Application of the Accountability Principle to Personal Data Processing Security Incidents: A Comparative Analysis of Colombia, Brazil, Peru, and Mexico

Authors

  • Lina M. Díaz Universidad Externado de Colombia

    Abogada de la Universidad Externado con Maestría en Propiedad Intelectual y Derecho de la Competencia de la London School of Economics (LSE) y Maestría en Economía Aplicada de la Universidad de los Andes. Cuenta con más de 7 años de experiencia en procesos administrativos y judiciales en materia de propiedad intelectual, protección de datos, protección al consumidor y derecho de la competencia.

DOI:

https://doi.org/10.18800/dys.202601.008

Keywords:

Accountability Principle, Security obligation, Cybersecurity, Administrative responsibility

Abstract

This article examines how the Accountability Principle and the security obligation, both conceived to ensure practical and up-to-date personal data protection, are affected when the mere occurrence of a security incident is automatically treated as evidence of non-compliance, thereby creating a moral hazard that discourages investment in preventive measures. It argues that a proper assessment of the security obligation, consistent with the Accountability Principle, requires the National Data Protection Authority (DPA) to examine the controller’s risk assessment, the appropriateness of the security measures implemented, and the controller’s post-incident response. Drawing on case studies from Colombia, Brazil, Peru, and Mexico, the article identifies divergent approaches to enforcement. In some cases, the mere occurrence of a security incident is treated as sufficient to establish liability, whereas in others the authorities undertake a more thorough assessment of the safeguards implemented before determining whether the controller breached its legal obligations. Finally, the article proposes a three-part analytical framework under which cyberattacks may, in certain circumstances, constitute a defence against liability. This framework seeks to reconcile the Accountability Principle with the security obligation while promoting diligent, risk-based information security management.

Downloads

Download data is not yet available.

Published

2026-08-14

How to Cite

Díaz, L. M. (2026). Application of the Accountability Principle to Personal Data Processing Security Incidents: A Comparative Analysis of Colombia, Brazil, Peru, and Mexico. Derecho & Sociedad, (66), 1–22. https://doi.org/10.18800/dys.202601.008

Issue

Section

Derecho Transnacional