Article 9 of Colombia’s Law 1581 of 2012 establishes the principle of “verifiable consent”. Processing of personal data requires prior, explicit, informed and traceable consent from data subjects; tacit consent has no legal effect. Subsequent SIC Practical Guide on Personal Data Protection and the Joint Circular Circular Conjunta No.001 de 2025 issued jointly by MinTIC and SIC further elaborate implementation standards: for marketing SMS scenarios, a secondary verification via verification code is required to validate ownership of the telephone number, commonly referred to in the industry as Double Opt‑in.
On 12 March 2026, Resolución SIC‑2026‑1123 (case involving heavy fines imposed on a cross-border cloud communications provider) formalised this operational standard through an administrative ruling. Marketing SMS sent without completing secondary verification by verification code shall be deemed unlawful transmission. This ruling carries administrative binding force for all A2P service providers and local PCA/IT integrators. The same consent requirements apply to outbound marketing voice calls.
From an operational perspective, a complete Double Opt‑in process consists of two steps: first, the user actively submits their mobile number; second, the user receives and enters the verification code for confirmation. Full records including timestamps, IP addresses and verification codes must be retained, and consent archives shall be stored for no less than 12 months. Single consent obtained merely by checkbox ticking is insufficient to defend against regulatory investigations. Even if mobile number databases are provided by overseas upstream clients, local PCA/Integrador Tecnológico as the onshore responsible entity remains obligated to verify Double Opt‑in evidence and cannot shift the burden of proof to overseas upstream parties.
