Colorado Code § 24-73-102

Governmental entity - protection of personal identifying information - definition
Open in Lexace · Ask the AI about this section
(1) To protect personal identifying information, as defined in section 24-73-101
(4)(b), from unauthorized access, use, modification, disclosure, or destruction, a governmental
entity that maintains, owns, or licenses personal identifying information shall implement and
maintain reasonable security procedures and practices that are appropriate to the nature of the
personal identifying information and the nature and size of the governmental entity.
(2) Unless a governmental entity agrees to provide its own security protection for the
information it discloses to a third-party service provider, the governmental entity shall require
that the third-party service provider implement and maintain reasonable security procedures and
practices that are:
(a) Appropriate to the nature of the personal identifying information disclosed to the
third-party service provider; and
(b) Reasonably designed to help protect the personal identifying information from
unauthorized access, use, modification, disclosure, or destruction.
(3) For the purposes of subsection (2) of this section, a disclosure of personal identifying
information does not include disclosure of information to a third party under circumstances
where the governmental entity retains primary responsibility for implementing and maintaining
reasonable security procedures and practices appropriate to the nature of the personal identifying
information and the governmental entity implements and maintains technical controls reasonably
designed to:
(a) Help protect the personal identifying information from unauthorized access,
modification, disclosure, or destruction; or
(b) Effectively eliminate the third party's ability to access the personal identifying
information, notwithstanding the third party's physical possession of the personal identifying
information.
(4) A governmental entity that is regulated by state or federal law and that maintains
procedures for storage of personal identifying information pursuant to the laws, rules,
regulations, guidances, or guidelines established by its state or federal regulator is in compliance
with this section.
(5) For the purposes of this section, "third-party service provider" means an entity that
has been contracted to maintain, store, or process personal identifying information on behalf of a
governmental entity.

‹ Prev All Colorado sections Next ›


Lexace provides legal information, not legal advice, and no attorney–client relationship is created. Statute text is provided for general information and may not reflect the most recent amendments; verify against the official state code.