State Breach Law
Colorado Data Breach Notification Law
C.R.S. § 6-1-716 • Effective 2006-09-01
Colorado requires 30-day breach notification and, with the new Colorado Privacy Act, has joined California and Virginia as states with comprehensive privacy laws. If you have data on Colorado residents, you need to comply with both breach notification AND privacy requirements.
Notification deadline: 30 days from determination that breach occurred
Enforcement: Colorado Attorney General
Overview
Colorado requires notification within 30 days of determining a breach occurred. The Colorado Privacy Act (effective 2023) adds significant new privacy rights and security requirements for businesses handling Colorado residents' data.
Who Must Be Notified
- • Affected Colorado residents
- • Colorado Attorney General (if 500+ residents affected)
Covered Data Types
Social Security number, Driver's license or ID card number, Passport number, Military ID number, Financial account number with access code, Biometric data, Medical information, Health insurance ID number, Username with password
Notification Requirements
- • Written, telephonic, or electronic notice within 30 days
- • Include date/estimated date of breach
- • Description of personal information involved
- • Contact information for the business
- • Toll-free numbers for credit bureaus
- • Submit notice to AG if 500+ Colorado residents affected
Is your business exposed?
Exemptions
- • Encrypted data (if key not compromised)
- • Truncated or redacted data
- • Entities in compliance with HIPAA, GLBA
Penalties
Civil penalties under Consumer Protection Act. AG can seek injunctions and penalties. Colorado Privacy Act violations can result in $20,000 per violation after cure period.
If You Experience a Breach
- 1.
Comply with Colorado Privacy Act requirements (if applicable)
- 2.
Be prepared to meet 30-day notification deadline
- 3.
Create breach notification templates
- 4.
Know how to report to CO Attorney General
- 5.
Implement reasonable security practices
- 6.
Review Colorado Privacy Act applicability thresholds
Official Source
https://coag.gov/resources/data-protection/Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required