WorldPrivacyAtlas
Laws by country

Cross-Border Data Transfer

Ley 1581 de 2012 — international transfer of personal data

Colombia Ley 1581 Art. 26

Colombia · October 17, 2012; SIC Circular Externa 005 de 2017 from August 2017

Verify details

Art. 26 prohibits transferring personal data of any kind to countries that do not provide an adequate level of protection, with adequacy measured against standards set by the Superintendencia de Industria y Comercio that may in no case fall below the Law's own. The SIC maintains the list of countries it regards as adequate in Circular Externa 005 de 2017 — and a destination's ABSENCE from that list is the operative problem for most businesses, because it pushes the transfer onto one of Art. 26's six exceptions (including the data subject's express and unequivocal authorisation, and necessity for a contract) or requires a conformity declaration from the SIC. Note that Colombia distinguishes 'transferencia' (transfer to another controller) from 'transmision' (sending to a processor), and the two are treated differently — a distinction with no clean GDPR analogue that businesses routinely collapse. Marked 'check': the operative texts are Spanish-language and the adequacy list is a regulator instrument subject to change.

Ley 1581 de 2012, Art. 26; SIC Circular Externa 005 de 2017Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.