CiberLATAMbywhalemate

Parlacen backs regional cybercrime law

Parlacen presented a regional cybercrime framework in Panama for SICA countries, with a focus on fraud.

Whalemate Labs · AI-assisted researchPublished:3 min read

The Central American Parliament presented in Panama a regional framework law against cybercrime for SICA member states. The text seeks to harmonize rules and strengthen cooperation against electronic fraud, cyberbullying and child exploitation, while Mexico, Chile, Paraguay and other countries move ahead or stall on their own bills.

The Central American Parliament presented in Panama a regional framework law against cybercrime for SICA member states. The proposal seeks to harmonize rules and strengthen cooperation against digital offenses such as electronic fraud, cyberbullying and child exploitation. It was also circulated as a nonbinding reference that each state would adapt to its own legal system.

What is Parlacen proposing?

The initiative was drafted by the Parlacen Committee on Security and Justice with support from experts from SICA countries. According to the institution’s statement, the framework law is meant as a tool for parliamentary work across the eight member states, with the goal of building, updating or changing specialized rules for prevention and protection against cybercrime.

TVN Noticias Panama reported that the proposal was presented during a permanent session in Panama, while Infobae said the document is aimed at aligning legal frameworks across the region. In both cases, the focus is on coordinating legal responses to conduct that now crosses borders with ease.

How is the rest of the region moving?

Mexico, Chile and Paraguay are moving at three different speeds. In Mexico, the Federal Cybersecurity Law initiative was introduced in the Senate on April 30, 2025 by Luis Donaldo Colosio Riojas and Lucía Trasviña Waldenrath, but as of August 2026 it remains in committee and no federal law has yet been published in the Official Gazette of the Federation.

That Mexican bill includes 64 articles, the creation of a National Cybersecurity Agency, a Registry of Critical Information Infrastructure, and a requirement to appoint a formal cybersecurity officer in the organizations covered. Intercompras added, based on estimates mentioned by private-sector actors, that it could be published in the second half of 2026, although that forecast has not been officially confirmed.

In Paraguay, the bill called "Que crea la Ley de Ciberseguridad de la República del Paraguay", Exp. D-2585561, has drawn criticism for its breadth. ABC Color said the text lacks a clear definition of critical infrastructure and mixes cybersecurity, cyberdefense and criminal prosecution functions. La Tribuna added that the draft introduces references to multidomain operations and regulates social media under a territoriality-based criterion, while comments on social media noted the inclusion of concepts such as artificial intelligence and nanotechnology.

What is happening with the data law in Chile?

Chile is considering delaying by one year the entry into force of its Personal Data Protection Law, approved by Congress in August 2024 and published as Law No. 21,719 on December 13, 2024. According to Diario y Radio Universidad de Chile, the government wants the future agency to begin operating on December 1, 2026 and the law to take effect on December 1, 2027, if the delay is approved.

The debate stems from the fact that the agency has still not been set up, due to a lack of agreement in the Senate on its board members, according to coverage by ADN Radio, Biobío and El Mostrador. At the same time, AGPD warned that a long delay could prolong legal uncertainty for data subjects and companies, and its president, Marcelo Drago, said on Cooperativa that the postponement should be no more than six months.

There are also practical readings on the timeline. OneTrust noted that the law includes a two-year transition period and that full compliance was scheduled for December 1, 2026, while an analysis aimed at SaaS companies in Latin America said that period ends on November 30, 2026. Publimetro added that, even with a possible delay, data governance, processing records and incident response obligations will remain demanding for companies and public services.

What is happening in countries without a comprehensive law?

Colombia, Peru, Bolivia and Ecuador present different scenarios, but none of them currently has a comprehensive cybersecurity bill comparable to the one Parlacen is promoting. In Colombia, specialized press reports say the country still relies on Law 1273 of 2009, Decree 338 of 2022 and the 2025 to 2027 National Cybersecurity Strategy, although there are partial initiatives to update cybercrime offenses and strengthen sanctioning capacity in data protection.

In Peru, El Peruano said the National Digital Security and Trust Strategy identifies the need for a future General Cybersecurity Law to define responsibilities for public entities and operators of essential services, but it does not detail any specific bill currently moving through the process. In Bolivia, press reviews and academic analysis point to reforms of the Penal Code and the Code of Criminal Procedure to add cyber offenses, without a standalone cybersecurity or critical infrastructure protection bill under parliamentary discussion.

Ecuador is in a different position. There, the General Regulation to the Organic Personal Data Protection Law, issued through Executive Decree No. 904, is already in force as a complementary rule for the practical application of the data framework.

What other data bill is being prepared in Africa?

Mozambique said it is preparing to submit a personal data protection bill to parliament. Authorities presented it as an opportunity to strengthen citizen rights and set clearer rules for public and private entities in their handling of personal information, with regulatory implications for companies with a regional presence, including those operating in Latin America.

Sources

View all