Skip to main content

Privacy Policy (Política de Tratamiento de Datos) Colombia

Política de Privacidad y Tratamiento de Datos Personales Colombia

Ley 1581 de 2012 — Decreto 1377 de 2013 — SIC

POLÍTICA DE PRIVACIDAD Y TRATAMIENTO DE DATOS PERSONALES

Ley 1581 de 2012 — Decreto 1377 de 2013 — Superintendencia de Industria y Comercio (SIC)

1. RESPONSABLE DEL TRATAMIENTO

[Nombre Empresa], identificada con NIT [NIT], con domicilio en [Domicilio], correo electrónico de privacidad: [Correo Privacidad], teléfono de atención: [Teléfono Atención].

2. MARCO LEGAL

La presente política se expide en cumplimiento de la Ley Estatutaria 1581 de 2012 (por la cual se dictan disposiciones generales para la protección de datos personales), el Decreto Reglamentario 1377 de 2013, el Decreto Único Reglamentario 1074 de 2015 (Libro 2, Parte 2, Título 3), y las instrucciones de la Superintendencia de Industria y Comercio (SIC) como autoridad de protección de datos en Colombia.

3. DATOS PERSONALES TRATADOS Y FINALIDADES

Categorías de datos tratados: [Categorías Datos]

Finalidades del tratamiento: [Finalidades]

4. DERECHOS DE LOS TITULARES

De conformidad con la Ley 1581 de 2012, los titulares de datos personales tienen los siguientes derechos: (i) conocer, actualizar y rectificar sus datos; (ii) solicitar prueba de la autorización otorgada; (iii) ser informados sobre el uso de sus datos; (iv) presentar quejas ante la SIC; (v) revocar la autorización y/o solicitar la supresión de sus datos; y (vi) acceder gratuitamente a sus datos.

Procedimiento para ejercer derechos: [Procedimiento Derechos]

5. TRANSFERENCIAS Y TRANSMISIONES

Terceros destinatarios de datos: [Terceros Destinatarios]

6. MEDIDAS DE SEGURIDAD

[Nombre Empresa] implementa medidas técnicas, humanas y administrativas necesarias para garantizar la seguridad de los datos personales y evitar su adulteración, pérdida, consulta, uso o acceso no autorizado, conforme al Artículo 17 literal e) de la Ley 1581 de 2012.

7. VIGENCIA

La presente política rige a partir del [Fecha Vigencia] y corresponde a la [Versión]. Cualquier modificación sustancial será informada a los titulares con al menos diez (10) días hábiles de antelación.

Expedida en [Ciudad], el [Fecha Vigencia].

[Nombre Empresa]

NIT: [NIT]

Representante Legal (Legal Representative)

________________

Signature

Maintained by Vladislav Sergienko, Founder·Template last modified: ·Report an error

What Is a Privacy Policy (Política de Tratamiento de Datos) Colombia?

A Privacy Policy (Política de Tratamiento de Datos Personales) in Colombia is the mandatory legal document required by Law 1581 of 2012 (Personal Data Protection Statute) through which the Data Controller informs data subjects about: processing purposes, legal basis, retention periods, recipients, data subject rights, and mechanisms to exercise them. Mandatory for any person or entity that collects, stores, uses, circulates, or deletes personal data of Colombian residents, whether the controller is domiciled in Colombia or abroad. Law 1581/2012 establishes eight governing principles (article 4): legality, purpose limitation, freedom (prior consent required), accuracy, transparency, restricted access and circulation, security, and confidentiality. The SIC (Superintendencia de Industria y Comercio) supervises compliance and can impose fines up to 2,000 SMMLV. The National Database Registry (RNBD) requires registration by controllers processing data from more than 5,000 holders.

The legal framework governing the Privacy Policy (Política de Tratamiento de Datos) Colombia in Colombia draws on several key statutes and regulatory bodies. Under the Constitucion Politica de 1991, Colombian administrative law governs government procedures. The DIAN administers tax declarations (RUT, IVA, Renta, Retencion). The Codigo de Procedimiento Administrativo (CPACA, Ley 1437 de 2011) governs administrative proceedings. The Accion de Tutela (art. 86) protects fundamental rights through the Corte Constitucional. The Defensoria del Pueblo assists citizens. Parties executing a Privacy Policy (Política de Tratamiento de Datos) Colombia in Colombia should confirm the document reflects current law, including any amendments enacted since the original drafting date. The Ley 1581/2012; Decreto 1377/2013 sets the foundational requirements.

When Do You Need a Privacy Policy (Política de Tratamiento de Datos) Colombia?

A Privacy Policy is mandatory in Colombia for every company, startup, independent professional, NGO, or public entity that collects, stores, uses, processes, or shares personal data of Colombian individuals. It is especially critical for: websites and mobile apps collecting Colombian user data (requiring prior explicit consent under Law 1581/2012); companies with databases of customers, suppliers, workers, or visitors (those with 5,000+ holders must register with the SIC's RNBD); e-commerce platforms processing financial and payment data; health, education, or insurance companies processing sensitive data (requiring reinforced protection under art. 6 of Law 1581/2012); companies transferring data internationally (article 26 of Law 1581/2012 requires specific guarantees); and employers managing candidate and employee data under SIC guidelines for employment data processing.

Parties in Colombia should prepare a Privacy Policy (Política de Tratamiento de Datos) Colombia proactively rather than waiting for a dispute to arise. Courts interpret agreements based on the written terms rather than oral representations. Under the Constitucion Politica de 1991, Colombian administrative law governs government procedures. The DIAN administers tax declarations (RUT, IVA, Renta, Retencion). The Codigo de Procedimiento Administrativo (CPACA, Ley 1437 de 2011) governs administrative proceedings. The Accion de Tutela (art. 86) protects fundamental rights through the Corte Constitucional. The Defensoria del Pueblo assists citizens. Where the transaction involves regulated activities, prior approval from the relevant authority may be required before execution.

What to Include in Your Privacy Policy (Política de Tratamiento de Datos) Colombia

A valid Colombian Privacy Policy compliant with Law 1581/2012 and Decree 1377/2013 must include: complete Data Controller identification with NIT, physical address, and dedicated Habeas Data contact email; exhaustive list of specific processing purposes; categories of personal data collected including sensitive data with reinforced protection under art. 6 of Law 1581/2012; lawful basis for each processing purpose (consent, legal obligation, contract, vital interest, legitimate interest); data subject rights and exercise procedures (15-business-day response deadlines under art. 22); consent collection mechanism (prior, express, and informed); third-party sharing and international transfer safeguards under art. 26 of Law 1581/2012; security measures (technical, organizational, legal); retention periods aligned with legal obligations; policy update procedure; and effective date and version number. The forms-legal.com Privacy Policy (Política de Tratamiento de Datos) Colombia template covers the mandatory elements under Ley 1581/2012; Decreto 1377/2013.

Additional compliance elements for a Privacy Policy (Política de Tratamiento de Datos) Colombia used in Colombia include: Under the Constitucion Politica de 1991, Colombian administrative law governs government procedures. The DIAN administers tax declarations (RUT, IVA, Renta, Retencion). The Codigo de Procedimiento Administrativo (CPACA, Ley 1437 de 2011) governs administrative proceedings. The Accion de Tutela (art. 86) protects fundamental rights through the Corte Constitucional. The Defensoria del Pueblo assists citizens. Forms-legal.com provides this template as a starting point for Colombia-compliant documentation.

Cite this page

Reference this free template in an article, syllabus, or research note:

APA

Forms Legal. (2026). Privacy Policy (Política de Tratamiento de Datos) Colombia (Colombia) [Legal document template]. Forms Legal. https://forms-legal.com/colombia/government/declarations/privacy-policy-data-protection-colombia

MLA

"Privacy Policy (Política de Tratamiento de Datos) Colombia (Colombia)." Forms Legal, 2026, https://forms-legal.com/colombia/government/declarations/privacy-policy-data-protection-colombia.

BibTeX
@misc{formslegal-privacy-policy-data-protection-colombia,
  author       = {{Forms Legal}},
  title        = {Privacy Policy (Política de Tratamiento de Datos) Colombia (Colombia)},
  year         = {2026},
  howpublished = {\url{https://forms-legal.com/colombia/government/declarations/privacy-policy-data-protection-colombia}},
  note         = {Free legal document template}
}

Also available for these jurisdictions:

Frequently Asked Questions

Statute-referenced template — Template last modified June 2026

This template is provided for informational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change over time. Consult a qualified attorney for advice specific to your situation.Full disclaimer

Found an error? Let us know