Colorado
Colorado Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 10 primary sources cited on this page. How we verify our legal content

Under C.R.S. 6-1-716, Colorado requires businesses to notify affected residents within 30 days of determining a data breach has occurred. Organizations must also report to the Colorado Attorney General within that same window when 500 or more Colorado residents are affected.
Colorado has one of the most demanding data breach notification laws in the United States. The state's 30-day notification deadline gives organizations less time to respond than nearly every other jurisdiction, and its definition of protected personal information is among the broadest nationwide.
The current law took shape through House Bill 18-1128, signed into law in 2018 and effective September 1, 2018. That legislation overhauled Colorado's previous breach notification rules by shortening the notification window, expanding what counts as personal information, and adding an Attorney General reporting requirement.
For a broader look at Colorado's privacy framework, including the Colorado Privacy Act, see the parent guide to Colorado Data Privacy Laws.
Who Must Comply
Colorado's breach notification obligations apply to two categories of entities.
Private entities fall under C.R.S. 6-1-716. This covers any person or commercial entity that maintains, owns, or licenses computerized data containing the personal information of Colorado residents in the course of business.
Government entities fall under C.R.S. 24-73-103. This covers state agencies, counties, municipalities, school districts, and other governmental bodies that maintain personal information.
Both statutes impose the same 30-day notification timeline and the same personal information definitions. The key distinction is the enforcement mechanism: under C.R.S. 6-1-716(4) the Attorney General may bring an action in law or equity against a private entity, including to recover direct economic damages, while under C.R.S. 24-73-103(4) the Attorney General's remedy against a governmental entity is an action for injunctive relief.
Third-party service providers are not covered entities. C.R.S. 6-1-716(1)(b) states that a covered entity does not include a person acting as a third-party service provider. A provider that maintains, stores, or processes personal information for a covered entity has a narrower duty under C.R.S. 6-1-716(2)(b): it must notify and cooperate with the covered entity in the most expedient time possible after discovering a breach. Notifying affected residents and the Attorney General remains the covered entity's job.
Vendor contracting is governed by a separate statute. Under C.R.S. 6-1-713.5(2), unless a covered entity agrees to provide its own security protection for the information it discloses to a third-party service provider, it must require the provider to implement and maintain reasonable security procedures and practices appropriate to the information disclosed.
What Qualifies as Personal Information
Colorado's definition of personal information is among the broadest in the country. Under C.R.S. 6-1-716(1)(g), the law protects a Colorado resident's first name or first initial and last name combined with any of the following unencrypted data elements:
- Social Security number
- Driver's license number or state identification card number
- Student identification number
- Military identification number
- Passport number
- Medical information
- Health insurance identification number
- Biometric data used for authentication purposes

The law also protects two standalone categories that do not require a name match:
- A username or email address combined with a password or security questions and answers that would permit access to an online account
- An account number or credit or debit card number combined with any required security code, access code, or password
The inclusion of passport numbers, student IDs, and military IDs distinguishes Colorado from most other states, which typically limit their definitions to Social Security numbers, driver's licenses, and financial account data.
Personal information does not include data that is lawfully available from government records or widely distributed media.
What Triggers the Notification Requirement
A security breach under Colorado law is the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a covered entity.
When an entity becomes aware that a breach may have occurred, it must conduct a prompt, good-faith investigation to determine whether personal information has been or will be misused. The investigation must assess the nature and scope of the incident.
Notification is required only when the investigation determines that misuse of personal information has occurred or is reasonably likely to occur. If the entity determines there is no reasonable likelihood of misuse, notification is not required, but the entity should document its analysis.
The 30-Day Notification Deadline
Colorado requires notification in the most expedient time possible and without unreasonable delay, but no later than 30 days after the entity determines a breach has occurred.
This 30-day clock starts when the entity makes a determination that a breach occurred, not when the breach itself happened or when the entity first became aware of suspicious activity. However, the investigation itself must be prompt. Delaying an investigation to avoid triggering the clock would likely violate the statute's good-faith requirement.
The 30-day timeline is notably shorter than most states. Many states allow 45 or 60 days, and some have no specific deadline beyond "without unreasonable delay."
Law enforcement may request a delay in notification if it would impede a criminal investigation. The entity must provide notification as soon as the law enforcement agency determines that notification will no longer compromise the investigation.
What the Notice Must Include
Colorado specifies the content that breach notification letters must contain. Notices sent to affected residents must include:
- The date or estimated date range of the security breach
- A description of the personal information that was acquired or reasonably believed to have been acquired
- Contact information for the entity providing the notice
- Contact information for the Federal Trade Commission and the credit reporting agencies
- Toll-free numbers, addresses, and websites for the consumer reporting agencies
- A statement that the resident can obtain information from the FTC and credit reporting agencies about fraud alerts and security freezes
If the breach involved login credentials (username or email with password), the notice must direct the resident to promptly change their password and security questions for the affected account and any other account using the same credentials.
Attorney General Reporting
When a breach is reasonably believed to have affected 500 or more Colorado residents, the entity must notify the Colorado Attorney General's office within the same 30-day window.
The AG notification is submitted through an online Data Breach Reporting Form maintained by the Consumer Protection Section. If the online form is unavailable, entities can email databreach@coag.gov.
The reporting form requires:
- Entity name, type, address, and contact details
- Types of personal information compromised
- Number of Colorado residents affected and total individuals affected across all states
- Dates the breach started, ended, was discovered, and when the determination was made
- Planned notification dates for affected residents
- Whether the data was encrypted
- Type of breach (hacking, phishing, malware, lost equipment, insider misuse, etc.)
- Description of the incident
- Method of notification to residents
The reporting form states that the contact information, the date range of the reported breach, the types of affected personal information, and examples of consumer notices may be a public record and may be disclosed to third parties outside the Attorney General's office. It states that the rest of the submission is treated as confidential investigatory material.

Consumer Reporting Agency Notification
If the breach is reasonably believed to have affected more than 1,000 Colorado residents, the entity must also notify the nationwide consumer reporting agencies (Equifax, Experian, and TransUnion).
This notice must include the anticipated date of notification to affected residents and the approximate number of residents who will be notified. The purpose is to prepare the credit bureaus for an influx of fraud alert and credit freeze requests.
Substitute Notice
Colorado allows substitute notice when direct notification is not feasible. An entity may use substitute notice if it demonstrates that:
- The cost of providing notice would exceed $250,000
- The affected class exceeds 250,000 Colorado residents
- The entity does not have sufficient contact information
Substitute notice consists of all three of the following, not a choice among them:
- Email notice, if the entity has email addresses for members of the affected class
- Conspicuous posting of the notice on the entity's website, if it maintains one
- Notification to major statewide media
C.R.S. 24-73-103(1)(f)(IV) imposes the same three-part requirement on government entities.
Encryption Safe Harbor
Colorado provides an encryption safe harbor. Personal information that is encrypted, redacted, or secured by any other method that renders it unreadable or unusable is not considered to have been breached.
This means if the compromised data was properly encrypted at the time of unauthorized access, the notification requirements generally do not apply. The encryption must have been in place before the breach, not applied afterward.
The safe harbor has a statutory exception. Under C.R.S. 6-1-716(2)(a.4) and (2)(g), notification is still required if the confidential process, encryption key, or other means to decipher the data was also acquired, or reasonably believed to have been acquired, in the same breach. Encryption only protects an entity from notification duties when the key to unlock it stayed secure.
Reasonable Security and Data Disposal Requirements
Beyond breach notification, Colorado law imposes ongoing data protection obligations through C.R.S. 6-1-713.5 and C.R.S. 6-1-713.
Under C.R.S. 6-1-713.5, covered entities must implement and maintain reasonable security procedures appropriate to the nature of the personal information they hold. The standard is flexible and considers factors such as the size and complexity of the business and the sensitivity of the data.
Under C.R.S. 6-1-713, entities must also develop and maintain a written policy for the destruction and proper disposal of paper and electronic documents containing personal information. When documents are no longer needed, the entity must render the personal information unreadable.
These two sections use a broader term than the breach notification statute. Personal identifying information under C.R.S. 6-1-713(2)(b) covers a Social Security number, a personal identification number, a password or pass code, a state or government-issued driver's license or identification card number, a government passport number, biometric data, an employer, student, or military identification number, and a financial transaction device. Those extra elements drive the disposal and reasonable security duties. They are not part of the breach notification definition in C.R.S. 6-1-716, so an incident limited to them does not by itself trigger notification.

Interaction with Federal and State Regulations
Entities that comply with breach notification requirements under federal or state regulatory frameworks, such as HIPAA for healthcare or the Gramm-Leach-Bliley Act for financial institutions, are deemed in compliance with Colorado's notification provisions.
However, there are two important exceptions. Even HIPAA- and GLBA-regulated entities must still:
- Notify the Colorado Attorney General when 500 or more Colorado residents are affected
- Follow whichever notice timeline is shortest under state or federal law. Today that means Colorado's 30-day window controls, because it is shorter than the HIPAA and GLBA deadlines, not because Colorado's timeline automatically overrides federal law
Colorado's breach notification law also exists alongside the Colorado Privacy Act (CPA), which took effect July 1, 2023. The CPA addresses broader data privacy rights (access, deletion, opt-out), while the breach notification statute focuses specifically on security incidents. They are complementary, and businesses handling Colorado consumer data should comply with both.
Enforcement and Penalties
The Colorado Attorney General enforces the breach notification law. There is no private right of action, meaning individual consumers cannot sue directly for notification failures.
Enforcement runs through C.R.S. 6-1-716(4), which lets the Attorney General bring an action in law or equity to address violations of the breach notification, disposal, and reasonable security sections, to obtain other relief that ensures compliance, or to recover direct economic damages. Breach notification is not one of the deceptive trade practices enumerated in C.R.S. 6-1-105, which is why C.R.S. 6-1-113 opens no private civil action for it. Because C.R.S. 6-1-716 sits inside article 1 of title 6, the civil penalty provision at C.R.S. 6-1-112(1)(a) reaches it: up to $20,000 per violation, counting each consumer or transaction as a separate violation, with no cap on the total penalty for a related series of violations.
The Attorney General has actively enforced these provisions. Notable actions include:
- Savory Spice Shop (2022): A Denver company paid $30,000 after two breaches exposed payment card data of 13,888 Colorado customers. The company failed to maintain adequate security and delayed notification for nine months despite a 30-day policy commitment.
- Impact MHC (2021): A mobile home park management company paid $25,000 (with an additional $30,000 suspended pending compliance) after a phishing attack exposed Social Security numbers and financial data of over 700 Coloradans. The company delayed notification for 10 months.
Both cases resulted in requirements to implement written information security policies, develop incident response plans, and maintain ongoing compliance programs.

More Colorado Laws
Frequently Asked Questions
How quickly must a Colorado business notify residents of a data breach?
Colorado requires notification within 30 days after the entity determines a security breach has occurred. This is one of the shortest deadlines in the country. The 30-day clock begins when the entity makes its determination, not when the breach itself happened. The entity must conduct a prompt, good-faith investigation before making that determination.
When must the Colorado Attorney General be notified of a data breach?
Entities must notify the Colorado Attorney General within 30 days when a breach is reasonably believed to have affected 500 or more Colorado residents. The notification is submitted through an online reporting form at coag.gov. If the breach affects more than 1,000 residents, the entity must also notify the nationwide consumer reporting agencies (Equifax, Experian, TransUnion).
Does Colorado law require notification if the breached data was encrypted?
Generally, no. Colorado provides an encryption safe harbor for personal information that was encrypted, redacted, or otherwise rendered unreadable or unusable at the time of the breach, and the encryption must have been in place before the unauthorized access occurred. The safe harbor does not apply if the encryption key or other means to decipher the data was also acquired, or reasonably believed to have been acquired, in the same breach, in which case notification is still required.
Can individuals sue for data breach notification violations in Colorado?
No. Colorado does not provide a private right of action for breach notification violations. Only the Colorado Attorney General can enforce the law. C.R.S. 6-1-716(4) lets the Attorney General bring an action in law or equity and recover direct economic damages, and because the statute sits in article 1 of title 6, civil penalties under C.R.S. 6-1-112(1)(a) can reach $20,000 per violation. Breach notification is not on the list of deceptive trade practices in C.R.S. 6-1-105, so C.R.S. 6-1-113 gives consumers no private claim for it. Individuals who suffer identity theft or fraud may have other legal remedies available.
How does Colorado's breach notification law interact with HIPAA and the Colorado Privacy Act?
HIPAA-regulated healthcare entities and GLBA-regulated financial institutions that comply with their federal notification requirements are generally deemed compliant with Colorado law. However, they must still notify the Colorado Attorney General when 500 or more residents are affected. Notice to individuals is governed by whichever timeline is shortest under state or federal law, which currently means Colorado's 30-day window controls because it is shorter than the HIPAA and GLBA deadlines. The Colorado Privacy Act (CPA) is a separate law addressing broader privacy rights like data access and deletion. Businesses should comply with both the breach notification statute and the CPA.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the enforcement section: breach notification violations are not deceptive trade practices under the Colorado Consumer Protection Act but are enforced by the Attorney General under C.R.S. 6-1-716(4) with civil penalties under C.R.S. 6-1-112(1)(a); added the mandatory major-statewide-media element of substitute notice, removed data elements that belong to the disposal statute rather than the breach statute, corrected the treatment of third-party service providers, and repointed statutory citations to the official Colorado Revised Statutes text.
Corrected the encryption safe harbor to note it does not apply if the decryption key was also stolen, fixed the consumer-reporting-agency notice trigger from "1,000 or more" to "more than 1,000" residents, separated the reasonable-security-procedures duty (C.R.S. 6-1-713.5) from the disposal-policy duty (C.R.S. 6-1-713), and clarified that Colorado's 30-day HIPAA/GLBA carve-out applies because it is currently the shortest timeline, not because it automatically overrides federal law.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Colorado Revised Statutes, Title 6: Consumer and Commercial Affairs
§ 6-1-716Notification of security breachIn force
(1) Definitions. As used in this section, unless the context otherwise requires: (a) Biometric data means unique biometric data generated from measurements or analysis of human body characteristics for the purpose of authenticating the individual when he or she accesses an online account. (b) Covered entity means a person, as defined in section 6-1-102 (6), that maintains, owns, or licenses personal information in the course of the person's business, vocation, or occupation. Covered entity does not include a person acting as a third-party service provider as defined in subsection (1)(i) of this section. (c) Determination that a security breach occurred means the point in time at which there is sufficient evidence to conclude that a security breach has taken place. (d) Encrypted means rendered unusable, unreadable, or indecipherable to an unauthorized person through a security technology or methodology generally accepted in the field of information security. (e) Medical information means any information about a consumer's medical or mental health treatment or diagnosis by a health-care professional.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at olls.info
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Colorado Consumer Data Protection Laws FAQ(coag.gov).gov
- HB 18-1128 Protections for Consumer Data Privacy(leg.colorado.gov).gov
- Colorado AG Data Breach Reporting Form(coag.gov).gov
- Colorado AG Data Privacy Complaints(coag.gov).gov
- Colorado Privacy Act(coag.gov).gov
- Colorado AG Data Security Best Practices(coag.gov).gov
- Savory Spice Shop Settlement(coag.gov).gov
- Impact MHC Settlement(coag.gov).gov
- HIPAA Information(hhs.gov).gov
- Gramm-Leach-Bliley Act(ftc.gov).gov
- Colorado Revised Statutes 2026, Title 6 (C.R.S. 6-1-716, 6-1-713, 6-1-713.5, 6-1-112, 6-1-105, 6-1-113)(olls.info)
- Colorado Revised Statutes 2026, Title 24 (C.R.S. 24-73-103, governmental entity breach notification)(olls.info)