{
  "node_id": "co-slhc-2012",
  "title": "Colombia Statutory Law 1581 of 2012 - Ley de Habeas Data and SIC Enforcement",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "Colombia's Ley Estatutaria de Protección de Datos Personales (Statutory Law on the Protection of Personal Data) - Ley Estatutaria 1581 of 2012, passed by the Colombian Congress and signed into law on 17 October 2012, published in the Diario Oficial No. 48.587 - is Colombia's primary comprehensive personal data protection legislation, establishing the legal framework for the collection, storage, use, circulation, and deletion of personal data. Ley 1581 of 2012 is constitutionally grounded in Colombia's habeas data right, recognised in Art. 15 of the 1991 Constitution of Colombia, which grants every person the right to know, update, and rectify information collected about them in databases and archives. Ley 1581 of 2012 was preceded by Law 1266 of 2008, which regulated financial, credit, commercial, and other data (commonly known as the 'Habeas Data Law for financial data'). Ley 1581 of 2012 operates alongside Law 1266/2008 - financial credit data is primarily governed by Law 1266/2008 while general personal data falls under Ley 1581/2012. The enforcement authority is the Superintendencia de Industria y Comercio (SIC - Superintendency of Industry and Commerce), which has a dedicated Personal Data Protection Division (Delegatura para la Protección de Datos Personales). Key features of Ley 1581/2012: (1) Responsible and Encargado - 'Responsible' (Responsable del Tratamiento - the data controller equivalent) and 'Encargado' (Encargado del Tratamiento - the data processor equivalent) terminology; (2) Eight principles: lawfulness, purpose, freedom, truthfulness/quality, transparency, restricted access and circulation, security, and accountability (Confidencialidad); (3) Sensitive data - race or ethnicity; political orientation; religious or philosophical convictions; trade union membership; social organisations membership; human rights organisations membership; data relating to health; sexual life; biometric data; (4) Consent - freely given, prior, and express consent is required for processing personal data; (5) Habeas data rights - individuals have the right to know, update, rectify, and suppress their personal data; (6) Registration - all databases containing personal data must be registered with the National Registry of Databases (Registro Nacional de Bases de Datos - RNBD) maintained by the SIC; (7) Privacy notice (Aviso de Privacidad) - mandatory before processing; (8) Data Processor Agreement - agreements between Responsible (controller) and Encargado (processor) are mandatory; (9) International data transfers - transfers to countries without adequate protection require prior SIC authorisation or data transfer agreements; (10) Administrative sanctions: up to COP 2,000 daily minimum wages (approximately COP 2.5 billion or USD 600,000 as of 2026) for violations; Colombia does not have EU GDPR adequacy recognition. Colombia is South America's third-largest economy and a major technology hub, particularly in fintech and digital commerce.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-27001-2022",
    "iso-27701-privacy-information-management"
  ],
  "primary_citations_count": 6
}