
The National Database Registry (Registro Nacional de Bases de Datos or RNBD) is the public registry administered by the Colombian Superintendency of Industry and Commerce (Superintendencia de Industria y Comercio or SIC) in which personal databases subject to processing in Colombia must be registered when their controller falls within the categories required to do so under applicable law. Among other matters, the registry identifies who processes the information, the purposes for which it is processed and the channels available for data subjects to exercise their rights.
Registration with the RNBD does not replace the other obligations established under Colombia’s personal data protection regime. As applicable, the data controller must also have a data processing policy, privacy notices, mechanisms to obtain and retain authorizations, procedures for handling inquiries and complaints, and appropriate security measures.
What is a personal database?
A database is an organized collection of personal data that is subject to processing. It may be stored in physical or electronic form and is not subject to a minimum number of records. Records relating to employees, customers, suppliers, contractors, users, students or patients may constitute databases when they contain information associated or capable of being associated with natural persons.
For RNBD purposes, it is essential to identify each database, its purpose, the manner in which the data is processed, the categories of data stored, and the persons acting as data controllers or data processors.
Who is required to register their databases?
Under the scope established by Decree 90 of 2018, the following entities must register their databases with the RNBD:
- Companies and nonprofit organizations with total assets exceeding 100,000 Tax Value Units (UVT).
- Public legal entities.
An organization that does not meet the asset threshold may be exempt from the registration requirement, but it remains subject to Law 1581 of 2012 and all other rules applicable to personal data processing. This distinction is fundamental: not being required to register a database does not mean being exempt from the data protection regime.
What information must be reported to the RNBD?
Registration requires the collection and reporting of accurate information about the data controller and each database. Depending on the nature of the processing, the registration mainly includes:
- Identification and contact information of the data controller and data processors.
- The name and purpose of the database and the manner in which the data is processed.
- The channels available for data subjects to exercise their rights.
- The categories and nature of the personal data stored.
- The source of the data and the existence of authorization or a statutory exception.
- The security measures implemented to protect the information.
- Domestic or international transfers and transmissions of personal data, where applicable.
- The data processing policy.
The quality of the registration depends on a reliable preliminary inventory. Before completing it, organizations should verify which databases exist, where they are stored, who has access to them, their purpose, the source of the data and the third parties with whom the data is shared.
Deadlines for registering and updating information
Registration of new databases
Databases created after the initial registration deadlines expired must be registered within two months of their creation, provided that the data controller falls within one of the categories required to register.
Annual update
Registered information must be updated annually between January 2 and March 31. The data controller must review each registration even if it considers that the information remains current.
Material changes
When material changes occur in the reported information, the registration must be updated within the first ten business days of the month following the month in which the change occurred. Material changes include, among others, changes concerning the purpose of processing, data processors, service channels, types of data stored, security measures, the data processing policy, and international transfers or transmissions.
Complaints and security incidents
Data subject complaints must be updated semiannually within the first fifteen business days of February and August. Security incidents affecting a database must be reported through the RNBD within fifteen business days following their detection and notification to the person or department responsible for handling them.
Penalties for noncompliance
Article 23 of Law 1581 of 2012 authorizes the SIC, following an administrative proceeding, to impose the following penalties on data controllers or data processors:
- Personal and institutional fines of up to the equivalent of 2,000 current statutory monthly minimum wages, which may be imposed successively for as long as the violation continues.
- Suspension of data processing activities for up to six months, together with instructions regarding the corrective measures that must be adopted.
- Temporary closure of data processing operations if the corrective measures ordered during the suspension are not adopted.
- Immediate and permanent closure of operations involving the processing of sensitive data, in the circumstances provided by law.
Any penalty will depend on the circumstances of the case, the statutory criteria for determining penalties and the proceedings conducted by the authority. Registration should therefore form part of an effective compliance program and should not be treated as an isolated formality.
Our National Database Registry services
Cárdenas Vega Asesores assists companies and other entities with preparing, registering and updating their information in the RNBD. Our services may include:
- Determining whether the registration requirement and applicable threshold apply.
- Taking inventory of, identifying and classifying personal databases.
- Reviewing or preparing the personal data processing policy and the documents required for compliance.
- Identifying data controllers, data processors, processing purposes, channels, data categories, and domestic or international data flows.
- Registering databases on the SIC platform and obtaining the relevant certificates.
- Completing annual updates and reporting material changes, complaints and security incidents.
Frequently asked questions about the RNBD
Must all companies register their databases?
No. The registration requirement applies to companies and nonprofit organizations with total assets exceeding 100,000 UVT and to public legal entities. However, those not required to register must comply with all other applicable personal data protection provisions.
Is registration a one-time requirement?
No. In addition to the initial registration, data controllers must complete annual updates and report material changes, complaints and security incidents within the applicable deadlines.
Does registering databases establish compliance with all legal requirements?
No. RNBD registration is a specific obligation. The data controller must also comply with the principles, duties, procedures and measures required under personal data protection law.
