Law / Colombia

Colombia

7 of 9 named instruments researched to a stage, across four of the six areas of law we track: 7 in force. As of 5 September 2026.

When they take effect7 of 7 carry a date. Earlier is before 2014.
Before 2014: 4 instruments (4 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 1 instrument (1 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 0 instruments 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 2
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (159 words)

Colombia has no general artificial-intelligence statute in force. Documento CONPES 4144 de 2025, adopted 14 February 2025 by the Consejo Nacional de Politica Economica y Social, is a national AI policy document that sets strategic objectives and directs public entities to adopt ethical AI principles, but a CONPES document is an executive-branch policy directive rather than a law and creates no legal obligation on a private actor.

Proyecto de Ley 043 de 2025 Senado, 324 de 2025 Camara, a government-sponsored comprehensive AI regulation bill inspired by the European Union's AI Act, remains pending before Congress and has not been enacted.

The one enacted, AI-specific legal duty is a criminal aggravation: Ley 2502 de 2025 amended article 296 of the Codigo Penal so that when the personal-falsehood offense is committed by impersonating a person through an artificial-intelligence-generated deepfake, the fine is increased by up to one third; that amendment took effect one year after the law's 28 July 2025 sanction.

AI prohibited practices

Codigo Penal, Falsedad Personal, AI Deepfake Aggravation

Ley 599 de 2000, art. 296 (as amended by Ley 2502 de 2025)Ley 2502 de 2025, official text, Regimen Legal de Bogota D.C. (Secretaria Juridica Distrital)

In force 50 days, effective 28 July 2026. Binds public and private bodies.

What this law does

Article 296 of the Codigo Penal punishes with a fine whoever, to obtain a benefit for themselves or another or to cause harm, substitutes or impersonates a person or attributes to themselves a name, age, marital status, or capacity with legal effects, provided the conduct does not constitute another offense; the article carries no term of imprisonment.

Ley 2502 de 2025 added a second paragraph providing that when the personal falsehood is committed using artificial intelligence, the fine is increased by up to one third, and article 2 defines a deepfake as the creation, modification, or use of a false audiovisual record, including photographs, videos, images or sound recordings, made through artificial intelligence so that it appears to be a real person's authentic speech or conduct.

Article 6 of Ley 2502 de 2025 delayed this amendment's commencement to one year after the law's sanction and promulgation on 28 July 2025, so the deepfake aggravation itself entered into force on 28 July 2026, while the law's other provisions, including its definitions and its public-policy directives to the National Government, the Fiscalia and the Policia Nacional, took effect immediately on sanction.

What it requires

Privacy law2 instruments, 2 in force

Research summary (123 words)

Colombia's comprehensive personal-data regime is Ley Estatutaria 1581 de 2012, grounded in the constitutional habeas data right and enforced by the Superintendencia de Industria y Comercio (SIC), requiring the data subject's prior, explicit and informed authorization before their personal data is collected or processed and naming biometric data expressly as a sensitive category subject to heightened restrictions.

The SIC's Circular Externa No. 002 de 2024 extends this technology-neutral regime to artificial intelligence systems, and states that personal data being accessible on the internet does not make it data of a public nature exempt from the authorization requirement. Ley 1581 also prohibits transferring personal data to a country the SIC has not found to offer an adequate level of protection, subject to statutory exceptions.

Comprehensive regime

Ley 1581 de 2012, General Personal Data Protection

Ley Estatutaria 1581 de 2012, arts. 1-30 (Proteccion de Datos Personales)Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica

In force since 17 October 2012. Binds public and private bodies.

What this law does

Article 1 develops the constitutional right, under article 15 of the 1991 Constitution, of every person to know, update and rectify information collected about them in a database, and article 2 applies the law to personal data registered in any database made susceptible to processing by a public or private entity.

Article 9 requires the data controller to obtain the data subject's prior and informed authorization before processing their data, and article 4 sets the governing principles, including legality, purpose limitation, and security.

Article 5 defines sensitive data as data that affects a person's privacy or whose misuse can generate discrimination, expressly naming racial or ethnic origin, political opinion, religious or philosophical belief, union or human-rights-organization membership, health, sexual life, and biometric data, and article 6 prohibits processing sensitive data unless the data subject gives explicit authorization or a narrow statutory exception applies.

Articles 14 to 16 give the data subject rights to consult and to lodge a claim for correction, updating, or deletion with the controller, escalable to the Superintendencia de Industria y Comercio (SIC) once that internal process is exhausted.

Article 23 authorizes the SIC to impose administrative fines of up to 2,000 monthly legal minimum wages, suspend the processing activity for up to six months, or order the immediate and permanent closure of an operation involving sensitive data; the sanctions provided are purely administrative and the law does not create a criminal offense.

Article 26 prohibits transferring personal data of any kind to a country that does not provide an adequate level of data protection, as determined by SIC standards, subject to exceptions including the data subject's express consent and international cooperation exchanges.

What it requires

Superintendencia Circular on AI and Personal Data

SIC Circular Externa 002 de 2024 (Lineamientos sobre Tratamiento de Datos Personales en Sistemas de Inteligencia Artificial) 21 de agosto de 2024Official Circular Externa text, Superintendencia de Industria y Comercio

In force since 21 August 2024. Binds public and private bodies.

What this law does

The SIC's Circular Externa No. 002 de 2024 instructs every data controller and processor subject to Ley 1581 de 2012 and Ley 1266 de 2008 on how those technology-neutral statutes apply to developing, deploying, or using an artificial intelligence system that processes personal data.

It states that personal data being accessible on the internet does not make it data of a public nature, so a controller that collects personal, semi-private, or sensitive data online is not thereby entitled to treat it for an AI system's purposes without the data subject's prior, express and informed authorization.

It requires a documented privacy impact assessment before an AI system likely to pose a high risk to data subjects processes their personal data, requires privacy-by-design measures such as differential privacy so that training data cannot identify the person who provided it, and requires that a data subject be able to obtain, at any time and without restriction, information about how an AI system is processing their personal data.

What it requires

Scraping law3 instruments, 3 in force

Research summary (275 words)

Colombia has no scraping-specific statute, so general law governs each dimension separately.

Article 269A of the Codigo Penal, inserted by Ley 1273 de 2009, criminalizes accessing a computer system without authorization or beyond what was agreed, whether or not the system is protected by a security measure, so a plain reading reaches unauthorized access to an unprotected, public page and does not require defeating a technical control; no reported Colombian case confirms or narrows that reading for a scraper reading a public unauthenticated page.

Article 269F separately criminalizes obtaining, compiling, or extracting personal data from a file, database, or similar medium without authorization and for one's own or a third party's benefit, so scraping personal data without authorization exposes the scraper to that offense independently of Ley 1581 de 2012's administrative regime, which applies to scraped personal data without a general public-accessibility carve-out.

Ley 23 de 1982, as amended by Ley 1915 de 2018, gives the author the exclusive right to authorize or prohibit reproduction of a work by any means, including temporary electronic storage, and creates no text-and-data-mining exception and no opt-out mechanism, so training a model on scraped copyrighted text rests only on the narrow enumerated exceptions (quotation, teaching illustration, private and non-commercial single-copy reproduction) rather than a general research or text and data mining (TDM) ground; Colombian copyright law confers no sui generis database right, protecting a compilation only as a collective work.

No Colombian statute or reported case establishes a scraping-specific unfair-competition or misappropriation doctrine, assigns legal weight to a robots.txt directive, or imposes an AI-training-specific rule, and no Colombian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

Computer misuse

Codigo Penal, Acceso Abusivo a un Sistema Informatico

Ley 599 de 2000, art. 269A (added by Ley 1273 de 2009)Ley 1273 de 2009

In force since 5 January 2009. Binds public and private bodies.

What this law does

Article 269A punishes whoever, without authorization or beyond what was agreed, accesses in whole or part a computer system protected or not by a security measure, or remains within it against the will of the person entitled to exclude them, with imprisonment of 48 to 96 months and a fine of 100 to 1,000 monthly legal minimum wages.

Because the article expressly covers a system whether or not it is protected by a security measure, its authorization test does not, on its plain text, require defeating a technical access control the way jurisdictions that condition the offense on infringing a security measure do.

What it requires

Copyright and text and data mining (TDM)

Copyright Act, Exclusive Reproduction Right, No Text and Data Mining Exception

Ley 23 de 1982, art. 12 (as amended by Ley 1915 de 2018)Ley 23 de 1982 sobre Derechos de Autor, as amended by Ley 1915 de 2018, official text, WIPO Lex

In force since 12 July 2018. Binds public and private bodies.

What this law does

Article 12, as rewritten by article 3 of Ley 1915 de 2018, gives the author the exclusive right to authorize or prohibit reproduction of the work by any means or form, permanent or temporary, including temporary electronic storage, as well as communication to the public, distribution, importation, commercial rental, and transformation.

Ley 23 de 1982 creates no text-and-data-mining exception and no machine-readable opt-out mechanism; its narrow enumerated exceptions (quotation with attribution, illustration for non-commercial teaching, single-copy reproduction for private non-commercial use) do not create a general ground for reproducing copyrighted text to train a model.

Colombian copyright law confers no sui generis database right; a compilation is protected only as a collective work for eighty years from publication in favor of its director, under article 24.

What it requires

Personal data

Codigo Penal, Violacion de Datos Personales

Ley 599 de 2000, art. 269F (added by Ley 1273 de 2009)Ley 1273 de 2009

In force since 5 January 2009. Binds public and private bodies.

What this law does

Article 269F punishes whoever, without authorization and for their own or a third party's benefit, obtains, compiles, extracts, offers, sells, exchanges, sends, buys, intercepts, discloses, modifies, or uses personal codes or personal data contained in files, archives, databases, or similar media, with imprisonment of 48 to 96 months and a fine of 100 to 1,000 monthly legal minimum wages.

Scraping personal data without the controller's authorization can independently expose the scraper to this criminal offense, on top of the administrative duties Ley 1581 de 2012 imposes on the processing itself; the Superintendencia de Industria y Comercio's Circular Externa 002 de 2024 states that personal data being accessible on the internet does not make it data of a public nature, so Colombia's personal-data regime does not carve out publicly accessible personal data from its own reach.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (204 words)

Colombia has no press-publisher neighbouring right of the kind the European Union's Digital Single Market Directive article 15 creates, and no mandatory platform-to-publisher bargaining code; the general copyright framework of Ley 23 de 1982, as amended by Ley 1915 de 2018, is the only law reaching an aggregator's reproduction of news content.

Article 31 permits quoting an author by transcribing necessary passages, provided they are not so extensive as to amount to a simulated and substantial reproduction, with the source author and title named in each citation.

Articles 33 to 35 separately permit reproducing titles, photographs, illustrations and commentary about current events published by the press or broadcast, unless expressly prohibited, and permit the lawful reproduction, distribution and communication to the public of news or other information about facts that have already been publicly disseminated by the press or broadcasting, without requiring authorization; no reported Colombian decision applies these articles to a systematic news aggregator as opposed to an individual republication.

No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer. The statute predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

Snippet reproduction

Copyright Act, News Reporting and Press Reproduction Exception

Ley 23 de 1982, arts. 33-35 (Noticias de Actualidad)Ley 23 de 1982 sobre Derechos de Autor, official text, WIPO Lex

In force since 28 January 1982. Binds public and private bodies.

What this law does

Article 33 permits reproducing any title, photograph, illustration or commentary about a current event that has been published by the press or broadcast by radio or television, unless this has been expressly prohibited. Article 34 makes it lawful to reproduce, distribute, and communicate to the public news or other information about facts or events that have already been publicly disseminated by the press or broadcasting, with no authorization required.

Article 35 lets speeches, addresses, sermons and similar works delivered in public be published as current-events news in the press, by radio or by television without authorization, unless the author has expressly reserved ownership, though such works may not be published in a separate collection without the author's permission. None of the three articles caps a headline's or extract's length beyond the express-prohibition and non-collection conditions they each state.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.