Data Privacy
Compliance with Law 1581, privacy policies, consent, registries and incident management.
Almost every company processes personal data every day, even if it does not call it that: the customer base, payroll, the CRM, the forms on the website, the cameras at the premises, the CVs from the last hiring round. Law 1581 of 2012 sets out what may be done with that information and what the company owes the person whose data it holds. Supervision sits with the Superintendence of Industry and Commerce (SIC), which acts on a data subject's complaint and on its own initiative.
What we usually find is not an absence of documents, but documents that do not describe what the company actually does: policies taken from a template, consent wording that does not cover the real purposes, vendors receiving data with no agreement, inherited databases whose origin no one can explain. So we start from the operation—what is collected, where it ends up, who looks at it, who it is shared with—and only then draft. We hand it over so it stays in the client's hands: an inventory the client's own team can maintain, and a procedure customer service can apply without calling a lawyer for every case.
When to call us
- A data subject has complained, or the Superintendence has sent a request.
- A client, a public entity or a tender requires evidence of compliance.
- A database has leaked, or information reached someone who should not have it.
- A cloud, payroll or marketing vendor is about to be engaged to process the data.
- The operation involves a parent company, platforms or teams abroad.
We work from Bogotá with clients across Colombia. Where the data comes out of the consumer relationship, the work is coordinated with our Consumer Protection Law practice; where it will feed artificial intelligence systems, with AI Audit and Implementation.
Services within this area
Data processing policy, privacy notice and consent wording
We map what data your company actually handles and draft the policy, privacy notice and consent wording around that reality. Bogotá, Colombia.
Learn more →Database inventory and registration before the SIC
We check whether your company is required to file, build the database inventory, handle the SIC procedure and leave it maintainable. Bogotá, Colombia.
Learn more →Data processor contracts and international data transfers
We review and draft contracts with providers that process data on your behalf and structure the flow of information abroad. Bogotá, Colombia.
Learn more →Protocol for handling data subject requests and complaints
We design the channel, response templates and rules to handle access, correction, deletion and withdrawal requests within the legal deadlines. Bogotá.
Learn more →Data Privacy Attorney in Colombia
Advice on Colombia data protection law, national database registry, consent, international transfers.
Learn more →Handling security incidents and personal data breaches
We run the first hours of an incident: containment, assessment, filing with the SIC, notice to affected individuals and a record of decisions. Bogotá.
Learn more →Defence before the SIC in data protection investigations
We take on the defence before the Superintendence: information requests, complaints, replies, evidence and appeals, with the file kept in order. Bogotá.
Learn more →Frequently asked questions
Does my company have to comply with Law 1581 of 2012 even if it is small? +
The law applies because personal data is being processed, not because of the size of the company. A business with few employees that runs a customer base, a payroll and a contact form is already processing data and owes the duties on policy, consent and handling data subject requests. What does change with size and other criteria is whether the company must file with the National Database Registry, which we check case by case.
What documents do I receive at the end of an implementation? +
An inventory of the databases and information flows, the processing policy, the privacy notice, consent wording adapted to each collection point, processing agreements with the vendors that need them, the protocol for handling queries and complaints, and the incident protocol. Everything is delivered in editable form, so the company can maintain it as the operation changes.
Can I download a processing policy from the internet and put my company's name on it? +
It gives you a document, not compliance. The policy has to describe the real purposes of the processing and the channels the company actually operates. A copied policy usually announces purposes that do not exist and leaves out the ones that do, and that gap is the first thing that shows when a data subject complains or the authority asks for an explanation. The policy on its own is also not enough: it has to be pushed down into the forms, contracts and scripts where data is collected.
What is the difference between transmission and transfer of personal data? +
In a transmission a third party processes the data on the controller's behalf and under its instructions, as happens with a cloud provider or outsourced payroll. In a transfer the recipient receives the data to process on its own account. The distinction determines what obligations each party assumes, what the contract must say and what additional requirements apply when the recipient is abroad.
A customer asked us to delete their data. Do we always have to do it? +
Not always. The right to deletion has limits: some information must be kept because of a legal or contractual duty, for example accounting records or documents from a terminated employment relationship. What is mandatory is to respond within the statutory deadlines, explain the decision and keep a record. That is why the protocol defines in advance what is deleted, what is retained and on what basis, so the service team does not improvise.
We had a data breach. What do we do first? +
Contain and document, in that order, before communicating anything externally. We need to know what data was affected, how many people it concerns, how it got out and whether access is still open. That determines whether a report to the Superintendence of Industry and Commerce and a communication to data subjects are due, and those texts are then drafted. Improvised drafts written in the first hours are often the worst part of the case, so it is worth calling us before sending them.
We received a request from the Superintendence of Industry and Commerce. How urgent is it? +
It is urgent. A deadline starts running from service of the notice, and whatever is filed shapes the entire discussion that follows, including any later formal charges. The first thing we do is confirm the date of service and the applicable deadline, review what documentation actually exists and settle the company's position before responding. A rushed answer can concede facts that cannot be walked back later.
We want to use our database to train an artificial intelligence model. Is that allowed? +
It depends on the purposes disclosed to the data subject and on the type of data involved. If consent was obtained for something else, using that base to train a model may go beyond the authorised purpose. We review what was authorised, what alternatives exist (anonymisation, fresh consent, narrowing the dataset) and what has to be documented before starting. We run that analysis together with our AI audit and implementation practice.
Ready to protect what you've built?
Every case starts with an honest conversation. Book 30 minutes, no commitment.
Book →