After constitutionality was confirmed and with the pertinent presidential sanction, the rule that modifies and adds to the Statutory Law on “Habeas Data” (Law 1266/08) came into force in Colombia.
The law, described as a “clean slate” by its sponsors, provides several benefits: an amnesty for those who become current within the first 12 months of its validity or did so before its entry into force, the automatic removal of negative reports for certain sectors of the population if they pay off the debts that originated the data, and it also requires information sources to send at least two communications on different days before reporting debts of less than 15% of the current legal monthly minimum wage.
On the other hand, the law prohibits consulting credit bureaus for the granting of employment, provides for the automatic normalization of credit ratings when the negative report is removed, as well as the free access to information consulted through all channels, and establishes the expiration of negative data and data related to default situations after eight years, counted from the date the obligation became overdue. After that term, they must be removed from the database.
Likewise, it has been established that everything related to the provision of financial, credit, commercial, and service information, as well as information from third countries, whether by sources, users, or operators, must be carried out for the purpose of expanding and democratizing credit.
Precisely, users of such information must assess it together with other factors or elements of judgment that, in principle, have an impact on risk assessment and credit analysis.
All this, because they cannot base their decisions solely on the information on default provided by operators when considering credit applications, in order to avoid sanctions that may be imposed by the Financial Superintendency.
Thus, in cases of denial of a credit application, and at the request of the data subject, the institution or entity belonging to the financial or insurance system must provide written reasons for such denial.
However, if the data subject claims to be a victim of the crime of personal identity theft, as provided in the Criminal Code, and has been required to pay obligations due to the punishable act of which they are a victim, they must request a correction from the source, attaching documentation proving that they have been a victim of the aforementioned crime.
When the source receives such a request, within 10 days from receipt, it must compare the documents used to acquire the obligation with those provided by the data subject in the request, which will constitute summary evidence to prove the identity theft.
Thus, the source must change the negative report, the history, or any other information reflecting the data subject's behavior, noting that the victim of identity theft did not incur the obligations, and it must specify that they were a “victim of personal identity theft.”

Also available in Spanish:Leer en español
After constitutionality was confirmed and with the pertinent presidential sanction, the rule that modifies and adds to the Statutory Law on 'Habeas Data' (Law 1266/08) came into force in Colombia....
Share article
November 16, 2021
