Comprehensive Privacy Law
General Regime for the Protection of Personal Data (Statutory Law 1581 of 2012)
Colombia · October 17, 2012
Verify detailsApplies to personal data recorded in any database processed in Colombian territory, and to controllers not established in Colombia where Colombian law applies under international treaty or rules — a territorial/means test rather than a GDPR targeting test, so the trigger below is modeled on established presence only. Two duties catch foreign-owned Colombian entities by surprise: databases must be registered in the Registro Nacional de Bases de Datos (RNBD) maintained by the Superintendencia de Industria y Comercio, and prior authorization is required for international transfers unless the destination country is on the SIC's adequacy list or an approved transfer mechanism applies. The SIC is an active enforcer with meaningful fine practice. Processing of children's data is prohibited except where it respects the child's best interests and fundamental rights.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.