Colorado
For Colorado, statute citation is C.R.S. § 6-1-716; individual notice deadline is in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred; individual notice hard deadline (days) is 30; ag / regulator notice deadline is in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred; ag notice resident-count trigger is five hundred Colorado residents or more, recorded from its source on 2026-08-18.
- State
- Colorado verified
- Statute citation
- C.R.S. § 6-1-716
- Individual notice deadline
- in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred verified
- Individual notice hard deadline (days)
- 30 our reading
- AG / regulator notice deadline
- in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred verified
- AG notice resident-count trigger
- five hundred Colorado residents or more
- Consumer reporting agency notice trigger (residents)
- more than one thousand Colorado residents
- Encryption safe harbor
- yes our reading
- Notes
- Record taken from the Colorado Revised Statutes 2023 Title 6 text (C.R.S. § 6-1-716). The 30-day deadline and 500-resident AG threshold were added by HB 21-1130 (2021 session). GLBA-covered entities are exempt from the CRA notice requirement (subsection 2(d)). CRA notice requires anticipated date of notification and approximate number of residents, not names. our reading
Values marked our reading are our classification of what the source says — the source does not print them in those words. The quote below is the evidence for each one; judge it yourself.
What the source says
A covered entity that maintains, owns, or licenses computerized data that includes personal information about a resident of Colorado shall, when it becomes aware that a security breach may have occurred, conduct in good faith a prompt investigation to determine the likelihood that personal information has been or will be misused. The covered entity shall give notice to the affected Colorado residents unless the investigation determines that the misuse of information about a Colorado resident has not occurred and is not reasonably likely to occur. Notice must be made in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system.
— leg.colorado.gov, retrieved 2026-08-18
Source
- leg.colorado.govhttps://leg.colorado.gov/sites/default/files/images/olls/crs2023-title-06.pdf