Chile and Peru tighten cyber incident reporting
Chile and Peru set deadlines and penalties for incident reporting, while an Argentine ruling shifts attention to user conduct.
Chile and Peru moved ahead with concrete incident-notification obligations for regulated entities, while a recent ruling in Argentina again put the focus on user conduct rather than a bank failure. The regional picture also includes references to DORA, Russia’s GOST framework, and the BCRA’s regulatory role over fintech and payments.
Shorter deadlines and tougher penalties
Chile and Peru are pushing new incident-reporting standards that will affect banks, fintechs and other supervised operators. In Chile, Law 21.663 requires an early alert within 3 hours, an update within 72 hours and a final report within 15 days for cyberattacks or incidents with significant impact. For operators of vital importance, if the incident affects the delivery of essential services, the update window drops to 24 hours and fines can reach 40,000 UTM in the most serious violations, according to guidance from Chile’s National Congress Library.
The same BCN cybersecurity guide also explains that covered entities must implement security controls, manage risks, protect personal data, maintain incident response plans and be able to show those measures to the authority. In parallel, another BCN guide on cybercrime says offenses include obstructing or preventing the normal operation of a computer system, altering or destroying data, and computer forgery, with penalties that vary depending on the severity of the offense.
Peru sets a 24-hour incident notice rule
In Peru, the SBS has ordered that cybersecurity incidents affecting users or service channels be publicly reported within 24 hours. When the incident does not interrupt service channels, the entity must notify affected users directly within 10 business days. According to information published by Ecosistema Startup, the resolution will take effect 360 days after publication, giving supervised entities close to a year to adjust processes and systems.
DORA and the operational resilience benchmark
Outside the region, the European Union’s DORA regime requires financial entities to maintain a documented ICT risk management framework, reviewed at least once a year. Springlex says those entities may outsource tasks tied to verifying risk-management requirements, but they remain fully responsible for compliance.
The Bank of Greece’s DORA guide adds continuous monitoring, incident detection, business continuity and recovery testing, and mandatory reporting of serious incidents through specific templates and secure channels. It also refers to annual testing of critical systems and advanced threat-led penetration testing for selected entities.
Russia and the GOST framework
In Russia, Polozhenie 672-P requires credit institutions to comply with GOST 57580.1 at least at the standard protection level, while card payment processing centers must reach the enhanced level as soon as the standard enters into force, according to Angara Security.
Argentina, fintech and bank liability
In Argentina, a recent ruling found that a bank is not liable for harm suffered by a customer when the disputed transactions took place after the user exposed security credentials under deception, and no failure was proven in the home banking platform or in the institution’s security mechanisms. The court placed primary responsibility on the user who repeatedly entered token passwords and rejected claims against the bank for transactions carried out in that context.
That approach fits with the local regulatory framework. J.F. Cattáneo’s guide on fintech in Argentina identifies the BCRA as a key authority in payments, foreign exchange and certain lending models, with direct compliance and cybersecurity implications for financial institutions and fintechs. The same analysis also points to the CNV, the UIF, the data protection authority, consumer protection bodies and the tax authority, depending on the business activity.
In the same vein, a comment on a proposed reform of the BCRA’s Organic Charter argues that the central bank should receive explicit powers to regulate and supervise virtual asset service providers and modernize payments with cybersecurity and AML safeguards.
Sources
- Regulación Fintech en Argentina: Guía Legal 2026jfcattorneys.com· J.F. Cattáneo Attorneys
- Más de 50 fintech serían supervisadas por el BCRP, ¿pasarán la prueba de fuego?gestion.pe· Gestión
- Del mandato único a los activos digitales: los 5 cambios que necesita la Carta Orgánica del BCRAcronista.com· El Cronista
- DORA - Digital Operational Resilience Act for the financial sectorbankofgreece.gr· Bank of Greece
- DORA regulation: ICT risk managementspringlex.eu· SpringlexUnverified URL
- Robos y fraudes en el uso de tarjetas e instrumentos financierosbcn.cl· Biblioteca del Congreso Nacional de Chile
- Guía de ciberseguridad (Ley 21.663 y 21.719)preyproject.com· Prey Project
- BCRA — Comunicacionesalmanac.ar· Almanac.ar
- Regulation fintech in Argentinacattaneolaw.com· J.F. Cattáneo AttorneysUnverified URL
- Polozhenie 672-P and GOST 57580.1angarasecurity.com· Angara SecurityUnverified URL
- Ciberseguridad de los organismos del Estado e infraestructura crítica de la informaciónbcn.cl· Biblioteca del Congreso Nacional de Chile
- Cómo cumplir con la Ley de Protección de Datos en Chilepreyproject.com· Prey ProjectUnverified URL
- Reforma Carta Orgánica BCRA, VASP, ciberseguridad y AMLcronista.com· El Cronista
- DORA guidancebankofgreece.gr· Bank of GreeceUnverified URL
- Соответствие новым требованиям ЦБ РФ в области информационной безопасности для финансовых организацийangarasecurity.ru· Angara Security
- Fallos Negligencia del usuario: El banco no es responsable del daño sufrido por el cliente a causa de operaciones que no se produjeron por una falla en el funcionamiento del sistema bancarioaldiaargentina.microjuris.com· Microjuris Argentina
- SBS Perú: 24 horas para reportar incidentes de ciberseguridadecosistemastartup.com· Ecosistema Startup
- Art. 6 ICT risk management framework | DORA regulationspringlex.eu· Springlex
- Delitos informáticosbcn.cl· Biblioteca del Congreso Nacional de Chile



