Law / Colombia

Ley 1581 de 2012, General Personal Data Protection

Ley Estatutaria 1581 de 2012, arts. 1-4, 9-11, 13, 17-18, 25, 28-30 (Objeto, Principios, Autorizacion y Deberes Generales)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 17 October 2012.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Obtain the data subject's prior, explicit and informed authorization before collecting or processing their personal data, unless a statutory exception applies.
  • Apply the legality, purpose limitation, freedom, accuracy, transparency, restricted access and confidentiality principles to every processing operation, and do not process partial, incomplete, fragmented or misleading personal data.
  • Keep proof of the data subject's authorization, tell them at authorization the purpose of the processing, keep their personal data updated and accurate, secure it against unauthorized alteration, loss, consultation, use or access, and correct it once it is shown to be incorrect.
  • As a data processor, keep personal data secure in the same way, update or correct it as the controller instructs within five business days, and adopt an internal manual of policies and procedures for handling consultations and claims.
  • Share personal data only with the data subject or their representatives, a public authority acting within its legal functions or under court order, or a third party the data subject or the law has authorized, and supply any information you owe them in an easily readable format matching what is on file.
  • Register your databases with the Superintendencia de Industria y Comercio's National Registry of Databases and submit data treatment policies that never fall below this law's duties.

What it reaches

Obligation class

Consent, Governance, Security, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 1 develops the constitutional right, under article 15 of the 1991 Constitution, of every person to know, update and rectify information collected about them in a database, and article 2 applies the law to personal data registered in any database made susceptible to processing by a public or private entity, exempting only purely personal or household databases, national security and anti money laundering databases, intelligence databases, journalistic databases, and databases the credit reporting law (Ley 1266 de 2008) or the cooperative law (Ley 79 de 1993) already regulates.

Article 4 sets the governing principles, including legality, purpose limitation, freedom of processing tied to the data subject's consent, accuracy, transparency, restricted access and circulation, security and confidentiality.

Article 9 requires the data controller to obtain the data subject's prior and informed authorization before processing their data, and article 10 lists the narrow cases where that authorization is not required, including data a public authority requests in exercise of its legal functions and data of a public nature.

Articles 11 and 13 require any information owed to the data subject to be supplied in an easily readable form matching what is on file, and limit disclosure of personal data to the data subject and their representatives, a public authority acting within its legal functions or under court order, and third parties the data subject or the law has authorized.

Articles 17 and 18 set the controller's and the processor's general duties, including keeping proof of the authorization obtained, telling the data subject the purpose of the processing, keeping the data secure, accurate and updated, correcting it once shown wrong, and adopting an internal manual of policies and procedures for consultations and claims.

Article 25 makes the National Registry of Databases, administered by the Superintendencia de Industria y Comercio, the precondition for registering a database, requiring the interested party to submit data treatment policies that may never fall below this law's own duties. Articles 28 through 30 give a six month transition period, preserve the exceptions of article 2 from the general repeal, and set the law in force from its promulgation on 17 October 2012.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app