Rappi is publishing on its Colombian legal website a 71-page court file in a group action that seeks compensation for every person who registered on its app or website in Colombia before April 25, 2019, on the grounds that the delivery company could not prove those users ever authorized the use of their personal data.

In Short

A man in Bogota sued Rappi in 2020, saying the company used his personal details without the permission Colombian law requires, and he asked the court to let everyone in the same position join the case. The judge agreed to hear it, and in 2023 ordered Rappi to tell the people on its own user list that the lawsuit exists. Companies that send texts and emails to customers are watching because the case rests on a regulator's finding that ticking "I accept the terms" is not the same as giving consent.

The file Rappi is hosting

The page sits at legal.rappi.com.co under the heading "Acción de Grupo Expediente Número 11001-31-03-041-2020-00212-00", beneath a "Rappi, Inc." label and a country selector set to Colombia. The page carries no publication date. The copy reviewed for this article was printed with the stamp "9/10/26, 7:10 PM" and runs to 71 pages, two of which are blank. The footer of the page links to Rappi's personal data treatment policy, its terms and conditions, a user data authorization and a Colombia cookie policy.

The dossier is not a summary. It reproduces, in sequence, the original complaint against Rappi S.A.S., a correction filed after the court initially declined to admit it, a 13-page certificate of existence and legal representation from the Bogota Chamber of Commerce, the email that served the complaint on Rappi, a petition the plaintiff sent the company, a 16-page public version of a 2019 sanction issued by the Superintendencia de Industria y Comercio (SIC), and two orders from the 41st Civil Circuit Court of Bogota. Everything is in Spanish. Quotations in this article are translated from the original.

Why would a defendant publish the claim against it? The last order in the file answers that. On April 27, 2023, Judge Janeth Jazmina Britto Rivero ordered Rappi S.A.S. to inform each person on a list the company had supplied to the court that the action exists, so they could decide whether to join. The court said the list covered "an enormous magnitude of people" and that individual communications "far exceed the operational capacity of this court." Rappi, it added, is the party "that does enjoy the corresponding technological facilities."

Who is suing, and for whom

The plaintiff is Camilo Araque Blanco, represented by lawyer Juan David Mesa Ramirez. The complaint is dated "June 2020" in Bogota, signed through DocuSign, and addressed to the civil circuit judges of Bogota for allocation. It invokes Article 88 of Colombia's Constitution, which provides for group actions, and Law 472 of 1998, which regulates them. The defendant is Rappi S.A.S., identified with tax number 900843898-9, and the complaint names Felipe Villamarin Lafaurie as its legal representative.

The claim is brought on behalf of what Colombian procedure calls an open group: people whose identities cannot be fully established at the outset. The complaint sets three criteria for membership. Geographically, it covers every user registered on Rappi's website and app anywhere in Colombia. In time, it covers users registered "on a date prior to April 25, 2019," the date of the SIC sanction. And it includes anyone who can prove that status "through documentary means or any other means of proof."

A footnote qualifies the cut-off. The complaint says the date "is subject to the date on which RAPPI S.A.S. demonstrates the effective adoption of measures" ordered by the SIC, meaning users who joined after April 25, 2019 but before Rappi changed its practices could also qualify. That makes the eventual group larger than a simple date filter would suggest.

According to the complaint, Rappi collects "name, identification, physical address, email address, mobile number, socioeconomic stratum, consumption preferences, among many others." The socioeconomic stratum is a Colombian classification of residential areas used for utility pricing, and its appearance in the list of data points is one of the more specific details in the file.

What the complaint asks for

The complaint makes seven requests. The core one is an order for Rappi, as "controller and processor" of its users' data, to compensate the open and closed group for material and non-material damage.

For material damage, framed as "daño emergente," the complaint proposes a formula: the unit value of a personal data record, to be established during the proceedings, multiplied by the number of group members. No unit value is proposed.

For non-material damage, it proposes two separate amounts. Moral damage is set at one current monthly minimum wage per group member, "in the absence of an objective parameter for its quantification." A second category, damage to "personal goods of constitutional relevance," is also set at one monthly minimum wage per member. In both cases the complaint asks the judge, as an alternative, to fix the amount using the judicial discretion known as arbitrium judicis.

The remaining requests ask for the individual amounts to be added together, indexed and paid into the Fund for the Defense of Collective Rights and Interests administered by the Ombudsman's Office (Defensoria del Pueblo), with an alternative of crediting a balance to each member's Rappi account. The complaint also seeks non-monetary measures: public apologies "through the same media in which the advertising materialized," public commitments not to repeat the conduct, and publication of the judgment on Rappi's website "for a period of not less than 1 year." It asks for a committee to verify compliance, costs, and fees for the coordinating lawyers.

The complaint does not estimate the total. It says the amount "cannot be estimated" at this stage "because the exact information necessary" is missing, and it asks the court to order Rappi to report "the number of total users registered on its digital platforms (app and web page) cut off at April 25, 2019."

The plaintiff's own figure

The court did ask for a number. In the correction filed in August 2020, after an inadmission order dated July 31, 2020, the lawyer estimated Araque's individual damage at "one million pesos ($1,000,000 COP) or the higher amount proven," and noted that it was set "indicatively as the value equivalent to 1 smlmv." The correction refused to estimate the collective figure, arguing that it would be "a legal impossibility to calculate the individual damages of individuals who are not yet identified."

The correction also pushed back on the court's view that the group criteria were too general. It cited a Bogota Superior Tribunal decision in a group action against Uber Colombia S.A.S., case 2018-00313-01, where the tribunal reversed a lower court's rejection based on similar reasoning. "The cases are identical," the correction says: "there is a platform that causes different types of damage to its users."

The SIC sanction at the heart of the case

The complaint builds almost entirely on Resolution 9800 of April 25, 2019, issued by the SIC's Director of Personal Data Protection Investigation, Carlos Enrique Salazar Muñoz, under file number 18-89592. The public version included in the dossier explains how a single complaint turned into a set of orders covering all of Rappi's users.

The sequence, according to the resolution, began on November 3, 2016, when a Rappi user asked the company to stop using his data, requesting that it "abstain from (i) using my information and my data for any and all purposes; and (ii) sending me any email or data message to my email addresses and my mobile number." He kept receiving messages. He complained to the SIC on February 9, 2017.

Rappi told the regulator that text messages to the user stopped on March 10, 2017 and that he was removed from its SMS database on March 28, 2017. The SIC calculated that the user "had to wait four (4) months and twenty-five (25) days" for his request to be honored. His email address, Rappi said, was deleted only on April 27, 2018, because on March 15, 2018 he had asked to be included again. The SIC rejected that argument, finding that the evidence on file did not show "prior, express and informed consent" for the re-registration either.

Formal charges came through Resolution 21206 of March 26, 2018. A correction followed on June 29, 2018, and notice was served on July 12, 2018. Rappi, the resolution notes, did not file a defence within the 15-day window: "it remained silent." It later supplied evidence on September 28, 2018 and closing arguments on March 26, 2019, in which it said it had "at all times safeguarded the rights" of the data subject.

The finding that matters most for marketers concerns how Rappi recorded consent. Rappi argued, according to the resolution, that every user "at the moment of downloading the Rappi application must accept the terms and conditions," and it provided the time and date of the user's acceptance plus a screenshot of its registration record.

The SIC was not persuaded. Rappi's records, it said, "only indicate the date of creation of the user, without evidence that the data subject performed the validation of the 'check' in the box to accept the terms and conditions." It went further: "the terms and conditions must not be confused with the prior, express and informed authorization required by law. Although they are not mutually exclusive, the former do not necessarily meet the legal requirements of authorization."

The regulator also took issue with identity. Rappi's website said all visitors "must register and authorize the processing of personal data," but the SIC asked how Rappi could establish that a visitor was the specific person whose data it held "and not another person." Without that, it said, there was no way to confirm who had given consent at all. Under Article 2.2.2.25.2.4 of Decree 1074 of 2015, unequivocal conduct can count as authorization, but "in no case may silence be equated with unequivocal conduct." The SIC concluded it could not infer authorization "from the mere registration of a subscription date."

The fine and the orders

The SIC fined Rappi S.A.S. COP 298,121,760, equivalent to 360 monthly minimum wages, for breaching Article 17(a) of Law 1581 of 2012 (guaranteeing the data subject's right to habeas data) and Article 17(b) (requesting and keeping a copy of the authorization). Law 1581 allows fines of up to 2,000 monthly minimum wages, so the penalty was 18% of the ceiling, a calculation from the figures in the resolution. The SIC noted that it found no economic benefit to Rappi, no repeat offence and no obstruction, but declined to apply the mitigating factor for accepting the violations "since the investigated party did not recognize or accept" them.

The orders reached far beyond the single complaint. Within three months of the decision becoming final, Rappi had to adopt measures to:

  • stop sending text messages, emails or calls to people "with respect to whom it does not have full proof of the prior, express and informed authorization";
  • establish "the full identity" of website visitors and platform users whose data it collects;
  • delete data definitively when any user asks, "with respect to all the services" or specific ones;
  • keep proof of each user's authorization; and
  • offer free, easy deletion and revocation mechanisms "through the same means or channels" Rappi uses to contact people.

Rappi also had to set up permanent monitoring, deliver within two months a compliance certificate from an impartial third-party specialist, and commission an external audit whose results were due three months after the orders were met. Noncompliance, the resolution warns, could lead to fines of up to 2,000 minimum wages, suspension of the processing activities, or temporary closure of operations related to the processing.

One timing detail in the resolution does not line up neatly. The measures are due within three months, yet the third-party certificate of compliance is due within two months, measured from the same starting point. The resolution does not explain how compliance could be certified before the deadline for the measures themselves.

How the group action uses the SIC finding

The complaint treats Resolution 9800 as "documentary and circumstantial evidence" that until Rappi complied, it failed "generically" and "in relation to all its users" to meet "at least 6 mandatory rules" of a statutory law. A footnote makes the bridge explicit: although the administrative case "was triggered by a single user," the SIC's decision "concerns not only the specific case but its behavior in relation to other users."

Six specific failures are pleaded on Araque's behalf, mirroring the SIC's reasoning: no authorization for use of his data; denial of the right to deletion, because there was "no clear, free and easily accessible mechanism"; failure to guarantee habeas data rights; failure to keep a copy of the authorization; breach of the principle of freedom in Article 4(c) of Law 1581; and breach of the right to information under Law 1480 of 2011, the Consumer Statute. On the last point, the complaint argues that because Rappi's "main input" is "the personal data it captures from its users," its customers are e-commerce consumers protected by that statute, a status it says Rappi "has tried to deny."

The complaint also cites SIC Resolution 40212 of August 28, 2019, which it describes as an e-commerce order classifying Rappi as an online commerce provider. That resolution is listed among the annexes as "Orden Rappi SIC comercio elerctronico.pdf" but is not reproduced in the dossier.

Araque's own evidence is modest. The complaint lists four phone screenshots showing he is a Rappi user and a petition sent to Rappi on July 24, 2020 at 10:36, asking for "the date of my activation" and "the documents I signed or accepted for the handling and processing of personal data." The complaint says the petition went unanswered. The complaint and its annexes were emailed to felipe@rappi.com the same evening, at 22:19, under the procedure of Decree Law 806 of June 4, 2020, an emergency measure that moved Colombian court filings online during the pandemic.

From inadmission to admission

The court file shows a slow path. The complaint was filed in mid-2020 and found inadmissible on July 31, 2020 on four points: the group identification criteria, the way the non-monetary claims were framed, the absence of a damages estimate, and the power of attorney. The correction answered all four in August 2020.

The next document is the admission order, dated January 14, 2022, nearly 18 months after the correction. It admits the group action "filed by CAMILO ARAQUE BLANCO in his own name and on behalf of the group that may be formed by the people who have entrusted their personal data" to Rappi. It gives Rappi 10 days to answer, orders publication on the court's microsite on the Judicial Branch website, and orders notice to the Ombudsman under Article 53 of Law 472 of 1998.

The April 2023 order refers to a decision of the Bogota Superior District Tribunal dated January 28, 2021, which it says stressed the need to bring the group of possible victims into the proceedings. That decision is not in the file. Whether it reversed an earlier rejection, as happened in the Uber case the correction cited, cannot be confirmed from the documents.

The admission order also contains a slip. It describes the data as "not processed in accordance with Law 1581 of 2021." The data protection statute is Law 1581 of 2012, as every other document in the file states.

The 2023 notification order

The final document, dated April 27, 2023, records that Rappi complied with an order of May 26, 2022 by "providing the list of people who could eventually have suffered some harm." The court found that the list showed the group "easily exceeds" the 20 people Law 472 requires, and that those people are represented by the plaintiff under the paragraph of Article 48.

The court then shifted the burden of notification to Rappi. Within 15 days of receiving the communication, the company had to send each person on the list information about the action, together with the admission order, the complaint and annexes, and the April 2023 order, and then prove to the court that it had done so. The format, the court said, would follow Article 8 of Law 2213 of 2022, which made the pandemic-era digital notification rules permanent, and would explain that recipients may join under Article 55 of Law 472.

Rappi asked for privacy protections and got them. Because the list contains "sensitive data touching on the right to privacy of those who appear in it," the court ordered it kept in reserve "so that only the court has access to it." The number of people on that list does not appear anywhere in the published dossier.

What the corporate certificate shows

The Chamber of Commerce certificate, issued on July 23, 2020 at 21:11:18, fills in Rappi's corporate structure at the time. Rappi S.A.S. was incorporated by a private shareholders' document on April 23, 2015 and registered on April 29, 2015. Rappi Inc., domiciled outside Colombia, declared control over it effective March 3, 2016, and in August 2018 clarified that the business group included both RappiPay S.A.S. and Rappi S.A.S. as subordinates.

Authorized capital was COP 2.8 billion, with COP 1,800,122,350 subscribed and paid. The general manager could commit the company to contracts of up to US$2.5 million without shareholder approval. Felipe Villamarin Lafaurie was listed as general manager, with Simon Borrero Posada and Diego Felipe Alonso Cruz among the alternates.

The certificate contains one figure that looks out of place. Under the company size heading, it classifies Rappi S.A.S. as a "Microempresa" based on reported ordinary revenue of COP 198,980,406, with software development (CIIU code 6201) as its main activity. The certificate notes that the classification relies on "information reported by the registrant" in the RUES registry form. Nothing in the file reconciles that revenue line with the scale of operations the court described.

The certificate also records that on October 3, 2018, the 11th Civil Circuit Court of Bogota ordered a separate lawsuit, brought by an individual in a verbal proceeding, to be inscribed against the company. The dossier gives no further detail on that case.

A redaction gap

The SIC resolution in the file is labelled "public version" on its first page and "reserved version" on the following pages, and the complainant's name is covered by black bars throughout most of it. In two passages, on pages 5 and 10 of the resolution, his surname or full name appears in plain text. This article does not reproduce it.

Why this matters for the marketing community

The case turns on a question every advertiser with a customer database eventually faces: what counts as proof that a person agreed to be contacted? Colombia's regulator gave a narrow answer in 2019. A sign-up timestamp and a terms-and-conditions acceptance were not enough; the company needed evidence that a specific, identified person ticked a specific box authorizing a specific use. That is a standard closer to consented data as European regulators describe it than to the click-through acceptance many apps still rely on.

Similar reasoning has surfaced repeatedly in European enforcement. Spain's data protection authority fined Yoti 950,000 euros in part for using pre-ticked boxes to collect research consent. France's CNIL fined EXTIA 300,000 euros after 204 of 265 deletion requests went unprocessed or late, a pattern that echoes the four months and 25 days Rappi took to stop texting a user who asked it to. An industry guide covered by PPC Land in April set out the prior-consent requirement for B2C email and SMS prospecting in France, the same channels at issue in the Rappi sanction. And a German local court ruled in 2025 that data subjects cannot demand proof that deletion took place, a contrast with the Colombian orders, which require Rappi to keep proof of authorization and to certify compliance through a third party.

The difference in the Rappi case is the private damages layer. A regulatory fine of COP 298 million was the end of the administrative matter. The group action converts the same finding into a potential per-person claim, with the number of persons set by the company's own user list. If a Colombian court were to accept even the two minimum wages per member the complaint proposes, the multiplier would be the size of Rappi's pre-2019 Colombian user base, a number that is sealed.

Delivery platforms have become advertising businesses in their own right. DoorDash, for example, described itself in June as a commerce media platform serving more than 400,000 advertisers. Any retail media network built on a delivery app depends on first-party data collected at sign-up, which is exactly the moment the SIC found Rappi could not document. Colombian courts have also shown willingness to apply constitutional rights to platforms: in May, the Constitutional Court ruled that X owed a journalist due process before suspending his account.

There is also an operational point. The court made the defendant responsible for telling potential claimants about the claim, using the same digital channels whose consent records are in question. The 2019 SIC orders, for their part, require deletion and revocation tools to be available "through the same means or channels" Rappi uses to contact people. Both decisions push the remedy into the company's own messaging infrastructure.

What the file does not say

The dossier leaves several questions open. It contains no answer from Rappi to the complaint, no record of whether Rappi appealed Resolution 9800, and no indication of whether the SIC accepted the third-party certificate and audit. It does not say whether Rappi completed the 2023 notification, how many people were contacted, or how many have joined. It contains no ruling on the merits and no hearing dates. The page itself is undated, so it is not possible to tell from the document when Rappi began hosting it or whether it is the channel through which notified users are being directed.

The 40212 resolution on e-commerce, the Tribunal's January 2021 decision and the May 2022 order requiring the user list are all referenced but not reproduced.

Timeline

  • April 23, 2015 - Rappi S.A.S. incorporated by private shareholders' document; registered with the Bogota Chamber of Commerce on April 29, 2015.
  • March 3, 2016 - Rappi Inc. control over Rappi S.A.S. takes effect, according to the Chamber of Commerce certificate.
  • November 3, 2016 - A Rappi user asks the company to stop using his data and stop sending him messages.
  • February 9, 2017 - The user files a complaint with the SIC.
  • March 10, 2017 - Text messages to the user stop, according to Rappi.
  • March 28, 2017 - The user is removed from Rappi's SMS database, four months and 25 days after his request.
  • October 23, 2017 - SIC Resolution 66983 refers the matter for investigation.
  • March 26, 2018 - SIC Resolution 21206 opens the formal investigation and sets out charges.
  • April 27, 2018 - Rappi deletes the user's email address.
  • July 12, 2018 - Corrected charges served; Rappi does not respond within 15 days.
  • September 28, 2018 - Rappi submits evidence to the SIC.
  • October 3, 2018 - A separate lawsuit against Rappi S.A.S. is inscribed by order of the 11th Civil Circuit Court of Bogota.
  • March 26, 2019 - Rappi files closing arguments.
  • April 25, 2019 - SIC Resolution 9800 fines Rappi COP 298,121,760 (360 minimum wages) and orders measures covering all users.
  • August 28, 2019 - SIC Resolution 40212 on Rappi as an e-commerce provider.
  • June 2020 - Date on Camilo Araque Blanco's group action complaint.
  • July 24, 2020 - Araque petitions Rappi for his activation date and consent documents; the complaint is emailed to Rappi that evening.
  • July 31, 2020 - The 41st Civil Circuit Court of Bogota finds the complaint inadmissible on four points.
  • August 2020 - Correction filed, estimating Araque's individual damage at COP 1,000,000.
  • January 28, 2021 - Bogota Superior District Tribunal decision referenced in the 2023 order.
  • January 14, 2022 - Group action admitted; Rappi given 10 days to answer.
  • May 26, 2022 - Court orders Rappi to provide a list of potentially affected people.
  • April 27, 2023 - Court finds the group exceeds 20 people and orders Rappi to notify everyone on the list within 15 days; the list is sealed.
  • April 14, 2025 - German court rules data subjects cannot demand deletion proof.
  • March 10, 2026 - Spain fines Yoti 950,000 euros over biometric data and pre-ticked consent boxes.
  • April 25, 2026 - PPC Land covers the French prospecting guide on email and SMS consent.
  • May 28, 2026 - Colombia's Constitutional Court rules X owes a journalist due process.
  • June 4, 2026 - DoorDash Ads repositions as a global commerce media platform with 400,000 advertisers.
  • September 12, 2026 - CNIL fines EXTIA 300,000 euros over 204 mishandled erasure requests.
  • September/October 2026 - The 71-page dossier is printed from Rappi's Colombian legal website, stamped "9/10/26, 7:10 PM".

Summary

Who: Camilo Araque Blanco, represented by lawyer Juan David Mesa Ramirez, on behalf of an open group of Rappi users, against Rappi S.A.S., the Colombian subsidiary of Rappi Inc. The 41st Civil Circuit Court of Bogota, under Judge Janeth Jazmina Britto Rivero, is hearing the case. The underlying finding comes from Colombia's Superintendencia de Industria y Comercio.

What: A group action seeking compensation for users whose data Rappi processed without provable authorization, including one monthly minimum wage per member for moral damage and one for harm to constitutionally protected interests, plus material damages based on the value of a personal data record. It rests on SIC Resolution 9800, which fined Rappi COP 298,121,760 and found that terms-and-conditions acceptance and a sign-up timestamp did not prove consent. Rappi is hosting the full 71-page file on its Colombian legal website.

When: The SIC sanction is dated April 25, 2019. The complaint is dated June 2020, the action was admitted on January 14, 2022, and the court ordered Rappi to notify listed users on April 27, 2023. The web page is undated; the copy reviewed was printed with the stamp "9/10/26".

Where: Bogota, Colombia, case 11001-31-03-041-2020-00212-00. The group covers Rappi users across Colombia who registered before April 25, 2019, or later if Rappi had not yet implemented the SIC's orders.

Why: The case tests whether a regulator's finding about missing consent records can become a per-user damages claim. The size of any eventual liability depends on Rappi's pre-2019 Colombian user count, which the court has sealed, and the reasoning applies to any company that relies on sign-up flows to justify text and email marketing.