Colombia

Comprehensive

Law 1581 of 2012 (Statutory Law on Data Protection)

Authority: Superintendence of Industry and Commerce (SIC) | Enforcement: Active | Enacted: October 2012

Overview

Colombia has comprehensive data protection since 2012. The SIC actively enforces the law with significant fines. Colombia has EU adequacy status. The framework covers consent, data subject rights, international transfers, and DPO requirements.

14-Topic Coverage

Data Protection Authority

Fully Addressed

SIC's Delegatura for Data Protection oversees compliance and enforcement.

Data Subject Rights

Fully Addressed

Rights to access, update, rectify, delete, and revoke consent.

Cross-Border Transfer

Fully Addressed

Transfers to adequate countries per SIC list, or with consent. Colombia has EU adequacy.

Breach Notification

Partially Addressed

No explicit statutory requirement. SIC guidance recommends notification.

DPO Requirements

Partially Addressed

Must designate person or area for processing requests. Not formally called DPO.

Children's Data

Fully Addressed

Children's data classified as sensitive. Parental or guardian consent required.

Penalties & Enforcement

Fully Addressed

Fines up to 2,000 minimum wages (approx. COP 2.6 billion). Database suspension. Active enforcement.

Sector-Specific Rules

Fully Addressed

SFC financial data rules, health data regulations, telecom provisions.

AI & Automated Decisions

Not Addressed

No specific AI or automated decision provisions.

Data Localisation

Not Addressed

No general data localisation requirement.

Significant Data Fiduciary

Not Addressed

No equivalent concept.

Government Data

Fully Addressed

Law applies to both public and private sector. Transparency Law also applies.