🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CO · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 16 sources retrieved model claude-sonnet-5 ·

Colombia

CO schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 35 claims · 16 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
35Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statutory framework in force with an active, sanctioning regulator and constitutional backstop.

Primary frameworkStatutory Law 1581 of 2012 (Data Protection Law), supplemented by Decree 1377 of 2013 and Statutory Law 1266 of 2008 (credit reporting habeas data)
Traffic-light rationale — GreenComprehensive statutory framework in force with an active, sanctioning regulator and constitutional backstop.

Sub-modules (5)

Regulator And AuthorityGreen

SIC is institutionally housed within the Ministry of Industry, Trade and Tourism yet Law 1581 vests it with independent sanctioning and inspection powers.

Claims: CLM-CO-a1b2c3d4

Act And InstrumentsGreen

Two parallel statutes (1266/2008 and 1581/2012) form a common legal regime for personal data protection.

Claims: CLM-CO-b2c3d4e5

Material ScopeGreen

The constitutional habeas data action operates as a directly enforceable fundamental right independent of statutory processes.

Claims: CLM-CO-c3d4e5f6

Territorial ScopeAmber

Historical reporting (2018) indicated a draft bill to extend SIC's investigative jurisdiction over foreign-headquartered controllers; current legislative status of that specific proposal could not be confirmed in this research pass.

Claims: CLM-CO-d4e5f6a7

Regulator Registration And FilingGreen

Controllers/processors above defined asset thresholds must register databases in the National Database Registry (RNBD); SMEs and natural persons are exempted since Decree 90/2018.

Claims: CLM-CO-e5f6a7b8

Category narrative69 words

Colombia operates a dual-statute omnibus regime: Statutory Law 1581 of 2012 (general personal data protection) and Statutory Law 1266 of 2008 (habeas data financiero / credit reporting), both enforced by the Superintendencia de Industria y Comercio (SIC), which sits administratively inside the Ministry of Industry, Trade and Tourism but holds independent sanctioning powers. The constitutional 'habeas data' remedy provides a directly judicially enforceable data-protection right supplementing the statutory regime.

Sources and claims (5)
  1. ConfirmedIAPPAlthough the SIC is integrated within the structure of the Ministry of Industry, Trade and Tourism, Law 1581 provides it with the power to impose sanctions and other powers necessary for compliance with the law's objectives.
  2. ConfirmedIAPPColombia has two data protection statutes — Law 1266 of 2008 (credit reporting) and Law 1581 of 2012 (general personal data protection) — which together constitute a common legal regime.
  3. ConfirmedIAPPThe Colombian Constitution provides a special judicial remedy for data protection known as 'habeas data,' a fundamental and directly applicable right before any judge.
  4. UncertainDataGuidanceAs of 2018 reporting, a draft bill existed to give the SIC power to investigate companies headquartered outside Colombia (e.g., Facebook, Google), though current passage status is unconfirmed.
  5. ConfirmedDataGuidanceNatural persons and SMEs are exempt from RNBD registration, while public legal entities and companies/non-profits with assets above 100,000 UVT must register their databases within established deadlines.

#

Core consent/special-category rules are well documented; pseudonymisation/anonymisation standards are not clearly codified.

Primary frameworkStatutory Law 1581 of 2012; Decree 1377 of 2013
Traffic-light rationale — AmberCore consent/special-category rules are well documented; pseudonymisation/anonymisation standards are not clearly codified.

Sub-modules (4)

Lawful BasesGreen

Article 17 of Law 1581 requires controllers to adopt an internal manual of policies and procedures as the operative accountability/legal-basis documentation mechanism.

Claims: CLM-CO-f6a7b8c9

Special CategoriesGreen

Decree 1377 introduced biometric data into the sensitive-data definition, and children's data is treated jointly with sensitive data as a special category requiring the child's superior interest to be considered.

Claims: CLM-CO-b8c9d0e1, CLM-CO-c9d0e1f2

Pseudonymisation And AnonymisationRed

No dedicated statutory pseudonymisation/anonymisation safe-harbour definition was located in the sources reviewed.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , L, a, w, , 1, 5, 8, 1, , p, s, e, u, d, o, n, y, m, i, s, a, t, i, o, n, , a, n, o, n, y, m, i, s, a, t, i, o, n, , d, e, f, i, n, i, t, i, o, n, , S, I, C, , g, u, i, d, a, n, c, e.

Category narrative46 words

Law 1581 and its implementing Decree 1377 establish authorization (consent) as the default lawful basis, with an express carve-out for 'public data,' and elevate biometric and children's data to sensitive-category treatment. No pseudonymisation/anonymisation safe-harbour framework analogous to GDPR Art 4(5) was identified in this research pass.

Sources and claims (4)
  1. ConfirmedIAPPArticle 17 of Law 1581 lists data controller responsibilities including the requirement to adopt an internal manual of policies and procedures to ensure proper compliance.
  2. ConfirmedIAPPPublic data — data that is not sensitive, private, or semiprivate, such as data from public registries, official bulletins or judicial decisions — does not require data-subject authorization under the Data Protection Law.
  3. ConfirmedIAPPDecree 1377 introduced a new definition of sensitive data that includes biometric data.
  4. ConfirmedIAPPChildren's personal data is treated together with sensitive data as a special category, with a specific provision that the superior interest of the child be considered when such data is collected.

#

Core access/rectification/erasure rights are confirmed; response-window specifics and portability are not clearly codified in the sources reviewed.

Primary frameworkStatutory Law 1581 of 2012; Decree 1377 of 2013
Traffic-light rationale — AmberCore access/rectification/erasure rights are confirmed; response-window specifics and portability are not clearly codified in the sources reviewed.

Sub-modules (5)

Access RightGreen

Law 1581 provides for access rights for data subjects.

Claims: CLM-CO-d0e1f2a3

Rectification And ErasureGreen

Rectification, update and deletion rights are provided alongside access.

Claims: CLM-CO-d0e1f2a3

Restriction And ObjectionRed

No dedicated restriction-of-processing or objection right distinct from rectification/erasure was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , L, a, w, , 1, 5, 8, 1, , r, i, g, h, t, , t, o, , o, b, j, e, c, t, , r, e, s, t, r, i, c, t, i, o, n, , o, f, , p, r, o, c, e, s, s, i, n, g.

Data PortabilityRed

No express statutory data-portability right was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , L, a, w, , 1, 5, 8, 1, , d, a, t, a, , p, o, r, t, a, b, i, l, i, t, y, , r, i, g, h, t.

Deadlines And Response WindowsAmber

Decree 1377 Article 27 requires controllers to adopt a process for addressing and responding to data-subject queries, requests and claims, though a specific statutory day-count deadline was not confirmed in sources reviewed.

Claims: CLM-CO-e1f2a3b4

Category narrative45 words

Law 1581 enumerates access, rectification, update and deletion rights, and Decree 1377 requires controllers to maintain a process for responding to data-subject queries and claims. No explicit statutory deadline analogous to GDPR's 30-day window, nor a distinct data-portability right, was confirmed in the sources reviewed.

Sources and claims (2)
  1. ConfirmedIAPPLaw 1581 contains provisions relating to the rights of data subjects, such as access, rectification, update and deletion, and the corresponding obligations of controllers and processors.
  2. ProbableIAPPArticle 27 of Decree 1377/2013 requires the adoption of a process for addressing and responding to queries, requests and claims by data subjects regarding any aspect of treatment.

#

Accountability, security, breach-notification and retention duties are well evidenced through statute, decree and enforcement action; joint-controller-specific rules are less clearly codified.

Primary frameworkStatutory Law 1581 of 2012; Decree 1377 of 2013
Traffic-light rationale — GreenAccountability, security, breach-notification and retention duties are well evidenced through statute, decree and enforcement action; joint-controller-specific rules are less clearly codified.

Sub-modules (7)

Accountability And DpiaGreen

Compliance must be proportionate to controller size/nature, data sensitivity, processing type and risk to data subjects (Decree 1377 Art 26).

Claims: CLM-CO-f2a3b4c5

Dpo RequirementsAmber

No named 'Data Protection Officer' title is mandated; instead a responsible person or group must be designated.

Claims: CLM-CO-a3b4c5d6

Ropa RequirementsGreen

RNBD registration operates as the functional equivalent of a records-of-processing obligation for qualifying entities.

Claims: CLM-CO-e5f6a7b8

Joint Controller ArrangementsRed

No specific joint-controller allocation-of-liability framework distinct from general controller/processor duties was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , L, a, w, , 1, 5, 8, 1, , j, o, i, n, t, , c, o, n, t, r, o, l, l, e, r, , l, i, a, b, i, l, i, t, y, , f, r, a, m, e, w, o, r, k.

Security MeasuresGreen

SIC has ordered comprehensive technical/organisational security programs (e.g., Uber order) grounded in the Law 1581 responsibility principle.

Claims: CLM-CO-b4c5d6e7, CLM-CO-c5d6e7f8

Breach NotificationGreen

Security incidents must be reported to the SIC's National Database Registry (RNBD) within 15 working days of detection, with no risk-based reporting threshold.

Claims: CLM-CO-d6e7f8a9, CLM-CO-e7f8a9b0

Retention And DisposalGreen

Data must be retained only for the purpose of collection and erased thereafter absent a legal or contractual retention duty.

Claims: CLM-CO-f8a9b0c1

Category narrative65 words

Colombia's accountability regime (Decree 1377, Arts 13/23/26/27) requires proportionate compliance programs, a responsible person/group in lieu of a formally titled DPO, RNBD registration functioning as a de-facto processing registry, security-of-processing obligations enforced through orders such as the Uber security-program mandate, a 15-working-day breach-notification duty to the RNBD for all incidents regardless of assessed impact, and purpose-limited retention with erasure absent a legal/contractual duty to retain.

Sources and claims (7)
  1. ConfirmedIAPPAt the SIC's request, data controllers must prove appropriate and effective compliance proportionate to (1) legal nature/size of the controller, (2) nature of the data, (3) type of processing, and (4) potential risks to data subjects.
  2. ConfirmedIAPPDecree 1377 requires a person or group within each controller/processor to be in charge of the data-protection compliance program, without mandating a formally titled Data Protection Officer.
  3. ConfirmedIAPPThe SIC ordered Uber to develop, implement and maintain a comprehensive security program addressing risks of unauthorized access and protecting confidentiality/integrity of personal data, with independent third-party audits for five years.
  4. ConfirmedIAPPLaw 1581 makes companies responsible for users' personal data in their custody and requires implementation of policies and practices giving effect to Colombian data-protection principles.
  5. ConfirmedDataGuidanceSecurity incidents must be reported to the SIC's National Database Registry within 15 working days from the moment they are detected and brought to the attention of the responsible person or area.
  6. ConfirmedDataGuidanceBecause the general personal-data regime makes no distinction based on impact, the RNBD reporting procedure must be activated for all security incidents in personal data processing, regardless of severity.
  7. ConfirmedIAPPPersonal data should be preserved according to the purpose of its collection and later erased unless a legal or contractual duty to preserve it exists.

#

Transfer mechanisms and SIC-granted adequacy are well documented; EU-adequacy status is unresolved/stalled and data-localisation rules were not identified.

Primary frameworkStatutory Law 1581 of 2012, Article 26; Circular Externa No. 003 of 2025
Traffic-light rationale — AmberTransfer mechanisms and SIC-granted adequacy are well documented; EU-adequacy status is unresolved/stalled and data-localisation rules were not identified.

Sub-modules (6)

Transfer MechanismsGreen

Four mechanisms exist: SIC adequacy decision, statutory exception under Art 26(2), an authority statement on a specific transfer, or binding corporate rules.

Claims: CLM-CO-a9b0c1d2

Adequacy ReceivedRed

Colombia has not received an EU Commission adequacy decision; EU internal materials describe the Colombia adequacy process as stalled despite Colombia's expressed interest.

Claims: CLM-CO-b0c1d2e3

Adequacy GrantedGreen

The SIC has declared adequacy standing under Law 1581 to Australia, Costa Rica, the United States, Mexico, Peru, Serbia and South Korea.

Claims: CLM-CO-c1d2e3f4

Sccs And BcrsGreen

Circular Externa 003/2025 (effective 19 Dec 2025) introduces voluntary Model Contractual Clauses for international transfers/transmissions; once adopted, compliance with the clauses becomes mandatory and enforceable by the SIC.

Claims: CLM-CO-d2e3f4a5, CLM-CO-e3f4a5b6

Transfer Impact AssessmentAmber

A 2017 draft regulation proposed an accountability-based risk assessment requiring exporters to evaluate importer safeguards; confirmation of its final enactment status was not obtained in this pass.

Claims: CLM-CO-f4a5b6c7

Data LocalisationRed

No general data-localisation mandate was identified in the sources reviewed.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , d, a, t, a, , l, o, c, a, l, i, s, a, t, i, o, n, , m, a, n, d, a, t, e, , p, e, r, s, o, n, a, l, , d, a, t, a, , S, I, C.

Category narrative108 words

Colombia treats every non-Colombian jurisdiction as a 'third country' and requires an adequate level of protection for outbound transfers, achievable via SIC adequacy decisions, statutory exceptions, authority statements on specific transfer operations, or binding corporate rules. The SIC has itself granted adequacy standing to several third countries (Australia, Costa Rica, US, Mexico, Peru, Serbia, South Korea). Colombia has expressed interest in obtaining EU adequacy but has not received an EU Commission adequacy decision, with EU internal materials describing the process as stalled. In December 2025 the SIC issued Circular Externa 003/2025 introducing voluntary (but, once adopted, binding) Model Contractual Clauses based on the Ibero-American Data Protection Network model.

Sources and claims (6)
  1. ConfirmedIAPPUnder Colombia's framework, cross-border personal data transfers require either an SIC adequacy decision, a statutory exception under Article 26(2) of Law 1581, an SIC statement on a specific transfer operation, or the use of binding corporate rules.
  2. UncertainEDPBEU internal documentation notes that the adequacy decision process for Colombia (along with Mexico) has stalled, notwithstanding Colombia's stated interest in the EU adequacy process.
  3. ConfirmedIAPPThe SIC has declared adequacy standing under Law 1581 to third countries including Australia, Costa Rica, the United States, Mexico, Peru, Serbia and South Korea.
  4. ConfirmedIAPPOn 19 December 2025 the SIC issued Circular Externa No. 003 of 2025, introducing Model Contractual Clauses for international transfers and transmissions of personal data with detailed instructions for use.
  5. ConfirmedIAPPAdoption of the Circular 003/2025 Model Contractual Clauses is facultative, but once a controller/processor adopts them, compliance with their obligations becomes binding and enforceable by the SIC as an instruction under Law 1581.
  6. UncertainIAPPA draft regulation proposed that, under the accountability principle, exporters demonstrate the data importer has adopted breach and security policies as a condition for recognizing a transfer's adequacy.

#

Financial/credit-reporting overlay is well evidenced; other sectoral overlays are not confirmed in sources reviewed.

Primary frameworkStatutory Law 1266 of 2008 (habeas data financiero)
Traffic-light rationale — AmberFinancial/credit-reporting overlay is well evidenced; other sectoral overlays are not confirmed in sources reviewed.

Sub-modules (7)

Financial Sector OverlayGreen

Law 1266/2008 governs financial, credit, commercial and services-related personal data (habeas data financiero), enforced separately from Law 1581.

Claims: CLM-CO-a5b6c7d8

Credit And ScoringGreen

SIC enforcement confirms obligations to notify individuals before generating negative credit reports.

Claims: CLM-CO-b6c7d8e9

Health Sector OverlayRed

No health-sector-specific data protection overlay was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , h, e, a, l, t, h, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , o, v, e, r, l, a, y, , H, I, P, A, A, -, e, q, u, i, v, a, l, e, n, t.

Telecoms And EprivacyRed

No telecoms/ePrivacy-specific cookie or communications-data overlay was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , t, e, l, e, c, o, m, s, , e, p, r, i, v, a, c, y, , c, o, o, k, i, e, s, , c, o, m, m, u, n, i, c, a, t, i, o, n, s, , d, a, t, a, , l, a, w.

Employment DataRed

No employment-specific data protection code was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , e, m, p, l, o, y, m, e, n, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , c, o, d, e, , S, I, C, , g, u, i, d, a, n, c, e.

EducationRed

No education-sector-specific data protection rules were identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , e, d, u, c, a, t, i, o, n, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, u, l, e, s.

InsuranceRed

No insurance-sector-specific data protection rules were identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , i, n, s, u, r, a, n, c, e, , s, e, c, t, o, r, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, u, l, e, s, , S, I, C.

Category narrative49 words

The clearest sectoral overlay is the financial/credit-reporting regime under Law 1266 of 2008 (habeas data financiero), enforced through fines such as those against Comfamiliar and Refinancia for publishing negative credit reports without prior authorization/communication. No health, telecoms/ePrivacy, employment-specific, education, or insurance sectoral overlays were confirmed in this research pass.

Sources and claims (2)
  1. ConfirmedDataGuidanceThe SIC fined Comfamiliar for publishing a negative credit report without prior communication to the information owner, violating Articles 8(10) and 12 of Statutory Law 1266 of 2008.
  2. ConfirmedDataGuidanceThe SIC upheld a fine against Refinancia for publishing a negative credit report without the necessary authorization of the information owner, in violation of Article 8(1) and 8(5) of Law 1266 of 2008.

#

Direct-marketing consent enforcement is confirmed; adtech-specific sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) show no comprehensive regime in sources reviewed.

Primary frameworkStatutory Law 1581 of 2012
Traffic-light rationale — AmberDirect-marketing consent enforcement is confirmed; adtech-specific sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) show no comprehensive regime in sources reviewed.

Sub-modules (6)

Direct MarketingGreen

SIC's highest fine to date (Comcel) addressed unauthorized data collection during a marketing campaign for lack of informed consent.

Claims: CLM-CO-c7d8e9f0

Cookies And TrackersRed

No dedicated cookie/tracker consent regime was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , c, o, o, k, i, e, , c, o, n, s, e, n, t, , l, a, w, , S, I, C, , e, P, r, i, v, a, c, y, , e, q, u, i, v, a, l, e, n, t.

Dark PatternsRed

No dark-pattern-specific prohibition was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , d, a, r, k, , p, a, t, t, e, r, n, s, , p, r, o, h, i, b, i, t, i, o, n, , c, o, n, s, u, m, e, r, , d, a, t, a, , l, a, w.

Opt Out SignalsRed

No Global Privacy Control/DAA-equivalent opt-out-signal framework was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , o, p, t, -, o, u, t, , s, i, g, n, a, l, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , S, I, C.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules were identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , d, a, t, a, , c, l, e, a, n, , r, o, o, m, , r, u, l, e, s, , S, I, C.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context advertising regime was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , c, r, o, s, s, -, c, o, n, t, e, x, t, , a, d, v, e, r, t, i, s, i, n, g, , s, a, l, e, , s, h, a, r, e, , d, a, t, a, , l, a, w.

Category narrative41 words

Direct-marketing consent enforcement is confirmed via SIC's largest-to-date fine against Comcel for collecting personal data without informed consent during a marketing campaign. No cookie/tracker-specific consent regime, dark-pattern prohibition, opt-out-signal framework, clean-room rules, or cross-context-advertising ('sale'/'share') regime analogous to CPRA was identified.

Sources and claims (1)
  1. ConfirmedDataGuidanceThe SIC imposed its highest fine to date (COP 1,306,289,600) on Comcel S.A. for failing to obtain informed consent from customers during the 'Friends who reward you' marketing campaign, violating Law 1581 of 2012.

#

Biometric classification is confirmed and in force; AI governance is at the proposed-legislation stage; profiling/ADM/genetic/surveillance sub-modules lack confirmed coverage.

Primary frameworkDecree 1377 of 2013 (biometric data); AI Bill (Congress, pending, as of research date)
Traffic-light rationale — AmberBiometric classification is confirmed and in force; AI governance is at the proposed-legislation stage; profiling/ADM/genetic/surveillance sub-modules lack confirmed coverage.

Sub-modules (6)

Biometric RegimeGreen

Biometric data is classified as sensitive personal data under Decree 1377.

Claims: CLM-CO-d8e9f0a1

Ai Risk AssessmentsAmber

An AI Bill submitted to Congress in May 2025 proposes a comprehensive ethical AI governance framework with extraterritorial application; it remains a proposal, not yet enacted.

Claims: CLM-CO-e9f0a1b2, CLM-CO-f0a1b2c3

Profiling RestrictionsRed

No dedicated statutory profiling-restriction provision was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , p, r, o, f, i, l, i, n, g, , r, e, s, t, r, i, c, t, i, o, n, s, , A, r, t, i, c, l, e, , 2, 2, , G, D, P, R, , e, q, u, i, v, a, l, e, n, t.

Automated Decision Making TransparencyRed

No specific ADM transparency/explanation right was identified distinct from the pending AI Bill.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , a, u, t, o, m, a, t, e, d, , d, e, c, i, s, i, o, n, -, m, a, k, i, n, g, , t, r, a, n, s, p, a, r, e, n, c, y, , r, i, g, h, t.

Genetic DataRed

No genetic-data-specific regime distinct from general sensitive-data rules was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , g, e, n, e, t, i, c, , d, a, t, a, , r, e, g, i, m, e, , S, I, C.

State Surveillance CarveoutsRed

No detailed state-surveillance carve-out framework beyond the general public-authority access constraints was identified in this pass.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , s, t, a, t, e, , s, u, r, v, e, i, l, l, a, n, c, e, , n, a, t, i, o, n, a, l, , s, e, c, u, r, i, t, y, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , c, a, r, v, e, -, o, u, t.

Category narrative67 words

Biometric data is expressly classified as sensitive under Decree 1377. A comprehensive Artificial Intelligence Bill was submitted to Congress in May 2025 to establish an ethical AI governance framework (human oversight, transparency, explainability) with extraterritorial reach to foreign AI systems used in Colombia; as a bill, it is not yet binding law. No dedicated Art 22 GDPR-style ADM/profiling-restriction provision, genetic-data regime, or state-surveillance carve-out framework was confirmed.

Sources and claims (3)
  1. ConfirmedIAPPDecree 1377 introduced a new definition of sensitive data that includes biometric data.
  2. ProbableDataGuidanceOn 7 May 2025, Colombia's Ministry of Science, Technology and Innovation submitted an Artificial Intelligence Bill to Congress aiming to establish a comprehensive legal framework for the ethical development, use and governance of AI systems.
  3. ProbableDataGuidanceThe AI Bill would apply extraterritorially to entities located abroad whose AI systems are used within Colombia.

#

Children's-data special-category treatment is confirmed; age-verification, minor-profiling-ban, education-setting and dependent-adult sub-modules lack confirmed coverage.

Primary frameworkDecree 1377 of 2013
Traffic-light rationale — AmberChildren's-data special-category treatment is confirmed; age-verification, minor-profiling-ban, education-setting and dependent-adult sub-modules lack confirmed coverage.

Sub-modules (5)

Minor Profiling BansRed

No explicit minor-specific profiling ban was identified beyond the general superior-interest principle.

Claims: CLM-CO-a1b2c3e4

Age VerificationRed

No dedicated statutory age-verification mechanism was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , a, g, e, , v, e, r, i, f, i, c, a, t, i, o, n, , m, e, c, h, a, n, i, s, m, , m, i, n, o, r, s, , d, a, t, a, , l, a, w.

Education SettingsRed

No education-settings-specific children's-data rules were identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , e, d, u, c, a, t, i, o, n, , s, e, t, t, i, n, g, s, , c, h, i, l, d, r, e, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, u, l, e, s.

Dependent AdultsRed

No dependent-adults (elderly/incapacitated) specific data protection provisions were identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , v, u, l, n, e, r, a, b, l, e, , p, e, r, s, o, n, s, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , p, r, o, v, i, s, i, o, n, s.

Category narrative41 words

Colombian law treats children's personal data as a special category jointly with sensitive data, requiring consideration of the child's superior interest during collection. No distinct statutory age-verification mechanism, minor-specific profiling ban, education-settings rule, or dependent-adults provision was confirmed in sources reviewed.

Sources and claims (1)
  1. ConfirmedIAPPUnder Decree 1377, personal data from children is considered together with sensitive data as a special category, and a specific provision requires the superior interest of the child to be taken into account when such data is collected.

#

Regulator powers and enforcement activity are well evidenced with recent (2025-2026) enforcement and rulemaking; collective-redress, private-right-of-action, and regulator-capacity sub-modules lack confirmed coverage.

Primary frameworkStatutory Law 1581 of 2012
Traffic-light rationale — GreenRegulator powers and enforcement activity are well evidenced with recent (2025-2026) enforcement and rulemaking; collective-redress, private-right-of-action, and regulator-capacity sub-modules lack confirmed coverage.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

SIC fines can reach up to 2,000 legal monthly minimum wages in force at the time of sanction.

Claims: CLM-CO-b2c3e4f5

Enforcement Activity IndexGreen

Recent enforcement includes the August 2025 Risks International fine and the historically largest Comcel fine, reflecting active SIC sanctioning practice.

Claims: CLM-CO-c3e4f5a6, CLM-CO-d4e5f6a8

Recent Developments 180DGreen

SIC issued Circular Externa No. 003 of 2025 on Model Contractual Clauses effective 19 December 2025, within the 180-day look-back window from the research date.

Claims: CLM-CO-e5f6a8b9

Collective Redress And Class ActionsRed

No dedicated collective-redress or class-action mechanism specific to data protection was identified.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , c, l, a, s, s, , a, c, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , c, o, l, l, e, c, t, i, v, e, , r, e, d, r, e, s, s, , m, e, c, h, a, n, i, s, m.

Private Right Of ActionAmber

Beyond the constitutional habeas data judicial remedy, no distinct statutory private right of action for data protection breaches was confirmed.

Absence provenance: not recorded. Searched: C, o, l, o, m, b, i, a, , p, r, i, v, a, t, e, , r, i, g, h, t, , o, f, , a, c, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, t, a, t, u, t, e.

Regulator Funding And CapacityRed

No SIC funding or headcount data was located in this research pass.

Absence provenance: not recorded. Searched: S, I, C, , C, o, l, o, m, b, i, a, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , d, i, v, i, s, i, o, n, , b, u, d, g, e, t, , h, e, a, d, c, o, u, n, t, , f, u, n, d, i, n, g.

Category narrative103 words

The SIC's sanctioning power under Law 1581 allows fines of up to 2,000 legal monthly minimum wages, a significant penalty by Colombian standards. Enforcement activity in the trailing 12 months includes the August 2025 fine against Risks International S.A.S. (COP 190 million) for processing sensitive data without consent, alongside the historically largest fine against Comcel S.A. Recent developments (within 180 days) include SIC's Circular Externa No. 003 of 2025 on Model Contractual Clauses (19 December 2025). No dedicated collective-redress/class-action mechanism or explicit private right of action distinct from the habeas data judicial remedy, and no regulator funding/headcount data, were confirmed in sources reviewed.

Sources and claims (4)
  1. ConfirmedIAPPUnder Law 1581, the fine for breach of data-transfer or data-protection obligations could be equivalent to 2,000 legal monthly minimum wages in force at the time of sanction, a significant penalty in Colombia.
  2. ConfirmedDataGuidanceOn 6 August 2025, the SIC announced a fine of COP 190 million (approx. $47,460) against Risks International S.A.S. for violating Law 1581 of 2012 by managing a database of sensitive personal data without consent.
  3. ConfirmedDataGuidanceOn 6 July 2023, the SIC imposed its highest fine to date, COP 1,306,289,600 (approx. $309,072), on Comcel S.A. for unlawful collection of personal data.
  4. ConfirmedIAPPOn 19 December 2025, the SIC issued Circular Externa No. 003 of 2025 introducing Model Contractual Clauses for international data transfers, adding a new instrument to Colombia's cross-border transfer framework.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Colombia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 35 claim(s), 16 source(s) in the cumulative register.