Law / United States / Colorado
Disposal of personal identifying information, written policy duty
C.R.S. 6-1-713 (amended by HB 18-1128, 2018 Colo. Sess. Laws ch. 266, section 1)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 September 2018.
A security baseline statutes rule binding private bodies.
As of 12 September 2026.
What it requires
- This binds any person who maintains, owns, or licenses personal identifying information of a Colorado resident in the course of the person's business, vocation, or occupation; a covered entity already regulated by a state or federal regulator whose data-disposal requirements it follows is deemed to comply.
- Develop a written policy for the destruction or proper disposal of paper and electronic documents containing personal identifying information, and, once those documents are no longer needed, destroy or arrange for their destruction by shredding, erasing, or otherwise modifying the personal identifying information to make it unreadable or indecipherable.
- Enforcement runs alongside the reasonable-security-procedures duty at section 6-1-713.5: the Colorado Attorney General may bring an action under section 6-1-716(4) to compel compliance or recover direct economic damages, and a violation is also a deceptive trade practice under section 6-1-105(1)(x), reaching the Consumer Protection Act's civil penalty of up to $20,000 per violation and a private right of action under section 6-1-113.
If you get it wrong
Private right of actionYes
Who enforces it
Enforcement body
The Colorado Attorney General may bring an action in law or equity under C.R.S. 6-1-716(4) to address a violation of this section, either to compel compliance or to recover direct economic damages. A violation is also a deceptive trade practice under C.R.S. 6-1-105(1)(x), enforceable by the Attorney General or a district attorney under the Colorado Consumer Protection Act's general civil-penalty provision, C.R.S. 6-1-112.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A covered entity that maintains paper or electronic documents containing personal identifying information during the course of business must develop a written policy for the destruction or proper disposal of those documents. Once the documents are no longer needed, the covered entity must destroy or arrange for their destruction by shredding, erasing, or otherwise modifying the personal identifying information to make it unreadable or indecipherable through any means.
"Covered entity" and "personal identifying information" carry the same definitions this section shares with the reasonable-security-procedures duty at C.R.S. 6-1-713.5, and a covered entity already regulated by state or federal law and following that regulator's own disposal procedures is deemed compliant.
Unless an entity specifically contracts with a recycler or disposal firm for destruction, the recycler or disposal firm has no duty to verify that the documents it receives were properly destroyed.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Colorado Revised Statutes Title 6, Consumer and Commercial Affairs, as compiled by FindLaw