CiberLATAMbywhalemate

Guatemala, Uruguay and Chile tighten cyber rules

Guatemala is defining cybercrime offenses, Uruguay now requires annual state reports, and Chile adds incident reporting

Whalemate Labs · AI-assisted researchJul 17, 20262 min read

Guatemala moved to define cybercrime offenses during debate on the National Port System Law. At the same time, Uruguay and Chile advanced their regulatory frameworks with new reporting duties for public bodies and essential operators.

Guatemala defines cyber offenses in port law debate

Guatemala's Congressional Economy Commission moved forward with defining cybercrime offenses during debate on the National Port System Law. According to Infobae's coverage, the legislative work included conduct such as unlawful access to computer systems or data, unlawful interception of data, attacks on the integrity of data and systems, computer forgery, computer fraud, misuse of devices, and child pornography.

The report also makes clear that this approach is taking shape within the port law debate, and that final approval of a specific cybercrime penal code has not yet been determined. For now, the reference is to progress in defining conduct within that legislative process.

Uruguay requires annual reports from each agency

In Uruguay, the new Rendición de Cuentas includes cybersecurity changes that require each state agency to prepare an annual report on its security posture and send it to AGESIC. The text uses Uruguay's Cybersecurity Framework as a reference, according to El Observador's coverage.

The publication also details that each state agency must conduct its own cybersecurity review once a year, present the report to its top authority by March 1, and then send it to AGESIC within 60 days. The measure adds a formal routine of review and reporting for Uruguay's public sector.

Chile formalizes reporting and sanctions

The BCN's Ley Fácil guide describes a cybersecurity law that sets out the institutional framework, principles, and general rules to structure, regulate, and coordinate cybersecurity actions by state agencies and by entities that provide essential services or are operators of vital importance.

That law requires public and private institutions covered by the rule to report cyberattacks and cybersecurity incidents that could have significant effects to the National CSIRT, within the time limits established by the law itself. It also creates a tiered sanctions regime, with minor, major, and very serious violations.

The BCN adds that fines can reach up to 20,000 UTM, or up to 40,000 UTM in the case of operators of vital importance. Taken together, the changes in Guatemala, Uruguay, and Chile point to more specific obligations around reporting, incident classification, and the definition of conduct with direct impact on public agencies and essential sectors.

Sources

View all