Guide: Law 2573 of 2026 on Identity Theft in Colombia | Veridas

Ultimate Guide to the Identity Theft Law in Colombia (Law 2573 of 2026)

José Miguel Sánchez
Identity Verification Expert

Contents

On May 19, 2026, Statutory Law 2573 of 2026 (known as the Identity Theft Law) was enacted in Colombia. This regulation marks a turning point in fraud management within the country, becoming a momentous regulatory shift that completely redefines corporate responsibility across both physical and digital customer service channels.

The core of the law is clear: it removes the burden of proof from the citizen who is a victim of fraud and shifts all responsibility directly to companies. If your company assumes that current customer onboarding processes are sufficient because “that’s the way it’s always been done,” it is time to sound the alarm. The rules of the game have changed, and the financial risk is imminent.

Who is mandatorily affected by this identity theft law?

The regulation is of mandatory application throughout the Colombian territory and directly affects three major economic sectors involved in customer origination or onboarding processes:

In short: Practically any company in Colombia that sells on credit or under contract and requires a customer onboarding process for a new client falls under the umbrella of this law.

The Paradigm Shift with Law 2573 of 2026: Burden of Proof and the Security Obligation

Previously, if a criminal took out a loan in your name, you as a citizen had to go through an ordeal to prove that your identity had been stolen. Today, the scale tips completely through two critical pillars:

1. The Digital Security Obligation (Article 4)

The law expressly requires the obligated entities to “adopt sufficient and reasonable digital security measures necessary to establish the veracity of the identity of individuals and the documents presented.” In the current era, this takes on a critical meaning: Artificial Intelligence has democratized the creation of hyper-realistic deepfakes and the large-scale digital alteration of identity documents. Faced with this sophistication of AI-driven fraud, the law completely invalidates lax or merely visual and manual validation processes. A human eye is no longer capable of detecting a synthetic document, which suddenly raises the technical standard required for companies to operate and mitigate this technological risk.

2. The Dynamic Burden of Proof (Article 5)

In the event of an identity theft claim, “it will be up to the entities to provide the arguments and evidence that demonstrate due diligence in the onboarding or contracting processes.” If your entity does not have an unalterable technical record of how it verified that user, it will automatically lose the case. To shield this defense, it is fundamental to rely on identity verification solutions that offer timestamping for each process, guaranteeing the exact date and time the validation was performed and ensuring the immutable integrity of the evidence before regulators.

The Legal and Financial Abyss After the Identity Theft Law: The Consequences of Failing

Law 2573 does not create direct technical penalties or independent fines simply for “not having biometric software.” The real approach is linking it to compliance with Habeas Data (Article 11). If your identity verification (IDV) system fails or does not store evidence, the regulatory bodies (the SIC and the Superfinanciera) will apply a devastating sanction regime:

Additionally, the regulatory bodies (SIC, Superfinanciera, and MinTIC) have until November 20, 2026, to formally regulate the technological mechanisms, tools, and methodologies that will be mandatory for full user identification and report handling.

Veridas: The Technological Shield Against Law 2573

At Veridas, we provide the exact technological solution required by this new regulation. Our identity verification (IDV) technology and the generation of robust technical evidence are the key tools to mitigate legal risks and protect your revenue streams:

Frequently Asked Questions (FAQs)

When did the identity theft law in Colombia (Law 2573 of 2026) come into effect?

The law was enacted on May 19, 2026, in Colombia. Obligated companies must immediately review their authentication controls.

What exactly happens if a customer claims fraud and we have no way to prove that we verified their identity?

Due to the reversal of the burden of proof (Art. 5), if your company does not provide the arguments and unalterable technical evidence of having applied due diligence, you will lose the case automatically. Furthermore, you have a strict limit of 15 business days to resolve the claim; if the deadline expires without a response backed by evidence, Positive Administrative Silence will take effect, forcing your company to absorb 100% of the loss and wipe out the debt.

Is my company required to comply with this law if we only do online sales?

Yes. If your online store (e-commerce) or digital platform is involved in credit origination processes, direct financing, or installment sales through contracts, you are an obligated entity under the law, just like traditional banks, fintechs, or telecommunications companies.

Is Veridas an obligated entity under this regulation?

Veridas is not an obligated entity. However, the Veridas platform provides the technical evidence, audit logs, and certified biometrics that obligated entities (banks, telcos, and merchants) mandatorily need to defend themselves against claims and comply with the burden of proof.