Application of the Accountability Principle to Personal Data Processing Security Incidents: A Comparative Analysis of Colombia, Brazil, Peru, and Mexico
DOI:
https://doi.org/10.18800/dys.202601.008Keywords:
Accountability Principle, Security obligation, Cybersecurity, Administrative responsibilityAbstract
This article examines how the Accountability Principle and the security obligation, both conceived to ensure practical and up-to-date personal data protection, are affected when the mere occurrence of a security incident is automatically treated as evidence of non-compliance, thereby creating a moral hazard that discourages investment in preventive measures. It argues that a proper assessment of the security obligation, consistent with the Accountability Principle, requires the National Data Protection Authority (DPA) to examine the controller’s risk assessment, the appropriateness of the security measures implemented, and the controller’s post-incident response. Drawing on case studies from Colombia, Brazil, Peru, and Mexico, the article identifies divergent approaches to enforcement. In some cases, the mere occurrence of a security incident is treated as sufficient to establish liability, whereas in others the authorities undertake a more thorough assessment of the safeguards implemented before determining whether the controller breached its legal obligations. Finally, the article proposes a three-part analytical framework under which cyberattacks may, in certain circumstances, constitute a defence against liability. This framework seeks to reconcile the Accountability Principle with the security obligation while promoting diligent, risk-based information security management.








