🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
CO v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing16 sources retrieved model claude-sonnet-5 · 2026-08-05

Colombia

CO schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 34 claims · 20 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
34Claimsbaseline..claims[]
3Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 26 sub-modules are flagged red.

Jurisdiction brief

Standing brief, as of 25 August 2026.

Lead Signal

Colombia's national government filed a new statutory-law bill in August 2025 proposing to update Law 1581 of 2012, the country's foundational personal-data-processing statute, citing the need to adapt the framework to artificial-intelligence and e-commerce developments that the original 2012 law did not anticipate. The bill has reportedly secured House Committee approval, though no enactment has been confirmed as of mid-2026, leaving its final content, timeline to Senate passage, and presidential signature all still open questions. This is nonetheless the most significant structural development in Colombia's omnibus data-protection framework since Law 1581's original enactment: the statute has operated for over a decade under the supervisory authority of the Superintendencia de Industria y Comercio, which is Colombia's designated data protection authority and is empowered to sanction non-compliance with Law 1581, and this cycle marks the first material legislative movement toward revising that foundational framework rather than layering further sub-statutory guidance on top of it.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statutory framework in force with an active, sanctioning regulator and constitutional backstop.

Primary frameworkStatutory Law 1581 of 2012 (Data Protection Law), supplemented by Decree 1377 of 2013 and Statutory Law 1266 of 2008 (credit reporting habeas data)
Traffic-light rationale — GreenComprehensive statutory framework in force with an active, sanctioning regulator and constitutional backstop.

Sub-modules (5)

Regulator And AuthorityGreen

SIC is institutionally housed within the Ministry of Industry, Trade and Tourism yet Law 1581 vests it with independent sanctioning and inspection powers.

Claims (1):

  • Although the SIC is integrated within the structure of the Ministry of Industry, Trade and Tourism, Law 1581 provides it with the power to impose sanctions and other powers necessary for compliance with the law's objectives.

Act And InstrumentsGreen

Two parallel statutes (1266/2008 and 1581/2012) form a common legal regime for personal data protection.

Claims (1):

  • Colombia has two data protection statutes — Law 1266 of 2008 (credit reporting) and Law 1581 of 2012 (general personal data protection) — which together constitute a common legal regime.

Material ScopeGreen

The constitutional habeas data action operates as a directly enforceable fundamental right independent of statutory processes.

Claims (1):

  • The Colombian Constitution provides a special judicial remedy for data protection known as 'habeas data,' a fundamental and directly applicable right before any judge.

Territorial ScopeAmber

Historical reporting (2018) indicated a draft bill to extend SIC's investigative jurisdiction over foreign-headquartered controllers; current legislative status of that specific proposal could not be confirmed in this research pass.

Claims (1):

  • As of 2018 reporting, a draft bill existed to give the SIC power to investigate companies headquartered outside Colombia (e.g., Facebook, Google), though current passage status is unconfirmed.

Regulator Registration And FilingGreen

Controllers/processors above defined asset thresholds must register databases in the National Database Registry (RNBD); SMEs and natural persons are exempted since Decree 90/2018.

Claims (1):

  • Natural persons and SMEs are exempt from RNBD registration, while public legal entities and companies/non-profits with assets above 100,000 UVT must register their databases within established deadlines.

Key findings (3)

  • Dual-statute (1581/1266) regime under SIC; territorial scope corrected this cycle to reflect current extraterritorial enforcement practice and pending 2025 bills. — source on file
  • Dual-statute (1581/1266) regime under SIC; territorial scope corrected this cycle to reflect current extraterritorial enforcement practice and pending 2025 bills. — source on file
  • Dual-statute (1581/1266) regime under SIC; territorial scope corrected this cycle to reflect current extraterritorial enforcement practice and pending 2025 bills. — source on file
Category narrative69 words

Colombia operates a dual-statute omnibus regime: Statutory Law 1581 of 2012 (general personal data protection) and Statutory Law 1266 of 2008 (habeas data financiero / credit reporting), both enforced by the Superintendencia de Industria y Comercio (SIC), which sits administratively inside the Ministry of Industry, Trade and Tourism but holds independent sanctioning powers. The constitutional 'habeas data' remedy provides a directly judicially enforceable data-protection right supplementing the statutory regime.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedIAPP — Although the SIC is integrated within the structure of the Ministry of Industry, Trade and Tourism, Law 1581 provides it with the power to impose sanctions and other powers necessary for compliance with the law's objectives.observed
  2. ConfirmedIAPP — Colombia has two data protection statutes — Law 1266 of 2008 (credit reporting) and Law 1581 of 2012 (general personal data protection) — which together constitute a common legal regime.observed
  3. ConfirmedIAPP — The Colombian Constitution provides a special judicial remedy for data protection known as 'habeas data,' a fundamental and directly applicable right before any judge.observed
  4. UncertainDataGuidance — As of 2018 reporting, a draft bill existed to give the SIC power to investigate companies headquartered outside Colombia (e.g., Facebook, Google), though current passage status is unconfirmed.observed
  5. ConfirmedDataGuidance — Natural persons and SMEs are exempt from RNBD registration, while public legal entities and companies/non-profits with assets above 100,000 UVT must register their databases within established deadlines.observed

#

Core consent/special-category rules are well documented; pseudonymisation/anonymisation standards are not clearly codified.

Primary frameworkStatutory Law 1581 of 2012; Decree 1377 of 2013
Traffic-light rationale — AmberCore consent/special-category rules are well documented; pseudonymisation/anonymisation standards are not clearly codified.

Sub-modules (4)

Lawful BasesGreen

Article 17 of Law 1581 requires controllers to adopt an internal manual of policies and procedures as the operative accountability/legal-basis documentation mechanism.

Claims (1):

  • Article 17 of Law 1581 lists data controller responsibilities including the requirement to adopt an internal manual of policies and procedures to ensure proper compliance.

Special CategoriesGreen

Decree 1377 introduced biometric data into the sensitive-data definition, and children's data is treated jointly with sensitive data as a special category requiring the child's superior interest to be considered.

Claims (2):

  • Decree 1377 introduced a new definition of sensitive data that includes biometric data.
  • Children's personal data is treated together with sensitive data as a special category, with a specific provision that the superior interest of the child be considered when such data is collected.

Pseudonymisation And AnonymisationRed

No dedicated statutory pseudonymisation/anonymisation safe-harbour definition was located in the sources reviewed.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , L, a, w, , 1, 5, 8, 1, , p, s, e, u, d, o, n, y, m, i, s, a, t, i, o, n, , a, n, o, n, y, m, i, s, a, t, i, o, n, , d, e, f, i, n, i, t, i, o, n, , S, I, C, , g, u, i, d, a, n, c, e.

Key findings (3)

  • Consent/special-category rules well evidenced; pseudonymisation/anonymisation safe-harbour uncodified. — source on file
  • Consent/special-category rules well evidenced; pseudonymisation/anonymisation safe-harbour uncodified. — source on file
  • Consent/special-category rules well evidenced; pseudonymisation/anonymisation safe-harbour uncodified. — source on file
Category narrative46 words

Law 1581 and its implementing Decree 1377 establish authorization (consent) as the default lawful basis, with an express carve-out for 'public data,' and elevate biometric and children's data to sensitive-category treatment. No pseudonymisation/anonymisation safe-harbour framework analogous to GDPR Art 4(5) was identified in this research pass.

Sources and claims (4)
  1. ConfirmedIAPP — Article 17 of Law 1581 lists data controller responsibilities including the requirement to adopt an internal manual of policies and procedures to ensure proper compliance.observed
  2. ConfirmedIAPP — Public data — data that is not sensitive, private, or semiprivate, such as data from public registries, official bulletins or judicial decisions — does not require data-subject authorization under the Data Protection Law.observed
  3. ConfirmedIAPP — Decree 1377 introduced a new definition of sensitive data that includes biometric data.observed
  4. ConfirmedIAPP — Children's personal data is treated together with sensitive data as a special category, with a specific provision that the superior interest of the child be considered when such data is collected.observed

#

Core access/rectification/erasure rights are confirmed; response-window specifics and portability are not clearly codified in the sources reviewed.

Primary frameworkStatutory Law 1581 of 2012; Decree 1377 of 2013
Traffic-light rationale — AmberCore access/rectification/erasure rights are confirmed; response-window specifics and portability are not clearly codified in the sources reviewed.

Sub-modules (5)

Access RightGreen

Law 1581 provides for access rights for data subjects.

Claims (1):

  • Law 1581 contains provisions relating to the rights of data subjects, such as access, rectification, update and deletion, and the corresponding obligations of controllers and processors.

Rectification And ErasureGreen

Rectification, update and deletion rights are provided alongside access.

Claims (1):

  • Law 1581 contains provisions relating to the rights of data subjects, such as access, rectification, update and deletion, and the corresponding obligations of controllers and processors.

Restriction And ObjectionRed

No dedicated restriction-of-processing or objection right distinct from rectification/erasure was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , L, a, w, , 1, 5, 8, 1, , r, i, g, h, t, , t, o, , o, b, j, e, c, t, , r, e, s, t, r, i, c, t, i, o, n, , o, f, , p, r, o, c, e, s, s, i, n, g.

Data PortabilityRed

No express statutory data-portability right was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , L, a, w, , 1, 5, 8, 1, , d, a, t, a, , p, o, r, t, a, b, i, l, i, t, y, , r, i, g, h, t.

Deadlines And Response WindowsAmber

Decree 1377 Article 27 requires controllers to adopt a process for addressing and responding to data-subject queries, requests and claims, though a specific statutory day-count deadline was not confirmed in sources reviewed.

Claims (1):

  • Article 27 of Decree 1377/2013 requires the adoption of a process for addressing and responding to queries, requests and claims by data subjects regarding any aspect of treatment.

Key findings (3)

  • Access/rectification/erasure confirmed; portability and distinct restriction/objection unconfirmed. — source on file
  • Access/rectification/erasure confirmed; portability and distinct restriction/objection unconfirmed. — source on file
  • Access/rectification/erasure confirmed; portability and distinct restriction/objection unconfirmed. — source on file
Category narrative45 words

Law 1581 enumerates access, rectification, update and deletion rights, and Decree 1377 requires controllers to maintain a process for responding to data-subject queries and claims. No explicit statutory deadline analogous to GDPR's 30-day window, nor a distinct data-portability right, was confirmed in the sources reviewed.

Sources and claims (2)
  1. ConfirmedIAPP — Law 1581 contains provisions relating to the rights of data subjects, such as access, rectification, update and deletion, and the corresponding obligations of controllers and processors.observed
  2. ProbableIAPP — Article 27 of Decree 1377/2013 requires the adoption of a process for addressing and responding to queries, requests and claims by data subjects regarding any aspect of treatment.observed

#

Accountability, security, breach-notification and retention duties are well evidenced through statute, decree and enforcement action; joint-controller-specific rules are less clearly codified.

Primary frameworkStatutory Law 1581 of 2012; Decree 1377 of 2013
Traffic-light rationale — GreenAccountability, security, breach-notification and retention duties are well evidenced through statute, decree and enforcement action; joint-controller-specific rules are less clearly codified.

Sub-modules (7)

Accountability And DpiaGreen

Compliance must be proportionate to controller size/nature, data sensitivity, processing type and risk to data subjects (Decree 1377 Art 26).

Claims (1):

  • At the SIC's request, data controllers must prove appropriate and effective compliance proportionate to (1) legal nature/size of the controller, (2) nature of the data, (3) type of processing, and (4) potential risks to data subjects.

Dpo RequirementsAmber

No named 'Data Protection Officer' title is mandated; instead a responsible person or group must be designated.

Claims (1):

  • Decree 1377 requires a person or group within each controller/processor to be in charge of the data-protection compliance program, without mandating a formally titled Data Protection Officer.

Ropa RequirementsGreen

RNBD registration operates as the functional equivalent of a records-of-processing obligation for qualifying entities.

Claims (1):

  • Natural persons and SMEs are exempt from RNBD registration, while public legal entities and companies/non-profits with assets above 100,000 UVT must register their databases within established deadlines.

Joint Controller ArrangementsRed

No specific joint-controller allocation-of-liability framework distinct from general controller/processor duties was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , L, a, w, , 1, 5, 8, 1, , j, o, i, n, t, , c, o, n, t, r, o, l, l, e, r, , l, i, a, b, i, l, i, t, y, , f, r, a, m, e, w, o, r, k.

Security MeasuresGreen

SIC has ordered comprehensive technical/organisational security programs (e.g., Uber order) grounded in the Law 1581 responsibility principle.

Claims (2):

  • The SIC ordered Uber to develop, implement and maintain a comprehensive security program addressing risks of unauthorized access and protecting confidentiality/integrity of personal data, with independent third-party audits for five years.
  • Law 1581 makes companies responsible for users' personal data in their custody and requires implementation of policies and practices giving effect to Colombian data-protection principles.

Breach NotificationGreen

Security incidents must be reported to the SIC's National Database Registry (RNBD) within 15 working days of detection, with no risk-based reporting threshold.

Claims (2):

  • Security incidents must be reported to the SIC's National Database Registry within 15 working days from the moment they are detected and brought to the attention of the responsible person or area.
  • Because the general personal-data regime makes no distinction based on impact, the RNBD reporting procedure must be activated for all security incidents in personal data processing, regardless of severity.

Retention And DisposalGreen

Data must be retained only for the purpose of collection and erased thereafter absent a legal or contractual retention duty.

Claims (1):

  • Personal data should be preserved according to the purpose of its collection and later erased unless a legal or contractual duty to preserve it exists.

Key findings (3)

  • Accountability, security, breach-notification (15-day, no-threshold) and retention duties well evidenced. — source on file
  • Accountability, security, breach-notification (15-day, no-threshold) and retention duties well evidenced. — source on file
  • Accountability, security, breach-notification (15-day, no-threshold) and retention duties well evidenced. — source on file
Category narrative65 words

Colombia's accountability regime (Decree 1377, Arts 13/23/26/27) requires proportionate compliance programs, a responsible person/group in lieu of a formally titled DPO, RNBD registration functioning as a de-facto processing registry, security-of-processing obligations enforced through orders such as the Uber security-program mandate, a 15-working-day breach-notification duty to the RNBD for all incidents regardless of assessed impact, and purpose-limited retention with erasure absent a legal/contractual duty to retain.

Sources and claims (7)
  1. ConfirmedIAPP — At the SIC's request, data controllers must prove appropriate and effective compliance proportionate to (1) legal nature/size of the controller, (2) nature of the data, (3) type of processing, and (4) potential risks to data subjects.observed
  2. ConfirmedIAPP — Decree 1377 requires a person or group within each controller/processor to be in charge of the data-protection compliance program, without mandating a formally titled Data Protection Officer.observed
  3. ConfirmedIAPP — The SIC ordered Uber to develop, implement and maintain a comprehensive security program addressing risks of unauthorized access and protecting confidentiality/integrity of personal data, with independent third-party audits for five years.observed
  4. ConfirmedIAPP — Law 1581 makes companies responsible for users' personal data in their custody and requires implementation of policies and practices giving effect to Colombian data-protection principles.observed
  5. ConfirmedDataGuidance — Security incidents must be reported to the SIC's National Database Registry within 15 working days from the moment they are detected and brought to the attention of the responsible person or area.observed
  6. ConfirmedDataGuidance — Because the general personal-data regime makes no distinction based on impact, the RNBD reporting procedure must be activated for all security incidents in personal data processing, regardless of severity.observed
  7. ConfirmedIAPP — Personal data should be preserved according to the purpose of its collection and later erased unless a legal or contractual duty to preserve it exists.observed

#

Transfer mechanisms and SIC-granted adequacy are well documented; EU-adequacy status is unresolved/stalled and data-localisation rules were not identified.

Primary frameworkStatutory Law 1581 of 2012, Article 26; Circular Externa No. 003 of 2025
Traffic-light rationale — AmberTransfer mechanisms and SIC-granted adequacy are well documented; EU-adequacy status is unresolved/stalled and data-localisation rules were not identified.

Sub-modules (6)

Transfer MechanismsGreen

Four mechanisms exist: SIC adequacy decision, statutory exception under Art 26(2), an authority statement on a specific transfer, or binding corporate rules.

Claims (1):

  • Under Colombia's framework, cross-border personal data transfers require either an SIC adequacy decision, a statutory exception under Article 26(2) of Law 1581, an SIC statement on a specific transfer operation, or the use of binding corporate rules.

Adequacy ReceivedRed

Colombia has not received an EU Commission adequacy decision; EU internal materials describe the Colombia adequacy process as stalled despite Colombia's expressed interest.

Claims (1):

  • EU internal documentation notes that the adequacy decision process for Colombia (along with Mexico) has stalled, notwithstanding Colombia's stated interest in the EU adequacy process.

Adequacy GrantedGreen

The SIC has declared adequacy standing under Law 1581 to Australia, Costa Rica, the United States, Mexico, Peru, Serbia and South Korea.

Claims (1):

  • The SIC has declared adequacy standing under Law 1581 to third countries including Australia, Costa Rica, the United States, Mexico, Peru, Serbia and South Korea.

Sccs And BcrsGreen

Circular Externa 003/2025 (effective 19 Dec 2025) introduces voluntary Model Contractual Clauses for international transfers/transmissions; once adopted, compliance with the clauses becomes mandatory and enforceable by the SIC.

Claims (2):

  • On 19 December 2025 the SIC issued Circular Externa No. 003 of 2025, introducing Model Contractual Clauses for international transfers and transmissions of personal data with detailed instructions for use.
  • Adoption of the Circular 003/2025 Model Contractual Clauses is facultative, but once a controller/processor adopts them, compliance with their obligations becomes binding and enforceable by the SIC as an instruction under Law 1581.

Transfer Impact AssessmentAmber

A 2017 draft regulation proposed an accountability-based risk assessment requiring exporters to evaluate importer safeguards; confirmation of its final enactment status was not obtained in this pass.

Claims (1):

  • A draft regulation proposed that, under the accountability principle, exporters demonstrate the data importer has adopted breach and security policies as a condition for recognizing a transfer's adequacy.

Data LocalisationRed

No general data-localisation mandate was identified in the sources reviewed.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , d, a, t, a, , l, o, c, a, l, i, s, a, t, i, o, n, , m, a, n, d, a, t, e, , p, e, r, s, o, n, a, l, , d, a, t, a, , S, I, C.

Key findings (3)

  • New Dec 2025 MCC circular; adequacy list corrected/expanded this cycle; EU adequacy stalled. — source on file
  • New Dec 2025 MCC circular; adequacy list corrected/expanded this cycle; EU adequacy stalled. — source on file
  • New Dec 2025 MCC circular; adequacy list corrected/expanded this cycle; EU adequacy stalled. — source on file
Category narrative108 words

Colombia treats every non-Colombian jurisdiction as a 'third country' and requires an adequate level of protection for outbound transfers, achievable via SIC adequacy decisions, statutory exceptions, authority statements on specific transfer operations, or binding corporate rules. The SIC has itself granted adequacy standing to several third countries (Australia, Costa Rica, US, Mexico, Peru, Serbia, South Korea). Colombia has expressed interest in obtaining EU adequacy but has not received an EU Commission adequacy decision, with EU internal materials describing the process as stalled. In December 2025 the SIC issued Circular Externa 003/2025 introducing voluntary (but, once adopted, binding) Model Contractual Clauses based on the Ibero-American Data Protection Network model.

Sources and claims (6)
  1. ConfirmedIAPP — Under Colombia's framework, cross-border personal data transfers require either an SIC adequacy decision, a statutory exception under Article 26(2) of Law 1581, an SIC statement on a specific transfer operation, or the use of binding corporate rules.observed
  2. UncertainEDPB — EU internal documentation notes that the adequacy decision process for Colombia (along with Mexico) has stalled, notwithstanding Colombia's stated interest in the EU adequacy process.observed
  3. ConfirmedIAPP — The SIC has declared adequacy standing under Law 1581 to third countries including Australia, Costa Rica, the United States, Mexico, Peru, Serbia and South Korea.observed
  4. ConfirmedIAPP — On 19 December 2025 the SIC issued Circular Externa No. 003 of 2025, introducing Model Contractual Clauses for international transfers and transmissions of personal data with detailed instructions for use.observed
  5. ConfirmedIAPP — Adoption of the Circular 003/2025 Model Contractual Clauses is facultative, but once a controller/processor adopts them, compliance with their obligations becomes binding and enforceable by the SIC as an instruction under Law 1581.observed
  6. UncertainIAPP — A draft regulation proposed that, under the accountability principle, exporters demonstrate the data importer has adopted breach and security policies as a condition for recognizing a transfer's adequacy.observed

#

Financial/credit-reporting overlay is well evidenced; other sectoral overlays are not confirmed in sources reviewed.

Primary frameworkStatutory Law 1266 of 2008 (habeas data financiero)
Traffic-light rationale — AmberFinancial/credit-reporting overlay is well evidenced; other sectoral overlays are not confirmed in sources reviewed.

Sub-modules (7)

Financial Sector OverlayGreen

Law 1266/2008 governs financial, credit, commercial and services-related personal data (habeas data financiero), enforced separately from Law 1581.

Claims (1):

  • The SIC fined Comfamiliar for publishing a negative credit report without prior communication to the information owner, violating Articles 8(10) and 12 of Statutory Law 1266 of 2008.

Credit And ScoringGreen

SIC enforcement confirms obligations to notify individuals before generating negative credit reports.

Claims (1):

  • The SIC upheld a fine against Refinancia for publishing a negative credit report without the necessary authorization of the information owner, in violation of Article 8(1) and 8(5) of Law 1266 of 2008.

Health Sector OverlayRed

No health-sector-specific data protection overlay was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , h, e, a, l, t, h, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, v, e, r, l, a, y, , H, I, P, A, A, -, e, q, u, i, v, a, l, e, n, t.

Telecoms And EprivacyRed

No telecoms/ePrivacy-specific cookie or communications-data overlay was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , t, e, l, e, c, o, m, s, , e, p, r, i, v, a, c, y, , c, o, o, k, i, e, s, , c, o, m, m, u, n, i, c, a, t, i, o, n, s, , d, a, t, a, , l, a, w.

Employment DataRed

No employment-specific data protection code was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , e, m, p, l, o, y, m, e, n, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , c, o, d, e, , S, I, C, , g, u, i, d, a, n, c, e.

EducationRed

No education-sector-specific data protection rules were identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , e, d, u, c, a, t, i, o, n, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, u, l, e, s.

InsuranceRed

No insurance-sector-specific data protection rules were identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , i, n, s, u, r, a, n, c, e, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, u, l, e, s, , S, I, C.

Key findings (3)

  • Financial/credit-reporting overlay actively enforced; no other sectoral overlays confirmed. — source on file
  • Financial/credit-reporting overlay actively enforced; no other sectoral overlays confirmed. — source on file
  • Financial/credit-reporting overlay actively enforced; no other sectoral overlays confirmed. — source on file
Category narrative49 words

The clearest sectoral overlay is the financial/credit-reporting regime under Law 1266 of 2008 (habeas data financiero), enforced through fines such as those against Comfamiliar and Refinancia for publishing negative credit reports without prior authorization/communication. No health, telecoms/ePrivacy, employment-specific, education, or insurance sectoral overlays were confirmed in this research pass.

Sources and claims (2)
  1. ConfirmedDataGuidance — The SIC fined Comfamiliar for publishing a negative credit report without prior communication to the information owner, violating Articles 8(10) and 12 of Statutory Law 1266 of 2008.observed
  2. ConfirmedDataGuidance — The SIC upheld a fine against Refinancia for publishing a negative credit report without the necessary authorization of the information owner, in violation of Article 8(1) and 8(5) of Law 1266 of 2008.observed

#

Direct-marketing consent enforcement is confirmed; adtech-specific sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) show no comprehensive regime in sources reviewed.

Primary frameworkStatutory Law 1581 of 2012
Traffic-light rationale — AmberDirect-marketing consent enforcement is confirmed; adtech-specific sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) show no comprehensive regime in sources reviewed.

Sub-modules (6)

Direct MarketingGreen

SIC's highest fine to date (Comcel) addressed unauthorized data collection during a marketing campaign for lack of informed consent.

Claims (1):

  • The SIC imposed its highest fine to date (COP 1,306,289,600) on Comcel S.A. for failing to obtain informed consent from customers during the 'Friends who reward you' marketing campaign, violating Law 1581 of 2012.

Cookies And TrackersRed

No dedicated cookie/tracker consent regime was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , c, o, o, k, i, e, , c, o, n, s, e, n, t, , l, a, w, , S, I, C, , e, P, r, i, v, a, c, y, , e, q, u, i, v, a, l, e, n, t.

Dark PatternsRed

No dark-pattern-specific prohibition was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , d, a, r, k, , p, a, t, t, e, r, n, s, , p, r, o, h, i, b, i, t, i, o, n, , c, o, n, s, u, m, e, r, , d, a, t, a, , l, a, w.

Opt Out SignalsRed

No Global Privacy Control/DAA-equivalent opt-out-signal framework was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , o, p, t, -, o, u, t, , s, i, g, n, a, l, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , S, I, C.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules were identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , d, a, t, a, , c, l, e, a, n, , r, o, o, m, , r, u, l, e, s, , S, I, C.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context advertising regime was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , c, r, o, s, s, -, c, o, n, t, e, x, t, , a, d, v, e, r, t, i, s, i, n, g, , s, a, l, e, , s, h, a, r, e, , d, a, t, a, , l, a, w.

Key findings (3)

  • Direct-marketing consent enforcement (Comcel) confirmed; adtech-specific sub-regimes unconfirmed. — source on file
  • Direct-marketing consent enforcement (Comcel) confirmed; adtech-specific sub-regimes unconfirmed. — source on file
  • Direct-marketing consent enforcement (Comcel) confirmed; adtech-specific sub-regimes unconfirmed. — source on file
Category narrative41 words

Direct-marketing consent enforcement is confirmed via SIC's largest-to-date fine against Comcel for collecting personal data without informed consent during a marketing campaign. No cookie/tracker-specific consent regime, dark-pattern prohibition, opt-out-signal framework, clean-room rules, or cross-context-advertising ('sale'/'share') regime analogous to CPRA was identified.

Sources and claims (1)
  1. ConfirmedDataGuidance — The SIC imposed its highest fine to date (COP 1,306,289,600) on Comcel S.A. for failing to obtain informed consent from customers during the 'Friends who reward you' marketing campaign, violating Law 1581 of 2012.observed

#

Biometric classification is confirmed and in force; AI governance is at the proposed-legislation stage; profiling/ADM/genetic/surveillance sub-modules lack confirmed coverage.

Primary frameworkDecree 1377 of 2013 (biometric data); AI Bill (Congress, pending, as of research date)
Traffic-light rationale — AmberBiometric classification is confirmed and in force; AI governance is at the proposed-legislation stage; profiling/ADM/genetic/surveillance sub-modules lack confirmed coverage.

Sub-modules (6)

Biometric RegimeGreen

Biometric data is classified as sensitive personal data under Decree 1377.

Claims (1):

  • Decree 1377 introduced a new definition of sensitive data that includes biometric data.

Ai Risk AssessmentsAmber

An AI Bill submitted to Congress in May 2025 proposes a comprehensive ethical AI governance framework with extraterritorial application; it remains a proposal, not yet enacted.

Claims (2):

  • On 7 May 2025, Colombia's Ministry of Science, Technology and Innovation submitted an Artificial Intelligence Bill to Congress aiming to establish a comprehensive legal framework for the ethical development, use and governance of AI systems.
  • The AI Bill would apply extraterritorially to entities located abroad whose AI systems are used within Colombia.

Profiling RestrictionsRed

No dedicated statutory profiling-restriction provision was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , p, r, o, f, i, l, i, n, g, , r, e, s, t, r, i, c, t, i, o, n, s, , A, r, t, i, c, l, e, , 2, 2, , G, D, P, R, , e, q, u, i, v, a, l, e, n, t.

Automated Decision Making TransparencyRed

No specific ADM transparency/explanation right was identified distinct from the pending AI Bill.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , a, u, t, o, m, a, t, e, d, , d, e, c, i, s, i, o, n, -, m, a, k, i, n, g, , t, r, a, n, s, p, a, r, e, n, c, y, , r, i, g, h, t.

Genetic DataRed

No genetic-data-specific regime distinct from general sensitive-data rules was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , g, e, n, e, t, i, c, , d, a, t, a, , r, e, g, i, m, e, , S, I, C.

State Surveillance CarveoutsRed

No detailed state-surveillance carve-out framework beyond the general public-authority access constraints was identified in this pass.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , s, t, a, t, e, , s, u, r, v, e, i, l, l, a, n, c, e, , n, a, t, i, o, n, a, l, , s, e, c, u, r, i, t, y, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , c, a, r, v, e, -, o, u, t.

Key findings (3)

  • Biometric data confirmed sensitive; extraterritorial AI Bill pending before Congress. — source on file
  • Biometric data confirmed sensitive; extraterritorial AI Bill pending before Congress. — source on file
  • Biometric data confirmed sensitive; extraterritorial AI Bill pending before Congress. — source on file
Category narrative67 words

Biometric data is expressly classified as sensitive under Decree 1377. A comprehensive Artificial Intelligence Bill was submitted to Congress in May 2025 to establish an ethical AI governance framework (human oversight, transparency, explainability) with extraterritorial reach to foreign AI systems used in Colombia; as a bill, it is not yet binding law. No dedicated Art 22 GDPR-style ADM/profiling-restriction provision, genetic-data regime, or state-surveillance carve-out framework was confirmed.

Sources and claims (3)
  1. ConfirmedIAPP — Decree 1377 introduced a new definition of sensitive data that includes biometric data.observed
  2. ProbableDataGuidance — On 7 May 2025, Colombia's Ministry of Science, Technology and Innovation submitted an Artificial Intelligence Bill to Congress aiming to establish a comprehensive legal framework for the ethical development, use and governance of AI systems.observed
  3. ProbableDataGuidance — The AI Bill would apply extraterritorially to entities located abroad whose AI systems are used within Colombia.observed

#

Children's-data special-category treatment is confirmed; age-verification, minor-profiling-ban, education-setting and dependent-adult sub-modules lack confirmed coverage.

Primary frameworkDecree 1377 of 2013
Traffic-light rationale — AmberChildren's-data special-category treatment is confirmed; age-verification, minor-profiling-ban, education-setting and dependent-adult sub-modules lack confirmed coverage.

Sub-modules (5)

Minor Profiling BansRed

No explicit minor-specific profiling ban was identified beyond the general superior-interest principle.

Claims (1):

  • Under Decree 1377, personal data from children is considered together with sensitive data as a special category, and a specific provision requires the superior interest of the child to be taken into account when such data is collected.

Age VerificationRed

No dedicated statutory age-verification mechanism was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , a, g, e, , v, e, r, i, f, i, c, a, t, i, o, n, , m, e, c, h, a, n, i, s, m, , m, i, n, o, r, s, , d, a, t, a, , l, a, w.

Education SettingsRed

No education-settings-specific children's-data rules were identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , e, d, u, c, a, t, i, o, n, , s, e, t, t, i, n, g, s, , c, h, i, l, d, r, e, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, u, l, e, s.

Dependent AdultsRed

No dependent-adults (elderly/incapacitated) specific data protection provisions were identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , v, u, l, n, e, r, a, b, l, e, , p, e, r, s, o, n, s, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , p, r, o, v, i, s, i, o, n, s.

Key findings (3)

  • Children's-data special category confirmed; age-verification and dependent-adult protections unconfirmed. — source on file
  • Children's-data special category confirmed; age-verification and dependent-adult protections unconfirmed. — source on file
  • Children's-data special category confirmed; age-verification and dependent-adult protections unconfirmed. — source on file
Category narrative41 words

Colombian law treats children's personal data as a special category jointly with sensitive data, requiring consideration of the child's superior interest during collection. No distinct statutory age-verification mechanism, minor-specific profiling ban, education-settings rule, or dependent-adults provision was confirmed in sources reviewed.

Sources and claims (1)
  1. ConfirmedIAPP — Under Decree 1377, personal data from children is considered together with sensitive data as a special category, and a specific provision requires the superior interest of the child to be taken into account when such data is collected.observed

#

Regulator powers and enforcement activity are well evidenced with recent (2025-2026) enforcement and rulemaking; collective-redress, private-right-of-action, and regulator-capacity sub-modules lack confirmed coverage.

Primary frameworkStatutory Law 1581 of 2012
Traffic-light rationale — GreenRegulator powers and enforcement activity are well evidenced with recent (2025-2026) enforcement and rulemaking; collective-redress, private-right-of-action, and regulator-capacity sub-modules lack confirmed coverage.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

SIC fines can reach up to 2,000 legal monthly minimum wages in force at the time of sanction.

Claims (1):

  • Under Law 1581, the fine for breach of data-transfer or data-protection obligations could be equivalent to 2,000 legal monthly minimum wages in force at the time of sanction, a significant penalty in Colombia.

Enforcement Activity IndexGreen

Recent enforcement includes the August 2025 Risks International fine and the historically largest Comcel fine, reflecting active SIC sanctioning practice.

Claims (2):

  • On 6 August 2025, the SIC announced a fine of COP 190 million (approx. $47,460) against Risks International S.A.S. for violating Law 1581 of 2012 by managing a database of sensitive personal data without consent.
  • On 6 July 2023, the SIC imposed its highest fine to date, COP 1,306,289,600 (approx. $309,072), on Comcel S.A. for unlawful collection of personal data.

Recent Developments 180DGreen

SIC issued Circular Externa No. 003 of 2025 on Model Contractual Clauses effective 19 December 2025, within the 180-day look-back window from the research date.

Claims (1):

  • On 19 December 2025, the SIC issued Circular Externa No. 003 of 2025 introducing Model Contractual Clauses for international data transfers, adding a new instrument to Colombia's cross-border transfer framework.

Collective Redress And Class ActionsRed

No dedicated collective-redress or class-action mechanism specific to data protection was identified.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , c, l, a, s, s, , a, c, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , c, o, l, l, e, c, t, i, v, e, , r, e, d, r, e, s, s, , m, e, c, h, a, n, i, s, m.

Private Right Of ActionAmber

Beyond the constitutional habeas data judicial remedy, no distinct statutory private right of action for data protection breaches was confirmed.

Absence provenance: unavailable. Searched: C, o, l, o, m, b, i, a, , p, r, i, v, a, t, e, , r, i, g, h, t, , o, f, , a, c, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, t, a, t, u, t, e.

Regulator Funding And CapacityRed

No SIC funding or headcount data was located in this research pass.

Absence provenance: unavailable. Searched: S, I, C, , C, o, l, o, m, b, i, a, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , d, i, v, i, s, i, o, n, , b, u, d, g, e, t, , h, e, a, d, c, o, u, n, t, , f, u, n, d, i, n, g.

Key findings (3)

  • Active 2025 enforcement and new MCC rulemaking; collective-redress/private-right-of-action/funding unconfirmed. — source on file
  • Active 2025 enforcement and new MCC rulemaking; collective-redress/private-right-of-action/funding unconfirmed. — source on file
  • Active 2025 enforcement and new MCC rulemaking; collective-redress/private-right-of-action/funding unconfirmed. — source on file
Category narrative103 words

The SIC's sanctioning power under Law 1581 allows fines of up to 2,000 legal monthly minimum wages, a significant penalty by Colombian standards. Enforcement activity in the trailing 12 months includes the August 2025 fine against Risks International S.A.S. (COP 190 million) for processing sensitive data without consent, alongside the historically largest fine against Comcel S.A. Recent developments (within 180 days) include SIC's Circular Externa No. 003 of 2025 on Model Contractual Clauses (19 December 2025). No dedicated collective-redress/class-action mechanism or explicit private right of action distinct from the habeas data judicial remedy, and no regulator funding/headcount data, were confirmed in sources reviewed.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedIAPP — Under Law 1581, the fine for breach of data-transfer or data-protection obligations could be equivalent to 2,000 legal monthly minimum wages in force at the time of sanction, a significant penalty in Colombia.observed
  2. ConfirmedDataGuidance — On 6 August 2025, the SIC announced a fine of COP 190 million (approx. $47,460) against Risks International S.A.S. for violating Law 1581 of 2012 by managing a database of sensitive personal data without consent.observed
  3. ConfirmedDataGuidance — On 6 July 2023, the SIC imposed its highest fine to date, COP 1,306,289,600 (approx. $309,072), on Comcel S.A. for unlawful collection of personal data.observed
  4. ConfirmedIAPP — On 19 December 2025, the SIC issued Circular Externa No. 003 of 2025 introducing Model Contractual Clauses for international data transfers, adding a new instrument to Colombia's cross-border transfer framework.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct15.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Colombia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 34 claim(s) (35 category placement(s)), 20 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator/framework, lawful-processing core rules, data-subject core rights (access/rectification/erasure), controller/processor accountability-security-breach-retention duties, cross-border transfer mechanisms and SIC-granted adequacy, financial-sector/credit-reporting overlay, direct-marketing enforcement, biometric classification, children's-data special category, and enforcement powers/recent activity all rest on T2/T3 secondary sources (IAPP, DataGuidance) reporting or analyzing primary SIC/statutory instruments — no direct T1 statutory-text retrieval was performed in this pass, so these are treated as T3-grounded with high confidence given source convergence. Genuinely thin coverage (T4/absent, relying on absent_field_provenance) applies to: pseudonymisation/anonymisation definitions, data portability, restriction/objection rights distinct from rectification, joint-controller arrangements, data localisation, health/telecoms/employment/education/insurance sectoral overlays, cookies/dark-patterns/opt-out-signals/clean-rooms/cross-context-advertising, profiling restrictions/ADM transparency/genetic data/state-surveillance carve-outs distinct from the pending AI Bill, age verification/education-settings/dependent-adults protections, and collective-redress/private-right-of-action/regulator-funding specifics.

Unresolved questions (6):

  • Current legislative status of the combined bill amending Colombia's data protection law (House Committee approval reported October 2025) — full provisions and passage status not confirmed.
  • Whether the 2018-reported draft bill granting SIC extraterritorial investigative jurisdiction over foreign-headquartered controllers (e.g., Facebook, Google) was ever enacted.
  • Final enactment status of the 2017 draft regulation on accountability-based transfer risk assessment (transfer impact assessment analogue).
  • Whether Colombia's EU adequacy process has been formally resumed, abandoned, or remains dormant as of 2026.
  • Whether a distinct data-portability right or GDPR Art 22-style ADM/profiling restriction exists in Colombian law or subordinate SIC guidance not captured by secondary sources reviewed.
  • Current status and final text of the Colombian AI Bill (introduced May 2025) — whether enacted, amended, or still pending as of the research date.

Escalate to primary-source review: yes