Guide: Law 2573 of 2026 on Identity Theft in Colombia | Veridas
Ultimate Guide to the Identity Theft Law in Colombia (Law 2573 of 2026)
José Miguel Sánchez
Identity Verification Expert
- July 3, 2026
- 5 mins read
Contents
On May 19, 2026, Statutory Law 2573 of 2026 (known as the Identity Theft Law) was enacted in Colombia. This regulation marks a turning point in fraud management within the country, becoming a momentous regulatory shift that completely redefines corporate responsibility across both physical and digital customer service channels.
The core of the law is clear: it removes the burden of proof from the citizen who is a victim of fraud and shifts all responsibility directly to companies. If your company assumes that current customer onboarding processes are sufficient because “that’s the way it’s always been done,” it is time to sound the alarm. The rules of the game have changed, and the financial risk is imminent.
Who is mandatorily affected by this identity theft law?
The regulation is of mandatory application throughout the Colombian territory and directly affects three major economic sectors involved in customer origination or onboarding processes:
- Financial and credit institutions: Traditional banks, neobanks, credit fintechs, financial cooperatives, and commercial financing companies.
- Telecommunications operators: Mobile phone and internet providers—a sector especially vulnerable when it comes to post-paid service contracts or equipment and handset financing (where a high volume of identity theft has historically been concentrated).
- Commercial establishments: Any brick-and-mortar store or e-commerce platform involved in credit origination processes, offering installment sales, or providing direct financing through contracts.
In short: Practically any company in Colombia that sells on credit or under contract and requires a customer onboarding process for a new client falls under the umbrella of this law.
The Paradigm Shift with Law 2573 of 2026: Burden of Proof and the Security Obligation
Previously, if a criminal took out a loan in your name, you as a citizen had to go through an ordeal to prove that your identity had been stolen. Today, the scale tips completely through two critical pillars:
1. The Digital Security Obligation (Article 4)
The law expressly requires the obligated entities to “adopt sufficient and reasonable digital security measures necessary to establish the veracity of the identity of individuals and the documents presented.” In the current era, this takes on a critical meaning: Artificial Intelligence has democratized the creation of hyper-realistic deepfakes and the large-scale digital alteration of identity documents. Faced with this sophistication of AI-driven fraud, the law completely invalidates lax or merely visual and manual validation processes. A human eye is no longer capable of detecting a synthetic document, which suddenly raises the technical standard required for companies to operate and mitigate this technological risk.
2. The Dynamic Burden of Proof (Article 5)
In the event of an identity theft claim, “it will be up to the entities to provide the arguments and evidence that demonstrate due diligence in the onboarding or contracting processes.” If your entity does not have an unalterable technical record of how it verified that user, it will automatically lose the case. To shield this defense, it is fundamental to rely on identity verification solutions that offer timestamping for each process, guaranteeing the exact date and time the validation was performed and ensuring the immutable integrity of the evidence before regulators.
- Immediate Protections for the Identity Theft Victim: Immediate Suspension and Protection: Upon reporting the fraud, the entity must freeze collections and interest. Credit bureaus (such as Datacrédito) will include the legend “Victim of Personal Forgery,” without this affecting the citizen’s credit score.
- Direct Exoneration: If there are evident discrepancies (such as signatures or photos that do not match), the company must exonerate the citizen directly, without forcing them to go through the Attorney General’s Office (Fiscalía).
- Positive Administrative Silence within 15 Days: Companies have a strict deadline of 15 business days to resolve claims by providing evidence. If they miss it by a single day, the fraud is assumed to be true, forcing the company to eliminate the debt and absorb 100% of the financial loss.
The Legal and Financial Abyss After the Identity Theft Law: The Consequences of Failing
Law 2573 does not create direct technical penalties or independent fines simply for “not having biometric software.” The real approach is linking it to compliance with Habeas Data (Article 11). If your identity verification (IDV) system fails or does not store evidence, the regulatory bodies (the SIC and the Superfinanciera) will apply a devastating sanction regime:
- Million-dollar Fines (Habeas Data): Under the regime of Law 1266 of 2008 (Article 18), violating the security, veracity, and quality of credit history data exposes companies to fines of up to 2,000 SMLMV (Minimum Monthly Legal Wages). This is equivalent to more than 2.6 billion COP (approximately $650,000 USD).
- Digital Blackout (Suspension of Channels): According to Law 1581 of 2012 (Article 23), if authorities prove that a web platform or mobile app lacks adequate technical measures and suffers from systematic fraud, they can order the temporary suspension of data processing operations, effectively disabling that digital sales channel.
Additionally, the regulatory bodies (SIC, Superfinanciera, and MinTIC) have until November 20, 2026, to formally regulate the technological mechanisms, tools, and methodologies that will be mandatory for full user identification and report handling.
Veridas: The Technological Shield Against Law 2573
At Veridas, we provide the exact technological solution required by this new regulation. Our identity verification (IDV) technology and the generation of robust technical evidence are the key tools to mitigate legal risks and protect your revenue streams:
- Auditable Technical Evidence: Our platform prevents fraud and automatically generates the technical logs, similarity scores, and audit trails necessary for clients to comply with Article 5 (burden of proof) before regulatory bodies.
- World-Class Technology: We displace competitors and basic or deficient IDV solutions that now carry a high risk of fines. Veridas’ positioning is built on proprietary biometric engines ranked among the top globally by NIST and backed by the iBeta ISO 30107-3 certification against presentation attacks and deepfakes.
Frequently Asked Questions (FAQs)
When did the identity theft law in Colombia (Law 2573 of 2026) come into effect?
The law was enacted on May 19, 2026, in Colombia. Obligated companies must immediately review their authentication controls.
What exactly happens if a customer claims fraud and we have no way to prove that we verified their identity?
Due to the reversal of the burden of proof (Art. 5), if your company does not provide the arguments and unalterable technical evidence of having applied due diligence, you will lose the case automatically. Furthermore, you have a strict limit of 15 business days to resolve the claim; if the deadline expires without a response backed by evidence, Positive Administrative Silence will take effect, forcing your company to absorb 100% of the loss and wipe out the debt.
Is my company required to comply with this law if we only do online sales?
Yes. If your online store (e-commerce) or digital platform is involved in credit origination processes, direct financing, or installment sales through contracts, you are an obligated entity under the law, just like traditional banks, fintechs, or telecommunications companies.
Is Veridas an obligated entity under this regulation?
Veridas is not an obligated entity. However, the Veridas platform provides the technical evidence, audit logs, and certified biometrics that obligated entities (banks, telcos, and merchants) mandatorily need to defend themselves against claims and comply with the burden of proof.