Ley 1581 de 2012, Supervisory Authority and Sanctions
Ley 1581 de 2012, arts. 19-24 (Autoridad y Sanciones)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 17 October 2012.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Expect the Superintendencia de Industria y Comercio to investigate a violation on its own initiative or on complaint and to order the measures needed to make the habeas data right effective, including access, rectification, updating or deletion of the data at issue.
- Expect the Superintendencia de Industria y Comercio to temporarily block your processing of a data subject's information where the evidence shows a real risk to their fundamental rights, until it reaches a final decision.
- Comply with an administrative fine of up to 2,000 current monthly legal minimum wages, a suspension of your processing activity for up to six months, or the immediate and permanent closure of an operation involving sensitive data, imposed by the Superintendencia de Industria y Comercio for violating this law; these sanctions apply only to private parties, and a public authority's violation goes to the Procuraduria General de la Nacion instead.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Who enforces it
Enforcement body
Superintendencia de Industria y Comercio (Delegatura para la Proteccion de Datos Personales)
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 19 designates the Superintendencia de Industria y Comercio, acting through its Delegatura para la Proteccion de Datos Personales, as the authority that oversees compliance with this law's principles, rights, guarantees and procedures.
Article 21 empowers the Superintendencia to investigate a violation on its own initiative or on complaint and order the measures needed to make the habeas data right effective, temporarily block a controller's processing where the evidence shows a real risk to a data subject's fundamental rights, promote and publicize data subjects' rights, instruct controllers and processors on adapting their operations to this law, issue the declaration of conformity for an international transfer, and administer the National Public Registry of Databases.
Article 22 requires the Superintendencia, once it establishes a violation, to apply the Codigo Contencioso Administrativo for anything this law does not itself regulate, and the sanctions this law provides are purely administrative, since it creates no criminal offense.
Article 23 lets the Superintendencia impose a fine of up to 2,000 current monthly legal minimum wages, suspend the processing activity for up to six months, or order the immediate and permanent closure of an operation that involves sensitive data, reserving these sanctions for private parties and referring a public authority's violation to the Procuraduria General de la Nacion instead.
Article 24 grades a sanction by the extent of the harm or danger, the economic benefit the infringer or a third party obtained, repeat infringement, resistance or obstruction of the investigation, defiance of the Superintendencia's orders, and the infringer's own acknowledgment of the violation before the sanction is imposed.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.