AZC Legal
    Not Being Obligated to Register Databases Does Not Exempt from the Obligation to Comply with the Personal Data Protection Law (Law 1581 of 2012)
    Back to Legal News

    Not Being Obligated to Register Databases Does Not Exempt from the Obligation to Comply with the Personal Data Protection Law (Law 1581 of 2012)

    Also available in Spanish:Leer en español

    In order to comply with the provisions of Decree 090 of 2018, the Superintendence of Industry and Commerce (SIC) calls on legal entities to...

    Share article

    In order to comply with the provisions of Decree 090 of 2018, the Superintendence of Industry and Commerce (SIC) calls on legal entities to timely register their databases in the National Database Registry (RNBD) and, as stipulated in the aforementioned decree, the registration deadline is as follows:

    First, the parties responsible for registering companies and non-profit entities with assets exceeding 610,000 UVT (tax value units) have until September 30, 2018, to carry out this act.

    If the parties responsible for registering companies and non-profit entities have assets exceeding 100,000 and up to 610,000 UVT (tax value units), they have until November 30, 2018, to carry out this act.

    Finally, the parties responsible for registering public legal entities have until January 31, 2019, to complete the registration.

    Likewise, databases created after the expiration of the aforementioned deadlines must be registered within the following 2 months, counted from their creation.

    Additionally, the parties responsible for processing must update the registered information as follows: (i) Once registered in the database, if substantial changes to the registered information are required, such changes may be made within the first 10 business days of each month. (ii) Furthermore, the Superintendence of Industry and Commerce (SIC) has established that starting in 2020, information must be updated annually, between January 2 and March 31. (iii) Likewise, the SIC informs that within the first 15 business days of February and August of each year, starting from the registration, information on all claims filed by data subjects must be updated.

    On the other hand, the SIC, through Circular No. 003 of August 1, 2018, stipulates that legal and natural persons who are not required to register continue to be obligated to comply with the other duties under Law 1581 of 2012; that is, the parties responsible for processing personal data.

    Additionally, those who are not required to register their database with the RNBD (National Database Registry) and encounter any incident regarding the information contained in the database must report security incidents through the means established by the Superintendence and the available channels within 15 business days from the moment the incident is identified and the person or area responsible for handling the case is known. Likewise, it should be noted that all information related to security measures, claims by data subjects, and security incidents reported in the registry is not available to the public.

    In conclusion, it can be said that timely registration of the database by the data processor, who is understood to be the person responsible for carrying out all necessary procedures for the registration and recording of the database, ensures full compliance with Law 1581 of 2012 and, by virtue of this, the exercise of the rights to update, know, and rectify the information contained in the database if necessary, and likewise, in the event of any problem or incident, to be able to identify and correct it in a timely manner, both for the person obligated to register and for those who do not have such an obligation.

    August 15, 2018