Law / United States / Colorado

Colorado Cybercrime statute (unauthorized access, tracking the federal CFAA)

C.R.S. § 18-5.5-102

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 July 2000.

A computer misuse rule binding public and private bodies.

As of 29 August 2026.

What it requires

  • Do not access a Colorado-connected computer without authorization, or beyond the scope of granted authorization, to collect data; this statute's language closely tracks the federal Computer Fraud and Abuse Act (CFAA) rather than a broader state standard.
  • No Colorado court has yet decided whether a public, unauthenticated page counts as authorized under this statute, so treat that question as unsettled rather than resolved by analogy to federal case law.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Subsection (1)(a) makes it a cybercrime for a person to knowingly access a computer without authorization, exceed authorized access, or use a computer without authorization or in excess of authorized access, language that tracks the federal Computer Fraud and Abuse Act (CFAA)'s structure almost verbatim rather than California's broader without permission standard.

No Colorado court has construed this language in a scraping context, so whether Colorado would follow the narrow, gates-based reading the US Supreme Court gave the federal statute in Van Buren v. United States (593 U.S. 374, 2021) is unsettled as a matter of Colorado law.

A 2018 act (HB 18-1200, session law chapter 379, confirmed against the official signed act) renamed the section from computer crime to cybercrime and added the current subsections (1)(h) through (1)(j) and an escalated penalty tier; a 2023 act (HB 23-1293, confirmed against the official signed act) amended only the repeat-offender penalty clause at (3)(b), not the underlying conduct definition at (1)(a).

The underlying text is confirmed directly against the official Colorado Revised Statutes (leg.colorado.gov): the section's own source note shows the article was entire added in 1979, subsection (1) was amended in 1983, and the entire section was reenacted in 2000; no amendment since 2000 has touched subsection (1)(a) itself, so the currently codified without-authorization or exceeds-authorized-access language traces to that 2000 reenactment rather than to the 1979 original.

When LexLint raises it

  • crawls_web

Read the law

official text, Colorado Revised Statutes, Office of Legislative Legal Services (leg.colorado.gov)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app