Colombia’s regime looks familiar from the outside, consent, a registry, a superintendency, and is easy to underestimate for that reason. The SIC is among Latin America’s most active privacy enforcers by case volume, its fines land on household names year after year, and two structural features catch foreign companies: the RNBD registration duty (with breach reporting wired into it) and an authorization standard strict enough that most marketing-consent practices imported from the US fail it. Financial data adds a second statute with its own rules.
| Law | Ley 1581 de 2012; Decree 1377 of 2013 |
|---|---|
| Regulator | SIC (Delegatura de Proteccion de Datos) |
| Max fine | 2,000 monthly minimum wages (~USD 700K) + suspension/closure |
| Registry | RNBD for companies above 100,000 UVT in assets |
| Sensitive/children | Express authorization; best-interest test |
The Colombia checklist
Prove your authorizations. The burden of demonstrating prior, informed consent sits with the controller; retrofit consent records for marketing databases first, since unauthorized marketing is the SIC’s highest-volume sanction category.
Register and maintain the RNBD entry. If asset thresholds are met, register every database, keep entries current, and use the RNBD’s breach-report channel within the required window, silence there aggravates any later case.
Segment the financial data. Credit and financial habeas data (Law 1266) has distinct rules on reporting, retention (caducidad), and consumer rights; do not run it through the general-track machinery unchecked.
Reconcile regionally. Colombia’s consent-first design contrasts with Brazil’s ten bases and resembles Argentina’s regime; the transfer rules interact with Argentine adequacy and Brazilian SCCs in multi-country flows.
Marketing trackers firing on Colombian visitors without authorization are exactly what complaints cite: audit your site with a free scan.