2023-09-26 | Resolução BCB 342Added
The resolution mandates Pix participants to notify natural person account holders of security incidents involving personal data related to Pix components or infrastructure, regardless of whether the participant is responsible for the incident or if the risk is deemed low. It updates the Pix Penalty Manual to define specific infractions for failing to meet technical security requirements or to notify incidents, establishing penalty criteria based on the type of institution, the participant's share of SPI transactions, and the percentage of compromised Pix keys. Weighting factors for fine calculations are set in three tables, assigning multipliers ranging from 0.5 to 25 depending on institutional classification and the scale of the security breach.
BCB published 15 documents in the last 30 days — get each new one by email the day it lands.
BCB Resolution No. 342, OF SEPTEMBER 26, 2023
Amends the Regulation annexed to BCB Resolution No. 1, of August 12, 2020, which governs the operation of the Pix payment arrangement, to provide for the notification to holders of the occurrence of a security incident involving personal data, and amends Annexes I and II to BCB Resolution No. 177, of December 22, 2021 (Pix Penalty Manual), to provide for non-compliance with Pix technical security requirements and for the criteria for applying penalties.
Read the rest free, and get an email when BCB publishes again
Source: Banco Central do Brasil — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BCB
BCB published 15 documents in the last 30 days. We email you each new one the day it's published.