Skip to the content
Global Data RulesData governance rules, country by country

Colombia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Colombia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Active

Colombia does not force you to keep data inside the country. But you may not send personal data abroad unless one of three things is true. The destination country is on Colombia's approved list. Or your situation fits an exception in the law. Or you sign a transfer contract and write to the regulator first. The approved list is long and includes the United States. The regulator is fully staffed and fines companies most months. In 2026 it shut down a foreign biometric operation for good.

Data governance in Colombia

The eight things that decide how you handle data about people in Colombia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law applies to a foreign company with no office, no branch and no representative in Colombia. What matters is that you handle people's data inside Colombia. The regulator said exactly that in 2026. It shut down a foreign iris-scanning operation and rejected the claim that it was out of reach. There is no size or revenue limit that gets you out of the law itself.

Where the data is allowed to live

Yes, with paperwork. Nothing has to stay in Colombia. The law starts from a ban. You may not send personal data to a country that does not protect it well enough. The regulator publishes a list of countries that do. If your destination is on that list, you can send the data. If it is not, you have three options. Fit an exception in the law. Or sign a transfer contract and write to the regulator. Or get the regulator's own approval.

What to do: Get the paperwork for one of the routes below signed before any data leaves Colombia.

Sending data out of the country

Colombia uses an approved list, and it is a long one. Thirty-nine countries are named. Every country Europe has approved also counts. The United States is on the list. If your destination is not listed, you have four routes. Fit an exception in the law. Or show the country meets the published standards anyway. Or sign a transfer contract and write to the regulator. Or ask the regulator for a formal approval.

What you have to do here:
Written vendor contract
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Government sign-off needed · Explicit consent · Needed for a contract · Important public interest · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Superintendency of Industry and Commerce enforces, through its Delegate Office for Personal Data Protection. It is real, staffed and busy. It published privacy penalty decisions in every month of 2026 that we checked. It runs an annual national conference. In June 2026 it confirmed on appeal an order permanently shutting down a foreign company's biometric operation in Colombia. Banks and insurers answer to a second regulator, the Financial Superintendency, for their technology and cloud arrangements.

How long you must keep it — and when to delete it

Colombia is clearer about maximum keeping times than minimum ones. You may keep personal data only as long as is reasonable and necessary for the purpose you collected it for. After that you must delete it, unless a law or contract says otherwise. The sharpest fixed limits are in credit reporting. A bad payment record drops off four years after the debt is cleared. If the debt is never cleared, it drops off eight years after it first went unpaid. Medical records must be kept and archived under national archive rules.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Colombia gives you 15 working days, which is roughly three calendar weeks. The clock starts when the incident reaches the person or team responsible for handling it. Companies large enough to be on the national database register report through that register. Everyone else reports through the regulator's online form. There is no general duty to tell the affected people, though the regulator can order it.

What you have to do here:
Report breaches to the regulator · Secure the data

What to do: Your breach process has to reach Colombia's regulator inside the deadline above.

What catches people out

Five things catch people out. A child is anyone under 18, and using their data starts out banned. The transfer contract route only works if you write to the regulator first. Sending data to a supplier abroad is treated differently from sending it to a partner, with different paperwork. Encrypting or splitting biometric data does not stop it being personal data. And if you are a bank or insurer, you must tell the financial regulator where in the world your cloud region is. Do that 15 days before you switch it on.

What you have to do here:
Get a parent's consent for children · Written vendor contract · Put a transfer safeguard in place

What's changing next

The regulator is openly discussing a rewrite of the 2012 privacy law. It is talk so far, not law. The regulator's leadership says it wants stronger powers, more staff and more budget. It has named biometric data, identity fraud and artificial intelligence as its priorities for the coming months. In finance, the open finance technology and security standards are being phased in. The start date has already been pushed back once.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Cloud and outsourcing rules

Official name: Circular Básica Jurídica, Parte I, Título I, Capítulo VI — Reglas relativas al uso de servicios de computación en la nube · Added by Circular Externa 005 of 11 March 2019; Circular Básica Jurídica currently re-issued as C.E. 006 of 2025 · Regulator directive

In forceYes, with paperwork

Banks, insurers, pension and trust companies and securities intermediaries may run everything in the cloud, including abroad. First you must check that the destination country's data protection and cybercrime laws match or beat Colombia's. You must also tell the financial regulator the provider and the physical region 15 days in advance. The regulator must be able to reach the systems if the firm is taken over.

In force since 11 March 2019

Enforced by Financial Superintendency of Colombia

How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Certification scheme

Not fully verified — see “What we're not sure about” below.
Finance

Payment data rules

Official name: Ley Estatutaria 1266 de 2008 (hábeas data financiero), modificada por la Ley Estatutaria 2157 de 2021 · Ley 1266 de 2008; article 13 amended by Ley 2157 de 2021; instructions in Circular Única, Título V, Capítulo Primero · Act of parliament

In forceYes, with paperwork

Credit reporting has its own law, separate from the general privacy law. It is still bound by the rules on sending data abroad. It sets exactly how long a bad payment record can follow someone. The regulator fines lenders that report a borrower without warning them first.

In force since 31 December 2008Enforced from 1 January 2009

Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Health and social care

Health data rules

Official name: Resolución 1995 de 1999, por la cual se establecen normas para el manejo de la Historia Clínica · Resolución 1995 de 1999 · Directly binding regulation

In forceYes, with paperwork

The provider that created a Colombian medical record must archive it. The archive has three defined stages and follows national archive rules. We found no requirement that the records be stored inside Colombia. Medical data may also cross borders under the public health exception in the general privacy law.

In force since 8 July 1999

Enforced by Ministry of Health and Social Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Important public interest, Explicit consent

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Ley Estatutaria 1581 de 2012, por la cual se dictan disposiciones generales para la protección de datos personales · Ley 1581 de 2012 · Act of parliament

In forceYes, with paperwork

Colombia's general privacy law. It runs on consent. It applies to the use of personal data in Colombia, even by companies with no presence there. It bans sending personal data to countries the regulator has not accepted as protecting it well enough. Fines apply only to private bodies. Public bodies are referred to the Attorney General instead.

In force since 17 October 2012Enforced from 17 April 2013

Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims

Children's data rules

Official name: Decreto 1377 de 2013, compilado en el Decreto Único Reglamentario 1074 de 2015 · Decreto 1377 de 2013 · Directly binding regulation

In forceYes, with paperwork

The regulation that makes the law workable. It splits two things apart. Sending data to a partner abroad is a 'transfer' and is tightly controlled. Sending it to a supplier abroad is a 'transmission' and is allowed on a contract. It also sets the maximum keeping time. And it starts from a ban on using children's data.

In force since 27 June 2013

Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Standard contract clauses, Official 'this country is safe' decision

Breach reporting rules

Official name: Circular Única de la Superintendencia de Industria y Comercio, Título V — Protección de datos personales · Capítulo Tercero added by Circular Externa 05 of 10 August 2017 (Diario Oficial 50321); country list amended by Circular Externa 08 of 2017 and Circular Externa 02 of 2018; registry chapter amended by Circular Externa 03 of 2018; version consulted 29 September 2022 · Regulator directive

In forceYes, with paperwork

This is the main rule on sending data abroad. It publishes the list of countries treated as protecting data well enough. That is 39 named countries, including the United States, plus everywhere the European Commission has approved. It sets the tests for judging other countries. It creates the Declaration of Conformity route. It also carries the national database registry rules and the 15-working-day breach reporting deadline.

In force since 10 August 2017

Enforced by Superintendency of Industry and Commerce — Delegate Office for Personal Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Government sign-off needed

Who you would hear from

  • Superintendencia de Industria y Comercio, Delegatura para la Protección de Datos Personales

    National data protection authority: general privacy law, credit reporting, the national database registry, breach reporting and international transfer approvals

    Fully operational and visibly busy as at 18 August 2026. Delegate Superintendent Juan Carlos Upegui presented a record of work for 2022 to 2026 in July 2026. Penalty decisions were published in February, March, May and later months of 2026. In June 2026 it dismissed the appeal of World Foundation and Tools for Humanity. It confirmed the permanent shutdown of their biometric operation in Colombia. There is one gap. It cannot fine public bodies. It can only refer them.

  • Superintendencia Financiera de Colombia

    Banks, insurers, pension and trust companies, securities intermediaries: cloud use, outsourcing, information security and open finance standards

    Active. It re-issued its Basic Legal Circular as External Circular 006 of 2025. It re-issued its Basic Financial Circular as External Circular 004 of 2026. It also issued a 2026 circular extending the start date of the open finance technology and security standards.

  • Ministerio de Salud y Protección Social

    Clinical records, health information systems

  • Procuraduría General de la Nación

    Receives referrals where a public body breaches the privacy law, because the fine regime does not apply to public bodies

    We worked out its role from the paragraph to article 23 of Law 1581 of 2012. We did not check how many privacy referrals it has acted on.

  • Empresa Industrial y Comercial del Estado Administradora del Monopolio Rentístico de los Juegos de Suerte y Azar

    Online and land-based gambling licensing

    It is operating. We could not confirm its rulebook for internet games against an official source. So this record makes no claim about gambling data rules.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the list of countries with an adequate level of protection has not changed since 29 September 2022

    We could not confirm that the approved-country list is up to date. The version we read is dated 29 September 2022. The regulator's old circular archive shows nothing after December 2022, because the site moved. The new site's search returned no results for us. The list may have changed since, and the circular lets the regulator revise it at any time. Check the current list before you rely on a destination.

  • Whether online gambling operators licensed in Colombia must host their gaming platform or player data inside the country

    We could not confirm whether gambling data must stay in Colombia. Countries nearby often have such a rule, and it would change our overall rating. We could not read the gambling regulator's documents. If you run gambling services, check with the regulator before you rely on this.

  • Whether telecoms operators face a data retention or in-country storage duty, and for how long

    Many sources say Colombian intelligence and interception law makes telecom operators keep subscriber records for five years. We could not confirm this against a government source. If you are a telecom operator, check before you rely on it.

  • Whether public sector bodies face any cloud where data has to be stored requirement

    We found no rule requiring government data to stay in Colombia. We looked at the Ministry of Information Technologies and Communications' own site and found only digital government material. Finding nothing is not proof that nothing exists. Check with the ministry if you supply government bodies.

  • The exact retention period for clinical records, and the current status of the interoperable electronic clinical record rules

    We could not confirm how many years medical records must be kept. The 1999 resolution refers to the period provided by law without saying what it is. The 2021 health ministry resolution is a scanned image we could not read. Ask the health ministry if you hold clinical records.

  • The peso and dollar value of the maximum fine and of the 100,000 tax unit registration threshold

    We could not confirm these amounts against an official source. They are tied to the 2026 monthly minimum wage and the 2026 tax unit value. We could not reach the labour ministry site and could not find the tax authority's figure. Treat the numbers here as rough only.

  • The exact numbering of the cloud computing chapter inside the Basic Legal Circular as re-issued in 2025

    We could not confirm the current chapter number. We read the chapter as published with the 2019 circular that created it. The circular was re-issued as External Circular 006 of 2025, so the chapter may have been renumbered. We found no sign it was withdrawn. Check the current circular for the right reference.

  • Whether any bill to replace or amend the 2012 privacy law has been formally introduced in Congress, and its stage

    We could not confirm that any reform bill exists in Congress. The regulator calls reform an active debate and its own priority. We found no adopted text and no bill number. Do not plan around this as if it were law.

  • The precise second and third breach reporting clocks for financial entities and for criminal matters

    We could not confirm the financial regulator's own breach reporting deadline. It publishes information security and cyber indicators and supervises how firms handle incidents. If you are a supervised financial firm, ask the regulator for its deadline.

  • That the national statute text we relied on is identical to the official gazette version

    We could not confirm this text against the national gazette. The national legal databases were unreachable for us. We used the Bogotá district government's official legal collection instead. That is a government source, but it is not the national gazette.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.