Law / United States / Colorado

Protection of personal identifying information, reasonable security procedures duty

C.R.S. 6-1-713.5 (added by HB 18-1128, 2018 Colo. Sess. Laws ch. 266, section 2)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 September 2018.

A security baseline statutes rule binding private bodies.

As of 12 September 2026.

What it requires

  • This binds any person who maintains, owns, or licenses the personal identifying information of a Colorado resident in the course of the person's business, vocation, or occupation; a covered entity already regulated by a state or federal regulator whose data-security requirements it follows is deemed to comply.
  • Implement and maintain reasonable security procedures and practices, appropriate to the nature of the information and the nature and size of the business, to protect personal identifying information (a Social Security number, a personal identification number, a password or pass code, a state driver's license or identification card number, a government passport number, biometric data, an employer, student, or military identification number, or a financial transaction device) from unauthorized access, use, modification, disclosure, or destruction.
  • Where personal identifying information is disclosed to a third-party service provider, require that provider to implement and maintain its own reasonable security procedures and practices, unless the covered entity retains primary responsibility and implements technical controls that protect the information from unauthorized access or effectively eliminate the third party's ability to access it.
  • A violation is enforceable by the Colorado Attorney General under section 6-1-716(4) to compel compliance or recover direct economic damages, and, as a violation of part 7 of the Colorado Consumer Protection Act, is also a deceptive trade practice under section 6-1-105(1)(x), reaching the act's civil penalty of up to $20,000 per violation under section 6-1-112(1)(a) and a private right of action under section 6-1-113 for actual damages, a $500 statutory minimum, treble damages for bad-faith conduct, and attorney fees.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

Civil penalty under C.R.S. 6-1-112(1)(a) for a violation of any provision of the Colorado Consumer Protection Act, reached here because a violation of this section is a deceptive trade practice under C.R.S. 6-1-105(1)(x); a violation against an elderly person carries a civil penalty of up to $50,000 under C.R.S. 6-1-112(1)(c). This is separate from, and not exclusive of, the direct-economic-damages action C.R.S. 6-1-716(4) gives the Attorney General against a violation of this section, which states no fixed cap of its own.

Rule
Per violation only
As of
12 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
20,000

Who enforces it

Enforcement body

The Colorado Attorney General may bring an action in law or equity under C.R.S. 6-1-716(4) to address a violation of this section, either to compel compliance or to recover direct economic damages. A violation is also a deceptive trade practice under C.R.S. 6-1-105(1)(x), enforceable by the Attorney General or a district attorney under the Colorado Consumer Protection Act's general civil-penalty provision, C.R.S. 6-1-112.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A covered entity, a person that maintains, owns, or licenses personal identifying information of a Colorado resident in the course of its business, vocation, or occupation, must implement and maintain reasonable security procedures and practices, appropriate to the nature of the information and the nature and size of the business, to protect personal identifying information from unauthorized access, use, modification, disclosure, or destruction.

Personal identifying information is defined narrowly: a Social Security number, a personal identification number, a password or pass code, a state driver's license or identification card number, a government passport number, biometric data, an employer, student, or military identification number, or a financial transaction device.

Where a covered entity discloses that information to a third-party service provider, it must require the provider to implement and maintain its own reasonable security procedures, unless the covered entity retains primary responsibility and implements technical controls that protect the information. A covered entity already regulated by state or federal law and following that regulator's own data-security procedures is deemed compliant.

This duty binds a private person or commercial entity; a governmental entity's parallel duty sits at C.R.S. 24-73-102, outside this profile's private-sector scope.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Colorado Revised Statutes Title 6, Consumer and Commercial Affairs, as compiled by FindLaw

Back to the example  ·  Lint your app