Data Security & Breach Notification
Ley 1581 de 2012 — reporting of security incidents to the Superintendencia de Industria y Comercio
Colombia · October 17, 2012 (Ley 1581); RNBD incident reporting operative from the 2015 Circular
Verify detailsColombia's duty runs to the regulator, not to individuals — the mirror image of Mexico's. The statutory hook sits in the controller and processor duties in Arts. 17-18 of Ley 1581, which require informing the data protection authority when violations of the security codes occur and there are risks in the administration of data subjects' information. The reporting channel and the deadline come from the RNBD rules rather than the statute: incidents affecting databases registered in the Registro Nacional de Bases de Datos must be reported to the Superintendencia de Industria y Comercio as an update to the registration, within 15 business days of detection. That is by far the longest window in this dataset, and there is no general statutory duty to notify affected data subjects. Marked 'check': the operative texts are Spanish-language, the 15-business-day figure comes from SIC circulars rather than the Law, and the reporting duty is tied to RNBD registration — confirm whether your databases are registrable before assuming the channel applies.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.