Identity theft has become a growing risk for companies that provide financing, sell goods or services on credit, manage postpaid arrangements, or report information to credit bureaus. In such cases, individuals may discover that their personal data has been used to purchase a product, contract a service, or incur an obligation they never authorized.
Statutory Law 2573 of 2026 seeks to protect individuals and legal entities against collection actions and negative credit reports arising from this type of fraud. Its primary effect is to assign companies a more active role in preventing, investigating, and resolving identity theft cases.
As a general rule, the law will enter into force on November 19, 2026. However, the provisions concerning the issuance of security protocols and the consequences of failing to comply with them have been in force since the law was enacted, in accordance with Article 13.
Which companies should pay attention to this law?
Law 2573 expressly applies to telecommunications operators, financial or credit institutions, and other commercial establishments with the authority to approve goods or services, create payment obligations, and provide financial or credit information. In the private sector, its application does not depend solely on the company’s registered business activity. The determining factor will be the manner in which the company interacts with its customers and the obligations arising from that relationship.
A company may fall within the scope of the law when it directly finances its products, makes sales on credit, manages receivables, provides postpaid services, or reports its customers’ payment behavior. It may also be subject to the law when acting as a source of information, meaning that it obtains personal data through a commercial or service relationship and subsequently provides that data to an information operator, as defined in Article 3.
This means that the law should not automatically be applied to every transaction carried out by a company. A business that only makes cash sales and does not create subsequent obligations is in a different position from one that finances goods, collects installments, or reports defaults to credit bureaus. Each company must determine which of its products or services may result in a debt, a subsequent collection action, or a credit report. Its compliance measures should focus on those transactions.
Prevention begins with identity verification
The first corporate duty is to adopt sufficient and reasonable measures to verify individuals’ identities and the authenticity of the documents submitted to purchase a product or contract a service. Article 5 also requires the implementation of mechanisms to validate the information provided by customers. The law does not require a particular technology or mandate the use of biometric verification in every transaction. The level of control may be adjusted according to the level of risk.
A low-value sale does not necessarily require the same mechanisms used to approve a loan, make a disbursement, or finance a higher-value asset. In some cases, verifying the identity document, email address, and telephone number may be sufficient. Higher-risk transactions may require multifactor authentication, confirmation through a second channel, biometric verification, or liveness checks.
What truly matters is that the company can demonstrate which controls it applied and the outcome of those controls. It must therefore properly retain applications, agreements, documents, recordings, messages, electronic records, and any other evidence used to approve the transaction. This obligation is connected to the principle of the dynamic burden of proof established in Article 2. In identity theft cases, the company is generally in a better position to explain how the contract was entered into and which documents were submitted. For this reason, it must provide the information used to approve the relevant good or service.
A complaint must trigger an immediate response
One of the most significant changes introduced by Law 2573 is that a company may not continue its normal collection activities while reviewing a complaint concerning possible identity theft. From the moment a person states that they do not recognize an obligation, the company must immediately suspend the provision or use of the fraudulently contracted service, whenever possible. It must also stop collecting the principal, installments, interest, collection costs, and any other amounts associated with the disputed obligation.
The suspension must also cover calls, messages, pre-litigation collection measures, and new negative credit reports. It is not sufficient for the legal department to receive the complaint while the company’s receivables systems continue to generate interest or collection notices automatically. Articles 5 and 8 require the suspension to be effective and timely. To comply with this obligation without creating an excessive operational burden, the company may introduce a special status within its receivables system for obligations suspended due to possible identity theft. This status should simultaneously block collections, interest, and reporting while the case is under review.
The company must also inform the complainant that they have twenty business days to file a criminal complaint with the Office of the Attorney General and submit the corresponding supporting documents. If the person does not provide this documentation within the statutory period, the company may resume collection and reporting activities under Article 8.
The company must provide the information and investigate the case
Upon request, the company must provide the person who was allegedly impersonated with copies of the information and documents used to approve the product or service and may not refuse to do so. In addition, when acting as a source of information, the company must compare those documents with the documents provided by the true identity holder within the following ten business days. This review may include verification of identity, signatures, contact details, authentication records, and information relating to the delivery of the goods, provision of the service, or disbursement of funds.
When a criminal complaint for false personation has been filed, the record must be marked with the statement “Victim of False Personation”. This notation may not be treated as negative information, reduce the person’s credit rating, or adversely affect financial assessments. The company must also request the correction of the payment history, credit score, and any other information that attributes to the person an obligation they did not incur. Accordingly, handling the case does not end with suspending collection activities. The company must also ensure that the relevant financial and credit information is corrected in a timely manner.
The company must investigate the fraud and report the scam when the comparison of the documents reveals material discrepancies. It must also determine whether employees, contractors, intermediaries, sales personnel, or technology providers participated in the transaction, particularly where there are indications that internal controls were omitted or applied improperly. When the documentation clearly demonstrates identity theft, the company must eliminate the obligation, terminate collection efforts, and correct the reports without waiting for the criminal proceedings to conclude.
If the evidence is inconclusive and the affected person has submitted the required criminal complaint and supporting documentation within the applicable period, the company must keep collection activities suspended until a judicial decision is issued. Once the proceedings have ended, the company must permanently eliminate the obligation if the identity theft is confirmed. Alternatively, it may resume collection under Article 9 if the competent authority concludes that the fraud did not occur.
The law also requires the company to submit the corresponding report to Colombia’s National Tax and Customs Authority, DIAN, to prevent the fraudulent transaction from creating adverse tax consequences for the impersonated person. The form and channel for submitting this report must comply with the instructions issued by the competent authorities.
Consequences of non-compliance
When it is established that the company failed to comply with the applicable security guidelines or protocols and an identity theft complaint has been filed, the company must suspend collection activities, amend the relevant reports, and, where appropriate, refund the amounts collected or eliminate the receivables arising from the fraud. Article 5, paragraph 2, further provides that the company may not indefinitely wait for authorization from the holder of the account to which the funds were transferred before carrying out the corresponding reversal.
Failure to respond within the statutory time limits may also result in the complaint being deemed resolved in favor of the identity holder, without prejudice to any proceedings that may be initiated by the Superintendence of Industry and Commerce or the Financial Superintendence of Colombia.
An opportunity to review corporate processes
Law 2573 of 2026 changes the way companies must respond to identity theft. An organization that approves a product, creates an obligation, manages receivables, or reports information may no longer simply shift the problem to the affected person. It must demonstrate how identity was verified, suspend collection activities in a timely manner, provide the relevant documentation, correct the reports, and investigate the circumstances surrounding the transaction. Implementation may be simple and proportionate, provided that the procedure is effective, properly documented, and understood by the departments involved in customer onboarding, receivables management, collections, and customer service.
At DEC Consultores, we assist companies in determining the scope of Law 2573 of 2026, reviewing their customer onboarding and receivables processes, and designing protocols for preventing and handling identity theft cases. Contact our team to schedule a diagnostic meeting and identify the measures your company must implement before the law enters into force generally.