CiberLATAMbywhalemate

Chile, Mexico and Brazil tighten PLD rules

Chile, Mexico, Brazil and others are speeding up new data, fraud, cybersecurity and virtual asset rules through 2028.

Whalemate Labs · AI-assisted researchPublished:37 min read

Between August and September 2026, regulators across Latin America moved data protection, cybersecurity, fraud prevention and virtual asset rules toward stricter regimes for banks, fintechs and other regulated entities. The common pattern is more monitoring, more traceability, more data governance and more demonstrable accountability to supervisors.

Executive summary

Chile, Mexico, Brazil, Peru, Colombia, Paraguay, Argentina, Uruguay and Bolivia entered the second half of 2026 with overlapping reforms that all point in the same direction: more traceability, more reporting obligations, more automated controls and more direct supervisory or sanctioning power over banks, fintechs and other regulated entities. The shift is staged, but not fragmented. In most countries, the relevant calendar now runs from November 2026 through January 2028, with interim milestones already forcing changes to processes, systems and internal governance.

The clearest picture is in Mexico, where Agreement 115/2026 rewrote the General Rules under the LFPIORPI and moved compliance for vulnerable activities away from a file-and-notice model toward documented risk management, automated monitoring, customer classification and annual audits. The research material shows that this is not just a semantic change. The risk-based assessment requirement begins in March 2027 for several operational components, while the general effective date starts on November 30, 2026 and extends through January 2028. At the same time, Brazil closed its authorization framework for virtual asset service providers and later added specific anti-fraud controls that take effect in January 2027.

In data protection and identity fraud, Colombia and Chile delivered two particularly relevant regulatory signals for banking and telecom. Colombia put Statutory Law 2573 into force, strengthening identity validation, protecting victims of impersonation and requiring sufficient and reasonable digital security measures. Chile still formally keeps Law 21,719 set for December 2026, although the executive branch has already asked to delay it by one year and reinforce the institutional framework for the future Personal Data Protection Agency. Peru followed a similar tightening path, with the SBS linking cybersecurity, transparency, operational continuity and BaaS.

Paraguay deserves separate treatment because it brings three fronts together at once: a new comprehensive personal data law with a specialized agency, an annual reporting duty for cryptoassets and an automated information exchange system between the DNIT and banks. That makes it one of the few countries in the report where privacy, taxation and access to banking information are moving in sync. The practical effect for entities is straightforward: customer data, tax filings, bank transactions and virtual asset activity are starting to converge through formal channels of exchange and verification.

Threat conditions also explain why these frameworks are hardening. Casbaneiro kept targeting banks across the region using distributed infrastructure, while actors such as CL-CRI-1163, BREEZE COMET and campaigns assisted by language models added pressure on fraud and security teams. The practical result for banks and fintechs is a 2026 to 2027 calendar in which compliance, cybersecurity, personal data and fraud analytics stop operating as silos and move onto the same operational plane.

Context and background

The available material shows that 2026 became a hinge year for compliance frameworks in the region. On one side are laws on personal data protection, identity fraud and incident reporting that are entering into force or nearing it. On the other are transition periods that push full implementation into 2027 or 2028. That combination matters because the market is no longer dealing with a single effective date, but with staged schedules, mandatory appointments, methodology documentation and testing requirements.

Chile, for example, has Law No. 21,719, published in December 2024 and scheduled to take effect on December 1, 2026, although the Ministry of Economy said on September 1, 2026 that the government proposed moving that date to December 1, 2027 to buy time for the Personal Data Protection Agency to be set up and for application standards to be defined. According to Anguita & Osorio, the bill would also adjust the agency's institutional design, expand the board from three to five members and allow a written warning as the first sanction during the first 12 months of application.

Paraguay arrives with a different but related picture. Law No. 7593/2025 creates the National Personal Data Protection Agency within MITIC, sets a 24-month vacatio legis and adds concrete rules on incident notification, international transfers and sanctioning powers. At the same time, the DNIT published General Resolution No. 47/2026 on cryptoassets, which requires residents and platforms to report annual transactions above US$5,000 through Marangatu, under obligation 959-DJI with an annual filing deadline. The country is also moving toward a data-sharing platform between DNIT and banks, based on web services, which speeds access to financial movements during audits.

Peru, meanwhile, shows a more fragmented but still coherent sequence. Supreme Decree No. 016-2024-JUS modernized the regulations for Personal Data Protection Law 29733 and set staggered deadlines for appointing the Personal Data Officer. At the same time, the SBS has been updating its incident and continuity framework, with one cybersecurity resolution and another on operational incidents under public consultation. Resolution SBS No. 01747-2026, meanwhile, sets the operating model for Banking as a Service, with board policies, prior risk assessment, continuous monitoring and minimum contractual terms.

Mexico, Brazil and Argentina add another layer that should be read as convergence between fraud prevention, operational risk and beneficial ownership control. In Mexico, the LFPIORPI reform centers on risk, monitoring, auditing and customer classification. In Argentina, the BCRA added a specific section for fraud risk management within operational risk guidelines. And in Brazil, the central bank not only regulated PSAV authorization and operation, but also moved virtual asset transactions into the foreign exchange perimeter and strengthened anti-fraud controls with temporary preventive holds.

Key facts table

Date Event Source Confidence
2026-09-01 Chile reported that the executive branch proposed delaying Law 21,719 until December 1, 2027 Chile Ministry of Economy Confirmed
2026-09-05 DMCI&A noted that Law 21,719 replaces Law 19,628 and will give sanctioning powers to the new agency DMCI&A Confirmed
2026-08-31 Paraguay, via Lawwwing, described the National Personal Data Protection Agency as a decentralized unit within MITIC Lawwwing Confirmed
2026-09-07 Edydsi indicated 72-hour incident notification and fines of up to 10,000 minimum wage units in Paraguay Edydsi Confirmed
2026-08-22 Paraguay's DNIT required annual reporting of cryptoassets above US$5,000 through Marangatu Pytagua Confirmed
2026-09-05 El Nacional reported progress on data sharing between DNIT and ASOBAN El Nacional Confirmed
2026-09-10 Mexico published Agreement 115/2026 reforming the LFPIORPI General Rules PLD.mx Confirmed
2026-09-08 COEM said the risk-based approach will apply starting March 1, 2027 Coem.mx Confirmed
2026-09-18 COEM detailed the mandatory annual internal audit for vulnerable activities Coem.mx Confirmed
2026-09-04 Colombia: Law 2573 was published and takes effect six months later, except for exceptions in Article 5 Superintendence of Finance of Colombia Confirmed
2026-09-10 Baker McKenzie explained that Law 2573 requires identity verification and document authenticity measures Baker McKenzie Confirmed
2026-08-27 Argentina: the BCRA issued Communication A 8471 on fraud risk management Official Gazette of the Argentine Republic Confirmed
2026-09-01 Argentina published Communication A 8471 in the Official Gazette Argentina.gob.ar Confirmed
2026-09-12 Brazil: Blue Consult summarized Central Bank Resolutions 519, 520 and 521 for PSAV Blue Consult Confirmed
2026-09-10 Brazil: Resolution BCB 584 added anti-fraud controls and temporary preventive retention Campos Thomaz Advogados Confirmed
2026-09-07 Peru: Supreme Decree 016-2024-JUS and its Personal Data Officer directive were already in force Apaxi Confirmed
2026-08-25 Peru: Resolution SBS 01747-2026 established the operating framework for BaaS Ozone API Confirmed
2026-09-01 Uruguay activated the mandatory PSAV register and a digital authorization channel iProUP Confirmed
2026-09-10 Bolivia formalized a commitment before the IMF for a robust virtual asset framework CryptoNews.net Confirmed

Operational timeline

Date Event Actor/vector Verified source
2026-08-22 Paraguay's DNIT publishes the annual reporting obligation for cryptoassets above US$5,000 Tax authority Pytagua
2026-08-25 Peru defines the BaaS operating framework with Resolution SBS 01747-2026 SBS / open banking Ozone API
2026-08-27 The BCRA issues Communication A 8471 on fraud risk Central bank / operational fraud Official Gazette of the Argentine Republic
2026-08-27 Mexico already has the substantive LFPIORPI reform circulated under Agreement 115/2026 AML regulation PLD.mx
2026-08-31 Paraguay consolidates the reading of its data law and agency within MITIC Privacy and supervision Lawwwing
2026-09-01 Chile presents a bill to delay Law 21,719 Executive / personal data Chile Ministry of Economy
2026-09-01 Argentina publishes Communication A 8471 in the Official Gazette Central bank / fraud Argentina.gob.ar
2026-09-01 Uruguay activates the digital channel for PSAV authorization and registration Central bank / virtual assets CriptoNoticias
2026-09-04 Colombia confirms the phased entry into force of Law 2573 Identity protection Superintendence of Finance of Colombia
2026-09-05 Paraguay advances a DNIT-ASOBAN web service mechanism Tax supervision El Nacional
2026-09-07 Paraguay sets 72-hour security incident notification Personal data Edydsi
2026-09-10 Mexico enters a phase of documented risk-based obligations AML / compliance Jones Day
2026-09-10 Colombia opens a public consultation on identity verification systems SIC / identity validation Baker McKenzie
2026-09-12 Brazil consolidates the BCB 519, 520 and 521 framework for PSAV and the FX market Virtual assets Blue Consult
2026-09-18 Brazil strengthens anti-fraud controls with Resolution BCB 584 PSAV / fraud Campos Thomaz Advogados
2026-09-19 Uruguay increases fraud protection in payment methods with stronger authentication Payment methods / authentication El País (Uruguay)
2027-01-01 New anti-fraud rules for virtual assets take effect in Brazil PSAV / temporary retention MercGroup
2027-03-01 Mexico activates several operational components of the new regime RBA / classification / monitoring Coem.mx
2027-09-01 Argentina reaches full force of the new fraud risk management framework Operational risk / fraud Bruchou & Funes
2027-11-27 Paraguay reaches the general effective date of its Law 7593/2025 Personal data El Nacional de Paraguay
2027-12-01 Chile, if the delay does not pass, brings Law 21,719 into force Personal data / agency BCN Chile

Attack chain and TTPs

Casbaneiro remains the clearest example of how a regional banking campaign adapts to defenses and to regulatory environments that demand finer monitoring. According to the research reports, the payload stays dormant until it detects that the user has accessed banking sites, at which point it intercepts credentials and manipulates financial sessions. That makes it especially relevant for banks and fintechs that rely only on hash blocking or domain blocking, because the operational trigger happens during real browsing.

The infrastructure architecture also changed. SocPrime described distributed data reception servers for C2, with multiple exfiltration endpoints. RST Cloud, for its part, documented MITRE ATT&CK techniques that include obfuscation, system discovery, execution through the web and process manipulation, which fits an operation designed to persist, hide and exfiltrate data in layers. The practical result is that detection cannot depend on a single signature or a single blocklist.

The campaign observed in August 2026 affected banking users in Mexico, Peru, Argentina and Colombia, with invoice or legal notice lures and malicious PDFs. That was joined by job-themed phishing campaigns in Brazil, and by BREEZE COMET, a financially motivated actor also active in that country. The research also mentions LLM-assisted intrusions, DuckDNS domains and multiple binaries, suggesting an operational surface where automation, exfiltration and post-exploitation are no longer unusual exceptions.

Casbaneiro Attack FlowPhishingInvoice or noticeDormant payloadBanking detectionTheft ofcredentialsSessionhijackedDistributed C2and exfiltration
Casbaneiro Attack Flow — From phishing and banking activation to distributed exfiltration.
TTP Description Source
T1027 Obfuscated files or information to hinder analysis RST Cloud
T1027.009 Packed or obfuscated content RST Cloud
T1027.013 Additional obfuscation technique observed in the campaign RST Cloud
T1033 System information discovery RST Cloud
T1036 Masquerading of names or artifacts RST Cloud
T1047 WMI execution RST Cloud
T1055 Process injection or manipulation RST Cloud
T1059.007 Script-based execution RST Cloud
T1071.001 Web channels for command and control RST Cloud
T1082 System information discovery RST Cloud

Observed flow in the Casbaneiro campaign

The technical sequence described in the reports suggests a fairly classic but still effective path: delivery through phishing, activation when the victim visits a financial site, dormant loading, credential theft, session manipulation and exfiltration toward distributed servers. The relevant point is not the novelty of each step, but how they fit together. When the outbound infrastructure shifts to a distributed model, reputation controls and static blocking lose effectiveness quickly.

That pattern also helps explain why several of the new regulatory frameworks in the report are pushing toward automated monitoring, deviation alerts and historical evidence retention. Regulatory defense and technical defense are starting to look alike. The supervisor demands traceability, and the attacker forces organizations to produce it for every incident, transaction or suspicious access.

Regional impact

The regional picture shows a converging movement: regulators are no longer limiting themselves to asking for reports or consent, but are demanding operational capability to classify risk, preserve evidence, notify incidents, audit processes and justify automated decisions. That affects banks, fintechs, PSAVs, telecom operators, credit entities and, in several countries, any organization that handles personal data or sensitive financial information flows. The pressure is not uniform, but it is synchronized: the hardest deadlines fall between November 2026 and January 2028.

Regional overview

Chile, Paraguay, Mexico and Brazil concentrate the most structural changes in personal data, virtual assets and AML. Peru and Colombia are advancing in cybersecurity, operational incidents and identity verification. Argentina is introducing a formal fraud management framework in the financial system. Uruguay is ordering PSAV authorization and adding a new anti-fraud layer in payment methods. Bolivia, for now, sits in an intermediate position, with a reform commitment that still has no closed calendar.

Chile

Chile has Law No. 21,719, which according to the National Congress Library takes effect on December 1, 2026 and replaces the old Law No. 19,628. The Ministry of Economy, however, said the government proposed pushing that date to December 1, 2027 to give time for the Personal Data Protection Agency to be installed and for application standards to be defined. The change is not minor, because the bill also expands the agency's board from three to five members and adjusts the first appointments of its authorities.

For the private sector, the result is twofold. If the original date holds, the agency will receive sanctioning powers over controllers, including private companies. If the delay moves forward, organizations gain time, but not a full pause, because the institutional design will be more detailed and adaptation will need to start early. The Anguita & Osorio report makes clear that the debate is not whether compliance will happen, but when and under what architecture.

Paraguay

Paraguay has one of the densest frameworks in the report. Law No. 7593/2025 creates the National Personal Data Protection Agency within MITIC, sets a 24-month transition, orders incident notification within 72 hours and regulates international transfers under adequacy or contractual safeguard criteria. The law applies to any public or private organization that handles personal data and provides for fines of up to 10,000 minimum wage units.

At the same time, the DNIT issued General Resolution No. 47/2026 to declare annual cryptoasset transactions above US$5,000. The process requires a tax ID, obligation 959-DJI, filing in Marangatu and an informational sworn statement before Internal Revenue. In addition, banking and tax information is moving faster between DNIT and ASOBAN through a web service, which strengthens oversight and financial traceability. For banks, fintechs and exchanges, the pressure is happening on three layers: privacy, taxation and access to financial information.

Peru

Peru is showing a mix of data protection, cybersecurity and new financial distribution models. Supreme Decree 016-2024-JUS modernized the regulations for Law 29733 and established a size-based timeline for appointing the Personal Data Officer. According to the material reviewed, mid-sized firms with annual sales between 1,700 and 2,300 UIT must appoint the officer by November 30, 2026. The regulation also requires notification of incidents to the National Personal Data Protection Authority within 48 hours and adoption of standards such as ISO/IEC 27001.

The SBS is also pushing the operational front. Resolution SBS No. 01741-2026, according to Apaxi, requires reporting cybersecurity incidents and channel outages within 24 hours and notifying affected users within 10 business days. Resolution SBS No. 01747-2026 sets the BaaS framework with board policies, risk assessment, continuous monitoring, minimum contracts and biannual publication of active recipients. And the draft single operational incident reporting procedure, still under consultation, could unify outages and cybersecurity events under one channel.

Colombia

Colombia is tackling identity impersonation. Law 2573 protects victims from negative reports and debt collection, imposes sufficient and reasonable digital security measures to verify identity and document authenticity, and requires the person to be marked as a victim of personal falsity when there is a complaint. According to the Superintendence of Finance, the law was published on May 19, 2026 and takes effect six months later, except for parts of Article 5 that apply from promulgation.

The effect for banks, telecoms and merchants is operational. They must retain evidence of the onboarding process, including biometrics, IP and document validation, and respond to claims under a framework in which the burden of proof shifts. The public consultation opened by the SIC in September 2026 is aimed precisely at strengthening identity validation and personal data processing, so the Colombian ecosystem is moving toward more technical and auditable controls. The proposed reform of Law 1581 adds another layer, although it remains only a proposal.

Argentina

Argentina focused on internal and external fraud. BCRA Communication A 8471 created Section 6.5, Fraud Risk Management, within the risk management guidelines. The rule requires a specific organizational structure, assignment of responsibilities, self-assessment of risk, a mitigation plan and coordination with technology and information security risk management. In addition, the phased schedule pushes full effectiveness to September 2027.

The practical burden is not abstract. Entities must define risk appetite, document processes, report indicators to the board and adjust controls to new fraud patterns. LM Neuquén added that, starting in September 2026, immediate transfer administrators will receive public information from the BCRA to build person-level fraud risk profiles. That places the Argentine system into a more granular prevention model, with transfers and personal fraud as the main focus.

Brazil

Brazil already had a robust framework for PSAVs and kept refining it. Central Bank Resolutions 519, 520 and 521 build the authorization, operation and regulated perimeter architecture for virtual assets. PSAVs must show financial capacity, lawful source of capital, business viability, compatible technology infrastructure, proper governance and the technical reputation of administrators and controllers. In addition, certain virtual asset transactions were brought under the foreign exchange market and require counterparty identification.

The next layer came with Resolution BCB 584, which expands anti-fraud rules and enables a preventive hold of up to 24 hours for certain transfers above US$10,000 per client per day when they are sent abroad or to self-custody wallets. The jump is significant because supervision is no longer limited to authorizing entities, but can intervene in the transaction flow when the risk warrants it. In practical terms, Brazil is pushing PSAVs and banks toward preventive control, not only reactive control.

Mexico

Mexico is the largest case in the report. Agreement 115/2026 rewrote the General Rules under the LFPIORPI, added 11 new chapters and put the risk-based approach at the center of compliance. The change covers vulnerable activities and PSAVs, with a requirement for documented methodology, customer classification into three levels, enhanced due diligence, beneficial owner identification with a 25% threshold, annual training and periodic audits.

Implementation is phased. General effectiveness begins on November 30, 2026, but several operational components activate on March 1, 2027 and the annual audit period begins on January 1, 2028. Automated monitoring mechanisms must keep files, group transactions, feed the risk assessment, generate alerts and store histories for at least 10 years. For sectors such as casinos, gaming, sweepstakes and other vulnerable activities, this means reworking platforms, alert rules and internal manuals from end to end.

Bolivia

Bolivia does not yet have a closed regime, but it does have a clear direction. The Economic and Financial Policy Memorandum dated September 10, 2026 commits the country, under the IMF program, to develop a robust virtual asset framework. The goal is to prevent illicit capital outflows and protect financial resilience. The available material makes clear that there is still no defined timeline, no single main authority and no detailed legislative approach.

The cautious reading is that Bolivia is entering a design phase. Some reports speak of tripartite oversight between the Central Bank, ASFI and the UIF, while others mention possible stricter AML rules for VASPs, but those pieces are not confirmed at the same level as the memorandum. For this report, the verifiable point is the intention to create a robust framework and the absence of a closed calendar.

Uruguay

Uruguay consolidated its PSAV regime and added another layer on payment fraud. The Central Bank said it had prepared a regulatory project for PSAVs and, according to iProUP, activated a mandatory register formally effective as of September 1, 2026. The country already has a digital channel for authorization and registration, and the rules require fund segregation, transparency, cybersecurity and internal controls.

At the same time, the BCU introduced a proposal to reinforce fraud protection in payment methods. The initiative calls for stronger authentication when electronic instruments are linked to digital wallets and allows a tokenized instrument to function as a possession factor if it has a unique and secure link to the customer's device. It is a clear sign of convergence between payments, identity and fraud management.

Technical indicators

Type Value Source
Domain m-doxa-apodo.duckdns.org GBHackers / SocDefenders AI
Domain m-doxa-geo.duckdns.org GBHackers
Domain m-doxa-intel.duckdns.org GBHackers
IP 178.128.87.160 GBHackers
IP 165.22.184.26 GBHackers
IP 167.148.195.53:8888 SocDefenders AI
Cert hash SHA-256 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c GBHackers / SocDefenders AI
Cert hash SHA-256 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 GBHackers / SocDefenders AI
Cert hash SHA-256 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 GBHackers / SocDefenders AI
Binary socktz_v9.exe SocDefenders AI
PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 GBHackers
PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd GBHackers
Malicious email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 GBHackers
Malicious email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 GBHackers

Analysis for security teams

The first operational takeaway from the report is that the risk surface can no longer be managed by business function alone. Fraud, data, cybersecurity, compliance and operational risk teams now have to work from the same process map. The reason is simple: in the region, several regulators are asking for the same thing under different names, whether that is risk-based assessment, evidence retention, stronger authentication, automated monitoring or incident reporting.

On detection, the priority pattern is to combine identity, behavior and transaction monitoring. Mexico requires keeping risk histories for at least 10 years and generating alerts for high-risk customers, PEPs and restrictive lists. Colombia pushes identity control into onboarding and requires evidence retention. Uruguay and Brazil are pushing stronger authentication and anti-fraud controls in payments and virtual assets. That suggests effective detection now extends beyond SIEM or SOC operations and must include business rules, customer profiling and correlation with regulatory events.

On mitigation, priorities change by country, but not the logic. Where deadlines are short, as in Peru and Argentina, the urgency is governance, appointments and internal manuals. Where the change is structural, as in Mexico and Brazil, the urgency is redesigning monitoring engines, classifying risk by level, formalizing methodology and making sure evidence is exportable and auditable. Where the law is still in transition, as in Chile or Bolivia, it makes sense to prepare architecture and contracts before the political window closes.

In threat intelligence terms, the material on Casbaneiro, CL-CRI-1163, BREEZE COMET and LLM-assisted campaigns points to a particular focus on email, banking navigation, endpoint devices and distributed C2. The fact that Casbaneiro's payload activates when a user accesses banking sites means browser protection, behavioral analysis and session-manipulation detection need to be strengthened. In Brazil, campaigns aimed at HR show that the entry point can be a corporate email, not a digital banking portal.

Based on the research, the recommended prioritization would be the following. First, close compliance gaps with hard deadlines, especially in Mexico, Peru, Argentina and Paraguay. Second, consolidate evidence and logs, because several rules already require proving that validation or assessment actually took place. Third, review third parties, PSPs and cloud or BaaS providers, since third-party risk responsibility appears in Peru, New York and Mexico. Fourth, integrate fraud and cybersecurity into a single dashboard, because attacks that hit banks now exploit identity, email, web and automation at the same time.

Country matrix and focusPersonal dataFraud and cyberAML and CFTVirtual assetsCharges and reportingChileParaguayPeruColombiaBrazilMexico
Country matrix and focus — 2026-2027 comparison map by obligation type.

Frequently asked questions

Which countries in the report have the most urgent changes between 2026 and 2027?

Mexico, Brazil, Peru, Colombia, Paraguay and Argentina concentrate the nearest milestones because they combine phased effective dates, adaptation deadlines and new monitoring or reporting requirements. Chile is also relevant because of its data law, although its timeline depends on the possible legislative delay. Uruguay and Bolivia are in different stages, more focused on registration or regulatory design.

Which frameworks require automated monitoring rather than only manual controls?

Mexico explicitly requires it under the amended LFPIORPI, with six minimum functions and historical retention. Brazil links it to anti-fraud controls for virtual assets, and Peru incorporates it through different incident reporting and supervision schemes in cybersecurity and digital banking. At the same time, the technical pressure from Casbaneiro reinforces the need for automated detection.

Which countries already require or anticipate short incident-reporting deadlines?

Paraguay sets a 72-hour deadline for security incidents, Peru calls for 24-hour reporting of cybersecurity incidents and 10 business days to notify affected users, and Colombia is moving identity validation into a regime that protects victims of impersonation. In the United States, the research also mentions 36-hour and four-business-day clocks for banks and issuers.

Where is the convergence between fraud, personal data and operational risk clearest?

Argentina, Mexico and Colombia show that convergence most clearly. Argentina created a specific fraud risk section within operational risk. Mexico turned AML, customer classification, beneficial ownership and auditing into a formal program. Colombia tied its identity impersonation law to identity verification, documentary proof and personal data protection.

Which jurisdictions in the report already affect crypto and virtual assets directly?

Brazil, Uruguay, Paraguay and, at an earlier stage, Bolivia. Brazil already has authorization, a foreign exchange perimeter and anti-fraud controls. Uruguay activated registration and authorization for PSAVs. Paraguay added an annual reporting duty for cryptoassets and banking cross-checks with the DNIT. Bolivia has only committed to a robust framework before the IMF so far, without a closed calendar.

Material limitations

The material provided allows for a fairly precise reconstruction of regulatory calendars, main obligations and part of the regional operating context, but it does not include the full text of some rules or their technical annexes. In Chile, for example, the postponement bill has already been reported, but the final status of the legislative process cannot be confirmed from this research alone. In Bolivia, the available information is programmatic and does not allow a final authority or timeline to be fixed.

It was also not possible to directly verify some details published by secondary sources when they themselves mark them as uncertain, such as the exact 270-day period for the transitional PSAV authorization process in Brazil or the operational start of the DNIT-ASOBAN platform in Paraguay. In those cases, the report keeps the attribution to the source and does not elevate the claim to the same level as the confirmed facts.

Regional 2026-2028 calendar2026Chile: draftofpostponement2026Mexico: entryinto generalforce2027Mexico: EBR andclassification2027Argentina: fullyin force of thefraud2027Paraguay: datafully in forcein force2028Mexico: auditof the firstyear
Regional 2026-2028 calendar — Regulatory milestones and implementation deadlines by country.
Most Affected SectorsQualitative reading based on the number of frameworks and depth of obligationsBanksFraud, identity, AML, cyberFintechBaaS, crypto, monitoringVASPAuthorization, segregation, auditTelecom and creditIdentity verification
Most Affected Sectors — Banks, fintech, VASPs, and regulated entities bear the heaviest compliance burden.

Sources

View all