2022-12-30
Added · Updated
The Superintendency of Financial Services replaces Articles 30.1.1, 30.1.2, and 30.1.4 of the Compilation of Pension Fund Control Regulations to impose stricter requirements on the outsourcing of services and data processing. Administrators must obtain express authorization for services provided by third parties located abroad or from abroad, and domestic outsourcing requires contracts containing specific clauses on confidentiality, audit rights, and continuity. The resolution also updates Articles 144.1, 144.3, and 144.6 to mandate robust data safeguarding procedures, including daily backups, off-site storage, and annual integrity tests, while defining senior personnel responsible for these operations.
Montevideo, December 30, 2022 Ref: COMPILATION OF PENSION FUND CONTROL REGULATIONS - Modifications Regarding Data Safeguarding and Outsourcing
The market is informed that the Superintendency of Financial Services adopted the following resolution on December 27, 2022:
ARTICLE 30.1.1 (AUTHORIZATION OF OUTSOURCING). The authorization referred to in Article 30.1 may be granted expressly or tacitly according to the following provisions:
The authorization request must be accompanied by the text of the service contract to be signed and a report stating the evaluation of risks associated with the outsourcing, including the assessment of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to legal risks to which the information subject to secrecy is exposed, in accordance with Uruguayan legislation. The contract must comply with the requirements referred to in item 1) of Art. 30.1.2. Once the authorization is granted, the aforementioned report must be kept in the offices of the institution at the disposal of the Superintendency of Financial Services and updated periodically based on the results of the risk assessment carried out regarding the outsourcing.
The authorization will refer only to the specific service that is the subject of the request and will be made without prejudice to the registrations of databases and authorizations for international transfer of personal data that may correspond before the Regulatory and Control Unit of Personal Data of the Agency for Electronic Government and Information and Knowledge Society.
Any subsequent change to the scope or conditions on the basis of which the original authorization was granted must be the subject of a new request.
The granted authorization may be revoked if deviations from the indicated are observed, without prejudice to other sanctions that may be applied to the institution for non-compliance with the instructions issued by the Superintendency of Financial Services.
The costs incurred by the Superintendency of Financial Services for supervision activities abroad of outsourced services will be charged to the supervised institution.
The Superintendency of Financial Services may provide that certain services will not require express authorization for their contracting, establishing the conditions for such contracting to be considered authorized.
Those outsourcings carried out with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity will only need to comply with what is stipulated in item 1) letter e) of the aforementioned article to be considered authorized.
For the purposes of outsourcings that imply data processing, the provisions of Articles 30.1.3 and 30.1.4 will also apply.
The contracting of promoters will be governed by what is stipulated in Article 11.
The Superintendency of Financial Services may establish that certain services will not require authorization for their contracting.
ARTICLE 30.1.2 (OUTSOURCING OF SERVICES PROVIDED IN THE COUNTRY BY THIRD PARTIES LOCATED IN IT).
The outsourcing of services provided in the country by third parties located in it will be considered authorized when they meet the requirements established below:
a) Identification of the contracting parties, their representatives, and legal domiciles.
b) Object of the contract, indicating the services to be outsourced in detail, their scope, and the minimum service levels and conditions established by the contracting institution.
When the contracted services imply data processing, the location from which said processing, its maintenance, and backups are provided must be identified.
c) Responsibility of the institution for the services provided by the contracted third party.
d) Commitments regarding confidentiality and data protection.
When the contracted services imply data processing, the obligation of the service provider –upon termination of the contract– to transfer or offer tools that allow the transfer of data to whom the supervised institution disposes and its elimination once the availability and integrity of these are confirmed at the destination must be incorporated.
e) Right to carry out audits or periodic evaluations, without any restriction whatsoever, by the Superintendency of Financial Services and the contracting institution, either directly or through independent audits.
For these purposes, unrestricted access to data and all documentation and technical information related to the services provided must be provided. Such unrestricted access must also be provided –if applicable– to the person responsible for the intervention, resolution, or liquidation process.
f) Procedures to obtain the necessary information so that the service can continue to be provided in any situation that might affect the third party and prevent it from continuing to fulfill the contracted service.
The obligation of the provider to inform the supervised institution about any event that could significantly affect the provision of the service must be included.
g) Obligation of the provider –as long as the substantive obligations of the supervised institution are still exercised according to the contract, including payment obligations– to continue providing the service when the institution is in the process of intervention, resolution, or liquidation.
h) Grounds for termination, among which the instruction to cease the provision of services through the outsourced company by the Superintendency of Financial Services must be included.
The requirements detailed in letters b), d), e), f), and g) will also be enforceable for contracts with subcontracting companies by the outsourced company, if any.
If deemed necessary, the Superintendency of Financial Services may require modifications to both the contracts with the outsourced company and those with subcontracting companies.
a) The contracts celebrated with the company in which the services were outsourced, as well as copies of the contracts corresponding to subcontracting, if any.
b) Report stating the evaluation of risks associated with the outsourcing, including the assessment of the financial and technical solvency of the contracted third party and subcontractors if any, as well as aspects related to legal risks to which the information subject to secrecy is exposed.
The aforementioned report must be updated periodically based on the results of the risk assessment carried out regarding the outsourcing.
VALIDITY: The modifications stipulated will govern contracts signed from the effective date of this resolution. For existing contracts, it is admitted that said modifications be made when they are renewed.
ARTICLE 30.1.4 (ADDITIONAL REQUIREMENTS FOR DATA PROCESSING IN OR FROM OUTSIDE THE COUNTRY).
When data processing is provided by a third party located abroad or in the country but the service is provided wholly or partially in or from abroad, pension savings fund administrators must evaluate the existing legal and regulatory requirements in the host jurisdiction as well as potential political, economic, and social conditions or other events that could conspire against the provider's ability to satisfactorily fulfill the agreed obligations.
These aspects must be verified both at the time of the initial selection of the provider and at the time of any contract renewals.
The third party must have an operational mode and equipment such that online access to all information from the terminals installed in the supervised company is possible at all times.
Regarding the safeguarding of information abroad, one of the copies referred to in Article 144.3 must be physically located in Uruguay and remain accessible to the officials of the Superintendency of Financial Services within a time frame not greater than that fixed by the aforementioned Superintendency based on the location of the processing.
It will be admitted that a copy is not located in Uruguay when institutions implement and make available a physical space with the necessary technological infrastructure to allow total, continuous, and permanent access and control of all data processed outside the country, as well as its backups and the keys necessary for its access and eventual decryption. This unified access point must be located in the country, in the headquarters or some dependency of the institution, and concentrate all accesses, regardless of the locations, providers, and nature of the services provided from abroad. Institutions must inform the Superintendency of Financial Services of the location assigned to the point.
At least once a year, formal and duly documented tests of the functioning of the point and of each of the accesses must be carried out.
With respect to the operational continuity plan referred to in Article 144.9, it must be tested with successful results prior to the start of the processing activity and subsequently, at least once a year. The Superintendency of Financial Services may provide that these tests be carried out under its supervision.
ARTICLE 144.1 (ACCESS TO INFORMATION).
The Central Bank of Uruguay will have access to all information and documentation it deems necessary for the fulfillment of its legal duties.
The natural or legal persons that the Central Bank of Uruguay disposes for these purposes are obligated to provide said information in a timely manner, in the form, and with accuracy.
Upon request by the interested party, justified and in writing, the Superintendency of Financial Services may extend the deadline for presenting the information.
The information and documentation referred to in this article must be available at all times for the Central Bank of Uruguay, regardless of the jurisdiction where it is located. Without prejudice to the sanctions that may correspond to the institution in case of non-compliance with such obligation, the members of the Board of Directors, administrative body, or –if applicable– the corporate administrators, will be responsible before the Central Bank of Uruguay for said non-compliance.
ARTICLE 144.3 (SAFEGUARDING OF INFORMATION).
Pension savings fund administrators must implement data and software safeguarding procedures, such that it is possible to reconstruct the information issued to the Central Bank of Uruguay, the accounting records, and each of the transactions that give rise to them –to a degree of detail such that it allows the identification of accounts and transactions in the items of the financial statements–, as well as any other data, including emails, instant messaging, and any other form of electronic messaging, that is considered relevant in the reconstruction of operations for the purposes of the Central Bank of Uruguay or for judicial requirements.
Likewise, they must safeguard the keys that allow the decryption of the data. The storage formats will be stipulated –in each case– by the Superintendency of Financial Services.
The aforementioned procedures must include, at a minimum, a daily backup and must provide for the generation of at least 2 (two) backup copies, one of which must be stored at a reasonable distance from the processing center, in a building different from the same. The data, the keys, and their mentioned copies must not be exposed to the possibility that a single risk event could affect them simultaneously.
Incremental backup will be admitted, that is, a backup that considers only the changes since the last backup performed, provided that the recovery procedures allow the complete restoration of the information for any day.
Likewise, they must have procedures that allow the recovery of all backed-up information.
At least once a year, formal and duly documented tests of recovery and integrity of data backups must be carried out, which must ensure the administrator's capacity to recover all safeguarded information.
ARTICLE 144.6 (RESPONSIBLE FOR THE SAFEGUARDING OF DATA, SOFTWARE, AND DOCUMENTATION).
Pension savings fund administrators must appoint a person responsible for the execution of data, software, and documentation safeguarding procedures. In particular, they will be responsible for the safeguarding of keys for data access and decryption, as well as for ensuring that the administrator has a procedure for said access and decryption that does not involve requiring authorizations or actions from personnel not under the dependency of the supervised institution. When the institution chooses to establish a unified access point, they will also be responsible for determining the physical space where it will be located, its implementation, and testing. This official will be included in the category of senior personnel referred to in Article 149.1.
ARTICLE 149.1 (SENIOR PERSONNEL - DEFINITION).
Senior personnel is considered for the purposes of the provisions of this Compilation to:
a. Persons who hold positions as directors, trustees, or are part of Fiscal Commissions, Audit Committees, or other commissions delegated by the Board of Directors, as well as attorneys-in-fact or legal representatives of the company.
b. Persons who hold the positions or perform the functions of general manager, deputy general manager, managers, internal auditor, general accountant, compliance officer, information regime responsible, data, software, and documentation safeguarding responsible, and claims attention function responsible.
c. Persons who, holding positions or maintaining a permanent relationship with the institutions, advise the directing body.
JUAN PEDRO CANTERA Superintendent of Financial Services 2022-50-1-02450
More like this from BCU
We email you every new BCU publication the day it's published.