CiberLATAMbywhalemate

Colombia moves to classify biometrics as sensitive data

Colombia has refiled a reform to Law 1581 to add biometrics to sensitive data rules, tighten company duties and increase penalties.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Colombia refiled in August 2026 a reform to Law 1581 of 2012 to add unique-identification biometrics to the sensitive data regime, expand company obligations and strengthen sanctions. The bill is still moving as a statutory law and has not yet been assigned a number.

Update September 15, 2026: Colombia refiled the reform to Law 1581 of 2012 in August 2026 and now seeks to add unique-identification biometrics as sensitive data. The bill is still moving as a statutory law, has not been assigned a number, and adds new requirements for companies, along with prior review by the Constitutional Court.

Brazil, Chile, Mexico, Colombia, Peru and Guatemala all have cybersecurity, data protection and digital security proposals moving through their legislatures, though at different stages and with different effects for companies, public agencies and digital platforms. In Brazil, an outline General Cybersecurity Law has already been sent to the Civil House, alongside a Senate bill to create a National Digital Security and Resilience Program, a committee-approved law that would prioritize funding against electronic fraud, and an initiative on remote drone identification.

What is happening in Brazil?

Brazil is advancing several regulatory tracks at once. The National Cybersecurity Committee finished drafting a General Cybersecurity Law in December 2025 and sent it to the Civil House, but it has not yet become a formal bill in Congress. At the same time, Senate bill PL 4.752/2025, sponsored by Esperidião Amin, was introduced to create a legal framework for cybersecurity and a National Digital Security and Resilience Program.

Brazil’s parliamentary debate has also moved forward on narrower issues. The Public Security Committee in the Chamber of Deputies approved PL 3751/2025, which would steer federal resources from the National Public Security Fund toward fighting virtual financial crimes and electronic fraud. The text includes the purchase of investigative software and digital intelligence tools, as well as technical cooperation with financial institutions and digital asset platforms, in line with the LGPD. The bill will now move to the Finance and Taxation Committee and the Constitution and Justice Committee.

Added to that is PL 5255/2026, registered in the Federal Senate, which would require a remote real-time identification system for drones sold in the country and is listed as pending in the plenary. On the regulatory side, a comparative international analysis cited by Telefónica says Chile’s 2024 Law 21.663, inspired by Europe’s NIS2 directive, serves as a reference for designing Brazil’s future cybersecurity framework.

What changes are Chile, Mexico and Colombia discussing?

Chile, Mexico and Colombia each have different files moving, but all point toward stricter rules for data handling and digital security. In Chile, cybersecurity law 21.663 has already been highlighted as a Latin American adaptation of the European NIS2 directive, while the local data protection debate continues on its own track and other legislative coverage points to a delay in the entry into force of Law 21.719 until 2027, though that point is not part of the main comparative material in this note.

Mexico is moving on a bill the Senate received on September 2, 2026, which reforms the General Law on the Rights of Girls, Boys and Adolescents. The text seeks to protect minors’ personal data on digital platforms and apps, guarantee environments free of cyberbullying and violence, and requires authorities at every level to prevent, address and punish violence in digital settings. The bill was sent to joint committees for review and possible approval.

Colombia, meanwhile, is processing a bill to reform Statutory Law 1581 of 2012 on personal data protection. The text was refiled in the Chamber of Representatives in August 2026 as a statutory bill, still without an assigned number, after two earlier attempts that did not complete their progress in the 2024-2025 and 2025-2026 legislative sessions. The proposal would broaden the legal bases for data processing, add new categories of sensitive data, require impact assessments and make it mandatory to appoint a data protection officer in certain cases, while also raising penalties.

The main new element is that the draft explicitly includes "biometric data used to uniquely identify a natural person" as sensitive data. That wording limits the scope to identification biometrics, not biometrics in a generic sense. The specialized source cited in the material notes that the bill is not yet in force and remains in an early administrative stage within Congress.

Because this is a statutory law, the reform must go through four ordinary debates, two in the Chamber of Representatives and two in the Senate, within a single legislative session, plus prior and automatic constitutional review by the Constitutional Court before presidential approval. For banks, fintechs and other companies that use biometrics for onboarding, authentication or identity verification, that means reviewing the legal basis for processing, subjecting those uses to impact assessments, adjusting storage models and formalizing the data protection officer role.

The debate also comes with regulatory and judicial precedents. The Superintendence of Industry and Commerce opened consultations on identity verification systems, including biometrics, and the Constitutional Court has reiterated that the state’s collection of biometric data for procedures such as passports does not, by itself, violate privacy or habeas data rights, although it ordered clear rules on retention, justification and possible deletion of that data. At the same time, labor guidance cited in the material distinguishes between direct biometric images, encrypted templates and anonymized records, with different classifications under the personal data regime.

What happens if a company uses biometrics in Colombia?

The Colombian bill would force companies to review how biometric data is collected, stored and justified, because processing could fall under a stricter sensitive-data category. That would especially affect banks, fintechs and employers that use fingerprints, facial recognition or mathematical templates to identify people or manage access and attendance.

The labor practice guidance cited in the material sets out three different technical scenarios. Direct biometric images are treated as direct sensitive data, encrypted vector-based mathematical templates are treated as pseudonymized sensitive data, and anonymized records become anonymous data. That distinction will matter if the reform advances, because not every biometric record will receive the same legal treatment or require the same safeguards.

What is happening in Peru and Guatemala?

Peru does not yet have a general cybersecurity law in force, and Congress only has scattered initiatives, according to the regulatory analysis cited in the material. Those include an opinion declaring the creation of a High-Level State Cybersecurity Committee to be in the national interest, based on bills 8842/2024-CR and 9906/2024-CR, and another declaring November 30 National Cybersecurity Day, based on bills 13415/2025-CR and 13511/2025-CR. For now, there is no approved general regime of cybersecurity obligations.

Guatemala’s discussion is more advanced. Initiative 6347, called the Cybersecurity Law, was introduced in 2024, received a favorable opinion with amendments in August 2025, reached its third reading in April 2026, and was then sent back to committee for further study and a new opinion. The bill aims to protect the confidentiality, integrity and availability of information, strengthen cybersecurity and cyber defense capabilities, create a national CSIRT, and safeguard state information systems and critical infrastructure. Investigative coverage of this initiative also identifies CSIRT-GT as one of its pillars for coordinating responses to information security incidents and protecting critical state infrastructure.

Sources

View all