House Bill 18-1128: The Consumer Data Privacy Law: Are you in Compliance?

House Bill 18-1128, effective on September 1, 2018, requires certain businesses to come into compliance with consumer data privacy protections. Does this law apply to associations and management companies? If so, how do you achieve compliance?

To whom does the law apply?

The new law applies to any entity/person that “maintains, owns or licenses personal identifying information in the court of the person’s business, vocation or occupation”.  Most management companies and common interest communities either maintain some of these documents or could potentially come into possession of this information.

What sort of information is protected?

Social security numbers, personal identification numbers, passwords, pass codes, driver’s licenses or other government issued identifications, biometric data or employer student or military identification number. While an association or management company may not be in possession of most of this information, a ‘personal identification number’ is typically tied into most homeowner accounts. Further, an association and/or management company may be in possession of social security information relating to association employees or even copies of driver licenses if it keeps copies when notarizing documents.

What needs to be done to protect the information?

It is recommended that a policy be adopted that provides for reasonable security procedures and practices for protected information. Also, the policy needs to define what occurs in the event of a security breach including proper disclosure procedures.

Is each managed association required to maintain a policy or can the management company maintain one policy for each client?

While the law is not clear on this point, I recommend that both management companies and each, individual association maintain a separate policy. This ensures that the policy is part of the association’s official records and further guarantees continued compliance in the event of a management company change.

Given the potential liability for not complying with the new law, associations and management companies should act quickly to adopt the requisite policy. The Dupont Law Firm is here to help prepare the policy at a reasonable cost.

duponts1

Share
Published by
duponts1

Recent Posts

Act Now: New HOA Legislation in Place

The Colorado legislature recently passed legislation relating to common interest communities that require actions to…

9 months ago

Senate Bill 23-213: Coming (possibly) to an HOA near you!

The passage of House Bill 22-1137 has caused most of us quite the amount of…

1 year ago

A solution for HB-1137 required collection notice postings: ‘HOA Postings’

Colorado House Bill 22-1137, effective on August 10, 2022, requires Associations to post a copy…

2 years ago

Has your community adopted the HB-1137 policies?

Effective on August 10, 2022, House Bill 22-1137 requires most common interest communities in Colorado…

2 years ago

Has your Association adopted policies to comply with the new legislation?

As you likely have heard, new legislation is in effect as of September 7, 2021…

3 years ago

Covid-19 Immunity Proposed: Does it Apply to Associations?

House Bill 21-1074 was introduced on February 16, 2021 and proposes to provide immunity from…

3 years ago