Free scan About Support Contact
Get Velo

Already have an account? Log in

Regulations

Colombia's Ley 1581,
prior consent handled.

Colombia's data protection law asks for prior, express and informed authorisation before personal data is processed. Velo starts every consent signal denied until visitors make that choice.

The rule,
at a glance.

General information, checked September 2026. Not legal advice.

Applies to
Processing of personal data in Colombia.
The rules
Ley 1581 de 2012 and Decreto 1377 de 2013.
Consent model
Prior, express and informed authorisation, with proof kept.
Enforced by
The Superintendencia de Industria y Comercio (SIC).
Maximum fine
Up to 2,000 monthly minimum legal wages.
Velo default
Every Consent Mode v2 signal starts denied, with the banner in Spanish.

What Ley 1581 asks.
What Velo does.

The Velo mascot behind a clay globe with two location pins, each linked to its own small consent banner, on a lavender studio backdrop.

Prior consent for visitors in Colombia

Velo reads the visitor's country at the edge. Visitors in Colombia start opt in, with every Consent Mode v2 signal denied until they choose.

The Velo mascot sliding a script row from a checked list into a stack of category trays, on a lavender studio backdrop.

Informed, in Spanish

Authorisation has to be informed. The banner ships in Spanish and explains each category before the visitor chooses.

The Velo mascot between a clay checklist and a receipt with a verified seal, on a lavender studio backdrop.

Proof of authorisation

Ley 1581 expects you to keep proof of authorisation. Each decision is stored with a receipt id, the region and the banner version.

The Velo mascot pointing at a clay consent dashboard with a donut chart and bars, on a lavender studio backdrop.

Change or withdraw any time

The floating button reopens preferences, so visitors can revoke or change what they allowed.

What the law
actually says.

Ley 1581 de 2012 is Colombia's general data protection law. Before you process someone's personal data you need their authorisation, and it has to be prior, express and informed: people know what you collect and why, and they agree before it happens.

Decreto 1377 de 2013 fills in the detail. You have to keep proof of each authorisation and publish a data processing policy that explains how people can consult, correct or delete their data.

Up and running
in four steps.

From the first script tag to the first recorded choice.

  1. The Velo mascot fitting a purple puzzle piece with a code symbol into a clay browser window, on a lavender studio backdrop.

    Add Velo to your site

    Install it with the Google Tag Manager template or paste one script tag. Guides cover WordPress, Shopify, Webflow and other platforms.

  2. The Velo mascot inspecting clay cookies with a magnifying glass beside a stack of sorting trays, on a lavender studio backdrop.

    Scan and sort your cookies

    Velo scans your pages, lists the cookies and scripts it finds and suggests a category for each one. You confirm or change them.

  3. The Velo mascot painting a clay cookie banner whose two buttons are the same size, on a lavender studio backdrop.

    Design the banner

    Pick colours, wording and languages. Reject sits next to accept on the first layer.

  4. The Velo mascot pressing a button on a clay box that prints a receipt with a check seal, on a lavender studio backdrop.

    Publish and check

    Visitors in Colombia get opt in defaults, with every consent signal denied until they choose. Each choice lands in your consent log with its receipt id.

Before you
go live.

Velo handles the banner, the regional defaults and the records. These parts stay with you.

  • Your privacy or cookie notice names each purpose and each third party that sets cookies.
  • Tags in Google Tag Manager wait for the matching consent signal before they fire.
  • You tested from the region itself: nothing optional loads before a visitor chooses.
  • Someone on the team reviews new scripts when a scan finds them.
  • Your data processing policy (política de tratamiento) is published on the site.
  • You checked whether your databases must be registered in the SIC's Registro Nacional de Bases de Datos.

In every plan, from €0

Consent Mode v2 advancedRegional defaults by countryGlobal Privacy Control honouredReceipt for every choiceReject as easy as acceptFloating preferences button
Nine banner languagesCookie and tracker scanChoices by categoryConsent log and dashboardWorks with Google Tag ManagerInstallation help

Questions,
answered.

What teams ask about Ley 1581.

What does Ley 1581 de 2012 require?

It is Colombia's general data protection law. Processing personal data needs the prior, express and informed authorisation of the data subject, and controllers must be able to show it was obtained.

Who enforces it?

The Superintendencia de Industria y Comercio (SIC), which can investigate, order changes and impose fines.

Why does Velo use opt in for Colombia?

Because authorisation has to come before processing, Velo starts every consent signal denied for visitors in Colombia until they choose.

Is this legal advice?

No. This page is general information about Ley 1581 and how Velo behaves.