The following outlines the key data protection requirements under Colombia’s Law 1581 of 2012 and related regulations, and how IDMERIT ensures full alignment with these legal obligations to the greatest extent possible:
Consent
Under Colombia’s Law 1581 of 2012, personal data processing requires prior, express, and informed consent from the data subject. Consent must be clear, voluntary, and documented before any personal data can be collected, stored, or used for purposes such as identity verification.IDMERIT ensures that all data processing activities are based on valid consent and aligned with Colombian regulatory requirements. We work closely with our data providers and partners to ensure that personal data used in our services is collected and shared in compliance with applicable authorization standards.We are committed to maintaining transparent, consent-driven data practices that fully respect the rights of data subjects under Colombian law.
Security
Under Colombia’s Law 1581 of 2012 and related data protection regulations, personal data must be processed securely to ensure confidentiality, integrity, and proper use, including during cross-border verification activities. IDMERIT’s identity verification solution connects securely to authorized data sources through encrypted APIs to validate identities, while only returning verification results to the requesting system. This ensures that sensitive personal data is protected, minimizes unnecessary data transfer, and fully aligns with Colombian data protection requirements and best security practices.
Legitimate Interest
Under Colombia’s data protection framework, personal data may be processed when there is a valid legal basis such as authorization or a legitimate business need, including compliance with KYC and AML obligations. IDMERIT ensures that all identity verification activities are carried out lawfully, transparently, and with appropriate safeguards, supporting Colombian businesses in meeting regulatory requirements while maintaining responsible and compliant data processing practices.