Chile, Mexico and Brazil tighten PLD rules
Chile, Mexico, Brazil and others are speeding up new data, fraud, cybersecurity and virtual asset rules through 2028.
Between August and September 2026, regulators across Latin America moved data protection, cybersecurity, fraud prevention and virtual asset rules toward stricter regimes for banks, fintechs and other regulated entities. The common pattern is more monitoring, more traceability, more data governance and more demonstrable accountability to supervisors.
Executive summary
Chile, Mexico, Brazil, Peru, Colombia, Paraguay, Argentina, Uruguay and Bolivia entered the second half of 2026 with overlapping reforms that all point in the same direction: more traceability, more reporting obligations, more automated controls and more direct supervisory or sanctioning power over banks, fintechs and other regulated entities. The shift is staged, but not fragmented. In most countries, the relevant calendar now runs from November 2026 through January 2028, with interim milestones already forcing changes to processes, systems and internal governance.
The clearest picture is in Mexico, where Agreement 115/2026 rewrote the General Rules under the LFPIORPI and moved compliance for vulnerable activities away from a file-and-notice model toward documented risk management, automated monitoring, customer classification and annual audits. The research material shows that this is not just a semantic change. The risk-based assessment requirement begins in March 2027 for several operational components, while the general effective date starts on November 30, 2026 and extends through January 2028. At the same time, Brazil closed its authorization framework for virtual asset service providers and later added specific anti-fraud controls that take effect in January 2027.
In data protection and identity fraud, Colombia and Chile delivered two particularly relevant regulatory signals for banking and telecom. Colombia put Statutory Law 2573 into force, strengthening identity validation, protecting victims of impersonation and requiring sufficient and reasonable digital security measures. Chile still formally keeps Law 21,719 set for December 2026, although the executive branch has already asked to delay it by one year and reinforce the institutional framework for the future Personal Data Protection Agency. Peru followed a similar tightening path, with the SBS linking cybersecurity, transparency, operational continuity and BaaS.
Paraguay deserves separate treatment because it brings three fronts together at once: a new comprehensive personal data law with a specialized agency, an annual reporting duty for cryptoassets and an automated information exchange system between the DNIT and banks. That makes it one of the few countries in the report where privacy, taxation and access to banking information are moving in sync. The practical effect for entities is straightforward: customer data, tax filings, bank transactions and virtual asset activity are starting to converge through formal channels of exchange and verification.
Threat conditions also explain why these frameworks are hardening. Casbaneiro kept targeting banks across the region using distributed infrastructure, while actors such as CL-CRI-1163, BREEZE COMET and campaigns assisted by language models added pressure on fraud and security teams. The practical result for banks and fintechs is a 2026 to 2027 calendar in which compliance, cybersecurity, personal data and fraud analytics stop operating as silos and move onto the same operational plane.
Context and background
The available material shows that 2026 became a hinge year for compliance frameworks in the region. On one side are laws on personal data protection, identity fraud and incident reporting that are entering into force or nearing it. On the other are transition periods that push full implementation into 2027 or 2028. That combination matters because the market is no longer dealing with a single effective date, but with staged schedules, mandatory appointments, methodology documentation and testing requirements.
Chile, for example, has Law No. 21,719, published in December 2024 and scheduled to take effect on December 1, 2026, although the Ministry of Economy said on September 1, 2026 that the government proposed moving that date to December 1, 2027 to buy time for the Personal Data Protection Agency to be set up and for application standards to be defined. According to Anguita & Osorio, the bill would also adjust the agency's institutional design, expand the board from three to five members and allow a written warning as the first sanction during the first 12 months of application.
Paraguay arrives with a different but related picture. Law No. 7593/2025 creates the National Personal Data Protection Agency within MITIC, sets a 24-month vacatio legis and adds concrete rules on incident notification, international transfers and sanctioning powers. At the same time, the DNIT published General Resolution No. 47/2026 on cryptoassets, which requires residents and platforms to report annual transactions above US$5,000 through Marangatu, under obligation 959-DJI with an annual filing deadline. The country is also moving toward a data-sharing platform between DNIT and banks, based on web services, which speeds access to financial movements during audits.
Peru, meanwhile, shows a more fragmented but still coherent sequence. Supreme Decree No. 016-2024-JUS modernized the regulations for Personal Data Protection Law 29733 and set staggered deadlines for appointing the Personal Data Officer. At the same time, the SBS has been updating its incident and continuity framework, with one cybersecurity resolution and another on operational incidents under public consultation. Resolution SBS No. 01747-2026, meanwhile, sets the operating model for Banking as a Service, with board policies, prior risk assessment, continuous monitoring and minimum contractual terms.
Mexico, Brazil and Argentina add another layer that should be read as convergence between fraud prevention, operational risk and beneficial ownership control. In Mexico, the LFPIORPI reform centers on risk, monitoring, auditing and customer classification. In Argentina, the BCRA added a specific section for fraud risk management within operational risk guidelines. And in Brazil, the central bank not only regulated PSAV authorization and operation, but also moved virtual asset transactions into the foreign exchange perimeter and strengthened anti-fraud controls with temporary preventive holds.
Key facts table
| Date | Event | Source | Confidence |
|---|---|---|---|
| 2026-09-01 | Chile reported that the executive branch proposed delaying Law 21,719 until December 1, 2027 | Chile Ministry of Economy | Confirmed |
| 2026-09-05 | DMCI&A noted that Law 21,719 replaces Law 19,628 and will give sanctioning powers to the new agency | DMCI&A | Confirmed |
| 2026-08-31 | Paraguay, via Lawwwing, described the National Personal Data Protection Agency as a decentralized unit within MITIC | Lawwwing | Confirmed |
| 2026-09-07 | Edydsi indicated 72-hour incident notification and fines of up to 10,000 minimum wage units in Paraguay | Edydsi | Confirmed |
| 2026-08-22 | Paraguay's DNIT required annual reporting of cryptoassets above US$5,000 through Marangatu | Pytagua | Confirmed |
| 2026-09-05 | El Nacional reported progress on data sharing between DNIT and ASOBAN | El Nacional | Confirmed |
| 2026-09-10 | Mexico published Agreement 115/2026 reforming the LFPIORPI General Rules | PLD.mx | Confirmed |
| 2026-09-08 | COEM said the risk-based approach will apply starting March 1, 2027 | Coem.mx | Confirmed |
| 2026-09-18 | COEM detailed the mandatory annual internal audit for vulnerable activities | Coem.mx | Confirmed |
| 2026-09-04 | Colombia: Law 2573 was published and takes effect six months later, except for exceptions in Article 5 | Superintendence of Finance of Colombia | Confirmed |
| 2026-09-10 | Baker McKenzie explained that Law 2573 requires identity verification and document authenticity measures | Baker McKenzie | Confirmed |
| 2026-08-27 | Argentina: the BCRA issued Communication A 8471 on fraud risk management | Official Gazette of the Argentine Republic | Confirmed |
| 2026-09-01 | Argentina published Communication A 8471 in the Official Gazette | Argentina.gob.ar | Confirmed |
| 2026-09-12 | Brazil: Blue Consult summarized Central Bank Resolutions 519, 520 and 521 for PSAV | Blue Consult | Confirmed |
| 2026-09-10 | Brazil: Resolution BCB 584 added anti-fraud controls and temporary preventive retention | Campos Thomaz Advogados | Confirmed |
| 2026-09-07 | Peru: Supreme Decree 016-2024-JUS and its Personal Data Officer directive were already in force | Apaxi | Confirmed |
| 2026-08-25 | Peru: Resolution SBS 01747-2026 established the operating framework for BaaS | Ozone API | Confirmed |
| 2026-09-01 | Uruguay activated the mandatory PSAV register and a digital authorization channel | iProUP | Confirmed |
| 2026-09-10 | Bolivia formalized a commitment before the IMF for a robust virtual asset framework | CryptoNews.net | Confirmed |
Operational timeline
| Date | Event | Actor/vector | Verified source |
|---|---|---|---|
| 2026-08-22 | Paraguay's DNIT publishes the annual reporting obligation for cryptoassets above US$5,000 | Tax authority | Pytagua |
| 2026-08-25 | Peru defines the BaaS operating framework with Resolution SBS 01747-2026 | SBS / open banking | Ozone API |
| 2026-08-27 | The BCRA issues Communication A 8471 on fraud risk | Central bank / operational fraud | Official Gazette of the Argentine Republic |
| 2026-08-27 | Mexico already has the substantive LFPIORPI reform circulated under Agreement 115/2026 | AML regulation | PLD.mx |
| 2026-08-31 | Paraguay consolidates the reading of its data law and agency within MITIC | Privacy and supervision | Lawwwing |
| 2026-09-01 | Chile presents a bill to delay Law 21,719 | Executive / personal data | Chile Ministry of Economy |
| 2026-09-01 | Argentina publishes Communication A 8471 in the Official Gazette | Central bank / fraud | Argentina.gob.ar |
| 2026-09-01 | Uruguay activates the digital channel for PSAV authorization and registration | Central bank / virtual assets | CriptoNoticias |
| 2026-09-04 | Colombia confirms the phased entry into force of Law 2573 | Identity protection | Superintendence of Finance of Colombia |
| 2026-09-05 | Paraguay advances a DNIT-ASOBAN web service mechanism | Tax supervision | El Nacional |
| 2026-09-07 | Paraguay sets 72-hour security incident notification | Personal data | Edydsi |
| 2026-09-10 | Mexico enters a phase of documented risk-based obligations | AML / compliance | Jones Day |
| 2026-09-10 | Colombia opens a public consultation on identity verification systems | SIC / identity validation | Baker McKenzie |
| 2026-09-12 | Brazil consolidates the BCB 519, 520 and 521 framework for PSAV and the FX market | Virtual assets | Blue Consult |
| 2026-09-18 | Brazil strengthens anti-fraud controls with Resolution BCB 584 | PSAV / fraud | Campos Thomaz Advogados |
| 2026-09-19 | Uruguay increases fraud protection in payment methods with stronger authentication | Payment methods / authentication | El País (Uruguay) |
| 2027-01-01 | New anti-fraud rules for virtual assets take effect in Brazil | PSAV / temporary retention | MercGroup |
| 2027-03-01 | Mexico activates several operational components of the new regime | RBA / classification / monitoring | Coem.mx |
| 2027-09-01 | Argentina reaches full force of the new fraud risk management framework | Operational risk / fraud | Bruchou & Funes |
| 2027-11-27 | Paraguay reaches the general effective date of its Law 7593/2025 | Personal data | El Nacional de Paraguay |
| 2027-12-01 | Chile, if the delay does not pass, brings Law 21,719 into force | Personal data / agency | BCN Chile |
Attack chain and TTPs
Casbaneiro remains the clearest example of how a regional banking campaign adapts to defenses and to regulatory environments that demand finer monitoring. According to the research reports, the payload stays dormant until it detects that the user has accessed banking sites, at which point it intercepts credentials and manipulates financial sessions. That makes it especially relevant for banks and fintechs that rely only on hash blocking or domain blocking, because the operational trigger happens during real browsing.
The infrastructure architecture also changed. SocPrime described distributed data reception servers for C2, with multiple exfiltration endpoints. RST Cloud, for its part, documented MITRE ATT&CK techniques that include obfuscation, system discovery, execution through the web and process manipulation, which fits an operation designed to persist, hide and exfiltrate data in layers. The practical result is that detection cannot depend on a single signature or a single blocklist.
The campaign observed in August 2026 affected banking users in Mexico, Peru, Argentina and Colombia, with invoice or legal notice lures and malicious PDFs. That was joined by job-themed phishing campaigns in Brazil, and by BREEZE COMET, a financially motivated actor also active in that country. The research also mentions LLM-assisted intrusions, DuckDNS domains and multiple binaries, suggesting an operational surface where automation, exfiltration and post-exploitation are no longer unusual exceptions.
| TTP | Description | Source |
|---|---|---|
| T1027 | Obfuscated files or information to hinder analysis | RST Cloud |
| T1027.009 | Packed or obfuscated content | RST Cloud |
| T1027.013 | Additional obfuscation technique observed in the campaign | RST Cloud |
| T1033 | System information discovery | RST Cloud |
| T1036 | Masquerading of names or artifacts | RST Cloud |
| T1047 | WMI execution | RST Cloud |
| T1055 | Process injection or manipulation | RST Cloud |
| T1059.007 | Script-based execution | RST Cloud |
| T1071.001 | Web channels for command and control | RST Cloud |
| T1082 | System information discovery | RST Cloud |
Observed flow in the Casbaneiro campaign
The technical sequence described in the reports suggests a fairly classic but still effective path: delivery through phishing, activation when the victim visits a financial site, dormant loading, credential theft, session manipulation and exfiltration toward distributed servers. The relevant point is not the novelty of each step, but how they fit together. When the outbound infrastructure shifts to a distributed model, reputation controls and static blocking lose effectiveness quickly.
That pattern also helps explain why several of the new regulatory frameworks in the report are pushing toward automated monitoring, deviation alerts and historical evidence retention. Regulatory defense and technical defense are starting to look alike. The supervisor demands traceability, and the attacker forces organizations to produce it for every incident, transaction or suspicious access.
Regional impact
The regional picture shows a converging movement: regulators are no longer limiting themselves to asking for reports or consent, but are demanding operational capability to classify risk, preserve evidence, notify incidents, audit processes and justify automated decisions. That affects banks, fintechs, PSAVs, telecom operators, credit entities and, in several countries, any organization that handles personal data or sensitive financial information flows. The pressure is not uniform, but it is synchronized: the hardest deadlines fall between November 2026 and January 2028.
Regional overview
Chile, Paraguay, Mexico and Brazil concentrate the most structural changes in personal data, virtual assets and AML. Peru and Colombia are advancing in cybersecurity, operational incidents and identity verification. Argentina is introducing a formal fraud management framework in the financial system. Uruguay is ordering PSAV authorization and adding a new anti-fraud layer in payment methods. Bolivia, for now, sits in an intermediate position, with a reform commitment that still has no closed calendar.
Chile
Chile has Law No. 21,719, which according to the National Congress Library takes effect on December 1, 2026 and replaces the old Law No. 19,628. The Ministry of Economy, however, said the government proposed pushing that date to December 1, 2027 to give time for the Personal Data Protection Agency to be installed and for application standards to be defined. The change is not minor, because the bill also expands the agency's board from three to five members and adjusts the first appointments of its authorities.
For the private sector, the result is twofold. If the original date holds, the agency will receive sanctioning powers over controllers, including private companies. If the delay moves forward, organizations gain time, but not a full pause, because the institutional design will be more detailed and adaptation will need to start early. The Anguita & Osorio report makes clear that the debate is not whether compliance will happen, but when and under what architecture.
Paraguay
Paraguay has one of the densest frameworks in the report. Law No. 7593/2025 creates the National Personal Data Protection Agency within MITIC, sets a 24-month transition, orders incident notification within 72 hours and regulates international transfers under adequacy or contractual safeguard criteria. The law applies to any public or private organization that handles personal data and provides for fines of up to 10,000 minimum wage units.
At the same time, the DNIT issued General Resolution No. 47/2026 to declare annual cryptoasset transactions above US$5,000. The process requires a tax ID, obligation 959-DJI, filing in Marangatu and an informational sworn statement before Internal Revenue. In addition, banking and tax information is moving faster between DNIT and ASOBAN through a web service, which strengthens oversight and financial traceability. For banks, fintechs and exchanges, the pressure is happening on three layers: privacy, taxation and access to financial information.
Peru
Peru is showing a mix of data protection, cybersecurity and new financial distribution models. Supreme Decree 016-2024-JUS modernized the regulations for Law 29733 and established a size-based timeline for appointing the Personal Data Officer. According to the material reviewed, mid-sized firms with annual sales between 1,700 and 2,300 UIT must appoint the officer by November 30, 2026. The regulation also requires notification of incidents to the National Personal Data Protection Authority within 48 hours and adoption of standards such as ISO/IEC 27001.
The SBS is also pushing the operational front. Resolution SBS No. 01741-2026, according to Apaxi, requires reporting cybersecurity incidents and channel outages within 24 hours and notifying affected users within 10 business days. Resolution SBS No. 01747-2026 sets the BaaS framework with board policies, risk assessment, continuous monitoring, minimum contracts and biannual publication of active recipients. And the draft single operational incident reporting procedure, still under consultation, could unify outages and cybersecurity events under one channel.
Colombia
Colombia is tackling identity impersonation. Law 2573 protects victims from negative reports and debt collection, imposes sufficient and reasonable digital security measures to verify identity and document authenticity, and requires the person to be marked as a victim of personal falsity when there is a complaint. According to the Superintendence of Finance, the law was published on May 19, 2026 and takes effect six months later, except for parts of Article 5 that apply from promulgation.
The effect for banks, telecoms and merchants is operational. They must retain evidence of the onboarding process, including biometrics, IP and document validation, and respond to claims under a framework in which the burden of proof shifts. The public consultation opened by the SIC in September 2026 is aimed precisely at strengthening identity validation and personal data processing, so the Colombian ecosystem is moving toward more technical and auditable controls. The proposed reform of Law 1581 adds another layer, although it remains only a proposal.
Argentina
Argentina focused on internal and external fraud. BCRA Communication A 8471 created Section 6.5, Fraud Risk Management, within the risk management guidelines. The rule requires a specific organizational structure, assignment of responsibilities, self-assessment of risk, a mitigation plan and coordination with technology and information security risk management. In addition, the phased schedule pushes full effectiveness to September 2027.
The practical burden is not abstract. Entities must define risk appetite, document processes, report indicators to the board and adjust controls to new fraud patterns. LM Neuquén added that, starting in September 2026, immediate transfer administrators will receive public information from the BCRA to build person-level fraud risk profiles. That places the Argentine system into a more granular prevention model, with transfers and personal fraud as the main focus.
Brazil
Brazil already had a robust framework for PSAVs and kept refining it. Central Bank Resolutions 519, 520 and 521 build the authorization, operation and regulated perimeter architecture for virtual assets. PSAVs must show financial capacity, lawful source of capital, business viability, compatible technology infrastructure, proper governance and the technical reputation of administrators and controllers. In addition, certain virtual asset transactions were brought under the foreign exchange market and require counterparty identification.
The next layer came with Resolution BCB 584, which expands anti-fraud rules and enables a preventive hold of up to 24 hours for certain transfers above US$10,000 per client per day when they are sent abroad or to self-custody wallets. The jump is significant because supervision is no longer limited to authorizing entities, but can intervene in the transaction flow when the risk warrants it. In practical terms, Brazil is pushing PSAVs and banks toward preventive control, not only reactive control.
Mexico
Mexico is the largest case in the report. Agreement 115/2026 rewrote the General Rules under the LFPIORPI, added 11 new chapters and put the risk-based approach at the center of compliance. The change covers vulnerable activities and PSAVs, with a requirement for documented methodology, customer classification into three levels, enhanced due diligence, beneficial owner identification with a 25% threshold, annual training and periodic audits.
Implementation is phased. General effectiveness begins on November 30, 2026, but several operational components activate on March 1, 2027 and the annual audit period begins on January 1, 2028. Automated monitoring mechanisms must keep files, group transactions, feed the risk assessment, generate alerts and store histories for at least 10 years. For sectors such as casinos, gaming, sweepstakes and other vulnerable activities, this means reworking platforms, alert rules and internal manuals from end to end.
Bolivia
Bolivia does not yet have a closed regime, but it does have a clear direction. The Economic and Financial Policy Memorandum dated September 10, 2026 commits the country, under the IMF program, to develop a robust virtual asset framework. The goal is to prevent illicit capital outflows and protect financial resilience. The available material makes clear that there is still no defined timeline, no single main authority and no detailed legislative approach.
The cautious reading is that Bolivia is entering a design phase. Some reports speak of tripartite oversight between the Central Bank, ASFI and the UIF, while others mention possible stricter AML rules for VASPs, but those pieces are not confirmed at the same level as the memorandum. For this report, the verifiable point is the intention to create a robust framework and the absence of a closed calendar.
Uruguay
Uruguay consolidated its PSAV regime and added another layer on payment fraud. The Central Bank said it had prepared a regulatory project for PSAVs and, according to iProUP, activated a mandatory register formally effective as of September 1, 2026. The country already has a digital channel for authorization and registration, and the rules require fund segregation, transparency, cybersecurity and internal controls.
At the same time, the BCU introduced a proposal to reinforce fraud protection in payment methods. The initiative calls for stronger authentication when electronic instruments are linked to digital wallets and allows a tokenized instrument to function as a possession factor if it has a unique and secure link to the customer's device. It is a clear sign of convergence between payments, identity and fraud management.
Technical indicators
| Type | Value | Source |
|---|---|---|
| Domain | m-doxa-apodo.duckdns.org | GBHackers / SocDefenders AI |
| Domain | m-doxa-geo.duckdns.org | GBHackers |
| Domain | m-doxa-intel.duckdns.org | GBHackers |
| IP | 178.128.87.160 | GBHackers |
| IP | 165.22.184.26 | GBHackers |
| IP | 167.148.195.53:8888 | SocDefenders AI |
| Cert hash SHA-256 | 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c | GBHackers / SocDefenders AI |
| Cert hash SHA-256 | 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 | GBHackers / SocDefenders AI |
| Cert hash SHA-256 | 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 | GBHackers / SocDefenders AI |
| Binary | socktz_v9.exe | SocDefenders AI |
| PDF SHA-256 | 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 | GBHackers |
| PDF SHA-256 | 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd | GBHackers |
| Malicious email SHA-256 | debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 | GBHackers |
| Malicious email SHA-256 | eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 | GBHackers |
Analysis for security teams
The first operational takeaway from the report is that the risk surface can no longer be managed by business function alone. Fraud, data, cybersecurity, compliance and operational risk teams now have to work from the same process map. The reason is simple: in the region, several regulators are asking for the same thing under different names, whether that is risk-based assessment, evidence retention, stronger authentication, automated monitoring or incident reporting.
On detection, the priority pattern is to combine identity, behavior and transaction monitoring. Mexico requires keeping risk histories for at least 10 years and generating alerts for high-risk customers, PEPs and restrictive lists. Colombia pushes identity control into onboarding and requires evidence retention. Uruguay and Brazil are pushing stronger authentication and anti-fraud controls in payments and virtual assets. That suggests effective detection now extends beyond SIEM or SOC operations and must include business rules, customer profiling and correlation with regulatory events.
On mitigation, priorities change by country, but not the logic. Where deadlines are short, as in Peru and Argentina, the urgency is governance, appointments and internal manuals. Where the change is structural, as in Mexico and Brazil, the urgency is redesigning monitoring engines, classifying risk by level, formalizing methodology and making sure evidence is exportable and auditable. Where the law is still in transition, as in Chile or Bolivia, it makes sense to prepare architecture and contracts before the political window closes.
In threat intelligence terms, the material on Casbaneiro, CL-CRI-1163, BREEZE COMET and LLM-assisted campaigns points to a particular focus on email, banking navigation, endpoint devices and distributed C2. The fact that Casbaneiro's payload activates when a user accesses banking sites means browser protection, behavioral analysis and session-manipulation detection need to be strengthened. In Brazil, campaigns aimed at HR show that the entry point can be a corporate email, not a digital banking portal.
Based on the research, the recommended prioritization would be the following. First, close compliance gaps with hard deadlines, especially in Mexico, Peru, Argentina and Paraguay. Second, consolidate evidence and logs, because several rules already require proving that validation or assessment actually took place. Third, review third parties, PSPs and cloud or BaaS providers, since third-party risk responsibility appears in Peru, New York and Mexico. Fourth, integrate fraud and cybersecurity into a single dashboard, because attacks that hit banks now exploit identity, email, web and automation at the same time.
Frequently asked questions
Which countries in the report have the most urgent changes between 2026 and 2027?
Mexico, Brazil, Peru, Colombia, Paraguay and Argentina concentrate the nearest milestones because they combine phased effective dates, adaptation deadlines and new monitoring or reporting requirements. Chile is also relevant because of its data law, although its timeline depends on the possible legislative delay. Uruguay and Bolivia are in different stages, more focused on registration or regulatory design.
Which frameworks require automated monitoring rather than only manual controls?
Mexico explicitly requires it under the amended LFPIORPI, with six minimum functions and historical retention. Brazil links it to anti-fraud controls for virtual assets, and Peru incorporates it through different incident reporting and supervision schemes in cybersecurity and digital banking. At the same time, the technical pressure from Casbaneiro reinforces the need for automated detection.
Which countries already require or anticipate short incident-reporting deadlines?
Paraguay sets a 72-hour deadline for security incidents, Peru calls for 24-hour reporting of cybersecurity incidents and 10 business days to notify affected users, and Colombia is moving identity validation into a regime that protects victims of impersonation. In the United States, the research also mentions 36-hour and four-business-day clocks for banks and issuers.
Where is the convergence between fraud, personal data and operational risk clearest?
Argentina, Mexico and Colombia show that convergence most clearly. Argentina created a specific fraud risk section within operational risk. Mexico turned AML, customer classification, beneficial ownership and auditing into a formal program. Colombia tied its identity impersonation law to identity verification, documentary proof and personal data protection.
Which jurisdictions in the report already affect crypto and virtual assets directly?
Brazil, Uruguay, Paraguay and, at an earlier stage, Bolivia. Brazil already has authorization, a foreign exchange perimeter and anti-fraud controls. Uruguay activated registration and authorization for PSAVs. Paraguay added an annual reporting duty for cryptoassets and banking cross-checks with the DNIT. Bolivia has only committed to a robust framework before the IMF so far, without a closed calendar.
Material limitations
The material provided allows for a fairly precise reconstruction of regulatory calendars, main obligations and part of the regional operating context, but it does not include the full text of some rules or their technical annexes. In Chile, for example, the postponement bill has already been reported, but the final status of the legislative process cannot be confirmed from this research alone. In Bolivia, the available information is programmatic and does not allow a final authority or timeline to be fixed.
It was also not possible to directly verify some details published by secondary sources when they themselves mark them as uncertain, such as the exact 270-day period for the transitional PSAV authorization process in Brazil or the operational start of the DNIT-ASOBAN platform in Paraguay. In those cases, the report keeps the attribution to the source and does not elevate the claim to the same level as the confirmed facts.
Sources
- How Does Brazil's New Digital Asset Regulation Work?transfero.com· Transfero
- Ley Chile - Decreto 662 (09-sep-2026) M. de Haciendabcn.cl· Biblioteca del Congreso Nacional de Chile
- Gobierno propone ampliar plazo para implementar nueva ley de protección de datos y institucionalidadeconomia.gob.cl· Ministerio de Economía de Chile
- Law 21.719: What Companies in Chile Must Do Before December 1dmcia.cl· DMCI&A
- What Is Paraguay's Data Protection Law?offlist.me· OfflistMe
- Cloud vs. on-premise: dónde deben vivir sus datosedydsi.com· Edydsi
- Paraguay's New Data Protection Regulation: Law No. 7593/2025lawwwing.com· Lawwwing
- DNIT do Paraguai exige declaração de criptoativos acima de US$ 5.000pytagua.com· Pytagua
- Criptomonedas: El Fisco Da el Primer Paso Hacia la Regulación Formalpyinforma.com· Pyinforma
- Criptoactivos: nueva obligación de información ante la DNITconsultoria.com.py· Consultoria.com.py
- DNIT y bancos cruzarán datos financieros durante las fiscalizacioneselnacional.com.py· El Nacional
- RESOLUCIÓN SBS N° 01741-2026normaslegalesonline.pe· Normas Legales Online
- A Look at Peru: Two Open Finance Paths at Onceozoneapi.com· Ozone API
- Plazos y multas de protección de datos en Perúmifirmadigital.pe· Mifirmadigital
- Medianas: el Oficial de Datos Personales vence el 30 de noviembre de 2026wavys-technologies.com· Wavys Technologies
- Oficial de Datos Personales: La Figura que el Reglamentoaypdigital.com· Aypdigital
- Normas de ciberseguridad para empresas en el Perú (2026)apaxi.info· Apaxi
- Reglas de Carácter General LFPIORPI: Guía 2026pld.mx· Pld.mx
- Acuerdo 115/2026: Nuevas Reglas LFPIORPI Antilavadopiranirisk.com· Pirani Risk
- Mexico Overhauls AML Rules: Key Changes Under Acuerdo 115/2026jonesday.com· Jones Day
- Resumen Semanal PLD: 5 al 11 de Septiembre de 2026pld.mx· Pld.mx
- Conocer al cliente ya no basta, ahora habrá que medir su riesgocoem.mx· Coem.mx
- Auditoría anual de Actividades Vulnerablescoem.mx· Coem.mx
- Compilación Jurídica - Ley 2573 de 2026normograma.mintic.gov.co· Ministerio TIC de Colombia
- Colombia: SIC Opens Consultation on Identity Verification Systemsbakermckenzie.com· Baker McKenzie
- Boletín Jurídico No. 123superfinanciera.gov.co· Superintendencia Financiera de Colombia
- Ley 2573 de 2026: una protección necesaria, pero aún sin reglas clarasasuntoslegales.com.co· Asuntos Legales
- Law 2573 Compliance: A 2026 Guide for Banksfeedzai.com· Feedzai
- La ciberseguridad ya no es un asunto de TIrevistaclevel.com· Revista C-Level
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINA - Comunicación A 8471boletinoficial.gob.ar· Boletín Oficial de la República Argentina
- Nueva regulación del BCRA sobre gestión del riesgo de fraude (Com. A 8471)bruchoufunes.com· Bruchou & Funes
- El Gobierno ingresa proyecto que posterga un año la Ley 21.719clya.cl· CLYA
- CISO Daily Briefing – September 3, 2026labs.cloudsecurityalliance.org· Cloud Security Alliance
- Empresas se preparan para una nueva era de privacidadelnacional.com.py· El Nacional
- Stablecoins for Companies in Paraguay: Legal Frameworksoulbit.io· Soulbit
- Criptomonedas en Boliviacarlosmaiz.com· Carlos Maiz
- La Directiva de Seguridad para el tratamiento de datos personalesapaxi.info· Apaxi
- Reforma Ley 1581: biometría como dato sensiblefacephi.com· Facephi
- Newsletter (#009/2026) de Fintechs, Bancos, Serviços Financeiros e Ativos Virtuais do Campos Thomaz Advogadoscamposthomaz.com· Campos Thomaz Advogados
- Artículo 18 LFPIORPI: Obligaciones Clave para Actividades ...pld.mx· PLD.mx
- The 36-Hour Notification Clock Doesn't Wait for Your Investigation. Here's What the OCC's June 2026 Cybersecurity Report Means for Your Incident Response Program.risktemplate.com· RiskTemplates
- NY DFS Strengthens Cybersecurity Rules with New Risk ...ffnews.com· FF News
- Comunicación A 8471/2026: lineamientos de gestión del riesgodequesetrata.org· DeQueSeTrata.org
- La ley de IA chilena no tiene apuro. Tiene un problema de ...antoniovasquez.cl· Antonio Vásquez
- Alternative CISO Daily Briefing – 2026-09-03labs.cloudsecurityalliance.org· Cloud Security Alliance
- Mapa regulatorio de IA en Paraguaymuchotexto.net· MuchoTexto
- Is Crypto Legal in Paraguay? Regulations, Licensing & Taxweb3compliance.ai· Web3Compliance
- Cuentas bancarias en la mira de DNIT: experta advierte sobre prácticas que ya deben evitarseabc.com.py· ABC Color
- Bolivia Crypto Ban Lifted: From Prohibition to Adoptionshareholdersunited.org· Shareholders United
- Ciberseguridad Bancos Perú: SBS 504-2021 y Fraudearmourcyber.io· Armour Cybersecurity
- Ciberseguridad Manufactura Perú: OT y Ley 29733armourcyber.io· Armour Cybersecurity
- Videovigilancia y protección de datos personales en el Perú: Directiva 01-2020-JUS/DGTAIPDapaxi.info· Apaxi
- Colombia's Data Protection Reform: What Reclassifying Biometrics as Sensitive Data Means for Banksfacephi.com· Facephi
- Acuerdo 115/2026 LFPIORPI: Calendario y EBRaudita-pld.com· Audita-PLD
- Nuevos formatos de avisos de actividades vulnerables 2026siemprealdia.co· Siempre al Día
- Incident Response for Financial Servicescyble.com· Cyble
- Normativa – sección general de proyectos y regulaciones del BCUbcu.gub.uy· Banco Central del UruguayUnverified URL
- El BCRA endurecerá los controles sobre las transferenciaslmneuquen.com· LM Neuquén
- Government submits bill postponing by one year the entry into force of Law No. 21,719 on Personal Data Protection and strengthening the institutional framework of the Data Protection Agencycarey.cl· Carey
- Financially Motivated Threat Actor BREEZE COMET Targets Brazilcloud.google.com· Google Cloud
- La verdadera prueba de la Ley N.º 7593: Por qué la protección de datos será el nuevo eje de podertamaratischler.blogspot.com· Tamara Tischler (Blogspot)
- Crypto in Paraguay: Bitcoin, Taxes, Residency & Payments (2026)easyparaguay.com· EasyParaguay
- Bolivia se comprometió con el FMI a regular las criptomonedascryptonews.net· CryptoNews.net
- Edición 09-09-2026fliphtml5.com· Fliphtml5 / Editorial La EstrellaUnverified URL
- El Peruano te informa: consulta aquí las principales normas legales de hoy, miércoles 16 de setiembre del 2026elperuano.pe· El Peruano
- PSAV: o que é e qual o prazo para se adequar à regulação ...transfeera.com· Transfeera
- Calendario de obligaciones LFPIORPI 2026-2028, acuerdo 115/2026amcpdf.org.mx· AMCPDF
- Reforma Ley Antilavado México: Cambios, Obligaciones y Riesgoselfactork.com· El Factor K
- NYDFS Issues Extensive Guidance on Cybersecurity Risk Assessmentsmayerbrown.com· Mayer Brown
- Uruguay regula a las billeteras y criptomonedas en su territorio (versión AMP)iproup.com· iProUP
- Resoluções BCB 520 e 521: o que muda na operação com criptoblueconsult.com.br· Blue Consult
- Chile: El Ejecutivo presenta proyecto para postergar la entrada en vigor de la nueva Ley de Protección de Datos Personalesgarrigues.com· Garrigues
- América Latina es ahora la región más atacada del mundoredtigerit.com· RedTiger IT
- Paraguay's New Data Protection Regulation: Law No. 7593/2025lawwwing.com· Lawwwing
- Paraguay's DNIT Requires Declaration of Crypto Assets Above $5,000, Businesses Fear Informal Shiftpytagua.com· Pytagua
- Bolivia Crypto Rules Under IMF Program Explainedcapwolf.com· Capwolf
- Resolución SBS N° 02271-2026actualidadpenal.pe· Actualidad Penal
- Sentencia de Constitucionalidad nº C-413-25, Corte Constitucional de Colombiavlex.com.co· vLex
- Ley Antilavado LFPIORPI 2026: Acuerdo 115/2026, Nuevas ...carbajalcontadores.com· Carbajal Contadores
- Segob va contra lavado de dinero en casinos y centros de apuestasinfobae.com· Infobae
- CISA's CIRCIA Is Finalizing This Month. Here's What the New 72-Hour Reporting Clock Means for Your Financial Services Incident Response Program.risktemplate.com· RiskTemplates
- Uruguay regula a las billeteras y criptomonedas en su territorioiproup.com· iProUP
- Resolução BCB 519: precisa de autorização até 30/10?blueconsult.com.br· Blue Consult
- Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin Americagbhackers.com· GBHackers
- DNIT und Banken treiben den virtuellen und nachvollziehbaren Informationsaustausch voranecmueller.com.py· ECMueller
- Bolivia commits to establishing a cryptocurrency regulatory framework.techflowpost.com· TechFlow Post
- La lucha contra la corrupción de datos en el Perú: entre filtraciones masivas y un marco legal que avanzaruwamux.com· Ruwamux
- SBS busca que bancos informen en máximo dos horas sobre caídas de sistema y otros incidentesinfobae.com· Infobae Perú
- PSAV: o que é e como funciona a autorização no Banco Centralhodle.com.br· Hodle
- Ya salieron las Reglas de Carácter General: qué hacer ahora (plan ...)cumplimientopld.com.mx· CumplimientoPLD
- Implementación PLD en Juegos, Concursos y Sorteos en Méxicopld.mx· PLD.mx
- NYDFS Tells Financial Firms Cyber Risk Assessments Must Drive Real Actionnews.codegotech.com· CodegoTech News
- Licencia cripto en Uruguay - BCU (Ley 20.345)prifinance.com· Prifinance
- Autorização de VASP no Banco Central do Brasilsoulbit.io· Soulbit
- Resumen Semanal PLD: 29 de Agosto al 4 de Septiembre de 2026pld.mx· PLD.mx
- Attackers Expose Ongoing AI Tool Use Targeting ...socdefenders.ai· SocDefenders AI
- Empezar por lo básico en la nueva ley de datosultimahora.com· Última Hora
- Acuerdo entre DNIT y Bancos, así funcionará el nuevo cruce de datosultimahora.com· Última Hora
- Bolivia to tighten crypto oversight as part of IMF backed reformscrypto.news· Crypto.news
- Protección de datos en Perú: fechas del D.S. 016-2024-JUSmifirmadigital.pe· Mi Firma Digital
- Suplantación de identidad como afectación de derechosmobbeel.com· Mobbeel
- Resoluções BCB 552 e 553, normas que realmente 'ligaram' Psavs ao arcabouço do BCalvarorocha.com.br· Alvaro Rocha
- Actividades vulnerables: Cómo blindar tu empresa con el EBRidconline.mx· IDC Online
- Beneficial Ownership Across the Border: United States ...swlaw.com· Snell & Wilmer
- NYDFS Penetration Testing Requirements (2026)stingrai.io· Stingrai
- ¿Cobrás en cripto? Cuándo tenés que registrarte en el BCUconlyapp.com· ConlyApp
- Fintech Laws and Regulations 2026 – Brazilgloballegalinsights.com· Global Legal Insights
- Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websiteszerohour.day· ZeroHour
- Comunicación "A" 8471 - Gestión del riesgo de fraudebcra.gob.ar· Banco Central de la República Argentina
- Criptoactivos: Sepa las dudas que dejó la DNIT sobre el momento de pagar impuestosabc.com.py· ABC Color
- Control Bancario Automatizado por la DNITpasmorabogados.com· Pasmor Abogados
- Bolivia Pledges Crypto Regulatory Framework to IMF Amid Capital Flow Concernscryptodlhub.com· Cryptodlhub
- Consulta pública SIC Colombia 2026: refuerzo de validación de identidad y tratamiento de datospulzo.com· Pulzo
- BRICS Pay: o que existe hoje como produto e o que ainda depende do Brasilbitnoticias.com.br· Bitnoticias
- Manual antilavado: ¿Qué cambiar con las nuevas reglas?idconline.mx· IDC Online
- ¿interna o auditor externo certificado por la UIF?cumplimientopld.com.mx· CumplimientoPLD
- How does the NY DFS regulate AI in banking?bankingnewsai.com· BankingNewsAI
- Mayor protección ante fraudes: la nueva propuesta del BCU para realizar compras y definir reclamoselpais.com.uy· El País (Uruguay)
- Lineamientos para la gestión de riesgos en las entidades financierasargentina.gob.ar· Gobierno de Argentina
- Casbaneiro Banking Trojan Uses Distributed Data-Receiving Serverssocprime.com· SocPrime
- Nueva regulación del BCRA sobre gestión del riesgo de fraude (Com. A 8471)abogados.com.ar· Abogados.com.ar
- Qué es una Criptomoneda y Cómo se Usa en Paraguaygetmeru.com· Meru
- 玻利维亚向 IMF 承诺制定加密资产监管框架:主权融资如何倒逼虚拟资产反洗钱合规aiying.cc· aiYing.cc
- Gaceta 1217 de 2026: Proyecto de Ley Estatutaria 282 de 2026 Cámaraavancejuridico.info· Avance Jurídico
- PREVENÇÃO À LAVAGEM DE DINHEIRO E CARTEIRAS ...revistatopicos.com.br· Revista Tópicos
- ¿Qué exige la prevención de lavado de dinero en México?smpslegal.com· SMPS Legal
- Funciones y Rol de la UIF en la PLD en México 2026pld.mx· PLD.mx
- Banking Agencies Rewrite Third-Party Risk Guidance | Isora GRCsaltycloud.com· SaltyCloud (Isora GRC)
- Semana clave para la Ley de Datos: reglamento del modelo…anguitaosorio.cl· Anguita & Osorio
- Casbaneiro: A Banking Trojan with Distributed Data-Receiving Serversx.com· RST Cloud
- El BCRA endurecerá los controles sobre las transferencias en Argentinalmneuquen.com· LM Neuquén
- Stablecoins para empresas en Paraguay: marco legalsoulbit.io· Soulbit
- 玻利维亚向 IMF 承诺制定加密资产监管框架:主权融资如何倒逼虚拟资产反洗钱合规 - law.aiyinglaw.aiying.cc· law.aiying
- Colombia's third data bill would fine firms up to 5% of revenueppc.land· PPC Land
- Resolução BCB 584: controles antifraude em ativos virtuaismercgroup.com.br· MercGroup
- Mecanismos automatizados de monitoreo (Art. 41): las 6 ...cumplimientopld.com.mx· CumplimientoPLD
- Ranking 2026: Mejores Softwares de KYC/KYB para PLD en Méxicopld.mx· PLD.mx
- New York tells financial firms to update cyber risk assessments at least annuallyfingerlakes1.com· FingerLakes1
- Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websitescybersecuritynews.com· Cybersecurity News
- Financial Sector Security Advisorycert.ug· CERT.UG/CC
- Política de Privacidadyvylotes.com· YvyLotes
- DNIT y bancos cruzarán datos financieros durante las fiscalizacioneselnacional.com.py· El Nacional
- Agregación de Tags de Noticias Cripto y Contenido Temático | LBanklbank.com· LBank
- Bolivia y el FMI: nuevo marco para criptomonedascriptoperiodico.com· Criptoperiodico
- Ley 29733: qué exige a un sistema con datos personalesgrupohermoza.com· Grupo Hermoza
- Capítulo 9 — Moeda Digital, Pagamentos e Criptoativosdireito.legal· Direito.Legal
- Resumen Semanal PLD: 12 al 18 de Septiembre de 2026pld.mx· PLD.mx
- Reforma Ley Antilavado 2026 - Blog dSoftblog.dsoft.mx· dSoft
- New York DFS Tells Financial Firms to Treat Cyber Risk Assessments as Living Documentsgrcreport.com· GRCReport
- Uruguay está a horas de activar el registro para empresas de criptomonedascriptonoticias.com· CriptoNoticiasUnverified URL



