Colombia's Congress has a third attempt in front of it to rewrite the country's 2012 data protection statute, and this version reaches advertising technology companies that have never opened a Bogotá office. Statutory Bill No. 282 of 2026 appeared in the Congressional Gazette on Tuesday, September 8, 2026, carrying fines of up to 5% of annual operating revenue and a scope clause modelled on European territorial reach.
In Short
Colombia's Congress is looking at a bill that would rewrite the country's 2012 privacy law and pull it much closer to European rules. It would cover any company anywhere that sells to people in Colombia or tracks what they do there, so a demand-side platform or measurement vendor with no Colombian entity could still be caught. If the bill passes, location data becomes sensitive, people get an explicit right to refuse advertising profiling, and penalties can reach 5% of a company's revenue.
A third filing, and the paperwork behind it
The text runs across the 33-page edition of the Congressional Gazette, Year XXXV, No. 1217, published in Bogotá on September 8, 2026, under the imprint of the National Printing Office of Colombia. According to the covering letter reproduced in the Gazette, the bill was submitted to the General Secretariat of the House of Representatives in August 2026, invoking Article 154 of the Constitution and Articles 139, 140 and 149 of Law No. 5 of 1992. Two signatures close the text: María Fernanda Carrascal Rojas, Representative to the Chamber for Bogotá, and Duvalier Sánchez Arango, Senator of the Republic.
None of this is a first pass. The explanatory memorandum states that the same initiative was filed during the 2025-2026 legislative session as PLE 274 of 2025 and during the 2024-2025 session as PLE 152 of 2024, and that the legislative process was not completed on either occasion.
The filing surfaced publicly through a LinkedIn post by Luis Alberto Montezuma, a data and privacy policy commentator whose document-sharing has become a regular early signal for legislative texts outside Europe. According to Montezuma, Carrascal has brought the amendment forward for the third time, and Colombia's Law 1581 of 2012 is itself built on Directive EU 95/46, the 1995 European instrument that the General Data Protection Regulation replaced. His assessment of the regional picture was blunt: the current political climate, he wrote, "is not conducive to passing data protection reforms," grouping Colombia with Argentina and Costa Rica, and noting separately that Chile's government has moved to delay its own law's entry into force.
A source discrepancy sits inside the memorandum itself and is worth flagging rather than smoothing over. The background section names PLE 274 of 2025 and PLE 152 of 2024 as the two prior filings, while the account of the September 2025 hearing refers to Carrascal as author of "House Bill No. 214 of 2025" and an intervention by the Ombudsman's Office cites "Bill 247/2025 C". The numbering is inconsistent across the document, and the Gazette offers no reconciliation.
The scope clause that reaches outside Colombia
Article 2 of the bill rewrites the territorial reach of Law 1581. According to the text, the law would apply to processing by any natural or legal person, public or private, regardless of the means used, the country of residence or domicile of the obligated party, or the location of the data, where any of three circumstances apply: the processing takes place inside Colombian territory; the processing relates to the provision of goods or services, whether paid or free, to data subjects located in Colombia; or the processing relates to the monitoring or tracking of the behaviour of data subjects located in Colombia.
That third limb is the one that matters for programmatic supply chains. A bidder building segments from Colombian browsing behaviour, a measurement vendor running cross-site attribution on Colombian traffic, or an identity graph resolving Colombian mobile identifiers would all sit inside the scope clause without owning a single asset in the country.
An obligation follows from it. Paragraph 2 of the same article requires controllers and processors not domiciled in Colombia to establish a contact channel and to designate in writing a representative with full powers before the National Authority for the Protection of Personal Data, or to open a branch office, or both. The national government would have six months from enactment to issue regulations setting the conditions and the date from which that obligation becomes enforceable. The pattern matches what Indonesian regulators built into Government Regulation No. 33 of 2026, which set 72-hour response deadlines and mandated impact assessments for large-scale profiling.
Carve-outs narrow the reach in places. The law would not apply to processing in a purely personal or domestic context, to journalistic activities and other editorial content, to national security and defence processing, to anti-money-laundering and counter-terrorism-financing work by competent authorities, to intelligence and counterintelligence held by authorities with jurisdiction, or to processing governed by Law 1266 of 2008, except as regards international transfers.
Consent stops being the only pillar
The most consequential architectural change is the addition of legal bases beyond consent. Article 9 as amended lists six grounds on which processing becomes lawful: prior consent for one or more specific purposes, compliance with a legal obligation, performance of a contract or precontractual measures, protection of life or health, exercise of public functions, and the legitimate interests of the controller or a third party.
Two constraints attach to that last ground. Public entities exercising their functions cannot rely on it. And establishing it requires a prior, detailed and documented assessment weighing lawfulness, necessity and balance against the data subject's fundamental rights, with the principles of fairness, data minimisation and proportionality reinforced. Ecuador's data protection superintendent set out an almost identical documentation regime in Resolution No. SPDP-SPD-2025-0041-R of November 7, 2025, requiring written justification and a five-part balancing test before any private-sector controller can rely on the basis.
The European experience with that basis is not encouraging for anyone treating it as a shortcut. A case digest analysing 62 one-stop-shop decisions found controllers systematically underestimating what the balancing test demands, with commercial interests accepted in principle but repeatedly failing at the necessity and balancing stages.
Where consent is used, Article 10 tightens it considerably. The controller must demonstrate that consent was given in advance, expressly, freely, specifically, with full knowledge and unequivocally, through a statement or clear affirmative action. Multiple purposes require separate consent for each. And the bill states plainly that "Silence, pre-checked boxes, or inaction shall not constitute valid expressions of consent." Where consent is bundled into a written statement covering other matters, the request must be clearly distinguishable from the surrounding content.
An objection right written for advertising
Article 8 rebuilds the catalogue of data subject rights, and one subparagraph is drafted directly at the advertising industry. According to the bill, data subjects may object to processing including, but not limited to, cases where it lacks a legitimate basis, affects fundamental rights, or is carried out for advertising or direct marketing purposes, including profiling to the extent it relates to such activity.
Subparagraph (g) addresses automated processing. A data subject would not be subject to decisions that restrict fundamental rights, have discriminatory effects, or significantly affect them based solely on automated processing or profiling. Where such a decision occurs, the person may state a point of view, receive a clear and sufficient explanation of the logic, criteria and determining factors used, request reconsideration, and request human intervention, without compromising trade secrets, intellectual property or third-party rights. Where the automated decision rests on a contract or on law, the right to human intervention and to an explanation survives. Dutch regulators have been working through what a sufficient explanation actually looks like in practice, opening a consultation in 2026 that made clear risk scores and categorisation outputs derived from profiling fall inside access requests.
Other rights in the article include portability in a structured, commonly used format, with direct controller-to-controller transfer where technically feasible; erasure; restriction of processing; withdrawal of consent at any time, with the text specifying that withdrawing is as easy as granting; complaints filed with the Superintendency of Industry and Commerce, personally or anonymously; and compensation for damages caused by improper processing.
A procedural deadline accompanies the list. Where a processor receives a rights request, it has two business days to give the data subject the identity, physical or electronic address and telephone number of the controller, and to forward the request onward.
Geolocation and neurodata become sensitive
Article 5 adds geolocation data, data relating to gender identity or expression, genetic data and neurodata to the category of sensitive data. The definition in Article 3(l) already covers racial or ethnic origin, political opinions, religious or philosophical beliefs, union membership, membership in social or human rights organisations, genetic data, neurodata, biometric data intended to uniquely identify a person, health data, data relating to sex or biological characteristics, gender identity or expression, and sexual orientation.
Reclassifying location as sensitive is the single provision with the most direct operational consequence for media buying. Under Article 6, processing sensitive data remains prohibited except in enumerated cases, to which the bill adds compliance with legal obligations and the exercise of specific rights. The European analogue, special category data, carries a comparable default prohibition and has already reshaped what platforms will accept as targeting input.
Neurodata places Colombia alongside a small group of jurisdictions legislating for signals that barely exist as commercial inventory. California added neural data as a protected category through amendments effective January 1, 2026.
Fourteen as the consent threshold
Article 7 sets the age at which a minor's own consent becomes valid at fourteen. Below that, processing is lawful only with the express consent of a legal representative, and the controller must take all reasonable measures, accounting for available technology, to verify that the authorisation was effectively granted or endorsed. Where legal representation is shared, consent from one representative is presumed to reflect the will of all, though any representative may revoke it before the controller, after which authorisation requires mutual agreement or a court decision.
Brazil's regulator has been running ahead of the region on this question, adding child protection to its enforcement priorities in December 2025 and opening a consultation on age verification mechanisms in May 2026. Enforcement followed: ByteDance faced R$ 153.7 million in fines over the handling of children's data on TikTok.
Duties that land on the vendor stack
Article 12 of the bill rewrites the duties of controllers in Article 17 of the existing law, and the additions read like a compliance checklist for an ad tech vendor. Impact assessments become mandatory for large-scale processing, for automated or semi-automated processing including profiling, and in all cases for automated processing of sensitive data. A data protection officer must be appointed where processing is large-scale, where sensitive data forms part of core business, or where a public authority is the controller. Security incidents must be reported to the national authority within 72 hours of detection, with affected data subjects notified where the incident poses a high risk to their rights.
Further duties require formalising processor relationships by contract, progressively incorporating privacy-enhancing technologies into systems involving automated data analysis or large-scale processing, training personnel with written confidentiality commitments, and conducting an internal or external review of processing systems at least every two years. That biennial clock resets whenever substantial modifications are made to the systems. Where two or more controllers jointly determine purposes and means, they become joint controllers and must agree transparently on their respective obligations, with the essential aspects made available to the data subject.
Processor duties in Article 13 mirror the structure. Processors must follow controller instructions and flag instructions they consider unlawful, adopt an internal manual of policies, use data solely for the assignment, appoint an officer under the same triggers, refrain from subcontracting without express authorisation, return data at the end of the relationship, and facilitate inspections and audits.
The definitional apparatus supporting all of this is imported wholesale. Article 3 adds definitions for biometric data, genetic data, health-related data, profiling, security incidents, pseudonymisation, international transfer, large-scale processing, anonymisation, data protection impact assessments and privacy-enhancing technologies. Article 4 adds principles of transparency, demonstrated accountability, fairness and non-discrimination, data minimisation, storage limitation, proportionality and explainability. European regulators took eight years after the GDPR became applicable to publish a standardised impact assessment template, a gap that indicates how much implementation work sits behind a one-line statutory duty.
Two regulators and a 5% ceiling
Supervision stays with the Superintendency of Industry and Commerce, acting through an Office for the Protection of Personal Data described in Article 14 as impartial, autonomous and independent. The office would be headed by a Deputy Superintendent appointed by the Superintendent for a four-year term without immediate reelection, following a public call for nominations.
A second institution joins it. Article 15 adds Article 19A, giving the Office of the Attorney General of the Nation six months from the law's effective date to create a Deputy Attorney General's Office for personal data protection, staffed through internal redistribution within the approved budget. Its remit under Article 21A covers preventive oversight of public entities and disciplinary investigations of public officials, and it includes monitoring the use of artificial intelligence systems, big data, biometrics, georeferencing and surveillance technologies by government entities.
Penalties sit in Article 20. According to the bill, the Superintendency may impose personal and institutional fines of up to the equivalent of 10,000 legal monthly minimum wages in effect when the sanction is imposed, or up to 5% of the offender's operating revenue in the fiscal year immediately preceding the sanction. Fines may be imposed repeatedly for as long as the noncompliance persists, and permanent closure of data processing operations is available once a suspension period elapses without the ordered corrective measures. At the monthly minimum wage set for 2026 in Colombia, 1,750,905 pesos, the wage-based ceiling works out near 17.5 billion pesos, though the figure is derived rather than stated in the bill and moves each year with the wage.
Article 21 adds criteria for calibrating severity, including the effective implementation of demonstrated accountability measures, the degree of cooperation with the authority, and the existence of a data protection officer where one was not required. The penalties apply to private individuals, mixed-economy companies and state-owned industrial and commercial enterprises; alleged violations by public authorities are referred to the Attorney General instead.
Transfers and the adequacy question
Article 22 rebuilds the international transfer regime. Transfers are permitted to countries providing adequate levels of protection, with adequacy measured against standards set by the National Authority that may never fall below the protections the law provides domestically. Where the destination lacks adequacy, controllers must implement additional safeguards drawn from three mechanisms: a declaration of compliance filed with the authority, binding corporate rules approved by it for intra-group transfers regardless of geography, or model contractual clauses it has approved.
Where neither adequacy nor safeguards are available, transfers proceed only in exceptional cases, including express and unequivocal consent, medical data exchange for treatment, bank or securities transfers, treaty-based transfers on a reciprocity principle, contractual necessity, and transfers required to safeguard the public interest or defend a right in judicial proceedings.
The architecture is recognisably European, and the question of data adequacy is the one that determines whether cross-border advertising data flows survive contact with it. Brazil sits further along that path: the European Data Protection Board assessed its framework in Opinion 28/2025, noting close alignment with the GDPR while flagging transparency limits tied to commercial secrecy.
The complaint record behind the filing
The justification rests on volume. According to the explanatory memorandum, the Superintendency of Industry and Commerce reported, in response to a petition, that 161,098 complaints alleging violations of the fundamental right to habeas data were filed over the preceding decade. The annual series runs from 3,954 in 2013 to 5,634, 6,134, 6,875 and 7,317 across the following four years, then 10,057 in 2018, 15,158 in 2019, 18,920 in 2020, 31,237 in 2021 and 37,973 in 2022, with 17,839 recorded for 2023 and marked as partial data.
Two charts reproduced in the filing break the volume down by cause. Under Statutory Law 1581 of 2012, roughly 83% of complaints concerned authorisation. Under Statutory Law 1266 of 2008, about 82.5% concerned veracity and quality of information. Those shares are read from charts in the Gazette rather than from tabulated figures, and the underlying counts are not published alongside them.
The memorandum frames the problem in terms that sit unusually close to advertising's own mechanics. It argues that consent granted in seconds, on a thirty-page form nobody reads, within a culture that rewards constant exposure of private life, is not a free and informed decision, and that market self-regulation and user goodwill are insufficient to protect a fundamental right. The argument is supported by reference to the philosopher Byung-Chul Han and to control exercised through transparency rather than prohibition.
What the hearings surfaced
Two public hearings preceded this filing. The first was held on March 7, 2024, convened by the ten members of the First Permanent Constitutional Committee of the House of Representatives, with the Ministry of ICTs, the Financial Superintendency of Colombia and the Superintendency of Industry and Commerce summoned. Leonardo Cervera Navas, Secretary General of the European Data Protection Supervisor, participated virtually. A second hearing on September 25, 2025 produced a debate on Bill No. 274 of 2025.
Industry objections are recorded in the memorandum without being resolved. Diego Casas Correal of the Tunja Chamber of Commerce raised concern that extraterritorial application generates negative effects on the digital ecosystem and risks creating legal uncertainty. Germán López of the Colombian Chamber of Information Technology and Communications argued that implementing the scope of application could be risky and that applying the same control to artificial intelligence could be dangerous, citing legal uncertainty over roles within the digital ecosystem. Natalia Forero of the Colombian Chamber of Electronic Commerce pressed for narrower definitions to avoid legal disputes and pointed to excessive burdens on organisations. Adolfo Enrique Gómez argued for a transitional regime for micro, small and medium-sized enterprises.
The regulator itself was not uniformly enthusiastic. Juan Carlos Upegui, a delegate from the Superintendency of Industry and Commerce, argued for maintaining the current regulatory model provided for in Law 1581, while raising a point about the recognition of new rights.
Why it matters for the marketing community
Article 23 sets the effective date, and it is the provision most likely to be underestimated. According to the bill, the Act takes effect upon enactment, amending Articles 2, 3, 4, 5, 6, 7, 8, 12, 17, 18, 19, 21, 23, 24 and 26, superseding Articles 9 and 10, and adding Articles 19A, 21A, 21B and 21C. There is no general transition period. Only two clocks run past enactment: six months for the government to regulate the foreign representative obligation, and six months for the Attorney General to stand up the new deputy office.
Colombia is not a marginal market for the practices the bill would constrain. Mobile app installs in the country grew 17% year over year according to benchmark data covering six Latin American markets, with regional smartphone penetration forecast at 93% by 2030.
The wider pattern is a regional convergence on European drafting. Paraguay's Chamber of Deputies approved a comprehensive data protection law in May 2025. Ecuador issued its legitimate interest framework that November. Egypt published implementing regulations after a five-year gap. Indonesia's authority-building process remains contested in its Constitutional Court even as its implementing regulation takes shape. In the United States, the SECURE Data Actproposes the opposite move, pre-empting state rules with a single federal standard.
What separates this filing from the others is the arithmetic of its own history. Two versions have already died without completing the legislative process, and the text arrives in a session where, on Montezuma's reading, regional appetite for data protection reform has thinned. The compliance question for vendors operating in Colombia is therefore not what the bill requires but whether it survives committee. The operational one, for anyone whose bid requests carry Colombian location signals, is what a statute with no transition period would mean on the day it is enacted.
Timeline
- 2008 - Colombia enacts Law 1266 of 2008, the financial habeas data regime that Bill 282 leaves in place except for international transfers
- 2012 - Statutory Law 1581 of 2012 establishes Colombia's general data protection framework, built on Directive EU 95/46
- 2013 to 2023 - The Superintendency of Industry and Commerce records 161,098 complaints alleging habeas data violations, rising from 3,954 in 2013 to 37,973 in 2022
- March 7, 2024 - First public hearing convened by ten members of the First Permanent Constitutional Committee, with EDPS Secretary General Leonardo Cervera Navas participating virtually
- 2024-2025 session - The initiative is filed as PLE 152 of 2024 and does not complete the legislative process
- May 2025 - Paraguay's Chamber of Deputies approves a comprehensive data protection law
- September 25, 2025 - Second public hearing leads to debate on Bill No. 274 of 2025
- November 5, 2025 - The European Data Protection Board assesses Brazil's adequacy position in Opinion 28/2025
- November 7, 2025 - Ecuador issues Resolution No. SPDP-SPD-2025-0041-R on documented legitimate interest assessments
- December 22, 2025 - Brazil's ANPD approves 2026-2027 enforcement priorities with child protection added
- January 1, 2026 - Neural data takes effect as a protected category under California amendments
- March 10, 2026 - The European Data Protection Board adopts its first standardised impact assessment template
- April 21, 2026 - The SECURE Data Act is filed in the US House, proposing federal pre-emption of state privacy law
- May 23, 2026 - Brazil's ANPD opens a public consultation on age verification mechanisms
- July 16, 2026 - Indonesia signs Government Regulation No. 33 of 2026, setting 72-hour deadlines and profiling impact assessments
- August 2026 - Statutory Bill No. 282 of 2026 is submitted to the General Secretariat of the House of Representatives
- September 8, 2026 - The Congressional Gazette, Year XXXV No. 1217, publishes the bill and its explanatory memorandum across a 33-page edition
Related PPC Land coverage
- Firms face up to 4% turnover fines under Montenegro's new data law - A 106-article statute applying from March 2027 that extends obligations to companies anywhere selling to or tracking people in Montenegro.
- Canada's Bill C-36 sets $10 million privacy fines as Parliament returns - The proposed replacement for PIPEDA, including a legitimate interest basis conditioned on documented impact assessments.
- Firms could face 5% revenue fines for re-identifying data in Canada - The criminal tier of the same Canadian bill and how its ceilings compare with the administrative regime.
- Ecuador establishes framework for legitimate interest data processing - The Andean precedent for requiring a written balancing test before relying on legitimate interest.
- European data protection board evaluates Brazil adequacy decision - How a Latin American framework was measured against GDPR standards, and where it fell short.
- Data controllers face 2% revenue fines under Indonesia's new data rules - A 225-article implementing regulation naming advertising targeting of vulnerable groups as a refusable decision.
- EDPB's damning digest: how 'legitimate interest' fails in practice - An analysis of 62 decisions showing where controllers relying on the basis lose.
- ByteDance faces R$ 153.7 million in fines over TikTok children's data - What enforcement of a Latin American children's data regime looks like in practice.
Summary
Who: Representative María Fernanda Carrascal Rojas of Bogotá and Senator Duvalier Sánchez Arango, who signed Statutory Bill No. 282 of 2026; the Superintendency of Industry and Commerce, which would supervise private-sector compliance through a new Office for the Protection of Personal Data; the Office of the Attorney General of the Nation, which would gain a deputy office for public-sector oversight; and any controller or processor, domiciled in Colombia or not, that handles Colombian personal data. The text was surfaced publicly by Luis Alberto Montezuma.
What: A partial amendment to Statutory Law 1581 of 2012 that adds five legal bases alongside consent, classifies geolocation and neurodata as sensitive, creates an explicit right to object to advertising and direct marketing processing including profiling, mandates impact assessments for large-scale and profiling operations, requires a data protection officer in three defined cases, sets 72-hour breach notification, obliges foreign controllers to appoint a local representative, and raises penalties to 10,000 legal monthly minimum wages or 5% of prior-year operating revenue.
When: Published in the Congressional Gazette, Year XXXV No. 1217, on Tuesday, September 8, 2026, after submission in August 2026. Under Article 23 the Act would take effect upon enactment, with six-month windows for the representative regulations and for standing up the Attorney General's deputy office.
Where: Colombia, with extraterritorial reach over processing linked to goods or services offered to people in Colombia and over monitoring of their behaviour, regardless of where the controller sits.
Why: The explanatory memorandum cites 161,098 habeas data complaints filed with the Superintendency between 2013 and 2023 and argues that consent alone can no longer carry the architecture of data protection. For advertising, the consequence is that location signals, profiling-based targeting and cross-border data flows out of Colombia would each acquire a documentation requirement and a revenue-linked penalty, in a statute drafted without a general transition period. Two previous versions failed to complete the legislative process.
Discussion