CiberLATAMbywhalemate

Colombia moves on data privacy law

Colombia's SIC says the bill modernizes Law 1581 of 2012 and expands coverage to Colombian and foreign firms handling data in Colombia.

Whalemate Labs · AI-assisted researchPublished:Updated 1 min read

Colombia's Superintendence of Industry and Commerce has released a guide to the Personal Data Protection Bill, which seeks to modernize Law 1581 of 2012 and update the country's data protection regime.

Colombia’s Superintendence of Industry and Commerce (SIC) has published the document "ABC of the Personal Data Protection Bill in Colombia," saying the proposal would modernize Law 1581 of 2012 and update the country’s personal data protection framework. According to the SIC, the bill would also extend its reach to Colombian and foreign companies that process personal data in Colombia.

Who would the bill apply to?

According to the SIC, the bill would apply to Colombian and foreign companies that process personal data in Colombia. That wording expands the scope of application beyond Law 1581 of 2012.

The document released by the agency adds to the legislative debate over personal data processing in the country and makes clear that the reform is not limited to local actors. It would also cover foreign companies that handle personal information within Colombian territory.

What official information did the SIC release?

The Superintendence of Industry and Commerce released the document "ABC of the Personal Data Protection Bill in Colombia." In that material, the agency says the initiative seeks to modernize Law 1581 of 2012 and update the personal data protection regime.

The official reference used by the SIC is Law 1581 of 2012, which would be updated if the presented bill moves forward. The superintendence did not provide a rollout schedule or an effective date in the material it shared.

What did the material not clarify?

Based on the verified facts available, the confirmed information is limited to two points: the SIC’s publication of the ABC and the intent to modernize the current legal framework. The material does not provide further details on specific articles, the legislative timeline, or any exact changes to obligations for data controllers and processors.

The superintendence did not provide a rollout schedule or an effective date in the material it shared.

Sources

View all