State Breach Law

Colorado Data Breach Notification Law

C.R.S. § 6-1-716 • Effective 2006-09-01

Colorado requires 30-day breach notification and, with the new Colorado Privacy Act, has joined California and Virginia as states with comprehensive privacy laws. If you have data on Colorado residents, you need to comply with both breach notification AND privacy requirements.

Notification deadline: 30 days from determination that breach occurred

Enforcement: Colorado Attorney General

Overview

Colorado requires notification within 30 days of determining a breach occurred. The Colorado Privacy Act (effective 2023) adds significant new privacy rights and security requirements for businesses handling Colorado residents' data.

Who Must Be Notified

  • Affected Colorado residents
  • Colorado Attorney General (if 500+ residents affected)

Covered Data Types

Social Security number, Driver's license or ID card number, Passport number, Military ID number, Financial account number with access code, Biometric data, Medical information, Health insurance ID number, Username with password

Notification Requirements

  • Written, telephonic, or electronic notice within 30 days
  • Include date/estimated date of breach
  • Description of personal information involved
  • Contact information for the business
  • Toll-free numbers for credit bureaus
  • Submit notice to AG if 500+ Colorado residents affected

Is your business exposed?

Exemptions

  • Encrypted data (if key not compromised)
  • Truncated or redacted data
  • Entities in compliance with HIPAA, GLBA

Penalties

Civil penalties under Consumer Protection Act. AG can seek injunctions and penalties. Colorado Privacy Act violations can result in $20,000 per violation after cure period.

If You Experience a Breach

  1. 1.

    Comply with Colorado Privacy Act requirements (if applicable)

  2. 2.

    Be prepared to meet 30-day notification deadline

  3. 3.

    Create breach notification templates

  4. 4.

    Know how to report to CO Attorney General

    CO AG Data Breach Report

  5. 5.

    Implement reasonable security practices

  6. 6.

    Review Colorado Privacy Act applicability thresholds

Official Source

https://coag.gov/resources/data-protection/

Other State Breach Laws

New York, Texas, Florida

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required