Privacy Law Library

Colorado Privacy Act biometric amendments (Privacy of Biometric Identifiers and Data)

CPA biometric (HB 24-1130)

Biometric · Employees

HB 24-1130 added biometric-specific duties to the Colorado Privacy Act, reaching any controller that handles biometric identifiers regardless of size and covering employees. Controllers need a public written retention and deletion policy, advance notice, consent, and may not sell biometric identifiers. Employers may require consent only for listed purposes such as secure access, timekeeping, and safety.

Where
Colorado
Citation
C.R.S. 6-1-1314; 6-1-1303(2.4), (2.5); 6-1-1304(1)(a)(II)
Status
In force
In force since
2025-07-01
Enforced by
Colorado Attorney General and district attorneys
People can sue
No
Penalties
Enforced as a Colorado Privacy Act violation: deceptive trade practice, up to $20,000 per violation (6-1-1311; 6-1-112).
Applies to
  • Any controller that controls or processes biometric identifiers or biometric data, regardless of volume, as to those data (6-1-1304(1)(a)(II))
  • Employers collecting biometric identifiers of employees and prospective employees, including contractors, interns, and fellows (6-1-1314(1)(b), (6))
  • The right to access biometric data applies to larger controllers (100,000 / 25,000-plus-sale thresholds), commonly branded affiliates, and small joint ventures (6-1-1314(5)(b))

What a privacy notice must say

  • Before collecting a biometric identifier, inform the consumer that it is being collected, the specific purpose, the retention period, and any disclosure to processors.C.R.S. 6-1-1314(4)(a)

Rights it gives people

  • On request, disclose free of charge the source, purpose, third-party recipients, and categories of biometric data disclosed.C.R.S. 6-1-1314(5) · Only if: Applies to controllers meeting 6-1-1314(5)(b)

Practices it requires

  • Do not sell, lease, or trade biometric identifiers, and disclose them only with consent, for a requested financial transaction, to a processor for the consented purpose, or as required by law.C.R.S. 6-1-1314(4)(b)
  • Do not refuse service or charge different prices because a consumer declines biometric collection unless the biometric is necessary to provide the service.C.R.S. 6-1-1314(4)(c)
  • Adopt a written policy with a retention schedule, an incident-response protocol, and deletion by the earliest of purpose satisfied, 24 months after last interaction, or 45 days after storage is found unnecessary; make it public (with exceptions for employee-only policies).C.R.S. 6-1-1314(2)
  • Employers may condition employment on biometric consent only for secure access, recording the work day, workplace safety or security, or public emergencies; other uses need voluntary consent without retaliation.C.R.S. 6-1-1314(6)
  • Obtain consent before collecting biometric data (sensitive data).C.R.S. 6-1-1314(4)(e); 6-1-1308(7)

Security duties

  • Store, transmit, and protect biometric identifiers using the industry standard of care; processors need a breach-response protocol that notifies the controller.C.R.S. 6-1-1314(3), (4)(d)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.