Colombia's 2026C Bill 282 Adds Duties
Colombia’s Bill 282 of 2026C would add data breach reporting within 72 hours, new obligations and extraterritorial reach.
Colombia’s Statutory Bill 282 of 2026C, under review by the First Committee, would partially reform the country’s data protection regime with extraterritorial reach, 72-hour security incident reporting, data protection officers, impact assessments and new penalties.
Colombia’s Statutory Bill 282 of 2026C is moving through the First Committee with a proposal to partially reform the country’s data protection regime. According to the regulatory analysis material available, the text adds extraterritorial reach, 72-hour security incident reporting, data protection officers, impact assessments and new penalties.
What new obligations does the bill propose?
The regulatory analysis from the Regulatory Studies Center indicates that the bill adds further duties for anyone processing personal data. Those include having a legal basis for processing, formally contracting processors, applying privacy by design and by default, and reviewing systems every two years.
What deadlines does it set for implementation?
The bill sets a six-month deadline to regulate the figure of the representative or branch office and to put a Delegate Prosecutor’s Office into operation, along with a 72-hour deadline to report security incidents, according to the Regulatory Studies Center’s analysis.
How does it differ from the current rules?
The proposal does not replace the current regime on its own, but seeks to partially reform it, according to the material reviewed. The available reference on the current framework is Siberson’s data sheet on Colombia Data Security and Law 1581, together with the mention of cybersecurity from the Financial Superintendence, although the specific details of those rules are not developed in the facts provided.
Because it is still at the initial stage before the First Committee, the initiative remains a bill in process, not an approved law. Its extraterritorial reach and the additional obligations it proposes remain conditional on the bill’s legislative path.
Sources
- Congreso de la República, Proyecto de Ley Estatutariacerlatam.com· Centro de Estudios Regulatorios
- Colombia Data Security, Law 1581 & SFC Cybersecuritysiberson.com· Siberson



