Law status
Verified comprehensive law
Yes - Colorado Privacy Act
- Official name / citation
- Colo. Rev. Stat. §§ 6-1-1301 to 6-1-1313 (SB 21-190, Ch. 483)
- Status / effective date
- Enacted and in force per fetched session law
- Principal enforcer
- Colorado Attorney General (and district attorneys under the CPA's own terms; state-level enforcer is the AG)
Direct attached-library attribution
0 cases · $0
These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.
The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.
Official law sources
Other generally applicable PII law
n.a.
Public enforcement context
Tier 1
23andMe (bankruptcy claims)
$18 million to participating states; Colorado share stated as $394,324; separate $46.75 million class settlement · July 14, 2026
Colorado joined 41 other AGs resolving claims over the 2023 23andMe genetic-data breach.
Legal basis: State privacy/consumer-protection claims in bankruptcy
Mapped control outcomes
1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence
Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.
Educational information, not legal advice. The supplied snapshot is dated August 25, 2026; confirm current law, applicability, exceptions, official status, and reporting decisions with qualified counsel and the relevant authority.