Skip to the content
Global Data RulesData governance rules, country by country

Colombia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: MediumEnforcement: Active

Colombia does not force you to keep data inside the country. But sending personal data abroad is banned unless the destination is on an approved list, you fit an exception, or you sign a transfer contract and write to the regulator. The list is long and includes the United States. The regulator is fully staffed, fines companies most months, and in 2026 shut a foreign biometric operation for good.

Data governance in Colombia

The eight things that decide how you handle data about people in Colombia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a foreign company with no office, no branch and no local representative in Colombia, as long as it handles people's data inside Colombian territory. The regulator said exactly that in 2026 when it shut down a foreign iris-scanning operation and rejected the argument that it was out of reach. There is no size or revenue threshold that lets you escape the law itself.

High confidenceNational rulesControllerProcessor

Where the data is allowed to live

Yes, with paperwork. Nothing has to stay in Colombia. But the starting point in the law is a ban: you may not send personal data to a country that does not protect it well enough. The regulator publishes a list of countries that do. If your destination is on that list you can send data. If it is not, you need an exception, or a signed transfer contract plus a letter to the regulator, or the regulator's own approval.

High confidenceYes, with paperworkAllowlistFinanceHealth and social care

Sending data out of the country

The model is an approved list, and the list is genuinely full. Thirty-nine countries are named, plus every country Europe has approved. The United States is on it, which surprises people. If your destination is not listed you have four routes: an exception in the law, showing the country meets the published standards anyway, signing a transfer contract and writing to the regulator, or asking the regulator for a formal approval.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesGovernment sign-off neededExplicit consentNeeded for a contractImportant public interestLegal claimsWritten vendor contract

The regulator, and whether it actually acts

The Superintendency of Industry and Commerce, through its Delegate Office for Personal Data Protection. It is real, staffed and busy. It published data protection penalty decisions in every month of 2026 that we checked, it runs an annual national conference, and in June 2026 it confirmed on appeal an order permanently shutting down a foreign company's biometric operation in Colombia. Banks and insurers answer to a second regulator, the Financial Superintendency, for their technology and cloud arrangements.

High confidenceActiveRegulator

How long you must keep it — and when to delete it

Colombia sets a ceiling more clearly than a floor. You may keep personal data only for as long as is reasonable and necessary for the purpose you collected it for, and then you must delete it unless a law or contract says otherwise. The sharpest fixed limits are in credit reporting: a bad payment record drops off four years after the debt is cleared, and eight years after the debt first went unpaid even if it never is. Medical records must be kept and archived under national archive rules.

Medium confidenceDelete data after a periodKeep data for a minimum periodKeep records of processing

If something goes wrong

Colombia's main breach clock is unusually generous: 15 working days, roughly three calendar weeks, from the moment the incident reaches the person or team responsible for handling it. Companies large enough to be on the national database register report through that register. Everyone else reports through the regulator's online form. There is no general duty to tell the affected people, though the regulator can order it.

High confidenceReport breaches to the regulatorSecure the data

What catches people out

Five things that cost people their weekend. A child is anyone under 18, and processing their data starts from a position of being banned. The transfer contract route only works if you actually write to the regulator first. Sending data to a supplier abroad is treated as a different animal from sending it to a partner, with different paperwork. Encrypting or splitting biometric data does not make it stop being personal data. And if you are a bank or insurer, you must tell the financial regulator where in the world your cloud region is, 15 days before you switch it on.

High confidenceGet a parent's consent for childrenWritten vendor contractPut a transfer safeguard in placeBiometric dataChildren's data

What's changing next

A rewrite of the 2012 privacy law is being openly discussed by the regulator itself, but it is talk and not yet a binding law. The regulator's own leadership says it wants stronger powers, more staff and more budget, and has named biometric data, identity fraud and artificial intelligence as the priorities for the coming months. In the financial sector, the open finance technology and security standards are being phased in, and the start date has already been pushed back once.

Medium confidenceIn forceRegulator directive

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Circular Básica Jurídica, Parte I, Título I, Capítulo VI — Reglas relativas al uso de servicios de computación en la nube

Regulator directive · Added by Circular Externa 005 of 11 March 2019; Circular Básica Jurídica currently re-issued as C.E. 006 of 2025

In forceYes, with paperwork

Banks, insurers, pension and trust companies and securities intermediaries may run everything in the cloud, including abroad, but only after checking that the destination country's data protection and cybercrime laws match or beat Colombia's, and only after telling the financial regulator the provider and the physical region 15 days in advance. The regulator must also be able to reach the systems if the entity is taken over.

In force since 11 March 2019

Enforced by Financial Superintendency of Colombia

Transfer model: Approval each time · Accepted routes: Security review needed, Certification scheme

Medium confidence
Finance

Ley Estatutaria 1266 de 2008 (hábeas data financiero), modificada por la Ley Estatutaria 2157 de 2021

Act of parliament · Ley 1266 de 2008; article 13 amended by Ley 2157 de 2021; instructions in Circular Única, Título V, Capítulo Primero

In forceYes, with paperwork

Credit reporting has its own statute, carved out of the general privacy law but still bound by its transfer rules. It fixes exactly how long a bad payment record may follow someone, and the regulator fines lenders that report without warning the borrower first.

In force since 31 December 2008But only enforceable from 1 January 2009

Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed

Medium confidence
Health and social care

Resolución 1995 de 1999, por la cual se establecen normas para el manejo de la Historia Clínica

Directly binding regulation · Resolución 1995 de 1999

In forceYes, with paperwork

Colombian medical records must be archived by the provider that created them, in a defined three-stage archive under national archive rules. No requirement was found that they be stored inside Colombia. Medical data may also cross borders under the public health exception in the general privacy law.

In force since 8 July 1999

Enforced by Ministry of Health and Social Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Important public interest, Explicit consent

Medium confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Ley Estatutaria 1581 de 2012, por la cual se dictan disposiciones generales para la protección de datos personales

Act of parliament · Ley 1581 de 2012

In forceYes, with paperwork

Colombia's general privacy statute. Consent-led, applies to processing carried out in Colombia even by companies with no presence there, and bans sending personal data to countries the regulator has not accepted as offering adequate protection. Fines apply only to private bodies; public bodies are referred to the Attorney General instead.

In force since 17 October 2012But only enforceable from 17 April 2013

Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims

High confidence

Decreto 1377 de 2013, compilado en el Decreto Único Reglamentario 1074 de 2015

Directly binding regulation · Decreto 1377 de 2013

In forceYes, with paperwork

The regulation that makes the statute workable. It separates sending data to a partner abroad (a transfer, tightly controlled) from sending it to a supplier abroad (a transmission, allowed on a contract), sets the retention ceiling, and starts from a ban on processing children's data.

In force since 27 June 2013

Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection

Transfer model: Allowlist · Accepted routes: Standard contract clauses, Official 'this country is safe' decision

High confidence

Circular Única de la Superintendencia de Industria y Comercio, Título V — Protección de datos personales

Regulator directive · Capítulo Tercero added by Circular Externa 05 of 10 August 2017 (Diario Oficial 50321); country list amended by Circular Externa 08 of 2017 and Circular Externa 02 of 2018; registry chapter amended by Circular Externa 03 of 2018; version consulted 29 September 2022

In forceYes, with paperwork

The operative transfer instrument. It publishes the list of countries deemed to protect data adequately — 39 named countries including the United States, plus everywhere the European Commission has approved — sets the criteria for judging others, and creates the Declaration of Conformity route. It also carries the national database registry rules and the 15-working-day breach reporting deadline.

In force since 10 August 2017

Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed

High confidence

Who you would hear from

  • Superintendencia de Industria y Comercio, Delegatura para la Protección de Datos Personales

    National data protection authority: general privacy law, credit reporting, the national database registry, breach reporting and international transfer approvals

    Fully operational and visibly busy as at 18 August 2026. Serving Delegate Superintendent Juan Carlos Upegui presented a 2022-2026 record of work in July 2026. Penalty resolutions were published in February, March, May and later months of 2026. In June 2026 it dismissed the appeal of World Foundation and Tools for Humanity and confirmed the permanent shutdown of their biometric operation in Colombia. Note the structural gap: it cannot fine public bodies, only refer them.

  • Superintendencia Financiera de Colombia

    Banks, insurers, pension and trust companies, securities intermediaries: cloud use, outsourcing, information security and open finance standards

    Active. Re-issued its Basic Legal Circular as External Circular 006 of 2025 and its Basic Financial Circular as External Circular 004 of 2026, and issued a 2026 circular extending the start date of the open finance technology and security standards.

  • Ministerio de Salud y Protección Social

    Clinical records, health information systems

  • Procuraduría General de la Nación

    Receives referrals where a public body breaches the privacy law, because the fine regime does not apply to public bodies

    Role inferred from the paragraph to article 23 of Law 1581 of 2012. We did not verify how many privacy referrals it has actually acted on.

  • Empresa Industrial y Comercial del Estado Administradora del Monopolio Rentístico de los Juegos de Suerte y Azar

    Online and land-based gambling licensing

    Operating, but we could not open its rulebook for internet-operated games within this research budget, so no gambling data rule is asserted in this record.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the list of countries with an adequate level of protection has not changed since 29 September 2022

    The consolidated Title V we read is dated 29 September 2022 and the regulator's old circular repository shows no entries after December 2022, apparently because the site was migrated to a new electronic office. The new site's norm search returned no results for us. The list may have been amended since; the circular expressly lets the regulator revise it at any time.

  • Whether online gambling operators licensed in Colombia must host their gaming platform or player data inside the country

    This is a common localisation rule in the region and would change the headline rating if true. The gambling regulator's document listings would not render for us. No official text was obtained, so no rule is asserted either way.

  • Whether telecoms operators face a data retention or in-country storage duty, and for how long

    Colombian intelligence and interception legislation is widely reported to require operators to keep subscriber records for five years. We could not open the operative text on an official government source within this research budget. Not asserted.

  • Whether public sector bodies face any cloud data residency requirement

    We reviewed the Ministry of Information Technologies and Communications' own site and found digital government material but no residency instruction. Absence of a finding is not proof of absence.

  • The exact retention period for clinical records, and the current status of the interoperable electronic clinical record rules

    The 1999 resolution points to 'the period provided by law' without stating it, and the 2021 resolution we downloaded from the health ministry is a scanned image our tools could not read.

  • The peso and dollar value of the maximum fine and of the 100,000 tax unit registration threshold

    These are pegged to the 2026 monthly minimum wage and the 2026 tax unit value. Neither was verified on an official source, because the labour ministry site refused our connection and the tax authority's figure was not located. The figures given are approximations only.

  • The exact numbering of the cloud computing chapter inside the Basic Legal Circular as re-issued in 2025

    We read the chapter as published with the 2019 circular that created it. The circular was re-issued as External Circular 006 of 2025 and the chapter may have been renumbered, though we found no sign it was withdrawn.

  • Whether any bill to replace or amend the 2012 privacy law has been formally introduced in Congress, and its stage

    The regulator describes reform as an active debate and its own priority. We found no adopted text and did not verify any specific bill number in Congress. Nothing here should be planned around as binding.

  • The precise second and third breach reporting clocks for financial entities and for criminal matters

    The financial regulator publishes information security and cyber indicators and supervises incident handling, but we did not open the operative reporting deadline within this research budget.

  • That the national statute text we relied on is identical to the official gazette version

    The national legal databases we would normally use for the gazette copy were unreachable from our network. We used the Bogotá district government's official legal compilation instead, which is a government source but not the national gazette.

60-day cadence. Two dormant switches justify it: the regulator can revise the approved-country list at any time by circular with no consultation, and it holds an open mandate to issue new security instructions. A rewrite of the 2012 statute is also being actively promoted by the regulator itself.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Colombia versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.