In brief

On 19 May 2026, the Congress of the Republic of Colombia enacted Statutory Law 2573 of 2026, introducing a new protection framework for identity theft that directly impacts telecommunications providers, financial institutions and commercial businesses. In addition to strengthening the rights of identity theft victims, the law establishes new obligations concerning customer identity verification, the handling of fraud claims, the retention of supporting documentation, the suspension of collection activities, and the correction of credit reporting information. As a result, organizations should review their customer onboarding and fraud prevention processes to mitigate operational, regulatory and legal risks arising from identity theft schemes.

Although the law will enter into force six months after its enactment, certain provisions related to the development of regulatory protocols became effective upon its publication.

Key takeaways 

Law 2573 of 2026 aims to establish measures, processes and policies to protect individuals affected by the fraudulent use of their personal data to acquire goods or services, preventing improper collection activities and adverse credit reporting resulting from identity theft.

Its main developments include the following:

  1. Immediate suspension of collection activities: Once an entity is notified of an alleged identity theft, it must immediately suspend the collection of the relevant goods or services, including accrued interest, collection fees and any related charges.
  2. Protection against adverse credit reporting: Where an individual claims to be a victim of identity fraud and provides the relevant supporting documentation, the information source must request the correction of the reported information and include the designation "Victim of Identity Fraud" in the individual's record, without any adverse effect on the individual's credit score or creditworthiness assessment.
  3. New identity verification obligations: Telecommunications providers, financial institutions and commercial businesses must implement digital security measures and reasonable verification mechanisms to validate the identity of individuals acquiring goods or services.
  4. Timely handling of claims: Entities must process requests and complaints submitted by individuals claiming to have been victims of identity theft within 10 business days following their submission, in accordance with Law 2157 of 2021.

 

What does this mean for businesses?

Although the law has primarily been presented as a mechanism to protect victims of identity theft, its practical implications extend well beyond credit reporting.

The new regulatory framework raises regulatory expectations regarding the measures companies use to verify the identity of customers and users. As a result, organizations that offer goods or services through physical or digital channels should assess the effectiveness of their authentication, customer onboarding and transaction approval processes, particularly in areas with greater exposure to document fraud or identity theft schemes.

In addition, the law expressly incorporates the principle of dynamic burden of proof, requiring entities to provide the information and documentation used to approve a product or service whenever an individual claims to have been the victim of identity theft. This increases the importance of maintaining adequate document traceability and preserving evidence related to customer onboarding and verification processes.

Risks of investigations and liability in identity theft cases

Law 2573 of 2026 also establishes mechanisms aimed at facilitating the detection, investigation and prosecution of fraud schemes involving identity theft.

In particular, where discrepancies are identified between the documents used to obtain a product, service or financial obligation and those subsequently provided by an individual claiming to have been the victim of identity theft, the relevant entity must report the matter to the competent authorities. The law also contemplates investigations aimed at determining the potential involvement of employees or other personnel in identity theft schemes where circumstances suggest such participation.

These provisions underscore the importance of implementing robust procedures for incident response, internal investigations, evidence preservation and coordination with enforcement authorities in cases involving suspected fraud. From a compliance and corporate investigations perspective, organizations should ensure that their fraud response frameworks are capable of identifying, documenting and appropriately escalating potential identity theft incidents.

Practical recommendations 

Companies affected by Law 2573 of 2026 should review their internal procedures from both a preventive and operational perspective. In particular, we recommend considering the following measures:

  • Review identity verification mechanisms used across both physical and digital channels to assess whether they reasonably verify the applicant’s identity and effectively detect documentary or transactional inconsistencies.
  • Assess the adequacy of controls designed to detect document fraud and identity-related fraud, particularly in customer onboarding, product approval and service acquisition processes.
  • Update complaint-handling protocols to ensure there is a clear process for identifying claims involving potential identity theft, triggering the suspension of collection activities and coordinating the delivery of relevant documentation to the affected individual.
  • Review credit reporting and collection procedures to avoid pursuing disputed obligations arising from alleged identity theft and to prevent adverse credit reporting that may improperly affect the data subject.
  • Enhance internal investigation, evidence management and regulatory response procedures, strengthening document traceability and record-keeping practices in anticipation of potential requests for information and supporting documentation in identity theft cases.
  • Monitor forthcoming regulations to be issued by the Superintendence of Industry and Commerce (SIC), the Financial Superintendence of Colombia (SFC) and the Ministry of Information and Communications Technologies (MinTIC) regarding protocols for handling suspected identity theft cases.

 

Additional information

Statutory Law 2573 of 2026 was enacted on 19 May 2026 and will enter into force six months after its enactment, except for paragraphs 1 and 2 of Article 5, which became effective upon the law’s publication.

For further information, please refer to Law 2573 of 2026 at the following link: Ley 2573 de 2026 Congreso de la República - Gestor Normativo - Función Pública.

Santiago Jaramillo, Associate, has contributed to this legal update.

Download the Spanish version.

Explore More Insight