Regulatory update
SIC fines for lacking a personal data processing policy
Colombia's data protection authority, the Superintendencia de Industria y Comercio (SIC), can fine a company up to 2,000 monthly legal minimum wages, plus suspend or close its operations, for processing personal data without a data processing policy that meets Law 1581 of 2012. This is not a new rule or a theoretical risk: in 2025 the SIC opened 101 investigations, up from 83 in 2024 and 55 in 2023, and its rulings show the most common ground for sanction is not a sophisticated data breach, but simply not having the policy manual the law has required for over a decade.
Schedule a consultationThe rule in force, and a citation error that gives away who did not check it
The sanctioning regime sits in article 23 of Law 1581 of 2012: fines of up to 2,000 monthly legal minimum wages in force at the time of the sanction, plus suspension of up to six months, temporary closure, or immediate and permanent closure when sensitive data is involved. The decree regulating the minimum content of the data processing policy has not been Decree 1377 of 2013 since 2015: that decree was fully repealed and compiled into Decree 1074 of 2015, chapter 25 of the Commerce, Industry and Tourism book. Citing the 2013 decree as if it were still in force is the first mistake a colleague will catch when reading a legal opinion or a contract.
Five 2025 sanctions that show the pattern
These are real cases, with resolution numbers and amounts verified in each ruling's operative section.
The SIC sanctioned Confiar EES S.A.S. in liquidation (Resolution 24388 of 2025) with a six-month suspension of data processing for lacking both a policy that met the law and a security procedures manual. It fined Construcciones y Diseños Planificados S.A.S. (Resolution 17874 of 2025) 176,884,224 pesos for sending a mass email that exposed a person's data without authorization, also failing to show a policy manual or a manual for handling inquiries and complaints. Neither is a large company: this is exactly the profile of a mid-sized business that tends to assume this rule is for someone else.
The SIC fined Clínica Porvenir S.A.S. (Resolution 77220 of 2025) 107,202,560 pesos for not registering its databases with the National Database Registry (RNBD). One important nuance: the authority does not usually fine a company outright for lacking that registration; it first issues an order and then sanctions the failure to comply with that order. What it punishes harshly is not correcting the problem once warned.
It fined Vanti S.A. E.S.P. (Resolution 38583 of 2025) 412,729,856 pesos for lacking detection and monitoring measures and for not reporting a security incident to the RNBD. And it fined MercadoLibre Colombia Ltda. (Resolution 16582 of 2025) 214,405,120 pesos for conditioning access to a user's account on handing over biometric data and for refusing to delete that data when the user requested it.
Five compliance points that keep a company from being the next case
None of these five points is optional, and the cases above show the SIC sanctions a company that is missing even one of them.
First, an internal data processing policy manual with six minimum contents: identification of the data controller, the purpose of the processing, the data subject's rights, the area that handles requests and complaints, the procedure to exercise those rights, and how long the policy and the database remain in force. Second, prior, express and informed authorization from each data subject, with an extra layer when the data is sensitive, such as health or biometric data.
Third, registration with the RNBD, which is only mandatory for companies and non-profits with total assets above 100,000 Tax Value Units (UVT) and for public-sector legal entities: companies below that threshold are exempt from registration, though not from the other duties. Fourth, a channel for data subjects to know, update, correct or delete their data, or revoke their authorization, within the legal deadlines of ten or fifteen business days depending on whether it is an inquiry or a complaint.
Fifth, a procedure to report security incidents within fifteen business days of detecting them. This point catches more companies off guard than it should: the duty to report applies even to those exempt from RNBD registration because of their size. Being exempt from registering is not the same as being exempt from reporting, and the SIC's sanctions for unreported incidents confirm it.
The blind spot that connects to every company's payroll
Law 1581 applies to any database held by a public or private entity, with no exception beyond the strictly personal or domestic sphere. That includes payroll, resumes, occupational medical exams and personnel selection processes, made more sensitive by the fact that entry exams, time-clock fingerprints and occupational results are sensitive data requiring explicit consent and reinforced security measures. An updated set of internal work regulations solves none of this: these are different documents, with different content and different obligations.
There is not yet an SIC sanction whose central fact is, by itself, that an employer lacked a data policy for its payroll, and this article does not claim otherwise. What does exist are cases that show the same logic applied to the workplace: Resolution 79163 of 2025 fined a personnel security screening provider 201,004,800 pesos because its reports, containing household composition, occupational background, employment references and polygraph results for candidates and employees, were left accessible online due to a basic security flaw. Two separate 2025 rulings sanctioned companies for sending a person's debt information to their employer, showing that the workplace is a setting where the SIC has already acted over improper disclosure of data. A company that already updated its internal work regulations under Law 2466 of 2025 has, in that same payroll, a distinct obligation it has not yet addressed.
None of the five compliance points requires a large investment. What they require is having the right document in place before the Superintendencia asks for it. The companies sanctioned in 2025 were not chosen at random: they were the ones that, when asked, did not have the paperwork the law has required since 2012.
