CiberLATAMbywhalemate

Chile and Peru tighten cyber incident reporting

Chile and Peru set deadlines and penalties for incident reporting, while an Argentine ruling shifts attention to user conduct.

Whalemate Labs · AI-assisted researchJul 21, 20264 min read

Chile and Peru moved ahead with concrete incident-notification obligations for regulated entities, while a recent ruling in Argentina again put the focus on user conduct rather than a bank failure. The regional picture also includes references to DORA, Russia’s GOST framework, and the BCRA’s regulatory role over fintech and payments.

Shorter deadlines and tougher penalties

Chile and Peru are pushing new incident-reporting standards that will affect banks, fintechs and other supervised operators. In Chile, Law 21.663 requires an early alert within 3 hours, an update within 72 hours and a final report within 15 days for cyberattacks or incidents with significant impact. For operators of vital importance, if the incident affects the delivery of essential services, the update window drops to 24 hours and fines can reach 40,000 UTM in the most serious violations, according to guidance from Chile’s National Congress Library.

The same BCN cybersecurity guide also explains that covered entities must implement security controls, manage risks, protect personal data, maintain incident response plans and be able to show those measures to the authority. In parallel, another BCN guide on cybercrime says offenses include obstructing or preventing the normal operation of a computer system, altering or destroying data, and computer forgery, with penalties that vary depending on the severity of the offense.

Peru sets a 24-hour incident notice rule

In Peru, the SBS has ordered that cybersecurity incidents affecting users or service channels be publicly reported within 24 hours. When the incident does not interrupt service channels, the entity must notify affected users directly within 10 business days. According to information published by Ecosistema Startup, the resolution will take effect 360 days after publication, giving supervised entities close to a year to adjust processes and systems.

DORA and the operational resilience benchmark

Outside the region, the European Union’s DORA regime requires financial entities to maintain a documented ICT risk management framework, reviewed at least once a year. Springlex says those entities may outsource tasks tied to verifying risk-management requirements, but they remain fully responsible for compliance.

The Bank of Greece’s DORA guide adds continuous monitoring, incident detection, business continuity and recovery testing, and mandatory reporting of serious incidents through specific templates and secure channels. It also refers to annual testing of critical systems and advanced threat-led penetration testing for selected entities.

Russia and the GOST framework

In Russia, Polozhenie 672-P requires credit institutions to comply with GOST 57580.1 at least at the standard protection level, while card payment processing centers must reach the enhanced level as soon as the standard enters into force, according to Angara Security.

Argentina, fintech and bank liability

In Argentina, a recent ruling found that a bank is not liable for harm suffered by a customer when the disputed transactions took place after the user exposed security credentials under deception, and no failure was proven in the home banking platform or in the institution’s security mechanisms. The court placed primary responsibility on the user who repeatedly entered token passwords and rejected claims against the bank for transactions carried out in that context.

That approach fits with the local regulatory framework. J.F. Cattáneo’s guide on fintech in Argentina identifies the BCRA as a key authority in payments, foreign exchange and certain lending models, with direct compliance and cybersecurity implications for financial institutions and fintechs. The same analysis also points to the CNV, the UIF, the data protection authority, consumer protection bodies and the tax authority, depending on the business activity.

In the same vein, a comment on a proposed reform of the BCRA’s Organic Charter argues that the central bank should receive explicit powers to regulate and supervise virtual asset service providers and modernize payments with cybersecurity and AML safeguards.

Sources

View all