Ley 1581 de 2012, Security Breach Notification to the Authority
Ley 1581 de 2012, arts. 17(n), 18(k) (Notificacion de Violaciones de Seguridad)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 17 October 2012.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Superintendencia de Industria y Comercio when a violation of the security codes occurs and creates a risk in the administration of a data subject's personal information; the law fixes no deadline for this notice.
- As a data processor, notify the Superintendencia de Industria y Comercio under the same terms when a security code violation creates that risk; neither duty requires telling the affected data subject directly.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 17(n) requires a data controller to inform the data protection authority when a violation of the security codes occurs and there is a risk in the administration of a data subject's information. Article 18(k) imposes the identical duty on a data processor, requiring it to inform the Superintendencia de Industria y Comercio under the same terms.
Neither literal fixes a deadline for the notice or requires telling the affected data subject directly, so the clock this law states runs only to the Superintendencia, triggered by a security code violation that creates that risk.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbot
Read the law
Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.