Biometric Authentication in Financial Institutions' Databases and Habeas Data
We explain External Circular 029 of December 11, 2019, from the Financial Superintendency, on implementing and using biometrics as an electronic authentication factor.

Note: this article was originally published in 2021 and is kept here as a historical reference on this Financial Superintendency circular.
As part of the minimum requirements set by the Colombian Financial Superintendency's External Circular 029 of December 11, 2019, for the financial institutions it oversees, regarding the implementation and use of biometrics as an electronic authentication factor, here are the instructions that apply whenever institutions use biometrics for authentication, in relation to protecting personal data and habeas data — safeguarding financial customers' sensitive information.
Financial institutions must therefore:
- Verify the customer's identity against the databases of the National Civil Registry Office, authorized digital citizen-services or digital-identity operators, or their own databases.
- When a customer can't use biometrics for medical or physical reasons, institutions must set up alternative mechanisms to complete the authentication process.
- When institutions use their own databases, they must:
- Store biometric templates using tokenization systems or strong encryption algorithms such as AES256, RSA, 3DES, or higher.
- Refrain from storing biometric samples taken for authentication purposes, unless the explicit consent referred to in clause (a) of article 6 of Law 1581 of 2012 (or any rule implementing, amending, or supplementing it) has been obtained, and only when necessary for financial-inclusion programs in remote areas of the country.
- In any case, storage must follow biometric data security standards such as ISO 24741:2007 and 24745:2011.
- Store customers' demographic information separately from biometric templates, linking them through codes generated by mathematical algorithms that aren't easily decoded.
- Include liveness-detection mechanisms when implementing biometric factors, to strengthen the system's reliability and security — such as: i) measuring physiological properties of the individual, ii) identifying human behavioral responses, or iii) challenge-response protocols.
- Establish controls during the initial capture of customers' biometric samples to ensure the data is obtained directly from the data subject.
- Properly manage the associated risks, regularly verify the effectiveness of the controls implemented, and comply with the current rules on data protection and habeas data.
If you have questions about implementing these measures, contact us on WhatsApp by clicking here.
At Consejurídico #WeWantToBeThere
Source: External Circular 029 of December 11, 2019, from the Colombian Financial Superintendency.
El asistente jurídico digital de Jurídiconline analiza tu situación específica. La revisión inicial es gratuita.