Guide
Colorado HB 24-1130 Guide
Understand the opt-in, notice, and deletion mandates before enforcement begins.
Scope and Applicability
HB 24-1130 amended the Colorado Privacy Act (CPA) to add biometric identifiers as a category of sensitive data requiring affirmative consent before processing. The statute applies to controllers and processors subject to the CPA that collect, store, or use biometric identifiers in connection with individuals in Colorado.
Unlike Illinois BIPA, HB 24-1130 does not create a private right of action. Enforcement authority rests with the Colorado Attorney General and district attorneys under the Colorado consumer protection framework. This distinction matters for how organizations prioritize evidence design — the evidentiary audience is the AG and its investigators, not class action plaintiffs and their counsel.
- •Controllers and processors subject to the CPA are in scope
- •Government agencies and their vendors handling biometric identifiers fall within scope
- •Private-sector organizations meeting CPA threshold criteria are covered
- •No private right of action — AG and district attorney enforcement only
Core Requirements
The statute requires organizations to implement affirmative consent sequencing before collecting biometric identifiers, maintain a clear and publicly accessible privacy disclosure, constrain processing to specific and disclosed purposes, and operate rights-response workflows within applicable statutory timelines.
Data-protection assessment and processor-governance records are required for higher-risk processing. Organizations that use processors or subcontractors for biometric handling must ensure contractual controls mirror controller obligations.
- •Affirmative consent required before biometric collection
- •Publicly accessible privacy policy with version controls
- •Processing constrained to specific, explicit, disclosed purposes
- •Consumer rights-response timelines apply under the CPA framework
- •Data-protection assessments for higher-risk biometric processing
- •Processor contracts must reflect controller obligations
Evidence Expectations
Because enforcement is AG-driven, the evidentiary question is whether an organization can reconstruct and demonstrate its compliance posture from structured records — not whether it can survive discovery in class litigation.
The most common failure modes in similar enforcement contexts involve policy text that exists but lacks a version lineage, consent artifacts that are not linked to specific processing purposes, rights workflows that are manual and cannot demonstrate timeline proof, and processor contracts that do not mirror controller restrictions.
- •Consent receipts tied to purpose and collection channel
- •Privacy policy versions with publication timestamps
- •Rights-request intake and fulfillment timeline logs
- •Data-protection assessment records and processor contract controls
Action Plan
Map every biometric capture point and classify each system as controller or processor. For each capture point, confirm that affirmative consent is obtained before collection, that the privacy policy version in effect at the time of consent is preserved, and that the processing purpose is documented and bounded.
Implement logging for each consent event and rights-request interaction. Ensure processor contracts are updated to include CPA-required restrictions. Run a documentation dry run before enforcement begins in July 2025 — produce the evidence package you would hand to an investigator and verify it tells a complete, coherent story.
Representative Use Cases
Illustrative examples based on real compliance workflows and customer conversations.
State Agency (Representative)
In a representative deployment, unified consent notices across kiosks and badge replacements with versioned policy publication and consent receipt logging.
Transit Program (Representative)
Deployed affirmative consent checkpoints before biometric faregate scans, with purpose-bound processing logs and rights-request workflows.
Need help with HB 24-1130?
We provide architecture reviews, DPIA templates, and regulator-ready evidence packages.