Chile Tightens Financial Cyber Rules
Chile’s CMF and Central Bank move on outsourcing, risk, stablecoins and data protection, with new compliance pressure for finance firms.
Chile’s Financial Market Commission published General Regulation No. 573 on outsourced services in insurance and reinsurance, tying it directly to corporate governance, operational risk management and cybersecurity. At the same time, the Central Bank outlined a framework for stablecoins, and the future Data Protection Agency will expand oversight powers starting in December.
Chile’s Financial Market Commission has published General Regulation No. 573, which governs outsourced services in insurance and reinsurance companies and explicitly links them to corporate governance, operational risk management and cybersecurity. The CMF had already issued General Regulation No. 571 for exchanges and intermediaries, with requirements covering risk, information security, cybersecurity and business continuity.
What does the new outsourcing rule require?
General Regulation No. 573 sets prudential requirements for contracting outside services and requires firms to treat outsourcing under the frameworks of General Regulation No. 309, General Regulation No. 325 and General Regulation No. 454. According to Diario Estrategia, the rule also adds minimum principles and requirements for identifying, assessing, monitoring and controlling the risks that come with outsourced services.
Latino Insurance added that the regulation includes a transitional provision so companies can adjust their outsourcing contracts before full entry into force. That matters because the rule goes beyond broad principles and places outsourcing squarely within operational risk management and control.
What changed for exchanges, brokers and agents?
General Regulation No. 571, issued on July 27, 2026, consolidated and organized the rules that apply to securities and commodity exchanges, stockbrokers and securities agents, and required them to demonstrate risk management policies, information security, cybersecurity and business continuity in order to operate before the CMF.
Garrigues said the text strengthens risk standards as part of authorization and operating requirements. In practice, the measure leaves financial market participants with more formal obligations to show that their technology and continuity controls are documented and working.
What did the Central Bank say about stablecoins?
The Central Bank of Chile said in its Payment Systems Report that it will put a new regulatory framework for stablecoins out for consultation, with conditions for issuance in Chile when they can be used as a means of payment. Chócale added that Claudio Raddatz, head of the Financial Policy Division, set the target as a draft rule for consultation by late 2026 and a final regulation in 2027.
That timeline gives banks and payment service providers a clearer adjustment window for working with these instruments. The Central Bank said the scope of the framework will carry compliance implications for financial institutions and payment providers.
What does the personal data agenda add?
An analysis of Chile’s future Personal Data Protection Agency said that, starting December 1, 2026, the authority will be able to issue binding instructions, interpret the law, carry out ex officio inspections and impose sanctions without needing a civil trial. That expands oversight over banks, insurers and other financial market players in how they process and secure data.
Together, the rules on outsourcing, risk, stablecoins and personal data leave Chilean financial institutions facing stricter compliance requirements, with a focus on operational controls, cybersecurity and information management.
Sources
- Lo que Chile sí regula y lo que todavía no: una mirada a la protección de datosactualidadjuridica.doe.cl· DOE Actualidad Jurídica
- Postergar la Ley de Datos Personales: un síntoma, no una solucióntrendtic.cl· TrendTIC
- Chile: la CMF consolida la regulación de bolsas de valores e intermediarios y refuerza estándares de riesgosgarrigues.com· Garrigues
- Agencia de Protección de Datos Chile: facultades, sanciones y lecciones desde casos reales en el mercado chilenoefectus.cl· Efectus
- Chile Data Protection & Privacy Regulation Monitordataprotection.gi· GDPRI Data Protection & Privacy Regulation Monitor
- CMF publica normativa sobre externalización de servicios compañías seguros y reasegurosdiarioestrategia.cl· Diario Estrategia
- Cómo afecta la nueva Ley de Protección de Datos al corredor de seguroscolegiodecorredores.cl· Colegio de Corredores de Seguros de Chile
- Informe de Sistemas de Pagobcentral.cl· Banco Central de Chile
- Claudio Raddatz, del Banco Central: "Aspiramos a generar ..."chocale.cl· Chócale
- Chile: Ley de Protección de Datos e Inteligencia Artificial, el doble desafío que enfrentan las empresascompliancelatam.legal· Compliance Latam
- ¿Se puede vender por WhatsApp? Qué cambia para las pymes con la Ley de Protección de Datos Personalesbiobiochile.cl· BioBioChile
- Ciberataques | Noticias de Hoyfmplus.cl· FMPlus
- Ley 21.719: protección de datos de salud en Chilesalutexa.com· Salutexa
- CMF publica normativa sobre externalización de servicios para compañías de seguros y reasegurosboletines.latinoinsurance.com· Latino Insurance Boletines



