Student Data Transparency and Security Act
Colorado Student Data Act
Students · Children · Data security
Colorado's student privacy law requires education technology vendors under contract with public schools to disclose what student data they collect and why, use it only for contracted purposes, and never sell it or use it for targeted advertising. Vendors must maintain an information security program, notify schools of misuse, and destroy data on request or at contract end. Parents gain inspection, correction, and complaint rights.
- Where
- Colorado
- Citation
- C.R.S. 22-16-101 to 22-16-112
- Status
- In force
- In force since
- 2016-08-10
- Enforced by
- Contracting public education entities (contract remedies and termination after public hearing); Colorado Department of Education
- People can sue
- No
- Penalties
- No civil penalty; a material breach involving misuse or unauthorized release of student data triggers a public hearing on contract termination, and districts may not contract with providers that failed to comply (22-16-107(2)).
- Applies to
- School service contract providers: vendors under contract with a Colorado public education entity to provide school services that involve student personally identifiable information (22-16-103, 22-16-108 to 22-16-110)
- School service on-demand providers (click-through terms) used by local education providers (22-16-107(3))
- Colorado public education entities (state board, department, districts, BOCES, charter schools) (22-16-104 to 22-16-107, 22-16-112)
What a privacy notice must say
- Provide layperson-readable information on the student data elements collected, the learning purpose, and how data are used and shared, for posting on the school's website; give notice before material privacy policy changes.C.R.S. 22-16-108(1)-(2)
Rights it gives people
- Facilitate access to and correction of factually inaccurate student data at the school's request; parents may inspect and seek correction.C.R.S. 22-16-108(3); 22-16-112
Practices it requires
- Use and share student personally identifiable information only as authorized by contract or with student or parent consent.C.R.S. 22-16-109(1)
- Do not sell student personally identifiable information, use it for targeted advertising to students, or build student profiles beyond authorized purposes.C.R.S. 22-16-109(2)
- Destroy student data on the school's request during the contract and at contract end, and notify the school of the destruction date.C.R.S. 22-16-110(2)-(3)
Security duties
- Maintain a comprehensive information security program with administrative, technical, and physical safeguards.C.R.S. 22-16-110(1)
Breach duties
- Notify the contracting public education entity as soon as possible after discovering misuse or unauthorized release of student data.C.R.S. 22-16-108(4)
Sources
- Official text
- Colorado Revised Statutes 2024, Title 22 (Office of Legislative Legal Services, leg.colorado.gov)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: No amendments after 2016 were identified in the section source notes read (22-16-108 to 22-16-110); other sections were not checked for later amendments.
Research reference, not legal advice.