Colombia updates Data Law with Bill 282
Bill 282 of 2026 expands Colombia’s data protection scope and adds stricter compliance, oversight, and cross-border transfer rules.
Bill 282 of 2026 in the Colombian House would partially amend Law 1581 of 2012 on personal data protection. It applies to processing by natural or legal persons, public or private, including activity outside Colombia when it affects people located in the country or their data. The proposal also tightens compliance duties, strengthens the SIC’s role, and adds more detail on international data transfers.
Bill 282 of 2026 in the Colombian House would partially amend Law 1581 of 2012 on personal data protection and set a broad scope for personal data processing. The proposal applies to natural or legal persons, public or private, and also reaches processing carried out outside Colombia when it affects people located in the country or their data.
What changes in the personal data regime?
The text adds new definitions and terminology changes that expand Colombia’s regulatory language. Among the concepts it introduces are biometric data, genetic data, profiling, accountability, data minimization, storage limitation, and explainability, in wording that brings the local framework closer to standards such as the European GDPR.
Gaceta 1217 of 2026 identifies the initiative as a reform to the personal data protection regime and notes that, because it is a statutory bill, it must follow the special procedure required for statutory laws in Colombia’s Congress. That parliamentary track matters because it changes the debate and the legislative route the bill must complete.
What new obligations does it impose?
The bill raises the compliance bar for controllers and processors by requiring documented technical and organizational measures, mandatory appointment of data protection officers, and notification of security incidents to both the authority and affected data subjects. In practice, that expands data compliance and risk management duties across both the public and private sectors.
It also introduces more detailed rules for international transfers of personal data. The framework relies on the principle that the destination country must provide an adequate level of protection, and it requires additional safeguards when data is transferred to jurisdictions without an adequate level, with exceptions allowed under specific conditions.
Which agencies are strengthened?
The bill consolidates the Superintendence of Industry and Commerce as Colombia’s National Data Protection Authority. It also creates a Delegate Prosecutor’s Office with specific data protection functions, broadening the institutional network for oversight, disciplinary enforcement, and interagency coordination.
That institutional redesign comes on top of the bill’s extraterritorial reach and its new rules for international transfers, two points that could directly affect Colombian companies working with foreign vendors or parent companies. The full text published in Gaceta 1217 of 2026 describes a more technically detailed reform than the current Law 1581.
Sources
- Bases de Datos Públicas en Colombia: Lo Que Sabe el Estadohunterx.com.co· HunterxUnverified URL
- Gaceta 1217 de 2026: Proyecto de Ley Estatutaria 282 de 2026 Cámara (Modificación parcial de la Ley 1581 de 2012 sobre protección de datos personales)avancejuridico.info· Avance Jurídico (repositorio de Gacetas del Congreso de Colombia)



