Law / Colombia

Ley 1581 de 2012, General Personal Data Protection

Ley Estatutaria 1581 de 2012, arts. 1-30 (Proteccion de Datos Personales)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 17 October 2012.

A comprehensive regime rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Obtain the data subject's prior, explicit and informed authorization before collecting or processing their personal data, unless a statutory exception applies.
  • Before processing sensitive personal data, including biometric data, health data, or data revealing racial or ethnic origin, political opinion, or religious belief, obtain the data subject's explicit authorization; sensitive-data processing is otherwise prohibited.
  • Before requesting authorization, tell the data subject what their data will be used for, and let them consult, update, correct, or seek deletion of it.
  • Do not transfer personal data to a country the Superintendencia de Industria y Comercio has not found to offer an adequate level of data protection, absent a recognized exception.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Who enforces it

Enforcement body

Superintendencia de Industria y Comercio (Delegatura para la Proteccion de Datos Personales)

What it reaches

Obligation class

Consent, Biometric, Data subject rights, Transfer, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 1 develops the constitutional right, under article 15 of the 1991 Constitution, of every person to know, update and rectify information collected about them in a database, and article 2 applies the law to personal data registered in any database made susceptible to processing by a public or private entity.

Article 9 requires the data controller to obtain the data subject's prior and informed authorization before processing their data, and article 4 sets the governing principles, including legality, purpose limitation, and security.

Article 5 defines sensitive data as data that affects a person's privacy or whose misuse can generate discrimination, expressly naming racial or ethnic origin, political opinion, religious or philosophical belief, union or human-rights-organization membership, health, sexual life, and biometric data, and article 6 prohibits processing sensitive data unless the data subject gives explicit authorization or a narrow statutory exception applies.

Articles 14 to 16 give the data subject rights to consult and to lodge a claim for correction, updating, or deletion with the controller, escalable to the Superintendencia de Industria y Comercio (SIC) once that internal process is exhausted.

Article 23 authorizes the SIC to impose administrative fines of up to 2,000 monthly legal minimum wages, suspend the processing activity for up to six months, or order the immediate and permanent closure of an operation involving sensitive data; the sanctions provided are purely administrative and the law does not create a criminal offense.

Article 26 prohibits transferring personal data of any kind to a country that does not provide an adequate level of data protection, as determined by SIC standards, subject to exceptions including the data subject's express consent and international cooperation exchanges.

When LexLint raises it

  • crawls_web
  • processes_biometrics

Read the law

Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica

Back to the example  ·  Lint your app