CiberLATAMbywhalemate

Uruguay BCU tightens payment authentication

The central bank proposed stronger authentication for card-not-present purchases and digital wallet enrollment

Whalemate Labs · AI-assisted researchPublished:2 min read

Uruguay's central bank proposed stronger authentication for card-not-present transactions and for enrolling electronic instruments in digital wallets. The plan includes an exception for certain recurring merchant-initiated payments, while AEBU warned parliament about data leaks and fraud risks in open finance.

The Central Bank of Uruguay has introduced a proposal that would require stronger authentication for card-not-present transactions and for enrolling electronic payment instruments in digital wallets, with an exception for certain recurring payments initiated by the merchant, according to El País. At the same time, AEBU warned a parliamentary committee that a financial data interoperability scheme without minimum requirements and security standards for all participants could raise the risk of data leaks, fraud, and other cybercrime.

What does the BCU proposal include?

The Central Bank of Uruguay proposal would tighten authentication in two specific areas, card-not-present transactions and the enrollment of electronic instruments in digital wallets. El País also reported that the text includes an exception for certain recurring payments initiated by the merchant.

The measure is aimed at standardizing how purchases and enrollments are verified in digital channels, as Uruguay's regulator also moves on other parts of the financial system. El País placed the proposal within a broader discussion about stronger protection against fraud.

What did AEBU warn about open finance?

AEBU told a parliamentary committee that a financial data interoperability system without minimum requirements and security standards for all participants could increase the risk of information leaks, fraud, and other cybercrime. The warning was linked to the competitiveness bill and the open finance framework.

El Observador described that system as a regulated digital infrastructure supervised by the Central Bank of Uruguay, giving individuals and companies more control over their financial data. AEBU's concern is that data sharing should not advance without uniform security conditions.

What changed for fiduciaries?

FERRERE reported that the BCU changed the regime applicable to general and financial fiduciaries, and that financial professional fiduciaries that do not comply with the new rules have until March 31, 2027 to adapt. That deadline sets the regulatory horizon for the sector's transition.

The update adds another compliance front for actors in Uruguay's financial system, alongside the debates over payments, digital wallets, and open finance. Together, the measures and warnings point to a regulatory adjustment that touches both data handling and validation mechanisms, as well as fiduciary governance.

Sources

View all