Privacy Law Library

Colorado data breach notification law (Notification of security breach)

Colorado breach notification

Breach notification

Colorado requires businesses to investigate a possible breach promptly and notify affected Colorado residents within 30 days after determining that a breach occurred, unless misuse is not reasonably likely. The Attorney General must be notified within 30 days if 500 or more residents are affected, and national consumer reporting agencies if more than 1,000. Personal information includes name plus SSN, ID numbers, medical or health insurance information, or biometric data, and online credentials.

Where
Colorado
Citation
C.R.S. 6-1-716
Status
In force
In force since
2006-09-01
Last amended
2018-09-01
Enforced by
Colorado Attorney General (6-1-716(4))
People can sue
No
Penalties
The Attorney General may sue in law or equity for compliance relief and direct economic damages (6-1-716(4)); no penalty amount is set in the section.
Applies to
  • Covered entities: any person that maintains, owns, or licenses computerized personal information of Colorado residents in the course of business (6-1-716(1)(b))
  • Third-party service providers that maintain data for a covered entity must notify and cooperate with the covered entity (6-1-716(2)(b))
  • Entities regulated under state or federal breach rules are deemed compliant if they follow those procedures, but must still notify the Attorney General (6-1-716(3)(b))

Breach duties

  • On learning of a possible breach, promptly investigate in good faith and notify affected Colorado residents in the most expedient time possible and no later than 30 days after determining a breach occurred, unless misuse is not reasonably likely.C.R.S. 6-1-716(2)(a)
  • Notices must include the breach date or range, the information involved, contact information, consumer reporting agency and FTC contact details, and a statement about fraud alerts and security freezes.C.R.S. 6-1-716(2)(a.2)
  • For breached online credentials, direct users to change passwords and security questions; do not send notice only to a compromised email account.C.R.S. 6-1-716(2)(a.3)
  • Notify the Attorney General within 30 days if the breach is reasonably believed to affect 500 or more Colorado residents.C.R.S. 6-1-716(2)(f) · Only if: 500+ Colorado residents
  • Notify nationwide consumer reporting agencies of timing and number of notices if more than 1,000 residents are notified (not required for GLBA-regulated entities).C.R.S. 6-1-716(2)(d) · Only if: More than 1,000 Colorado residents
  • Third-party service providers must notify the covered entity without unreasonable delay and cooperate.C.R.S. 6-1-716(2)(b)
  • Encrypted data breaches must be reported if the key was also acquired; residents may not be charged for notice; waivers are void.C.R.S. 6-1-716(2)(a.4), (a.5), (e)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.