TMT 2025

COLOMBIA Law and Practice Contributed by: Maria Carolina Pardo, Ciro Meza, Angélica Navarro and Carlos Ignacio Arboleda, Baker McKenzie

Specific regulations for cloud computing include External Circular 005 of 2019, issued by the Financial Superintendence of Colombia ( Super- intendencia Financiera de Colombia ; SFC), which delineates rules for the use of cloud computing services by financial institutions covering the requirements for risk management, data security and reporting obligations. Furthermore, Decree 338 of 2022 offers guidelines for digital secu - rity, identifying critical cyber infrastructures and managing risks associated with digital services. The SIC has issued several guides related to the processing of personal data in digital environ - ments, including the Security Guide for the Pro - cessing of Personal Data, the Security Incident Management Guide, the Guide for the Process - ing of Personal Data for E-commerce Purposes, the Guide for the Processing of Personal Data for Cloud Computing Services, the Personal Data Protection Officer’s Guide and the Guide for Keeping Personal Data Secure in the Digital Environment. These guides encompass obliga - tions and recommendations derived from the aforementioned laws, tailored to specific sec - tors. Certain regulated industries, such as banking and insurance, are subject to more stringent regulations regarding the use of cloud comput - ing services. Financial institutions must adhere to the specific requirements outlined in External Circular 005 of 2019, which mandates rigorous risk management and data security measures. Similarly, insurance companies are required to comply with regulations ensuring the security and confidentiality of customer data when utilis - ing cloud services. These additional regulations are intended to protect sensitive financial infor - mation and maintain the integrity of the financial system.

There are several other specific issues concern - ing the processing of personal data in the con - text of cloud computing in Colombia. One critical issue is data localisation, where companies must ensure that personal data processed in the cloud adheres to Colombian data protection laws if collected locally, regardless of whether the data is stored on servers located outside Colombia. Ensuring the security and privacy of personal data in the cloud is essential, and the control - lers of the data must implement robust security measures, such as encryption and access con - trols, to safeguard it from unauthorised access and breaches. Data controllers must also obtain explicit consent from individuals before process - ing their personal data in the cloud and be trans - parent about how the data will be used, ensuring it is only used for the purposes for which consent was given, and execute data transmission/trans - fer agreements if required. 3. Artificial Intelligence 3.1 Liability, Data Protection, IP and Fundamental Rights In Colombia, the regulatory framework for AI is currently under development. As of now, there is no specific legislation governing AI, but several regulatory bills are under discussion. Notably, Bill 059 of 2023 has been introduced to establish legal guidelines for the development, use and implementation of AI. This bill primarily aims to create policies for data protection, intellectual property (IP) rights and a code of ethics for AI usage. Additionally, it mandates that any AI- related proposals be registered with the Ministry of Science, Technology, and Innovation. Colombia is currently examining regulatory measures to protect individuals’ likenesses and moral rights in the context of deepfake technolo -

38

CHAMBERS.COM

Powered by