Colorado data breach notification law (Notification of security breach)
Colorado breach notification
Breach notification
Colorado requires businesses to investigate a possible breach promptly and notify affected Colorado residents within 30 days after determining that a breach occurred, unless misuse is not reasonably likely. The Attorney General must be notified within 30 days if 500 or more residents are affected, and national consumer reporting agencies if more than 1,000. Personal information includes name plus SSN, ID numbers, medical or health insurance information, or biometric data, and online credentials.
- Where
- Colorado
- Citation
- C.R.S. 6-1-716
- Status
- In force
- In force since
- 2006-09-01
- Last amended
- 2018-09-01
- Enforced by
- Colorado Attorney General (6-1-716(4))
- People can sue
- No
- Penalties
- The Attorney General may sue in law or equity for compliance relief and direct economic damages (6-1-716(4)); no penalty amount is set in the section.
- Applies to
- Covered entities: any person that maintains, owns, or licenses computerized personal information of Colorado residents in the course of business (6-1-716(1)(b))
- Third-party service providers that maintain data for a covered entity must notify and cooperate with the covered entity (6-1-716(2)(b))
- Entities regulated under state or federal breach rules are deemed compliant if they follow those procedures, but must still notify the Attorney General (6-1-716(3)(b))
Breach duties
- On learning of a possible breach, promptly investigate in good faith and notify affected Colorado residents in the most expedient time possible and no later than 30 days after determining a breach occurred, unless misuse is not reasonably likely.C.R.S. 6-1-716(2)(a)
- Notices must include the breach date or range, the information involved, contact information, consumer reporting agency and FTC contact details, and a statement about fraud alerts and security freezes.C.R.S. 6-1-716(2)(a.2)
- For breached online credentials, direct users to change passwords and security questions; do not send notice only to a compromised email account.C.R.S. 6-1-716(2)(a.3)
- Notify the Attorney General within 30 days if the breach is reasonably believed to affect 500 or more Colorado residents.C.R.S. 6-1-716(2)(f) · Only if: 500+ Colorado residents
- Notify nationwide consumer reporting agencies of timing and number of notices if more than 1,000 residents are notified (not required for GLBA-regulated entities).C.R.S. 6-1-716(2)(d) · Only if: More than 1,000 Colorado residents
- Third-party service providers must notify the covered entity without unreasonable delay and cooperate.C.R.S. 6-1-716(2)(b)
- Encrypted data breaches must be reported if the key was also acquired; residents may not be charged for notice; waivers are void.C.R.S. 6-1-716(2)(a.4), (a.5), (e)
Sources
- Official text
- Colorado Revised Statutes 2024, Title 6 (Office of Legislative Legal Services, leg.colorado.gov)
- Data Protection Laws (Colorado Attorney General resource page)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Research reference, not legal advice.