CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
with Law No 19.628 on the protection of per - sonal data and its updates. The General Standard issued by the CMF that regulates the SFA establishes that information service providers ( instituciones proveedoras de información , or IPIs) and account provid - ers ( instituciones proveedoras de cuentas , or IPCs) must obtain the express consent of the data subject to share financial information with information-based service providers ( institu - ciones proveedoras de servicios basados en información , or PSBIs) and payment initiation service providers ( proveedores de servicio de iniciación de pagos , or PSIPs). Also, consent must be specific, informed and unequivocal, detailing the information to be shared, the insti - tution that will receive it, the validity period and the purpose. PSBIs and PSIPs cannot request additional con - sent for the same exchange of information, nor discourage or hinder the consent process. In addition, both PSBIs/PSIPs and IPIs/IPCs must record and store consent for a minimum period of five years. In terms of information security and cybersecu - rity, on the other hand, financial institutions must implement information security and cybersecu - rity measures to protect customers’ personal data. These include, for example: • policies and procedures to manage informa - tion security and cybersecurity risks; • access controls to protect restricted areas and user privileges; • tools to control, record and monitor user activities; • mechanisms to control access to electronic channels to mitigate the risk of impersona - tion;
• encryption techniques to protect the confi - dentiality and integrity of information; • regular data quality tests; and • policies and procedures for business continu - ity. Finally, other rules are applicable, for example, to the outsourcing of services applicable to both traditional financial institutions and institutions providing fintech services (including, for exam - ple, alternative asset transaction mechanisms), in which it is necessary to adopt risk manage - ment and operational safeguard measures that include verifying that the jurisdiction in which the data is processed has high levels of protection of personal data. See also 5.3 Data Localisation Requirements . 5. International Considerations 5.1 Restrictions on International Data Transfers At present, the Law does not contain a specific provision in respect of international data trans - fers. However, the transfer of personal data out - side the jurisdiction may be deemed as a use of data, for which authorisation and other require - ments established by the Law would therefore be required. However, the New Law has a chapter dedicated to the international transfer of personal data, contemplating a wide catalogue of cases that would allow data to be implemented dynami - cally. See 5.5 Recent Developments . 5.2 Government Notifications and Approvals No government notifications or approvals are required to transfer data internationally.
68
CHAMBERS.COM
Powered by FlippingBook