Colombia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Colombia does not force you to keep data inside the country. But sending personal data abroad is banned unless the destination is on an approved list, you fit an exception, or you sign a transfer contract and write to the regulator. The list is long and includes the United States. The regulator is fully staffed, fines companies most months, and in 2026 shut a foreign biometric operation for good.
Data governance in Colombia
The eight things that decide how you handle data about people in Colombia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a foreign company with no office, no branch and no local representative in Colombia, as long as it handles people's data inside Colombian territory. The regulator said exactly that in 2026 when it shut down a foreign iris-scanning operation and rejected the argument that it was out of reach. There is no size or revenue threshold that lets you escape the law itself.
Article 2 of Law 1581 of 2012 applies the regime to processing carried out in Colombian territory, and to processors or controllers not established in Colombia where Colombian law applies under treaties. The Delegate Office for Personal Data Protection went further in Resolution 45710 of 18 June 2026: it 'reiterated that Law 1581 of 2012 applies to anyone who processes personal data in Colombia, even partially, and even when they are not established in Colombia, do not have a branch there, or have not formalized local representation'. Separately, a size threshold does exist but only for one duty: registration in the National Database Registry is required of companies and non-profits with total assets above 100,000 tax units, and of all public bodies. No general obligation to appoint a local representative was found, checked 18 August 2026.
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey Estatutaria 1581 de 2012, article 2 (ámbito de aplicación)
alcaldiabogota.gov.co
“La presente ley aplicará al tratamiento de datos personales efectuado en territorio colombiano o cuando al Responsable del Tratamiento o Encargado del Tratamiento no establecido en territorio nacional le sea aplicable la legislación colombiana en virtud de normas y tratados internacionales.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioThe SIC confirms the immediate and permanent shutdown of the sensitive data processing operation carried out by World Foundation and Tools for Humanity Corporation, 8 July 2026
sedeelectronica.sic.gov.co
“Law 1581 of 2012 applies to anyone who processes personal data in Colombia, even partially, and even when they are not established in Colombia, do not have a branch there, or have not formalized local representation.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioRegistro Nacional de Bases de Datos — who must register
sic.gov.co
“Los sujetos que continúan con el deber de registrar sus bases de datos son las sociedades y entidades sin ánimo de lucro que tengan activos totales superiores a 100 mil Unidades de Valor Tributario (UVT) y las entidades de naturaleza pública.”
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. Nothing has to stay in Colombia. But the starting point in the law is a ban: you may not send personal data to a country that does not protect it well enough. The regulator publishes a list of countries that do. If your destination is on that list you can send data. If it is not, you need an exception, or a signed transfer contract plus a letter to the regulator, or the regulator's own approval.
Sector by sector, checked 18 August 2026: BANKING, INSURANCE, PENSIONS, TRUST COMPANIES AND SECURITIES INTERMEDIARIES — rated conditional, and stricter than the national rule. Chapter VI of Part I, Title I of the Financial Superintendency's Basic Legal Circular (added by External Circular 005 of 11 March 2019) lets supervised entities run any process in the cloud, including abroad, but requires them to 'verify that the jurisdictions where the information will be processed have rules equivalent to or higher than those applicable in Colombia' on data protection and computer crime; to check the provider holds ISO 27001; to guarantee the regulator can still reach the systems if the entity is taken over; and to notify the regulator, 15 days before processing begins, of the provider, the subcontractors, the processes involved and 'the physical location or region where the data will be processed and stored'. CREDIT AND FINANCIAL REPORTING DATA — rated conditional, separate statute. Law 1266 of 2008 governs credit bureaus and the sources and users that feed them, and is expressly carved out of the general law. Article 26 of Law 1581 still applies to it. HEALTH — no localisation rule found, checked 18 August 2026. Custody of a clinical record sits with the provider that created it, and the record must be archived under National Archive rules, but nothing found requires Colombian storage. Medical data may also cross borders under the public-health exception in the transfer article. GOVERNMENT, TELECOMS, EDUCATION, GAMING, MAPPING AND DEFENCE — no localisation rule confirmed on an official source within this research budget. Absence of a finding is not proof of absence; each is listed in 'unconfirmed'.
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey Estatutaria 1581 de 2012, article 26 (prohibición)
alcaldiabogota.gov.co
“Se prohíbe la transferencia de datos personales de cualquier tipo a países que no proporcionen niveles adecuados de protección de datos.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V (Protección de datos personales), Capítulo Tercero, version of 29 September 2022
sic.gov.co
“garantizan un nivel adecuado de protección los siguientes países: Alemania; Australia, Austria; Bélgica; Bulgaria; Chipre; Costa Rica; Croacia; Dinamarca; Eslovaquia; Eslovenia; Estonia; España; Estados Unidos de América; Finlandia; Francia; Grecia; Hungría; Irlanda; Islandia; Italia; Japón; Letonia; Lituania; Luxemburgo; Malta; México; Noruega; Países Bajos; Perú; Polonia; Portugal; Reino Unido; República Checa; República de Corea; Rumania; Serbia; Suecia; y los países que han sido declarados con el nivel adecuado de protección por la Comisión Europea.”
Link checked 18 August 2026
- Official sourceSuperintendencia Financiera de ColombiaCircular Básica Jurídica, Parte I, Título I, Capítulo VI — Reglas relativas al uso de servicios de computación en la nube (annex to External Circular 005 of 2019)
superfinanciera.gov.co
“Verificar que las jurisdicciones en donde se procesará la información cuenten con normas equivalentes o superiores a las aplicables en Colombia, relacionadas con la protección de datos personales y penalización de actos que atenten contra la confidencialidad, integridad y disponibilidad de los datos y de los sistemas informáticos.”
Link checked 18 August 2026
- Official sourceMinisterio de Salud y Protección SocialResolución 1995 de 1999, article 13 (custodia de la historia clínica)
minsalud.gov.co
“La custodia de la historia clínica estará a cargo del prestador de servicios de salud que la generó en el curso de la atención.”
Link checked 18 August 2026
Sending data out of the country
The model is an approved list, and the list is genuinely full. Thirty-nine countries are named, plus every country Europe has approved. The United States is on it, which surprises people. If your destination is not listed you have four routes: an exception in the law, showing the country meets the published standards anyway, signing a transfer contract and writing to the regulator, or asking the regulator for a formal approval.
Routes in order of practical use. (1) The published list. Thirty-nine named countries plus all destinations approved by the European Commission. Even then you must be able to show you put real safeguards in place. (2) The six statutory exceptions in article 26 of Law 1581 of 2012: the person's express and unambiguous consent; medical data exchange required for the person's treatment or for public health; banking and stock exchange transfers; transfers under a treaty Colombia has signed, on a reciprocity basis; transfers needed to perform a contract with the person; and transfers required to protect the public interest or to bring or defend a legal claim. (3) The contract route, which is the workhorse. Where the sender signs a contract or other legal instrument with the recipient setting out how the data will be handled, the circular says the operation 'is presumed viable and to have a Declaration of Conformity'. The catch is that the sender must first send a communication to the regulator's data protection division describing the operation and declaring that the contract is signed. (4) A formal Declaration of Conformity applied for in writing, with all supporting documents translated into Spanish. Two useful clarifications sit in the same chapter. Data merely passing through a country on its way somewhere else is not a transfer. And sending data to a supplier abroad who processes it on your behalf — a 'transmission' rather than a 'transfer' — needs no consent and no notice to the individual, provided there is a supplier contract meeting article 25 of Decree 1377 of 2013.
Sources
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V, Capítulo Tercero, numerals 3.1 to 3.3 — adequacy standards, country list and Declaration of Conformity
sic.gov.co
“se presumirá que la operación es viable y que cuenta con Declaración de Conformidad. En consecuencia, los Responsables del Tratamiento podrán realizar dicha transferencia, previa comunicación remitida a la Delegatura para la Protección de Datos Personales.”
Link checked 18 August 2026
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalDecreto 1377 de 2013, articles 24 and 25 — international transfer and transmission, and the supplier contract
alcaldiabogota.gov.co
“Las transmisiones internacionales de datos personales que se efectúen entre un responsable y un encargado para permitir que el encargado realice el tratamiento por cuenta del responsable, no requerirán ser informadas al Titular ni contar con su consentimiento cuando exista un contrato en los términos del artículo 25 siguiente.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioTransferencia Internacional de datos personales — SIC legal bulletin, October 2017
sic.gov.co
“El numeral 3.2 del Capítulo tercero, del Título V de la Circular Única de esta Superintendencia (Circular 05 del 10 de agosto de 2017) señala la lista de países que reúnen los estándares que garantizan un nivel adecuado de protección.”
Link checked 18 August 2026
The regulator, and whether it actually acts
The Superintendency of Industry and Commerce, through its Delegate Office for Personal Data Protection. It is real, staffed and busy. It published data protection penalty decisions in every month of 2026 that we checked, it runs an annual national conference, and in June 2026 it confirmed on appeal an order permanently shutting down a foreign company's biometric operation in Colombia. Banks and insurers answer to a second regulator, the Financial Superintendency, for their technology and cloud arrangements.
Law 1581 of 2012 names the Superintendency of Industry and Commerce as the data protection authority and gives it investigation, order and penalty powers. Evidence it is operating, gathered 18 August 2026: a published register of data protection sanctions for 2026 containing resolutions dated February, March, May and later; Resolution 45710 of 18 June 2026 dismissing World Foundation's and Tools for Humanity's appeal, with no further appeal available; the thirteenth national data protection conference held on 28 and 29 July 2026, opened by the serving Delegate Superintendent for Personal Data Protection, Juan Carlos Upegui; and a new guidance document for universities published on 13 August 2026. One structural weakness: the penalty regime in article 23 applies only to private bodies. Where a public body breaks the rules, the Superintendency must hand the file to the Attorney General's disciplinary office instead of fining it.
Sources
- Official sourceSuperintendencia de Industria y ComercioSanciones 2026 — published data protection penalty resolutions
sic.gov.co
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioXIII Congreso Internacional de Protección de Datos Personales, 28-29 July 2026
sedeelectronica.sic.gov.co
“el superintendente delegado para la Protección de Datos Personales, Juan Carlos Upegui, presentó un balance de la gestión realizada entre 2022 y 2026”
Link checked 18 August 2026
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey Estatutaria 1581 de 2012, articles 19 and 23
alcaldiabogota.gov.co
“Las sanciones indicadas en el presente artículo sólo aplican para las personas de naturaleza privada.”
Link checked 18 August 2026
How long you must keep it — and when to delete it
Colombia sets a ceiling more clearly than a floor. You may keep personal data only for as long as is reasonable and necessary for the purpose you collected it for, and then you must delete it unless a law or contract says otherwise. The sharpest fixed limits are in credit reporting: a bad payment record drops off four years after the debt is cleared, and eight years after the debt first went unpaid even if it never is. Medical records must be kept and archived under national archive rules.
The ceiling comes from article 11 of Decree 1377 of 2013: data may be held only for the time that is reasonable and necessary given the purpose and the administrative, accounting, tax, legal and historical aspects of the information, after which it must be deleted unless a legal or contractual obligation requires it be kept. The same article requires organisations to document their retention and deletion procedures. The credit reporting floor and ceiling are precise. If the arrears lasted less than two years, the negative record may stay for at most twice the length of the arrears. If the arrears lasted two years or more, the negative record stays four years from the date the debt is settled. If the debt is never settled, the record expires eight years after the arrears began — a rule added by Law 2157 of 2021. Health: clinical records stay with the provider that created them and must be organised through management, central and historical archives under General Archive of the Nation rules. Where a provider is wound up, the liquidator must name someone to hold the records for the legally required period. The exact number of years was not confirmed on an official source within this research budget and is listed in 'unconfirmed'. General tax and commercial book retention periods were likewise not confirmed on an official source and should not be relied on from this record.
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalDecreto 1377 de 2013, article 11 (limitaciones temporales al Tratamiento)
alcaldiabogota.gov.co
“Los Responsables y Encargados del Tratamiento solo podrán recolectar, almacenar, usar o circular los datos personales durante el tiempo que sea razonable y necesario, de acuerdo con las finalidades que justificaron el tratamiento.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V, Capítulo Primero, numeral 1.6 — permanencia de la información negativa
sic.gov.co
“Si la mora reportada es igual o superior a dos (2) años, el dato negativo permanecerá por cuatro (4) años, contados a partir de la fecha en que se extinga la obligación por cualquier modo.”
Link checked 18 August 2026
- Official sourceMinisterio de Salud y Protección SocialResolución 1995 de 1999, articles 12 and 13 — archiving and custody of clinical records
minsalud.gov.co
Link checked 18 August 2026
If something goes wrong
Colombia's main breach clock is unusually generous: 15 working days, roughly three calendar weeks, from the moment the incident reaches the person or team responsible for handling it. Companies large enough to be on the national database register report through that register. Everyone else reports through the regulator's online form. There is no general duty to tell the affected people, though the regulator can order it.
The instruction covers 'violation of security codes or the loss, theft and/or unauthorised access to information in a database'. Two routes, one deadline. Controllers required to register their databases report the incident as a 'novedad' inside the National Database Registry within 15 working days. Controllers who are not required to register, and all processors, report through the application on the data protection division's pages or any other official channel, also within 15 working days. Incident reports are not published. Count a second clock if you are supervised by the Financial Superintendency, which runs its own information security and cyber incident reporting expectations for banks, insurers and other supervised entities, and a third if a criminal offence is involved. Neither was verified in detail within this research budget.
Sources
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V, Capítulo Segundo, numeral 2.1(f)(ii) — reporte de incidentes de seguridad
sic.gov.co
“deberán reportarse al RNBD ... dentro de los quince (15) días hábiles siguientes al momento en que se detecten y sean puestos en conocimiento de la persona o área encargada de atenderlos.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioProtección de Datos Personales — Reporte de Incidentes de Seguridad channel
sic.gov.co
Link checked 18 August 2026
What catches people out
Five things that cost people their weekend. A child is anyone under 18, and processing their data starts from a position of being banned. The transfer contract route only works if you actually write to the regulator first. Sending data to a supplier abroad is treated as a different animal from sending it to a partner, with different paperwork. Encrypting or splitting biometric data does not make it stop being personal data. And if you are a bank or insurer, you must tell the financial regulator where in the world your cloud region is, 15 days before you switch it on.
(1) Children. Decree 1377 of 2013 starts from a prohibition on processing the data of children and adolescents, lifted only where the data is public in nature and the processing respects the child's best interests and fundamental rights, with the legal representative authorising after the child has been heard. Colombia treats everyone under 18 as a child; there is no lower digital consent age as in Europe. The regulator's August 2026 university guidance carves out one narrow area: adolescents over 14 can authorise processing of their own data where that is needed for access to education. (2) The presumed approval trap. Signing a transfer contract does not by itself make a transfer lawful. The circular presumes a Declaration of Conformity only where the sender has first sent a communication to the regulator's data protection division describing the operation and declaring that the contract exists. The regulator can check at any time and investigate if it finds otherwise. (3) Transfer versus transmission. Sending data to a supplier who processes it for you needs no consent and no notice to the individual, but only if there is a contract meeting article 25 of Decree 1377, which must impose principle compliance, security and confidentiality on the supplier. Sending data to another organisation for its own purposes is a transfer, and the article 26 regime applies in full. (4) Advanced cryptography is not anonymisation. In its 2026 decision the regulator rejected the argument that an iris code, encrypted and split across nodes using secure multi-party computation, ceased to be personal data. It held that because the system could still recognise an already-registered person, the link to an identifiable individual survived. (5) Financial cloud pre-notification. Supervised financial entities must send the Financial Superintendency the provider name, the subcontractors, the processes, and the physical location or region of processing and storage, 15 days before processing starts. Changing cloud region is therefore a regulatory event, not just an engineering one.
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalDecreto 1377 de 2013, articles 12, 24 and 25
alcaldiabogota.gov.co
“El Tratamiento de datos personales de niños, niñas y adolescentes está prohibido, excepto cuando se trate de datos de naturaleza pública.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioSIC guidance on personal data in the university context, 13 August 2026
sedeelectronica.sic.gov.co
“los adolescentes mayores de 14 años pueden autorizar el tratamiento de sus propios datos cuando sea necesario para garantizar su acceso al servicio público de educación”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioSIC decision on World Foundation and Tools for Humanity, Resolution 45710 of 18 June 2026
sedeelectronica.sic.gov.co
“the adoption of advanced cryptographic mechanisms—applied after collection—does not render the information anonymous”
Link checked 18 August 2026
- Official sourceSuperintendencia Financiera de ColombiaCircular Básica Jurídica, Parte I, Título I, Capítulo VI, numeral 6 — pre-notification of cloud processing
superfinanciera.gov.co
“Dentro de los 15 días anteriores al inicio del procesamiento de información en la nube ... 6.3. La ubicación física o región donde se procesarán y almacenarán los datos.”
Link checked 18 August 2026
What's changing next
A rewrite of the 2012 privacy law is being openly discussed by the regulator itself, but it is talk and not yet a binding law. The regulator's own leadership says it wants stronger powers, more staff and more budget, and has named biometric data, identity fraud and artificial intelligence as the priorities for the coming months. In the financial sector, the open finance technology and security standards are being phased in, and the start date has already been pushed back once.
Do not plan around the reform as if it were law. As at 18 August 2026 the regulator describes it as a debate and a roadmap, not an enacted statute; no adopted replacement for Law 1581 of 2012 was found on an official source. The dormant switches matter more, because each can move without a new law and without consultation: (1) The country list. The circular states plainly that the Superintendency 'shall exercise, at any time, its regulatory capacity to review the above list and proceed to include those not part of it or to exclude whomever it considers appropriate'. A destination you rely on today, including the United States, can be removed by circular. (2) The adequacy standards themselves. The six criteria in numeral 3.1 are the regulator's own, and it can restate them. (3) Security instructions. Article 19 of Decree 1377 of 2013 gives the Superintendency an open mandate to issue instructions on security measures, which is the same power that produced the 15-working-day breach reporting rule. (4) Financial sector timing. The Financial Superintendency issued a 2026 circular extending the start date of the open finance architecture, security and technology standards set by its External Circular 013 of 2025.
Sources
- Official sourceSuperintendencia de Industria y ComercioArtificial intelligence, new technologies and reform of Law 1581 dominated the XIII international data protection congress, 30 July 2026
sedeelectronica.sic.gov.co
“El congreso también retomó el debate sobre la actualización de la Ley 1581 de 2012, la regulación de las nuevas tecnologías y los asuntos que requerirán especial atención en los próximos meses”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V, numeral 3.2 — power to revise the country list at any time
sic.gov.co
“La Superintendencia de Industria y Comercio ejercerá, en cualquier tiempo, su capacidad regulatoria para revisar la lista anterior y proceder a incluir a quienes no hacen parte de la misma o para excluir a quien se considere conveniente.”
Link checked 18 August 2026
- Official sourceSuperintendencia Financiera de ColombiaCirculares Externas 2026 — extension of the entry into force of External Circular 013 of 2025 (open finance standards)
superfinanciera.gov.co
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Circular Básica Jurídica, Parte I, Título I, Capítulo VI — Reglas relativas al uso de servicios de computación en la nube
Regulator directive · Added by Circular Externa 005 of 11 March 2019; Circular Básica Jurídica currently re-issued as C.E. 006 of 2025
Banks, insurers, pension and trust companies and securities intermediaries may run everything in the cloud, including abroad, but only after checking that the destination country's data protection and cybercrime laws match or beat Colombia's, and only after telling the financial regulator the provider and the physical region 15 days in advance. The regulator must also be able to reach the systems if the entity is taken over.
Enforced by Financial Superintendency of Colombia
Transfer model: Approval each time · Accepted routes: Security review needed, Certification scheme
What it makes you do
- Hold a security certificateThe cloud provider must hold and maintain ISO 27001 at minimum, follow ISO 27017 and 27018, and produce SOC 1, SOC 2 and SOC 3 reports.
- Put a transfer safeguard in placeThe entity must verify that every jurisdiction where data will be processed has data protection and computer crime laws equivalent to or stronger than Colombia's.
- Register or notifyNotify the regulator 15 days before cloud processing of core or accounting processes begins, naming the provider, subcontractors, processes and the physical location or region of processing and storage.
- Written vendor contractThe contract must state that the data belongs to the supervised entity, cannot be used for any other purpose, and must be securely erased when the contract ends.
- Make switching cloud provider possibleA migration strategy to another platform must exist before you need it.
- Independent auditInternal and external auditors must be selected with the technical competence to assess cloud services.
Sources
- Official sourceSuperintendencia Financiera de ColombiaAnnex to External Circular 005 of 2019 — Parte I, Título I, Capítulo VI, Computación en la nube
superfinanciera.gov.co
“Establecer las medidas necesarias para garantizar que, en el evento de toma de posesión, la SFC, Fogafín, Fogacoop, o quienes éstas designen, puedan acceder a la información y a la administración de los sistemas de información que operan en la nube.”
Link checked 18 August 2026
- Official sourceSuperintendencia Financiera de ColombiaNormativa general — Circular Básica Jurídica (C.E. 006/25) and the 2019 circulars index
superfinanciera.gov.co
Link checked 18 August 2026
Ley Estatutaria 1266 de 2008 (hábeas data financiero), modificada por la Ley Estatutaria 2157 de 2021
Act of parliament · Ley 1266 de 2008; article 13 amended by Ley 2157 de 2021; instructions in Circular Única, Título V, Capítulo Primero
Credit reporting has its own statute, carved out of the general privacy law but still bound by its transfer rules. It fixes exactly how long a bad payment record may follow someone, and the regulator fines lenders that report without warning the borrower first.
Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed
What it makes you do
- Delete data after a period — 4 yearsNegative record stays four years from settlement where arrears ran two years or more; at most twice the arrears period where arrears ran under two years.
- Keep data for a minimum period — 8 yearsWhere the debt is never paid, the negative record expires eight years after the arrears began.
- Let people correct their data
- Tell people what you doThe source must warn the individual before making a negative report.
- Secure the data
Sources
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V, Capítulo Primero — hábeas data financiero, numeral 1.6
sic.gov.co
“el término de caducidad de los datos negativos de un Titular de información será de ocho (8) años contados a partir de la fecha en que entre en mora la obligación, tal como lo señala el parágrafo 1 del artículo 13 de la Ley Estatutaria 1266 de 2008, adicionado por la Ley Estatutaria 2157 de 2021”
Link checked 18 August 2026
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey 1581 de 2012, article 2(e) and article 26 paragraph 2 — carve-out for Ley 1266 databases, transfer rules still apply
alcaldiabogota.gov.co
“Las disposiciones contenidas en el presente artículo serán aplicables para todos los datos personales, incluyendo aquellos contemplados en la Ley 1266 de 2008.”
Link checked 18 August 2026
Resolución 1995 de 1999, por la cual se establecen normas para el manejo de la Historia Clínica
Directly binding regulation · Resolución 1995 de 1999
Colombian medical records must be archived by the provider that created them, in a defined three-stage archive under national archive rules. No requirement was found that they be stored inside Colombia. Medical data may also cross borders under the public health exception in the general privacy law.
Enforced by Ministry of Health and Social Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Important public interest, Explicit consent
What it makes you do
- Keep records of processingEvery healthcare provider must keep a single clinical records archive in three stages — active, central and historical — organised under General Archive of the Nation rules.
- Keep data for a minimum periodRecords must be kept for the period set by law; on liquidation of a provider the liquidator must name who holds them for that period.
- Extra vendor secrecy termsCustody sits with the provider that created the record, so outsourcing storage does not move responsibility.
Sources
- Official sourceMinisterio de Salud y Protección SocialResolución 1995 de 1999 — manejo de la Historia Clínica
minsalud.gov.co
“Todos los prestadores de servicios de salud, deben tener un archivo único de historias clínicas en las etapas de archivo de gestión, central e histórico.”
Link checked 18 August 2026
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey 1581 de 2012, article 26(b) — medical data exception to the transfer ban
alcaldiabogota.gov.co
“Intercambio de datos de carácter médico, cuando así lo exija el Tratamiento del Titular por razones de salud o higiene pública”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Ley Estatutaria 1581 de 2012, por la cual se dictan disposiciones generales para la protección de datos personales
Act of parliament · Ley 1581 de 2012
Colombia's general privacy statute. Consent-led, applies to processing carried out in Colombia even by companies with no presence there, and bans sending personal data to countries the regulator has not accepted as offering adequate protection. Fines apply only to private bodies; public bodies are referred to the Attorney General instead.
Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims
What it makes you do
- Get consentPrior, informed authorisation is the default basis, recorded so it can be checked later.
- Tell people what you do
- Let people see their dataFree of charge at least once a calendar month.
- Let people correct their data
- Let people delete their data
- Secure the data
- Put a transfer safeguard in place
- Publish a complaints contactThe processing policy must name the person or area handling requests, queries and complaints.
- Get a parent's consent for children — applies at: under 18Starts from a prohibition; the child must be heard before the legal representative authorises.
What it costs if you get it wrong
- Fixed maximum fine: 2.000 salarios mínimos mensuales legales vigentes — about $750 thousandAny breach by a private body; fines may be repeated while the breach continues
- Order to stop: Suspensión hasta por seis (6) meses; cierre temporal; cierre inmediato y definitivoContinuing breach, or any operation involving sensitive data
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey Estatutaria 1581 de 2012 — full consolidated text
alcaldiabogota.gov.co
“Multas de carácter personal e institucional hasta por el equivalente de dos mil (2.000) salarios mínimos mensuales legales vigentes al momento de la imposición de la sanción.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioProtección de Datos Personales — the authority's own portal
sic.gov.co
Link checked 18 August 2026
Decreto 1377 de 2013, compilado en el Decreto Único Reglamentario 1074 de 2015
Directly binding regulation · Decreto 1377 de 2013
The regulation that makes the statute workable. It separates sending data to a partner abroad (a transfer, tightly controlled) from sending it to a supplier abroad (a transmission, allowed on a contract), sets the retention ceiling, and starts from a ban on processing children's data.
Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection
Transfer model: Allowlist · Accepted routes: Standard contract clauses, Official 'this country is safe' decision
What it makes you do
- Written vendor contractA supplier abroad may process data with no consent and no notice to the individual, but only under a contract imposing principle compliance, security and confidentiality.
- Tell people what you doEither a full processing policy or a short privacy notice pointing to it, at the latest when data is collected.
- Delete data after a periodKeep only for as long as is reasonable and necessary, then delete unless a law or contract requires otherwise.
- Keep records of processingRetention and deletion procedures must be documented.
- Get a parent's consent for children — applies at: under 18
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalDecreto 1377 de 2013 — full text
alcaldiabogota.gov.co
“Una vez cumplida la o las finalidades del tratamiento y sin perjuicio de normas legales que dispongan lo contrario, el Responsable y el Encargado deberán proceder a la supresión de los datos personales en su posesión.”
Link checked 18 August 2026
Circular Única de la Superintendencia de Industria y Comercio, Título V — Protección de datos personales
Regulator directive · Capítulo Tercero added by Circular Externa 05 of 10 August 2017 (Diario Oficial 50321); country list amended by Circular Externa 08 of 2017 and Circular Externa 02 of 2018; registry chapter amended by Circular Externa 03 of 2018; version consulted 29 September 2022
The operative transfer instrument. It publishes the list of countries deemed to protect data adequately — 39 named countries including the United States, plus everywhere the European Commission has approved — sets the criteria for judging others, and creates the Declaration of Conformity route. It also carries the national database registry rules and the 15-working-day breach reporting deadline.
Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed
What it makes you do
- Register or notify — applies at: Companies and non-profits with total assets above 100,000 tax units, and all public bodiesRegistration in the Registro Nacional de Bases de Datos; new databases must be registered within two months of creation.
- Report breaches to the regulator — within 360 hours15 working days, roughly three calendar weeks, from when the incident is detected and reaches the person or area responsible. Registered controllers report inside the registry; everyone else uses the regulator's online form.
- Put a transfer safeguard in placeWhere the destination is not on the list, either fit a statutory exception, show the country meets the published standards, sign a transfer contract and write to the regulator first, or obtain a Declaration of Conformity.
- Delete data after a period — 4 yearsCredit reporting: negative records drop off four years after settlement where the arrears ran two years or more, and expire eight years after the arrears began if never settled.
Sources
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V — Protección de datos personales, consolidated version of 29 September 2022
sic.gov.co
“Parágrafo Tercero: El simple tránsito transfronterizo de datos no comporta una transferencia de datos a terceros países.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioRegistro Nacional de Bases de Datos — scope after Decreto 090 de 2018
sic.gov.co
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the list of countries with an adequate level of protection has not changed since 29 September 2022
The consolidated Title V we read is dated 29 September 2022 and the regulator's old circular repository shows no entries after December 2022, apparently because the site was migrated to a new electronic office. The new site's norm search returned no results for us. The list may have been amended since; the circular expressly lets the regulator revise it at any time.
Whether online gambling operators licensed in Colombia must host their gaming platform or player data inside the country
This is a common localisation rule in the region and would change the headline rating if true. The gambling regulator's document listings would not render for us. No official text was obtained, so no rule is asserted either way.
Whether telecoms operators face a data retention or in-country storage duty, and for how long
Colombian intelligence and interception legislation is widely reported to require operators to keep subscriber records for five years. We could not open the operative text on an official government source within this research budget. Not asserted.
Whether public sector bodies face any cloud data residency requirement
We reviewed the Ministry of Information Technologies and Communications' own site and found digital government material but no residency instruction. Absence of a finding is not proof of absence.
The exact retention period for clinical records, and the current status of the interoperable electronic clinical record rules
The 1999 resolution points to 'the period provided by law' without stating it, and the 2021 resolution we downloaded from the health ministry is a scanned image our tools could not read.
The peso and dollar value of the maximum fine and of the 100,000 tax unit registration threshold
These are pegged to the 2026 monthly minimum wage and the 2026 tax unit value. Neither was verified on an official source, because the labour ministry site refused our connection and the tax authority's figure was not located. The figures given are approximations only.
The exact numbering of the cloud computing chapter inside the Basic Legal Circular as re-issued in 2025
We read the chapter as published with the 2019 circular that created it. The circular was re-issued as External Circular 006 of 2025 and the chapter may have been renumbered, though we found no sign it was withdrawn.
Whether any bill to replace or amend the 2012 privacy law has been formally introduced in Congress, and its stage
The regulator describes reform as an active debate and its own priority. We found no adopted text and did not verify any specific bill number in Congress. Nothing here should be planned around as binding.
The precise second and third breach reporting clocks for financial entities and for criminal matters
The financial regulator publishes information security and cyber indicators and supervises incident handling, but we did not open the operative reporting deadline within this research budget.
That the national statute text we relied on is identical to the official gazette version
The national legal databases we would normally use for the gazette copy were unreachable from our network. We used the Bogotá district government's official legal compilation instead, which is a government source but not the national gazette.
60-day cadence. Two dormant switches justify it: the regulator can revise the approved-country list at any time by circular with no consultation, and it holds an open mandate to issue new security instructions. A rewrite of the 2012 statute is also being actively promoted by the regulator itself.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Colombia versus
Compare