CiberLATAMbywhalemate

Colombia updates open finance deadlines

The SFC opened comments on GERCO and set the open finance data exchange timeline, while supervision rules remain in force.

Whalemate Labs · AI-assisted researchPublished:Updated 5 min read

Colombia’s financial watchdog opened two new regulatory processes, one on conduct-risk management for financial consumers and another on the information exchange timeline for open finance standards. Comments for both run until Sept. 15, 2026.

Update September 3, 2026: Colombia’s Financial Superintendence opened comments on a new draft external circular for GERCO and published the timeline for information exchange standards in the open finance system. It also kept a supplementary version of the draft in table format.

The Superintendence issued External Circular 007 of Aug. 26, 2026, requiring supervised entities to take steps to reduce the impact of the disaster situation on affected financial consumers. The move adds to a broader round of regulatory changes in Colombia, where the open finance agenda is now operating under new security deadlines, stronger data traceability requirements, and tighter digital identity controls.

What did the Financial Superintendence order?

External Circular 007 instructs supervised entities to adopt measures to lessen the impact of the disaster situation on affected financial consumers. The announcement was published by Colombia’s Financial Superintendence on Aug. 27, 2026, as part of its external circulars for that year.

The official source does not provide additional operational detail on those instructions, but it does confirm the regulatory هدف is to protect users hit by the disaster situation and guide the response of supervised institutions.

La República also reported that External Circular 007, dated Aug. 26, 2026, was issued to set relief measures for debtors affected by the disaster situation, during a period in which the Superintendence maintained additional supervisory activity.

What changed in the open finance roadmap?

The transition period tied to the security profile in External Circular 004 from February 2024 expired on Aug. 7, 2026, after two additional six-month extensions, according to a technical analysis by Ozone API of Colombia’s open finance roadmap.

That same analysis describes a staggered rollout for supervised entities once data standards are issued by category. The base deadline is 12 months, with a one-time extension of up to 6 additional months, plus another 6 months only for large-company data.

Under that sequence, the regulatory cap is 18 months for individuals and micro, small and medium-sized enterprises, and 24 months for large companies. Facephi Observatory adds that open finance obligations from 2026 are tied to data governance and audit requirements from the Financial Superintendence, including traceability of which data was used, under what explicit consent, and for what decision.

In parallel, Colombia’s Financial Superintendence published the draft circular letter dated Aug. 31, 2026, with the timeline for issuing information exchange standards for the open finance system, and opened comments until Sept. 15, 2026 at 5:00 p.m. The agency also kept a complementary publication of the same draft in table format.

What does the new GERCO draft mean?

Draft External Circular 14 of 2026 seeks to set instructions on the Management of Risk from Conduct Affecting Financial Consumers, under a public consultation process open until Sept. 15, 2026 at 5:00 p.m.

Colombia’s Financial Superintendence published the document as part of its 2026 regulatory activity, showing continuity in its market-conduct and financial consumer protection supervision agenda. The publication is not presented as an enacted rule, but as a draft subject to comments.

How does this affect sensitive data and digital identity?

The combination of open finance, data governance and audit strengthens controls over sensitive data and digital identity in highly personalized products, according to Facephi Observatory. In that framework, the use of information for financial decisions must be traceable and tied to explicit consent, according to the cited analysis.

That regulatory focus sits alongside a recent biometrics case in Cartagena. Infobae reported that a resolution dated June 18, 2026 ordered the permanent deletion of sensitive personal data, including iris codes, collected since the start of certain activities linked to alleged identity theft.

The same report says the resolution upheld a prior order from October 2025 and recommended that affected people exercise their habeas data rights. Those steps include requesting deletion from platforms, sending formal requests to the privacy team, unlinking accounts and, if needed, filing a complaint with the Superintendence of Industry and Commerce.

Specialized outlets also say that, in Colombia’s regulatory framework, the Financial Superintendence and Personal Data Protection Law 1581 impose strict demonstrated-accountability standards on payment gateways and e-commerce players, including information security and personal data protection requirements for payment services linked to the financial system.

A national business press analysis also says Colombia still lacks a comprehensive cybersecurity law, and that the legal framework for the digital and financial environment depends on scattered rules such as Law 1273 of 2009, Decree 338 of 2022 and the National Cybersecurity Strategy 2025-2027, presented in June 2026.

What about crypto assets and VASPs?

Colombia does not currently have a formal VASP registry, despite DIAN’s adoption of the CARF, because the bill that would have created it was shelved in August 2026, according to Fluyez’s report. That leaves the country without an authority that registers, authorizes or fully supervises exchanges operating in the local market.

At the same time, a legal analysis by Nieto & Nieto Lawyers notes that DIAN treats crypto assets as intangible assets under the general rules of the Tax Statute. The same analysis says using self-custody wallets does not remove tax obligations and cites an official May 2026 response in which DIAN said it does not have an automatic tool to link all private wallets to taxpayers.

The official list of regulatory projects from Colombia’s Financial Superintendence in 2026 shows continued regulatory activity, but the available documents do not identify explicit references to BCRA cybersecurity rules or CNBV or Banxico regulations, indicating no direct formal alignment with specific requirements from Argentina or Mexico in recent Colombian drafts.

Sources

View all