2016-02-22 | SGDB N°005/2016Added · Updated
The Central Bank of Bolivia mandates updated minimum operational security requirements for electronic payment instruments, including payment orders, mobile wallets, and electronic cards, which supersede Circular Externa SGDB N° 016/2012. Financial entities, payment service companies, and related issuers must implement robust authentication mechanisms such as two-factor authentication, enforce SSL/TLS encryption, and adhere to specific data protection and transaction processing standards. The regulation establishes detailed obligations for identity verification, data retention, and liability allocation for disputes involving magnetic stripe versus chip-based transactions.
BCB published 10 documents in the last 30 days — get each new one by email the day it lands.
[Logo: BANCO CENTRAL DE BOLIVIA]
BCB-DGD-VUC
BANCO CENTRAL DE BOLIVIA
ESTADO PLURINACIONAL DE BOLIVIA
EXTERNAL CIRCULAR
La Paz, February 12, 2016
SGDB No. 005/2016
FROM: GENERAL MANAGEMENT
FINANCIAL ENTITIES MANAGEMENT
TO: FINANCIAL ENTITIES, PAYMENT SERVICE COMPANIES, ACCL S.A., EDV S.A.
SUBJECT: MINIMUM OPERATIONAL SECURITY REQUIREMENTS FOR ELECTRONIC PAYMENT INSTRUMENTS
Ladies and Gentlemen:
In the framework of its regulatory powers over the national payments system and in accordance with Article 27 of the Regulation of Payment Services, Electronic Payment Instruments, Compensation and Settlement, approved by Supreme Decree No. 134/2015 of July 28, 2015, the Central Bank of Bolivia transmits for application and compliance the update to the minimum operational security requirements for electronic cards, payment orders, and mobile wallets, which renders Circular Externa SGDB No. 016/2012 of April 17, 2012, null and void.
Read the rest free, and get an email when BCB publishes again
This document supersedes: SGDB No. 016/2012: Minimum Operational Security Requirements for Electronic Payment Instruments
Source: Banco Central de Bolivia — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works