WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Ley 1581 de 2012 — reporting of security incidents to the Superintendencia de Industria y Comercio

Colombia security incident report

Colombia · October 17, 2012 (Ley 1581); RNBD incident reporting operative from the 2015 Circular

Verify details

Colombia's duty runs to the regulator, not to individuals — the mirror image of Mexico's. The statutory hook sits in the controller and processor duties in Arts. 17-18 of Ley 1581, which require informing the data protection authority when violations of the security codes occur and there are risks in the administration of data subjects' information. The reporting channel and the deadline come from the RNBD rules rather than the statute: incidents affecting databases registered in the Registro Nacional de Bases de Datos must be reported to the Superintendencia de Industria y Comercio as an update to the registration, within 15 business days of detection. That is by far the longest window in this dataset, and there is no general statutory duty to notify affected data subjects. Marked 'check': the operative texts are Spanish-language, the 15-business-day figure comes from SIC circulars rather than the Law, and the reporting duty is tied to RNBD registration — confirm whether your databases are registrable before assuming the channel applies.

Ley 1581 de 2012, Arts. 17-18 (duties of controllers and processors); Decreto 1074 de 2015; SIC Circular Externa 002 de 2015 and 003 de 2018 (Registro Nacional de Bases de Datos)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.