Colombia’s data protection authority has issued two opposing yet legally binding decisions about biometric authentication in financial services, creating uncertainty and compliance challenges for businesses.
The Superintendencia de Industria y Comercio (SIC) imposed a penalty on September 16, 2025, against an online marketplace for demanding biometric data as a prerequisite to access an existing customer account. Just two days later, the same regulator released Circular Externa 001 of 2025, recognizing that biometric processing plays an essential role in preventing fraud, verifying identities, and validating high-risk transactions within financial and quasi-financial sectors.
The contradiction arises from a fundamental legal provision: Article 2.2.2.25.2.3 of Decree 1074 of 2015 bars service providers from requiring sensitive data, including biometrics, unless they offer genuine and equivalent non-biometric alternatives. The SIC has made clear these alternatives must be substantive, not merely symbolic. However, the Circular Básica Jurídica (later reissued as Circular Externa 006 of 2025) narrows this requirement to cases where clients have physical or medical disabilities, excluding those who simply decline biometric verification.
This creates a regulatory dilemma: financial institutions must implement robust identity verification to combat fraud, yet the most reliable method, biometrics, faces legal restrictions. The SIC’s stance forces businesses to strengthen fraud prevention while simultaneously limiting the tools available to do so. Law 2573 of 2026 further complicates matters by placing the financial burden of fraud detection on institutions, requiring measures such as suspended transactions, expedited document verification, and mandatory identity checks, even as it restricts the most effective fraud-detection methods.
The predictable outcome is that fraudsters will target the weakest verification pathways. When regulators mandate non-biometric alternatives, they inadvertently highlight which verification methods are less secure. The requirement to provide alternatives does not eliminate risk; instead, it shifts it toward the channels that are easiest to exploit.
While biometrics are not a universal solution, their irreversible nature raises valid privacy concerns. The current legal framework, however, fails to define what constitutes an acceptable non-biometric alternative, or how institutions should respond when fraud occurs through the verification methods regulators have compelled them to adopt.
In the absence of clear directives, companies are left to develop makeshift compliance strategies. Some are testing device-based authentication, real-time official database cross-references with automatic data deletion, or tiered validation processes based on transaction risk. To withstand regulatory scrutiny, institutions must document these decisions proactively, justifying their necessity before any incident arises, not just during an investigation.
