Colombia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Colombia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Colombia does not force you to keep data inside the country. But you may not send personal data abroad unless one of three things is true. The destination country is on Colombia's approved list. Or your situation fits an exception in the law. Or you sign a transfer contract and write to the regulator first. The approved list is long and includes the United States. The regulator is fully staffed and fines companies most months. In 2026 it shut down a foreign biometric operation for good.
Data governance in Colombia
The eight things that decide how you handle data about people in Colombia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law applies to a foreign company with no office, no branch and no representative in Colombia. What matters is that you handle people's data inside Colombia. The regulator said exactly that in 2026. It shut down a foreign iris-scanning operation and rejected the claim that it was out of reach. There is no size or revenue limit that gets you out of the law itself.
Article 2 of Law 1581 of 2012 covers the use of personal data inside Colombia. It also covers companies not based in Colombia where Colombian law applies under a treaty. The Delegate Office for Personal Data Protection went further in Resolution 45710 of 18 June 2026. It repeated that Law 1581 of 2012 applies to anyone who uses personal data in Colombia, even in part. That holds even if you are not based there, have no branch there, and have never set up formal local representation. A size limit does exist, but only for one duty. Companies and non-profits with total assets above 100,000 tax units must register in the National Database Registry. So must all public bodies. We found no general requirement to appoint a local representative, checked 18 August 2026.
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey Estatutaria 1581 de 2012, article 2 (ámbito de aplicación)
alcaldiabogota.gov.co
“La presente ley aplicará al tratamiento de datos personales efectuado en territorio colombiano o cuando al Responsable del Tratamiento o Encargado del Tratamiento no establecido en territorio nacional le sea aplicable la legislación colombiana en virtud de normas y tratados internacionales.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioThe SIC confirms the immediate and permanent shutdown of the sensitive data processing operation carried out by World Foundation and Tools for Humanity Corporation, 8 July 2026
sedeelectronica.sic.gov.co
“Law 1581 of 2012 applies to anyone who processes personal data in Colombia, even partially, and even when they are not established in Colombia, do not have a branch there, or have not formalized local representation.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioRegistro Nacional de Bases de Datos — who must register
sic.gov.co
“Los sujetos que continúan con el deber de registrar sus bases de datos son las sociedades y entidades sin ánimo de lucro que tengan activos totales superiores a 100 mil Unidades de Valor Tributario (UVT) y las entidades de naturaleza pública.”
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. Nothing has to stay in Colombia. The law starts from a ban. You may not send personal data to a country that does not protect it well enough. The regulator publishes a list of countries that do. If your destination is on that list, you can send the data. If it is not, you have three options. Fit an exception in the law. Or sign a transfer contract and write to the regulator. Or get the regulator's own approval.
Industry by industry, checked 18 August 2026: BANKING, INSURANCE, PENSIONS, TRUST COMPANIES AND SECURITIES INTERMEDIARIES. Conditions apply, and they are stricter than the national rule. Chapter VI of Part I, Title I of the Financial Superintendency's Basic Legal Circular sets them out. It was added by External Circular 005 of 11 March 2019. Supervised firms may run any process in the cloud, including abroad. First you must check the laws of every country where the data will be handled. Their data protection and computer crime laws must equal or beat Colombia's. You must check the provider holds ISO 27001. You must guarantee the regulator can still reach the systems if the firm is taken over. And you must tell the regulator 15 days before you start. Name the provider, the subcontractors, the processes involved, and the physical location or region where the data will be handled and stored. CREDIT AND FINANCIAL REPORTING DATA. Conditions apply, under a separate law. Law 1266 of 2008 governs credit bureaus and the lenders and users that feed them. It sits outside the general privacy law. Article 26 of Law 1581 still applies to it. HEALTH. We found no rule requiring health data to stay in Colombia, checked 18 August 2026. The provider that created a clinical record keeps custody of it. The record must be archived under National Archive rules. Nothing we found requires Colombian storage. Medical data may also cross borders under the public health exception in the transfer article. GOVERNMENT, TELECOMS, EDUCATION, GAMING, MAPPING AND DEFENCE. We could not confirm any rule requiring data to stay in Colombia in these areas against an official source. Finding nothing is not proof that nothing exists. Each is listed under 'unconfirmed'.
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey Estatutaria 1581 de 2012, article 26 (prohibición)
alcaldiabogota.gov.co
“Se prohíbe la transferencia de datos personales de cualquier tipo a países que no proporcionen niveles adecuados de protección de datos.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V (Protección de datos personales), Capítulo Tercero, version of 29 September 2022
sic.gov.co
“garantizan un nivel adecuado de protección los siguientes países: Alemania; Australia, Austria; Bélgica; Bulgaria; Chipre; Costa Rica; Croacia; Dinamarca; Eslovaquia; Eslovenia; Estonia; España; Estados Unidos de América; Finlandia; Francia; Grecia; Hungría; Irlanda; Islandia; Italia; Japón; Letonia; Lituania; Luxemburgo; Malta; México; Noruega; Países Bajos; Perú; Polonia; Portugal; Reino Unido; República Checa; República de Corea; Rumania; Serbia; Suecia; y los países que han sido declarados con el nivel adecuado de protección por la Comisión Europea.”
Link checked 18 August 2026
- Official sourceSuperintendencia Financiera de ColombiaCircular Básica Jurídica, Parte I, Título I, Capítulo VI — Reglas relativas al uso de servicios de computación en la nube (annex to External Circular 005 of 2019)
superfinanciera.gov.co
“Verificar que las jurisdicciones en donde se procesará la información cuenten con normas equivalentes o superiores a las aplicables en Colombia, relacionadas con la protección de datos personales y penalización de actos que atenten contra la confidencialidad, integridad y disponibilidad de los datos y de los sistemas informáticos.”
Link checked 18 August 2026
- Official sourceMinisterio de Salud y Protección SocialResolución 1995 de 1999, article 13 (custodia de la historia clínica)
minsalud.gov.co
“La custodia de la historia clínica estará a cargo del prestador de servicios de salud que la generó en el curso de la atención.”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Colombia.
Sending data out of the country
Colombia uses an approved list, and it is a long one. Thirty-nine countries are named. Every country Europe has approved also counts. The United States is on the list. If your destination is not listed, you have four routes. Fit an exception in the law. Or show the country meets the published standards anyway. Or sign a transfer contract and write to the regulator. Or ask the regulator for a formal approval.
- What you have to do here:
- Written vendor contract
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Government sign-off needed · Explicit consent · Needed for a contract · Important public interest · Legal claims
Here are the routes, in order of how often they are used. (1) The published list. Thirty-nine named countries, plus every destination approved by the European Commission. Even then you must be able to show you put real safeguards in place. (2) The six exceptions in article 26 of Law 1581 of 2012. The person gives express and unambiguous consent. Medical data is exchanged for the person's treatment or for public health. The transfer is a banking or stock exchange transfer. The transfer is made under a treaty Colombia has signed, on a reciprocal basis. The transfer is needed to perform a contract with the person. Or the transfer is needed to protect the public interest, or to bring or defend a legal claim. (3) The contract route, which most companies use. You sign a contract with the recipient setting out how the data will be handled. The circular then treats the transfer as viable and as having a Declaration of Conformity. The catch is that you must first write to the regulator's data protection division. Describe the transfer and state that the contract is signed. (4) A formal Declaration of Conformity. You apply in writing, with all supporting documents translated into Spanish. Two other points sit in the same chapter. Data merely passing through a country on its way somewhere else does not count as a transfer. And sending data to a supplier abroad who handles it on your behalf is a 'transmission', not a 'transfer'. That needs no consent and no notice to the individual. You do need a supplier contract meeting article 25 of Decree 1377 of 2013.
Sources
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V, Capítulo Tercero, numerals 3.1 to 3.3 — adequacy standards, country list and Declaration of Conformity
sic.gov.co
“se presumirá que la operación es viable y que cuenta con Declaración de Conformidad. En consecuencia, los Responsables del Tratamiento podrán realizar dicha transferencia, previa comunicación remitida a la Delegatura para la Protección de Datos Personales.”
Link checked 18 August 2026
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalDecreto 1377 de 2013, articles 24 and 25 — international transfer and transmission, and the supplier contract
alcaldiabogota.gov.co
“Las transmisiones internacionales de datos personales que se efectúen entre un responsable y un encargado para permitir que el encargado realice el tratamiento por cuenta del responsable, no requerirán ser informadas al Titular ni contar con su consentimiento cuando exista un contrato en los términos del artículo 25 siguiente.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioTransferencia Internacional de datos personales — SIC legal bulletin, October 2017
sic.gov.co
“El numeral 3.2 del Capítulo tercero, del Título V de la Circular Única de esta Superintendencia (Circular 05 del 10 de agosto de 2017) señala la lista de países que reúnen los estándares que garantizan un nivel adecuado de protección.”
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Superintendency of Industry and Commerce enforces, through its Delegate Office for Personal Data Protection. It is real, staffed and busy. It published privacy penalty decisions in every month of 2026 that we checked. It runs an annual national conference. In June 2026 it confirmed on appeal an order permanently shutting down a foreign company's biometric operation in Colombia. Banks and insurers answer to a second regulator, the Financial Superintendency, for their technology and cloud arrangements.
Law 1581 of 2012 names the Superintendency of Industry and Commerce as the data protection authority. It can investigate, give orders and impose penalties. Here is what we saw on 18 August 2026. A published register of data protection penalties for 2026, with decisions dated February, March, May and later. Resolution 45710 of 18 June 2026, dismissing the appeal by World Foundation and Tools for Humanity, with no further appeal available. The thirteenth national data protection conference, held on 28 and 29 July 2026. It was opened by the serving Delegate Superintendent for Personal Data Protection, Juan Carlos Upegui. And new guidance for universities, published on 13 August 2026. There is one structural weakness. The penalties in article 23 apply only to private bodies. If a public body breaks the rules, the Superintendency cannot fine it. It must hand the file to the Attorney General's disciplinary office instead.
Sources
- Official sourceSuperintendencia de Industria y ComercioSanciones 2026 — published data protection penalty resolutions
sic.gov.co
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioXIII Congreso Internacional de Protección de Datos Personales, 28-29 July 2026
sedeelectronica.sic.gov.co
“el superintendente delegado para la Protección de Datos Personales, Juan Carlos Upegui, presentó un balance de la gestión realizada entre 2022 y 2026”
Link checked 18 August 2026
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey Estatutaria 1581 de 2012, articles 19 and 23
alcaldiabogota.gov.co
“Las sanciones indicadas en el presente artículo sólo aplican para las personas de naturaleza privada.”
Link checked 18 August 2026
How long you must keep it — and when to delete it
Colombia is clearer about maximum keeping times than minimum ones. You may keep personal data only as long as is reasonable and necessary for the purpose you collected it for. After that you must delete it, unless a law or contract says otherwise. The sharpest fixed limits are in credit reporting. A bad payment record drops off four years after the debt is cleared. If the debt is never cleared, it drops off eight years after it first went unpaid. Medical records must be kept and archived under national archive rules.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep records of how you use data
The maximum comes from article 11 of Decree 1377 of 2013. You may hold data only for the time that is reasonable and necessary for the purpose. You must also weigh the administrative, accounting, tax, legal and historical sides of the information. After that you must delete it, unless a law or contract requires you to keep it. The same article requires you to write down your keeping and deletion procedures. The credit reporting limits are precise. If the arrears lasted less than two years, the negative record may stay for at most twice the length of the arrears. If the arrears lasted two years or more, the negative record stays four years from the date the debt is settled. If the debt is never settled, the record expires eight years after the arrears began. Law 2157 of 2021 added that last rule. Health. Clinical records stay with the provider that created them. They must be organised through management, central and historical archives under General Archive of the Nation rules. If a provider is wound up, the liquidator must name someone to hold the records for the period the law requires. We could not confirm the exact number of years against an official source. It is listed under 'unconfirmed'. We also could not confirm general tax and commercial book keeping periods, so do not rely on this record for those.
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalDecreto 1377 de 2013, article 11 (limitaciones temporales al Tratamiento)
alcaldiabogota.gov.co
“Los Responsables y Encargados del Tratamiento solo podrán recolectar, almacenar, usar o circular los datos personales durante el tiempo que sea razonable y necesario, de acuerdo con las finalidades que justificaron el tratamiento.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V, Capítulo Primero, numeral 1.6 — permanencia de la información negativa
sic.gov.co
“Si la mora reportada es igual o superior a dos (2) años, el dato negativo permanecerá por cuatro (4) años, contados a partir de la fecha en que se extinga la obligación por cualquier modo.”
Link checked 18 August 2026
- Official sourceMinisterio de Salud y Protección SocialResolución 1995 de 1999, articles 12 and 13 — archiving and custody of clinical records
minsalud.gov.co
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Colombia gives you 15 working days, which is roughly three calendar weeks. The clock starts when the incident reaches the person or team responsible for handling it. Companies large enough to be on the national database register report through that register. Everyone else reports through the regulator's online form. There is no general duty to tell the affected people, though the regulator can order it.
- What you have to do here:
- Report breaches to the regulator · Secure the data
The rule covers a breach of security codes, and the loss, theft or unauthorised access to information in a database. There are two routes and one deadline. If you must register your databases, report the incident as a 'novedad' inside the National Database Registry within 15 working days. You may not have to register, or you may be a supplier handling data for someone else. Then report through the form on the data protection division's pages, or any other official channel. The deadline is the same 15 working days. Incident reports are not published. There is a second deadline if the Financial Superintendency supervises you. It sets its own information security and cyber incident reporting expectations for banks, insurers and other supervised firms. There is a third if a crime is involved. We did not verify either in detail.
Sources
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V, Capítulo Segundo, numeral 2.1(f)(ii) — reporte de incidentes de seguridad
sic.gov.co
“deberán reportarse al RNBD ... dentro de los quince (15) días hábiles siguientes al momento en que se detecten y sean puestos en conocimiento de la persona o área encargada de atenderlos.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioProtección de Datos Personales — Reporte de Incidentes de Seguridad channel
sic.gov.co
Link checked 18 August 2026
What to do: Your breach process has to reach Colombia's regulator inside the deadline above.
What catches people out
Five things catch people out. A child is anyone under 18, and using their data starts out banned. The transfer contract route only works if you write to the regulator first. Sending data to a supplier abroad is treated differently from sending it to a partner, with different paperwork. Encrypting or splitting biometric data does not stop it being personal data. And if you are a bank or insurer, you must tell the financial regulator where in the world your cloud region is. Do that 15 days before you switch it on.
- What you have to do here:
- Get a parent's consent for children · Written vendor contract · Put a transfer safeguard in place
(1) Children. Decree 1377 of 2013 starts from a ban on using the data of children and teenagers. The ban lifts only where the data is public in nature. The use must respect the child's best interests and basic rights. The legal representative must authorise it after the child has been heard. Colombia treats everyone under 18 as a child. There is no lower digital consent age as in Europe. The regulator's August 2026 university guidance opens one narrow gap. Teenagers over 14 can authorise the use of their own data where that is needed to get access to education. (2) The presumed approval trap. Signing a transfer contract does not by itself make a transfer lawful. The circular presumes a Declaration of Conformity only if you have first written to the regulator's data protection division. Your letter must describe the transfer and state that the contract exists. The regulator can check at any time and investigate if it finds otherwise. (3) Transfer versus transmission. Sending data to a supplier who handles it for you needs no consent and no notice to the individual. But that only holds if you have a contract meeting article 25 of Decree 1377. The contract must bind the supplier to the privacy principles, to security and to confidentiality. Sending data to another organisation for its own purposes is a transfer. Then the article 26 rules apply in full. (4) Advanced cryptography does not make data anonymous. In its 2026 decision the regulator rejected the argument that an iris code stopped being personal data. The code was encrypted and split across nodes using secure multi-party computation. The regulator held that the system could still recognise someone already registered. So the link to an identifiable person survived. (5) Financial cloud notice in advance. Supervised financial firms must report to the Financial Superintendency. Give the provider name, the subcontractors, the processes, and the physical location or region where data is handled and stored. Send it 15 days before you start. Changing cloud region is a regulatory event, not just an engineering one.
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalDecreto 1377 de 2013, articles 12, 24 and 25
alcaldiabogota.gov.co
“El Tratamiento de datos personales de niños, niñas y adolescentes está prohibido, excepto cuando se trate de datos de naturaleza pública.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioSIC guidance on personal data in the university context, 13 August 2026
sedeelectronica.sic.gov.co
“los adolescentes mayores de 14 años pueden autorizar el tratamiento de sus propios datos cuando sea necesario para garantizar su acceso al servicio público de educación”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioSIC decision on World Foundation and Tools for Humanity, Resolution 45710 of 18 June 2026
sedeelectronica.sic.gov.co
“the adoption of advanced cryptographic mechanisms—applied after collection—does not render the information anonymous”
Link checked 18 August 2026
- Official sourceSuperintendencia Financiera de ColombiaCircular Básica Jurídica, Parte I, Título I, Capítulo VI, numeral 6 — pre-notification of cloud processing
superfinanciera.gov.co
“Dentro de los 15 días anteriores al inicio del procesamiento de información en la nube ... 6.3. La ubicación física o región donde se procesarán y almacenarán los datos.”
Link checked 18 August 2026
What's changing next
The regulator is openly discussing a rewrite of the 2012 privacy law. It is talk so far, not law. The regulator's leadership says it wants stronger powers, more staff and more budget. It has named biometric data, identity fraud and artificial intelligence as its priorities for the coming months. In finance, the open finance technology and security standards are being phased in. The start date has already been pushed back once.
Do not plan around the reform as if it were law. As at 18 August 2026 the regulator calls it a debate and a roadmap. It is not an enacted statute. We found no adopted replacement for Law 1581 of 2012 on an official source. Four things matter more, because each can change with no new law and no consultation. (1) The country list. The circular says plainly that the Superintendency may review the list at any time. It can add countries or remove any it chooses. A destination you rely on today, including the United States, can be dropped by circular. (2) The standards used to judge countries. The six tests in numeral 3.1 are the regulator's own. It can restate them. (3) Security instructions. Article 19 of Decree 1377 of 2013 gives the Superintendency an open mandate to issue instructions on security measures. That is the same power that produced the 15-working-day breach reporting rule. (4) Financial sector timing. The Financial Superintendency issued a 2026 circular extending the start date of the open finance architecture, security and technology standards. Those were set by its External Circular 013 of 2025.
Sources
- Official sourceSuperintendencia de Industria y ComercioArtificial intelligence, new technologies and reform of Law 1581 dominated the XIII international data protection congress, 30 July 2026
sedeelectronica.sic.gov.co
“El congreso también retomó el debate sobre la actualización de la Ley 1581 de 2012, la regulación de las nuevas tecnologías y los asuntos que requerirán especial atención en los próximos meses”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V, numeral 3.2 — power to revise the country list at any time
sic.gov.co
“La Superintendencia de Industria y Comercio ejercerá, en cualquier tiempo, su capacidad regulatoria para revisar la lista anterior y proceder a incluir a quienes no hacen parte de la misma o para excluir a quien se considere conveniente.”
Link checked 18 August 2026
- Official sourceSuperintendencia Financiera de ColombiaCirculares Externas 2026 — extension of the entry into force of External Circular 013 of 2025 (open finance standards)
superfinanciera.gov.co
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: Circular Básica Jurídica, Parte I, Título I, Capítulo VI — Reglas relativas al uso de servicios de computación en la nube · Added by Circular Externa 005 of 11 March 2019; Circular Básica Jurídica currently re-issued as C.E. 006 of 2025 · Regulator directive
Banks, insurers, pension and trust companies and securities intermediaries may run everything in the cloud, including abroad. First you must check that the destination country's data protection and cybercrime laws match or beat Colombia's. You must also tell the financial regulator the provider and the physical region 15 days in advance. The regulator must be able to reach the systems if the firm is taken over.
Enforced by Financial Superintendency of Colombia
How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Certification scheme
What you have to do
- Hold a security certificateThe cloud provider must hold and keep ISO 27001 as a minimum. It must follow ISO 27017 and 27018. It must produce SOC 1, SOC 2 and SOC 3 reports.
- Put a transfer safeguard in placeYou must check that every country where the data will be handled has data protection and computer crime laws equal to or stronger than Colombia's.
- Register or notifyTell the regulator 15 days before core or accounting work starts running in the cloud. Name the provider, the subcontractors, the processes, and the physical location or region where the data is handled and stored.
- Written vendor contractThe contract must say the data belongs to the supervised firm. It cannot be used for any other purpose. It must be securely erased when the contract ends.
- Make switching cloud provider possibleHave a plan for moving to another platform before you need it.
- Independent auditPick internal and external auditors who have the technical skill to assess cloud services.
Sources
- Official sourceSuperintendencia Financiera de ColombiaAnnex to External Circular 005 of 2019 — Parte I, Título I, Capítulo VI, Computación en la nube
superfinanciera.gov.co
“Establecer las medidas necesarias para garantizar que, en el evento de toma de posesión, la SFC, Fogafín, Fogacoop, o quienes éstas designen, puedan acceder a la información y a la administración de los sistemas de información que operan en la nube.”
Link checked 18 August 2026
- Official sourceSuperintendencia Financiera de ColombiaNormativa general — Circular Básica Jurídica (C.E. 006/25) and the 2019 circulars index
superfinanciera.gov.co
Link checked 18 August 2026
Payment data rules
Official name: Ley Estatutaria 1266 de 2008 (hábeas data financiero), modificada por la Ley Estatutaria 2157 de 2021 · Ley 1266 de 2008; article 13 amended by Ley 2157 de 2021; instructions in Circular Única, Título V, Capítulo Primero · Act of parliament
Credit reporting has its own law, separate from the general privacy law. It is still bound by the rules on sending data abroad. It sets exactly how long a bad payment record can follow someone. The regulator fines lenders that report a borrower without warning them first.
Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed
What you have to do
- Delete data after a period — 4 yearsWhere arrears ran two years or more, the negative record stays four years from the date the debt is settled. Where arrears ran under two years, it stays at most twice the length of the arrears.
- Keep data for a minimum period — 8 yearsWhere the debt is never paid, the negative record expires eight years after the arrears began.
- Let people correct their data
- Tell people what you doYou must warn the person before you file a negative report about them.
- Secure the data
Sources
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V, Capítulo Primero — hábeas data financiero, numeral 1.6
sic.gov.co
“el término de caducidad de los datos negativos de un Titular de información será de ocho (8) años contados a partir de la fecha en que entre en mora la obligación, tal como lo señala el parágrafo 1 del artículo 13 de la Ley Estatutaria 1266 de 2008, adicionado por la Ley Estatutaria 2157 de 2021”
Link checked 18 August 2026
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey 1581 de 2012, article 2(e) and article 26 paragraph 2 — carve-out for Ley 1266 databases, transfer rules still apply
alcaldiabogota.gov.co
“Las disposiciones contenidas en el presente artículo serán aplicables para todos los datos personales, incluyendo aquellos contemplados en la Ley 1266 de 2008.”
Link checked 18 August 2026
Health data rules
Official name: Resolución 1995 de 1999, por la cual se establecen normas para el manejo de la Historia Clínica · Resolución 1995 de 1999 · Directly binding regulation
The provider that created a Colombian medical record must archive it. The archive has three defined stages and follows national archive rules. We found no requirement that the records be stored inside Colombia. Medical data may also cross borders under the public health exception in the general privacy law.
Enforced by Ministry of Health and Social Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Important public interest, Explicit consent
What you have to do
- Keep records of how you use dataEvery healthcare provider must keep one clinical records archive in three stages. The stages are active, central and historical. Organise them under General Archive of the Nation rules.
- Keep data for a minimum periodKeep records for the period the law sets. If a provider is wound up, the liquidator must name who holds them for that period.
- Extra vendor secrecy termsThe provider that created the record keeps custody. Outsourcing storage does not move that responsibility.
Sources
- Official sourceMinisterio de Salud y Protección SocialResolución 1995 de 1999 — manejo de la Historia Clínica
minsalud.gov.co
“Todos los prestadores de servicios de salud, deben tener un archivo único de historias clínicas en las etapas de archivo de gestión, central e histórico.”
Link checked 18 August 2026
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey 1581 de 2012, article 26(b) — medical data exception to the transfer ban
alcaldiabogota.gov.co
“Intercambio de datos de carácter médico, cuando así lo exija el Tratamiento del Titular por razones de salud o higiene pública”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Ley Estatutaria 1581 de 2012, por la cual se dictan disposiciones generales para la protección de datos personales · Ley 1581 de 2012 · Act of parliament
Colombia's general privacy law. It runs on consent. It applies to the use of personal data in Colombia, even by companies with no presence there. It bans sending personal data to countries the regulator has not accepted as protecting it well enough. Fines apply only to private bodies. Public bodies are referred to the Attorney General instead.
Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims
What you have to do
- Get consentBy default you need the person's informed permission first. Record it so you can prove it later.
- Tell people what you do
- Let people see their dataFree of charge at least once a calendar month.
- Let people correct their data
- Let people delete their data
- Secure the data
- Put a transfer safeguard in place
- Publish a complaints contactYour privacy policy must name the person or team that handles requests, questions and complaints.
- Get a parent's consent for children — applies at: under 18This starts out banned. The child must be heard before the legal representative gives permission.
What it costs if you get it wrong
- Fixed maximum fine: 2.000 salarios mínimos mensuales legales vigentes — about $750 thousandAny breach by a private body; fines may be repeated while the breach continues
- Order to stop: Suspensión hasta por seis (6) meses; cierre temporal; cierre inmediato y definitivoContinuing breach, or any operation involving sensitive data
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalLey Estatutaria 1581 de 2012 — full consolidated text
alcaldiabogota.gov.co
“Multas de carácter personal e institucional hasta por el equivalente de dos mil (2.000) salarios mínimos mensuales legales vigentes al momento de la imposición de la sanción.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioProtección de Datos Personales — the authority's own portal
sic.gov.co
Link checked 18 August 2026
Children's data rules
Official name: Decreto 1377 de 2013, compilado en el Decreto Único Reglamentario 1074 de 2015 · Decreto 1377 de 2013 · Directly binding regulation
The regulation that makes the law workable. It splits two things apart. Sending data to a partner abroad is a 'transfer' and is tightly controlled. Sending it to a supplier abroad is a 'transmission' and is allowed on a contract. It also sets the maximum keeping time. And it starts from a ban on using children's data.
Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Standard contract clauses, Official 'this country is safe' decision
What you have to do
- Written vendor contractA supplier abroad may handle the data with no consent and no notice to the individual. You need a contract binding them to the privacy principles, to security and to confidentiality.
- Tell people what you doGive people either a full privacy policy or a short notice pointing to it. Do it by the time you collect the data at the latest.
- Delete data after a periodKeep data only as long as is reasonable and necessary. Then delete it, unless a law or contract says otherwise.
- Keep records of how you use dataWrite down your keeping and deletion procedures.
- Get a parent's consent for children — applies at: under 18
Sources
- Official sourceRégimen Legal de Bogotá, Secretaría Jurídica DistritalDecreto 1377 de 2013 — full text
alcaldiabogota.gov.co
“Una vez cumplida la o las finalidades del tratamiento y sin perjuicio de normas legales que dispongan lo contrario, el Responsable y el Encargado deberán proceder a la supresión de los datos personales en su posesión.”
Link checked 18 August 2026
Breach reporting rules
Official name: Circular Única de la Superintendencia de Industria y Comercio, Título V — Protección de datos personales · Capítulo Tercero added by Circular Externa 05 of 10 August 2017 (Diario Oficial 50321); country list amended by Circular Externa 08 of 2017 and Circular Externa 02 of 2018; registry chapter amended by Circular Externa 03 of 2018; version consulted 29 September 2022 · Regulator directive
This is the main rule on sending data abroad. It publishes the list of countries treated as protecting data well enough. That is 39 named countries, including the United States, plus everywhere the European Commission has approved. It sets the tests for judging other countries. It creates the Declaration of Conformity route. It also carries the national database registry rules and the 15-working-day breach reporting deadline.
Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed
What you have to do
- Register or notify — applies at: Companies and non-profits with total assets above 100,000 tax units, and all public bodiesYou must register in the Registro Nacional de Bases de Datos, the national database registry. Register a new database within two months of creating it.
- Report breaches to the regulator — within 360 hoursYou have 15 working days, roughly three calendar weeks. The clock starts when the incident is found and reaches the person or team responsible. If you are on the registry, report inside it. Everyone else uses the regulator's online form.
- Put a transfer safeguard in placeIf the destination is not on the list, you have four options. Fit an exception in the law. Show the country meets the published standards. Sign a transfer contract and write to the regulator first. Or get a Declaration of Conformity.
- Delete data after a period — 4 yearsCredit reporting. Where the arrears ran two years or more, negative records drop off four years after the debt is settled. If it is never settled, the record expires eight years after the arrears began.
Sources
- Official sourceSuperintendencia de Industria y ComercioCircular Única, Título V — Protección de datos personales, consolidated version of 29 September 2022
sic.gov.co
“Parágrafo Tercero: El simple tránsito transfronterizo de datos no comporta una transferencia de datos a terceros países.”
Link checked 18 August 2026
- Official sourceSuperintendencia de Industria y ComercioRegistro Nacional de Bases de Datos — scope after Decreto 090 de 2018
sic.gov.co
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the list of countries with an adequate level of protection has not changed since 29 September 2022
We could not confirm that the approved-country list is up to date. The version we read is dated 29 September 2022. The regulator's old circular archive shows nothing after December 2022, because the site moved. The new site's search returned no results for us. The list may have changed since, and the circular lets the regulator revise it at any time. Check the current list before you rely on a destination.
Whether online gambling operators licensed in Colombia must host their gaming platform or player data inside the country
We could not confirm whether gambling data must stay in Colombia. Countries nearby often have such a rule, and it would change our overall rating. We could not read the gambling regulator's documents. If you run gambling services, check with the regulator before you rely on this.
Whether telecoms operators face a data retention or in-country storage duty, and for how long
Many sources say Colombian intelligence and interception law makes telecom operators keep subscriber records for five years. We could not confirm this against a government source. If you are a telecom operator, check before you rely on it.
Whether public sector bodies face any cloud where data has to be stored requirement
We found no rule requiring government data to stay in Colombia. We looked at the Ministry of Information Technologies and Communications' own site and found only digital government material. Finding nothing is not proof that nothing exists. Check with the ministry if you supply government bodies.
The exact retention period for clinical records, and the current status of the interoperable electronic clinical record rules
We could not confirm how many years medical records must be kept. The 1999 resolution refers to the period provided by law without saying what it is. The 2021 health ministry resolution is a scanned image we could not read. Ask the health ministry if you hold clinical records.
The peso and dollar value of the maximum fine and of the 100,000 tax unit registration threshold
We could not confirm these amounts against an official source. They are tied to the 2026 monthly minimum wage and the 2026 tax unit value. We could not reach the labour ministry site and could not find the tax authority's figure. Treat the numbers here as rough only.
The exact numbering of the cloud computing chapter inside the Basic Legal Circular as re-issued in 2025
We could not confirm the current chapter number. We read the chapter as published with the 2019 circular that created it. The circular was re-issued as External Circular 006 of 2025, so the chapter may have been renumbered. We found no sign it was withdrawn. Check the current circular for the right reference.
Whether any bill to replace or amend the 2012 privacy law has been formally introduced in Congress, and its stage
We could not confirm that any reform bill exists in Congress. The regulator calls reform an active debate and its own priority. We found no adopted text and no bill number. Do not plan around this as if it were law.
The precise second and third breach reporting clocks for financial entities and for criminal matters
We could not confirm the financial regulator's own breach reporting deadline. It publishes information security and cyber indicators and supervises how firms handle incidents. If you are a supervised financial firm, ask the regulator for its deadline.
That the national statute text we relied on is identical to the official gazette version
We could not confirm this text against the national gazette. The national legal databases were unreachable for us. We used the Bogotá district government's official legal collection instead. That is a government source, but it is not the national gazette.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.