AZC Legal
    Personal data and habeas data

    Personal data protection

    We implement and audit compliance with Colombia's personal data protection regime so that your company can process customer, employee and supplier information with legal backing.

    From a document in a drawer to a programme that works

    In Colombia, the processing of personal data is governed mainly by Ley 1581 de 2012 (Colombia's Data Protection Law) and its implementing decrees, with the Superintendencia de Industria y Comercio (SIC, the Colombian consumer protection and data authority) acting as the supervisory authority. Compliance is not about publishing a policy: it is about being able to show how each consent was collected, what the information is used for, and what happens when a data subject exercises their rights.

    Our work starts by understanding the company's real data flows — web forms, CRM, payroll, cameras, technology vendors, international transfers — and ends with documents and processes the team can run day to day without relying on the legal department for every query.

    We also support companies when something has already gone wrong: a security incident, a data subject's complaint, or a request from the SIC.

    What the advisory includes

    • Diagnosis and data mapping

      Identification of databases, purposes, data controllers and processors, sensitive data, and flows with third parties inside and outside the country.

    • Mandatory documentation

      Data-processing policy, privacy notice, consent clauses and wording, and a procedure for handling queries and complaints.

    • Registro Nacional de Bases de Datos (National Database Registry)

      Analysis of whether the company is required to register, preparation of the information, and management of the registration and its updates before the SIC.

    • Contracts with processors and vendors

      Data transmission and transfer agreements with technology providers, call centres, cloud services and business partners.

    • Security incidents

      Response protocol, assessment of the duty to report, and support in communicating with the authority and affected data subjects.

    • Defence before the SIC

      Responses to information requests, handling of data subjects' complaints, and representation in administrative investigations.

    Our process

    1. 01

      Fact-finding

      Interviews with the areas that process data (marketing, HR, technology, customer service) and review of existing documents.

    2. 02

      Gaps and priorities

      A findings report that distinguishes immediate legal obligations from recommended improvements.

    3. 03

      Document implementation

      Drafting and adjusting policies, notices, consent forms, contracts and internal procedures.

    4. 04

      Training and upkeep

      Training for the teams and periodic reviews so the programme stays current as processes or vendors change.

    Our Clients

    INMCOR
    MINTIC
    SELECT
    TENICAÑA
    ISB
    ELITEAUTOS
    PROVISER
    ECOPETROL
    SURA
    ALLIANZ
    HISMART
    INDUSQUIM
    INMCOR
    MINTIC
    SELECT
    TENICAÑA
    ISB
    ELITEAUTOS
    PROVISER
    ECOPETROL
    SURA
    ALLIANZ
    HISMART
    INDUSQUIM

    Frequently asked questions

    Does every company have to register its databases with the RNBD?

    Not all of them. The obligation depends on conditions set by the regulation and by SIC guidance, mainly relating to the type of data controller and its size. The first thing we check is whether your company falls within the registration requirement.

    Can we use a data-processing policy downloaded from the internet?

    Rarely. The policy must reflect the actual purposes of your operation and the channels through which you interact with data subjects; a generic template usually describes processing the company does not do and omits the processing it does do.

    What should we do if we had a data breach?

    Contain the incident, document it, and assess the duty to report to the authority and to data subjects. This is a scenario where order and timing matter, which is why we recommend having the protocol defined before you need it.

    Does the advisory cover international data transfers?

    Yes. We review vendors and partners outside Colombia and structure the contractual instruments needed for international transmission and transfer.

    Do you work with technology teams or only with legal?

    We work with both. Much of real compliance depends on how forms, the CRM and access permissions are configured, so the exercise is done jointly.

    Let's review your compliance level

    Book an initial meeting and get a concrete read on your company's gaps in personal data protection.

    Request a review