Paraguay, Chile and Mexico update digital rules
Paraguay, Chile, Mexico, Brazil and Argentina are advancing bills on cybersecurity, personal data, AI and safer digital environments.
Paraguay, Chile, Mexico, Brazil and Argentina have new proposals under review on cybersecurity, personal data, artificial intelligence and safer digital environments. The texts target critical operators, digital platforms, minors, data agencies and compliance rules for companies and public bodies.
Paraguay, Chile, Mexico, Brazil and Argentina moved several bills in September that touch cybersecurity, personal data, artificial intelligence and digital platform security. Taken together, the initiatives expand requirements for public and private operators, set new adjustment deadlines and strengthen compliance obligations for technology companies, public agencies and digital service providers.
What happened in Paraguay?
The Senate added the bill "On the protection of critical infrastructure" to the agenda for September 16. The proposal is based on the Budapest Convention on cybercrime. It seeks to identify public entities, create a national critical infrastructure registry and require incident detection and response systems.
The journalistic analysis cited by Última Hora adds that the text creates the figure of critical infrastructure operators, both public and private. Those entities would have to report incidents within 12 hours of the event, install IDS and IPS systems, and adopt security protocols for operational technology and IoT. According to that reporting, the scope includes banks, utilities and state digital services.
How is AI regulation moving in Brazil?
Bill 1797/2024 is still under review and aims to establish general rules for the development, implementation and responsible use of artificial intelligence systems. The goal is to protect human rights and ensure systems are safe and reliable, with direct implications for the use of data and algorithms.
In parallel, the regulatory tracking cited by LCF Consulting says Brazil's National Data Protection Authority has already begun inspections and sanctions linked to the use of AI and biometrics in 2026. It also launched a regulatory sandbox through Notice No. 2/2025 with selected companies, and identified the need to improve synthetic data protocols and technical communication. That backdrop points to compliance demands that intersect with the legislative process.
What is being discussed in Argentina about minors and platforms?
In the Chamber of Deputies, bill 1114-D-2026 was introduced in 2026 to protect minors' data on digital platforms. The text sets a tiered regime by age, bans account creation for children under 13, requires verifiable parental consent between ages 14 and 16, and obligates platforms to implement age-verification systems as a شرط to operate.
The analysis by Estudio Lexar adds that these proposals make age verification a general legal obligation for platforms, with adjustment periods to be set after regulation is issued. That point would affect compliance obligations for digital providers operating in the Argentine market.
What changes in Chile with Law 21.719?
The executive branch submitted a bill to the Senate on September 1 to delay by one year the full entry into force of Law No. 21.719, which regulates the protection and processing of personal data and creates the Data Protection Agency. If approved, the date would move from December 1, 2026 to December 1, 2027.
Chile's National Congress Library confirms that the law was published on December 13, 2024, and that its general effective date is currently set for December 1, 2026. The change would also modify the structure of the future agency, including the composition of the governing board, the quorum needed to operate and the deadline for its early appointment. Until the extension is approved, the 2026 timeline remains in force, even though the bill was introduced with maximum urgency.
Consultancies and civil society groups are already reading that scenario through a compliance lens. Some recommend moving ahead anyway with data governance, information security and responsible management. Others warn there will be an additional year of vacatio for the full protection of rights, though with more time for companies to adapt processes and policies.
What is being pushed in Mexico City and Sonora?
In Mexico City, lawmaker Alberto Martínez Urincho introduced an initiative to add Articles 6 Bis and 6 Ter to the Federal Political Constitution, with the goal of guaranteeing the right to live in a safe digital environment. The text assigns civil, administrative and criminal liability to digital service providers, technology platforms and social networks for harm caused by designs aimed at compulsive or addictive use.
The proposal also calls for strengthened default protections for minors and was sent to committees for review before a possible move to the Congress of the Union. In Sonora, meanwhile, a constitutional reform was introduced to recognize and strengthen the powers of Internal Control Bodies as guarantors of transparency, access to information and personal data protection, with technical autonomy, functional independence and resources to carry out their work.
The Sonoran proposal is still in the initial reading and debate stage, but it aligns with compliance frameworks by strengthening institutional oversight in personal data and transparency.
Sources
- Relatório e Estado da Regulação de IA no Brasilmonitor.lcfconsulting.com.br· LCF Consulting
- ANPD em nova fase: fiscalização, IA e biometria em 2026minutodaseguranca.blog.br· Minuto da Segurança
- Ley de Datos Personales: los cinco pasos que las empresas deben abordar antes de su entrada en vigenciag5noticias.cl· G5 Noticias
- Senado tratará “infraestructura crítica” en su sesión ordinariaultimahora.com· Última Hora
- Delay or pause? 10 practical considerations regarding the postponement of Law 21.719covarrubias.legal· Covarrubias Legal
- Ley Chile - Ley N° 21.719 y disposiciones transitoriasbcn.cl· Biblioteca del Congreso Nacional de Chile
- Legislação de Inteligência Artificial no Brasil — Regulação de IA: acompanhamento legislativomonitor.lcfconsulting.com.br· LCF Consulting
- Senado tratará “infraestructura crítica” en su sesión ordinariaultimahora.com· Última Hora
- Atualizações da regulação de IA no Brasil — o que mudoumonitor.lcfconsulting.com.br· LCF Consulting
- Protección de datos de menores en plataformas digitales | Lexarestudiolexar.com· Estudio Lexar
- Alerta Legal: La postergación de la Ley de Protección de Datos no es una treguaaninat.cl· Aninat Abogados
- Prórroga a ley de protección de datos personaleslatercera.com· La Tercera
- Buscan garantizar derecho de las personas a un entorno digital segurocdmx.info· CDMX Magacín
- El enjambre sin leyheraldodemexico.com.mx· El Heraldo de México
- Congreso Sonora impulsa iniciativas Órganos Internos Controlexpreso.com.mx· Expreso
- Ley 21.719 e IA: checklist para pymes antes de diciembre 2026ia2030.cl· IA2030.cl
- Government presents project to postpone the entry into force of the Personal Data Protection Law N° 21.719 in Chileeusee.hivos.org· Hivos / EUSEE
- Ley de Datos Personales: los cinco pasos que las empresas deben abordar antes de su entrada en vigenciag5noticias.cl· G5 Noticias



