Skip to content
Back to InsightsBusiness Law

This English translation is provided for general information and has not been legally verified. Consult the Spanish original for legal interpretation. The article reflects its original publication date, not subsequent changes in the law.

Personal data processing policies: how to draft them properly

Every company handling personal data needs a processing policy. We explain what it should contain, RNBD registration and the mistakes most frequently penalised by the SIC.

Marín Ortega Team · Marín Ortega Lawyers3 min read
Personal data processing policies: how to draft them properly

If your company handles personal data, whether belonging to employees, customers or suppliers, it needs a personal data processing policy that ensures compliance with Colombian legislation. The policy establishes how personal data is collected, stored, used, protected and deleted, safeguarding data subjects’ rights and information security. This article explains the key steps in creating an appropriate policy under Law 1581 of 2012 and other applicable Colombian rules.

The policy must align with the guidelines in Law 1581 of 2012. It should address the principles of lawfulness, meaning that processing must be based on the law and data subjects’ consent; purpose limitation, meaning data should be used only for legitimate purposes previously disclosed to the data subject; and transparency, ensuring that data subjects can know what information is being used and how. The policy must also provide for technical security measures to protect data against unauthorised access, loss or alteration, and restricted access, under which only people authorised by the data subjects or by law may access personal data.

The policy must also identify the categories of personal data to be processed. In Colombia, personal data falls into several categories, including sensitive data, which affects an individual’s private life, such as information about health, religious beliefs or political views, among other matters. Processing this data requires the data subject’s explicit consent unless a legal exception permits otherwise. The policy must also specify how private data, relevant only to the data subject, will be processed, as well as semi-private data, which, although not wholly private, may be of interest to a particular group of people.

The policy should describe in detail how personal data will be collected and used. It must identify the specific purposes for which data will be used, such as customer management, compliance with contractual obligations, service improvement or marketing communications. It must also ensure that data collection is preceded by explicit, informed notice: the data subject must be told why their data is being collected and how it will be processed. If the purpose of processing changes, new authorisation must be obtained.

The policy must address the data subject’s authorisation for processing personal data. Authorisation must be prior, express and informed, and obtained before any data is collected. For sensitive data, authorisation must be even more explicit because processing is restricted by law and may only take place with the data subject’s explicit consent. The policy must also explain how data subjects can revoke their consent at any time and exercise this right easily and accessibly.

Data subjects’ rights must also be clearly explained. These include the rights to access, update and correct their personal data, revoke authorisation for processing and request deletion when the data is no longer necessary for the purposes for which it was collected. Data subjects must also be able to consult and access the information held about them and submit complaints if they believe their rights are being infringed.

Let’s discuss this topic.

If this article relates to a matter affecting your company, share the context so we can review the scope of support.

Talk to us