LOADING 0%
ServicesWorkBlogGet in touch
Home / Blog / Information Security
Information Security September 29, 2026 · 6 min read

Had a Data Breach in Colorado? Your 30-Day Notification Clock, Explained

Colorado gives a business 30 days from determining a breach to notify residents, and the Attorney General at 500 or more. What counts and what to do first.

It usually starts small: a client says they got a strange invoice from your email address, or a server stops opening files. Within a day it becomes the question every owner dreads. Was customer data taken, and what do we have to do about it?

In Colorado, the law answers part of that with a deadline. Here is how the clock works under C.R.S. 6-1-716, who has to be told, and what to do in the first days so you meet it with facts rather than guesses.

When the 30 days start

Colorado requires notice "in the most expedient time possible and without unreasonable delay, but not later than thirty days after the date of determination that a security breach occurred."

The key word is determination. The statute defines it as "the point in time at which there is sufficient evidence to conclude that a security breach has taken place." It is not the day the attacker got in, and it is not the day a final report lands on your desk. Once you have enough evidence to conclude a breach happened, the clock runs. That is why the first days of investigation matter so much: they decide both when the clock starts and what you will be able to say when it ends.

Who has to notify

The duty sits with the "covered entity": a business that "maintains, owns, or licenses personal information in the course of the person's business, vocation, or occupation."

If the breach happened at your IT provider, your cloud host or another vendor, the law calls them a third-party service provider. Their duty is to "give notice to and cooperate with" you. The notification obligation to your customers stays with your business.

What counts as personal information

The statute covers a Colorado resident's name combined with any of these, when not encrypted:

  • Social Security number
  • student, military or passport ID number
  • driver's license or state ID number
  • medical information or a health insurance ID number
  • biometric data

It also covers two categories that surprise people:

  • Login credentials on their own: a "username or email address, in combination with a password or security questions and answers, that would permit access to an online account."
  • Financial account access: an account or card number together with the security or access code needed to use it.

A compromised mailbox is the common case. The credentials may count by themselves, and the mailbox usually holds attachments with the other categories in them.

Who you must tell, and when

  • Affected Colorado residents: within 30 days of determination.
  • The Colorado Attorney General: within the same 30 days, if the breach is reasonably believed to have affected 500 or more Colorado residents. The AG's office takes these reports through an online form on coag.gov. Businesses regulated under HIPAA or Gramm-Leach-Bliley still owe the AG this notice.
  • The nationwide consumer reporting agencies: if more than 1,000 Colorado residents are affected, tell them the anticipated date of the notices and the approximate number of people. Gramm-Leach-Bliley entities are exempt from this one.

The two duties that apply before any breach

Two neighbouring sections apply to every Colorado business that holds this kind of data, breach or no breach:

  • C.R.S. 6-1-713: keep a written policy for destroying paper and electronic documents with personal identifying information, making them "unreadable or indecipherable through any means."
  • C.R.S. 6-1-713.5: "implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal identifying information and the nature and size of the business," and, generally, require your service providers to do the same.

The Attorney General enforces all three sections. After a breach, the AG may well ask what your security procedures looked like beforehand.

What to do in the first 72 hours

  1. Preserve before you clean. The instinct is to wipe the laptop and restore from backup. Don't, not yet. Isolate affected machines from the network, but keep the disks, the mailbox and the logs. They are how you will find out what was actually taken.
  2. Lock the doors from a clean device. Reset passwords and turn on multi-factor authentication for affected accounts, starting with email and admin accounts. Do it from a machine you trust.
  3. Start a written timeline. Note when each fact became known and who knew it. The 30-day deadline turns on determination, so you will want to be able to show when that happened.
  4. Call your attorney and your cyber insurer early. Many policies set conditions on how and when you report and which vendors you use. Read yours before you hire anyone.
  5. Scope it. Which systems, which records, and how many Colorado residents? That number decides whether the AG and the credit bureaus are involved, and answering it is forensic work.

Where we fit

A breach is three jobs at once. Someone has to find out what happened (digital forensics and incident investigation), close the hole so it doesn't happen again (information security), and get the business working (data management and recovery). We do all three, and we keep the evidence intact while we do it, so your attorney gets facts they can use.

If you are building the security program the statute expects, our SOC 2 playbook for Colorado businesses is a good place to start.

Frequently asked questions

Does the 30-day clock start on the day we were hacked? No. It starts on the date of determination, when there is sufficient evidence to conclude that a breach took place. Discovery and investigation come before it, and delaying the investigation on purpose doesn't help, because notice also has to be made "without unreasonable delay."

Fewer than 500 Colorado residents were affected. Do we still notify? Yes, you still notify the affected residents. The 500-resident threshold only decides whether the Attorney General must also be told.

Our IT company was the one breached. Whose problem is it? Both. The vendor must notify you and cooperate. You remain responsible for notifying your customers, and Colorado law generally expects you to have required reasonable security from that vendor in the first place.

Does encryption get us off the hook? The definition of personal information is built around data that was not encrypted. Whether your encryption actually protected the data, for example whether the keys were stored with it, is something the investigation has to establish. Don't assume it.

This article summarizes C.R.S. 6-1-713, 6-1-713.5 and 6-1-716 as printed in the 2026 Colorado Revised Statutes. It is not legal advice. Decisions about notification belong with your attorney.

If you think something has happened, contact us and we will start by preserving what you have.

Eboxlab Team
Denver, CO

Have a platform in mind?

We scope, design, and build systems that outlast the spreadsheet they replace.

Start a project →