AZC Legal
    #Repost #SIC Superindustria Sanctions Directv, Comcel S.A., and Avantel for Non-Compliance with Data Protection Laws
    Back to Legal News

    #Repost #SIC Superindustria Sanctions Directv, Comcel S.A., and Avantel for Non-Compliance with Data Protection Laws

    Also available in Spanish:Leer en español

    The fines imposed on the companies amount to 864 million pesos for non-compliance with Laws 1266 of 2008 and 1581 of 2012. The SIC required the companies to strengthen...

    Share article

    • The fines imposed on the companies amount to 864 million pesos for non-compliance with Laws 1266 of 2008 and 1581 of 2012.
    • The SIC required the companies to strengthen the security of the data they handle, a measure that will benefit more than 36 million people.

    Bogotá D.C., July 26, 2019. The Superintendence of Industry and Commerce, in its role as the national authority for data protection, imposed fines on the companies COMCEL S.A. and AVANTEL for consulting, without prior authorization, the credit histories of their clients, thereby violating the provisions of the Financial Habeas Data Law (Law 1266 of 2008), and on DIRECTV for sending a client's information to a third party, thereby infringing Law 1581 of 2012.

    The four fines imposed by the Superintendence amount to 864 million pesos and also have an important preventive component, as the companies were required to strengthen the necessary security measures to prevent personal data leaks or consultations with credit bureaus without the express authorization of clients.

    Avantel Case

    Through Resolution 24801 of 2019, the Superintendence of Industry and Commerce imposed a fine of $176,388,708 on AVANTEL S.A. This decision was made following a complaint filed by a citizen stating that his credit history showed a "consultation trace" made by AVANTEL.

    The SIC concluded that AVANTEL:

    • Consulted the credit history of the data subject without having authorization to do so.
    • Failed to establish the necessary internal security controls to monitor consultations made from its accounts to the credit histories of data subjects.

    SEE RESOLUTION 24801 OF 2019 

    COMCEL Cases

    The Superintendence imposed two fines on COMCEL S.A. The first for $248,434,800 (Resolution 18210 of 2019) and the second for $215,310,160 (Resolution 23968 of 2019) for providing disproportionate information about a client and making unauthorized consultations with credit bureaus.

    The aforementioned decisions were made in response to complaints filed by two citizens who informed the SIC that COMCEL had failed to establish the necessary security measures to prevent an unauthorized consultation and excessive (or disproportionate) disclosure in response to a request from an administrative authority in a contractual dispute.

    The SIC concluded that:

    • A COMCEL employee, without authorization, consulted the credit history of a data subject, and the company failed to establish the necessary security controls to prevent unauthorized consultations with credit bureaus by its employees.
    • COMCEL provided excessive information in response to a request regarding a client's accounts with the company, because it delivered to an administrative entity the entire credit history regarding COMCEL and other organizations, disclosing personal information not requested by the authority nor pertinent to what was required.

    SEE RESOLUTION 18210 OF 2019

    SEE RESOLUTION 23968 OF 2019

    DIRECTV Case

    Through Resolution 20205 of June 10, 2019, the Superintendence of Industry and Commerce imposed a fine of $223,913,320 on DIRECTV COLOMBIA LTDA for violating the principle of information security. The aforementioned decision was issued in response to a complaint by a citizen who stated that DIRECTV sent information about him to another person's email address.

    The SIC concluded that:

    • A DIRECTV employee sent information about one of its clients to a third party, violating the principle of security because it provided private information of one person to another person.
    • It failed to establish the necessary security controls to prevent the sending of personal information to unauthorized third parties.

    In all four decisions, the Superintendence ordered the sanctioned companies to adopt the necessary security measures to prevent unauthorized consultations with the credit histories of data subjects for purposes other than the calculation of credit risk as provided for in Law 1266 of 2008.

    Additionally, to ensure legal certainty for the more than 36 million users of the three companies, the SIC requested that they develop, implement, and maintain an internal security program to prevent their employees from making unauthorized consultations with the credit histories of data subjects; ensure that the data collected and processed are accurate; and have the necessary mechanisms to minimize the risks of delivering private information to unauthorized third parties.

    The four decisions are subject to appeal and reconsideration.

    See more at http://www.sic.gov.co/Superindustria-sanciona-a-Directv-Comcel-SA-y-Avantel-por-incumplir-leyes-de-proteccion-de-datos

    August 12, 2019