Colombia’s Data Protection Reform: What Reclassifying Biometrics as Sensitive Data Means for Banks
Colombia’s data protection law is getting its most significant update since 2012. In August 2026, Congress filed a new statutory bill amending Statutory Law 1581 of 2012 (Ley 1581 de 2012), Colombia’s principal data protection statute — comparable in scope, though not in mechanics, to the EU’s GDPR. It follows two earlier filings that did not complete the legislative process. This article focuses on what matters to a biometric verification stack: the reclassification of identification biometrics as sensitive data, impact assessments, the Data Protection Officer role, explainability of automated decisions, cross-border transfers, and what changes for processors.
What the bill changes, and where it stands
The bill is a statutory bill, not yet law. The source text identifies it as “Proyecto de Ley Estatutaria No. ____ de 2026” — the filing number is still blank, because Colombia’s Chamber of Representatives only assigns one once the registration is formally processed, a step that follows the filing itself. That’s the normal state of any bill just filed, not an omission in the document. We’ll update this article once that number is known.
This is not the first attempt. According to the bill’s own explanatory memorandum, the same effort was filed in the 2024-2025 legislative term (PLE 152 of 2024) and the 2025-2026 term (PLE 274 of 2025), neither of which completed the process. Separately, in August 2025 Colombia’s national government — through the Ministries of Science, Technology and Innovation and of Commerce, Industry and Tourism, alongside the Superintendence of Industry and Commerce (SIC) — announced its own initiative to update the same law. Whether that announcement and the August 2026 bill are the same initiative, or two separate filings with the same aim, is an open question with the information available today — we won’t resolve it here rather than assert something the sources don’t confirm.
As a statutory bill, it requires four ordinary debates (two in each chamber) within a single legislative term, plus prior and automatic review by the Constitutional Court before presidential assent — a heavier procedural bar than an ordinary law, loosely comparable to the extra scrutiny major EU data-protection legislation goes through before entering into force. Until that process concludes, Law 1581 of 2012 remains the applicable regime, together with Decree 1377 of 2013 as its implementing regulation.
Identification biometrics become sensitive data
Under Law 1581 of 2012 as it stands, biometric data is not expressly listed as sensitive data — it receives reinforced protection through interpretation and case law, not through a closed statutory category. The bill makes it explicit. Article 3, letter l), lists among sensitive data “biometric data aimed at uniquely identifying a natural person,” alongside categories already recognised under Colombian law: racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, health data, and sexual orientation or gender identity or expression.
The practical effect is a change of regime. Sensitive data isn’t processed under the general rule for lawful bases: Article 6 of the bill keeps a general prohibition on processing sensitive data, subject to a closed list of exceptions. A controller’s generic legitimate interest — one of the standard bases for ordinary data — stops being sufficient on its own.
One precision worth keeping in any adaptation of this piece: the reclassification applies to biometrics aimed at uniquely identifying a natural person, not to every use of a physical, physiological or behavioural trait. Generalising it to “all biometric processing” is a legal overreach the bill’s text doesn’t support.
Legal basis for biometric processing in KYC
For a financial institution using biometrics in onboarding or in ongoing identity verification, the bill leaves two realistic routes.
The first is the data subject’s prior, express and informed consent, under the terms set out in Article 10 of the bill: obtained before processing, for one or more specific purposes, with silence, pre-ticked boxes or inaction explicitly ruled out as valid consent.
The second is the new letter f) of Article 6: processing sensitive data is lawful when “necessary to comply with legal obligations and to exercise specific rights of the controller or the data subject.” For KYC verification and anti-money-laundering processes supervised by Colombia’s Financial Superintendence, this second route is the natural one: identity verification isn’t a business choice, it’s a legal obligation on the regulated entity. It’s worth documenting that basis precisely, because the generic legitimate interest under Article 9 — valid for ordinary data — doesn’t on its own authorise processing sensitive data.
Impact assessments and data protection officers
The bill makes data protection impact assessments an explicit obligation — something Law 1581 of 2012 doesn’t currently spell out. The new letter s) of Article 17 (amended by Article 12 of the bill) requires an assessment for large-scale processing, automated or semi-automated processing, profiling, or a likely high risk to data subjects’ rights — and, “in any case,” for automated processing of sensitive data. That last clause leaves no room for interpretation for a biometric verification system: as automated processing of what the bill itself classifies as sensitive data, the impact assessment moves from good practice to a legal requirement.
The same article (new letter u) of Article 17) sets out three cases where appointing a Data Protection Officer stops being optional: large-scale processing of personal data, processing sensitive data as a core activity, or processing carried out by a public authority or body — a duty that extends to processors as well as controllers (Article 18, letter ñ). A practical note: the bill turns having a Data Protection Officer, even when not yet mandatory, into a mitigating factor when sanctions are graded (Article 21, new letter i) of Article 24 of Law 1581 of 2012).
Explainability and automated decisions
The bill adds explainability as one of the guiding principles of processing (Article 4) and turns it into a concrete right: data subjects can’t be the object of decisions that limit their fundamental rights, have discriminatory effects, or significantly affect them, when those decisions rely solely on automated processing or profiling (Article 8, letter g). When that happens, the data subject can demand a clear, accessible and sufficient explanation of the logic, criteria and determining factors involved, plus human intervention.
This bears directly on fraud scoring and account-risk decisions built on biometric verification or behavioural signals — the kind of fraud prevention layer many onboarding stacks already run. The operational requirement is concrete: the model’s logic, the factors it weighs, and the escalation path to human review all need to be documented, not just designed.
Cross-border transfers of biometric data
Article 22 of the bill redesigns Article 26 of Law 1581 of 2012 around a two-tier scheme closer to an adequacy-decision model than to today’s closed list of exceptions. First, transfers are allowed to countries offering an adequate level of protection under a standard set by Colombia’s National Data Protection Authority. Second, transfers to any other country require additional safeguards: a declaration of conformity filed with the Authority, binding corporate rules, or standard contractual clauses it approves. The exceptions under today’s Article 26 (express consent, contract performance, among others) remain available, but only as a last resort when there’s no adequacy decision or additional safeguard in place.
The architectural consequence is direct for any identity stack: processing or storing biometric templates outside Colombia adds a compliance layer that a local deployment doesn’t carry. It’s worth mapping now where those templates live and under what mechanism they cross the border.
Penalties under the proposed regime
Article 20 of the bill replaces Article 23 of Law 1581 of 2012. The current regime caps fines at 2,000 times the monthly minimum wage (SMMLV). The bill raises that ceiling to 10,000 times the minimum wage, or 5% of the infringer’s operating revenue for the prior fiscal year — whichever applies. Fines can be successive while the breach continues, and the sanctions catalogue keeps suspension of activities and permanent closure of processing operations when required corrective measures aren’t adopted. These sanctions apply to private entities, mixed-economy companies and state industrial and commercial enterprises; when the alleged infringer is a public authority, the matter is referred to Colombia’s Office of the Attorney General (Procuraduría General de la Nación).
What to review before the reform takes effect
| Requirement | Article of the bill | What to check in your current stack |
|---|---|---|
| Legal basis for biometric processing | Art. 6(f) and Art. 9 | If onboarding relies only on legitimate interest or a generic consent, document the legal-obligation basis for KYC/AML |
| Reclassification as sensitive data | Art. 3(l) | Confirm identification biometric templates are handled under the sensitive-data regime, not the general one |
| Impact assessment (DPIA) | Art. 17(s) (am. Art. 12) | Check whether a DPIA exists for the biometric verification system and when it was last updated |
| Data Protection Officer | Art. 17(u) and Art. 18(ñ) | Confirm whether the entity has already appointed a DPO; if not, assess whether it qualifies under large-scale or sensitive-data-as-core-activity |
| Explainability of automated decisions | Art. 4 and Art. 8(g) | Check whether the fraud-scoring model documents logic, factors and the human-review escalation path |
| Cross-border transfers of biometric templates | Art. 26 (am. Art. 22) | Locate where biometric templates reside and under what mechanism they’re transferred outside Colombia |
| Processor duties (subcontracting and audits) | Art. 18(p) and (r) (am. Art. 13) | If you work with external processors (biometric verification, cloud, BPO), confirm their processing agreements already bar subcontracting without the controller’s express authorisation and include a duty to allow audits and technical inspections |
| Sanctions exposure | Art. 23 and Art. 24 (am. Art. 20 and 21) | Estimate the impact of a fine of up to 5% of operating revenue against the cost of closing the gaps above |
This checklist gives compliance context for Colombia, but it doesn’t replace a closer look at LATAM regulatory compliance, the KYC verification process, AML screening, identity verification for banking, or fraud prevention in the automated-decisions flow — that’s where each point of this checklist is worth developing further.
Current regime vs. proposed regime
| Category | Law 1581 of 2012 (current) | 2026 bill (in progress) |
|---|---|---|
| Category of identification biometric data | Reinforced protection through interpretation; not expressly listed as sensitive data | Expressly sensitive data (Art. 3(l)), under a general prohibition with a closed list of exceptions |
| Legal basis for processing | Data subject consent as the general rule; no differentiated route for sensitive data | Express consent or compliance with a legal obligation (Art. 6(f)); generic legitimate interest is not enough |
| Impact assessment (DPIA) | Not an express requirement | Mandatory for automated processing of sensitive data, large-scale processing or profiling (Art. 17(s)) |
| Data Protection Officer | Not a mandatory legal role | Mandatory in three cases: large scale, sensitive data as core activity, or public entity (Art. 17(u)) |
| Cross-border transfers | Prohibited except for a closed list of exceptions (express consent, contract performance, among others) | Allowed to countries with an adequate level of protection or with additional safeguards; the closed-list exceptions become a last resort |
| Maximum penalty | Up to 2,000 times the minimum wage (SMMLV) | Up to 10,000 times the minimum wage (SMMLV) or 5% of the prior fiscal year’s operating revenue |
Frequently asked questions
The bill partially amends Statutory Law 1581 of 2012. It broadens the legal bases for processing, adds new categories of sensitive data — including biometric data used to uniquely identify a person — requires impact assessments, mandates a Data Protection Officer in defined cases, and raises penalties.
Not yet. It is a statutory bill filed with the Chamber of Representatives in August 2026. Statutory bills require four debates plus prior constitutional review by the Constitutional Court. Until it is enacted, Law 1581 of 2012 remains the applicable regime.
Under the current Law 1581, biometric data already receives reinforced protection through interpretation. The bill makes it explicit: biometric data aimed at uniquely identifying a natural person is listed as sensitive data, which triggers a general prohibition subject to a closed list of exceptions.
Two routes. Express prior consent from the data subject, or compliance with a legal obligation binding on the controller. For KYC and AML processes supervised by the financial regulator, the legal obligation route is the natural one. Generic legitimate interest does not authorise processing sensitive data.
Where there is large-scale processing, automated or semi-automated processing, profiling, or a likely high risk to data subjects’ rights. The bill includes automated processing of sensitive data in every case, which covers any biometric verification system.
Yes, under conditions. Transfers to countries offering an adequate level of protection under the national authority’s standard are permitted. Otherwise, additional safeguards are required: a declaration of conformity, binding corporate rules, or standard contractual clauses approved by the authority.