In response to the increasing number of massive data breaches over the last several years, the Colorado legislature passed new requirements for protecting the personal information of Colorado residents. The Colorado Protections for Consumer Data Privacy (HB18-1128) applies to public and private organizations that handle, process, store or otherwise have access to electronic or printed personally identifiable information (PII) of Colorado residents.
Key actions organizations need to take include:
There are additional details, but these are the major items to address. The measures are required now, as the law went into effect on September 1, 2018. The law requires disclosure of a breach to the Colorado Attorney General, when that occurs, the AG’s office will investigate and determine if the reporting organization demonstrated due care or if penalties are appropriate. We recommend organizations review the requirements, implement missing components and make sure you are demonstrating due care.
If you have questions about these new requirements and the impact to your organization, please contact one of RubinBrown’s Cyber Security Services Group professionals.
Readers should not act upon information presented without individual professional consultation.
Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.