AZC Legal
    HOW TO KNOW IF I AM OBLIGATED TO THE RNBD BEFORE THE SUPERINTENDENCY OF INDUSTRY AND COMMERCE? WHAT SHOULD I CONSIDER?
    Back to Legal News

    HOW TO KNOW IF I AM OBLIGATED TO THE RNBD BEFORE THE SUPERINTENDENCY OF INDUSTRY AND COMMERCE? WHAT SHOULD I CONSIDER?

    Also available in Spanish:Leer en español

    Both private companies, associations, and public entities are obligated to the National Database Registry (RNBD) before the Superintendency of Industry and Commerce (SIC), provided that, according to current regulations, they have total assets exceeding 100,000 Tax Value Units (UVT).

    Share article

    Both private companies, associations, and public entities are obligated to the National Database Registry (RNBD) before the Superintendency of Industry and Commerce (SIC), provided that, according to current regulations, they have total assets exceeding 100,000 Tax Value Units (UVT).

    Currently, the value of one UVT is $47,065, so the threshold for total assets is currently $4,706,500,000 in Colombian pesos. Therefore, they are under the legal obligation to register their databases with the Superintendency of Industry and Commerce (SIC) and update the information recorded in the RNBD; in this regard, it is highlighted that:

    1. The information recorded in the RNBD must be updated annually, between January 2 and March 31 of each year. During this period, at a minimum, the information related to the total number of data subjects must be updated.
    • Likewise, the RNBD must be updated periodically within the first 10 business days of the following month after the date when substantial changes occur.
    • Databases created after the expiration of the aforementioned deadlines must be registered within two (2) months following their creation.
    • Additionally, data controllers must report claims filed by data subjects of their databases within the first 15 business days of February and August of each year, starting from their registration.

    The report must include claims filed by data subjects against both the data controller and the data processor, and must be made in accordance with the RNBD User Manual, which is available at the following https://rnbd.sic.gov.co/sisiAyuda/

    • Incidents that pose a risk to the security of personal data must be reported to the SIC. This report must be made within 15 business days after becoming aware of the incident. A security incident occurs when there is a breach of security codes or the loss, theft, and/or unauthorized access to information contained in a database.
    • What is understood by substantial and non-substantial changes?

    According to the SIC, substantial changes are those related to the change of the purpose of a database, the data processor, the channels for serving data subjects, the classification or types of personal data stored in the database, the implemented information security measures, the Information Processing Policy, and the international transfer and transmission of personal data.

    In contrast, all changes related to other types of information recorded in the RNBD correspond to non-substantial changes that must be reported no later than March 31 of each year; the foregoing, without prejudice to the fact that, if the update of non-substantial changes has not been carried out, it may also be fulfilled at that time.

    • How can the information that must be updated be identified?

    It is recommended to have, as part of the procedure in charge of the area responsible for personal data protection matters, an internal document to control information about the databases reported in the RNBD that allows identifying changes subject to update.

    • What happens if I fail to comply with these obligations?

    The Superintendency of Industry and Commerce indicates that, once the breach of these obligations by the data controller or data processor is established, it will adopt the corresponding measures or impose the sanctions provided for in Article 23 of Law 1581 of 2012, which indicate:

    • Fines of a personal and institutional nature up to the equivalent of two thousand (2,000) monthly minimum legal wages in force at the time of imposing the sanction. Fines may be successive while the breach that caused them persists.
    • Suspension of activities related to the Processing for up to six (6) months. The suspension order shall indicate the corrective measures to be adopted.
    • Temporary closure of operations related to the Processing once the suspension period has elapsed without the corrective measures ordered by the Superintendency of Industry and Commerce having been adopted.
    • Immediate and definitive closure of the operation involving the Processing of sensitive data.
    July 24, 2024