Data Breach Notification Statutes – Colorado
Last Updated: 02/28/2024
- Applicable Statute: Colo. Rev. Stat. § 6-1-716
- Attorney General Notice Required: Yes – If more than 500 residents are notified, must provide notice to the Attorney General.
- Timing: Most expedient time possible, without unreasonable delay, but not later than 30 days of determination that breach has occurred.
- Method: Online form at https://coag.gov/data-breach-notification-report-form/
- Content: See above re form.
- Consumer Notice Requirements:
- Timing: Must be made in the most expedient time possible and without unreasonable delay, but not later than 30 days after determining a breach occurred, consistent with measures necessary to determine the scope of the breach and to restore reasonable integrity to the system.
- Content: Notice must include, at a minimum–
- The date or estimated date of the security breach;
- A description of the personal information that was acquired or was reasonably believed to have been acquired;
- Information that the resident can use to contact the subject entity to inquire about the security breach;
- The toll-free numbers, addresses, and websites for consumer reporting agencies;
- The toll-free number, address, and website for the Federal Trade Commission; and
- A statement that the resident can obtain information from the Federal Trade Commission and the credit reporting agencies about fraud alerts and security freezes.
- If a resident’s username or e-mail address, in combination with a password or security questions and answers that would permit access to an online account was affected, notice must direct the resident to promptly change their password and security question or answer, or take other steps to protect all applicable online accounts.
- Method: Notice may be written, telephonic, or electronic if the entity primarily communicates with the resident by email or if the notice is consistent with E-SIGN.
- Substitute notice may be available under certain circumstances.
- If a resident’s log-in credentials for an email account provided by the subject entity were affected, notice cannot be made to that same email address.
- Consumer Reporting Agency Obligations: If more than 1,000 residents are notified, must also notify all nationwide consumer reporting agencies. Entities subject to Title V of GLBA are exempted from this requirement.