Data Protection Atlas

Colombia

Tier 3 Comprehensive law Americas

Principal framework: Law 1581 on Personal Data Protection (2012). Regulator: SIC. Law 1581/2012 sits in the habeas data tradition; the SIC enforces actively and larger companies must register databases in the RNBD.

At a glance

Principal law
Law 1581 on Personal Data Protection
Regulator
SIC
Breach notification
Security incidents reported to the SIC (RNBD registry)
Maximum penalty
Fines up to about 2,000 minimum monthly wages
DPO required
A person or area responsible for data protection is required
Digital consent age
Children’s data processing tightly restricted
Extraterritorial reach
Limited — establishment-based

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
CO

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

No source recorded yet. This record cannot rise above Tier 3 until it has one — see depth tiers.

Never independently verified — seeded from the prototype.