By Rob Whittet, Agency Partner | CO License #342852
The Colorado Privacy Act gives Colorado residents rights over their personal data and places real obligations on the businesses that collect and process it. It applies to any business that handles the personal data of 100,000 or more Colorado consumers in a year, or that makes money selling the data of 25,000 or more consumers, and it has been in effect since July 1, 2023. There is no revenue threshold, so a smaller Denver metro business that happens to handle a lot of customer data can fall under the law even when its sales are modest. The law does not require you to buy insurance. What it does is make a data breach considerably more expensive, because a breach now triggers legal obligations on top of the technical cleanup. Here is who the law covers, what it requires, what a breach actually costs, and where cyber liability insurance fits.
Most owners I talk with in the Denver metro assume a cyberattack is something that happens to big companies. The opposite is true. Attackers target small businesses precisely because their defenses are thinner, and the financial hit lands much harder on a business that cannot absorb a large recovery bill.
How the Colorado Privacy Act raises the stakes
This is where Colorado businesses face more exposure than most realize. The Colorado Privacy Act, passed as Senate Bill 21-200+ and effective July 1, 2023, gives Colorado residents rights over their personal data and places real obligations on the businesses that collect and process it. It applies to any business that handles the personal data of 100,000 or more Colorado consumers in a year, or that makes money selling the data of 25,000 or more consumers.
The Colorado Privacy Act is enforced by the Colorado Attorney General and district attorneys, and a violation is treated as a deceptive trade practice. The window the state gave businesses to fix violations before facing enforcement has closed, which means the Attorney General can now pursue actions directly. On top of that, separate Colorado law requires businesses to notify affected residents after a data breach, and those notifications carry real cost and legal risk of their own.
Cyber liability insurance does not make your business compliant with the Colorado Privacy Act, and it is not something the law requires you to buy. What it does is cover the financial fallout when a breach triggers those legal obligations. A cyber policy can pay for the breach investigation, the customer notifications the law demands, legal defense, the cost of responding to a regulatory inquiry, and in some cases regulatory fines where the law allows them to be insured. The privacy law is the reason a data breach in Colorado is more expensive than owners expect, and cyber coverage is what absorbs that cost.
What cyber liability insurance covers
Cyber coverage comes in two halves. First party coverage, sometimes called data breach insurance, pays for the direct costs your business faces after an incident: hiring forensic experts to investigate, notifying affected customers as the law requires, providing credit monitoring, restoring lost data, covering income lost while you are down, and handling ransom demands and the negotiation that comes with them. This is the coverage almost every business needs, because these are the bills that arrive whether or not anyone ever sues you.
Third party coverage handles the other side, the legal costs if a client sues your business for failing to protect their data. Technology firms and any company responsible for a client’s systems or information carry this, often bundled with errors and omissions insurance in a package called tech E&O. What matters most is understanding that your general liability and commercial property policies exclude cyber events almost entirely. Without a dedicated cyber policy, these costs come straight out of your own accounts.
What a breach costs, and what coverage costs
Small business premiums for cyber liability insurance commonly range from a few hundred dollars a year for a low-risk sole proprietor to several thousand dollars a year for a business handling more sensitive data. The difference comes down mostly to how much sensitive data you hold, how many employees can access it, your revenue, your industry, and the security controls you have in place.
Weigh that against what a breach actually costs. IBM’s 2025 breach report, which studied 600 breached organizations across 17 industries, put the average breach in the United States at 10.22 million dollars, a record high the report attributes partly to rising regulatory costs. A small Colorado business will not face a figure anywhere in that range, but the same research found customer personal information was the single most frequently compromised data type, involved in 53 percent of breaches. Recovery cost scales with how many customer records you hold and how long the intrusion goes undetected, and even a contained incident can run past what most small businesses keep in reserve.
Insurers now expect basic protections before they will offer coverage at all, and multi factor authentication on email and remote access has become close to a universal requirement. Putting those controls in place not only helps you qualify, it often lowers your rate. Many businesses also bundle cyber coverage with a business owners policy, and technology firms fold it into a tech E&O policy.
Why Denver area businesses work with an independent broker
Cyber policies vary more than almost any other coverage, and the differences hide in the details. As an independent broker based in Centennial, I match the coverage to the data your business actually holds, check the sublimits that carriers use to quietly cap the most common claims like ransomware and funds transfer fraud, confirm your policy includes regulatory defense given Colorado’s privacy law, and help you meet the security requirements carriers now demand. I also look for chances to bundle cyber with the rest of your business insurance where it lowers your total cost. A cyber policy is only as good as what it pays when a breach actually happens, and that is decided long before the attack.
Frequently Asked Questions
Who does the Colorado Privacy Act apply to?
The Colorado Privacy Act applies to any business that handles the personal data of 100,000 or more Colorado consumers in a year, or that earns revenue from selling the personal data of 25,000 or more Colorado consumers. There is no revenue threshold, so a smaller business that processes a large volume of consumer data can fall under the law even when its sales are modest. The law took effect July 1, 2023 and is enforced by the Colorado Attorney General and district attorneys.
Does the Colorado Privacy Act require businesses to carry cyber insurance?
No, the Colorado Privacy Act does not require any business to carry cyber insurance. The law applies to businesses that handle the personal data of 100,000 or more Colorado consumers a year or earn revenue selling the data of 25,000 or more consumers, and it creates obligations such as breach response and consumer notification that make a data breach expensive. Cyber liability insurance is what covers those costs when a breach occurs.
What does cyber liability insurance cover?
Cyber liability insurance covers the costs a business faces after a data breach or cyberattack, including forensic investigation, customer notification, credit monitoring, legal defense, lost income during downtime, and ransomware payments. It comes in first party coverage, which pays for your own breach response costs, and third party coverage, which pays legal costs if a client sues you over a breach, and standard general liability and property policies do not cover these events.
