Colorado's security posture rests on two enacted state statutes added and amended together by HB 18-1128 (2018 Colo. Sess. Laws ch. 266, signed May 29, 2018, effective September 1, 2018): C.R.S. 6-1-713.5, requiring a covered entity that maintains, owns, or licenses the personal identifying information of a Colorado resident to implement and maintain reasonable security procedures and practices appropriate to the nature of that information and the nature and size of the business, and its disposal-of-documents sibling, C.R.S. 6-1-713, requiring a written policy to destroy or dispose of paper and electronic documents containing personal identifying information by shredding, erasing, or otherwise rendering it unreadable once no longer needed.
Both duties bind only a private person or commercial entity; a governmental entity's parallel duties sit at C.R.S. 24-73-102 (protection) and 24-73-103 (breach notice), outside this profile's private-sector scope.
No enacted Colorado statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's or Oregon's connected-device statutes; a search for a Colorado IoT or product-security bill returned only the state's general data-protection statutes, so this is treated as a researched absence rather than a gap in coverage.
No Colorado statute or regulation setting a sector-specific cyber-resilience regime for a software or technology provider, comparable to New York's 23 NYCRR Part 500, was located; the Colorado Division of Insurance may separately regulate insurer cybersecurity, but no citable text was located to support a row.
The Colorado Privacy Act carries its own security-of-processing clause, C.R.S. 6-1-1308(5)'s duty of care, requiring a controller to take reasonable measures to secure personal data during storage and use from unauthorized acquisition, appropriate to the volume, scope, and nature of the personal data and the nature of the business; because that duty is a section of Colorado's comprehensive data-protection act rather than a standalone security statute, it is this jurisdiction's privacy row, not a second row here.
Colorado's breach-notification duty, C.R.S. 6-1-716, is likewise already this jurisdiction's privacy row: a person or commercial entity that experiences unauthorized acquisition of unencrypted computerized personal identifying information must notify affected Colorado residents within 30 days of determination, the Attorney General once 500 or more residents are affected, and nationwide consumer reporting agencies once more than 1,000 are affected.
Enforcement of both security-topic statutes runs through C.R.S. 6-1-716(4), which lets the Attorney General bring an action in law or equity to address a violation of section 6-1-716, 6-1-713, or 6-1-713.5, either to compel compliance or to recover direct economic damages, and states that this route is not exclusive of other applicable law.
Because 6-1-713 and 6-1-713.5 sit in part 7 of the Colorado Consumer Protection Act, a violation of either is also a deceptive trade practice under C.R.S. 6-1-105(1)(x) (violating part 7 of the article), which reaches the article's general civil penalty of up to $20,000 per violation under C.R.S. 6-1-112(1)(a) (up to $50,000 per violation against an elderly person), enforced by the Attorney General or a district attorney, and a private right of action under C.R.S. 6-1-113 for actual damages (with prejudgment interest), a $500 statutory minimum, treble damages on clear and convincing evidence of bad faith, and attorney fees.
This is a broader private remedy than New York's SHIELD Act safeguards duty, which creates no private right of action at all.