Chile tightens cyber and fraud rules
Chile adds stronger authentication, faster reporting and new duties for banks, fintechs and payment firms under Law 21.719 and NCG 538.
Chile is adding cyber, data and fraud rules for banks, fintechs and payment providers, along with faster reporting and stronger security duties. Full enforcement of Law No. 21.719, set for Dec. 1, 2026, plus the obligations already set by Law No. 21.663, CMF NCG 538 and MK4’s fraud reform, is changing the compliance map for banks, fintechs and other actors in Chile’s financial system.
Update September 21, 2026: Law 21.663 and the upcoming Law 21.719 are now even more closely linked on the regulatory front, because a single breach could require notices to two different authorities with different deadlines and formats. Proactivanet also noted that the Cybersecurity Framework Law sets fines of up to 40,000 UTM for Vital Importance Operators.
Chile is adding cyber, data and fraud rules for banks, fintechs and payment providers, with faster reporting and stronger security duties. Full enforcement of Law No. 21.719, scheduled for Dec. 1, 2026, together with the obligations already set by Law No. 21.663, CMF NCG 538 and MK4’s fraud reform, is reshaping compliance for banks, fintechs and other players in Chile’s financial system. The new framework combines stronger authentication, faster reporting, tighter controls over personal data and a different split of responsibilities across payment rails.
What changes with Law 21.719?
Law No. 21.719 creates the Personal Data Protection Agency, requires breach notification and sets fines of up to 20,000 UTM or 4% of annual sales, according to the National Congress Library analysis. Kardu says the law includes a transition period and takes full effect on Dec. 1, 2026, when the agency will begin supervising and sanctioning all organizations that process personal data belonging to people in Chile.
That scope includes banks and other financial institutions. Saytec says data encryption, access controls, audit logs and incident management are now legal obligations, not recommendations. G5 Noticias adds that once December enforcement begins, organizations handling personal data must be able to prove high standards for managing, documenting and validating permissions granted by data subjects.
Vanlook Studio also warns that the law includes a 72-hour type of clock for reporting breaches to the authority when there is a risk to data subjects. In practice, that moves Chile’s financial-sector reporting discipline closer to a fast-disclosure standard similar to the European GDPR.
Later analysis adds that the Dec. 1, 2026 start date has been clouded by regulatory uncertainty because the government introduced a bill to push it back to Dec. 1, 2027. At the same time, failing to put in place adequate security measures, such as not deploying multi-factor authentication or keeping vulnerable software in place, could itself be punished under Law 21.719, even if no breach has occurred.
What does Law 21.663 require from financial players?
Law No. 21.663 created the National Cybersecurity Agency and made incident reporting to the National CSIRT mandatory within a maximum of 3 hours, according to the National Congress Library analysis. For Vital Importance Operators, a category that can include critical financial infrastructure, Proactivanet says noncompliance can lead to fines of up to 40,000 UTM.
Saytec says those organizations must also have detection, response and containment capabilities, post-incident forensic analysis and periodic response drills. Corvus reaches the same conclusion, describing a shift away from paper compliance and toward continuous risk management, with prevention, constant monitoring and remediation capacity.
PressLatam focuses on the law’s permanent obligations to prevent, report and resolve incidents, which force financial actors to move from a formal approach to active risk management. At the same time, Proactivanet warns that a single breach in the financial system could trigger simultaneous notices to ANCI and the future data authority, with different deadlines and formats.
The combination of Law 21.719 and Law 21.663 creates a dual reporting regime for financial institutions. Personal data breach notices go to the APDP, while cyber incident reports must reach the National CSIRT within 3 hours, raising operational demands for banks, fintechs and other market players.
How does this overlap with NCG 538?
CMF NCG 538 has required banks, fintechs, regulated card issuers and cooperatives since Aug. 1, 2026 to use at least two independent authentication factors for electronic transfers, digital customer onboarding and changes to sensitive data. The enhanced authentication allowed under the rule can include passwords, devices and biometrics such as fingerprints, facial recognition or voice recognition.
Chilean media and specialist coverage indicate that the requirement is already affecting day-to-day digital operations, because no covered actor can process those critical transactions without validating the user’s identity with two independent factors. The impact is not only regulatory, it also reaches onboarding flows and sensitive information updates.
How does this overlap with MK4 reform?
MK4’s reform to the Fraud Law changes the user liability standard in payment rails when enhanced authentication was used, shifting it from gross negligence to ordinary negligence, according to La Tercera. That change reinforces security demands on financial institutions and payment service providers, and it also introduces a presumption of user lack of care in court in those cases.
Chile’s reform of Law No. 20.009, within the broader capital markets overhaul, also expands security duties to processors, card brands, payment system administrators and Open Finance participants, while keeping financial institutions responsible for safeguarding electronic transactions, according to Garrigues. The same analysis says that if a transaction was authenticated with stronger controls, the user may be liable for ordinary negligence, adjusting the evidentiary standard and the allocation of responsibility in electronic fraud cases.
The same legal analysis cited by La Tercera keeps judicial authorization in place for an issuer to suspend reimbursement of funds. Garrigues adds that an issuer that repays money after a fraudulent transaction may seek recovery from other participants that contributed to the fraud, including processors, card brands, payment system administrators and Open Finance actors.
Economic coverage of MK4 also says the reform will allow the sale of specific fraud insurance for payment rails and add a single sworn-statement form to channel user complaints, standardizing how issuers and other financial-system players process reports of unrecognized transactions, according to La Tercera and MSN.
Holdo says the update to the Fraud Law is part of a broader package aimed at simplifying regulation and positioning Chile as a regional financial center. In that context, payment security changes and the redistribution of operational risk are tied to a competitiveness and market-trust strategy, not just a sector response to incidents.
The roadmap recently presented by the CMF on payment fraud and regulatory modernization is meant to complement the executive bill that amends Law No. 20.009, according to Chócale. That creates a coordination framework between CMF administrative supervision and legislative changes to the liability regime for fraud.
Sources
- Fintec: desafíos regulatorioslatercera.com· La Tercera
- NCG 461 y NCG 519: qué debe reportar tu empresa a la CMFinformat.cl· Informat
- Asesorías parlamentarias – análisis sobre Leyes 21.663 y 21.719bcn.cl· Biblioteca del Congreso Nacional de Chile
- Las tres medidas más relevantes en MK4 para la presidenta de la CMF: ajuste a ley de fraudes, Fonavi y separar roles en AGFlatercera.com· La Tercera
- Ley de Datos Personales: los cinco pasos que las empresas deben abordar antes de su entrada en vigenciag5noticias.cl· G5 Noticias
- José Antonio Gaspar por cambios en MK4 a ley de fraudes en medios de pago: “Es completamente positivo para todos los actores”latercera.com· La Tercera
- Chile impulsa una reforma estructural del mercado de capitales que ...garrigues.com· Garrigues
- Ley 21.719: obligaciones para empresas y multassaytec.cl· Saytec
- Responsabilidad bancaria por transferencias electrónicas y deberes de seguridadjurischile.com· JurisChile
- Chile's Law 21.719: What Changes for Marketingvanlookstudio.com· Vanlook Studio
- Dólar en $943, IPSA en 11.220 y petróleo sobre los US$ 100holdo.cl· Holdo
- Regulación de ciberseguridad 2026: España, Colombia y Chileproactivanet.com· Proactivanet
- Chile’s Law 21.719 — Compliance Guidekardu.eu· Kardu
- Del cumplimiento a la acción: los desafíos de ciberseguridad que aún persisten en Chilepresslatam.cl· PressLatam
- Ley 21.663: ¿qué significa para la ciberseguridad de las empresas en Chile?corvus.cl· Corvus
- Ley de Protección de Datos: ¿qué deben revisar las empresas para evitar riesgos?g5noticias.cl· G5 Noticias
- Monitoreo Regulatorio para Servicios Financieros en Chilelawmeter.io· Lawmeter.io
- Exposure Management - SEKsek.io· SEK · Security Ecosystem Knowledge
- José Antonio Gaspar por cambios en MK4 a ley de fraudes en medios de pago: 'Es completamente positivo para todos los actores'msn.com· MSN
- Presidenta de la CMF por cambios a la Ley de Fraudes ...chocale.cl· Chócale
- Ley 21.719: obligaciones, multas y plan de cumplimientopreyproject.com· Prey Project
- Chile refuerza la seguridad bancaria con doble autenticaciónportalmetropolitano.cl· Portal Metropolitano
- Nueva Ley Marco de Ciberseguridad de Chilenews.altonaspain.es· Altonaspain News
- Chile refuerza la seguridad bancaria: dos factores de identidad se vuelven obligatoriosg5noticias.cl· G5Noticias
- Ley de Protección de Datos Personales: claves para las empresascygnus.cl· Grupo Cygnus
- Checklist de seguridad WordPress para pymes chilenas (2026)brante.dev· Brante.dev
- La nueva regulación de los criptoactivos revoluciona mercados financieros internacionales y derechounir.net· UNIR Revista de Derecho
- Ley 21.719: Qué Es, Qué Exige y Cuándo Rigeahd.cl· AHD
- Ley 20.009 y demandas del banco por culpa grave: cómo la IA cambia el análisis de responsabilidadconstitucionalai.com· ConstitucionalAI
- Ley de Datos: 72% de empresas no está preparada y Gobierno busca aplazarlapoderyliderazgo.cl· Poder y Liderazgo
- People-Centered Cybersecurity: The New Approach Required by Law No. 21,663 in Chileaz.cl· AZ Tech
- Transferencias y operaciones bancarias críticas ya exigen doble verificación de identidad en Chilelinaresenlinea.cl· Linares en Línea



