R.S. §6-1-1303(6) as a Colorado resident acting in an individual or household context. Employees and B2B contacts are excluded, matching the rest of the cluster.

The opt-out triggers and how they apply to fingerprinting

C.R.S. §6-1-1306 grants Colorado consumers five rights: access, correction, deletion, portability, and opt-out. The opt-out right divides into three categories of processing, all of which intersect with fingerprinting in ways that matter operationally.

Targeted advertising under C.R.S. §6-1-1303(25) means displaying advertisements selected based on personal data obtained from the consumer's activities over time across non-affiliated websites, applications, or online services. Recognising a returning visitor by their fingerprint and serving them ads selected from cross-site behaviour is the canonical case. First-party retargeting on your own domain, frequency capping, and contextual advertising are excluded.

Sale of personal data under CPA is defined at C.R.S. §6-1-1303(23) as the exchange of personal data for monetary or other valuable consideration by the controller to a third party. The 'or other valuable consideration' clause makes CPA's sale definition broader than VCDPA's monetary-only definition. Sharing fingerprint hashes with an ad-tech partner for mutual lift, even without a direct dollar payment, is more likely to qualify as sale in Colorado than in Virginia.

Profiling under §6-1-1303(20) covers any form of automated processing performed on personal data to evaluate, analyse, or predict personal aspects related to an individual. The opt-out applies when profiling produces 'legal or similarly significant effects'. The AG's rules at 4 CCR 904-3 Rule 9 list the qualifying decision categories: financial services, housing, insurance, education, criminal justice, employment, healthcare, and 'essential goods or services'.

Common fingerprinting purposes under CPA

PurposePersonal data?DPA required (4 CCR 904-3 Rule 8)?Opt-out right applies?
Anti-fraud at login or paymentYesNo (not 'heightened risk' under Rule 8.04)No
Account-takeover detectionYesNoNo
Bot mitigation on a public formYesNoNo
Cross-site targeted advertisingYesYesYes (UOOM + on-site opt-out both required)
Sharing fingerprint hashes with an ad-tech partnerYesYesYes (likely sale under the 'other valuable consideration' clause)
Profiling for credit / insurance / employmentYesYesYes (any of Rule 9's listed decision categories)
Product analytics on your own serviceYesNoNo
Frequency capping on your own siteYesNoNo (first-party carve-out)

Data Protection Assessments under 4 CCR 904-3 Rule 8

Rule 8 of the Colorado AG's regulations is the most detailed DPA prescription in any US state law. It requires the assessment to identify the processing activity, document the categories of personal data, name the recipients, evaluate the risks to consumers, identify mitigations, and explicitly weigh the benefits against the residual risks. The assessment must be retained for at least three years and made available to the AG on request.

For a fingerprinting deployment used to power targeted advertising, an adequate Rule 8 assessment names the signal categories collected from the device, the hash construction, the retention window, the recipients (your ad-tech partners), the de-identification claim if any, and the operational controls that honour both the on-site opt-out and the UOOM. Rule 8.05 specifically permits one assessment to cover a 'comparable set' of processing activities, which means a single assessment can defensibly cover the entire Benny deployment for the targeted-advertising flow.

The cure period is gone

CPA originally included a 30-day right to cure after the AG issued a notice of violation. Section 6-1-1311(d) terminated that right on 1 July 2025. As of that date, the AG can initiate enforcement immediately upon identifying a violation. The AG's office has publicly stated that pre-1-July-2025 violations may still benefit from cure if the controller acted promptly, but post-sunset violations are first-strike.

Practically, this changes the operational posture for Colorado deployments. There is no longer a window to fix a missed UOOM check, a missing DPA, or an unscoped fingerprint-for-targeted-ads pipeline after the AG identifies it. The 'fix it when we get the letter' compliance model that worked in 2023 and 2024 no longer applies in Colorado.

Enforcement to date

  • The Colorado AG's Privacy Unit has been the most publicly active of any state attorney general under a Virginia-cluster law, issuing multiple formal opinions and informal guidance letters since 2023.
  • Early enforcement has emphasised missed UOOM handling, the AG has cited several controllers (publicly named or pseudonymised, depending on settlement terms) for fingerprinting scripts that fired before checking GPC headers.
  • DPA failures are the second-most-cited issue. Multiple settlements have included orders to produce and retain Rule 8-compliant assessments going forward.
  • Per-violation calculation has been controller-favourable so far: the AG has generally counted distinct processing activities rather than per-consumer instances when setting penalty amounts. This may tighten as the cure period sunset bites.

Territorial reach and the small-business question

CPA reaches any controller that conducts business in Colorado or that intentionally targets products or services to Colorado residents and meets one of the two thresholds. There is no carve-out for businesses based outside the United States; a fintech in Bangalore or a SaaS in London that meets the consumer-count threshold for Colorado consumers owes CPA obligations on that subset of its user base.

Unlike Utah's UCPA, Colorado does not exempt small businesses by revenue size. The 100,000-consumer or 25,000-with-any-sale-revenue thresholds apply equally to a 12-person startup and a 12,000-person enterprise.

How Benny the Doorman fits into a CPA-aware deployment

Benny is a fingerprinting SDK; Colorado's UOOM requirement is the architectural constraint that drives the integration shape. Three steps for a CPA-aware deployment.

First, install a GPC header check upstream of every Benny call used for targeted advertising or sale-flagged purposes. The check belongs at the application layer, not in Benny, Benny is engineered to be invoked once the controller has decided the processing is permitted.

Second, produce a Rule 8 Data Protection Assessment for each purpose listed in §6-1-1309 before going live. Benny's documentation enumerates the signal categories, the hash construction, the default retention window, and the per-call data flow, exactly the technical detail Rule 8.02 requires the assessment to capture.

Third, separate the regulated fingerprint flow from the anti-fraud flow at the architecture level. The §6-1-1306 opt-out (and the UOOM signal) must be honoured on the regulated flow without breaking the anti-fraud flow, which sits in the strictly-necessary lane and is not subject to the opt-out.

Frequently asked questions

Is browser fingerprinting illegal under the Colorado Privacy Act?

No. Fingerprinting is regulated as personal data when the fingerprint can be linked back to a Colorado consumer. Lawful use requires honouring the Universal Opt-Out Mechanism for targeted advertising and sale, completing a Data Protection Assessment under 4 CCR 904-3 Rule 8 before deploying fingerprinting for those purposes, and respecting any on-site opt-out request.

Do I have to honour Global Privacy Control under CPA?

Yes, since 1 July 2024. Colorado was the first US state to make Universal Opt-Out Mechanism support binding, and GPC is currently the only UOOM the AG recognises. A fingerprinting deployment that ignores a GPC signal from a Colorado browser is in violation of 4 CCR 904-3 Rule 5.07 regardless of any on-site opt-out the consumer never used.

How is CPA different from VCDPA for fingerprinting?

Three meaningful differences. CPA's sale definition includes 'other valuable consideration', making non-monetary data sharing more likely to count as sale. CPA's DPA requirements under Rule 8 are far more prescriptive. And CPA's cure period sunset on 1 July 2025, while Virginia's notice-and-cure mechanism remains in place. Maximum civil penalty is also higher: $20,000 per violation versus VCDPA's $7,500.

Does CPA apply to anti-fraud fingerprinting?

Yes, anti-fraud fingerprinting is personal-data processing under CPA, but the opt-out rights for targeted advertising, sale, and profiling do not apply to anti-fraud use, and a Rule 8 Data Protection Assessment is generally not required unless the processing carries a 'reasonably foreseeable risk of substantial injury'. Narrowly-scoped anti-fraud remains one of the lowest-friction use cases under the law.

What is a Data Protection Assessment under 4 CCR 904-3 Rule 8?

It is a documented internal analysis weighing the benefits of certain processing activities against the risks to the consumer. Required before engaging in targeted advertising, sale, sensitive-data processing, or profiling carrying reasonably foreseeable risk. The Colorado AG's regulations specify exactly what the assessment must contain, the most prescriptive DPA standard of any US state law.

Is sharing fingerprint hashes for ad-tech 'sale' under Colorado law?

Often yes. Colorado's sale definition includes 'monetary or other valuable consideration', which captures non-monetary data sharing that VCDPA's monetary-only definition does not. Sharing fingerprint hashes with an ad-tech partner for audience extension or mutual lift is more likely to require sale-opt-out handling in Colorado than in Virginia.

What are the fines for non-compliant fingerprinting under CPA?

Civil penalties under C.R.S. §6-1-112 reach $20,000 per violation, with each consumer affected counting as a separate violation in principle. The AG's office has favoured per-processing-activity counting in early settlements, but the cure-period sunset on 1 July 2025 has shifted the AG's stance toward stricter per-violation calculation for new matters.

Does CPA have a small-business exemption?

No. Unlike Utah's UCPA, CPA applies to any controller that meets one of the two consumer-count thresholds, regardless of company size or annual revenue. A 12-person startup that processes 100,000 Colorado consumers owes the same obligations as a Fortune-500 enterprise.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06