CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
Incident Reporting The CMF in Chile has established a regulatory frame - work for the management of operational and cyberse - curity incidents in the financial sector, with the aim of protecting users and the stability of the system. This framework applies to various entities, including banks, card issuers, insurers and fintechs, with specific regu - lations for each type of entity. With the entry into force of the Cybersecurity Frame - work Law, it is expected that there will be coordination between the CMF and the ANCI, and a multi-window platform will likely have to be created to facilitate inci - dent reporting. • Sanctions – failure to comply with these regulations can result in fines of up to 15,000 UF (approximate - ly USD420,000), which can increase fivefold in the case of repeat offences. • Incident reporting – all entities regulated by the CMF are required to report operational incidents, although deadlines vary. For example, banks and insurers must do so within 30 minutes of the incident, while specific fintech activities have a deadline of two hours. These reports must include detailed information about the incident, such as its description, date and time, causes, impact on customers and services, and measures taken for mitigation. • Communication – in general terms, entities should consider the need to inform their customers about incidents that affect the quality of services or that are publicly known. In addition, they should share relevant information about cybersecurity incidents with the rest of the industry, encouraging collabo - ration and prevention. 3.4 Operational Resilience Enforcement The CMF requires entities to guarantee access to the information and records of suppliers, both on-site and remotely, even if the supplier is abroad. The CMF reviews the audit reports carried out by the suppliers. Entities must report to the CMF any operational inci - dent that affects an outsourced service, allowing the CMF to supervise the incident response capacity and recovery plans.
In the event of non-compliance with the regulations, the CMF may require that the services be carried out in the country or that the entity execute them inter - nally, ensuring that the entity maintains a plan that allows it to comply with these requirements. 3.5 International Data Transfers According to Chapters 20-7 and 20-10 of the RAN, entities must have defined specific data processing sites. In the case of processing abroad, the jurisdiction must be defined and known. The city where the data centres operate must be known. Moreover, if an entity outsources data processing ser - vices outside the country, it must have a contingency data processing centre located in Chile and demon - strate a recovery time compatible with the criticality of the outsourced service. There is the possibility of exemption from this requirement if the entity main - tains adequate operational risk management and can ensure preventive measures such as a recovery time objective (RTO) approved by the board of directors, sites with adequate availability time, and sites in dif - ferent locations that mitigate both geographical and political risks. In addition, if the outsourced service includes the transmission of data outside the country that is sub - ject to secrecy or banking secrecy (according to Arti - cle 154 of the General Banking Law), prior authorisa - tion from each client is required. Regarding country risk, services can only be out - sourced in jurisdictions that have an investment grade country risk rating. If the country does not have this rating, the board of directors may make an excep - tion to this requirement as long as the country has adequate personal data protection and security laws. Finally, it stands out that communication connections between the entity and the provider must have a lev - el of encryption that ensures the confidentiality and integrity of data from end to end. The processed infor - mation must be stored and transported in encrypted form, with the decryption keys held by the entity.
3.6 Threat-Led Penetration Testing This issue has not arisen in this jurisdiction.
68 CHAMBERS.COM
Powered by FlippingBook