Colombia Put Existing Privacy Law Inside the AI Lifecycle
Colombia’s data protection authority issued External Circular 002 on 21 August 2024. Rather than waiting for a dedicated AI statute, the circular applies existing personal-data law to the design, development and use of artificial intelligence systems.
The circular is addressed to data controllers under the supervision of the Superintendence of Industry and Commerce that develop, deploy or use AI systems involving personal data. Its central message is simple: calling a system artificial intelligence does not suspend the duties already attached to personal information.
That matters because AI projects can change rapidly between experimentation and production. Data may be reused, models may be supplied by third parties and outputs may influence people even when no one intended to build a formal decision system.
Privacy by design begins before deployment
The SIC expects privacy by design and by default. Safeguards should therefore be built into decisions about data collection, training, testing, access, retention and output use. Adding a privacy notice after deployment will not correct an excessive dataset or an architecture that exposes sensitive information.
Teams need to know what personal data enters the system, the legal basis for each use, whether the data is representative and accurate, and whether the same objective can be achieved with less information. These questions apply to prompts and retrieved data as well as traditional training sets.
Accountability must be demonstrated
Colombia’s accountability principle requires more than a statement that the organisation takes privacy seriously. Controllers need measures that are appropriate to the nature and risks of the processing, together with evidence that those measures work.
For AI, that evidence can include documented roles, data provenance, risk decisions, model and vendor assessments, testing results, human-review rules, security controls, complaint handling and records of changes after deployment.
The proportionality test disciplines data use
The circular calls for a proportionality analysis covering suitability, necessity and the balance between the intended benefit and the effect on rights. This is particularly relevant when an AI system profiles people, uses sensitive data or contributes to decisions about access to an opportunity or service.
A model can be technically accurate and still create an unjustified privacy impact. The question is not only whether the system works. It is whether this use of personal data is needed, whether a less intrusive design is available and whether the remaining impact is acceptable.
Impact assessment connects legal and technical risk
The SIC recommends privacy impact assessments where processing is likely to create significant risk. The assessment should be early enough to change the design and should continue when the model, data, purpose or deployment context changes.
This process should bring legal, privacy, security, engineering and business owners together. It can expose gaps that none of those functions would see alone, such as a vendor retaining prompts, a feedback loop that collects new personal data or an output that is difficult to contest.
What organisations should do
- Inventory AI systems and experiments that collect, infer, retrieve or disclose personal data.
- Document purpose, legal basis, data sources, recipients and retention for each material use.
- Run proportionality and impact assessments before high-impact deployment.
- Build privacy, security, human review and rights handling into the lifecycle.
- Require vendors to provide the evidence needed for the controller’s accountability.
Existing law already reaches the model
Circular 002 makes Colombia’s regulatory position clear. Organisations do not need to wait for a single comprehensive AI law before governing personal-data use in AI. The legal duties already exist, and the AI lifecycle is where they must be made operational.
Official sources
This article provides general information and is not legal advice.
Continue the series: LATAM Cyber & Digital Law Series index


