{
 "jurisdiction_id": "CO",
 "jurisdiction": "Colombia",
 "url": "https://dataprotection.gi/jurisdictions/colombia/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 35,
  "sub_modules": 57,
  "source_register": 16
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/colombia/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive statutory framework in force with an active, sanctioning regulator and constitutional backstop.",
   "claims": [
    {
     "statement": "Although the SIC is integrated within the structure of the Ministry of Industry, Trade and Tourism, Law 1581 provides it with the power to impose sanctions and other powers necessary for compliance with the law's objectives.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/obtaining-adequacy-standing-for-colombia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Colombia has two data protection statutes — Law 1266 of 2008 (credit reporting) and Law 1581 of 2012 (general personal data protection) — which together constitute a common legal regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/obtaining-adequacy-standing-for-colombia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Colombian Constitution provides a special judicial remedy for data protection known as 'habeas data,' a fundamental and directly applicable right before any judge.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/obtaining-adequacy-standing-for-colombia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of 2018 reporting, a draft bill existed to give the SIC power to investigate companies headquartered outside Colombia (e.g., Facebook, Google), though current passage status is unconfirmed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://corporate.dataguidance.com/colombia-database-registration-amendments-put-end-complex-expensive-obligations-smes/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Natural persons and SMEs are exempt from RNBD registration, while public legal entities and companies/non-profits with assets above 100,000 UVT must register their databases within established deadlines.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://corporate.dataguidance.com/colombia-database-registration-amendments-put-end-complex-expensive-obligations-smes/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/colombia/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core consent/special-category rules are well documented; pseudonymisation/anonymisation standards are not clearly codified.",
   "claims": [
    {
     "statement": "Article 17 of Law 1581 lists data controller responsibilities including the requirement to adopt an internal manual of policies and procedures to ensure proper compliance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-is-a-data-protection-officer-required-for-compliance",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Public data — data that is not sensitive, private, or semiprivate, such as data from public registries, official bulletins or judicial decisions — does not require data-subject authorization under the Data Protection Law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-enacts-the-regulation-of-the-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Decree 1377 introduced a new definition of sensitive data that includes biometric data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-enacts-the-regulation-of-the-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Children's personal data is treated together with sensitive data as a special category, with a specific provision that the superior interest of the child be considered when such data is collected.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-enacts-the-regulation-of-the-data-protection-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/colombia/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core access/rectification/erasure rights are confirmed; response-window specifics and portability are not clearly codified in the sources reviewed.",
   "claims": [
    {
     "statement": "Law 1581 contains provisions relating to the rights of data subjects, such as access, rectification, update and deletion, and the corresponding obligations of controllers and processors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/obtaining-adequacy-standing-for-colombia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 27 of Decree 1377/2013 requires the adoption of a process for addressing and responding to queries, requests and claims by data subjects regarding any aspect of treatment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-is-a-data-protection-officer-required-for-compliance",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/colombia/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Accountability, security, breach-notification and retention duties are well evidenced through statute, decree and enforcement action; joint-controller-specific rules are less clearly codified.",
   "claims": [
    {
     "statement": "At the SIC's request, data controllers must prove appropriate and effective compliance proportionate to (1) legal nature/size of the controller, (2) nature of the data, (3) type of processing, and (4) potential risks to data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-is-a-data-protection-officer-required-for-compliance",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Decree 1377 requires a person or group within each controller/processor to be in charge of the data-protection compliance program, without mandating a formally titled Data Protection Officer.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-is-a-data-protection-officer-required-for-compliance",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The SIC ordered Uber to develop, implement and maintain a comprehensive security program addressing risks of unauthorized access and protecting confidentiality/integrity of personal data, with independent third-party audits for five years.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-dpa-order-uber-to-improve-security-measures-for-personal-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 1581 makes companies responsible for users' personal data in their custody and requires implementation of policies and practices giving effect to Colombian data-protection principles.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-dpa-order-uber-to-improve-security-measures-for-personal-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Security incidents must be reported to the SIC's National Database Registry within 15 working days from the moment they are detected and brought to the attention of the responsible person or area.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/colombia-framework-incident-notification",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Because the general personal-data regime makes no distinction based on impact, the RNBD reporting procedure must be activated for all security incidents in personal data processing, regardless of severity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/colombia-framework-incident-notification",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Personal data should be preserved according to the purpose of its collection and later erased unless a legal or contractual duty to preserve it exists.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-enacts-the-regulation-of-the-data-protection-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/colombia/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms and SIC-granted adequacy are well documented; EU-adequacy status is unresolved/stalled and data-localisation rules were not identified.",
   "claims": [
    {
     "statement": "Under Colombia's framework, cross-border personal data transfers require either an SIC adequacy decision, a statutory exception under Article 26(2) of Law 1581, an SIC statement on a specific transfer operation, or the use of binding corporate rules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombian-draft-regulation-introduces-accountability-principle-to-data-transfers",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EU internal documentation notes that the adequacy decision process for Colombia (along with Mexico) has stalled, notwithstanding Colombia's stated interest in the EU adequacy process.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2023-12/es_sa_gdpr_art-97questionnaire.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The SIC has declared adequacy standing under Law 1581 to third countries including Australia, Costa Rica, the United States, Mexico, Peru, Serbia and South Korea.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/obtaining-adequacy-standing-for-colombia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 19 December 2025 the SIC issued Circular Externa No. 003 of 2025, introducing Model Contractual Clauses for international transfers and transmissions of personal data with detailed instructions for use.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-introduces-new-model-contractual-clauses",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Adoption of the Circular 003/2025 Model Contractual Clauses is facultative, but once a controller/processor adopts them, compliance with their obligations becomes binding and enforceable by the SIC as an instruction under Law 1581.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-introduces-new-model-contractual-clauses",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A draft regulation proposed that, under the accountability principle, exporters demonstrate the data importer has adopted breach and security policies as a condition for recognizing a transfer's adequacy.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombian-draft-regulation-introduces-accountability-principle-to-data-transfers",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/colombia/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial/credit-reporting overlay is well evidenced; other sectoral overlays are not confirmed in sources reviewed.",
   "claims": [
    {
     "statement": "The SIC fined Comfamiliar for publishing a negative credit report without prior communication to the information owner, violating Articles 8(10) and 12 of Statutory Law 1266 of 2008.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colombia-sic-upholds-decision-fine-comfamiliar",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The SIC upheld a fine against Refinancia for publishing a negative credit report without the necessary authorization of the information owner, in violation of Article 8(1) and 8(5) of Law 1266 of 2008.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colombia-sic-upholds-resolutions-requiring-company-0",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/colombia/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Direct-marketing consent enforcement is confirmed; adtech-specific sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) show no comprehensive regime in sources reviewed.",
   "claims": [
    {
     "statement": "The SIC imposed its highest fine to date (COP 1,306,289,600) on Comcel S.A. for failing to obtain informed consent from customers during the 'Friends who reward you' marketing campaign, violating Law 1581 of 2012.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colombia-sic-imposes-highest-fine-date-comcel-unlawful",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/colombia/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric classification is confirmed and in force; AI governance is at the proposed-legislation stage; profiling/ADM/genetic/surveillance sub-modules lack confirmed coverage.",
   "claims": [
    {
     "statement": "Decree 1377 introduced a new definition of sensitive data that includes biometric data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-enacts-the-regulation-of-the-data-protection-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 7 May 2025, Colombia's Ministry of Science, Technology and Innovation submitted an Artificial Intelligence Bill to Congress aiming to establish a comprehensive legal framework for the ethical development, use and governance of AI systems.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colombia-bill-regulate-ai-introduced-congress",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The AI Bill would apply extraterritorially to entities located abroad whose AI systems are used within Colombia.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colombia-bill-regulate-ai-introduced-congress",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/colombia/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Children's-data special-category treatment is confirmed; age-verification, minor-profiling-ban, education-setting and dependent-adult sub-modules lack confirmed coverage.",
   "claims": [
    {
     "statement": "Under Decree 1377, personal data from children is considered together with sensitive data as a special category, and a specific provision requires the superior interest of the child to be taken into account when such data is collected.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-enacts-the-regulation-of-the-data-protection-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/colombia/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Regulator powers and enforcement activity are well evidenced with recent (2025-2026) enforcement and rulemaking; collective-redress, private-right-of-action, and regulator-capacity sub-modules lack confirmed coverage.",
   "claims": [
    {
     "statement": "Under Law 1581, the fine for breach of data-transfer or data-protection obligations could be equivalent to 2,000 legal monthly minimum wages in force at the time of sanction, a significant penalty in Colombia.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/obtaining-adequacy-standing-for-colombia",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 6 August 2025, the SIC announced a fine of COP 190 million (approx. $47,460) against Risks International S.A.S. for violating Law 1581 of 2012 by managing a database of sensitive personal data without consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colombia-sic-fines-risks-international-sas-cop-190",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 6 July 2023, the SIC imposed its highest fine to date, COP 1,306,289,600 (approx. $309,072), on Comcel S.A. for unlawful collection of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/colombia-sic-imposes-highest-fine-date-comcel-unlawful",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 19 December 2025, the SIC issued Circular Externa No. 003 of 2025 introducing Model Contractual Clauses for international data transfers, adding a new instrument to Colombia's cross-border transfer framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/colombia-introduces-new-model-contractual-clauses",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}