HB26-1091 would create a new set of consumer data privacy rules for homeowner’s insurance transactions in Colorado. The bill limits when insurers, insurance producers, surplus line insurers, their affiliates, and processors may collect, use, retain, share, or sell a consumer’s personal data. In general, personal data could be used only for purposes reasonably necessary to transact homeowner’s insurance or for other purposes the consumer specifically authorizes. For uses outside the insurance transaction—such as targeted advertising, sale of data, or joint marketing of cobranded financial products—the bill requires affirmative opt-in consent, and it prohibits retaliation against consumers who decline to consent.
The bill also gives consumers new rights to confirm whether their data is being processed, access it, request correction or deletion, and receive a portable copy in a usable format. Insurers would have to provide a detailed privacy notice, maintain retention and deletion policies, contractually bind processors to security and confidentiality requirements, and conduct data protection assessments for higher-risk processing. The bill further restricts underwriting practices by requiring specific reasons and supporting data for adverse underwriting decisions, and by prohibiting decisions based solely on a prior owner’s loss history or on certain processor-supplied data without independent support.
In terms of state law, the bill would add a new section to the insurance code, section 10-4-125, and amend the unfair practices statute to make any violation of the new privacy section an unfair or deceptive act or practice in the business of insurance. It authorizes enforcement by the insurance commissioner, including investigations and civil penalties, and it also creates a private right of action for aggrieved consumers with actual damages, statutory damages, attorney fees, and possible treble damages for bad-faith or intentional violations. The bill would apply beginning January 1, 2028, with certain contract and assessment requirements tied to that date, and it exempts depository institutions and affiliates already subject to federal Gramm-Leach-Bliley Act requirements in specified circumstances.
The overall sentiment reflected in the bill text is strongly pro-consumer and privacy-focused, with the General Assembly’s findings emphasizing confusion in existing privacy notices, overcollection of data, unwanted marketing, and the risk of retaliation or stale-data underwriting. Because there are no committee transcripts or recorded votes provided, there is no direct evidence of debate or bipartisan support in the materials supplied. However, the bill’s introduction and detailed consumer protections suggest an intent to respond to perceived gaps in insurance privacy law rather than to make incremental changes.
The main points of contention likely center on the breadth of the restrictions and the compliance burden on insurers and their vendors. Potentially sensitive issues include the opt-in requirement for non-insurance uses of data, the private right of action with statutory and treble damages, limits on underwriting inputs, mandatory data retention and deletion timelines, and the requirement for data protection assessments. The bill also reaches affiliates and processors, which could raise concerns from insurers about operational complexity, vendor management, and the scope of state regulation over insurance data practices.
The bill would add a new insurance-code section governing homeowner’s insurance consumer data privacy and would amend Colorado’s unfair insurance practices law to treat violations as unfair or deceptive acts or practices. It would impose new duties on insurers, producers, surplus line insurers, affiliates, processors, and certain related parties regarding notice, consent, access, correction, deletion, retention, security, contracting, underwriting disclosures, and data protection assessments. It also creates both administrative enforcement authority for the insurance commissioner and a private right of action for consumers, affecting insurers’ compliance obligations and litigation exposure beginning in 2028.
The bill’s framing is strongly supportive of consumer privacy and data control, and the legislative declaration describes the measure as closing gaps in existing protections and preventing overcollection, unwanted marketing, and retaliation. No committee testimony or vote record was provided, so there is no direct evidence of opposition or support from lawmakers in the supplied materials. The last recorded action—postponement indefinitely in the House Business Affairs & Labor Committee—suggests the bill did not advance, but the reason for that outcome is not available in the record provided.
Likely areas of contention include the bill’s broad restrictions on data processing, the requirement for affirmative opt-in consent for non-insurance uses, and the creation of a private right of action with statutory and treble damages. Insurers may also object to the limits on underwriting decisions, the obligation to disclose specific reasons and source data for adverse underwriting actions, and the operational burden of processor contracts, audits, retention schedules, and data protection assessments. Consumer advocates would likely support these provisions, while industry stakeholders may argue they are overly prescriptive or costly.