Colorado flag

Colorado

Colorado Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 10 primary sources cited on this page. How we verify our legal content

Colorado Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a Colorado business notify residents of a data breach?

Colorado requires notification within 30 days after the entity determines a security breach has occurred. This is one of the shortest deadlines in the country. The 30-day clock begins when the entity makes its determination, not when the breach itself happened. The entity must conduct a prompt, good-faith investigation before making that determination.

When must the Colorado Attorney General be notified of a data breach?

Entities must notify the Colorado Attorney General within 30 days when a breach is reasonably believed to have affected 500 or more Colorado residents. The notification is submitted through an online reporting form at coag.gov. If the breach affects more than 1,000 residents, the entity must also notify the nationwide consumer reporting agencies (Equifax, Experian, TransUnion).

Does Colorado law require notification if the breached data was encrypted?

Generally, no. Colorado provides an encryption safe harbor for personal information that was encrypted, redacted, or otherwise rendered unreadable or unusable at the time of the breach, and the encryption must have been in place before the unauthorized access occurred. The safe harbor does not apply if the encryption key or other means to decipher the data was also acquired, or reasonably believed to have been acquired, in the same breach, in which case notification is still required.

Can individuals sue for data breach notification violations in Colorado?

No. Colorado does not provide a private right of action for breach notification violations. Only the Colorado Attorney General can enforce the law. C.R.S. 6-1-716(4) lets the Attorney General bring an action in law or equity and recover direct economic damages, and because the statute sits in article 1 of title 6, civil penalties under C.R.S. 6-1-112(1)(a) can reach $20,000 per violation. Breach notification is not on the list of deceptive trade practices in C.R.S. 6-1-105, so C.R.S. 6-1-113 gives consumers no private claim for it. Individuals who suffer identity theft or fraud may have other legal remedies available.

How does Colorado's breach notification law interact with HIPAA and the Colorado Privacy Act?

HIPAA-regulated healthcare entities and GLBA-regulated financial institutions that comply with their federal notification requirements are generally deemed compliant with Colorado law. However, they must still notify the Colorado Attorney General when 500 or more residents are affected. Notice to individuals is governed by whichever timeline is shortest under state or federal law, which currently means Colorado's 30-day window controls because it is shorter than the HIPAA and GLBA deadlines. The Colorado Privacy Act (CPA) is a separate law addressing broader privacy rights like data access and deletion. Businesses should comply with both the breach notification statute and the CPA.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the enforcement section: breach notification violations are not deceptive trade practices under the Colorado Consumer Protection Act but are enforced by the Attorney General under C.R.S. 6-1-716(4) with civil penalties under C.R.S. 6-1-112(1)(a); added the mandatory major-statewide-media element of substitute notice, removed data elements that belong to the disposal statute rather than the breach statute, corrected the treatment of third-party service providers, and repointed statutory citations to the official Colorado Revised Statutes text.

Corrected the encryption safe harbor to note it does not apply if the decryption key was also stolen, fixed the consumer-reporting-agency notice trigger from "1,000 or more" to "more than 1,000" residents, separated the reasonable-security-procedures duty (C.R.S. 6-1-713.5) from the disposal-policy duty (C.R.S. 6-1-713), and clarified that Colorado's 30-day HIPAA/GLBA carve-out applies because it is currently the shortest timeline, not because it automatically overrides federal law.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Colorado Consumer Data Protection Laws FAQ(coag.gov).gov
  2. HB 18-1128 Protections for Consumer Data Privacy(leg.colorado.gov).gov
  3. Colorado AG Data Breach Reporting Form(coag.gov).gov
  4. Colorado AG Data Privacy Complaints(coag.gov).gov
  5. Colorado Privacy Act(coag.gov).gov
  6. Colorado AG Data Security Best Practices(coag.gov).gov
  7. Savory Spice Shop Settlement(coag.gov).gov
  8. Impact MHC Settlement(coag.gov).gov
  9. HIPAA Information(hhs.gov).gov
  10. Gramm-Leach-Bliley Act(ftc.gov).gov
  11. Colorado Revised Statutes 2026, Title 6 (C.R.S. 6-1-716, 6-1-713, 6-1-713.5, 6-1-112, 6-1-105, 6-1-113)(olls.info)
  12. Colorado Revised Statutes 2026, Title 24 (C.R.S. 24-73-103, governmental entity breach notification)(olls.info)
Share: