Data Protection for Colombian Companies: Real Obligations Under Law 1581
## Law 1581 of 2012: the data protection framework
Colombia has one of the most complete data protection frameworks in Latin America. Law 1581 (implemented by Decree 1377 of 2013) applies to any company that collects, stores, uses, or transfers personal data of Colombian citizens.
The oversight body is the Superintendency of Industry and Commerce (SIC).
Which companies are required to comply?
All legal entities and individuals that process third parties' personal data, regardless of size. There's no exemption for micro or small businesses.
Minimum obligations
1. Register your databases with the SIC Every company must register its databases that contain personal data in the SIC's National Database Registry (RNBD). URL: rnbd.sic.gov.co
2. Data-processing policy An internal document, approved by senior management, describing: - What data is collected and why - How it's protected - Data subjects' rights - How to exercise those rights
3. Privacy notice For direct data collection, the data subject must be informed before or at the moment of collection about: who's responsible, the purpose, their rights, and how to exercise them.
4. Obtaining consent For sensitive data (health, biometrics, sexual orientation, religious beliefs), consent must be express, informed, and freely given.
For ordinary data, it can be implied (continuing the relationship after the notice), but it's always best to get it in writing.
5. Contract with data processors If you hire a third party to process data (marketing, SaaS software, a call center), you need a contract that: - Requires the third party to process the data only for the authorized purposes - Sets security measures equivalent to your own - Governs what happens to the data when the contract ends
6. Procedure for handling data-subject requests An internal channel so people can access, update, correct, or delete their data. Response deadline: 10 business days.
Specially protected data
Sensitive data has additional protections: - It can only be processed with express consent - It must be stored with reinforced security measures - Services can't be denied to someone for not providing sensitive data
Sensitive data includes: health information, biometric data, sexual orientation, religion, political affiliation, ethnic origin.
International data transfers
If you send data to servers abroad (Gmail, Salesforce, AWS in the US), you must: - Verify the destination country has an adequate level of protection - Or sign international transfer clauses approved by the SIC - Or get the data subject's express consent
Penalties for non-compliance
The SIC can impose: - Fines: up to 2,000 monthly minimum wages per violation (~$2.6 billion COP) - Suspension of activities related to the offending database - Publication of the penalty (reputational damage)
Does your company still not have a data policy, or does it need to catch up on compliance? We can run a quick assessment and guide you through implementing the required measures.
El asistente jurídico digital de Jurídiconline analiza tu situación específica. La revisión inicial es gratuita.