Superintendencia Circular on AI and Personal Data
SIC Circular Externa 002 de 2024 (Lineamientos sobre Tratamiento de Datos Personales en Sistemas de Inteligencia Artificial) 21 de agosto de 2024
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 21 August 2024.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Before collecting personal data from the internet to develop, train, test or deploy an artificial intelligence system, obtain the data subject's prior, express and informed authorization; a datum being accessible online does not make it a public datum exempt from that requirement.
- Complete and document a privacy impact assessment before an artificial intelligence system likely to pose a high risk to data subjects processes their personal data.
- Apply privacy by design and by default, including techniques such as differential privacy, so that data used to train an artificial intelligence system does not allow the person who provided it to be identified.
- Let a data subject obtain, at any time and without restriction, information about how an artificial intelligence system is processing their personal data.
Who enforces it
Enforcement body
Superintendencia de Industria y Comercio
What it reaches
Obligation class
Consent, DPIA, Governance, Data subject rights
Who checks it
Audit expectation
on_request
Who audits it
Self
Where the report goes
Produced on request
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The SIC's Circular Externa No. 002 de 2024 instructs every data controller and processor subject to Ley 1581 de 2012 and Ley 1266 de 2008 on how those technology-neutral statutes apply to developing, deploying, or using an artificial intelligence system that processes personal data.
It states that personal data being accessible on the internet does not make it data of a public nature, so a controller that collects personal, semi-private, or sensitive data online is not thereby entitled to treat it for an AI system's purposes without the data subject's prior, express and informed authorization.
It requires a documented privacy impact assessment before an AI system likely to pose a high risk to data subjects processes their personal data, requires privacy-by-design measures such as differential privacy so that training data cannot identify the person who provided it, and requires that a data subject be able to obtain, at any time and without restriction, information about how an AI system is processing their personal data.
When LexLint raises it
crawls_webtrains_modelshigh_risk_decisions
Read the law
Official Circular Externa text, Superintendencia de Industria y Comercio