2016-02-02 | DOF 5424068Added
The National Banking and Securities Commission (CNBV) amends the General Provisions to impose new data breach reporting obligations on Popular Financial Societies. Specifically, it adds Articles 58 Bis through 190 Bis, requiring these entities to notify the CNBV within five natural days and affected clients within three business days of any loss, theft, or unauthorized access to sensitive client information, while mandating an immediate investigation. The resolution also substitutes Annex G to update the credit portfolio qualification format and Annex S to standardize the report for sensitive information loss events, and repeals Article 265 Bis 23. These changes entered into force the day after publication on February 2, 2016.
If the document appears incomplete on the right margin, it is because it contains tables that exceed the default width. If this is the case, click here to view it correctly.
DOF: 02/02/2016
RESOLUTION that modifies the General Provisions applicable to popular savings and credit entities, integration organizations, community financial societies, and rural financial integration organizations, referred to in the Popular Savings and Credit Law.
A seal with the National Coat of Arms appears at the margin, which says: United Mexican States.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.
The National Banking and Securities Commission, based on what is provided by articles 36 Bis 3, 116, fractions II and VII, and 122 Bis of the Popular Savings and Credit Law, as well as 4, fractions II, XXXVI and XXXVIII, 16, fraction I and 19 of the National Banking and Securities Commission Law, and
CONSIDERING
That it is pertinent to include the obligations to which popular financial societies will be subject in the event that sensitive information of their clients or users is lost, extracted, or if an unauthorized third party gains access to such information, as well as to adjust the reporting of sensitive information loss events of clients or users for such purposes, in order to strengthen the security and confidentiality of said information and prevent misuse of this,
And that it is necessary to make adjustments to the format in which popular financial societies must send to the National Banking and Securities Commission the information regarding the qualification of their credit portfolio, in order that this Decentralized Body has relevant information for supervision purposes, has resolved to issue the following:
RESOLUTION THAT MODIFIES THE GENERAL PROVISIONS APPLICABLE TO POPULAR SAVINGS AND CREDIT ENTITIES, INTEGRATION ORGANIZATIONS, COMMUNITY FINANCIAL SOCIETIES AND RURAL FINANCIAL INTEGRATION ORGANIZATIONS, REFERRED TO IN THE POPULAR SAVINGS AND CREDIT LAW
UNIQUE.- Articles 58 Bis; 86 Bis, 128 Bis and 190 Bis are ADDED; Articles 1, fraction XL; 232 Bis 2, third paragraph; 265 Bis 35, fraction II, second paragraph and the denomination of Annex S are REFORMED to read "Report of loss, extraction or unauthorized access events of sensitive information"; Article 265 Bis 23 is REPEALED; and Annexes G and S of the "General Provisions applicable to popular savings and credit entities, integration organizations, community financial societies and rural financial integration organizations, referred to in the Popular Savings and Credit Law", published in the Official Gazette of the Federation on December 18, 2006, updated with modifications published in said dissemination organ on January 18 and August 11, 2008, December 16, 2010, December 18, 2012, January 12, February 6, April 2, September 22 and October 29, 2015, and January 7, 2016, are SUBSTITUTED, to read as follows:
"TITLES FIRST to NINTH . . .
ANNEXES A to F
. . .
ANNEX G
Credit Portfolio Qualification Format.
ANNEXES H to R
. . .
ANNEX S
Report of loss, extraction or unauthorized access events of sensitive information.
ANNEXES T and U
. . . "
" Article 1.
. . .
I. to XXXIX.
. . .
XLIV.
Sensitive Information, to the information of Clients and public users that contains names, addresses, telephone numbers or email addresses, together with credit or debit card numbers, account numbers, credit limits, balances, User Identifiers or Authentication information.
XLI. to LXXIX.
. . . "
" Article 58 Bis.- In the event that Sensitive Information is extracted, lost, or if Popular Financial Societies suspect the commission of any act involving unauthorized access to such information, the General Director or personnel designated by him shall:
I.
Send in writing to the Commission, within five natural days following the event in question or when they have knowledge thereof, the information contained in Annex S of these provisions.
II.
Carry out an immediate investigation into the causes that generated the materialization of the extraction or loss event or, in its case, the unauthorized access to Sensitive Information, and regarding whether the information has been or may be misused. The result of said investigation must be sent to the Commission within a period not exceeding five natural days after its conclusion.
III.
Notify the Client of the possible extraction, loss or unauthorized access to their information within the following three business days from when the event occurred or when knowledge thereof was obtained, through the notification means that the Client has indicated for such effect, in order to warn them of the risks derived from the misuse of the information that has been extracted, lost or compromised, informing them of the measures they must take and, in its case, carrying out the replacement of the corresponding disposition means or the substitution of necessary Authentication Factors. "
" Article 86 Bis.- In the event that Sensitive Information is extracted, lost, or if Popular Financial Societies suspect the commission of any act involving unauthorized access to such information, the General Director or personnel designated by him shall:
I.
Send in writing to the Commission, within five natural days following the event in question or when they have knowledge thereof, the information contained in Annex S of these provisions.
II.
Carry out an immediate investigation into the causes that generated the materialization of the extraction or loss event or, in its case, the unauthorized access to Sensitive Information, and regarding whether the information has been or may be misused. The result of said investigation must be sent to the Commission within a period not exceeding five natural days after its conclusion.
III.
Notify the Client of the possible extraction, loss or unauthorized access to their information within the following three business days from when the event occurred or when knowledge thereof was obtained, through the notification means that the Client has indicated for such effect, in order to warn them of the risks derived from the misuse of the information that has been extracted, lost or compromised, informing them of the measures they must take and, in its case, carrying out the replacement of the corresponding disposition means or the substitution of necessary Authentication Factors. "
" Article 128 Bis.- In the event that Sensitive Information is extracted, lost, or if Popular Financial Societies suspect the commission of any act involving unauthorized access to such information, the General Director or personnel designated by him shall:
I.
Send in writing to the Commission, within five natural days following the event in question or when they have knowledge thereof, the information contained in Annex S of these provisions.
II.
Carry out an immediate investigation into the causes that generated the materialization of the extraction or loss event or, in its case, the unauthorized access to Sensitive Information, and regarding whether the information has been or may be misused. The result of said investigation must be sent to the Commission within a period not exceeding five natural days after its conclusion.
III.
Notify the Client of the possible extraction, loss or unauthorized access to their information, within the following three business days from when the event occurred or when knowledge thereof was obtained, through the notification means that the Client has indicated for such effect, in order to warn them of the risks derived from the misuse of the information that has been extracted, lost or compromised, informing them of the measures they must take and, in its case, carrying out the replacement of the corresponding disposition means or the substitution of necessary Authentication Factors. "
" Article 190 Bis.- In the event that Sensitive Information is extracted, lost, or if Popular Financial Societies suspect the commission of any act involving unauthorized access to such information, the General Director or personnel designated by him shall:
I.
Send in writing to the Commission, within five natural days following the event in question or when they have knowledge thereof, the information contained in Annex S of these provisions.
II.
Carry out an immediate investigation into the causes that generated the materialization of the extraction or loss event or, in its case, the unauthorized access to Sensitive Information, and regarding whether the information has been or may be misused. The result of said investigation must be sent to the Commission within a period not exceeding five natural days after its conclusion.
III.
Notify the Client of the possible extraction, loss or unauthorized access to their information, within the following three business days from when the event occurred or when knowledge thereof was obtained, through the notification means that the Client has indicated for such effect, in order to warn them of the risks derived from the misuse of the information that has been extracted, lost or compromised, informing them of the measures they must take and, in its case, carrying out the replacement of the corresponding disposition means or the substitution of necessary Authentication Factors. "
" Article 232 Bis 2 .- . . .
. . .
I. to IX. . . .
The delivery of the Independent External Auditor's opinion, including the basic consolidated financial statements, their relative notes, as well as the reports, opinions and communications established in fractions I, II, III, V, VI, VII, VIII and IX referred to in this article, must be carried out within 60 natural days following the closing of the fiscal year.
. . .
. . . "
" Article 265 Bis 23.- Repealed. "
" Article 265 Bis 35.- . . .
I.
. . .
II.
. . .
Regarding the commissions referred to in the Second Section of this chapter, the criteria oriented to evaluate the experience and technical capacity of the third party must adhere to what is provided by Annex R of these provisions.
III. to VII.
. . .
. . . "
TRANSITIONAL PROVISIONS
FIRST.- This Resolution shall enter into force the day following its publication in the Official Gazette of the Federation.
SECOND.- Popular financial societies are obligated to publish the result of the qualification of their credit portfolio in the format of Annex G substituted by this instrument, for the first time, within 60 natural days following the closing of the 2015 fiscal year, as provided by article 212, fraction IV of the General Provisions applicable to popular savings and credit entities, integration organizations, community financial societies and rural financial integration organizations, referred to in the Popular Savings and Credit Law.
Respectfully,
Mexico City, January 22, 2016. - The President of the National Banking and Securities Commission, Jaime González Aguadé.- Signature.
ANNEX G
NAME OF THE POPULAR FINANCIAL SOCIETY
CREDIT PORTFOLIO QUALIFICATION
AT ________________________
(Numbers in thousands of pesos)
AMOUNT
CREDIT PORTFOLIO
PREVENTIVE RESERVES NECESSARY
COMMERCIAL
CONSUMER
HOUSING
TOTAL
PREVENTIVE RESERVES
COMMERCIAL
OTHER THAN MICROLOAN
MICROLOAN
NON-REVOLVING
CREDIT CARD AND OTHERS
REVOLVING CREDITS
$ $ $ $ $ $ TOTAL $ $ $ $ $ $ Less: RESERVES CONSTITUTED $ EXCESS (INSUFFICIENCY) $ NOTES:
QUALIFICATION OF THE COMMERCIAL CREDIT PORTFOLIO (OTHER THAN MICROLOAN) AT ________________________ (Numbers in thousands of pesos) AMOUNT OF CREDITS UNDER THE SAME DEBTOR TOTAL PREVENTIVE RESERVES RISK GRADES CREDITS WITH BALANCES EQUAL TO OR GREATER THAN THE EQUIVALENT TO 900,000 UDIS CREDITS WITH BALANCES LESS THAN THE EQUIVALENT TO 900,000 UDIS A-1 $ $ A-2 $ $ B-1 $ $ B-2 $ $ B-3 $ $ C-1 $ $ C-2 $ $ D $ $ E $ $ TOTAL $ $ $ Less: RESERVES CONSTITUTED $ EXCESS (INSUFFICIENCY) $ 3. The [excess] [insufficiency] in the constituted preventive reserves is explained as follows _____________.
ANNEX S
REPORT OF LOSS, EXTRACTION OR UNAUTHORIZED ACCESS EVENTS OF SENSITIVE INFORMATION
I. Popular Financial Society Information
Name of the Popular Financial Society
Address of the office(s) where the information security incident occurred 2.1. City 2.2. State 2.3. Postal Code
Was the information involved administered by third parties? [ Yes ] [ No ] In the affirmative case: 3.1. Provider name 3.2. Provider address 3.3. Contact
II. Information Security Incident Information
Brief description of the information security incident
Compromised Information Client Personal Information Together with: Names [ ] Debit, credit or other card numbers [ ] Addresses [ ] Account numbers [ ] Phone numbers [ ] Passwords or Personal Identification Numbers [ ] Email addresses [ ] User Identifiers [ ] Other:_________________ [ ] Credit limits [ ] Balances [ ] Other:_____________________________ [ ]
Affected account number(s). Specify the number of accounts that are blocked or suspended: Number of affected accounts Number of blocked or suspended affected accounts Comments Attach to the report the disaggregated list of affected account numbers (in an electronic file attached to your report) as indicated in the following table: No. Affected account number Status of affected account (blocked, suspended, active) Comments 1 2 3 4
Date or period in which the information security incident occurred
Total amount in pesos known or estimated involved in the information security incident, if applicable
Classification of the information security incident (check all that apply): a. Computer equipment intrusion [ ] b. Consumer loans [ ] c. Credit cards [ ] d. Debit cards [ ] e. Electronic funds transfer [ ] f. Identity theft [ ] g. Theft of physical or electronic files [ ] h. Electronic Channels Specify channel (Internet, ATMs, Audio Response Service, Telephone Service, Point of Sale Terminal, Mobile Phone, Mobile Payment, Advanced Mobile Services) [ ] i. Correspondents [ ] j. Messaging [ ] j. Others (specify)
[ ]
Loss amount in pesos, if applicable
Recovered amount in pesos, if applicable
Has the information security incident been disclosed to any local or federal authority? [ Yes ] [ No ] In the affirmative case: To which authority? On what date?
III. Contact at the Popular Financial Society
Name of the person authorized to provide information to the CNBV
Position held
Telephone
Name and signature of the General Director or special designee
In the document you are viewing, there may be text, characters or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as reference. The content, form and scope of published documents are the strict responsibility of their issuer.
INQUIRY BY DATE Do Lu Ma Mi Ju Vi Sá INDICATORS Exchange Rate and Rates as of 31/08/2026 DOLLAR 17.0427 UDIS 8.810483 TIIE 28 DAYS 6.7659% TIIE 91 DAYS 6.8033% TIIE 182 DAYS 6.8577% TIIE OF FUNDING 6.51% See more SURVEYS Did you like the new look of the Official Gazette of the Federation website? No Yes Official Gazette of the Federation Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our menu of services Electronic address: dof.gob.mx 111 LEGAL NOTICE | SOME RIGHTS RESERVED © 2026
More like this from SHCP
SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.