Law / Colombia

Colombia

14 of 16 named instruments researched to a stage, across four of the six areas of law we track: 14 in force. As of 19 September 2026.

When they take effect14 of 14 carry a date. Earlier is before 2014.
Before 2014: 9 instruments (9 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 1 instrument (1 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 3 instruments (3 in force) 2025: 0 instruments 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 9
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (159 words)

Colombia has no general artificial-intelligence statute in force. Documento CONPES 4144 de 2025, adopted 14 February 2025 by the Consejo Nacional de Politica Economica y Social, is a national AI policy document that sets strategic objectives and directs public entities to adopt ethical AI principles, but a CONPES document is an executive-branch policy directive rather than a law and creates no legal obligation on a private actor.

Proyecto de Ley 043 de 2025 Senado, 324 de 2025 Camara, a government-sponsored comprehensive AI regulation bill inspired by the European Union's AI Act, remains pending before Congress and has not been enacted.

The one enacted, AI-specific legal duty is a criminal aggravation: Ley 2502 de 2025 amended article 296 of the Codigo Penal so that when the personal-falsehood offense is committed by impersonating a person through an artificial-intelligence-generated deepfake, the fine is increased by up to one third; that amendment took effect one year after the law's 28 July 2025 sanction.

AI prohibited practices

Código Penal, Falsedad Personal, AI Deepfake Aggravation

Ley 599 de 2000, art. 296 (as amended by Ley 2502 de 2025)Ley 2502 de 2025, official text, Regimen Legal de Bogota D.C. (Secretaria Juridica Distrital)

In force 57 days, effective 28 July 2026. Binds public and private bodies.

What this law does

Article 296 of the Codigo Penal punishes with a fine whoever, to obtain a benefit for themselves or another or to cause harm, substitutes or impersonates a person or attributes to themselves a name, age, marital status, or capacity with legal effects, provided the conduct does not constitute another offense; the article carries no term of imprisonment.

Ley 2502 de 2025 added a second paragraph providing that when the personal falsehood is committed using artificial intelligence, the fine is increased by up to one third, and article 2 defines a deepfake as the creation, modification, or use of a false audiovisual record, including photographs, videos, images or sound recordings, made through artificial intelligence so that it appears to be a real person's authentic speech or conduct.

Article 6 of Ley 2502 de 2025 delayed this amendment's commencement to one year after the law's sanction and promulgation on 28 July 2025, so the deepfake aggravation itself entered into force on 28 July 2026, while the law's other provisions, including its definitions and its public-policy directives to the National Government, the Fiscalia and the Policia Nacional, took effect immediately on sanction.

What it requires

Privacy law9 instruments, 9 in force

Research summary (323 words)

Colombia's comprehensive personal data regime is Ley Estatutaria 1581 de 2012, grounded in the constitutional habeas data right and enforced by the Superintendencia de Industria y Comercio (SIC) through its Delegatura para la Proteccion de Datos Personales, requiring the data subject's prior, explicit and informed authorization before their personal data is collected or processed.

The law names biometric data, health data, sexual life, and political, religious, union and racial or ethnic information as sensitive categories subject to a general prohibition on processing, lifted only by explicit authorization or a narrow set of statutory exceptions, and gives a child's or adolescent's personal data the same default prohibition unless the data is of a public nature.

A data subject may consult, correct, update or delete their personal data and complain to the SIC once the controller's own procedure is exhausted, free of charge; a controller or processor must also tell the SIC when a security code violation puts that data at risk, though the law fixes no deadline for that notice and does not require telling the data subject directly.

Ley 1581 also prohibits transferring personal data to a country the SIC has not found to offer an adequate level of protection, subject to statutory exceptions including the data subject's express consent, and arms the SIC with fines of up to 2,000 monthly legal minimum wages, suspension, or closure for a violation, none of it criminal.

The SIC's Circular Externa No. 002 de 2024 extends this technology neutral regime to artificial intelligence systems: it requires a documented privacy impact assessment before a high risk AI system processes personal data, privacy by design measures such as differential privacy, auditable security measures, and states that personal data being accessible on the internet does not make it data of a public nature exempt from the authorization requirement, while requiring that a data subject be able to learn at any time how an AI system is processing their data.

Breach notification

Ley 1581 de 2012, Security Breach Notification to the Authority

Ley 1581 de 2012, arts. 17(n), 18(k) (Notificacion de Violaciones de Seguridad)Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica

In force since 17 October 2012. Binds public and private bodies.

What this law does

Article 17(n) requires a data controller to inform the data protection authority when a violation of the security codes occurs and there is a risk in the administration of a data subject's information. Article 18(k) imposes the identical duty on a data processor, requiring it to inform the Superintendencia de Industria y Comercio under the same terms.

Neither literal fixes a deadline for the notice or requires telling the affected data subject directly, so the clock this law states runs only to the Superintendencia, triggered by a security code violation that creates that risk.

What it requires

Comprehensive regime

Ley 1581 de 2012, General Personal Data Protection

Ley Estatutaria 1581 de 2012, arts. 1-4, 9-11, 13, 17-18, 25, 28-30 (Objeto, Principios, Autorizacion y Deberes Generales)Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica

In force since 17 October 2012. Binds public and private bodies.

What this law does

Article 1 develops the constitutional right, under article 15 of the 1991 Constitution, of every person to know, update and rectify information collected about them in a database, and article 2 applies the law to personal data registered in any database made susceptible to processing by a public or private entity, exempting only purely personal or household databases, national security and anti money laundering databases, intelligence databases, journalistic databases, and databases the credit reporting law (Ley 1266 de 2008) or the cooperative law (Ley 79 de 1993) already regulates.

Article 4 sets the governing principles, including legality, purpose limitation, freedom of processing tied to the data subject's consent, accuracy, transparency, restricted access and circulation, security and confidentiality.

Article 9 requires the data controller to obtain the data subject's prior and informed authorization before processing their data, and article 10 lists the narrow cases where that authorization is not required, including data a public authority requests in exercise of its legal functions and data of a public nature.

Articles 11 and 13 require any information owed to the data subject to be supplied in an easily readable form matching what is on file, and limit disclosure of personal data to the data subject and their representatives, a public authority acting within its legal functions or under court order, and third parties the data subject or the law has authorized.

Articles 17 and 18 set the controller's and the processor's general duties, including keeping proof of the authorization obtained, telling the data subject the purpose of the processing, keeping the data secure, accurate and updated, correcting it once shown wrong, and adopting an internal manual of policies and procedures for consultations and claims.

Article 25 makes the National Registry of Databases, administered by the Superintendencia de Industria y Comercio, the precondition for registering a database, requiring the interested party to submit data treatment policies that may never fall below this law's own duties. Articles 28 through 30 give a six month transition period, preserve the exceptions of article 2 from the general repeal, and set the law in force from its promulgation on 17 October 2012.

What it requires

Superintendencia Circular on AI and Personal Data

SIC Circular Externa 002 de 2024 instrucciones I, II, VIII-IX (Lineamientos sobre Tratamiento de Datos en Sistemas de IA), 21 de agosto de 2024Official Circular Externa text, Superintendencia de Industria y Comercio

In force since 21 August 2024. Binds public and private bodies.

What this law does

The SIC's Circular Externa No. 002 de 2024 instructs every data controller and processor subject to Ley 1581 de 2012 and Ley 1266 de 2008 on how those technology neutral statutes apply to developing, deploying, or using an artificial intelligence system that processes personal data.

Instruction I requires that processing to satisfy a four factor weighing test: the processing must be suited to achieve its stated goal, no less intrusive measure must achieve that goal as effectively, the goal itself must be a constitutional one, and the benefit to that goal must not be outweighed by the harm the processing does to the right to data protection.

Instruction II requires an administrator of personal data to refrain from processing, or to adopt precautionary measures, wherever it cannot be certain that processing will not cause serious and irreversible harm, and to adapt its risk management systems to identify, measure, control and monitor the situations that could affect its compliance with personal data protection rules.

The circular next requires a documented privacy impact assessment, covering the processing operations, a specific evaluation of the risks to data subjects' rights and freedoms, and the measures planned to prevent those risks, before an artificial intelligence system likely to pose a high risk to data subjects processes their personal data, requires that data used in an artificial intelligence system be truthful, complete, exact, updated, verifiable and understandable, and requires privacy by design and by default through mathematical techniques such as differential privacy, so that training data cannot identify the person who provided it.

Instruction VIII requires technological, human, administrative, physical and contractual measures against unauthorized access to personal data, its manipulation or destruction, its misuse, and its unauthorized circulation, and requires those security measures to stay auditable by the authorities.

Instruction IX states that personal data being accessible on the internet does not make it data of a public nature, so a controller that collects personal, semiprivate, or sensitive data online is not thereby entitled to treat it for an artificial intelligence system's purposes without the data subject's prior, express and informed authorization.

What it requires

Cross border transfer

Ley 1581 de 2012, Cross Border Data Transfer

Ley 1581 de 2012, arts. 26-27 (Transferencia a Terceros Paises)Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica

In force since 17 October 2012. Binds public and private bodies.

What this law does

Article 26 prohibits transferring personal data of any kind to a country that does not provide an adequate level of data protection, measured by standards the Superintendencia de Industria y Comercio sets and that may never fall below this law's own requirements, unless the data subject has given express and unequivocal authorization for the transfer, the transfer is a medical data exchange required for the data subject's health treatment or public hygiene, the transfer is a banking or securities transfer under its own applicable law, the transfer is agreed under an international treaty Colombia has joined on a reciprocity basis, the transfer is necessary to perform a contract with the data subject or precontractual measures the data subject has authorized, or the transfer is legally required to safeguard the public interest or to establish, exercise or defend a right in a judicial proceeding, and requires the Superintendencia's declaration of conformity before any transfer outside those exceptions.

Article 27 requires the National Government to regulate Binding Corporate Rules certifying good personal data protection practices for a transfer to a third country.

What it requires

Data subject rights

Ley 1581 de 2012, Data Subject Rights and Procedures

Ley 1581 de 2012, arts. 8, 12, 14-16 (Derechos de los Titulares)Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica

In force since 17 October 2012. Binds public and private bodies.

What this law does

Article 8 gives every data subject the right to know, update and rectify their personal data before the controller or processor, request proof of the authorization given, be told on request how their data has been used, file a complaint with the Superintendencia de Industria y Comercio, revoke the authorization or seek deletion of the data where the processing does not respect their constitutional or statutory rights, and access their personal data free of charge.

Article 12 requires the controller, at the moment of requesting authorization, to tell the data subject clearly and expressly the purpose of the processing, that answering a question about sensitive data or a minor's data is optional, the rights the data subject holds, and the controller's identification and contact details, and to keep proof that this notice was given.

Article 14 gives the data subject or their successors the right to consult their personal data held in any public or private database, to be answered within ten business days, extendable by five more business days with notice of the delay and a new date.

Article 15 gives the right to lodge a claim for correction, updating or deletion, or over a suspected breach of any duty this law imposes, requires a pending claim legend to be added to the record within two business days of a complete claim, and sets fifteen business days to resolve it, extendable by eight more with notice of the delay and a new date.

Article 16 conditions a complaint to the Superintendencia de Industria y Comercio on having first exhausted the consultation or claim procedure before the controller or processor.

What it requires

SIC Circular on AI, Data Subject Rights

SIC Circular Externa 002 de 2024, instrucciones VII, X (Derechos de los Titulares en Sistemas de IA)Official Circular Externa text, Superintendencia de Industria y Comercio

In force since 21 August 2024. Binds public and private bodies.

What this law does

Instruction VII requires an administrator of personal data to guarantee a data subject's right to obtain information about how an artificial intelligence system is processing their personal data, at any time and without restriction.

Instruction X requires the treatment of personal data in an artificial intelligence system to provide pertinent, efficient and demonstrable strategies to guarantee the data subject rights that Ley 1266 de 2008, Ley 1581 de 2012, and their implementing decrees establish.

What it requires

Enforcement supervision

Ley 1581 de 2012, Supervisory Authority and Sanctions

Ley 1581 de 2012, arts. 19-24 (Autoridad y Sanciones)Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica

In force since 17 October 2012. Binds public and private bodies.

What this law does

Article 19 designates the Superintendencia de Industria y Comercio, acting through its Delegatura para la Proteccion de Datos Personales, as the authority that oversees compliance with this law's principles, rights, guarantees and procedures.

Article 21 empowers the Superintendencia to investigate a violation on its own initiative or on complaint and order the measures needed to make the habeas data right effective, temporarily block a controller's processing where the evidence shows a real risk to a data subject's fundamental rights, promote and publicize data subjects' rights, instruct controllers and processors on adapting their operations to this law, issue the declaration of conformity for an international transfer, and administer the National Public Registry of Databases.

Article 22 requires the Superintendencia, once it establishes a violation, to apply the Codigo Contencioso Administrativo for anything this law does not itself regulate, and the sanctions this law provides are purely administrative, since it creates no criminal offense.

Article 23 lets the Superintendencia impose a fine of up to 2,000 current monthly legal minimum wages, suspend the processing activity for up to six months, or order the immediate and permanent closure of an operation that involves sensitive data, reserving these sanctions for private parties and referring a public authority's violation to the Procuraduria General de la Nacion instead.

Article 24 grades a sanction by the extent of the harm or danger, the economic benefit the infringer or a third party obtained, repeat infringement, resistance or obstruction of the investigation, defiance of the Superintendencia's orders, and the infringer's own acknowledgment of the violation before the sanction is imposed.

What it requires

SIC Circular on AI, Demonstrated Accountability

SIC Circular Externa 002 de 2024, Decreto 1074 de 2015 art. 2.2.2.25.6.1 (Responsabilidad Demostrada)Official Circular Externa text, Superintendencia de Industria y Comercio

In force since 21 August 2024. Binds public and private bodies.

What this law does

The circular grounds its artificial intelligence specific duties in the demonstrated accountability rule the Superintendencia de Industria y Comercio already enforces under Decreto 1074 de 2015.

A data controller must be able to show, when the Superintendencia asks, that it has implemented measures that are appropriate and effective to comply with Ley 1581 de 2012 and that decree, and the circular treats the privacy impact assessment and privacy by design duties it imposes as how a controller meets that duty for an artificial intelligence system.

What it requires

Sensitive categories

Ley 1581 de 2012, Sensitive Categories and Children's Data

Ley 1581 de 2012, arts. 5-7 (Datos Sensibles y Menores)Official consolidated text, Gestor Normativo, Departamento Administrativo de la Funcion Publica

In force since 17 October 2012. Binds public and private bodies.

What this law does

Article 5 defines sensitive data as data that affects a person's privacy or whose misuse can generate discrimination, expressly naming racial or ethnic origin, political opinion, religious or philosophical belief, union or human rights organization membership, health, sexual life, and biometric data.

Article 6 prohibits processing sensitive data unless the data subject gives explicit authorization, the processing protects the data subject's vital interest and they cannot consent, a not for profit political, philosophical, religious or union body processes it about its own members without disclosing it to third parties, the processing establishes, exercises or defends a right in a judicial proceeding, or the processing serves a historical, statistical or scientific purpose and suppresses the data subject's identity.

Article 7 bars processing a child's or adolescent's personal data unless the data is of a public nature, and assigns the State and educational entities the task of informing and training legal representatives, guardians, children and adolescents about the risks of improper processing and the safe, responsible use of their personal data.

What it requires

Scraping law3 instruments, 3 in force

Research summary (275 words)

Colombia has no scraping-specific statute, so general law governs each dimension separately.

Article 269A of the Codigo Penal, inserted by Ley 1273 de 2009, criminalizes accessing a computer system without authorization or beyond what was agreed, whether or not the system is protected by a security measure, so a plain reading reaches unauthorized access to an unprotected, public page and does not require defeating a technical control; no reported Colombian case confirms or narrows that reading for a scraper reading a public unauthenticated page.

Article 269F separately criminalizes obtaining, compiling, or extracting personal data from a file, database, or similar medium without authorization and for one's own or a third party's benefit, so scraping personal data without authorization exposes the scraper to that offense independently of Ley 1581 de 2012's administrative regime, which applies to scraped personal data without a general public-accessibility carve-out.

Ley 23 de 1982, as amended by Ley 1915 de 2018, gives the author the exclusive right to authorize or prohibit reproduction of a work by any means, including temporary electronic storage, and creates no text-and-data-mining exception and no opt-out mechanism, so training a model on scraped copyrighted text rests only on the narrow enumerated exceptions (quotation, teaching illustration, private and non-commercial single-copy reproduction) rather than a general research or text and data mining (TDM) ground; Colombian copyright law confers no sui generis database right, protecting a compilation only as a collective work.

No Colombian statute or reported case establishes a scraping-specific unfair-competition or misappropriation doctrine, assigns legal weight to a robots.txt directive, or imposes an AI-training-specific rule, and no Colombian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

Computer misuse

Código Penal, Acceso Abusivo a un Sistema Informático

Ley 599 de 2000, art. 269A (added by Ley 1273 de 2009)Ley 1273 de 2009

In force since 5 January 2009. Binds public and private bodies.

What this law does

Article 269A punishes whoever, without authorization or beyond what was agreed, accesses in whole or part a computer system protected or not by a security measure, or remains within it against the will of the person entitled to exclude them, with imprisonment of 48 to 96 months and a fine of 100 to 1,000 monthly legal minimum wages.

Because the article expressly covers a system whether or not it is protected by a security measure, its authorization test does not, on its plain text, require defeating a technical access control the way jurisdictions that condition the offense on infringing a security measure do.

What it requires

Copyright and text and data mining (TDM)

Copyright Act, Exclusive Reproduction Right, No Text and Data Mining Exception

Ley 23 de 1982, art. 12 (as amended by Ley 1915 de 2018)Ley 23 de 1982 sobre Derechos de Autor, as amended by Ley 1915 de 2018, official text, WIPO Lex

In force since 12 July 2018. Binds public and private bodies.

What this law does

Article 12, as rewritten by article 3 of Ley 1915 de 2018, gives the author the exclusive right to authorize or prohibit reproduction of the work by any means or form, permanent or temporary, including temporary electronic storage, as well as communication to the public, distribution, importation, commercial rental, and transformation.

Ley 23 de 1982 creates no text-and-data-mining exception and no machine-readable opt-out mechanism; its narrow enumerated exceptions (quotation with attribution, illustration for non-commercial teaching, single-copy reproduction for private non-commercial use) do not create a general ground for reproducing copyrighted text to train a model.

Colombian copyright law confers no sui generis database right; a compilation is protected only as a collective work for eighty years from publication in favor of its director, under article 24.

What it requires

Personal data

Código Penal, Violación de Datos Personales

Ley 599 de 2000, art. 269F (added by Ley 1273 de 2009)Ley 1273 de 2009

In force since 5 January 2009. Binds public and private bodies.

What this law does

Article 269F punishes whoever, without authorization and for their own or a third party's benefit, obtains, compiles, extracts, offers, sells, exchanges, sends, buys, intercepts, discloses, modifies, or uses personal codes or personal data contained in files, archives, databases, or similar media, with imprisonment of 48 to 96 months and a fine of 100 to 1,000 monthly legal minimum wages.

Scraping personal data without the controller's authorization can independently expose the scraper to this criminal offense, on top of the administrative duties Ley 1581 de 2012 imposes on the processing itself; the Superintendencia de Industria y Comercio's Circular Externa 002 de 2024 states that personal data being accessible on the internet does not make it data of a public nature, so Colombia's personal-data regime does not carve out publicly accessible personal data from its own reach.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (204 words)

Colombia has no press-publisher neighbouring right of the kind the European Union's Digital Single Market Directive article 15 creates, and no mandatory platform-to-publisher bargaining code; the general copyright framework of Ley 23 de 1982, as amended by Ley 1915 de 2018, is the only law reaching an aggregator's reproduction of news content.

Article 31 permits quoting an author by transcribing necessary passages, provided they are not so extensive as to amount to a simulated and substantial reproduction, with the source author and title named in each citation.

Articles 33 to 35 separately permit reproducing titles, photographs, illustrations and commentary about current events published by the press or broadcast, unless expressly prohibited, and permit the lawful reproduction, distribution and communication to the public of news or other information about facts that have already been publicly disseminated by the press or broadcasting, without requiring authorization; no reported Colombian decision applies these articles to a systematic news aggregator as opposed to an individual republication.

No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer. The statute predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

Snippet reproduction

Copyright Act, News Reporting and Press Reproduction Exception

Ley 23 de 1982, arts. 33-35 (Noticias de Actualidad)Ley 23 de 1982 sobre Derechos de Autor, official text, WIPO Lex

In force since 28 January 1982. Binds public and private bodies.

What this law does

Article 33 permits reproducing any title, photograph, illustration or commentary about a current event that has been published by the press or broadcast by radio or television, unless this has been expressly prohibited. Article 34 makes it lawful to reproduce, distribute, and communicate to the public news or other information about facts or events that have already been publicly disseminated by the press or broadcasting, with no authorization required.

Article 35 lets speeches, addresses, sermons and similar works delivered in public be published as current-events news in the press, by radio or by television without authorization, unless the author has expressly reserved ownership, though such works may not be published in a separate collection without the author's permission. None of the three articles caps a headline's or extract's length beyond the express-prohibition and non-collection conditions they each state.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.