Ley 1581 de 2012, General Personal Data Protection
Ley Estatutaria 1581 de 2012, arts. 1-30 (Proteccion de Datos Personales)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 17 October 2012.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Obtain the data subject's prior, explicit and informed authorization before collecting or processing their personal data, unless a statutory exception applies.
- Before processing sensitive personal data, including biometric data, health data, or data revealing racial or ethnic origin, political opinion, or religious belief, obtain the data subject's explicit authorization; sensitive-data processing is otherwise prohibited.
- Before requesting authorization, tell the data subject what their data will be used for, and let them consult, update, correct, or seek deletion of it.
- Do not transfer personal data to a country the Superintendencia de Industria y Comercio has not found to offer an adequate level of data protection, absent a recognized exception.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Who enforces it
Enforcement body
Superintendencia de Industria y Comercio (Delegatura para la Proteccion de Datos Personales)
What it reaches
Obligation class
Consent, Biometric, Data subject rights, Transfer, Disclosure
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 1 develops the constitutional right, under article 15 of the 1991 Constitution, of every person to know, update and rectify information collected about them in a database, and article 2 applies the law to personal data registered in any database made susceptible to processing by a public or private entity.
Article 9 requires the data controller to obtain the data subject's prior and informed authorization before processing their data, and article 4 sets the governing principles, including legality, purpose limitation, and security.
Article 5 defines sensitive data as data that affects a person's privacy or whose misuse can generate discrimination, expressly naming racial or ethnic origin, political opinion, religious or philosophical belief, union or human-rights-organization membership, health, sexual life, and biometric data, and article 6 prohibits processing sensitive data unless the data subject gives explicit authorization or a narrow statutory exception applies.
Articles 14 to 16 give the data subject rights to consult and to lodge a claim for correction, updating, or deletion with the controller, escalable to the Superintendencia de Industria y Comercio (SIC) once that internal process is exhausted.
Article 23 authorizes the SIC to impose administrative fines of up to 2,000 monthly legal minimum wages, suspend the processing activity for up to six months, or order the immediate and permanent closure of an operation involving sensitive data; the sanctions provided are purely administrative and the law does not create a criminal offense.
Article 26 prohibits transferring personal data of any kind to a country that does not provide an adequate level of data protection, as determined by SIC standards, subject to exceptions including the data subject's express consent and international cooperation exchanges.
When LexLint raises it
crawls_webprocesses_biometrics
Read the law
Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica