Law note · Colorado
Colorado Cybercrime statute (unauthorized access, tracking the federal CFAA)
What it asks of an app
- Do not access a Colorado-connected computer without authorization, or beyond the scope of granted authorization, to collect data; this statute's language closely tracks the federal Computer Fraud and Abuse Act (CFAA) rather than a broader state standard.
- No Colorado court has yet decided whether a public, unauthenticated page counts as authorized under this statute, so treat that question as unsettled rather than resolved by analogy to federal case law.
When LexLint raises it
crawls_web
What we found
Subsection (1)(a) makes it a cybercrime for a person to knowingly access a computer without authorization, exceed authorized access, or use a computer without authorization or in excess of authorized access, language that tracks the federal Computer Fraud and Abuse Act (CFAA)'s structure almost verbatim rather than California's broader without permission standard.
No Colorado court has construed this language in a scraping context, so whether Colorado would follow the narrow, gates-based reading the US Supreme Court gave the federal statute in Van Buren v. United States (593 U.S. 374, 2021) is unsettled as a matter of Colorado law.
A 2018 act (HB 18-1200, session law chapter 379, confirmed against the official signed act) renamed the section from computer crime to cybercrime and added the current subsections (1)(h) through (1)(j) and an escalated penalty tier; a 2023 act (HB 23-1293, confirmed against the official signed act) amended only the repeat-offender penalty clause at (3)(b), not the underlying conduct definition at (1)(a).
This subsequent pass located the underlying text directly against the official Colorado Revised Statutes (leg.colorado.gov), closing the FindLaw-only gap flagged previously: the section's own source note shows the article was entire added in 1979, subsection (1) was amended in 1983, and the entire section was reenacted in 2000; no amendment since 2000 has touched subsection (1)(a) itself, so the currently codified without-authorization or exceeds-authorized-access language traces to that 2000 reenactment rather than to the 1979 original.