Colombia
Colombia Data Privacy Laws: Law 1581 and Habeas Data Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 15 primary sources cited on this page. How we verify our legal content

Colombia's personal data protection is grounded in Article 15 of the 1991 Constitution, which establishes habeas data as a fundamental right. Law 1581 of 2012 builds on that foundation, requiring prior, express, and informed consent before any personal data may be collected or processed, with enforcement by the Superintendencia de Industria y Comercio.
What Is Colombia's Data Protection Law?
Colombia protects personal data through a layered regime: a constitutional guarantee in Article 15 of the 1991 Political Constitution, two primary statutes (Law 1581 of 2012 for general data and Law 1266 of 2008 for financial data), implementing regulations in Decree 1377 of 2013, and binding circulars issued by the Superintendencia de Industria y Comercio (SIC). The framework is one of the most developed in Latin America, notable for treating data protection not as a statutory privilege but as a fundamental constitutional right called habeas data. Under Article 2, the law reaches processing carried out in Colombian territory, which the SIC applies to foreign companies processing data in Colombia even without a branch or formal representation there. It reaches a controller or processor outside Colombia only where Colombian law applies to it by virtue of international rules or treaties.
Jurisdiction scope: This article covers Colombia's national data protection framework, including Law 1581 of 2012, Decree 1377 of 2013, Law 1266 of 2008, SIC enforcement circulars, and the 2025 statutory reform bills that Congress archived in June 2026. It does not address Colombia's recording consent laws or Argentina, Chile, or Brazil's separate data protection regimes.

Constitutional Foundation: Habeas Data as a Fundamental Right
Colombia's approach to data privacy is distinctive in Latin America because it starts at the constitutional level. Article 15 of the Political Constitution of 1991 guarantees every person the right to personal and family privacy and to their good name. More importantly, Article 15 establishes what Colombian law calls habeas data: the specific right to know, update, and rectify any information collected about an individual in databases or records maintained by public or private entities. This is not a statutory afterthought. It is a fundamental constitutional right that carries the same weight as freedom of expression or due process.
Article 20 of the Constitution reinforces this framework by guaranteeing the right to receive truthful and impartial information. Together, these two provisions create a constitutional mandate that Congress was required to implement through legislation. Because the mandate flows from the Constitution itself, the implementing statute required the elevated legislative form of a ley estatutaria, subject to mandatory advance review by the Constitutional Court of Colombia before taking effect.
Key Constitutional Court Decisions
The Constitutional Court has built a substantial body of habeas data jurisprudence since 1992. Four decisions anchor the field:
- Sentence T-414 of 1992 first recognized that personal financial data protection constitutes an individual freedom the Court called "information processing liberty," distinct from the general right to privacy.
- Sentence T-022 of 1993 extended the analysis to the collection and circulation of financial information, framing it as a privacy problem amenable to constitutional protection through the tutela mechanism.
- Sentence C-748 of 2011 reviewed the constitutionality of the draft ley estatutaria that became Law 1581, interpreting many of the statute's core provisions before they came into force. This pre-clearance ruling is binding on all courts and public authorities.
- Ruling T-260 of 2012 held that a parent may not open a social media account in a small child's name. A father created a Facebook profile for his four-year-old daughter, describing it as a virtual family album identified to 24 relatives, and the child's mother brought the tutela. The Court found breaches of the child's habeas data and honra rights, because a four-year-old cannot give a prior, express, and informed consent and the child did not know the profile existed, and it ordered the father to cancel the account within 48 hours.
The significance of constitutional-level protection is procedural as well as substantive. A data subject does not have to wait through months of administrative proceedings before the SIC. Any person who believes their habeas data rights have been violated may file a tutela directly with any court. Under Article 86 of the Constitution, the court must rule within 10 days.
Law 1581 of 2012: The Core Data Protection Statute
Congress fulfilled its constitutional mandate by enacting Ley Estatutaria 1581 de 2012, which established the general framework for personal data protection in Colombia. The statute applies to all personal data recorded in any database that can be processed by public or private entities. Article 2 then sets the territorial reach, and it is narrower than readers coming from the GDPR expect. Law 1581 covers processing carried out in Colombian territory, and covers a controller or processor not established in Colombia only where Colombian law applies to it by virtue of international rules and treaties. There is no equivalent of the GDPR test that catches a foreign company simply for offering goods or services to people in the territory or monitoring their behaviour.
In practice the SIC still reaches foreign operators frequently, because it treats processing carried out in Colombia as covered even where the company has no branch, subsidiary, or formal representation in the country. It said exactly that in the World Foundation appeal decided in June 2026.
Where Law 1581 Does Not Apply
Article 2 also carves six kinds of database out of the regime:
- Databases or files kept in a purely personal or domestic setting.
- Databases whose purpose is national security and defence, or the prevention, detection, monitoring, and control of money laundering and terrorism financing.
- Databases holding intelligence and counter-intelligence information.
- Databases and files of journalistic information and other editorial content.
- Databases governed by Law 1266 of 2008, which is the financial and credit habeas data regime.
- Databases governed by Law 79 of 1993.
The carve-out is not total. A paragraph to Article 2 keeps the data protection principles applicable to the excepted databases, within the limits the law itself sets.
Data Categories Under Law 1581
The law distinguishes four categories of data, each carrying different protections:
| Category | Definition | Examples | Consent Required |
|---|---|---|---|
| Public data | Not semi-private, private, or sensitive | Public records, gazette publications | No |
| Semi-private data | Not intimate; access limited to specific persons or purposes | Financial and credit information | Governed by Law 1266/2008 |
| Private data | Intimate in nature; relevant only to the data subject | Personal correspondence, private messages | Yes |
| Sensitive data | Affects the most intimate sphere; risk of discrimination | Race, health, sexual orientation, biometrics, political opinions | Yes, with higher clarity standard |
Core Processing Principles
Law 1581 establishes eight principles that govern all data processing:
- Legality: Processing must comply with applicable laws.
- Purpose limitation: Data may only be collected for a legitimate, specific purpose communicated to the data subject.
- Freedom: Processing requires the data subject's prior, express, and informed consent.
- Truthfulness: Information must be accurate, complete, and up to date.
- Transparency: The data subject has the right to obtain information about their data at any time.
- Restricted access: Only authorized persons may process the data.
- Security: Data must be protected with technical, human, and administrative measures.
- Confidentiality: All persons involved in processing must maintain confidentiality, even after the processing relationship ends.
Consent Requirements Under Colombian Law
Consent is the cornerstone of Colombia's data protection regime. Article 9 of Law 1581 requires that data subjects provide prior, express, and informed authorization before their personal data can be collected or processed.
What Makes Consent Valid
Colombian law demands that consent meet four criteria:
- Prior: Authorization must be obtained before data collection begins, not after.
- Express: The data subject must actively indicate consent through a clear affirmative action.
- Informed: The data controller must explain what data will be collected, why, and how it will be used.
- Revocable: Data subjects can withdraw their consent at any time and for any reason.
Implicit or tacit consent is not sufficient. Pre-ticked boxes, consent buried in lengthy terms of service, or assumptions of consent from continued use of a service do not meet the standard set by the SIC. The Worldcoin enforcement action of October 2025 illustrated this directly: the SIC found that financial incentives used to induce iris scan collection rendered consent coercive and therefore legally invalid under Article 9 of Law 1581.
Exceptions to the Consent Requirement
Article 10 of Law 1581 sets a closed list of five cases where authorization is not required:
- Information required by a public or administrative entity in the exercise of its legal functions, or by judicial order.
- Data of a public nature.
- Cases of medical or health emergency.
- Processing authorized by law for historical, statistical, or scientific purposes.
- Data relating to the Civil Registry of Persons.
That list is exhaustive. Anyone who accesses personal data without prior authorization must still comply with every other provision of the law.
Sensitive Data: Heightened Protection
Article 5 of Law 1581 defines sensitive data as information that could lead to discrimination. This includes data revealing racial or ethnic origin, political orientation, religious beliefs, philosophical convictions, membership in trade unions or human rights organizations, health information, sexual life, and biometric data.
Article 6 prohibits the processing of sensitive data except in five cases. The list is closed:
- The data subject has given explicit authorization to that processing, except where the law does not require authorization.
- Processing is necessary to safeguard the data subject's vital interest and the data subject is physically or legally incapacitated. In that case the legal representatives must give the authorization.
- Processing is carried out in the course of the legitimate activities, and with due guarantees, of a foundation, NGO, association, or other nonprofit whose purpose is political, philosophical, religious, or trade-union, and it refers exclusively to its members or to people who keep regular contact with it because of that purpose. The data may not be supplied to third parties without the data subject's authorization.
- The data is necessary for the recognition, exercise, or defense of a right in judicial proceedings.
- Processing has a historical, statistical, or scientific purpose. In that case measures must be adopted to suppress the identity of the data subjects.
There is no civil registry exception in Article 6. Civil registry data sits in Article 10, which lists the cases where general authorization is not required. That is a different rule and it does not lift the sensitive-data prohibition.

Decree 1377 of 2013: Implementation Regulations
On June 27, 2013, the executive branch issued Decreto 1377 de 2013 to implement the operational requirements of Law 1581. This decree fills in the practical details the statute left to regulation.
Practitioners still cite it by number, but it no longer stands as a free-standing regulation. Its text was compiled into Decreto 1074 de 2015, the single regulatory decree for the Commerce, Industry and Tourism sector, where these provisions now sit in Book 2, Part 2, Title 2, Chapter 25. The SIC cites the compiled version in its own current guidance.
Privacy Policy Requirements
Article 13 of Decree 1377 requires every data controller to develop a written processing policy (política de tratamiento de la información). It must be in physical or electronic form, in clear and simple language, and made known to data subjects. The policy must include at minimum:
- Identification of the data controller.
- Description of the purposes and methods of data processing.
- The rights of data subjects and how to exercise them.
- Identification of the person or department responsible for data protection.
- Procedures for data subjects to file queries and complaints.
- The timeframe for which the policy applies.
Privacy Notice
Article 14 makes the privacy notice (aviso de privacidad) a fallback rather than a second universal duty. Where it is not possible to put the full processing policy in front of the data subject, the controller must instead tell them by privacy notice that the policy exists and how to reach it, in good time and in any event no later than the moment the data is collected.
Article 15 sets the notice's minimum content, and where sensitive data is collected the notice must state expressly that answering questions about that data is optional. Publishing a notice never relieves the controller of the duty to make the full policy known.
Articles 26 and 27 add the demonstrated-accountability duty. Controllers must be able to show the SIC, on request, that they have implemented appropriate and effective measures, proportionate to their size, the nature of the data, the type of processing, and the risk involved. The "programa integral de gestión de datos personales" that Colombian practice talks about comes from the SIC's accountability guidance, not from the text of the decree.
Documentation Obligations
Controllers must maintain documented evidence of the authorization obtained from each data subject. This proof must be available for inspection by the SIC at any time. The SIC has made documented consent a focus of enforcement audits since 2022, and the absence of documented authorization was one of several violations cited in the Worldcoin investigation.
Data Subject Rights (ARCO Rights and Beyond)
Article 8 of Law 1581 grants data subjects a set of rights. Colombian practice borrows the regional "ARCO" shorthand (Access, Rectification, Cancellation, Opposition), but the "O" for opposition comes from Mexican law and has no counterpart in Law 1581:
- Right to access: Individuals can request copies of all personal data held about them at no charge.
- Right to update: Data subjects can demand that inaccurate or incomplete information be corrected.
- Right to rectification: Specifically addresses errors in databases, including the correction of false or misleading entries.
- Right to erasure: Individuals may request deletion of their data when consent is revoked or when processing is no longer necessary for the stated purpose.
- Right to revoke consent: Data subjects can withdraw their authorization at any time and for any reason, without prejudice.
- Right to proof of the authorization: Article 8(b) lets the data subject require the controller to produce the authorization it obtained, except where Article 10 excuses authorization as a requirement. This is the provision that makes documented consent enforceable by the individual and not only by the SIC.
- Right to be told how the data was used: Under Article 8(c), the controller or processor must tell the data subject, on request, what use it has made of their personal data.
- No standalone right to object: Unlike the GDPR, Article 8 does not grant a right to object to processing. In practice, unwanted direct marketing is stopped by revoking the authorization under Article 8(e), not by objecting to a legal basis.
- Right to file complaints: Data subjects can file claims with the SIC when their rights are violated.
Under Article 14, a consultation must be answered within 10 business days. Where that is not possible, the controller must tell the requester why and give a date, which can be no more than 5 further business days after the first period expires.
Under Article 15, a claim must be answered within 15 business days, extendable on the same notice condition by up to 8 further business days. If the claim arrives incomplete, the controller has 5 days to ask the person to complete it, and the claim is treated as abandoned if 2 months pass with no response. Within 2 business days of receiving a complete claim, the database must carry a "reclamo en trámite" legend, which stays until the claim is decided.
Article 16 makes exhausting the consultation or claim process a precondition. Only once that internal route is finished may the data subject take a complaint to the SIC.
Watch out: Reform bills 214/2025C and 274/2025C would have added four rights that Law 1581 does not grant: the right not to be subject to solely automated decisions, the right to data portability, the right to restrict processing, and a right to object. Those bills were archived in June 2026, so none of those rights is part of Colombian law. Build compliance programs on Article 8 as it stands today.
The SIC: Colombia's Data Protection Authority
The Superintendencia de Industria y Comercio (SIC) is Colombia's national data protection authority. Within the SIC, the Deputy Superintendence for the Protection of Personal Data handles enforcement, investigation, and regulatory guidance. The SIC is a multi-function regulator, also overseeing consumer protection and competition law, but its data protection division operates with independent enforcement authority under Law 1581.
Powers and Functions
The SIC has broad authority under Law 1581 to:
- Investigate complaints filed by data subjects.
- Conduct inspections and audits of data controllers and processors, with or without prior notice.
- Issue binding instructions and guidelines (circulars).
- Impose administrative sanctions including monetary fines and operational restrictions.
- Order the temporary blocking of data where the data subject's request and evidence show a clear risk to their fundamental rights, while a final decision is pending.
- Maintain the National Registry of Databases (RNBD).
- Declare whether a foreign country provides adequate data protection for transfer purposes.
National Registry of Databases (RNBD)
One of Colombia's most distinctive requirements is the RNBD registration obligation. The RNBD is a publicly accessible directory of personal databases operating in Colombia, managed by the SIC and viewable by any citizen. Registration serves both transparency and regulatory oversight purposes.
Who must register: Under Decree 090 of 2018, companies and nonprofit entities with total assets above 100,000 UVT (Unidades de Valor Tributario), plus public-law legal persons, must register their databases. The UVT is reset every January, so the peso figure moves with it. At the 2026 UVT of COP 52,374, the threshold is about COP 5.24 billion.
Annual update window: The SIC's standing rule is that registry entries are updated each year between January 2 and March 31. Failing to update within the prescribed period is an independent infraction.
Ongoing obligations: Substantial changes must be reflected within the first ten business days of a month, which is a fixed monthly window rather than a rolling ten days from the change. The SIC's Circular Única defines a substantial change as one touching the purpose of the database, the processor, the channels for data subjects, the classification or types of personal data stored, the security measures implemented, the processing policy, or international transfers and transmissions. New databases must be registered within two months of creation.
Breach portal: For RNBD-registered entities, security breach notifications to the SIC must be submitted through the RNBD portal.
Penalties and SIC Enforcement
Law 1581 gives the SIC a graduated enforcement toolkit, and the authority has used it with increasing frequency since 2022.

Monetary Fines Under Current Law
The maximum fine is 2,000 times the monthly legal minimum wage in force when the sanction is imposed (SMMLV). With Colombia's 2026 minimum wage set at COP 1,750,905, the ceiling reaches about COP 3.5 billion. Article 23(a) adds that fines may be imposed successively for as long as the non-compliance that caused them persists, so the ceiling is a per-sanction figure rather than a lifetime cap. The dollar value moves with the exchange rate, so the SMMLV multiple and the peso amount are the reliable numbers to plan against. Article 24 sets the criteria for graduating a sanction, in so far as each one applies: the dimension of the harm or danger to the legal interests the law protects; the economic benefit the offender or a third party obtained from the infraction; recidivism; resistance, refusal, or obstruction of the SIC's investigation or supervision; refusal or contempt in complying with SIC orders; and express acknowledgment or acceptance of the infraction by the investigated party before the sanction is imposed. That last criterion is the one statutory route to a lower number, and it closes once the sanction is issued.
Operational Sanctions
Article 23 lists the sanctions beyond fines, and the trigger for each one matters:
- Suspension: Suspension of the activities related to the processing for up to six months. The suspension order must specify the correctives to be adopted.
- Temporary closure: Temporary closure of the operations, available once the suspension period has run without the ordered correctives being adopted.
- Immediate and definitive closure: Reserved for an operation that involves the processing of sensitive data. This is the ground the SIC used against World Foundation and Tools for Humanity.
Article 23 contains no sanction of closing and deleting a database as such. A paragraph to the same article limits all of these sanctions to private-law persons: where the SIC suspects a public authority of non-compliance, it refers the matter to the Procuraduría General de la Nación instead.
Enforcement Trends
Reading the SIC's 2024 accountability report, Holland and Knight counted a 22% rise in SIC sanctions in 2024 over the previous year. The SIC's own 2024 sanctions table lists the individual cases but does not publish that year-over-year comparison. Enforcement priorities have expanded from traditional consent-and-notice violations to cover emerging technologies, cross-border transfers, and biometric data collection.
The most high-profile enforcement action in the SIC's history came on October 3, 2025, when the SIC issued Resolution 78798 ordering the immediate and permanent shutdown of World Foundation and Tools for Humanity (Worldcoin) operations in Colombia. The SIC found that the companies had collected iris images from thousands of people in Colombia through "Orb" devices, in exchange for money, without consent that was genuinely free and sufficiently informed. World's own reported registration figure for Colombia was close to two million users as of September 2025, but the SIC never adopted that number, describing the collection only as reaching thousands of people. Key violations included: no Colombia-specific privacy addendum (while addenda existed for the EU, Japan, Argentina, and Peru); failure to disclose the Secure Multi-Party Computation protocol used to fragment and store iris codes with third parties; and use of financial incentives the SIC found rendered consent coercive. The SIC ordered deletion of all biometric data collected in Colombia since operations began and prohibited both entities from any further data processing in Colombia. The companies appealed. On June 18, 2026 the SIC's Delegatura para la Protección de Datos Personales issued Resolution 45710, resolving the recurso de apelación and confirming Resolution 78798 in full. No further administrative appeal is available, so the closure and the biometric deletion orders are final.
The appeal turned on a technical argument the SIC rejected. The companies said the iris code and the fragments derived from it through secure multi-party computation were no longer personal data, because they were encrypted, fragmented, and distributed across separate nodes. The Delegatura held that cryptographic measures applied after collection do not make information anonymous. The whole point of the World ID system is to recognise a person by verifying their uniqueness from biometric patterns, so the functional link to an identifiable individual survives the encryption.
Breach Notification Requirements
Article 17(n) of Law 1581 makes it a controller's duty to inform the data protection authority when there is a breach of the security codes and there are risks in the administration of data subjects' information. Article 18(k) puts the same duty on processors, addressed to the SIC by name. The SIC's Reporte de Incidentes de Seguridad is the channel for that report.
Notification Timeline and Process
Breaches must be reported to the SIC within 15 business days of detection. For databases registered in the RNBD, the notification is submitted through the RNBD portal. The report must describe the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed.
The Statutory Trigger Has Two Limbs
The duty in Articles 17(n) and 18(k) is conjunctive. It is owed when there is a breach of the security codes and there are risks in the administration of data subjects' information. That second limb is a risk element, not a rule that every incident must be reported whatever the circumstances.
It is still a low bar in practice. The SIC reads the risk limb broadly, and it is far easier to defend a report that turned out to be unnecessary than a decision not to report at all. But the law does not say harm and risk are irrelevant, and a compliance program built on the belief that Colombia has no threshold at all is built on the wrong text.
Notice to Affected Individuals
There is no specific statutory deadline for notifying affected individuals. However, the SIC has stated that individual notification should allow data subjects to take protective measures, and has indicated that unreasonable delays in individual notification can constitute an aggravating factor in enforcement proceedings.
Cross-Border Data Transfers
Article 26 of Law 1581 generally prohibits transferring personal data to countries that do not provide an adequate level of data protection. The SIC assesses adequacy based on whether a receiving country's legal framework provides protections at least equivalent to those under Colombian law.
Countries the SIC Has Recognized as Adequate
The operative text is numeral 3.2 of Chapter Three, Title V of the SIC's Circular Única, set by Circular Externa 005 of 2017 and amended by Circular Externa 002 of 2018, which added Australia. It names 38 countries: the 27 EU member states, plus Iceland and Norway, plus the United States, the United Kingdom, Costa Rica, Mexico, Peru, Serbia, the Republic of Korea, Japan, and Australia.
The list then closes with a catch-all covering countries the European Commission has declared to have an adequate level of protection. That matters, because it is how Canada qualifies. Canada is not named in the SIC's list, and neither is Liechtenstein despite being an EEA state. Other jurisdictions holding a European Commission adequacy decision, such as Switzerland, Argentina, Uruguay, Israel, and New Zealand, come in the same way. Transfers to any country on the named list or covered by the catch-all do not require additional authorization beyond the underlying consent and notice obligations of Law 1581.
Transfers to Non-Adequate Countries
When a transfer must go to a country not on the adequate list, the data controller must use one of the following mechanisms:
- A Declaration of Conformity (declaración de conformidad) issued by the SIC based on an analysis of the recipient's data protection practices.
- One of the exceptions in literals (a) to (f) of Article 26 itself, which has no numbered subsections: the data subject's express and unequivocal authorization for the transfer; exchange of medical data where the data subject's treatment requires it for reasons of health or public hygiene; banking or stock-exchange transfers under the law that governs them; transfers agreed under international treaties to which Colombia is a party, on the basis of reciprocity; transfers necessary to perform a contract between the data subject and the controller or to take pre-contractual steps, with the data subject's authorization; and transfers legally required to safeguard the public interest or to recognise, exercise, or defend a right in judicial proceedings.
- Self-verification under paragraph 2 of numeral 3.2 of the Circular Única. Where the destination country is not on the list, the controller may itself check whether that country meets the numeral 3.1 standards and, if it does, proceed on that basis. Only if neither an Article 26 exception nor the numeral 3.1 standards are met does it need to ask the SIC for a Declaration of Conformity.
Model Contractual Clauses (December 2025)
On December 19, 2025, the SIC issued Circular Externa No. 003 of 2025, introducing voluntary model contractual clauses for international transfers and transmissions of personal data. Adoption of the clauses is facultative, but once a controller or processor chooses to use them, the obligations in the clauses become binding and failure to comply can constitute a breach of Law 1581. The circular brings Colombia's transfer framework significantly closer to the European model of standard contractual clauses and provides organizations with a well-defined compliance path for transfers to countries not on the adequate list.
Law 1266 of 2008: Financial Habeas Data
Alongside Law 1581, Colombia maintains a specialized regime for financial data under Ley 1266 de 2008. This law governs the processing of financial, credit, commercial, and service-related data collected in credit bureaus and similar databases.
Under Law 1266, financial data processing generally does not require prior consent from the data subject. However, data subjects retain the right to access, update, and rectify their credit information.
Law 2157 of 2021, known as the "borrón y cuenta nueva" law, rewrote Article 13 of Law 1266 to set how long negative data may stay in the bureaus. Positive information stays indefinitely. Negative data has a permanence period of double the time of the default, capped at four years, and that clock starts on the date the overdue instalments are paid or the obligation is extinguished. It does not end there. Under paragraph 1, negative data expires in any case eight years after the obligation first went into default.
The immediate-deletion benefit many Colombians remember was a transitional regime, not the permanent rule. Article 9 of Law 2157 gave a six-month cap, and in several categories immediate removal, to people who extinguished a reported obligation within twelve months of the law entering into force. Law 2157 was published in Diario Oficial 51.842 on October 29, 2021 and took effect that day, so that window closed on October 29, 2022.
Anyone paying off a debt today is under the permanent rule. The negative record can remain for double the length of the default, up to four years counted from the date of payment, and it does not disappear the moment the debt is settled.
The SIC enforces both Law 1266 and Law 1581 through the same Deputy Superintendence for the Protection of Personal Data.
Artificial Intelligence and the SIC's Technology-Specific Guidance
Colombia has moved faster than most Latin American countries to issue binding regulatory guidance on how particular technologies and sectors handle personal data. Three circulars anchor the current framework, alongside the model contractual clauses of Circular 003 of 2025 covered above.
Circular 002 of 2024: AI Systems
The SIC issued Circular Externa No. 002 of August 21, 2024 to establish guidelines for personal data processed through AI systems. The circular applies to all data controllers, processors, and users that develop or deploy AI systems that use personal data. Key requirements include:
- Adherence to the principles of necessity, suitability, reasonableness, and proportionality when designing AI data pipelines.
- A privacy impact assessment (estudio de impacto en privacidad) must be completed before initiating any AI-based data collection, with minimum content requirements specified in the circular.
- Secure processing environments that comply with existing data protection regulations must be in place before collection begins, not after.
- Implementation of differential privacy techniques where feasible to prevent re-identification of data subjects in aggregate analysis.
- Transparency obligations: data subjects must be informed when AI systems are used to process their data.
Circular 001 of 2025: Fintech and Financial Services
On September 18, 2025, the SIC issued Circular Externa No. 001 of 2025, establishing binding guidelines for the processing of personal data in the fintech ecosystem. The circular applies to digital financial products and services including electronic wallets, SEDPE (electronic payment deposit specialists), low-amount deposit services, and acquiring services. It also covers any natural or legal person conducting credit, deposit, or quasi-financial services using technological means, even if not supervised by the Financial Superintendence of Colombia.
Key requirements under Circular 001 of 2025:
- Data minimization: Companies may only collect information that is strictly necessary and proportionate to the service purpose.
- Consent clarity: When requesting authorization, companies must clearly distinguish between consent essential to service delivery and accessory purposes such as marketing campaigns or additional product offers. Bundled consent does not satisfy Law 1581.
- Biometric data: Controllers must obtain explicit authorization for biometric data used in authentication or fraud prevention, apply data minimization principles, and implement additional security measures beyond the baseline Law 1581 standard.
- Automated decisions: Where automated systems produce decisions affecting data subjects, the company must provide information about the logic involved and ensure a human review mechanism exists.
- Security measures: Controls must be evaluated and documented periodically, with a demonstrable accountability record available for SIC inspection.
Circular 002 of 2026: Political and Electoral Data
On January 15, 2026 the SIC issued Circular Externa No. 002 of 2026, published in Diario Oficial 53.368 the same day. It binds political parties and movements, candidates, campaigns, electoral marketing firms, and other obligated parties, which makes it live compliance work for anyone running political outreach in Colombia.
The instructions are specific:
- Political or electoral use of personal data requires the data subject's prior and informed authorization. Collection channels, physical or digital, must carry the processing policy, privacy notices, and an authorization mechanism.
- Collecting, adding to a database, or analysing personal data through any digital tool without that authorization is prohibited. So is adding a person to a messaging group, a distribution list, or a mass-send without their prior informed consent.
- Building profiles based on political orientation without explicit prior authorization is prohibited, because of the risk of discrimination and manipulation.
- Controllers must tell data subjects, on request and proactively, how their data was used to deliver political messaging, including the segmentation criteria applied, the source of the data, and any use of artificial intelligence. The channels for knowing, updating, rectifying, or deleting data must be as easy to use as the ones used to collect it.
- Parties and movements may process the data of their affiliates, members, and followers to stay in contact with them, but may not pass that data to third parties without prior authorization.
The 2025 Reform Bills Were Archived
The national government and the SIC acknowledged that Law 1581, in force since 2012, does not address the data processing realities of the 2020s. In August 2025, SIC Superintendent Cielo Rusinque said publicly that reform of the statutory law framework was necessary, and two bills were filed in the House of Representatives that month. Neither became law.
What Happened to the Bills
Bill 214/2025C was promoted by a group of congress members allied with the executive branch and filed on August 22, 2025. Bill 274/2025C was filed jointly by the Ministries of Commerce, Industry and Tourism and of Science, Technology and Innovation on August 27, 2025. The First Permanent Constitutional Commission of the House accumulated the two files under article 151 of Law 5 of 1992, with 274/2025C as the principal, and approved the combined measure in first debate on October 28, 2025 (Acta 18). A second-debate report was published in Gaceta 2196 of 2025.
There the file stopped. It never reached the House floor, and the Senate column of the bill record is empty. Amending a ley estatutaria takes four debates plus advance review by the Constitutional Court, and article 153 of the Constitution requires all of that within a single legislature. Article 190 of Law 5 of 1992 expressly excludes statutory bills from the rule that lets an ordinary bill carry over into the next legislature. So when the 2025-2026 legislature closed on June 20, 2026, the file died. The Cámara de Representantes bill record now shows Estado: Archivado, with the observation "ARCHIVADO ARTICULO 190, LEY 5 DE 1992."
Law 1581 of 2012 is unchanged. Any renewed reform would have to be filed as a new bill and start over from first debate.
What the Archived Bills Would Have Changed
The proposals are worth knowing, because a future reform is likely to draw on them and because they show where Colombian law currently differs from the GDPR. None of it is law. Both bills would have introduced:
- Extended territorial scope: The law would apply to any controller or processor that offers goods or services to persons in Colombia or monitors their behavior, regardless of domicile, mirroring the GDPR's Article 3(2) approach.
- Mandatory local representative: Foreign controllers or processors subject to the extended scope must appoint a local representative in Colombia.
- New legal bases: Beyond consent, the bills would recognize contract performance, compliance with a legal obligation, protection of vital interests, performance of a task in the public interest, and legitimate interests as valid legal bases for processing.
- Accountability principle: Controllers would be required to demonstrate proactive compliance rather than merely comply reactively.
- New data subject rights: Right not to be subject to solely automated decisions with significant effects; right to data portability; right to restriction of processing; right to object to processing.
- Strengthened children's protections: Heightened requirements for processing the data of minors.
- Updated penalty regime: Both bills proposed fines of up to 5% of the violator's annual operational revenues. Bill 214/2025C capped fines at 4,000 SMMLV; Bill 274/2025C at 10,000 SMMLV. Either would have been a large increase over the 2,000 SMMLV ceiling that still applies.
Watch out: With the bills archived, Law 1581 of 2012 and Decree 1377 of 2013, as compiled into Decree 1074 of 2015, remain the operative legal framework, and nothing in the reform package has any legal effect. Build compliance programs on current law.
Business Compliance: What Organizations Must Do
Organizations processing personal data in Colombia should satisfy all of the following:
- Obtain valid authorization: Prior, express, and informed consent for all data processing. Document it.
- Adopt a privacy policy: A comprehensive internal policy meeting Decree 1377 requirements, covering all active databases.
- Provide privacy notices: Clear, readable notice to data subjects at the time of collection identifying the controller, purposes, data collected, and rights.
- Register databases with the RNBD: Required if the organization's assets exceed 100,000 UVT or if it is a public entity. Annual update window must not be missed.
- Appoint a responsible person or department: Designate and name the data protection function in internal policy and in RNBD filings.
- Implement layered security measures: Technical, administrative, and physical controls. Document and periodically evaluate them.
- Establish internal complaint procedures: Processes allowing data subjects to exercise their Article 8 rights within the statutory deadlines (10 business days for consultations, extendable by 5 with notice; 15 business days for claims, extendable by 8 with notice), including the "reclamo en trámite" legend within 2 business days.
- Maintain a breach response plan: Procedures to detect, investigate, and report to the SIC within 15 business days of detection, whenever a breach of the security codes creates risks in the administration of personal data.
- Audit cross-border transfers: Verify that all international transfers flow to adequate countries or have a valid legal mechanism. Circular 003/2025 model clauses are available for non-adequate transfers.
- Conduct AI privacy impact assessments: Mandatory under Circular 002/2024 before any AI-based personal data collection begins.
- Fintech-specific controls: If offering digital financial services, review Circular 001/2025 requirements on data minimization, biometric authorization, consent clarity, and automated decision-making.
- Political and electoral outreach controls: If the organisation is a political party or movement, a candidate, a campaign, or an electoral marketing firm, apply Circular 002 of 2026: prior informed authorization before any political or electoral use of personal data, no harvesting through digital tools without it, no adding people to messaging groups or distribution lists without consent, no profiling by political orientation without explicit authorization, and disclosure of segmentation criteria, data sources, and any AI used.
- Watch for a new reform bill: The 2025 reform bills were archived in June 2026. A renewed reform would have to be filed again and go through the full statutory-law process, so there is nothing to build for it today.
Frequently Asked Questions
Does Colombia's data protection law apply to foreign companies?
Often, but the test is narrower than the GDPR's. Article 2 applies Law 1581 to processing carried out in Colombian territory, and to a controller or processor not established in Colombia only where Colombian law reaches it by virtue of international rules or treaties. A foreign company is usually caught because the processing itself happens in Colombia. The SIC applies that broadly: in the World Foundation appeal decided in June 2026 it held that Law 1581 covers anyone processing personal data in Colombia, even partially, and even without a branch or formal representation there. Simply offering goods or services into Colombia from abroad is not itself the statutory trigger. Reform bills that would have added a GDPR-style offering-and-monitoring test were archived in June 2026.
What is habeas data in Colombia?
Habeas data is a fundamental constitutional right established in Article 15 of Colombia's 1991 Political Constitution. It gives every person the right to know what personal information is held about them in public or private databases, to update that information, and to rectify inaccurate entries. Unlike in countries where data protection is purely a statutory right, Colombia's constitutional-level protection means individuals can enforce habeas data immediately by filing a tutela (constitutional writ) with any court, which must rule within 10 days.
What is the difference between Law 1581 and Law 1266 in Colombia?
Law 1581 of 2012 is the general personal data regime, but Article 2 excludes several kinds of database from it, and one of those exclusions is databases governed by Law 1266 of 2008. Credit bureau data therefore sits outside Law 1581 rather than alongside it. Law 1266 covers financial, credit, and commercial data used in credit reporting databases. It does not require prior consent for processing in most cases, and as amended by Law 2157 of 2021 it lets negative data remain for double the time of the default, capped at four years counted from the date the overdue instalments are paid or the obligation is extinguished, with an outer expiry eight years after the default began. Immediate erasure on payment was a transitional benefit whose window closed on October 29, 2022. Both laws are enforced by the SIC.
How much can the SIC fine a company for data protection violations in Colombia?
Under Law 1581, the SIC can impose fines of up to 2,000 times the monthly legal minimum wage in force when the sanction is imposed (SMMLV). Based on the 2026 SMMLV of COP 1,750,905, the maximum is about COP 3.5 billion, and Article 23 allows fines to be repeated for as long as the non-compliance continues. Beyond fines, Article 23 allows suspension of the processing activities for up to six months, temporary closure if the ordered correctives are not adopted within that period, and immediate and definitive closure where the operation involves sensitive data. Reform bills that would have raised the ceiling to 5% of annual operational revenues were archived in June 2026, so the 2,000 SMMLV cap is what applies today.
Can I transfer personal data from Colombia to the United States?
Yes. The United States is among the countries the SIC has recognized as providing adequate data protection, so personal data transfers from Colombia to US recipients are permitted without additional SIC authorization. The data controller must still comply with all other requirements of Law 1581, including valid consent for the underlying processing and contractual or operational assurances that the US-based recipient maintains appropriate security measures.
What are Colombia's model contractual clauses for cross-border transfers?
In December 2025, the SIC issued Circular Externa No. 003 of 2025 introducing voluntary model contractual clauses for international transfers and transmissions of personal data to countries not on the SIC's adequacy list. Use of the clauses is optional, but once adopted they become binding. The mechanism parallels the EU's standard contractual clauses and provides a more predictable compliance path than the Declaration of Conformity process, which requires case-by-case SIC review.
What happened with Worldcoin in Colombia?
On October 3, 2025, the SIC issued Resolution 78798 ordering the immediate and definitive shutdown of all data processing operations by World Foundation and Tools for Humanity (Worldcoin) in Colombia. The SIC found that the companies had collected iris images from thousands of people in Colombia through Orb devices, in exchange for money, without consent that was genuinely free and sufficiently informed: there was no Colombia-specific privacy addendum despite such addenda existing for other jurisdictions, and the companies failed to disclose the secure multi-party computation protocol used to fragment and store iris codes with third parties. World's own reported registration count for Colombia was close to two million users, but the SIC never adopted that figure. The SIC ordered deletion of all biometric data collected in Colombia. The companies appealed, and on June 18, 2026 the SIC confirmed the sanction in full through Resolution 45710, holding that encrypting and fragmenting an iris code after collection does not make it anonymous. No further administrative appeal is available.
What does Colombia's AI data protection circular require?
SIC Circular 002 of August 21, 2024 applies to all controllers, processors, and users that develop or deploy AI systems using personal data. It requires: (1) a privacy impact assessment before any AI-based data collection begins; (2) adherence to the principles of necessity, suitability, reasonableness, and proportionality; (3) secure processing environments compliant with existing law before collection starts; (4) implementation of differential privacy techniques where feasible; and (5) transparency with data subjects about AI use in processing decisions. Violation of the circular's instructions can constitute a breach of Law 1581.
What happened to Colombia's 2025 data protection reform bills?
They were archived without becoming law. Bills 214/2025C and 274/2025C were accumulated, with 274/2025C as the principal file, and approved in first debate in the House First Constitutional Commission on October 28, 2025. They never reached the Senate. The Cámara de Representantes bill record now shows the file as Archivado, archived under article 190 of Law 5 of 1992 when the 2025-2026 legislature ended on June 20, 2026 without the statutory law completing its four debates and Constitutional Court review. The rights they proposed, which included a right not to be subject to solely automated decisions, data portability, restriction of processing, and a right to object, are not part of Colombian law. A renewed reform would have to be filed again and start the process over.
Updates
Third-round correction: FAQ 9's answer now matches its reworded question about the archived 2025 reform bills.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Full refresh: added Constitutional Court jurisprudence section, reform bills 214/274 of 2025 and House Committee approval status, SIC Circular 001 of 2025 (fintech), expanded Worldcoin resolution details, expanded FAQ to 9 questions, added data-categories comparison table, updated meta and keywords.
Reviewed and approved by an editor
Initial publication. Covered Ley 1581/2012, Decreto 1377/2013, SIC authority, RNBD, cross-border transfers, breach notification, Circular 002/2024 AI guidelines, Worldcoin enforcement.
Sources and References
- Constitución Política de Colombia 1991 — Artículo 15 (Derecho a la intimidad y habeas data)(constituteproject.org)
- Función Pública — Ley 1581 de 2012 (Ley Estatutaria de Protección de Datos Personales)(funcionpublica.gov.co).gov
- Función Pública — Decreto 1377 de 2013 (reglamentario de la Ley 1581 de 2012; texto compilado en el Decreto Único 1074 de 2015, Libro 2, Parte 2, Título 2, Capítulo 25)(funcionpublica.gov.co).gov
- SIC — Deputy Superintendence for the Protection of Personal Data(sic.gov.co).gov
- SIC — Circular Externa No. 002 de 2024: Lineamientos sobre el Tratamiento de Datos Personales en Sistemas de Inteligencia Artificial(sedeelectronica.sic.gov.co).gov
- SIC — Circular Externa No. 001 de 2025: Lineamientos para el tratamiento de datos personales en el ecosistema Fintech(sedeelectronica.sic.gov.co).gov
- SIC — Sanciones Protección de Datos Personales 2024(sic.gov.co).gov
- SIC — ABC del Proyecto de Ley de Protección de Datos Personales en Colombia (documento de la etapa del proyecto; los Proyectos de Ley Estatutaria 214/2025C y 274/2025C fueron archivados en junio de 2026 y no son derecho vigente)(sedeelectronica.sic.gov.co).gov
- Baker McKenzie — Colombia: 2026 update on minimum wage and allowances(bakermckenzie.com)
- SIC — Reporte de Incidentes de Seguridad (canal para informar violaciones a los códigos de seguridad, arts. 17(n) y 18(k) de la Ley 1581 de 2012)(sic.gov.co).gov
- Holland and Knight — Data Protection in Colombia: Sanctions, NEW SIC Rules and the Impact of Artificial Intelligence (2025)(hklaw.com)
- Holland and Knight — Obligations of the National Registry of Personal Databases Before the SIC in Colombia for 2025(hklaw.com)
- IAPP — Colombia introduces new model contractual clauses (Circular Externa No. 003 of 2025)(iapp.org)
- Allende and Brea — New bills to amend Colombia data protection law introduced in Congress (Bills 214/2025 and 274/2025, filed August 2025; both were archived in June 2026 and never became law)(allende.com)
- DataGuidance — Colombia: House Committee approves combined bill to amend data protection law (first-debate stage, October 2025; the combined file was archived in June 2026)(dataguidance.com)
- Biometric Update — Colombia orders World shut-down, citing biometrics compliance failures (Resolution 78798, October 3, 2025)(biometricupdate.com)
- DLA Piper — Data Protection Laws of the World: Colombia(dlapiperdataprotection.com)
- Privacy International — State of Privacy Colombia(privacyinternational.org)
- Cámara de Representantes — Ficha del Proyecto de Ley Estatutaria 274/2025C (acumulado con el 214/2025C bajo el art. 151 de la Ley 5a de 1992): Estado "Archivado", observación "ARCHIVADO ARTICULO 190, LEY 5 DE 1992"(camara.gov.co).gov
- SIC — Circular Externa No. 002 del 15 de enero de 2026: tratamiento de datos personales con fines políticos y electorales (Diario Oficial No. 53.368 del 15 de enero de 2026)(sedeelectronica.sic.gov.co).gov
- SIC — Comunicado: la Resolución 45710 del 18 de junio de 2026 resolvió el recurso de apelación y confirmó la Resolución 78798 del 3 de octubre de 2025 (World Foundation y Tools for Humanity); contra esa decisión no procede recurso alguno(sedeelectronica.sic.gov.co).gov
- Ley 2157 de 2021 ("borrón y cuenta nueva") — modifica el artículo 13 de la Ley 1266 de 2008 sobre permanencia de la información negativa (Diario Oficial No. 51.842 del 29 de octubre de 2021)(jurinfo.jep.gov.co).gov
- SIC — Circular Externa No. 002 de 2018: modifica el numeral 3.2 del Capítulo Tercero del Título V de la Circular Única (lista de países con nivel adecuado de protección; incorpora a Australia)(normas.cra.gov.co).gov
- SIC — Preguntas frecuentes del RNBD: están obligadas a registrar las sociedades y entidades sin ánimo de lucro con activos totales superiores a 100.000 UVT y las personas jurídicas de naturaleza pública (Decreto 090 del 18 de enero de 2018)(sic.gov.co).gov
- DIAN — Resolución 000238 del 15 de diciembre de 2025: fija en $52.374 el valor de la UVT que rige durante 2026(normograma.dian.gov.co).gov