# Colorado — US state data breach notification deadlines by state For Colorado, statute citation is C.R.S. § 6-1-716; individual notice deadline is in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred; individual notice hard deadline (days) is 30; ag / regulator notice deadline is in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred; ag notice resident-count trigger is five hundred Colorado residents or more, recorded from its source on 2026-08-18. - **State:** Colorado _(verified: appears in the quote below)_ - **Statute citation:** C.R.S. § 6-1-716 - **Individual notice deadline:** in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred _(verified: appears in the quote below)_ - **Individual notice hard deadline (days):** 30 _(our reading, not quoted from the source)_ - **AG / regulator notice deadline:** in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred _(verified: appears in the quote below)_ - **AG notice resident-count trigger:** five hundred Colorado residents or more - **Consumer reporting agency notice trigger (residents):** more than one thousand Colorado residents - **Encryption safe harbor:** yes _(our reading, not quoted from the source)_ - **Notes:** Record taken from the Colorado Revised Statutes 2023 Title 6 text (C.R.S. § 6-1-716). The 30-day deadline and 500-resident AG threshold were added by HB 21-1130 (2021 session). GLBA-covered entities are exempt from the CRA notice requirement (subsection 2(d)). CRA notice requires anticipated date of notification and approximate number of residents, not names. _(our reading, not quoted from the source)_ ## What the source says > A covered entity that maintains, owns, or licenses computerized data that includes personal information about a resident of Colorado shall, when it becomes aware that a security breach may have occurred, conduct in good faith a prompt investigation to determine the likelihood that personal information has been or will be misused. The covered entity shall give notice to the affected Colorado residents unless the investigation determines that the misuse of information about a Colorado resident has not occurred and is not reasonably likely to occur. Notice must be made in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system. ## Source - https://leg.colorado.gov/sites/default/files/images/olls/crs2023-title-06.pdf Last verified: 2026-08-18. Review by: 2027-02-14. Part of [US state data breach notification deadlines by state](https://referencesource.org/data-breach-notification-clocks/).