2026-09-14
Added
This regulation modifies General Standard No. 540 and its Information System Manual to establish operational norms for the Consolidated Debt Registry (REDEC), specifically introducing strict requirements for debtor consent management. It mandates that reporting entities notify debtors upon consent granting, maintain encrypted consent records in their Consent Management System, and allow debtors to revoke third-party authorizations before expiration. The amendments also define specific access timelines of 15 banking days, establish detailed operational incident reporting procedures within 30 minutes, and clarify the responsibilities of reporting entities and their mandated agents regarding data security and privacy.
CMF published 8 documents in the last 30 days — get each new one by email the day it lands.
REF: Introduce modifications to GS
No. 540 containing the Operational
Functioning Norms of the
Consolidated Debt Registry and to its Information System Manual, and create the REDEC Technical
Annex Document.
September 14, 2026
General Standard No. 576
This Commission, in exercise of the powers conferred by Law No. 21.680 which creates a Consolidated Debt Registry (REDEC), particularly in the second paragraph of Article 3; and in accordance with what was agreed upon by its Council in Ordinary Session No. 513 of September 10, 2026, executed via Exempt Resolution No. 9,967 of September 11, 2026, has resolved to modify the General Standard (GS) No. 540, its Information System Manual (REDEC ISM) and introduce the REDEC Technical Annex Document, where the Operational Functioning Norms of the REDEC are established. The agreed adjustments introduce guidelines of various kinds for reporters regarding the management of debtor consent for access to their REDEC information, both with respect to the debtor and with respect to the Commission. The foregoing, with the objective of promoting best practices in the obtaining, recording, reporting and accountability of debtor consent and thus ensuring its protection as the holder of the data. Regarding this, among the main modifications stand out the incorporation of the requirements for a notification to the debtor at the moment of granting their consent and the encrypted coding of the consent file, which the reporter must maintain in their Consent Management System. Another relevant adjustment is the enshrinement of the debtor's right to revoke authorizations to third parties, a figure created by Law No. 21.680, before the end of their validity. In concordance with the foregoing, in addition to other formal adjustments, changes are made to the provisions of GS No. 540 and the REDEC ISM.
I. MODIFICATIONS IN GS No. 540
The modifications listed in the following paragraphs are introduced, in addition to other formal adjustments:
i) The definition of Audit, contained in paragraph 1, is replaced by the following:
“Audit: Review, evaluation and/or verification of compliance with the compliance of the applicable legal and regulatory provisions for the REDEC, the effectiveness of the governance, control and risk management framework, the adequate operation of information systems and the consistent application of the policies, procedures and processes established.” ii) The definition of Cybersecurity in paragraph 1 is modified, remaining as follows:
“Cybersecurity: Comprises the set of actions destined for the protection of information present in cyberspace and of the infrastructure that supports it, which has as its object the preservation of its confidentiality, integrity and availability by a reporting entity.” iii) The term “express approval” at the beginning of the definition of Consent in paragraph 1 is replaced by “Manifestation of express will” and the phrase “with the sole purpose of evaluating its commercial, credit risk and risk management for specific operations” is intercalated between “to its debt information in the REDEC” and “in accordance with the provisions established in paragraph 7”. iv) The word “especially” is added after “juridical” and at the end of the definition of Mandataries the following: “under the terms of Article 6 of Law No. 21.680”. v) The definition in paragraph 1 for Operational Incident Reporting is replaced by the following:
“Operational Incident Reporting: Communication of an obligatory nature that reporters must make to the Commission, through the system enabled for these purposes, regarding operational incidents pertinent, in matters of security and privacy of the REDEC information, under the terms and within the time limit established in paragraph 6 of this standard.” vi) The definition of Query Service in paragraph 1 is modified in the following terms:
“Query Service: API provided by the Commission so that reporters, directly or through mandataries acting on their behalf, consult the REDEC information subject to consent.” vii) The title of paragraph 2 is changed to “On the Consolidated Debt Registry and its Information System Manual”. viii) The following sub-paragraphs are introduced in paragraphs 3.1 and 3.2 to improve the structure of the indications: “3.1.1. Types of reporters”, “3.1.2. Reporter’s Rights”, “3.1.3. Reporter’s Duties”, “3.2.1. Debtors’ Rights”, “3.2.2. Debtors’ Best Practices”, prior to the paragraphs that describe such content. ix) It is added in letter f) of paragraph 3.1.1. in the second paragraph: “without prejudice to the particular norms applicable to each type of reporter.” x) The terms “had” and “as well as” are replaced by “should have” and “and consequently, they also lose them”, respectively, in the last paragraph of paragraph 3.1.1. xi) The term “the following” is added at the end of the first paragraph of the new paragraph 3.1.2 Reporter’s Rights. xii) The term “grants or maintains” is replaced by “grants and maintains” in the point Access to information in paragraph 3.1.2 in its last sentence. xiii) The point Delegate the exercise of rights and specific operational activities of paragraph 3.1.2 is replaced by the following:
“Delegate the exercise of rights and specific operational activities: the reporter may delegate reporting activities to the REDEC, access to the REDEC and commercial risk evaluation using REDEC information to a natural or legal person who legally represents them in those tasks established in the mandate. For the purposes of this standard, such entity or person is called a mandatory. Mandataries, when acting on behalf of the reporter, may exercise the rights of the previous paragraph within the framework of the REDEC, in strict observance of the obligations that this same imposes, particularly the confidentiality of the information consulted. Reporters must inform the CMF of the authorized mandataries under the terms and channels that this Body makes available. In any case, mandataries cannot subdelegate their functions to third parties. Likewise, their mandates may be revoked by the reporters, who must immediately inform the Commission. Non-compliance with the duties in the management of the REDEC by the mandatory is imputable to the reporter, who is always considered as responsible for the purposes of this standard. By natural consequence, the mandatories must adhere to the same standards and requirements to which their principals are obligated. The terms established in this reporter’s right must be recorded in a mandate contract or similar instrument between the mandatory and the reporter.”. xiv) In the point on the duty of Rectification of information indicated in paragraph 3.1.3 the word “detect it” is introduced after the term “incomplete or incorrect after”. xv) In the point on the duty of Consent Management indicated in paragraph 3.1.3 the word “received” is eliminated. xvi) In the point on the duty of Management of requests in paragraph 3.1.3 the term “access” is replaced by “update”. xvii) It is added at the end of the point Delegation of the exercise of certain rights in paragraph 3.2.1 the following: “Likewise, debtors may revoke the authorization to third parties in accordance with what is indicated for this effect in paragraph 5.2 of this standard”. xviii) The third paragraph of paragraph 5 is replaced by the following: “Accesses to information that have a justification of lawfulness are exempt from consent, under the terms of Title III of Law 19.628 which authorizes credit entities to report credit obligations up to date or in default to the Commercial Bulletin.”. xix) The paragraphs “5.1. Notification to the debtor and management of accesses”, “5.2. Security in access” and “5.3. Time limit to access information” are added in paragraph 5 On access to information, prior to the paragraphs that describe such content. xx) The paragraphs of the new paragraph 5.1 are replaced by the following:
“When accessing individual information subject to consent, and to the extent that the debtor has previously registered on the platform provided for this purpose, the Commission will notify them electronically, indicating the name of the reporting entity that has accessed their information, whether directly or through a mandatory, the date and time. The foregoing will only take place when the Commission observes the first access of a reporter to the REDEC information of a debtor. Complementarily, the Commission will deliver, at least quarterly, to debtors who request it, through the website enabled for this purpose, a report with the reporters who, directly or through a mandatory, have accessed their information subject to consent in the last twelve months (History or Summary of accesses).” xxi) The first paragraph of the new paragraph 5.2 is replaced by the following:
“Access to individual information subject to consent is through the Commission’s Query Service, which provides an Application Programming Interface (API, from its acronym in English), which requires the identification and authentication of reporters and is detailed in API1 of the REDEC Technical Annex. The personnel of the reporting entity, or of its mandataries, who make use of the REDEC information must identify themselves and their accesses must be recorded in electronic records, which will be traceable and available for review by the audit function of the reporters and of the Commission, in case the latter so disposes. Once the information subject to consent has been consulted and the purpose of the consultation fulfilled, the information must be completely eliminated from the information systems of the reporter and/or its mandataries, in accordance with the procedures that the reporter has established for these purposes.” xxii) The last paragraph of the new paragraph 5.2 is replaced by the following:
“Authorized third parties may access the debtor’s personal information.
For this, the debtor must authorize it through a procedure provided in a secure portal enabled by the Commission, under its exclusive responsibility, where they must indicate the full name, RUT and email address of the authorized third party. Once the debtor has confirmed the person to authorize and the terms of their authorization, the authorized third party will be notified by the Commission of such situation, which will give them the right of access to the debtor’s information for a period of up to 15 banking business days, unless the debtor revokes such authorization in the same secure portal enabled by the Commission. Having fulfilled the time limit, the access permit will expire.” xxiii) The new paragraph 5.3 is replaced by the following:
“In accordance with what is mandated by Article 5 of Law No. 21.680, the reporter may access the information subject to consent for a period of 15 banking business days, or, in a shorter period in case the debtor revokes the consent in accordance with what is indicated in paragraph 7 of this standard, in the cases where it applies. The consent must always be obtained with the exclusive purpose of evaluating the commercial, credit risk and risk management for specific operations of the debtor. Likewise, if having been originally granted by the debtor previously, expressly and unequivocally with the purpose of allowing the evaluation of their credit or commercial risk for a specific operation, this is granted, said consent will be understood as extended for the creditor during the entire validity of the obligation or until the execution of the acceleration clause of the reportable obligation, with the exclusive purpose of being able to carry out the risk management of said obligation, including the constitution of provisions and other regulatory requirements, without the need to require a new manifestation of will on the part of the debtor. The time limit contemplated in this section must be counted from the moment of obtaining the consent. In case this time limit expires, the entity cannot access the individual debt information subject to consent, unless it obtains a new consent from the debtor.” xxiv) A sub-numbering is created in paragraph 6 On security and privacy of the information to incorporate paragraphs of such paragraphs into: “6.1 General elements of policy and procedures” and “6.2 Risk management elements”. Within 6.2, sub-paragraphs originating from the beginnings of paragraphs relating to risk management elements are incorporated. xxv) The following new fourth paragraph is incorporated in paragraph 6.1:
“Reporters must also establish within their policies, the processes and controls related to the administration of consents referred to in paragraph 7 of this standard.” xxvi) The title of paragraph 6.2.1 which referred to “Outsourcing through mandataries” is replaced by “Reporter’s responsibility for the action of its mandataries”. xxvii) In the last paragraph of paragraph 6.2.1 the phrase “…, the mandatory must make its own …” is replaced by “… the reporter must require the respective mandatory to make its own…”.xxviii) The term “In turn” is eliminated from paragraph 6.2. xxix) The paragraph “The entity must consider the following procedures adapted to its business model, its volume of operations, the number and type of clients:” of paragraph 6.2.3 is replaced by “The reporting entity must consider in its management the following procedures, adapting them to its business model, its volume of operations, and the number and type of clients:” xxx) The term “and/or captured” is added after the term “downloaded documentation” in the fifth point of paragraph 6.2.3. xxxi) The paragraphs of paragraph 6.2.4 “Operational incident reporting” are replaced by the following:
“Reporters must communicate to the Commission the operational incidents related to the security of information and the normal functioning of the REDEC through an Operational Incident Report (RIO) available in CMF Supervisa. Without prejudice to the reporting obligation indicated, when the Commission deems it appropriate, it may require the entity a report containing an analysis of the causes of the incident, the generation of documentation and reports of the investigation, an analysis of the impact, measures to prevent the incident from recurring, and other additional matters that it deems pertinent. The communication of operational incidents must be made within a period of 30 minutes once the reporter has taken knowledge of the fact. The communication of incidents, for the purposes of this standard, applies when among the affected channels is the REDEC, this without prejudice to the fact that the reporting entity has the obligation to inform this report on events pertinent to other types of current regulation that is applicable. When appropriate, the RIO must be complemented with new communications for the follow-up of the incident indicating: its causes, the actions to be taken and its resolution. The information indicated in this paragraph must be sent by the responsible official that the reporter defines, and whose designation and/or replacement must be communicated to the Commission via CMF Supervisa. The eventual lack of any antecedent referring to the characteristics of the operational incident of this paragraph, in no case must be an impediment for the proper sending of the RIO within the defined time limit. Once the incident is overcome, the reporter must also inform this Commission, indicating at least, the date and time of closure of the incident, the identified causes, the measures adopted and detail of the entities involved (for example, suppliers) and affected (for example, customers). With the aim of guaranteeing that the information is complete and available in the REDEC, reporters must adhere to the provisions on reporter information quality, specified in paragraph 8 of this standard; as well as those referred to audit of procedures defined in its paragraph 10.” xxxii) Paragraph 7 “On Consent Management” is replaced by the following:
“7. On Consent Management
7.1. Consent and its granting
Access to the debtor’s information subject to consent must guarantee an adequate administration of this, in order to guarantee lawful access to the financial information of the REDEC. Reporters must have the prior, express and unequivocal consent of the debtor before accessing and/or using their data subject to REDEC consent. The debtor’s will must be expressed expressly and unequivocally, in the following terms:
a) In the case of a natural person: by the respective debtor or their legal representative who proves sufficient their due representation. b) In the case of a legal person: by the legal representative(s) or attorney-in-fact.
The consent granted by the debtor must be obtained in writing, by verbal means or by electronic means, and, whatever the case, stored on a durable digital medium, which is suitable for safeguarding its security, integrity and access by the reporter, debtor, audit or the Commission, if this so requests. The consent granted must allow verification that it was manifested freely, informed, expressly and specifically as to the type of information required and the purpose. The consent granted must be duly issued by the debtor and it is the responsibility of the reporter take all necessary measures and safeguards to guarantee its authenticity. The person, or computer system that interacts with the debtor, must not exercise any undue influence over them to induce them to manifest their will. For example, the use of interfaces that induce users to make unintentional, involuntary or potentially counterproductive decisions for their interests must be avoided; requiring that consent be granted for the application of a discount or obtaining benefits; or that the options used for it to be granted are marked by default, are with colors, sizes or font styles that highlight them over those options that refer to not granting consent. At the time of requesting consent to access the debtor’s REDEC data, it must be made known to them, clearly, the type of information to which the reporter will access, the purpose of the access, the procedure for evaluating commercial risk, credit risk and risk management for specific operations. The format of the request cannot contain other information or require the debtor’s consent for acts or purposes other than those established in this standard, in addition to remaining available for supervision by this Commission. Likewise, it should be sought that the information that is made known to the debtor to obtain consent is expressed in simple, clear, precise language and avoiding jargon, except in cases where it is strictly necessary, explaining them clearly. In addition, it must have mechanisms that allow people with disabilities to access this information. Consent cannot be used for purposes other than those indicated explicitly in this paragraph, that is, for operations or acts that do not fall within the purpose for which it had to be granted.
7.2. Notification of consent to the debtor
As soon as the consent is obtained, the reporter or a mandatory of this, must send and/or deliver directly to the debtor a record of its granting, which clearly indicates, at least, the date and time, as well as the channel by which it was issued, and the internal code generated for said consent. The reporter must store both the consent granted and the evidence of the sending of the notification in their Consent Management System.
7.3. Preservation of consent
As soon as the consent is obtained, the reporter must assign it a unique code, which will be used for internal management purposes and will be called “internal consent code”.
The consents granted must be stored for at least five years, using mechanisms that safeguard their integrity, authenticity, confidentiality and fidelity over time and that are verifiable, all in accordance with the following principles:
a) Integrity: Quality that allows ensuring that the consent has not been altered or modified since its granting. b) Authenticity: Quality that allows unequivocally identifying the debtor who granted the consent or who has acted on their behalf. c) Fidelity: Quality that allows faithfully verifying the content and the conditions under which the consent was granted. d) Confidentiality: Provision that prevents access or reading of the consent by unauthorized third parties. This includes, when appropriate, the encryption of the information. e) Verifiability: Quality that allows checking with mechanisms technical and/or antecedents provided by the reporter, that the consents obtained meet the conditions of integrity, authenticity, fidelity and confidentiality. Each consent must be stored with its internal code, which must be maintained in a record, so that it can be unequivocally identified.
Regarding consents obtained by written means, a digitized copy must be stored, in accordance with the requirements of this section.
7.4. Revocation of Consent
Debtors may revoke their consent at any time and, at a minimum, through channels and authentication procedures homologous to those through which it was granted. Homologous channels are understood to be those that allow the debtor to revoke consent, at least, through a modality equivalent to that used for granting it, without imposing greater burdens or requirements on them.
The reporting entity must ensure that the revocation process is accessible, clear, and free of unjustified obstacles for the debtor. Likewise, it must generate internal records that support this action, which must be available for consultation by the debtor or the Commission.
As with granting, as soon as consent is revoked, the reporting entity, or its agent, must send and/or directly deliver to the debtor a notification of its revocation, which clearly indicates, at least, the date and time of such act, as well as the channel through which it was revoked.
The support for the revocation and the copy of the notification must be stored in the Reporting Entity's Consent Management System.
Consent extended originating from a current reportable obligation is not subject to revocation.
7.5. Mechanisms for Revocation of Consent
Reporting entities must enable digital and/or in-person channels for the submission of consent revocation requests, which must be homologous to those established for their granting. In the case of in-person requests that are not processed through an electronic medium, these must be resolved within a period not exceeding 1 business day; in the case of electronic requests, they must apply the revocation immediately. Following the revocation of consent, the reporting entity and its agents must cease access and eliminate information from the REDEC regarding the referred debtors immediately, unless the reporting entity is authorized to continue accessing it in accordance with the Law.
7.6. Debtor Consent Management System
Once the debtor has granted consent, reporting entities must individually maintain a consent management system with a debtor access functionality where they can know, verify, and revoke granted consents. The reporting entities' systems must eliminate debtor data when the debtor has revoked consent or lost legality. For this purpose, the consent management system must remain connected online with the REDEC access systems.
Regarding the above, the consent management system must comply with the following characteristics from the debtor's perspective:
7.7. Consent Administration System
Reporting entities must individually implement a digital or document management system that allows storing and managing consents securely, guaranteeing their fidelity, traceability, and ease of consultation.
The system must allow the generation of reports on the validity and status of consents, as well as the history of their administration. The system must comply with, but not be limited to, the following conditions:
7.8. Channel for Sending Digitized Consent Files to the Commission
The requirements for digitized consents will be communicated to reporting entities via API2 indicated in the Technical Annex of this standard, which is mandatory for all reporting entities. Meanwhile, the sending of digitized consent files requested by the Commission will be carried out via API3, indicated in the same technical annex, or through the CMF Supervisa portal.
The foregoing does not limit the Commission's ability to require the sending of documentation or complementary information through any other means. The response times for digitized consent requirements will be recorded in each request.
7.9. Exception to Requirements Associated with Consent Administration
Reporting entities that, based on their business models and/or strategy, decide not to access debtor information subject to consent must inform the Commission annually until August of each year, being exempt from complying with the requirements of sections 7 and 10.1 of this standard for the following period. Consequently, reporting entities that take advantage of the exemption must not use the Query Service, under their own responsibility.
xxxiii) Sections “8.1 Information Quality Tests” and “8.2 Communication of Contingencies and Rectifications” are added to section 8 on Information Quality, prior to the paragraphs referring to their content.
xxxiv) The second point of section 8.1, on “Analysis of Error Origin,” is replaced with the following: “for those cases where differences are detected between debtor information and other entity storage sources or inconsistencies related to regulatory files, the institution must identify their origin. Without prejudice to the foregoing, at any time the Commission may carry out information quality tests, for whose execution entities must make the requested supports available to this Agency, if the periodic information requested through the REDEC MSI Validation and Management System is not sufficient.”
xxxv) The phrase “the Commission, through communication conducted through the supervised attention channels” is replaced with the following “this Agency through the RIO indicated in section 6.2.4 of this standard, and, if applicable, also through CMF Supervisa, considering the following:” at the end of the first paragraph of section 8.2.
xxxvi) The precision of the Rectification Deadline point in section 8.2 is introduced, becoming: “... must be resolved within the period indicated by this in the request to the reporting entity, which will not exceed fifteen banking business days counted from the date of notification of the resolution.”
xxxvii) Sections “9.1 Receiving Channels for Requests,” “9.2 Processing of Requests by the Reporting Entity,” “9.3 Processing of Requests by the Commission,” and “9.4 Non-compliance by the Reporting Entity” are added to section 9 On the Request and Complaint Process, prior to the paragraphs referring to their content.
xxxviii) The first paragraph of section 9.2 is replaced with the following: “The exercise of the rights of update, rectification, completion, or cancellation that debtors associated with the application of the REDEC legal framework have considers the following milestones or stages:”.
xxxix) In the second paragraph of the “Reporting Entity receives the request from the debtor” point in section 9.2, the word “of” is replaced by “described in” and the term “their” is preceded before “requests”.
xl) The following paragraphs are moved, prior to the end of section 9, to the end of section 9.2:
“For adequate management of requests made to reporting entities, these must maintain an updated register of requests that includes at least: date of receipt of the request, case number, description, status, analysis result, resolution date, notification to the debtor, and corrective measures adopted, if any. Requests must have a receipt and/or support identifier for the debtor making it.
This register must remain available for audit and supervision review by the Commission when it so disposes.
Reporting entities must send the Commission a report on the requests received and their status as provided in the REDEC Information System Manual.”
xli) In the point “Debtor appeals to the Commission” in section 9.3, the expression “since they submitted their request” is added in the first paragraph after the phrase “fifteen banking business days”.
xlii) In the point “Commission analyzes and resolves the debtor's request” in section 9.3, its text is replaced with the following:
“Commission analyzes and resolves the debtor's request: For the analysis of the request, the Commission will consider the background documents accompanied by the debtor and may request the reporting entity any additional background documents it deems necessary. If the available background documents are not sufficient for its adequate resolution, the Commission may open an evidentiary term.
The Commission will review the grounds and background documents provided by the parties and will resolve with grounds whether it corresponds to modify the information registered by the reporting entity, notifying said decision to the parties. If applicable, the Commission will order the reporting entity the updates, rectifications, completions, or cancellations resolved, which must be practiced by it, within the period of five banking business days counted from the notification of the administrative act containing the respective instruction.
In case the Commission determines that modification is not warranted, it will likewise notify the reporting entity and inform the debtor.
If the Commission's decision is unfavorable to the debtor, the suspension of the reportable obligation will be voided, immediately. Otherwise, the reporting entity must rectify the debtor's information in the terms resolved.”
xliii) The paragraph referring to the right of cancellation before the commission is moved and reviewed as the last point of section 9.3, becoming as follows:
“Right of cancellation before the Commission: the right of cancellation may be exercised directly before the Commission only when the following requirements concur cumulatively: that it is not possible to determine the reporting entity that would have delivered the information stored in the REDEC, and that the debtor has sufficient background documents, duly grounded and sufficient to sustain that the debt should not be reported. The Commission will analyze the request, possibly requiring additional background documents for its resolution. The Commission will communicate to the applicant whether it accepts or denies the request expressing the grounds of its decision. If the elimination of the debt in the REDEC proceeds, it will be carried out by the Commission in the next update period of the registry.”
xliv) In section 9.4, the terms “own resolution” are replaced by “own decision”, “the Commission” by “this agency”, and the term “measures or” is intercalated between “the exercise of other” and “supervisory powers”.
xlv) In the first paragraph of section 10, the term “its function” is replaced by “its times”.
xlvi) The third paragraph of section 10 is replaced with the following: “External audits must be carried out by companies that, in accordance with the internal evaluation made by the entity, have sufficient suitability to issue a grounded opinion on the matter, considering a calendar year, and be available for examination by the Commission in the month of April of the following year.”
xlvii) Section “10.1 Minimum Aspects Subject to Internal Procedures” is added following the third paragraph of section 10 On Audits and Procedure Review.
xlviii) The first paragraph of section 10.1 is replaced with the following:
“Additionally, reporting entities must develop internal procedures that allow complying with the provisions contained in this standard, which must be reviewed annually and approved by the Entity's Board of Directors or whoever acts in their place.
Among the procedures, at least the following must be included:”.
xlix) In the point Reportable Obligations in section 10.1, the term “others established” is replaced by “other obligations established” and the term “the execution” by “exercise”.
l) The point Consent Administration in section 10.1 is replaced with the following:
“Consent Administration: corresponds to procedures associated with the management and preservation of consent that consider at least the following aspects: verify the obtaining of consent; audit the security, integrity, coding, and accessibility of consent; review that consent is registered considering at least the information established in this standard; evaluate that consent requests are clear and precise about the type of information to access, the purpose of access, among other aspects; verify that information to the public is presented in simple language; review that consent is not used for purposes different from those authorized; ensure that undue influence is not exercised at the moment of collecting consent; verify that there are accessible and clear means for debtors to revoke consent, and that the mechanisms established for revocation do not impose on the debtor burdens or requirements superior to those required for granting consent, being, at least, equivalent or homologable to this; verify that physical revocation requests are attended to within a maximum period of one business day and that electronic ones are processed as soon as the systems allow; audit the consent management system; evaluate the connection of the consent management system with REDEC access systems to avoid accesses after revocation; verify that the system preserves in an integral and traceable manner the consents and revocations for a period of at least five years; verify compliance and adequate use of the channel for sending digitized consents to the Commission; and review that the system allows visualizing the complete history of consents granted, revoked, or expired during the last five years, as well as the corresponding register of consent codes indicated in section 7.3 of this standard.”
li) In the point Information Quality in section 10.1, the term “These include” is replaced by “Such procedures must consider, at least,”, and after the term “internal reports or” the term “with the information” is added.
lii) The first and second paragraphs of section 11 are replaced with the following:
“In case a reporting entity or its agent fails to comply with the provisions established in the Law or this Standard, the Commission will be authorized to initiate the corresponding sanctioning procedure regarding the infringing reporting entity. This procedure will be carried out in accordance with Title IV of Decree Law No. 3,538.
Without prejudice to the foregoing, and in attention to what is provided in Article 23 of the Law, the following are indicated referentially, the conduct that could constitute minor, serious, and very serious infractions.”
liii) The first and second paragraphs of section 12 are replaced with the following:
“The Commission, in conformity with the good functioning of the System, and what is provided in Article 19 of Law No. 21,680, may suspend the access of reporting entities, in case of not complying with the provisions established in the Law or this standard. The suspension of access to the REDEC can be up to one year. With all, said suspension will not exempt the reporting entity from continuing to comply with the obligations established in section 3 of this Standard nor from the other obligations imposed by the Law.
The Commission may apply the suspension of reporting entities when legal or regulatory provisions are not complied with.”
liv) In the third paragraph of section 12, the term “the adoption of” is introduced before the term “urgent actions”, and the term “immediate, such as” is replaced by “that result necessary, included in case applicable,”.
lv) The third paragraph of section 13 is replaced with the following:
“As the Law indicates, data anonymization is a process through an irreversible procedure, by virtue of which a personal data cannot be linked or associated with a specific person, nor allow its identification, by having destroyed or eliminated the link with the personal information with the end that links, associates, or identifies that person.
The procedure to minimize the possibility of identifying an individual. This process that is treated includes the elimination of direct and indirect data that can be used for such re-identification, thus guaranteeing the protection of the privacy of persons. Anonymization must be carried out in such a way that data can be used for analytical, research, or statistical purposes, without compromising the privacy of debtors. In this context, an equilibrium must be maintained between the utility of the data and the risk of re-identification, applying an iterative approach to select the most adequate techniques and adjust them according to tolerable risk levels.”
lvi) The section “Implementation of the Regulation” is replaced with the following: “To comply with legal provisions, the Commission created and enabled the REDEC before the first day of the month of November 2025. The registry was enabled for institutions identified as reporting entities for the year 2026 and that are supervised by the Commission, to report from the first Friday after its creation.
The rest of the institutions obliged to report for the year 2026, identified in the list of reporting entities in section 3.1 of this standard, must report starting from January 2026 or March 2026 according to what the Second Transitory Article of the Law states. Without prejudice to the foregoing, these institutions are enabled to send regulatory files from November 2025. Reports sent before the mandatory date were reviewed by the Commission in its capacity as administrator of the REDEC.
Thus, for the purposes of the first list of reporting entities, all entities indicated in letter e) of section 3.1 that were continuously in the lists of the ICCMs of the years 2023, 2024, and 2025 were included.
With all, for what is not contemplated in the two previous paragraphs, the Law began to govern starting from April 1, 2026. The same period was considered for the application of the Operational Functioning Norms of the Consolidated Debt Registry that are introduced in this General Standard.”
II. CREATION OF TECHNICAL ANNEX DOCUMENT COMPLEMENTARY TO GENERAL STANDARD NO. 540
The document “REDEC Technical Annex” is introduced, which contains an annex throughout the General Standard No. 540 and in the Regulatory Report associated with this standard.
REDEC Technical Annex
“REDEC API Services”
The Commission will provide three API (Application Programming Interface) services, associated with access to REDEC information subject to consent, to be used exclusively by reporting entities, or their agents, that have a consent granted by a debtor.
Below, information about the respective services is provided, without prejudice to additional background documents that this Agency may remit:
a) API 1: REDEC Information Consultation of a Debtor by Consent.
| Field | Description |
|---|---|
| Service Name | ConsultaDeudaXConsentimiento: REDEC Information Consultation API. |
| Purpose | Obtain REDEC information of a debtor who has granted their consent to the reporting institution. Debtors included in the RDC10 file corresponding to the institution are excluded. |
| Fields to Consider | From the RDC30 file |
b) API 2: Commission Requests for Digitized Consent Requirements
| Field | Description |
|---|---|
| Service Name | consultaReqConsentimiento: Consent Request API. |
| Purpose | Provide a channel for Commission requests for digitized consents from the reporting entity for the purposes it defines. To comply with the foregoing, the reporting entity must enter this API to verify if there are new or pending requirements, which individually consign their peremptory response deadlines. |
| Fields to Consider | Internal consent code. |
c) API 3: Reporting Entity Submission of Consent Evidence
| Field | Description |
|---|---|
| Service Name | envioEvidenciaConsentimiento: Consent Documentation Submission API. |
| Purpose | Provide a channel for the reporting entity or agent to send the digitized consent evidence requested by the Commission. |
| Fields to Consider | Internal consent code. Digitized consent in PDF 2.0, WAV (Linear16), FLAC, or MP3 format. |
| Maximum File Size | 4 MB maximum per file. |
| Encryption | All communication and information transmission channels must use secure encryption protocols, with a minimum TLS 1.2 version or higher. Likewise, encryption negotiation (handshake) configurations must be adjusted to prioritize and always select the highest and unconditionally secure encryption level (cipher suite) available between the parties, explicitly disabling any degradation mechanism (downgrade attacks) or compatibility with algorithms or protocols declared obsolete or vulnerable. |
| Authentication | mTLS |
III. MODIFICATIONS TO THE REDEC MSI
The following adjustments are made to the RDC10 regulatory file:
i) The third paragraph of the file description is modified, now stating only "Access to the records in this file requires the debtor's consent." ii) The length assigned to field 27 "Updated percentage" is corrected; where it said "01", it should now say "03". iii) In the description of field 3 "Type of person", a clarification is added stating "For the purposes of this file, natural persons with a commercial activity will be reported with code 1 "Natural person"." iv) The description of field 9 "Weighted average residual term" is replaced with the following:
"Corresponds to the weighted average term, expressed in months, of the difference resulting from weighting the publication date of the respective RDC10 information and the OPERATION EXPIRATION DATE of the RDC01 file, with the CURRENT OPERATION AMOUNT, also recorded in the RDC01 file. To determine this field, reportable obligations whose OPERATION EXPIRATION DATE reported in the RDC01 file is equal to 19000101 or cases where the temporal difference indicated in the previous paragraph is negative will not be considered." The following adjustments are introduced in the RDC30 regulatory file:
v) The phrase "who are not part of their current debtors" is removed from the first paragraph of the regulatory file description. vi) The description of field 1 "INTERNAL CONSENT CODE" is replaced with the following:
"Refers to the unique code assigned by the reporting entity to the debtor's consent to access the information contained in the RDC10 file." vii) The names of fields 4 and 5 are modified to replace the term "end" with "revocation". viii) The description of field 4 is replaced with the following:
"This field must be completed with "19000101" whenever consent has not been revoked by the debtor. Conversely, when consent has been revoked by the debtor, the effective date (YYYYMMDD) of said event must be reported. In the event that a reporter obtains consent and it is revoked by the debtor within the same reporting period, a single record with the effective date (YYYYMMDD) of consent revocation must be reported." ix) The description of field 5 is replaced with the following:
"This field must be completed with "999999" whenever consent has not been revoked by the debtor. Conversely, when consent has been revoked by the debtor, the effective exact time (HHMMSS) of said event must be reported. In the event that a reporter obtains consent and it is revoked by the debtor within a reporting period, a single record with the effective exact time (HHMMSS) of consent revocation must be reported." x) The description for code 3 of field 7 MEANS OF CONSENT is replaced with "Written (record with physical support)". xi) The definition of field 8 PURPOSE OF CONSENT is replaced with the following:
"In this field, the purpose of consent must be identified as established in General Rule No. 540 in its Section 7. To do this, the corresponding code must be indicated according to the following table:
Code Purpose of consent
1 Commercial risk assessment
2 Credit risk assessment
3 Commercial and credit risk assessment
Among the types of risks associated with the purpose, code 1 will be reported when consent is granted to assess credit risk within the framework of the debtor's general compliance with obligations, and code 2 will be reported when it is a commercial operation or related to a business. In case there is more than one type of risk linked to the same consent, the entity must report code 3." The following clarification is made in the RDC31 regulatory file:
xii) The first paragraph of the file description is replaced with the following:
"File containing the record of accesses by the reporter or agents to individual debtor information that have been made through API 1 indicated in the REDEC Annex and who have granted their consent under section 7 of NCG No. 540. The file will be prepared by REDEC reporters, even in cases where access has been made by agents." xiii) The description of field 1 "INTERNAL CONSENT CODE" is adjusted in accordance with the same adjustment in the RDC30 file. The following adjustments are made to the RDC01 and RDC02 regulatory files:
xiv) Field 2 "Type of person" of the RDC01 file is adjusted in accordance with change iii) of this section. xv) The field "INTERNAL CONSENT CODE" is added with length X(20) and with the following description:
"Refers to the unique code assigned by the reporting entity to the process of obtaining and granting consent by the debtor to access information subject to access restrictions contained in the RDC10 file. The code reported in this field must correspond to one of the codes reported in the INTERNAL CONSENT CODE field of an RDC30 file. If the reported obligation was granted before April 1, 2026, this field must be completed with "9"s according to the field length. Furthermore, when the reported obligation was granted on or after April 1, 2026, and does not have associated consent, this field must be reported with "0"s according to the field length." xvi) As a consequence of the introduction of the new field, the record length of the RDC01 file is modified, increasing from 322 to 342 bytes. xvii) As a consequence of the introduction of the new field, the record length of the RDC02 file is modified, increasing from 360 to 380 bytes. xviii) In the RDC01 file, the Filler changes length from 299 to 319. xix) In the RDC02 file, the Filler changes length from 337 to 357. xx) In field 30 "REASON FOR DELETION OR OUT-OF-PHASE REPORT" of the RDC02 file, the description is modified to incorporate field 34 when referring to an operation deletion. xxi) In field 33 "REQUEST NUMBER" of the RDC02 file, the phrase ", prefixing the current year," is inserted between the word "rectification" and "preceded by zeros". The following adjustment is made to the RDC11 file:
xxii) In the second paragraph of the file description, the term "RDC10" is replaced by "RDC01".
The following adjustments are made to the General Instructions:
xxiii) The second paragraph of the REDEC MSI General Instructions is replaced with the following: "The Consolidated Debt Register (REDEC) will be administered exclusively by the Commission, which will be the authority responsible for maintaining it and granting access, through digital means or systems, such as remote and automated access interfaces or other additional ones it determines that allow direct interconnection and communication to reporters, their agents, debtors, and third parties authorized by the latter, in accordance with articles 5, 6 and 7, and must always ensure data privacy, in accordance with Law No. 19,628, on the protection of private life, the security and continuity of the Register. For its formation, reporting institutions must send regulatory files in accordance with the information requirements indicated in the Reporting System of this REDEC MSI. Information sent to the Commission will not require debtor consent." xxiv) Each reference to fields that must be reported with the HHMMSS format in the corresponding regulatory files is specified as "exact time". xxv) Clarifications are introduced in the character description in section 5. xxvi) The description of natural persons with respect to surnames in section 5 is modified. xxvii) In the Information System File Catalog, the paragraph following the Query System table is replaced with the following: "For the RDC10 file, the reporting institution may only access the record corresponding to its debtors if they have consent. For RDC11 and RDC12 files, the reporting institution may only access by authenticating itself in the Query System." A footnote is also added stating "Given that the legal requirement of consent did not exist prior to the effective date of Law No. 21,680, this formality will not be required for operations granted prior to its effective date" after the term "consent" in that paragraph.
IV. EFFECTIVE DATE
The adjustments introduced by this rule are subject to an implementation plan that considers gradualness and flexibility, and therefore, the deadlines determined for their entry into force are the following:
i) The debtor notification requirements of sections 7.1 and 7.4 of NCG No. 540 are enforceable one month after the publication of this rule. ii) The requirement related to the use of consent APIs in section 7.2 of NCG No. 540 is enforceable three months after the publication of this rule. iii) Regarding the requirements for modifications in the REDEC MSI:
Sign in to read the rest — it's free
Source: Comision para el Mercado Financiero — original document
Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
2026-09-11
Circular No. 2378 — Adjustments to Chapter 21-7 of the Updated Compilation of Bank Regulations on the Measurement of Risk-Weighted Assets for Market Risk and the Risk System of the Bank Information Systems Manual
2026-09-08
General Standard No. 575 — Amends General Standard No. 539 of 2025 as Stated
2026-09-08
Circular No. 2377 — Modifies Circular No. 2.110 as Specified
2026-09-02
Circular No. 2376 — Review and Rationalization of Regulatory Files
2026-08-24
General Standard No. 574 — Norms for Supervised Savings and Credit Cooperatives on Exceptional Requirements and Conditions for Requesting Refund of Participation Shares, and Establishing Modifications in the Compendium of Accounting Standards for Cooperatives
2026-08-20
Circular No. 2375 — Amends Circular No. 2062 Regarding Pension Recalculation Treatment in Life Annuity Insurance Policies under Decree Law No. 3,500 of 1980
2026-08-17
Circular No. 2374 — Establishes Adjustments to Chapter 2-13 of the Updated Compilation of Bank Regulations and Circular No. 1 of Non-Bank Payment Card Issuing Companies
2026-07-27
General Standard No. 572 — Amends General Standard No. 519 of 2024 Regarding the Integrated Annual Report
More like this from CMF
CMF published 8 documents in the last 30 days. We email you each new one the day it's published.