Colorado · verified official-source register

Colorado Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Colorado case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

23andMe

Date
July 14, 2026
Amount
$18 million paid to the states immediately; Colorado will receive $394,324; separate $46.75 million class-action settlement for affected U.S. consumers
Legal basis
Colorado’s data privacy and security laws; Colorado Privacy Act

Why the action was brought

23andMe’s 2023 credential-stuffing data breach compromised genetic and other customer data of 6.9 million consumers worldwide, including 140,517 Coloradans; some genetic ancestry information was published for sale on the dark web. The multistate investigation found unreasonable data-security practices, including delayed discovery, initial denial, and refusal to accept responsibility.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Marriott International, Inc.

Date
Oct. 9, 2024
Amount
$52 million payment to states; Colorado’s share: $822,434
Legal basis
state consumer protection laws and personal information protection laws

Why the action was brought

Marriott’s Starwood guest reservation system breach exposed 131.5 million U.S. guest records, including contact, gender, birth-date, reservation, stay-preference, limited unencrypted passport, and unexpired payment-card information. Intruders remained undetected from July 2014 through September 2018; Marriott acquired Starwood in 2016 but failed to diagnose and disclose the breach until years later, violating consumer and personal-information protection laws.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Blackbaud

Date
Oct. 5, 2023
Amount
$49.5 million payment to states; Colorado will receive over $785,000; $785,000 Blackbaud will pay
Legal basis
state and federal consumer protection, data security, and health information laws

Why the action was brought

Blackbaud’s 2020 ransomware breach exposed contact and demographic information, Social Security and driver’s-license numbers, financial and employment information, donation history, and protected health information. The company allegedly failed to implement reasonable security, remediate known gaps, and provide customers timely, accurate notifications, causing significantly delayed or absent consumer notifications and misleading customers about notification requirements.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.