Bidda Sovereign Intelligence · 10,090 Verified Nodes · 39 Sovereign Pillars

Colombia Statutory Law 1581 of 2012 - Ley de Habeas Data and SIC Enforcement

Colombia's Ley Estatutaria de Protección de Datos Personales (Statutory Law on the Protection of Personal Data) - Ley Estatutaria 1581 of 2012, passed by…

What Colombia Statutory Law 1581 of 2012 - Ley de Habeas Data and SIC Enforcement requires

Colombia's Ley Estatutaria de Protección de Datos Personales (Statutory Law on the Protection of Personal Data) - Ley Estatutaria 1581 of 2012, passed by the Colombian Congress and signed into law on 17 October 2012, published in the Diario Oficial No. 48.587 - is Colombia's primary comprehensive personal data protection legislation, establishing the legal framework for the collection, storage, use, circulation, and deletion of personal data. Ley 1581 of 2012 is constitutionally grounded in Colombia's habeas data right, recognised in Art. 15 of the 1991 Constitution of Colombia, which grants every person the right to know, update, and rectify information collected about them in databases and archives. Ley 1581 of 2012 was preceded by Law 1266 of 2008, which regulated financial, credit, commercial, and other data (commonly known as the 'Habeas Data Law for financial data'). Ley 1581 of 2012 operates alongside Law 1266/2008 - financial credit data is primarily governed by Law 1266/2008 while general personal data falls under Ley 1581/2012. The enforcement authority is the Superintendencia de Industria y Comercio (SIC - Superintendency of Industry and Commerce), which has a dedicated Personal Data Protection Division (Delegatura para la Protección de Datos Personales). Key features of Ley 1581/2012: (1) Responsible and Encargado - 'Responsible' (Responsable del Tratamiento - the data controller equivalent) and 'Encargado' (Encargado del Tratamiento - the data processor equivalent) terminology; (2) Eight principles: lawfulness, purpose, freedom, truthfulness/quality, transparency, restricted access and circulation, security, and accountability (Confidencialidad); (3) Sensitive data - race or ethnicity; political orientation; religious or philosophical convictions; trade union membership; social organisations membership; human rights organisations membership; data relating to health; sexual life; biometric data; (4) Consent - freely given, prior, and express consent is required for processing personal data; (5) Habeas data rights - individuals have the right to know, update, rectify, and suppress their personal data; (6) Registration - all databases containing personal data must be registered with the National Registry of Databases (Registro Nacional de Bases de Datos - RNBD) maintained by the SIC; (7) Privacy notice (Aviso de Privacidad) - mandatory before processing; (8) Data Processor Agreement - agreements between Responsible (controller) and Encargado (processor) are mandatory; (9) International data transfers - transfers to countries without adequate protection require prior SIC authorisation or data transfer agreements; (10) Administrative sanctions: up to COP 2,000 daily minimum wages (approximately COP 2.5 billion or USD 600,000 as of 2026) for violations; Colombia does not have EU GDPR adequacy recognition. Colombia is South America's third-largest economy and a major technology hub, particularly in fintech and digital commerce.

Pillar: Cybersecurity · Authority: Superintendencia de Industria y Comercio (SIC - Superintendency of Industry and Commerce, Colombia) · Version: 1.0.0 · Last updated:

Primary source: https://www.sic.gov.co/

SHA-256 integrity: 5a151b9823f9779a2714dda86d92c5ba90c7fe0c81d535c6be2c873712e74b07

Primary Citations — 6 traced to source

  • Ley Estatutaria 1581 of 2012 (Colombia) - published Diario Oficial No. 48.587, 17 October 2012; primary personal data protection legislation; eight principles: lawfulness, purpose, freedom, truthfulness/quality, transparency, restricted access and circulation, security, accountability; sensitive data: racial/ethnic origin, political orientation, religious/philosophical convictions, trade union membership, social/human rights organisations, health, sexual life, biometric data; prior, express consent for sensitive data; RNBD mandatory database registration; Aviso de Privacidad before collection; habeas data rights: access (10 business days), update/rectification/deletion (15 business days); fines up to COP 2,000 daily minimum wages (approximately COP 2.5 billion)
  • Superintendencia de Industria y Comercio (SIC, Colombia) - enforcement authority; Delegatura para la Protección de Datos Personales; maintains National Registry of Databases (RNBD); investigates complaints; conducts inspections; imposes administrative sanctions; authorises international data transfers; publishes guidance and model contracts at sic.gov.co; active enforcement including RNBD registration violations and sensitive data consent breaches

+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.