2022-12-30

Added · Updated

Compilation of Insurance and Reinsurance Rules - Modifications Regarding Data Safeguarding and Outsourcing

The Superintendence of Financial Services replaces Articles 16.1.1, 16.1.2, and 16.3 of the Insurance and Reinsurance Rules to update outsourcing authorization requirements, mandating express authorization for services provided from abroad and specifying contract clauses for domestic outsourcing. The resolution also amends Articles 120.1, 120.3, and 120.6 to strengthen data safeguarding obligations, requiring daily backups, off-site storage, annual integrity tests, and the designation of a senior data safeguarding officer. Additionally, Article 145.2 is updated to explicitly include the data safeguarding officer in the definition of senior personnel. These modifications apply to contracts signed after the resolution's effective date, with existing contracts required to comply upon renewal.

Banco Central del Uruguay logo

Uruguay

Banco Central del Uruguay

Click to view thumbnail

1 Montevideo, December 30, 2022 Ref: COMPILATION OF INSURANCE AND REINSURANCE RULES - Modifications Regarding Data Safeguarding and Outsourcing

The market is informed that the Superintendence of Financial Services adopted the following resolution on December 27, 2022:

  1. SUBSTITUTE in Chapter VI BIS – Outsourcing of Services, of Title I – Insurance and Reinsurance Companies, of Book I – Authorizations and Registrations, of the Compilation of Insurance and Reinsurance Rules, Articles 16.1.1, 16.1.2, and 16.3 with the following:

ARTICLE 16.1.1 (OUTSOURCING AUTHORIZATION). The authorization referred to in Article 16.1 may be granted expressly or tacitly according to the following provisions:

  1. When the services are provided by third parties located outside the country, express authorization from the Superintendence of Financial Services must be requested. Express authorization must also be requested when the third parties are located in the country but the services are provided wholly or partially from or in the exterior.

The authorization request must be accompanied by the text of the service contract to be signed and a report stating the assessment of risks associated with the outsourcing, including the valuation of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to legal risks to which the information subject to secrecy is exposed, in accordance with Uruguayan legislation. The contract must comply with the requirements referred to in numeral 1) of Art. 16.1.2. Once the authorization is granted, the aforementioned report must be kept in the offices of the institution at the disposal of the Superintendence of Financial Services and updated periodically based on the result of the risk assessment performed regarding the outsourcing.

Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy CIRCULAR N°2422

2 The authorization refers only to the specific service that is the object of the request and is made without prejudice to the registrations of databases and authorizations for international transfer of personal data that may correspond before the Regulatory and Control Unit of Personal Data of the Agency for Electronic Government and Information and Knowledge Society.

Any subsequent change to the scope or conditions on the basis of which the original authorization was granted must be the subject of a new request.

The granted authorization may be revoked if deviations from the indicated are observed, without prejudice to other sanctions that may be applied to the institution for non-compliance with the instructions issued by the Superintendence of Financial Services.

The costs incurred by the Superintendence of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution.

The Superintendence of Financial Services may provide that certain services will not require express authorization for their contracting, establishing the conditions for such contracting to be considered authorized.

  1. When the services are provided in the country by third parties located in it, their contracting will be considered authorized provided that the requirements referred to in Article 16.1.2 are met.

Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity will only need to comply with what is provided in numeral 1) literal e) of the aforementioned article to be considered authorized.

For the purposes of outsourcings that imply data processing, the provisions of Articles 16.2 and 16.3 will also apply.

The authorization for the use of third-party services to carry out due diligence procedures will be governed by what is provided in Article 79.

The Superintendence of Financial Services may establish that certain services will not require authorization for their contracting.

Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy

3 ARTICLE 16.1.2 (OUTSOURCING OF SERVICES PROVIDED IN THE COUNTRY BY THIRD PARTIES LOCATED IN IT).

Outsourcings of services provided in the country by third parties located in it will be considered authorized when they comply with the requirements established below:

  1. The outsourced services must be detailed in a contract between the parties that must contain, at a minimum, the following clauses:

a) Identification of the contracting parties, their representatives, and legal domiciles.

b) Object of the contract, indicating the services to be outsourced in detail, their scope, and the minimum service levels established by the contracting institution.

When the contracted services imply data processing, the location from which such processing is provided, its maintenance, and backups must be identified.

c) Responsibility of the institution for the services provided by the contracted third party.

d) Commitments regarding confidentiality and data protection.

When the contracted services imply data processing, the obligation of the service provider –upon contract termination– to transfer or offer tools that allow the transfer of data to whom the supervised institution disposes and its elimination once the availability and integrity of these are confirmed at the destination must be incorporated.

e) Right to perform audits or periodic evaluations, without any restriction whatsoever, by the Superintendence of Financial Services and the contracting institution, either directly or through independent audits.

For these purposes, unrestricted access to data and all documentation and technical information related to the services provided must be provided. Such unrestricted access must also be provided –if applicable– to the person responsible for the intervention, resolution, or liquidation process.

f) Procedures to obtain the necessary information so that the service can continue to be provided in any situation that the third party might suffer that prevents it from continuing to comply with the contracted service.

Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy

4 The obligation of the provider to inform the supervised institution about any event that could significantly affect the provision of the service must be included.

g) Obligation of the provider –as long as the substantive obligations of the supervised institution are still exercised according to the contract, including payment obligations– to continue providing the service when the institution is in the process of intervention, resolution, or liquidation.

h) Grounds for rescission, among which the instruction to cease the provision of services through the third-party company by the Superintendence of Financial Services must be included.

The requirements detailed in literals b), d), e), f), and g) will also be enforceable for contracts with subcontracting companies by the third-party company, if any.

If deemed necessary, the Superintendence of Financial Services may require modifications to both the contracts with the third-party company and regarding contracts with subcontracting companies.

  1. Institutions must keep in their offices at the disposal of the Superintendence of Financial Services:

a) The contracts entered into with the company in which the services were outsourced, as well as copies of the contracts corresponding to subcontracting, if any.

b) Report stating the assessment of risks associated with the outsourcing, including the valuation of the financial and technical solvency of the contracted third party and subcontractors if any, as well as aspects related to legal risks to which the information subject to secrecy is exposed.

The aforementioned report must be updated periodically based on the result of the risk assessment performed regarding the outsourcing.

VALIDITY: The modifications established will govern for contracts signed from the effective date of this resolution. For existing contracts, it is admitted that the aforementioned modifications be made when they are renewed.

Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy

5 ARTICLE 16.3 (ADDITIONAL REQUIREMENTS FOR DATA PROCESSING IN OR FROM OUTSIDE THE COUNTRY).

When data processing is provided by a third party located abroad or in the country but the service is provided wholly or partially from or in the exterior, insurance and reinsurance companies must, additionally, pay particular attention to the existing legal and regulatory requirements in the host jurisdiction as well as potential political, economic, and social conditions or other events that could conspire against the provider's ability to satisfactorily fulfill the agreed obligations.

These aspects must be verified both at the time of the initial selection of the provider and at the time of any contract renewals.

The third party must have an operational mode and equipment such that online access to all information from terminals installed in the supervised company is possible at all times.

Regarding the safeguarding of information abroad, one of the copies referred to in Article 120.3 must be physically located in Uruguay and remain accessible to officials of the Superintendence of Financial Services within a timeframe not greater than that fixed by the aforementioned Superintendence based on the location of the processing.

It is admitted that a copy is not located in Uruguay when institutions implement and make available a physical space with the necessary technological infrastructure to allow total, continuous, and permanent access and control of all data processed outside the country, as well as its backups and the keys necessary for its access and eventual decryption. This unified access point must be located in the country, in the headquarters or some dependency of the institution and concentrate all accesses, regardless of locations, providers, and nature of services provided from abroad. Institutions must inform the Superintendence of Financial Services of the location assigned to the point.

At least once a year, formal and duly documented tests of the functioning of the point and of each of the accesses must be performed.

Regarding the operational continuity plan referred to in Article 120.9, it must be tested with successful results prior to the start of the processing activity and subsequently, at least once a year. The

Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy

6 Superintendence of Financial Services may provide that these tests be performed under its supervision.

  1. SUBSTITUTE in Section I – Information and Documentation – Conditions and Forms of Safeguarding, of Chapter II – Information and Documentation, of Title I – Registrations, Documentation, and Conservation of Information, of Book VI – Information and Documentation, of the Compilation of Insurance and Reinsurance Rules, Articles 120.1, 120.3, and 120.6 with the following:

ARTICLE 120.1 (ACCESS TO INFORMATION).

The Central Bank of Uruguay will have access to all information and documentation it deems necessary for the fulfillment of its legal duties.

Natural or legal persons that the Central Bank of Uruguay disposes for these purposes are obligated to provide such information in a timely manner, in the form, and with accuracy.

Upon request by the interested party, substantiated and in writing, the Superintendence of Financial Services may extend the deadline for the presentation of information.

The information and documentation referred to in this article must be available at all times for the Central Bank of Uruguay, regardless of the jurisdiction where it is located. Without prejudice to the sanctions that may correspond to the institution in case of non-compliance with such obligation, the members of the Board of Directors, administrative body, or –if applicable– the social administrators, will be responsible before the Central Bank of Uruguay for such non-compliance.

ARTICLE 120.3 (SAFEGUARDING OF INFORMATION).

Insurance and reinsurance companies must implement data and software safeguarding procedures, such that it is possible to reconstruct the information issued to the Central Bank of Uruguay, the accounting records, and each of the movements that give rise to them –to a degree of detail such that it allows the identification of accounts and movements in the items of the financial statements–, as well as any other data, including emails, instant messaging, and any other form of electronic messaging, that is considered relevant in the reconstruction of operations for the purposes of the Central Bank of Uruguay or for judicial requirements.

Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy

7 Likewise, they must safeguard the keys that allow the decryption of data. The storage formats will be disposed –in each case– by the Superintendence of Financial Services.

The aforementioned procedures must include, at a minimum, a daily backup and must provide for the generation of, at least, 2 (two) backup copies, one of which must be stored at a reasonable distance from the processing center, in a building different from the same. The data, the keys, and their mentioned copies must not be exposed to the possibility that a single risk event is capable of affecting them simultaneously.

Incremental backup is admitted, that is, a backup that contemplates only the changes since the last backup performed always that the recovery procedures allow the complete restoration of information for any day.

Likewise, they must have procedures that allow the recovery of all backed-up information.

At least once a year, formal and duly documented tests of recovery and integrity of data backups must be performed, which must ensure the capacity of insurance and reinsurance companies to recover all backed-up information.

ARTICLE 120.6 (RESPONSIBLE FOR THE SAFEGUARDING OF DATA, SOFTWARE, AND DOCUMENTATION).

Insurance and reinsurance companies must appoint a responsible person for the execution of data, software, and documentation safeguarding procedures. In particular, the responsible person will be responsible for the safeguarding of keys for data access and decryption, as well as for ensuring that insurance and reinsurance companies have a procedure for such access and decryption that does not involve requiring authorizations or actions from personnel not under the dependency of the supervised company. When the institution opts to establish a unified access point, the responsible person will also be responsible for determining the physical space where it will be located, its implementation, and testing. This official will be included in the category of senior personnel referred to in Article 145.2.

  1. SUBSTITUTE in Chapter IV – Senior Personnel and Shareholders, of Title II – Information Regime, of Book VI – Information and Documentation, of the Compilation of Insurance and Reinsurance Rules, Article 145.2 with the following:

Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy

8 ARTICLE 145.2 (SENIOR PERSONNEL - DEFINITION).

Senior personnel is considered for the purposes of the provisions of this Compilation to:

a. Persons who hold positions of directors, trustees, or are part of Fiscal Commissions, Audit Committees, or other commissions delegated by the Board of Directors, as well as attorneys-in-fact or legal representatives of the company.

b. Persons who hold the positions or perform the functions of general manager, deputy general manager, managers, internal auditor, chief accountant, compliance officer, information regime responsible, data safeguarding responsible, software and documentation responsible, and claims handling function responsible.

c. Persons who, holding positions or maintaining a permanent relationship with the institutions, advise the directing body.

JUAN PEDRO CANTERA Superintendent of Financial Services 2022-50-1-02450

Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy

More like this from BCU

We email you every new BCU publication the day it's published.

Share