Peru moves on biometrics and mobile lines
Peru’s debate now includes new rules for identity systems, mobile line limits and penalties for lending bank or wallet accounts.
Peru’s debate over identity, biometric verification and control of digital services added new rulemaking deadlines, per-user limits and sanctions for people who lend bank accounts or digital wallets for criminal use.
Update August 25, 2026: Peru’s debate over identity and control of digital services added new rulemaking deadlines, limits on mobile line contracts, and a specific penalty for lending bank accounts or digital wallets for criminal purposes.
Peru’s debate over identity, biometric verification and control of digital services has now expanded to include new regulatory deadlines, limits on mobile lines, and tougher penalties for people who lend bank accounts or digital wallets for crimes. At the same time, Congress, OSIPTEL and various news reports have clarified how this agenda fits with existing identity and anti-fraud rules.
What is known about the proposal?
The bill titled "Law that Protects Identity and Establishes Guidelines for Financial Cybersecurity in Peru" appears as a legislative initiative in a regional analysis of artificial intelligence and cybersecurity regulation. That description says the proposal aims to protect identity through fingerprint use and set cybersecurity guidelines for the financial system.
The same description adds that the goal would be to provide legal protection for digital users. Under that framing, the initiative focuses on two specific fronts, identity validation and the security of financial transactions.
What changed in the legislative discussion?
The discussion widened with initiatives that set concrete deadlines to implement verification systems and with proposals that tighten control over bank accounts, digital wallets and mobile lines. According to the Congress of the Republic of Peru, the Executive Branch has 120 days to approve the corresponding regulation, and the Ministry of the Interior together with the National Police must implement the systems within the same period.
In the case of another proposal linked to identity and biometric verification in the financial system, La Razón reported that the SBS would have 90 calendar days to issue the technical regulation and interoperability protocols with RENIEC and the PNP. That same initiative includes a prison term of 10 to 15 years for anyone who lends, rents, transfers or allows someone else to use a bank account or digital wallet, knowing it will be used to commit a crime.
What is happening with mobile lines?
Bill 14522, according to Gestión, proposes a maximum of ten mobile lines per operator and 20 nationwide per natural person, and also creates a national integrated system for identification, verification and traceability of access to telecom services and digital platforms. The same report adds that the proposal also foresees a National Registry of Active Lines by User, administered by OSIPTEL.
That registry is intended to improve control and prevent identity theft or fraudulent use of phone numbering. Along the same lines, OSIPTEL has already approved complementary measures that allow any user to request a full block to prevent new mobile lines from being opened in their name, with in-person lifting and reinforced protocols.
What measures are already in force?
OSIPTEL also requires biometric validation for natural persons who have more than ten registered mobile lines and temporarily limits mobile service contracts to one service per month and per operating company. An earlier resolution, 000116-2025-CD/OSIPTEL, had already introduced the obligation to validate identity through biometric verification at authorized service points for those who exceed that line threshold.
The official gazette El Peruano said current rules set a cap of seven mobile lines per natural person and that OSIPTEL has been ordering the cancellation of additional lines when that limit is exceeded. The same report said the restriction is aimed at protecting security, identity and personal data.
Does the new proposal create new crimes?
Not necessarily. A legal analysis released by Canal N said the bill promoted by lawmaker María del Carmen Alva does not create the crime of lending accounts from scratch, but instead increases penalties and strengthens the prosecution of conduct already defined as aiding crime.
That reading narrows one of the most widespread versions of the proposal and places it within a broader regulatory package that combines biometric verification, user traceability and tougher punishments for conduct tied to fraud and extortion.
What regulatory background is close to this agenda?
The immediate backdrop already showed changes in the way financial and mobile services are contracted and controlled. In the payments system, the Central Bank allowed the use of the DNI number as an alias for instant transfers, while in telecoms OSIPTEL and the Executive Branch moved ahead with rules to curb identity theft and the mass contracting of lines.
A supreme decree regulating the National Police Law, cited by JurisPol, also reiterated that funding for new technological security and verification obligations will come from the institutional budget of the Ministry of the Interior, without requiring additional resources from the public treasury. That approach now appears reflected in the design of the new measures on biometric identity and access control.
What still does not appear in the public domain?
Additional sources available on Peru’s recent financial regulatory ecosystem point to rules already in force or being implemented, such as Central Bank circulars allowing the DNI number to be used as an alias for immediate payments and SBS resolutions on cybersecurity incident reporting. However, none of those references explicitly mention the title, wording or timeline of this law.
That suggests that, at least in the accessible public record, the proposal has not yet received specific coverage in general-interest media, official statements from Peru’s Congress, or detailed technical analysis from security firms. For now, the available material makes it possible to map the name of the initiative and its broad purpose, but not confirm its legislative status or when it might advance.
What is the nearby regulatory context?
The nearby regulatory picture does show changes in payment mechanisms and incident-reporting obligations. Against that backdrop, the identity and financial cybersecurity proposal appears as one more piece of a policy agenda that mixes digital identification, risk prevention and user protection in Peru’s financial system.
Sources
- Personas podrán transferir dinero al instante con número de DNI, ¿desaparecerán celular y QR?perucontable.com· Peru Contable
- Peru Will Let You Send Money Using Just Your ID Numberriotimesonline.com· The Rio Times
- Regulación sobre IA en América Latina y el Caribealgoritmos.uniandes.edu.co· Universidad de los Andes (Colombia) – Proyecto Algoritmos
- Maricarmen Alva propone el reconocimiento facial obligatoriolarazon.pe· La Razón
- Congreso: proponen eliminar el anonimato en líneas móviles y aplicativos para frenar la extorsióngestion.pe· Gestión
- Osiptel permite a usuarios restringir nuevas líneas móviles a su nombrelarepublica.pe· La República
- Protege tu identidad: la norma limita líneas móviles para prevenir fraudes. Conoce cómoelperuano.pe· El Peruano
- Congreso: proponen reconocimiento facial obligatorio en bancos y billeteras digitales para frenar la extorsiónlatinanoticias.pe· Latina Noticias
- Préstamo de cuentas ya es delito, advierte abogada Diana Pérezcanaln.pe· Canal N
- Reglamento del DL 1267, Ley de la PNP [DS 012-2025-IN]jurispol.pe· JurisPol
- Aprueban dictámenes sobre identidad policial, digitalización judicial y lucha contra el abigeatocomunicaciones.congreso.gob.pe· Congreso de la República del Perú
- OSIPTEL aprueba regulación y refuerza seguridad en la contratación del servicio móvilespecial.larepublica.pe· La República (Especial)



