Protections For Consumer Data Privacy
Data privacy - required policies - covered and governmental entities. Except for conduct in compliance with applicable federal, state, or local law, the act requires covered and governmental entities in Colorado that maintain paper or electronic documents (documents) that contain personal identifying information (personal information) to develop and maintain a written policy for the destruction and proper disposal of those documents. Entities that maintain, own, or license personal information, including those that use a nonaffiliated third party as a service provider, shall implement and maintain reasonable security procedures for the personal information. The notification laws governing disclosure of unauthorized acquisitions of unencrypted and encrypted computerized data are expanded to specify who must be notified following such unauthorized acquisition and what must be included in such notification.
(Note: This summary applies to this bill as enacted.)