EnglishEspañol
Colombia flag

Colombia

Colombia Data Privacy Laws: Law 1581 and Habeas Data Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 15 primary sources cited on this page. How we verify our legal content

Colombia Data Privacy Laws: Law 1581 and Habeas Data Guide (2026)

Frequently Asked Questions

Does Colombia's data protection law apply to foreign companies?

Often, but the test is narrower than the GDPR's. Article 2 applies Law 1581 to processing carried out in Colombian territory, and to a controller or processor not established in Colombia only where Colombian law reaches it by virtue of international rules or treaties. A foreign company is usually caught because the processing itself happens in Colombia. The SIC applies that broadly: in the World Foundation appeal decided in June 2026 it held that Law 1581 covers anyone processing personal data in Colombia, even partially, and even without a branch or formal representation there. Simply offering goods or services into Colombia from abroad is not itself the statutory trigger. Reform bills that would have added a GDPR-style offering-and-monitoring test were archived in June 2026.

What is habeas data in Colombia?

Habeas data is a fundamental constitutional right established in Article 15 of Colombia's 1991 Political Constitution. It gives every person the right to know what personal information is held about them in public or private databases, to update that information, and to rectify inaccurate entries. Unlike in countries where data protection is purely a statutory right, Colombia's constitutional-level protection means individuals can enforce habeas data immediately by filing a tutela (constitutional writ) with any court, which must rule within 10 days.

What is the difference between Law 1581 and Law 1266 in Colombia?

Law 1581 of 2012 is the general personal data regime, but Article 2 excludes several kinds of database from it, and one of those exclusions is databases governed by Law 1266 of 2008. Credit bureau data therefore sits outside Law 1581 rather than alongside it. Law 1266 covers financial, credit, and commercial data used in credit reporting databases. It does not require prior consent for processing in most cases, and as amended by Law 2157 of 2021 it lets negative data remain for double the time of the default, capped at four years counted from the date the overdue instalments are paid or the obligation is extinguished, with an outer expiry eight years after the default began. Immediate erasure on payment was a transitional benefit whose window closed on October 29, 2022. Both laws are enforced by the SIC.

How much can the SIC fine a company for data protection violations in Colombia?

Under Law 1581, the SIC can impose fines of up to 2,000 times the monthly legal minimum wage in force when the sanction is imposed (SMMLV). Based on the 2026 SMMLV of COP 1,750,905, the maximum is about COP 3.5 billion, and Article 23 allows fines to be repeated for as long as the non-compliance continues. Beyond fines, Article 23 allows suspension of the processing activities for up to six months, temporary closure if the ordered correctives are not adopted within that period, and immediate and definitive closure where the operation involves sensitive data. Reform bills that would have raised the ceiling to 5% of annual operational revenues were archived in June 2026, so the 2,000 SMMLV cap is what applies today.

Can I transfer personal data from Colombia to the United States?

Yes. The United States is among the countries the SIC has recognized as providing adequate data protection, so personal data transfers from Colombia to US recipients are permitted without additional SIC authorization. The data controller must still comply with all other requirements of Law 1581, including valid consent for the underlying processing and contractual or operational assurances that the US-based recipient maintains appropriate security measures.

What are Colombia's model contractual clauses for cross-border transfers?

In December 2025, the SIC issued Circular Externa No. 003 of 2025 introducing voluntary model contractual clauses for international transfers and transmissions of personal data to countries not on the SIC's adequacy list. Use of the clauses is optional, but once adopted they become binding. The mechanism parallels the EU's standard contractual clauses and provides a more predictable compliance path than the Declaration of Conformity process, which requires case-by-case SIC review.

What happened with Worldcoin in Colombia?

On October 3, 2025, the SIC issued Resolution 78798 ordering the immediate and definitive shutdown of all data processing operations by World Foundation and Tools for Humanity (Worldcoin) in Colombia. The SIC found that the companies had collected iris images from thousands of people in Colombia through Orb devices, in exchange for money, without consent that was genuinely free and sufficiently informed: there was no Colombia-specific privacy addendum despite such addenda existing for other jurisdictions, and the companies failed to disclose the secure multi-party computation protocol used to fragment and store iris codes with third parties. World's own reported registration count for Colombia was close to two million users, but the SIC never adopted that figure. The SIC ordered deletion of all biometric data collected in Colombia. The companies appealed, and on June 18, 2026 the SIC confirmed the sanction in full through Resolution 45710, holding that encrypting and fragmenting an iris code after collection does not make it anonymous. No further administrative appeal is available.

What does Colombia's AI data protection circular require?

SIC Circular 002 of August 21, 2024 applies to all controllers, processors, and users that develop or deploy AI systems using personal data. It requires: (1) a privacy impact assessment before any AI-based data collection begins; (2) adherence to the principles of necessity, suitability, reasonableness, and proportionality; (3) secure processing environments compliant with existing law before collection starts; (4) implementation of differential privacy techniques where feasible; and (5) transparency with data subjects about AI use in processing decisions. Violation of the circular's instructions can constitute a breach of Law 1581.

What happened to Colombia's 2025 data protection reform bills?

They were archived without becoming law. Bills 214/2025C and 274/2025C were accumulated, with 274/2025C as the principal file, and approved in first debate in the House First Constitutional Commission on October 28, 2025. They never reached the Senate. The Cámara de Representantes bill record now shows the file as Archivado, archived under article 190 of Law 5 of 1992 when the 2025-2026 legislature ended on June 20, 2026 without the statutory law completing its four debates and Constitutional Court review. The rights they proposed, which included a right not to be subject to solely automated decisions, data portability, restriction of processing, and a right to object, are not part of Colombian law. A renewed reform would have to be filed again and start the process over.

Updates

Third-round correction: FAQ 9's answer now matches its reworded question about the archived 2025 reform bills.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Full refresh: added Constitutional Court jurisprudence section, reform bills 214/274 of 2025 and House Committee approval status, SIC Circular 001 of 2025 (fintech), expanded Worldcoin resolution details, expanded FAQ to 9 questions, added data-categories comparison table, updated meta and keywords.

Reviewed and approved by an editor

Initial publication. Covered Ley 1581/2012, Decreto 1377/2013, SIC authority, RNBD, cross-border transfers, breach notification, Circular 002/2024 AI guidelines, Worldcoin enforcement.

Sources and References

  1. Constitución Política de Colombia 1991 — Artículo 15 (Derecho a la intimidad y habeas data)(constituteproject.org)
  2. Función Pública — Ley 1581 de 2012 (Ley Estatutaria de Protección de Datos Personales)(funcionpublica.gov.co).gov
  3. Función Pública — Decreto 1377 de 2013 (reglamentario de la Ley 1581 de 2012; texto compilado en el Decreto Único 1074 de 2015, Libro 2, Parte 2, Título 2, Capítulo 25)(funcionpublica.gov.co).gov
  4. SIC — Deputy Superintendence for the Protection of Personal Data(sic.gov.co).gov
  5. SIC — Circular Externa No. 002 de 2024: Lineamientos sobre el Tratamiento de Datos Personales en Sistemas de Inteligencia Artificial(sedeelectronica.sic.gov.co).gov
  6. SIC — Circular Externa No. 001 de 2025: Lineamientos para el tratamiento de datos personales en el ecosistema Fintech(sedeelectronica.sic.gov.co).gov
  7. SIC — Sanciones Protección de Datos Personales 2024(sic.gov.co).gov
  8. SIC — ABC del Proyecto de Ley de Protección de Datos Personales en Colombia (documento de la etapa del proyecto; los Proyectos de Ley Estatutaria 214/2025C y 274/2025C fueron archivados en junio de 2026 y no son derecho vigente)(sedeelectronica.sic.gov.co).gov
  9. Baker McKenzie — Colombia: 2026 update on minimum wage and allowances(bakermckenzie.com)
  10. SIC — Reporte de Incidentes de Seguridad (canal para informar violaciones a los códigos de seguridad, arts. 17(n) y 18(k) de la Ley 1581 de 2012)(sic.gov.co).gov
  11. Holland and Knight — Data Protection in Colombia: Sanctions, NEW SIC Rules and the Impact of Artificial Intelligence (2025)(hklaw.com)
  12. Holland and Knight — Obligations of the National Registry of Personal Databases Before the SIC in Colombia for 2025(hklaw.com)
  13. IAPP — Colombia introduces new model contractual clauses (Circular Externa No. 003 of 2025)(iapp.org)
  14. Allende and Brea — New bills to amend Colombia data protection law introduced in Congress (Bills 214/2025 and 274/2025, filed August 2025; both were archived in June 2026 and never became law)(allende.com)
  15. DataGuidance — Colombia: House Committee approves combined bill to amend data protection law (first-debate stage, October 2025; the combined file was archived in June 2026)(dataguidance.com)
  16. Biometric Update — Colombia orders World shut-down, citing biometrics compliance failures (Resolution 78798, October 3, 2025)(biometricupdate.com)
  17. DLA Piper — Data Protection Laws of the World: Colombia(dlapiperdataprotection.com)
  18. Privacy International — State of Privacy Colombia(privacyinternational.org)
  19. Cámara de Representantes — Ficha del Proyecto de Ley Estatutaria 274/2025C (acumulado con el 214/2025C bajo el art. 151 de la Ley 5a de 1992): Estado "Archivado", observación "ARCHIVADO ARTICULO 190, LEY 5 DE 1992"(camara.gov.co).gov
  20. SIC — Circular Externa No. 002 del 15 de enero de 2026: tratamiento de datos personales con fines políticos y electorales (Diario Oficial No. 53.368 del 15 de enero de 2026)(sedeelectronica.sic.gov.co).gov
  21. SIC — Comunicado: la Resolución 45710 del 18 de junio de 2026 resolvió el recurso de apelación y confirmó la Resolución 78798 del 3 de octubre de 2025 (World Foundation y Tools for Humanity); contra esa decisión no procede recurso alguno(sedeelectronica.sic.gov.co).gov
  22. Ley 2157 de 2021 ("borrón y cuenta nueva") — modifica el artículo 13 de la Ley 1266 de 2008 sobre permanencia de la información negativa (Diario Oficial No. 51.842 del 29 de octubre de 2021)(jurinfo.jep.gov.co).gov
  23. SIC — Circular Externa No. 002 de 2018: modifica el numeral 3.2 del Capítulo Tercero del Título V de la Circular Única (lista de países con nivel adecuado de protección; incorpora a Australia)(normas.cra.gov.co).gov
  24. SIC — Preguntas frecuentes del RNBD: están obligadas a registrar las sociedades y entidades sin ánimo de lucro con activos totales superiores a 100.000 UVT y las personas jurídicas de naturaleza pública (Decreto 090 del 18 de enero de 2018)(sic.gov.co).gov
  25. DIAN — Resolución 000238 del 15 de diciembre de 2025: fija en $52.374 el valor de la UVT que rige durante 2026(normograma.dian.gov.co).gov
Share: