CiberLATAMbywhalemate

Chile, Mexico and Colombia tighten controls

New privacy, AML and open finance rules advance in Chile, Mexico and Colombia, with different deadlines, sanctions and technical standards.

Whalemate Labs · AI-assisted researchPublished:37 min read

Chile, Mexico and Colombia are moving in parallel on three regulatory fronts that converge on the same demand, demonstrable control over sensitive data and operations. In Chile, Law 21,719 creates a new personal data protection framework with a specialized agency, mandatory activity logs, breach notification duties and risk-based technical safeguards, while the law still sets Dec. 1, 2026 as the effective date despite a bill seeking to push it to 2027. In Mexico, Agreement 115/2026 fully rewrites the general rules under the LFPIORPI, shifting the focus from formal compliance to effective risk management, adding 11 new chapters, strengthening customer classification, PEP controls, automated monitoring and annual audits, with a phased schedule running into 2028. In Colombia, Decree 368 of 2026 establishes the Open Finance System as mandatory infrastructure for covered entities, based on APIs, prior authorization from the account holder and standards set by the Financial Superintendency, while technical rulemaking and an implementation roadmap continue to move forward. The common thread is clear, more traceability, more provable accountability and less room for opaque data models or manual controls that are too weak.

Executive summary

Chile, Mexico and Colombia are advancing at the same time on three regulatory and technology fronts that meet at one point, the requirement for demonstrable controls over data and sensitive operations. In Chile, Law No. 21,719 replaces the old Law No. 19,628 and establishes a new personal data protection regime with a dedicated agency, mandatory records, stronger security duties and a stricter breach notification framework. In Mexico, Agreement 115/2026 rewrites the general rules of the LFPIORPI for vulnerable activities and shifts the focus from paper compliance to effective anti-money laundering and counterterrorist financing risk management. In Colombia, Decree 368 of 2026 builds a mandatory open finance infrastructure based on prior authorization, APIs and technical standards, while the Financial Superintendency defines the implementation architecture.

The timing is not accidental. The three rules already have fixed effective dates or staggered application schedules. In Chile, the current legal text and Decree 662 of 2026 place the general entry into force of Law 21,719 on Dec. 1, 2026, although a bill seeks to move it to 2027 and that delay has not been approved. In Mexico, Agreement 115/2026 takes effect as a general rule on Nov. 30, 2026, but some obligations, such as the risk-based approach, the institutional matrix, customer classification and automated mechanisms, activate later, between March and June 2027, with phased obligations running through 2028. In Colombia, Decree 368 was issued in April 2026 and is already in force, but its standardization depends on schedules and complementary resolutions.

The practical effect for financial entities and digital ecosystems is similar. Chilean companies will have to prove security, document their processing and notify breaches with traceability. Mexican obligated parties will need to recalibrate risk matrices, internal manuals, customer classification, PEP operation approvals and automated monitoring. Colombian entities, meanwhile, will have to operate under a regulated interoperability framework, where financial data exchange happens through APIs and with explicit, informed consent from the data subject. In all three cases, supervision is no longer limited to whether policies exist, but to whether those policies work, generate evidence and survive an audit or incident.

The regional picture also shows a major asymmetry. Chile and Mexico have entered an advanced implementation phase, with published texts, agencies or rules already in motion and adoption schedules underway. Colombia has already formalized its open finance system and is now working on deployment. The rest of the map covered in this report, especially Paraguay, Bolivia, Peru, Brazil, the United States and Uruguay, shows paths ranging from established regimes to frameworks in development or draft bills, which helps explain how digital regulatory infrastructure is moving across Latin America and how uneven compliance still is from one jurisdiction to another.

Background and context

The region has been stacking up changes that push financial and digital actors toward more open, more auditable and more governed architectures. Chile is leaving behind a data protection law widely seen in specialized analysis as outdated and replacing it with a rule that creates a specific authority, increases fines and requires formal registration of processing activities. Mexico, in parallel, is updating its anti-money laundering system for vulnerable activities and placing customer profiles, risk-based evaluation and automated controls at the center. Colombia, finally, is turning open finance into a regulated and mandatory infrastructure, where data flows are standardized through APIs and subject to prior authorization.

That regulatory movement is not isolated. In Chile, Law 21,719 is accompanied by a discussion over whether its effective date should be delayed by one year to allow more time for institutional implementation. In Mexico, the LFPIORPI reform already came with transitional timelines that spread obligations across Nov. 30, 2026, March 2027 and June 2027. In Colombia, Decree 368 of 2026 was followed by roadmap announcements, technical working groups, draft decrees and sector demands to speed up standards. The pattern is the same, legal text first, technical rollout later.

From an operational standpoint, that changes how companies have to prioritize resources. It is no longer enough to prepare a privacy policy or an internal anti-money laundering manual. What is now required is an inventory of processing activities, risk classification, transaction profile monitoring, access logs and the ability to show responses to incidents or changes in regulatory status. In Colombia, open finance also requires interoperability between supervised entities, technology providers and authorized third parties, with documentary control over consent and the circulation of financial information.

Key facts table

Date Event Source Confidence
2026-04-07 Decree 368 of 2026 was issued in Colombia to create the Open Finance System. GitHub, open-banking-colombia repository confirmed
2026-04-10 Decree 368 of 2026 entered into force in Colombia. GitHub, open-banking-colombia repository confirmed
2026-08-07 Mexico published a major reform of the general rules under LFPIORPI. biometric.vision confirmed
2026-09-01 Chile's government submitted to the Senate a bill to postpone Law 21,719 to Dec. 1, 2027. The Legal 500 confirmed
2026-09-08 Colombia's SIC opened a public consultation on identity verification and data processing. Baker McKenzie confirmed
2026-09-09 Chile's BCN published Decree 662, which references the effective date of Law 21,719 as Dec. 1, 2026. BCN Chile confirmed
2026-09-09 In Mexico, analysts described Agreement 115/2026 as the deepest change to the operational anti-money laundering rulebook. The Legal 500 confirmed
2026-09-11 TeleSemana reported an SMS Blaster campaign in Argentina to steal credentials and banking data. TeleSemana.com confirmed
2026-09-15 Peru's SBS launched a four-phase roadmap for the Open Finance System. Microfinanzas confirmed
2026-09-22 Forbes Colombia said Decree 368 of 2026 made the Open Finance System mandatory for regulated entities. Forbes Colombia confirmed
2026-09-25 TEDIC reported that Paraguay still needs to regulate its data protection law. TEDIC confirmed
2026-10-01 Uruguay's BCU sent a draft bill to create the Open Finance System. El País, Uruguay confirmed
2026-11-30 In Mexico, Agreement 115/2026 enters into force as a general rule. Forbes México confirmed
2026-12-01 Chile's Law 21,719 enters into general force under its transitional article and Decree 662 of 2026. BCN Chile confirmed
2027-03-01 In Mexico, the risk-based approach, institutional matrix and customer classification enter into force. CumplimientoPLD.com.mx confirmed
2027-06-01 In Mexico, the automated mechanisms of Article 41 enter into force. CumplimientoPLD.com.mx confirmed

Operation timeline

Date Event Actor/vector Verified source
2026-04-07 Issuance of Decree 368, which structures the Open Finance System. Government of Colombia GitHub
2026-04-10 Decree 368 enters into force. Colombian regulatory framework GitHub
2026-08-07 Publication of Mexico's anti-money laundering reform for vulnerable activities. Government of Mexico biometric.vision
2026-08-31 Signing of the presidential message proposing to delay Chile's Law 21,719. Chilean Executive Peritum
2026-09-01 Submission to the Chilean Senate of the delay bill. Government of Chile The Legal 500
2026-09-08 SIC public consultation on digital identity and data. SIC Colombia Baker McKenzie
2026-09-09 Publication of Chilean Decree 662, with an express reference to Dec. 1, 2026. Chilean Ministry of Finance BCN Chile
2026-09-17 Colombia's Financial Superintendency announces a roadmap and implementation working groups. Financial Superintendency El Heraldo
2026-09-22 CERLATAM reports the draft decree that sets deadlines for the schedule, board and indicators. Colombian Ministry of Finance CERLatam
2026-10-01 BCU sends draft bill on open finance. Central Bank of Uruguay El País, Uruguay
2026-11-30 General activation of Agreement 115/2026 in Mexico. Reform of LFPIORPI CumplimientoPLD.com.mx
2026-12-01 General force of Chile's Law 21,719. Chilean personal data law BCN Chile
2027-03-01 Start of the risk-based approach in Mexico. Reform of LFPIORPI PLD.mx
2027-06-01 Start of automated mechanisms in Mexico. Reform of LFPIORPI CumplimientoPLD.com.mx

Attack chain and TTPs

The material does not contain a single technical campaign with infrastructure, IP addresses, hashes or malware families that would allow for a classic attack-chain reconstruction. What it does show is a regional pattern of attack and control, where offensive pressure on financial data, identities and mobile messaging forces companies to raise defenses and regulators to demand traceability. In Argentina, SMS Blasters show a fraud vector based on brand impersonation and bypassing industry controls. In Paraguay, the forensic review cited by ABC Color describes undeclared functionality and blocking orders in license controllers. In Chile, the focus is on the regulatory response to breaches and on proving security. In Mexico and Colombia, the technical dimension shifts to monitoring, risk analysis and standardized data exchange.

So the TTP reading is structural, not forensic. The dominant vector is abuse of trust, whether through deceptive SMS, identity impersonation, credential abuse, hidden functionality or data exchange without enough governance. The objective is always the same, to access sensitive information, alter processes or monetize access to financial data. The regulatory response focuses on reducing exposure, strengthening authentication, documenting controls and requiring additional approval or traceability when risk rises.

TTP Description Source
SMS impersonation Fraudulent messaging campaign with deceptive links to steal banking credentials and passwords in Argentina. TeleSemana.com
Control evasion Messages that do not originate from official platforms and use mechanisms to evade traditional controls. TeleSemana.com
Functional concealment License controllers with undeclared functionality, partially hidden code and blocking orders. ABC Color
Transactional risk Banks required to detect unusual movements that do not match the customer's profile. Microjuris Argentina
Automated monitoring In Mexico, automated transaction-profile monitoring and alerts are required for PEPs and high-risk customers. biometric.vision, CumplimientoPLD.com.mx
Governed APIs In Colombia and Uruguay, data exchange depends on APIs under standards, consent and prior authorization. Forbes Colombia, El Observador

Regional impact

Regional overview

The comparative reading shows three different but complementary moves. Chile is consolidating a classic privacy regime with an authority, records, breach notification and enforceable technical measures. Mexico is turning operational anti-money laundering into a computable risk system, with automation, classification and auditing. Colombia is formalizing an infrastructure layer for open finance, where financial data circulates under authorization, interoperability and technical supervision rules.

In all three countries, protection is not limited to the legal plane. Data has to be inventoried, classified, protected, audited and, in some cases, shared through standardized interfaces. That affects banks, fintechs, merchants, software vendors, real estate firms, credit issuers, payment platforms and any actor that handles personal or financial data at operational scale.

Chile

Chile is imposing the clearest change in privacy, because Law 21,719 replaces the old Law 19,628 and creates a Personal Data Protection Agency with authority to supervise, instruct, certify prevention models, revoke certifications and impose administrative sanctions. The core of the reform is straightforward, document what data is processed, for what purpose, under what legal basis and with what security measures.

The rule also strengthens transparency duties, responses to data subject requests and breach notices. When a breach creates a reasonable risk, the company must notify the agency without undue delay and log the communication internally. If the breach involves sensitive data, data from children under 14 or financial data, the notification must also go to the affected data subject.

On security, the required standard is risk-based and includes pseudonymization, encryption, system resilience, quick restoration capability and periodic effectiveness testing. Siberson notes that after an incident, the controller will need to prove that the measures existed and worked properly, which forces retention of evidence, monitoring logs and test documentation. LexAlert adds that fines can exceed one billion Chilean pesos in serious or repeated cases.

The calendar remains critical. The legal text sets the date at Dec. 1, 2026, and Decree 662 reflects that date as well. However, there is a bill to postpone entry into force to Dec. 1, 2027 and strengthen the agency's institutional framework. Until that reform is approved and published, the legally enforceable deadline remains 2026.

Mexico

Mexico moved its anti-money laundering system toward a more sophisticated and more demanding compliance model for vulnerable activities. Agreement 115/2026 adds 11 new chapters to the general rules of the LFPIORPI and, according to the cited analysis, shifts the emphasis from formal compliance to effective risk management. That means looking at profiles, behaviors and relationships, not only amounts or forms.

The obligations are spread across several layers. The general reform takes effect on Nov. 30, 2026. On March 1, 2027, the risk-based approach, institutional matrix, customer risk classification, internal manual updates and related operational changes become effective. On June 1, 2027, the automated mechanisms of Article 41 enter into force, including alert systems for high-risk customers and politically exposed persons.

The technical content is extensive. HG Abogados and PLD.mx detail requirements for internal manuals, customer due diligence, risk classification, PEP lists management, beneficial owner identification, annual training with evaluation, automated transaction-profile monitoring and an annual independent audit. The Legal 500 adds that the interpretive shift also reaches trusts, joint venture arrangements and virtual asset service providers.

The most sensitive point is the decision chain. Coem.mx explains that when a customer is both a PEP and classified as high risk, any transaction must receive approval from an executive or equivalent. That adds a corporate governance layer to relationships that previously could be handled with less formal controls. Taken together, the reform turns risk into an operational input, not a standalone file detail.

Colombia

Colombia has formalized an open finance model that no longer depends only on best practices or private agreements. Decree 368 of 2026 establishes a regulated, interoperable and interconnected infrastructure for standardized access to and supply of financial data and services, with prior, express and informed authorization from the data subject. Forbes Colombia presents it as a mandatory framework for covered entities, with exchange through APIs under standards defined by the Financial Superintendency.

Implementation is still being built. El Heraldo reported seven technical working groups between June and July 2026 with more than 157 entities, while El País de Cali and CERLatam said the Financial Superintendency is advancing a roadmap and a schedule for issuing standards, the participant directory and tracking indicators. That shows the rule already exists, but real interoperability still depends on additional regulatory pieces.

The underlying logic is secure standardization. Material from Batea Fintech explains that certain financial data will circulate between authorized participants under applicable authorization and data protection rules. The goal is to increase competition, improve information symmetry and enable new products. In that framework, APIs are not a commercial option, but the interface that organizes exchange.

The identity verification debate adds another layer. Law 2573 of 2026, also in Colombia, reinforces protection against negative credit reports stemming from identity theft and requires sufficient and reasonable digital security measures for identity verification mechanisms and personal data processing. The SIC opened a public consultation to build guidelines and protocols, completing a regulatory ecosystem that mixes identity, credit and data protection.

Argentina

Argentina does not appear here with a new general law, but it does provide a real-world case that illustrates the operational risk of messaging fraud. TeleSemana reported an SMS Blaster campaign that uses portable antennas not belonging to licensed operators to send fraudulent messages with deceptive links aimed at stealing banking credentials and passwords. Claro and Telecom issued alerts and reinforced prevention protocols.

The legal dimension is also relevant. Microjuris Argentina cites case law holding that third-party access to banking data through specially designed deceit does not break the causal link, because the bank has a duty of result-level security and must detect unusual movements that do not match the customer's transactional profile. In another publication, Mario Vadillo says a recent court ruling assigned the bank 80 percent of the liability for failing to detect unusual transactions.

Paraguay

Paraguay already has Law No. 7593/2025 on personal data protection, with general effectiveness set for Nov. 27, 2027. The important point is not only the date, but that TEDIC warns the country still needs regulation and implementation mechanisms, which are key for the law to have real effect.

At the same time, the public cyber and banking docket remains active. ABC Color reported a fiscal investigation into Itti for alleged computer sabotage against Banco Atlas, with a forensic review that found undeclared functionality and blocking orders in core banking. The case highlights the importance of technical and contractual controls over critical software and access to financial systems.

Bolivia

Bolivia still does not have a general personal data protection law, and that gap translates into a lack of structural obligations for data controllers. Opinión and sala.red agree that there is no dedicated administrative authority, no specific sanctions regime and no duties such as telling users what data is stored, deleting it on request or notifying breaches. The Constitution provides a privacy protection action, but as an individual judicial remedy.

Despite that gap, the financial and fintech ecosystem operates with partial regulatory references. Yanapti says technology companies must address technology conditions, risk management, information handling, data protection and cybersecurity. 4notify adds that Law 164 protects privacy in electronic communications and that the Central Bank and ASFI regulate several payment rails, such as QR Simple and ACH-LIP. The country has regulatory activity, but not an integrated privacy framework.

Peru

Peru is in a design and phased rollout stage for its Open Finance System. The SBS published a four-phase roadmap extending through 2029, with a rules and specifications phase between 2026 and 2027, gradual implementation between the second half of 2026 and 2028, and a fourth phase that will include insurance, pensions, cooperatives and fintechs. Ligopay and Diario Financiero add that the focus is on interoperability standards, API security and user consent.

Peru's financial system also already has enabling pieces. The BCRP is developing a Retail Payments Platform that allows centralized payment initiation, and fintech regulation is split among the SBS, SMV and BCRP. Gestión warns that in partnerships with third parties, responsibility for data leaks will still rest with the financial institution. The picture is clear, Peru's open finance is being built on a payments and governance base that is still maturing.

Brazil

Brazil has the most mature Open Finance ecosystem. The model is regulated by the Central Bank, but operated by a private entity formed by market associations, under a logic of supervised self-regulation. SpaceMoney, ENAP and Openi agree that customer consent is mandatory, can be revoked and is implemented through secure APIs, with technical and security requirements set by regulation.

The system is still evolving, however. Valor Investe reported that the Central Bank is preparing new rules to allow companies outside the financial system to receive data from consenting customers. Convergência Digital stresses that security, certifications and technical specialization remain important challenges. The case of 644 Pix keys reported by Portal AZ confirms that the risk surface remains active even in a regulated, operational framework.

Mexico, the United States and Uruguay as complementary signals

Mexico shows the toughest version of risk-based control for vulnerable activities, while the United States is adding pieces of financial exchange and privacy through fragmented federal initiatives. Uruguay, by contrast, is designing its own open finance system with user control, APIs and Central Bank oversight, in line with its payments agenda and with stronger requirements for virtual asset service providers. The paths are different, but the direction is the same, more standardization, more documented consent and more regulatory accountability.

Technical indicators

No classic technical IOCs, such as domains, IPs, hashes or malware samples, were published in the consolidated material. The report can only reference vectors, rules and institutional actors, not verifiable forensic artifacts. That absence is consistent with the type of research available, which focuses on regulation, compliance and doctrinal or journalistic cases.

Analysis for security teams

The first operational adjustment is documentary. In Chile, any organization that processes personal data will need to reach Dec. 1, 2026 with a complete Records of Processing Activities inventory, identified lawful bases, mapped data flows and evidence of security measures. The rule does not reward intent, it requires proof. That means reviewing policies, logs, restoration tests, encryption, pseudonymization and breach response times.

The second adjustment is about risk. Mexico forces organizations to think in living matrices, not static files. Entities subject to the LFPIORPI will have to update customer classifications, strengthen PEP lists, automate monitoring and train staff with annual evaluation. A manual copied from templates will not be enough if it is not aligned with actual transaction behavior and the evidence required by the authority.

In Colombia, the focus must be on the integration layer. API-based exchange under standards set by the Financial Superintendency requires interface governance, traceable authorization, third-party control and monitoring of availability and performance. The risk is not only data leakage, but poor consent implementation, exposure through vendors and misalignment among authorized participants. The official roadmap and draft decrees show that this surface will keep changing.

For financial and payments environments, the cases in Argentina, Paraguay and Brazil work as control signals. Argentina shows that fraudulent messaging is still scaling and that banks can be exposed if they fail to detect unusual transactions. Paraguay shows how alleged software sabotage can strike core banking. Brazil confirms that even an advanced Open Finance model depends on sound access design, credential segregation and finely tuned permission governance.

Frequently asked questions

Which country has the most immediate regulatory change among Chile, Mexico and Colombia?

Chile, because Law 21,719 already has a general effective date set for Dec. 1, 2026 and requires preparation for records, security and breach notification. Mexico also turns on soon, but its obligations are phased through 2027. Colombia already has the base decree, but it is still refining implementation standards.

What is the technical difference between Chile's Law 21,719 and Mexico's Agreement 115/2026?

The Chilean law orders data protection, incident notification and risk-proportionate security measures. The Mexican agreement, by contrast, reorganizes anti-money laundering for vulnerable activities, introduces risk classification, a risk-based approach, automated monitoring and stronger controls over PEPs and beneficial owners.

What do Colombia and Uruguay have in common in their open finance projects?

Both countries propose regulated, interoperable infrastructure based on the user's prior, express and informed consent. In both cases, APIs are the exchange mechanism and the central bank plays a central role in regulation, supervision and the definition of technical standards for participants.

What does the cited case law on cyber fraud mean for an Argentine bank?

It means that a user's voluntary handover of credentials does not automatically erase the institution's liability. The cited case law and doctrinal commentary insist that the bank retains a security duty and must detect unusual movements that do not match the customer's transactional profile.

What new obligations appear in Chile if a breach involves sensitive data?

The company must notify the Data Protection Agency through the fastest available means and without undue delay, and must also log the communication internally. If the breach involves sensitive data, information about children under 14 or financial data, it must also inform the affected data subjects directly.

Limitations of the material

The material does not include a forensic investigation with verifiable technical indicators, so it was not possible to identify domains, IPs, hashes, samples, command-and-control infrastructure or campaigns attributed to a specific actor. Nor does it contain a single case that links the region's regulatory changes, in a proven way, to an adversary operation.

In Colombia, several pieces on the Open Finance System roadmap and schedule adjustments are attributed by the source to uncertainties or sector coverage, so they were kept that way and not elevated to confirmed fact when that was not appropriate. In Chile, the bill that would postpone Law 21,719 is still under review and does not change, for now, the effective date of Dec. 1, 2026.

This report was built exclusively from the material provided and does not include additional external corroboration. For that reason, the sections on Argentina, Paraguay, Bolivia, Peru, Brazil, Mexico, Colombia, the United States and Uruguay reflect only what could be verified within the consolidated research set.

Charts

2026-04Decree 368Colombia2026-08Agreement 115Mexico2026-09Chile draftpostponement2026-11Mexico entersinto force2026-12Chile in forceLaw 21.7192027-06Alerts PEPMexico
Comparative regulatory timeline — Key regulatory milestones in Chile, Mexico, and Colombia from April 2026 to June 2027.
ConsentOwner authorizesAPIs and standardsSecure exchangeMonitoringRisk and alertsReporting and proofEvidence and auditChile, Mexico, and Colombia converge on this operating sequence
Data regulatory flow — How consent, standardization, monitoring, and reporting link together in the frameworks analyzed.
CountryPrivacyRiskAPIsAuditChileMexicoColombiaBrazilUruguay
Country Obligations Matrix — Concise comparison of the regulatory pillars that most affect financial institutions and digital ecosystems.
Verified coverageChile, personal dataMexico, LFPIORPIColombia, open financePeru, open finance systemBrazil, Open Finance
Regional coverage map — Countries with verifiable facts in the compiled material and their main regulatory focus areas.

Sources

View all