Jurisdiction Guides / Americas
Colombia Privacy & Data Protection Laws
Every regime below can apply to a business handling Colombia residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Applies to personal data recorded in any database processed in Colombian territory, and to controllers not established in Colombia where Colombian law applies under international treaty or rules — a territorial/means test rather than a GDPR targeting test, so the trigger below is modeled on established presence only. Two duties catch foreign-owned Colombian entities by surprise: databases must be registered in the Registro Nacional de Bases de Datos (RNBD) maintained by the Superintendencia de Industria y Comercio, and prior authorization is required for international transfers unless the destination country is on the SIC's adequacy list or an approved transfer mechanism applies. The SIC is an active enforcer with meaningful fine practice. Processing of children's data is prohibited except where it respects the child's best interests and fundamental rights.
Cross-Border Data Transfer · 1
Art. 26 prohibits transferring personal data of any kind to countries that do not provide an adequate level of protection, with adequacy measured against standards set by the Superintendencia de Industria y Comercio that may in no case fall below the Law's own. The SIC maintains the list of countries it regards as adequate in Circular Externa 005 de 2017 — and a destination's ABSENCE from that list is the operative problem for most businesses, because it pushes the transfer onto one of Art. 26's six exceptions (including the data subject's express and unequivocal authorisation, and necessity for a contract) or requires a conformity declaration from the SIC. Note that Colombia distinguishes 'transferencia' (transfer to another controller) from 'transmision' (sending to a processor), and the two are treated differently — a distinction with no clean GDPR analogue that businesses routinely collapse. Marked 'check': the operative texts are Spanish-language and the adequacy list is a regulator instrument subject to change.
Data Security & Breach Notification · 1
Colombia's duty runs to the regulator, not to individuals — the mirror image of Mexico's. The statutory hook sits in the controller and processor duties in Arts. 17-18 of Ley 1581, which require informing the data protection authority when violations of the security codes occur and there are risks in the administration of data subjects' information. The reporting channel and the deadline come from the RNBD rules rather than the statute: incidents affecting databases registered in the Registro Nacional de Bases de Datos must be reported to the Superintendencia de Industria y Comercio as an update to the registration, within 15 business days of detection. That is by far the longest window in this dataset, and there is no general statutory duty to notify affected data subjects. Marked 'check': the operative texts are Spanish-language, the 15-business-day figure comes from SIC circulars rather than the Law, and the reporting duty is tied to RNBD registration — confirm whether your databases are registrable before assuming the channel applies.
Other Americas jurisdictions