Every time you ask a guest for their ID to comply with SIRE or the TRA, you become responsible for that data before Colombia's Superintendencia de Industria y Comercio. The good news: reporting to the authorities doesn't require consent, and most hosts don't have to register anywhere. The catch: storing ID photos does have rules, and fines reach 2,000 monthly minimum wages.
Start for free with RapitraThis is where most hosts get confused, and it's the first thing to get straight:
You do NOT need the guest's consent. Article 10 of Law 1581 of 2012 expressly exempts information required by a public or administrative entity in the exercise of its legal functions. Migración Colombia and MinCIT require that report by law, so transmitting it isn't optional or negotiable with the guest.
You DO need consent, and every rule applies: tell them what you use it for, store it securely, don't repurpose it, and respond if they ask to see or delete it. The Article 10 exception covers the report, not your database.
The National Database Registry scares a lot of people, but under Decreto 1074 de 2015 only these are required to register: companies and non-profits with total assets above 100,000 UVT, and public legal entities. Natural persons are expressly excluded.
In plain terms: if you're an individual host, you don't have to register anything in the RNBD — no matter how many properties you have. If you operate through a company, it only applies above that asset threshold, which is calculated using the UVT in force each year. Note: not being required to register does NOT exempt you from the rest of the law.
Article 5 of Law 1581 classifies biometric data as sensitive data, the most protected category. A facial photograph on an ID or passport falls in that zone, and that changes the rules:
Consent must be explicit — it can't be implied or buried in a wall of text
You must expressly state that this is sensitive data and what you use it for
The guest is not obliged to authorize the processing of sensitive data (Article 6)
You can't condition the stay on handing over more data than is necessary
Practical consequence: only ask for the ID photo if you genuinely need it. If you can comply with SIRE by capturing the document's data without keeping the image, you reduce your legal exposure without losing compliance.
Get informed consent
Before collecting, the guest must know who you are, what data you'll process, what for, and what their rights are. An "I accept" checkbox with no explanation doesn't cut it.
Have a data processing policy
It's mandatory for every controller, regardless of size. It must be a consultable document stating purposes, data subject rights, and your contact channel.
Keep proof of consent
The burden of proof is on you: if the SIC asks, you must be able to show when and how each guest consented. A timestamped record is the simplest way to have it.
Protect the information
ID documents can't live in a WhatsApp chat, your phone's photo gallery, or a shared cloud folder. Reasonable security measures against unauthorized access are required.
Handle queries and complaints
Guests can ask to access, update, correct, or delete their data. You have legal deadlines: 10 business days for queries, 15 for complaints.
Don't keep them forever
Data may only be kept while necessary for the purpose that justified it; keeping it indefinitely "just in case" is a violation. On the data that lives in Rapitra the deadline applies automatically. On any copies you hold elsewhere — your email, your phone, a spreadsheet — applying it is up to you.
Use it for marketing without separate, specific consent for that
Share or sell it to third parties the guest didn't authorize
Publish it, show it to other guests, or post it in group chats
Keep it indefinitely once the purpose has been fulfilled
Condition the service on handing over sensitive data that isn't necessary
Refuse to delete it when the subject asks and no legal obligation requires keeping it
The Superintendencia de Industria y Comercio investigates and sanctions. Under Article 23 of Law 1581 of 2012 it can impose:
Fines up to 2,000 monthly minimum wages (SMLMV), personal and institutional
Suspension of processing activities for up to 6 months
Temporary closure of processing operations
Immediate and permanent closure when sensitive data is involved
In August 2025 the Government filed a bill to raise that cap to 10,000 SMLMV and add an alternative criterion of 5% of the offender's operating revenue. It passed a first debate but was shelved without completing its passage — as was an earlier attempt the same year — because a statutory law must be approved within a single legislature. The 2,000 SMLMV cap therefore still stands; that this was the second attempt in two years signals where enforcement is heading.
Complying with this law remains yours: the processing policy and handling queries and complaints are defined by you as the controller. What Rapitra takes off your plate is the part where penalties most often come from simple forgetfulness — filing the TRA and the SIRE for every guest — so the data you already collect serves the legal purpose that justifies it and pending reports don't pile up. And it applies the deletion deadline for you on the data that lives in the platform.
ID documents are deleted 30 calendar days after check-out, and guest identifying data is anonymised after 6 months. The process runs automatically every day: it does not depend on anyone requesting it.
No. Article 10 of Law 1581 of 2012 exempts information required by a public entity in the exercise of its legal functions. Migración Colombia requires that report, so it doesn't depend on the guest's consent. What does require consent is collecting and storing that data in your own system.
If you're a natural person, no — they're expressly excluded. If you operate as a company, only if your total assets exceed 100,000 UVT. The vast majority of hosts fall outside that obligation, but the rest of the law still applies to you.
It's a bad idea. ID documents require reasonable security measures, and a photo gallery or WhatsApp chat doesn't meet them: they back up to the cloud, get shared by accident, and are readable by anyone who unlocks the phone.
The law sets no fixed number: only as long as necessary for the purpose. Beware of a common but mistaken line of reasoning: keeping the data "to prove you filed" does not protect you, because the record of that filing is held by MinCIT and Migración Colombia in their own systems. A guest sitting in your database with no transmission attached is evidence against you, not for you. In Rapitra, document images are deleted 30 days after check-out and identifying data is anonymised after 6 months; for any copies you hold elsewhere, set your own period and check it with an advisor.
You have 15 business days to answer a complaint. If the purpose is fulfilled and no legal obligation requires keeping it, you must delete it. If such an obligation does exist, you may refuse, but you have to explain the basis.
Rapitra automates TRA and SIRE reporting for every booking, so the purpose that justifies collecting that data is fulfilled on time and without relying on your memory.
Start for free