CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
This law applies to any natural or legal person, includ - ing public bodies, that carries out data processing. Unlike the Framework Law, it has a clear extraterri - torial reach. It applies whenever a data controller is established in Chile or when processing is intended to offer goods or services to, or monitor the behaviour of, individuals within the national territory. The law establishes the National Personal Data Pro - tection Agency as the supervisory authority with the power to issue binding instructions. These instruc - tions will define the technical and organisational measures necessary to ensure data confidentiality and resilience. Failure to comply with these security standards can result in severe financial penalties. The Computer Crimes Law The Computer Crimes Law No 21,459 was enacted to adapt domestic legislation to the international stand - ards of the Budapest Convention. It typifies specific offences such as illegal access to computer systems, unlawful interception, computer forgery and computer fraud. The law covers actions directed against any computer system or data located in Chile, as well as those perpetrated from within the country. One notable feature of this statute is the legal pro - tection provided for ethical hacking. Individuals who access a computer system in a responsible manner to identify vulnerabilities may be exempt from criminal sanctions. This requires registration with the ANCI and immediate reporting of the findings to both the Agency and the system operator. The subject-matter scope is strictly criminal, yet it interacts with cybersecurity management by impos - ing harsher penalties when an attack affects essential services. It also mandates that service providers must preserve data for criminal investigations upon request. This law applies transversally to all organisations and individuals. The Fintech Law No 21,521 Law No 21,521, also known as the Fintech Law, aims to promote competition and financial inclusion through technological innovation. It regulates crowd - funding platforms, alternative transaction systems, investment advisers and custody services. The law is
overseen by the CMF, which sets standards for infor - mation security and risk management. The organisations in scope include all providers reg - istered in the Registry of Financial Service Providers. For international companies, the law mandates the establishment of a legal domicile in Chile. The CMF is empowered to issue binding general instructions regarding cybersecurity and operational resilience. This law also establishes the Open Finance System (SFA), which requires participants to implement secure interfaces (APIs) for data exchange. These interfaces must comply with strict security and authentication standards defined by the CMF. Binding Standards and Sectoral Regulations Chile currently maintains several sector-specific regu - lations that impose binding cybersecurity standards. • Banking and finance – the CMF manages the “Updated Compilation of Standards” (RAN), par - ticularly Chapters 20-7 to 20-10, which regulate operational risk and cybersecurity. • Insurance – entities must comply with NCG No 454, which establishes principles for managing cybersecurity risks and reporting incidents. • Energy – the electricity sector follows the NERC- CIP standards adopted by the National Electric Coordinator (CEN) to ensure the continuity of the National Electric System. • Telecommunications – Resolution No 1,318 issued by the Undersecretariat of Telecommunications (Subtel) sets mandatory foundations for the design and operation of secure networks. • Healthcare – the Ministry of Health has issued technical instructions (eg, Resolution No 853) regarding telemedicine and the protection of clini - cal records. • Pensions – the Superintendency of Pensions main - tains a Model for Information Security and Cyber - security Management applicable to all pension fund managers. Interplay Between Regulations and Co-ordination The interplay between these regulations is governed by the co-ordination rules set out in the Cybersecurity Framework Law. The ANCI acts as the central techni -
60 CHAMBERS.COM
Powered by FlippingBook