Privacy Law Library

Disposal and protection of personal identifying information

Colorado data disposal and security

Data security

Colorado businesses must have a written policy to destroy paper and electronic records containing personal identifying information when no longer needed, rendering it unreadable. Since 2018 they must also maintain reasonable security procedures appropriate to the data and the business, and require service providers to do the same.

Where
Colorado
Citation
C.R.S. 6-1-713; 6-1-713.5
Status
In force
In force since
2004-08-04
Last amended
2018-09-01
Enforced by
Colorado Attorney General (6-1-716(4))
People can sue
No
Penalties
Attorney General actions in law or equity for compliance relief and direct economic damages (6-1-716(4)).
Applies to
  • Covered entities that maintain, own, or license personal identifying information (SSN, PINs, passwords, driver's license or ID, passport, biometric data, employer, student, or military ID, or financial transaction device) in the course of business (6-1-713(2))
  • Entities regulated under state or federal disposal or security rules are deemed compliant (6-1-713(3); 6-1-713.5(4))

Security duties

  • Adopt a written policy requiring destruction of paper and electronic documents containing personal identifying information, by shredding, erasing, or otherwise making the information unreadable, when no longer needed.C.R.S. 6-1-713(1)
  • Implement and maintain reasonable security procedures and practices appropriate to the nature of the information and the size and nature of the business.C.R.S. 6-1-713.5(1) · From 2018-09-01
  • Require third-party service providers receiving personal identifying information to maintain reasonable security, unless the covered entity keeps primary responsibility and technical controls.C.R.S. 6-1-713.5(2)-(3) · From 2018-09-01

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.