Latin America Colombia

Colombia Data Protection: Law 1581 and SIC Enforcement

Colombia's habeas data regime: Law 1581 of 2012, Decree 1377, the RNBD registry, SIC enforcement with fines to 2,000 minimum wages, and transfer rules.

Regulation

Statutory Law 1581 of 2012; Decree 1377 of 2013; Decree 090 of 2018 (RNBD); Law 1266 of 2008 (financial habeas data)

Max Penalty

Fines up to 2,000 current legal monthly minimum wages (roughly USD 700,000), plus suspension or closure of processing operations

Enforcing Authority

Superintendencia de Industria y Comercio (SIC), Delegatura de Proteccion de Datos Personales

Official Source

www.funcionpublica.gov.co

Executive Summary

  • Colombia protects personal data through the constitutional habeas data right (Article 15), implemented by Statutory Law 1581 of 2012 with Decree 1377 of 2013, plus the older Law 1266 of 2008 for financial and credit data.
  • The regime is authorization-based: prior, informed consent is the default rule, with express consent required for sensitive data and children's data, and narrow exceptions.
  • Larger companies must register their databases in the RNBD (Registro Nacional de Bases de Datos) run by the SIC, currently required of companies with assets above 100,000 UVT and non-profits above the same line.
  • The SIC enforces actively, fining banks, retailers, telecoms, and platforms for unauthorized processing, security failures, and marketing without consent, including repeated sanctions against delivery platform Rappi, with fines up to 2,000 monthly minimum wages.
  • International transfers are restricted to adequate countries or covered exceptions; the SIC's Circular Externa 005 of 2017 lists jurisdictions it deems adequate and consent as the general fallback.

Colombia’s regime looks familiar from the outside, consent, a registry, a superintendency, and is easy to underestimate for that reason. The SIC is among Latin America’s most active privacy enforcers by case volume, its fines land on household names year after year, and two structural features catch foreign companies: the RNBD registration duty (with breach reporting wired into it) and an authorization standard strict enough that most marketing-consent practices imported from the US fail it. Financial data adds a second statute with its own rules.

LawLey 1581 de 2012; Decree 1377 of 2013
RegulatorSIC (Delegatura de Proteccion de Datos)
Max fine2,000 monthly minimum wages (~USD 700K) + suspension/closure
RegistryRNBD for companies above 100,000 UVT in assets
Sensitive/childrenExpress authorization; best-interest test

The Colombia checklist

Prove your authorizations. The burden of demonstrating prior, informed consent sits with the controller; retrofit consent records for marketing databases first, since unauthorized marketing is the SIC’s highest-volume sanction category.

Register and maintain the RNBD entry. If asset thresholds are met, register every database, keep entries current, and use the RNBD’s breach-report channel within the required window, silence there aggravates any later case.

Segment the financial data. Credit and financial habeas data (Law 1266) has distinct rules on reporting, retention (caducidad), and consumer rights; do not run it through the general-track machinery unchecked.

Reconcile regionally. Colombia’s consent-first design contrasts with Brazil’s ten bases and resembles Argentina’s regime; the transfer rules interact with Argentine adequacy and Brazilian SCCs in multi-country flows.

Marketing trackers firing on Colombian visitors without authorization are exactly what complaints cite: audit your site with a free scan.

Frequently Asked Questions

Who must comply, and does the law reach foreign companies?

Controllers (responsables) and processors (encargados) processing personal data in Colombian territory, or where Colombian law applies by treaty. The SIC has applied the regime to foreign companies with Colombian operations, establishments, or processing directed at Colombia; a purely offshore website is harder to reach, but local subsidiaries, apps operating in Colombia, and vendors serving Colombian controllers are squarely covered. Financial and credit data runs on the separate Law 1266 track with its own rules and the same regulator.

How strict is the authorization (consent) requirement?

Prior and informed authorization is required before collection, demonstrable by the controller, with notice of the purposes, the optional nature of sensitive-data questions, rights, and the controller's identity. Exceptions are narrow: legal or judicial requirement, public registries, medical emergencies, statistical/historical/scientific purposes with dissociation. Sensitive data (health, biometrics, political and religious views, union membership, sex life, and data of children and adolescents) needs express authorization, and processing children's data is only lawful when it serves the minor's best interest and fundamental rights.

What is the RNBD and who must register?

The National Database Registry, a public directory of databases run by the SIC. After successive scope reductions (Decree 090 of 2018), registration is mandatory for companies and non-profits with total assets above 100,000 UVT (an inflation-indexed unit), and for public entities. Registrants describe each database's purposes, data categories, security measures, international transfers, and processor relationships, and must report substantial changes and update annually. Breach incidents must also be reported through the RNBD, which is how the SIC learns of security failures.

What does SIC enforcement look like in practice?

The SIC's data protection delegatura issues dozens of sanctions annually. Recurring patterns: marketing calls and messages without valid authorization (the largest category), security failures exposing customer data, ignoring deletion requests, and processing beyond the authorized purposes. Rappi has been fined repeatedly (including sanctions upheld in 2023-2024) over authorization and information duties; banks and telecoms feature constantly. Fines reach 2,000 current monthly minimum wages (about USD 700,000), and the SIC can also order suspension of processing or closure of databases, remedies it has used against non-cooperative controllers.

How do international transfers work?

Transfers of personal data abroad require the destination to provide adequate protection, per SIC Circular Externa 005 of 2017, which lists countries the SIC considers adequate (including the US for certain frameworks, EU members, and several others), or a covered exception: express authorization from the data subject, medical necessity, banking transfers, treaty obligations, or contract performance. Transmissions to processors acting for a Colombian controller can instead rely on a transmission contract meeting Decree 1377 requirements. Map which mechanism covers each flow; authorization is the fallback but fragile at scale.

Regulatory Crosswalk

GDPRLGPDArgentina PDPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.