Law / Colombia

Superintendencia Circular on AI and Personal Data

SIC Circular Externa 002 de 2024 instrucciones I, II, VIII-IX (Lineamientos sobre Tratamiento de Datos en Sistemas de IA), 21 de agosto de 2024

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 21 August 2024.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Before collecting personal data from the internet to develop, train, test or deploy an artificial intelligence system, obtain the data subject's prior, express and informed authorization; a datum being accessible online does not make it a public datum exempt from that requirement.
  • Weigh whether processing personal data in an artificial intelligence system is suitable to the goal pursued, necessary because no less intrusive measure achieves it equally well, reasonable because it serves a constitutional purpose, and proportionate because its benefits are not outweighed by the harm to the right to data protection.
  • Where you cannot be certain an artificial intelligence system's processing will not cause serious, irreversible harm, refrain from that processing or adopt precautionary measures, and adapt your risk management systems to identify, measure, control and monitor the situations that could affect your compliance with personal data protection rules.
  • Complete and document a privacy impact assessment before an artificial intelligence system likely to pose a high risk to data subjects processes their personal data, covering the processing operations, a risk evaluation, and the measures planned to prevent the risks identified.
  • Only process truthful, complete, exact, updated, verifiable and understandable personal data in an artificial intelligence system, and do not process partial, incomplete, fragmented or misleading personal data.
  • Apply privacy by design and by default, including techniques such as differential privacy, so that data used to train an artificial intelligence system does not allow the person who provided it to be identified.
  • Adopt technological, human, administrative, physical and contractual security measures to prevent unauthorized access to, manipulation, destruction, or unauthorized use or circulation of personal data processed in an artificial intelligence system, and keep those measures auditable by the authorities.

What it reaches

Obligation class

Consent, DPIA, Governance, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The SIC's Circular Externa No. 002 de 2024 instructs every data controller and processor subject to Ley 1581 de 2012 and Ley 1266 de 2008 on how those technology neutral statutes apply to developing, deploying, or using an artificial intelligence system that processes personal data.

Instruction I requires that processing to satisfy a four factor weighing test: the processing must be suited to achieve its stated goal, no less intrusive measure must achieve that goal as effectively, the goal itself must be a constitutional one, and the benefit to that goal must not be outweighed by the harm the processing does to the right to data protection.

Instruction II requires an administrator of personal data to refrain from processing, or to adopt precautionary measures, wherever it cannot be certain that processing will not cause serious and irreversible harm, and to adapt its risk management systems to identify, measure, control and monitor the situations that could affect its compliance with personal data protection rules.

The circular next requires a documented privacy impact assessment, covering the processing operations, a specific evaluation of the risks to data subjects' rights and freedoms, and the measures planned to prevent those risks, before an artificial intelligence system likely to pose a high risk to data subjects processes their personal data, requires that data used in an artificial intelligence system be truthful, complete, exact, updated, verifiable and understandable, and requires privacy by design and by default through mathematical techniques such as differential privacy, so that training data cannot identify the person who provided it.

Instruction VIII requires technological, human, administrative, physical and contractual measures against unauthorized access to personal data, its manipulation or destruction, its misuse, and its unauthorized circulation, and requires those security measures to stay auditable by the authorities.

Instruction IX states that personal data being accessible on the internet does not make it data of a public nature, so a controller that collects personal, semiprivate, or sensitive data online is not thereby entitled to treat it for an artificial intelligence system's purposes without the data subject's prior, express and informed authorization.

When LexLint raises it

  • crawls_web
  • trains_models
  • high_risk_decisions

Read the law

Official Circular Externa text, Superintendencia de Industria y Comercio

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app