{"id":146272,"date":"2026-08-11T09:53:13","date_gmt":"2026-08-11T09:53:13","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=146272"},"modified":"2026-08-11T09:53:13","modified_gmt":"2026-08-11T09:53:13","slug":"colombia-tmt","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/colombia-tmt\/","title":{"rendered":"Colombia: TMT"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-146272","comparative_guide","type-comparative_guide","status-publish","hentry","guides-tmt","jurisdictions-colombia"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">BBGS Abogados<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2026\/07\/BBGS-COL-LOGO_.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">BBGS Abogados<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2026\/07\/BBGS-COL-LOGO_.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of TMT laws and regulations applicable in Colombia<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 How are proprietary rights in software and associated materials protected?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Colombia, software is protected as a literary work under copyright law. The main sources are Law 23 of 1982 (Copyright Law), Law 44 of 1993, which amended Law 23 of 1982, Andean Decision 351 of 1993 (Andean Community Copyright Regime), and Law 1915 of 2018, which modernized the copyright framework.<\/p>\n<p>Software source code and object code are protected as original expressions without any formality requirements. Registration with the National Copyright Office (DNDA), regulated by Decree 1066 of 2015, is declaratory\u2014not constitutive\u2014but creates a presumption of authorship and ownership. Protection extends for the author\u2019s lifetime plus 80 years (for individuals) or 70 years from the first authorized publication (for legal entities), according to Article 4 of Law 1915 of 2018.<\/p>\n<p>Additionally, Ley 527 de 1999 on electronic commerce and digital signatures offers ancillary protection for software distributed electronically. Databases associated with software may receive sui generis protection where sufficient investment in compilation is demonstrated.<\/p>\n<p>Trade secrets provide a parallel protection layer under Decisi\u00f3n Andina 486 de 2000 (articles 260\u2013266) for algorithms, architectures and unpublished code, provided confidentiality measures are maintained.<\/p>\n<p>Patent protection for software per se is not available; however, software-implemented inventions that solve a technical problem may qualify for patents before the Superintendencia de Industria y Comercio (SIC), consistent with Andean Community guidelines.<\/p>\n<p>Technological protection measures (TPMs) enjoy both civil and criminal enforcement under article 12 of Ley 1915 de 2018.<\/p>\n<p>Criminal sanctions for software piracy are established in article 271 of the C\u00f3digo Penal (Ley 599 de 2000, as amended by Ley 1915 de 2018), imposing imprisonment of four to eight years and fines where infringement occurs with commercial purpose.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>According to the provisions of Andean Decision 351 (Article 10) and Law 23 of 1982 (Articles 20 and 91), the author (that is, the individual who creates the work) is the original owner of the rights, unless there is a valid assignment.<\/p>\n<p>For employment relationships and independent contractor arrangements, Article 20 of Law 23 of 1982 (as amended by Article 28 of Law 1450 of 2011) provides that, when a work is created under an employment contract or a service contract (contract for the provision of services), the employer or the contracting party holds the economic rights, provided that the scope of the contract covers such creation and the contract is in writing. However, the author retains moral rights, which are inalienable and perpetual.<\/p>\n<p>For independent contractors and consultants without written agreements, the developer retains both moral and economic rights. The law requires that, for the transfer to take effect under an employment or service relationship, the contract must be in writing; otherwise, the transfer is not valid.<\/p>\n<p>Therefore, explicit contractual provisions are essential. Best practices require: (a) the express assignment of economic rights (Article 183, Law 23 of 1982) or specification in the written contract of the presumption of transfer of rights under an employment or service relationship pursuant to the amended Article 20 of Law 23 of 1982; (b) specification of the forms of exploitation (reproduction, adaptation, distribution, communication to the public); and (c) recognition of inalienable moral rights that remain with the creator.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 Are there any specific laws that govern the harm \/ liability caused by Software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Colombia does not have a single law that specifically addresses liability for software products. The applicable legal framework derives from:<\/p>\n<p>Law 1480 of 2011 (Consumer Protection Law): This law establishes strict liability for defective goods and services. Software supplied as a product or integrated into a device falls within its scope. Suppliers, manufacturers, and importers may be jointly and severally liable for damages caused by defects.<\/p>\n<p>Law 1273 of 2009 (Crimes Against Information and Data): criminalizes unauthorized access, interference with computer systems, data interception, and the distribution of malware. Penalties range from 48 to 120 months in prison and fines of up to 1,500 SMLMV.<\/p>\n<p>Civil Code (Articles 2341 et seq.) and general principles of civil liability: Tort liability based on fault (culpa) applies to damages caused by software failures when the developer\u2019s negligence is proven.<\/p>\n<p>Law 1581 of 2012 (Data Protection): If software improperly processes personal data, causing harm, the SIC may impose administrative penalties of up to 2,000 SMLMV, in addition to civil liability toward the data subjects.}<\/p>\n<p>Law 1915 of 2018 regulates liability for circumventing technological protection measures, which is typically carried out through computer programs or information systems.<\/p>\n<p>No specific AI or algorithmic liability statute has been enacted to date, though the draft AI Bill currently under congressional review contemplates risk-based obligations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Key statutes include:<\/p>\n<p>Ley 1273 de 2009 on informatic crimes: articles 269A\u2013269J criminalise abusive access to computer systems, data destruction, system interference, phishing, use of malicious software, and impersonation through technological means.<\/p>\n<p>Ley 527 de 1999: regulates electronic documents, digital signatures and certification entities. It grants legal validity to electronic messages and software-based signatures, subject to reliability standards.<\/p>\n<p>Ley 1341 de 2009 (ICT Framework Law, as modified by Ley 1978 de 2019): establishes the general regulatory framework for telecommunications and digital services, including obligations for providers utilising software-based platforms.<\/p>\n<p>Decreto 1078 de 2015 (\u00danico Reglamentario del Sector TIC): compiles regulatory provisions on digital government, electronic authentication and interoperability of public-sector systems.<\/p>\n<p>Ley 2213 de 2022: makes permanent the use of ICT in judicial proceedings, validating software-based notifications, electronic filings and virtual hearings.<\/p>\n<p>Additionally, sector-specific regulation (financial, health, energy) imposes software audit, resilience and security requirements through circulars issued by respective superintendencies.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (Licence and SaaS) \u2013 Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Colombia does not have a comprehensive software licensing law or one specific to the cloud; rather, these agreements and their provisions are governed by the parties\u2019 freedom of contract, subject to the limits established by law.\u00a0 The legal framework consists of:<\/p>\n<p>Andean Decision 351 of 1993 (Article 25): expressly authorizes the legitimate owner of a copy of software to make a single backup copy and to adapt the program to the extent necessary for its use. In Colombia and, more generally, in the Andean Community\u2014unlike other legal systems around the world\u2014there is no provision for a right to tracking or remuneration for private copying.<\/p>\n<p>Law 23 of 1982 (Article 72, as amended): addresses the authorized use of computer programs.<\/p>\n<p>Law 1480 of 2011: applies consumer protection rules (information obligations, warranties, unfair terms) to B2C and SaaS software contracts.<\/p>\n<p>Decreto 1078 of 2015 (Articles 2.2.9.1.1.1 et seq., on digital citizen services): regulates cloud interoperability and authentication for public sector digital services, which indirectly affects private cloud providers contracted by the government.<\/p>\n<p>Decreto 1448 de 2022 (Sandbox Regulatorio): enables experimental provision of innovative ICT services, including cloud-based solutions, under a controlled regulatory framework.<\/p>\n<p>For public procurement, Decreto 620 de 2020 establishes conditions for digital services provisioning to state entities, including cloud requirements (data localisation is not mandated, though certain sensitive data categories face restrictions).<\/p>\n<p>There is no statutory prohibition on SaaS models. Licensing constructs follow freedom of contract (C\u00f3digo de Comercio, articles 824 et seq.), subject to copyright limitations under the Andean regime and the Consumer Statute where applicable.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If \u2018yes\u2019, what would be considered a market standard level of cap?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, liability caps are standard in negotiated software and SaaS agreements in Colombia. Market practice typically reflects:<\/p>\n<p>Enterprise licences\/SaaS: caps range from one to two times the annual contract value (i.e. 12\u201324 months of fees). For high-value transactions, 12 months&#8217; fees is the most common baseline.<\/p>\n<p>Mid-market\/SME contracts: caps may align with the total fees paid during the preceding 12-month period.<\/p>\n<p>Colombian law (C\u00f3digo Civil, article 1604; C\u00f3digo de Comercio, articles 822, 863) permits contractual limitation of liability, subject to public order constraints. Clauses purporting to exclude liability for dolo (wilful misconduct) or culpa grave (gross negligence) are void. Similarly, under Ley 1480 de 2011, consumer-facing limitations that eliminate the vendor&#8217;s obligation for product defects are deemed abusive and unenforceable.<\/p>\n<p>Caps denominated in foreign currency (typically USD) are enforceable, though payment must be made in Colombian pesos at the representative market rate (C\u00f3digo de Comercio, article 874; Banco de la Rep\u00fablica exchange regime).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor\u2019s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>(a) Confidentiality breaches \u2013 Frequently carved out or subject to an enhanced cap (commonly 2\u20133x the general cap). Market sophistication increasingly drives separate treatment given the significant exposure.<\/p>\n<p>(b) Data protection breaches \u2013 Typically carved out or subject to a super cap. Under Ley 1581 de 2012, both processors and controllers face direct regulatory sanctions, making contractual allocation critical.<\/p>\n<p>(c) Data security breaches (including loss of data) \u2013 Similar treatment to (b); enhanced cap or carve-out. Often combined with (b) into a single &#8216;data&#8217; super cap.<\/p>\n<p>(d) IPR infringement claims \u2013 Standard market practice is to carve out vendor indemnification obligations for third-party IP infringement from the general cap, or subject them to a separate enhanced cap.<\/p>\n<p>(e) Breaches of applicable law \u2013 Less consistently carved out; depends on negotiation leverage. In regulated industries (financial, telecom), compliance obligations are typically unlimited or subject to a super cap.<\/p>\n<p>(f) Regulatory fines \u2013 Increasing trend toward carve-out, particularly post Ley 1581 de 2012 enforcement activity by the SIC. However, many vendors resist accepting liability for fines imposed on the customer.<\/p>\n<p>(g) Wilful or deliberate breaches \u2013 Must be carved out from any cap, as Colombian law (C\u00f3digo Civil, article 1604) precludes limitation of liability for dolo.<\/p>\n<p>(h) Claims arising out of or in relation to AI \u2013 This is an emerging area. Current market practice is evolving; sophisticated contracts increasingly include either a specific AI-related carve-out or an enhanced cap, particularly where AI outputs generate third-party liability risks. No statutory mandate exists yet.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Source code escrow remains a recognised practice in Colombia for critical on-premise software licences, particularly in the financial sector and public procurement. However, its prevalence has declined as SaaS adoption grows.<\/p>\n<p>Typical escrow agents include international providers such as NCC Group (formerly Iron Mountain IP Management) and PRAXIS Technology Escrow. Locally, notarial deposit (dep\u00f3sito notarial) is occasionally used for source code, though it lacks the verification and update mechanisms of specialised escrow.<\/p>\n<p>For cloud-based software, traditional escrow is largely inadequate. The market has shifted toward:<\/p>\n<p>SaaS continuity provisions: contractual commitments to provide data export in standard formats upon termination, ongoing maintenance during transition periods, and access to APIs.<\/p>\n<p>Technology escrow alternatives: services offering automated, continuous deposits of source code, build scripts, infrastructure-as-code configurations, and deployment documentation (e.g. providers such as Escrow London, Codekeeper).<\/p>\n<p>In public procurement (governed by Ley 80 de 1993 and Decreto 1082 de 2015), escrow arrangements are sometimes included in terms of reference for mission-critical systems.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Colombia has no dedicated IT outsourcing statute. The legal framework applicable to IT outsourcing is composed of:<\/p>\n<p>General commercial law: C\u00f3digo de Comercio (articles 864 et seq.) governs service agreements.<\/p>\n<p>Ley 1581 de 2012: imposes data processing obligations on the outsource provider as Encargado del Tratamiento (data processor), including security duties and adherence to the controller&#8217;s instructions.<\/p>\n<p>Decreto 1074 de 2015 (article 2.2.2.25.3.1 et seq.): requires the data processing agreement (contrato de transmisi\u00f3n) to include scope, purpose, security measures and sub-processing restrictions.<\/p>\n<p>Sector-specific rules: Circular B\u00e1sica Jur\u00eddica 029 of the Superintendencia Financiera (Chapter XII, Title I) imposes strict outsourcing governance requirements on financial entities, including risk assessment, continuity planning, audit rights and regulatory notification.<\/p>\n<p>For public-sector outsourcing, Ley 1150 de 2007 and Decreto 1082 de 2015 establish procurement requirements, including SLAs, security obligations and reversibility conditions.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under Colombian law, it is permissible for the products or services developed by individual staff members to be transferred to an IT outsourcing service provider. In such cases, and subject to compliance with the requirements set forth in Law 23 of 1982 (regarding <em>work made-for-hire<\/em> or <em>copyright-assignment <\/em>agreements), the corresponding intellectual property rights may likewise be assigned to such third party. Accordingly, individual staff members shall not retain any economic rights over the works or creations transferred to the outsourcing provider, without prejudice to their moral rights, which shall remain vested in the authors and shall be perpetual, inalienable, non-waivable, and immune from attachment.<\/p>\n<p>Notwithstanding the foregoing, where an IT outsourcing arrangement gives rise to a breach of Colombian labour law, individual staff members may seek protection and enforcement of their rights through the applicable labour law mechanisms. In particular, Law 1429 of 2010 (Article 63) and Decree 583 of 2016 prohibit certain forms of labour intermediation through outsourcing (unlawful labour subcontracting), especially where the outsourced activities constitute the beneficiary company&#8217;s core and permanent business activities and the workers do not maintain a direct employment relationship with the entity benefiting from their services.<\/p>\n<p>Accordingly, IT outsourcing transactions require careful workforce analysis to determine whether the outsourcing structure complies with anti-intermediation rules.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and\/or services, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The regulatory architecture comprises:<\/p>\n<p>Ley 1341 de 2009 (as substantially modified by Ley 1978 de 2019): the overarching ICT framework establishing principles, institutional competences, and the general authorisation regime for telecommunications. It creates the Ministerio de Tecnolog\u00edas de la Informaci\u00f3n y las Comunicaciones (MinTIC) as the policy and spectrum authority, the Comisi\u00f3n de Regulaci\u00f3n de Comunicaciones (CRC) as the sector-specific regulator and the Fondo \u00danico de Tecnolog\u00edas de la Informaci\u00f3n y las Comunicaciones (FonTIC) as the state agancy responsible for financing plans and programs designed to facilitate universal access to information and communications technologies .<\/p>\n<p>Ley 1978 de 2019: modernised the legal framework to promote investment, modernise the spectrum allocation regime, and strengthen the CRC&#8217;s independence and enforcement powers.<\/p>\n<p>Decreto 1078 de 2015 (Decreto \u00danico Reglamentario del Sector TIC): consolidates all regulatory provisions.<\/p>\n<p>Ley 182 de 1995 and Ley 680 de 2001: govern television services (being progressively integrated into the general ICT framework following Ley 1978 de 2019 and the convergence approach).<\/p>\n<p>CRC resolutions: including Resoluci\u00f3n CRC 5050 de 2016 and subsequent amendments.<\/p>\n<p>The regime&#8217;s general purposes include: promoting investment and competition; ensuring universal access; efficient spectrum management; user rights protection; and technological neutrality.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Since Ley 1341 de 2009, Colombia operates a general authorisation regime rather than individual licences for most telecom services:<\/p>\n<p>Providers of telecommunications networks and services must register in the Registro de TIC maintained by MinTIC (article 15, Ley 1341; Decreto 2433 de 2015).<\/p>\n<p>Registration is declarative and enables the provision of any telecommunications service in Colombia without specific service-by-service authorisation.<\/p>\n<p>Spectrum use requires a separate permit granted by MinTIC through competitive selection or direct assignment, depending on the frequency band and use (articles 72\u201376, Ley 1341 as amended). Spectrum permits have a maximum term of 20 years, renewable.<\/p>\n<p>Broadcasting (radio): Concession contracts remain necessary for community and commercial radio stations under Resoluci\u00f3n MinTIC 415 de 2010 et seq.<\/p>\n<p>Internet Service Providers (ISPs): need only registration in the Registro de TIC.<\/p>\n<p>The regime eliminated the historical distinction between value-added services, carrier services, and basic services, embracing a convergent, technology-neutral model.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The applicable framework includes:<\/p>\n<p>Constituci\u00f3n Pol\u00edtica, article 15: protects the inviolability of private communications. Interception requires prior judicial order and article 75: which regulates that the electromagnetic spectrum is an inalienable and imprescriptible public good subject to the management and control of the State, annd\u00a0 article 77: indicaating that a general policy for television will be regulated and governed by the law.<\/p>\n<p>C\u00f3digo de Procedimiento Penal (Ley 906 de 2004, articles 235\u2013237): authorises the Fiscal\u00eda General de la Naci\u00f3n to request judicial authorisation for interception of communications in criminal investigations. Orders are confidential, time-limited (initially 3 months, extendable), and subject to proportionality.<\/p>\n<p>Ley 1621 de 2013 (Intelligence and Counterintelligence Law): authorises intelligence agencies to conduct signal interception with prior judicial order for national security purposes. Establishes oversight by a joint congressional commission.<\/p>\n<p>Decreto 1704 de 2012 (compiled in Decreto 1078 de 2015): requires telecommunications providers to implement technical capabilities enabling lawful interception and to provide metadata (subscriber data, traffic data) upon legitimate judicial or prosecutorial request.<\/p>\n<p>Types of data accessible: subscriber identification data, traffic\/connection metadata (origin, destination, time, duration), and content (only with judicial warrant).<\/p>\n<p>Safeguards: requests must be proportionate, targeted, and time-limited. Challenges are available post-factum once the subject is informed. The Constitutional Court (Sentencia C-594 de 2014) has circumscribed metadata access, requiring it to meet the same judicial authorisation standard as content interception.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that impose cyber security and\/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and\/or provision of telecommunications services.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Key provisions include:<\/p>\n<p>Ley 1341 de 2009 (article 2, principles): establishes ICT security as a guiding principle.<\/p>\n<p>Resoluci\u00f3n CRC 5569 de 2018 (as amended): establishes cybersecurity obligations for telecom operators, including incident reporting, security management systems, and cooperation with ColCERT (national cyber-response team).<\/p>\n<p>CONPES 3854 de 2016 (National Cybersecurity Policy): sets the strategic framework for cybersecurity governance, designating MinTIC and MinDefensa as coordinating entities, with sectoral responsibilities for critical infrastructure protection.<\/p>\n<p>Decreto 338 de 2022: creates the institutional governance model for digital security, establishing roles for the Grupo de Respuesta a Emergencias Cibern\u00e9ticas de Colombia (ColCERT) under MinTIC, CSIRT sectoral teams, and coordination mechanisms.<\/p>\n<p>Resoluci\u00f3n MinTIC 500 de 2021: establishes the cybersecurity model for government entities, with which operators serving the public sector must align.<\/p>\n<p>Operators must implement business continuity plans, perform vulnerability assessments, report significant incidents to the CRC within defined timeframes, and collaborate with authorities during cybersecurity emergencies.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Colombia does not have indigenous SSOs for mobile communications standards. Applicable standards derive from international bodies:<\/p>\n<p>3GPP (3rd Generation Partnership Project): defines LTE, 5G NR and related standards adopted by Colombian operators.<\/p>\n<p>IEEE (Institute of Electrical and Electronics Engineers): Wi-Fi, IoT connectivity protocols.<\/p>\n<p>ETSI (European Telecommunications Standards Institute): referenced in CRC regulations.<\/p>\n<p>ITU (International Telecommunication Union): Colombia is a member state; ITU recommendations inform spectrum allocation and technical planning through the Agencia Nacional del Espectro (ANE).<\/p>\n<p>ISO\/IEC JTC 1: information technology standards adopted via ICONTEC (Instituto Colombiano de Normas T\u00e9cnicas), Colombia&#8217;s national standards body.<\/p>\n<p>For digital health, Ministerio de Salud references HL7-FHIR interoperability standards. For connected vehicles, no specific national SSO exists; international standards (SAE, ISO 26262) apply by reference in sectoral discussions.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Colombia, technical interoperability standards impact connected technology development primarily through:<\/p>\n<p>CRC regulatory mandates: the CRC may establish minimum interoperability requirements for equipment and services (Ley 1341, article 22). Resoluci\u00f3n CRC 5050 and subsequent amendments address device portability and number portability obligations.<\/p>\n<p>IoT regulatory approach: Colombia has adopted a permissive, technology-neutral stance. The ANE has allocated spectrum bands (e.g. 915 MHz ISM band) for IoT devices without individual licensing, following ITU-R recommendations.<\/p>\n<p>Decree 1078 of 2015 (interoperability framework): establishes standards for digital government systems, requiring open protocols for public sector platforms. This indirectly promotes interoperable connected services.<\/p>\n<p>CONPES 3975 de 2019 identified interoperability as a critical enabler for Industry 4.0 and AI deployment.<\/p>\n<p>The absence of mandatory national standards for IoT security has been identified as a gap; the draft AI Bill and related policy initiatives contemplate risk-based technical requirements that may address this.<\/p>\n<p>SEP (Standard Essential Patent) licensing follows FRAND principles per international practice. Colombian competition law (Ley 1340 de 2009) provides the SIC with authority to address abusive SEP enforcement.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The core framework consists of:<\/p>\n<p>Constituci\u00f3n Pol\u00edtica, article 15: enshrines the fundamental right to habeas data (privacy, knowledge, update and rectification of personal information).<\/p>\n<p>Ley Estatutaria 1581 de 2012 (General Data Protection Law): the comprehensive statute governing the collection, processing, storage and transfer of personal data by public and private entities.<\/p>\n<p>Decreto 1377 de 2013 (compiled in Decreto 1074 de 2015): regulatory implementation provisions addressing consent, data processing agreements, international transfers and the Registro Nacional de Bases de Datos.<\/p>\n<p>Ley 1266 de 2008: governs financial and credit data (sectoral habeas data).<\/p>\n<p>Circular \u00danica de la SIC (Title V): compiles administrative guidance on data protection compliance.<\/p>\n<p>Key principles include lawfulness, purpose limitation, freedom (consent-based processing), accuracy, transparency, restricted access, security and confidentiality.<\/p>\n<p>The Superintendencia de Industria y Comercio (Delegatura para la Protecci\u00f3n de Datos Personales) is the supervisory authority.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under article 23 of Ley 1581 de 2012, the SIC may impose:<\/p>\n<p>Fines up to 2,000 current monthly minimum legal wages (SMLMV) per infraction. As of 2026, one SMLMV is COP 1,750,905, (c. USD 550) giving a maximum fine of approximately COP 3,501,810,000 (c. USD 1,033,000). Fines may be successive while non-compliance persists.<\/p>\n<p>Suspension of data processing activities for up to six months.<\/p>\n<p>Temporary closure of processing operations if corrective measures are not adopted after suspension.<\/p>\n<p>Immediate and definitive closure of operations involving sensitive data processing.<\/p>\n<p>These sanctions apply only to private-sector entities. Public-sector breaches are referred to the Procuradur\u00eda General de la Naci\u00f3n for disciplinary proceedings.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What data protection rules are relevant to technology contracts in your country?  Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Technology contracts in Colombia must address:<\/p>\n<p>Data processing agreements (contrato de transmisi\u00f3n\/encargo): required under Decreto 1074 de 2015 wherever a vendor processes personal data on behalf of the customer. Must specify: scope, purposes, security measures, sub-processing authorisation, and cross-border transfer mechanisms.<\/p>\n<p>International transfer mechanisms: under article 26 of Ley 1581 de 2012, transfers to countries lacking &#8216;adequate&#8217; protection levels (as declared by the SIC) require the data subject&#8217;s express authorisation or must fall within statutory exceptions (contractual necessity, public interest, judicial proceedings).<\/p>\n<p>Reference to EU GDPR: it is increasingly common for Colombian technology contracts with international elements to reference EU GDPR compliance standards, particularly where vendors serve European clients or process data of EU residents. This arises from practical commercial requirements rather than statutory mandate.<\/p>\n<p>CCPA\/US frameworks: less commonly referenced except in contracts with US-headquartered vendors who contractually commit to a single compliance standard.<\/p>\n<p>SIC declared adequacy list: countries deemed adequate include member states of the EU\/EEA, among others. Where the recipient country is not listed, standard contractual clauses (modelled after GDPR SCCs but adapted to Ley 1581) are increasingly used, though not formally regulated.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Colombia&#8217;s cybersecurity legal framework comprises:<\/p>\n<p>Ley 1273 de 2009: the primary criminal statute on cybercrime, adding Title VII Bis to the C\u00f3digo Penal. It criminalises: unauthorised access (269A), illegitimate system obstruction (269B), data interception (269C), computer damage (269D), use of malicious software (269E), unlawful data use (269F), software impersonation (269G), and electronic theft (269I).<\/p>\n<p>CONPES 3854 de 2016: National Digital Security Policy establishing the multi-stakeholder governance model, risk management approach, and institutional coordination (ColCERT, CSIRT Government, sector-specific CSIRTs).<\/p>\n<p>Decreto 338 de 2022: formalises the institutional structure for digital security, designating ColCERT within MinTIC, and establishing mandatory coordination between sector regulators.<\/p>\n<p>Ley 1712 de 2014 (Transparency and Access to Information): imposes security obligations on public entities managing information assets.<\/p>\n<p>Resoluci\u00f3n MinTIC 500 de 2021: Modelo de Seguridad y Privacidad de la Informaci\u00f3n (MSPI) for government entities.<\/p>\n<p>Sector-specific frameworks: financial sector (Circular Externa 007 de 2018, Superintendencia Financiera), health sector (Resoluci\u00f3n 866 de 2021), and telecom sector (Resoluci\u00f3n CRC 5569 de 2018).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sanctions depend on the applicable regime:<\/p>\n<p>Criminal sanctions (Ley 1273 de 2009): imprisonment from 48 to 120 months and fines from 100 to 1,500 SMLMV (c. 53,000 USD to 820,000 USD) for cybercrimes.<\/p>\n<p>Data protection (Ley 1581 de 2012): security breaches exposing personal data may trigger fines up to 2,000 SMLMV (c. 1,050,000 USD) per infraction by the SIC, plus possible suspension or closure of activities.<\/p>\n<p>Financial sector: the Superintendencia Financiera may impose institutional fines up to the higher of: (i) COP 1,645,000,000 (c. 510,000 USD) (approximately, updated annually); or (ii) an amount linked to the entity&#8217;s assets or revenue, under Ley 964 de 2005 and Decreto 2555 de 2010.<\/p>\n<p>Telecom sector: the CRC and MinTIC may impose sanctions including fines up to 2,000 SMLMV (c. 1,050,000 USD) and potential revocation of the TIC registration for serious non-compliance.<\/p>\n<p>No single maximum cross-sectoral cybersecurity fine exists; the applicable cap depends on the sector and regulator.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes:<\/p>\n<p>Financial sector: entities supervised by the Superintendencia Financiera must implement SARO (Operational Risk Management System) and comply with Circular Externa 007 de 2018 on cybersecurity. They must report cyber incidents and maintain a CSIRT or designated security function. No separate &#8216;cybersecurity registration&#8217; exists, but entities are supervised as part of their prudential licence.<\/p>\n<p>Telecom sector: providers registered in the Registro de TIC must comply with CRC cybersecurity obligations (Resoluci\u00f3n CRC 5569 de 2018) including incident reporting to ColCERT.<\/p>\n<p>Critical infrastructure operators: CONPES 3854 de 2016 and Decreto 338 de 2022 contemplate identification and mandatory security obligations for critical infrastructure sectors (energy, transport, water, health, financial, telecom). While a formal &#8216;critical infrastructure registry&#8217; remains under development, sector regulators increasingly impose security standards on designated operators.<\/p>\n<p>Government entities: must register in and comply with the Modelo de Seguridad y Privacidad (MSPI) under Resoluci\u00f3n MinTIC 500 de 2021.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the regulatory framework for the reporting of cybersecurity incidents.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The reporting framework varies by sector:<\/p>\n<p>General personal data breaches: under article 17(n) of Ley 1581 de 2012, data controllers must notify the SIC when security code violations occur and there are risks to data subjects. The SIC has issued guidance requiring notification within 15 business days of awareness.<\/p>\n<p>Telecom sector: Resoluci\u00f3n CRC 5569 de 2018 mandates reporting significant cybersecurity incidents to the CRC and ColCERT within defined timeframes (typically 24 hours for critical incidents).<\/p>\n<p>Financial sector: Circular Externa 007 de 2018 (Superintendencia Financiera) requires immediate reporting of significant cyber incidents to the supervisor and coordination with CSIRT Financiero (managed by Asobancaria).<\/p>\n<p>Government sector: Decreto 338 de 2022 mandates government entities to report incidents to ColCERT and the CSIRT Gobierno.<\/p>\n<p>Voluntary reporting: any entity may report incidents to ColCERT, which provides coordination and technical assistance.<\/p>\n<p>There is no single unified cybersecurity incident notification statute equivalent to the EU NIS2 Directive, though draft legislation has been proposed to consolidate obligations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Which body(ies), if any, is\/are responsible for the regulation of artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>As of June 2026, Colombia does not have a single dedicated AI regulator. Responsibility is distributed across existing authorities:<\/p>\n<p>MinTIC: leads AI policy under CONPES 3975 de 2019 and CONPES 4144 de 2025.<\/p>\n<p>Consejer\u00eda Presidencial para Asuntos Econ\u00f3micos y Transformaci\u00f3n Digital: coordinates whole-of-government AI strategy.<\/p>\n<p>SIC: enforces consumer protection, data protection, industrial property law, and competition rules as they apply to AI systems.<\/p>\n<p>DNDA: Colombian Copyright Office that establish administrative criteria regarding copyright dispositions on IA protection.<\/p>\n<p>Sector regulators: the Superintendencia Financiera (AI in financial services), CRC (AI in telecom), and others exercise jurisdiction within their sectors.<\/p>\n<p>The draft AI Bill (Proyecto de Ley de Inteligencia Artificial) currently progressing through Congress contemplates the creation of a coordination mechanism (not a standalone regulator) and risk-based classification of AI systems, drawing on elements of the EU AI Act framework.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Colombia currently has no comprehensive AI-specific legislation in force. The applicable legal framework consists of:<\/p>\n<p>CONPES 3975 de 2019: policy document establishing principles and strategic actions for AI development, including ethical guidelines, data infrastructure, talent development, and institutional governance. It establishes a &#8216;soft law&#8217; framework with 14 principles for responsible AI.<\/p>\n<p>CONPES 4144 de 2025: updates the national AI policy with more concrete governance provisions, sectoral implementation guidelines, and alignment with OECD AI Principles.<\/p>\n<p>Ley 1581 de 2012: applies to automated decision-making involving personal data. Data subjects have rights to transparency regarding automated processing and to object to solely automated decisions significantly affecting them.<\/p>\n<p>Ley 1480 de 2011 (Consumer Statute): product liability and information duties extend to AI-enabled products and services.<\/p>\n<p>Ethical Framework for AI (MinTIC, 2021): non-binding guidelines for responsible AI in government, referencing OECD principles.<\/p>\n<p>Draft AI Bill (Proyecto de Ley): proposes risk-based categorisation (unacceptable, high, limited, minimal risk), transparency obligations for high-risk systems, human oversight requirements, impact assessments, and sandbox mechanisms. Status: under congressional debate as of June 2026.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and\/or generative AI (including agentic AI)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>As of June 2026, no enacted legislation specifically addresses LLMs, generative AI, or agentic AI in Colombia. However:<\/p>\n<p>The draft AI Bill (under congressional review) includes provisions relevant to generative AI: mandatory disclosure\/labelling of AI-generated content (particularly synthetic media and deepfakes), transparency obligations regarding training data, and copyright-related provisions concerning AI-generated outputs.<\/p>\n<p>CONPES 4144 de 2025 references generative AI governance challenges and recommends policy responses addressing: misinformation, IP implications of training data, and accountability for autonomous AI agents.<\/p>\n<p>The Colombian Superintendence of Industry and Commerce (SIC) has issued guidance (2024\u20132025) clarifying that existing consumer protection regulations apply equally to AI-generated advertising and recommending that businesses ensure transparency regarding the use of AI in customer-facing interactions. In addition, through External Circular No. 002 of 2024, the SIC has urged companies and data controllers to implement appropriate measures to safeguard personal data and protect individuals&#8217; privacy when deploying or using AI systems. This regulation is, also applicable to corporate administrators by means of External Circular No. 003 of 2024.<\/p>\n<p>Direcci\u00f3n Nacional de Derecho de Autor (DNDA): has not issued a definitive position on whether AI-generated outputs qualify for copyright protection. The prevailing interpretation under Decisi\u00f3n Andina 351 requires a human author, meaning purely AI-generated works likely lack protection unless substantial human creative contribution is demonstrated.<\/p>\n<p>The electoral authority (CNE) and audio-visual regulator have addressed deepfake concerns through existing electoral advertising and broadcasting rules.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is currently no statutory mandate requiring specific AI risk provisions in technology contracts. However, market practice is evolving rapidly:<\/p>\n<p>Voluntary contractual provisions are increasingly common in enterprise technology agreements, particularly covering:<\/p>\n<p>Responsibility allocation for AI outputs (accuracy, bias, errors); IP ownership of AI-generated materials; Restrictions on training models using customer data; Transparency regarding AI use in service delivery; Indemnification for algorithmic discrimination claims; Human oversight and override mechanisms.<\/p>\n<p>CONPES 4144 de 2025 recommends that public procurement contracts for AI systems include risk assessment requirements, explainability conditions, and audit rights.<\/p>\n<p>Superintendencia Financiera: Circular Externa 013 de 2024 recommends that financial entities include AI governance provisions in third-party technology contracts, addressing model risk, bias testing, and data governance.<\/p>\n<p>The draft AI Bill, if enacted, would create mandatory contractual provisions for high-risk AI systems (documentation, impact assessments, human supervision mechanisms).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Increasingly, yes. Key contractual trends include:<\/p>\n<p>IP ownership of AI outputs: contracts commonly address whether customer owns outputs generated by AI tools deployed under the agreement. Under Colombian copyright law (Decisi\u00f3n Andina 351, Ley 23 de 1982), authorship requires human creative contribution. Parties typically allocate ownership through contractual assignment mechanisms or work-for-hire clauses, though enforceability of copyright claims in purely\/only AI-generated outputs remains legally unprotected.<\/p>\n<p>Training data restrictions: enterprise customers increasingly negotiate prohibitions on using their proprietary data or content to train the vendor&#8217;s general AI models. These clauses protect trade secrets (Decisi\u00f3n Andina 486) and avoid unintended IP leakage.<\/p>\n<p>IP indemnification for AI: vendor indemnities typically cover third-party IP infringement claims arising from AI-generated deliverables. Given the &#8216;hallucination&#8217; risk in generative AI and potential inadvertent reproduction of copyrighted material, these provisions attract significant negotiation attention.<\/p>\n<p>Ley 1915 de 2018 provisions on technological protection measures and information management rights apply to AI systems that reproduce or transform protected works.<\/p>\n<p>Moral rights: contracts cannot override the inalienable moral rights of human authors whose works may be used in training datasets. This creates compliance complexity for AI vendors operating in the Andean Community.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Blockchain \u2013 What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>(i) Blockchain: Colombia has no blockchain-specific legislation. The legal framework applicable to blockchain derives from:<\/p>\n<p>Ley 527 de 1999: provides legal validity to electronic records and messages, which extends to blockchain-based ledger entries as &#8216;data messages&#8217; meeting integrity and reliability criteria.<\/p>\n<p>Decreto 1078 de 2015: blockchain-based timestamping and authentication may qualify under the digital certification framework.<\/p>\n<p>(ii) Digital assets\/crypto-assets:<\/p>\n<p>Superintendencia Financiera: has issued multiple circulars (particularly Carta Circular 52 de 2017 and subsequent communications) clarifying that crypto-assets are not legal tender, not securities, and not foreign exchange. Financial institutions are not prohibited from exploring crypto-asset services but must manage associated risks.<\/p>\n<p>Decreto 1357 de 2018 (crowdfunding): establishes the regulatory sandbox approach but does not directly address tokenised assets.<\/p>\n<p>Decreto 1448 de 2022 (Sandbox Regulatorio): enables experimentation with blockchain-based products and services under controlled conditions.<\/p>\n<p>DIAN (Tax Authority): crypto-asset gains are taxable income. Resoluciones 000164 de 2021 and subsequent guidance require reporting of crypto-asset transactions.<\/p>\n<p>UIAF (Financial Intelligence Unit): imposes AML\/CFT obligations on entities dealing in virtual assets under FATF recommendations and Ley 526 de 1999.<\/p>\n<p>Draft legislation: multiple bills have been proposed to regulate crypto-assets comprehensively; none has been enacted as of June 2026.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Search Engines and Marketplaces \u2013 Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Colombia has no dedicated legislation for search engines or online marketplaces. The applicable framework includes:<\/p>\n<p>Ley 1480 de 2011 (Consumer Statute): applies to digital marketplaces; imposes information obligations, right of withdrawal in distance sales (5 business days), product liability, and prohibitions on misleading advertising. The SIC actively enforces consumer protection in e-commerce.<\/p>\n<p>Decreto 587 de 2016: specific provisions on e-commerce consumer protection, including transparency in platform terms, price disclosure, and confirmation mechanisms.<\/p>\n<p>Ley 1581 de 2012: applies to user data collected by platforms.<\/p>\n<p>Ley 1340 de 2009 (Competition Law): the SIC may investigate dominant position abuse by platforms exhibiting significant market power (e.g. self-preferencing, exclusionary practices).<\/p>\n<p>Ley 256 de 1996 (Unfair Competition): applicable to deceptive ranking manipulation, paid placement without disclosure, and parasitic conduct.<\/p>\n<p>Tax obligations: Ley 2010 de 2019 and Ley 2155 de 2021 impose VAT collection and income tax withholding obligations on non-resident digital platforms providing services to Colombian consumers.<\/p>\n<p>No &#8216;gatekeeper&#8217; or digital markets regulation analogous to the EU DMA has been enacted.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No single social media statute exists. The regulatory framework includes:<\/p>\n<p>Constituci\u00f3n Pol\u00edtica, articles 20 and 73: freedom of expression and press, balanced against honour, good name, and privacy (article 15).<\/p>\n<p>Ley 1581 de 2012: applies to personal data processing by platforms.<\/p>\n<p>Ley 1098 de 2006 (Childhood and Adolescence Code): imposes restrictions on content harmful to minors. Platforms must take measures to protect children from exploitation, grooming, and cyberbullying.<\/p>\n<p>Ley 1273 de 2009: criminalises identity theft and data misuse on digital platforms.<\/p>\n<p>Ley 1480 de 2011: regulates advertising on platforms (truthfulness, identifiability of commercial content).<\/p>\n<p>Ley 2089 de 2021: addresses cyberbullying and online violence against children and adolescents, imposing platform cooperation obligations with authorities.<\/p>\n<p>Ley 1712 de 2014 and Decreto 103 de 2015: transparency obligations potentially applicable to government use of social media.<\/p>\n<p>The SIC has exercised jurisdiction over misleading influencer advertising under existing consumer protection rules.<\/p>\n<p>A comprehensive &#8216;Online Safety Act&#8217; or &#8216;Digital Services Act&#8217; equivalent has not been enacted, though proposals are under discussion.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In the absence of a specific online safety statute, maximum sanctions derive from existing regimes:<\/p>\n<p>SIC (Consumer protection): fines up to 2,000 SMLMV (c. 1,050,000 USD) per infraction under Ley 1480 de 2011.<\/p>\n<p>SIC (Data protection): fines up to 2,000 SMLMV (c. 1,050,000 USD), plus suspension or closure of operations.<\/p>\n<p>Criminal sanctions (e.g. exploitation of minors online, Ley 679 de 2001 and Ley 1336 de 2009): imprisonment up to 20 years for serious offences.<\/p>\n<p>ICBF (child protection): may order platform access blocking through judicial proceedings.<\/p>\n<p>No single &#8216;online safety&#8217; fine ceiling exists equivalent to, for example, the UK Online Safety Act or EU DSA regime.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Spatial Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Colombia has no specific legislation addressing spatial computing, augmented reality (AR), extended reality (XR), virtual reality (VR), or &#8216;metaverse&#8217; environments.<\/p>\n<p>Applicable rules are drawn from existing frameworks:<\/p>\n<p>Ley 1581 de 2012: applies to biometric data, spatial tracking data, and behavioural data collected through AR\/VR devices (classified as sensitive data under certain circumstances).<\/p>\n<p>Copyright law (Ley 23 de 1982, Ley 1915 de 2018, Decisi\u00f3n Andina 351): protects virtual environments, avatars, and digital assets as audiovisual works or artistic creations where originality thresholds are met.<\/p>\n<p>Ley 1480 de 2011: consumer protection applies to virtual goods and services transactions.<\/p>\n<p>Ley 1273 de 2009: cybercrime provisions apply to unlawful access or manipulation of spatial computing systems.<\/p>\n<p>Competition law: the SIC may intervene if metaverse platform operators exercise dominance abusively.<\/p>\n<p>There is no regulatory framework for virtual property rights, avatar identity, or inter-platform portability of digital assets. These matters are governed by contract (platform terms of service) and general principles of Colombian civil and commercial law.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Quantum Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern quantum computing and\/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Colombia has no legislation specific to quantum computing or quantum cryptography. The topic remains at a policy and academic stage:<\/p>\n<p>CONPES 4144 de 2025 references emerging technologies including quantum computing as part of the broader digital transformation and AI ecosystem, without establishing specific legal obligations.<\/p>\n<p>General encryption rules: Colombia does not restrict the use of encryption technologies. Decree provisions on digital signatures (Ley 527 de 1999) are technology-neutral and could accommodate quantum-resistant algorithms.<\/p>\n<p>National security considerations: the intelligence framework (Ley 1621 de 2013) addresses interception capabilities but does not specifically contemplate quantum cryptanalysis threats.<\/p>\n<p>Standards: ICONTEC (as ISO member) may adopt post-quantum cryptography standards (e.g. NIST PQC standards) once finalised, which would influence the financial and government sectors.<\/p>\n<p>No quantum technology export controls exist at the Colombian level, though compliance with international non-proliferation regimes (Wassenaar Arrangement) applies.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Datacentres \u2013 Does your jurisdiction have any specific regulations that apply to data centres?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Colombia has no datacentre-specific legislation. Data centres operate under general frameworks:<\/p>\n<p>Urban planning and construction: municipal regulations (POT \u2013 Plan de Ordenamiento Territorial), building codes, and environmental licences (Ley 99 de 1993).<\/p>\n<p>Electricity: regulated consumption under CREG (Comisi\u00f3n de Regulaci\u00f3n de Energ\u00eda y Gas) framework. Large data centres may negotiate unregulated energy supply contracts.<\/p>\n<p>Environmental: cooling systems and energy consumption must comply with environmental standards. No specific energy efficiency mandates for data centres exist, unlike the EU Energy Efficiency Directive.<\/p>\n<p>Data protection: if housing personal data, the data centre operator may qualify as Encargado del Tratamiento under Ley 1581 de 2012, triggering security and confidentiality obligations.<\/p>\n<p>Telecom registration: if providing hosting or colocation services bundled with connectivity, registration in the Registro de TIC may be required.<\/p>\n<p>Tax incentives: Colombia offers tax benefits for qualifying technology investments under Ley 1819 de 2016 and Ley 2155 de 2021, which may apply to data centre construction.<\/p>\n<p>No data localisation mandate: Colombian law does not require personal data or other categories of data to be stored domestically, subject to international transfer requirements under Ley 1581 de 2012.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 What are your top 3 predictions for significant developments in technology law in the next 3 years?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>(1) Enactment of comprehensive AI legislation: the draft AI Bill, drawing on elements of the EU AI Act and OECD AI Principles, is expected to be enacted, establishing risk-based categorisation, mandatory impact assessments for high-risk systems, transparency obligations, and a governance coordination mechanism. This will be the most significant regulatory development for the technology sector. However, this will depend on the Congress\u2019 regulatory will and the next president\u2019s government agenda.<\/p>\n<p>(2) Modernisation of data protection law: amendments to Ley 1581 de 2012 are anticipated to align with global standards\u2014including enhanced data breach notification obligations, mandatory DPIAs, data portability rights, and strengthened rules on automated decision-making and profiling. The SIC has signalled its intent to modernise the regime via legislative proposal.<\/p>\n<p>(3) Digital platform regulation: following global trends (EU DMA\/DSA, UK Online Safety Act), Colombia is expected to advance legislation addressing digital gatekeeper obligations, algorithmic transparency, content moderation accountability, and enhanced liability frameworks for online intermediaries. Tax enforcement on digital platforms will continue intensifying.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 Do technology contracts in your country commonly include provisions to address sustainability \/ net-zero obligations or similar environmental commitments?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sustainability provisions in technology contracts are emerging but not yet standard practice in Colombia:<\/p>\n<p>Public procurement: Decree 1860 de 2021 and Colombia Compra Eficiente guidelines increasingly encourage (though do not mandate) sustainability criteria in ICT procurement, including energy efficiency standards, electronic waste management commitments, and circular economy principles.<\/p>\n<p>Large enterprise contracts: multinational clients and certain Colombian conglomerates are incorporating ESG provisions in technology agreements, typically covering: data centre energy sourcing (renewable energy commitments), carbon footprint reporting for cloud services, hardware lifecycle management, and e-waste disposal obligations.<\/p>\n<p>Regulatory drivers: Ley 1931 de 2018 (Climate Change Law) and Colombia&#8217;s NDC commitments under the Paris Agreement create an enabling context. However, no statute mandates net-zero provisions in private technology contracts.<\/p>\n<p>Market trend: sustainability provisions are more common in (a) data centre services agreements; (b) long-term cloud infrastructure contracts; and (c) public-sector frameworks. They remain uncommon in standard SaaS or licence agreements.<\/p>\n<p>Carbon credit and offset mechanisms (Decreto 926 de 2017) may be referenced in technology contracts where service providers commit to carbon neutrality.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">7759<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/146272","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=146272"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}