CiberLATAMbywhalemate

Chile tightens cyber, data rules

Chile’s CMF tightened AML due diligence for fintechs and other supervised entities, while ABIF and Microsoft expanded cybercrime cooperation.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Law 21.663, Law 21.719 and CMF changes are reshaping reporting, KYC and data rules across Chile’s financial sector. A recent AML update also raised due diligence requirements for fintechs and other supervised entities, while ABIF and Microsoft agreed to expand cooperation against cybercrime.

Update September 12, 2026: The CMF tightened due diligence and know-your-customer requirements in its anti-money laundering rules through Circular No. 2,325. ABIF and Microsoft also expanded their cooperation to share threat intelligence and information on malicious actors through Microsoft’s Cyber Threat Intelligence Program.

Chile’s Cybersecurity Framework Law No. 21,663 already sets specific risk management and significant incident reporting duties for certain essential service providers and operators of vital importance, a category that can include players in the financial system. At the same time, the CMF removed the requirement to send fraud information to the regulator every six months when that same information is already published on the websites of supervised entities.

What changes with Law 21,663?

Law No. 21,663 requires certain essential service providers and operators of vital importance to manage cybersecurity risks and report significant incidents. According to the analysis cited by IAPP, that can include actors in the financial system if they are classified in those categories.

The law is not limited to incident response. It also introduces preventive management requirements, raising the bar for internal cybersecurity governance in critical organizations.

How does Law 21,719 affect personal data?

Law No. 21,719, published in the Official Gazette on December 13, 2024, regulates the protection and processing of personal data in Chile, creates the Personal Data Protection Agency, and requires security incidents to be reported to that authority without undue delay when there is a reasonable risk to the rights and freedoms of data subjects.

PixaWeb’s guidance adds that this obligation also covers data tied to economic, financial, banking, or commercial obligations. In the same vein, Garrigues’ analysis describes a certification and registry framework for models to prevent data protection violations, designed to organize requirements, modalities, and procedures for implementation, certification, registration, and supervision.

What did the CMF do about fraud reporting?

According to legal analysis published by Veredictum, the CMF eliminated the obligation to send fraud information every six months under Law No. 20,009 when that information is already required to be posted on the websites of supervised entities. The publication duty remains, but the periodic filing with the regulator is removed starting with the report for the second half of 2026.

The change reduces one formal reporting step, but it does not eliminate transparency obligations to the public. For entities within the supervised perimeter, the update requires a review of internal publication processes and documentation compliance.

What other requirements are being tightened in the sector?

The CMF also updated its anti-money laundering rules through Circular No. 2,325, with stricter due diligence and know-your-customer requirements for the fintech ecosystem and other supervised entities, according to Truora. That comes on top of recent public alerts about companies without current registration or authorization to provide services regulated by the Fintech Law, such as E-PANDA Financiero SpA, as reported by outlets that echoed the CMF’s own notices.

At the same time, the CMF opened a consultation on a rule that conditions certain complementary activities of payment operators on counterparties acting in line with national law and holding the proper business authorization, reinforcing compliance oversight of payment service providers. Warnings have also been issued involving fintech and informal credit actors under closer scrutiny.

How is Chile’s financial industry responding?

The Chilean Association of Banks and Financial Institutions and Microsoft signed a cooperation agreement to strengthen the cybersecurity capabilities of Chile’s financial industry, with a focus on detection, prevention, and incident response.

Microsoft’s official statement says the alliance links ABIF’s Cybersecurity Coordination Group, the VTF, with Microsoft’s Digital Crimes Unit to identify, investigate, and disrupt cybercrime networks, generate threat intelligence, and work on analysis of malicious actors and emerging trends. It also gives Chile’s financial sector access to Microsoft’s Cyber Threat Intelligence Program, adding another layer of intelligence as regulators raise the bar on incident reporting and risk management.

The cooperation also includes, according to Base Nacional, the exchange of information on trends and malicious actors, analysis of emerging threats, and access to global threat intelligence capabilities through Microsoft’s Cyber Threat Intelligence Program (CTIP).

Sources

View all