AZC Legal
    Biometric Data Processing in Accordance with Law 1581 of 2012.
    Back to Legal News

    Biometric Data Processing in Accordance with Law 1581 of 2012.

    Also available in Spanish:Leer en español

    The General Regime for the Protection of Personal Data, regulated by Law 1581 of 2012, aims to protect the constitutional rights to privacy and information that all persons have to know, update, and rectify the information that has been collected about them, in databases and all types of files that may be subject to processing by public and private entities.

    Share article

    The General Regime for the Protection of Personal Data, regulated by Law 1581 of 2012, aims to protect the constitutional rights to privacy and information that all persons have to know, update, and rectify the information that has been collected about them, in databases and all types of files that may be subject to processing by public and private entities.

    In accordance with the foregoing, it is important to mention that the processing of personal data is understood as the activity of collecting, storing, using, circulating, or deleting information, carried out by natural or legal persons, whether public or private; such activity may only be exercised with the prior, express, and informed consent of the data subject.

    Now, when referring to biometric data, we refer to personal data such as fingerprints and images, which are processed by technical mechanisms that allow the identification of a person by their unique and non-transferable traits. Thus, these data are considered sensitive data[1], since the improper use of this information may lead to discrimination, among others.

    In this sense, entities that use technical mechanisms for the identification of persons, or that make video recordings in their facilities, must take into account that they are obliged, in accordance with the provisions of Law 1581 of 2012, to request authorization from the data subject, informing data subjects that they are being monitored by video cameras, and informing them where they can access to learn about privacy policies, through the publication of notices.

    Thus, all companies that manage or process the biometric data of individuals are obliged to request authorization for its collection.

    In this way, companies must take into account that any instrument used for the storage and use of personal data requires prior consent from the data subject, since the lack of authorization for the processing of personal data and the failure to inform the purpose of its collection constitutes a violation of the rights of individuals to know the information collected about them, to include new data in order to provide a complete picture of the data subject, to update the information so that it matches reality, and to exclude information from a database, due to its improper use or simply at the will of the data subject.

    Those who violate constitutional rights and infringe the provisions on the Processing of Personal Data have been sanctioned by the Superintendence of Industry and Commerce (SIC), the authority responsible for inspecting, monitoring, and controlling the Processing of Personal Data.

    Currently, the Superintendence of Industry and Commerce (SIC) has imposed sanctions exceeding $21,000 million because companies have violated constitutional rights and breached the rules established in Colombian legislation.

    Therefore, entities that engage in the Processing of Personal Data, both private and sensitive, are obliged to comply with the provisions established in Law 1581 of 2012, given that the use of sensitive data requested, collected, and stored on the data subject requires greater care and responsibility on the part of the entities and other parties responsible who have access to them.

    In this order of ideas, it is recommended that entities that have databases of data subjects comply with current regulations through the implementation of Personal Data Processing Manuals and other procedures to ensure the protection of the constitutional rights of data subjects.



    [1] Sensitive data are understood to be those that affect the privacy of the Data Subject or whose improper use may generate discrimination, such as those that reveal racial or ethnic origin, political orientation, religious or philosophical convictions, membership in unions, social organizations, human rights organizations, or that promote the interests of any political party or that guarantee the rights and guarantees of opposition political parties, as well as data relating to health, sexual life, and biometric data.

    December 1, 2017