Colorado AG’s Office Issues Data Security Guidance

Ballard Spahr LLP
Contact

Ballard Spahr LLP

On January 28, 2022 the Consumer Protection Section of the Colorado Attorney General’s Office issued guidance regarding data security best practices.  Businesses subject to the Colorado Privacy Act can look to these best practices as a roadmap for the technical and organizational data security safeguards the law requires businesses to implement.

The guidance instructs covered entities to incorporate the following best practices:

  1. Inventory the types of data collected and establish a system for how to store and manage that data;
  2. Develop a written information security policy;
  3. Adopt a written data incident response plan;
  4. Mange vendor security;
  5. Train employees to prevent and respond to cybersecurity incidents;
  6. Follow the Department of Law’s ransomware guidance to improve cybersecurity and resilience against ransomware and other attacks;
  7. Timely notify victims and the authorities (when required) in the event of a security breach;
  8. Protect individuals affected by a data breach from identity theft and related harms; and
  9. Regularly review and update security policies.

The guidance in its entirety is available here.

While many companies may already follow these practices as part of the data security regime, their publication shows the increased focus on privacy and data security in Colorado in the run up to the Colorado Privacy Act going into effect in 2023.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Ballard Spahr LLP

Written by:

Ballard Spahr LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Ballard Spahr LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide