2021-11-06 | NRP-30

Added · Updated

Technical Standards for the Authorization, Registration, and Operation of Data Information Agencies and Credit History Information Services

The Committee of Norms of the Central Reserve Bank of El Salvador issued these Technical Standards to regulate Data Information Agencies and credit history services following Legislative Decree No. 128. The document mandates that agencies implement user-friendly mechanisms for real-time credit history access and instant messaging alerts. It establishes specific authorization procedures, requiring a 60-day review period by the Superintendency of the Financial System and the submission of detailed operational and security documentation. Additionally, the standards permit the use of cloud computing for database storage, subject to cybersecurity and data protection compliance.

Superintendencia del Sistema Financiero logo

El Salvador

Superintendencia del Sistema Financiero

Click to view thumbnail

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 1 of 37 CNBCR-16/2021 NRP-30 TECHNICAL STANDARDS FOR THE AUTHORIZATION, REGISTRATION, AND OPERATION OF DATA INFORMATION AGENCIES AND CREDIT HISTORY INFORMATION SERVICES Approval: 06/11/2021 Validity: 23/11/2021

THE COMMITTEE OF NORMS OF THE CENTRAL RESERVE BANK OF EL SALVADOR,

CONSIDERING:

I. That by Legislative Decree No. 128, dated August 17, 2021, published in Official Diary No. 166, Volume No. 432, of September 1 of the same year, the Law on Regulation of Credit History Information Services for Persons was reformed.

II. That Legislative Decree No. 128 reformed, among others, article 14 letter a) and article 17 letter h) of the Credit History Law, pursuant to which it is established that data information agencies must implement other mechanisms or technological developments that contribute to facilitating access to information and are user-friendly, so that consumers can have real-time access to queries of their credit history, as well as receive alerts via instant messaging service when it is being reviewed by an economic agent of any kind.

III. That article 5 of the Law on Regulation of Credit History Information Services for Persons establishes that it is the responsibility of the Central Reserve Bank of El Salvador to issue the Technical Standards for the organization, operation, and control, and other aspects related to Data Information Agencies on Credit History and those personal data that must be provided by consumers or clients to Economic Agents.

IV. That article 7 of the Law on Supervision and Regulation of the Financial System establishes that the Superintendency of the Financial System is responsible for the supervision of specialized companies providing credit information services operating in El Salvador.

V. That article 78 letter l) of the Law on Supervision and Regulation of the Financial System establishes that the Superintendency of the Financial System will organize and keep updated the records of companies and persons providing services related to credit information and history.

VI. That article 24 of Legislative Decree No. 128, dated August 17, 2021, published in Official Diary No. 166, Volume No. 432, of September 1 of the same year, establishes that the Committee of Norms of the Central Reserve Bank will issue the corresponding regulations within a period of two months from the entry into force of said Decree.

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 2 of 37 CNBCR-16/2021 NRP-30 TECHNICAL STANDARDS FOR THE AUTHORIZATION, REGISTRATION, AND OPERATION OF DATA INFORMATION AGENCIES AND CREDIT HISTORY INFORMATION SERVICES Approval: 06/11/2021 Validity: 23/11/2021

VII. That Legislative Decree No. 280, of April 24, 2025, reformed letter n) of article 17 and letter h) of article 19 of the Law on Regulation of Credit History Information Services for Persons, pursuant to which it is established that cloud computing technology storage and processing services may be used for the database and its backup, with storage permitted within national territory, and in both cases granting unrestricted access to the Central Reserve Bank of El Salvador and to the Superintendency of the Financial System, for which Technical Standards will be issued to guarantee compliance with cybersecurity and data protection standards in the administration and backup of databases. (2)

VIII. That in order to safeguard the right to personal privacy and the right to informational self-determination, ensuring equality in the treatment of credit data and in accordance with the Law on Regulation of Credit History Information Services for Persons, it is necessary to issue new Technical Standards that allow for the development of the reforms approved to said Law.

THEREFORE, by virtue of the regulatory powers conferred by article 99 of the Law on Supervision and Regulation of the Financial System,

AGREES to issue the following:

TECHNICAL STANDARDS FOR THE AUTHORIZATION, REGISTRATION, AND OPERATION OF DATA INFORMATION AGENCIES AND CREDIT HISTORY INFORMATION SERVICES

TITLE I GENERAL ASPECTS

CHAPTER I OBJECT, SUBJECTS, AND TERMS

Object Art. 1.- These Standards aim to establish the requirements for authorization, organization, registration, operation, closure of operations, risk management, and the execution of mechanisms or technological developments to be implemented that must be complied with by legal entities, public or private, that are authorized by the Superintendency of the Financial System to operate as Data Information Agencies.

Likewise, it establishes the requirements that legal entities, public or private, that, in accordance with the Law on Regulation of Credit History Information Services for Persons, seek to obtain authorization to operate as a Data Information Agency, must comply with.

Furthermore, it establishes the personal and reference data to be collected from economic agents, the treatment of negative information of consumers or clients, and the proper handling of data for the creation of the credit history, guaranteeing the protection, confidentiality, and integrity of consumer or client information, in accordance with what is established in the Law on Regulation of Credit History Information Services for Persons.

Subjects Art. 2.- The subjects obliged to comply with the provisions established in these Standards are: a) Legal entities, public or private, that have expressed their interest before the Superintendency of the Financial System to obtain authorization to operate as Data Information Agencies; b) Authorized Data Information Agencies; and c) Economic Agents in accordance with what is regulated in article 2 of the Law on Regulation of Credit History Information Services for Persons.

Terms Art. 3.- For the purposes of these Standards, the terms indicated below have the following meaning: a) Data Update: Process in which Data Information Agencies update their databases with true and reliable information provided monthly by Economic Agents in the first ten calendar days and in the second half of each month with information related to the data holder, such as: corrections, settlements, modifications, or deletions due to erroneous and inaccurate data; b) Data Information Agency or DIA: Any legal entity, public or private, excluding the Superintendency of the Financial System, that is dedicated to collecting, storing, conserving, organizing, communicating, transferring, or transmitting data on the credit history of consumers or clients, through automated or non-automated technical procedures; c) Economic Agents or EA: Natural or legal persons, providers of goods and services, that register, supply, and obtain information from a database; d) Authenticity: Condition under which information is originated by who says to be the author or owner and received by who is the recipient; and that has not been altered at any time; e) Central Bank: Central Reserve Bank of El Salvador;

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 3 of 37 CNBCR-16/2021 NRP-30 TECHNICAL STANDARDS FOR THE AUTHORIZATION, REGISTRATION, AND OPERATION OF DATA INFORMATION AGENCIES AND CREDIT HISTORY INFORMATION SERVICES Approval: 06/11/2021 Validity: 23/11/2021

f) Database: Organized set of data on current or active credit histories, cancelled or inactive, that the consumer or client has or has had, regardless of the form or modality of its creation, storage, organization, and access; g) Complaint Resolution Center: Administrative offices enabled by Data Information Agencies for the resolution of concerns, handling of complaints, and other procedures contemplated in the Law on Regulation of Credit History Information Services for Persons, by consumers or clients; h) Confidentiality: Characteristic of information by which it is considered accessible only to those duly authorized and only for the clearly and expressly delimited purposes, in accordance with what is established by the Law on Regulation of Credit History Information Services for Persons; i) Consumer or client: Any natural or legal person who acquires, uses, or enjoys goods or services provided by an economic agent, regardless of the public or private character, individual or collective, of those who produce, market, facilitate, supply, or issue them; j) Data: Information on the credit history of consumers or clients, which is their property and is recorded in a database; k) Negative Data: Information recorded in a DIA database, relating to the history of delinquency or delays in fulfilling credit obligations and all those obligations agreed upon or payable in future or deferred payments, in their different unsatisfied modalities by consumers or clients; l) Defender: Consumer Defender; m) Authentication Factor: Information used to verify the identity of a person; n) Credit History: Data of consumers or clients, duly incorporated into a database, that reflect economic, commercial, financial, or banking transactions payable in installments; o) Sensitive Information: Information of clients and entities that cannot be exposed or shared with the public according to legislation; p) Integrity: Automated or non-automated mechanisms by which it is safeguarded that the information is complete, accurate, and valid; q) Credit History Law: Law on Regulation of Credit History Information Services for Persons; r) Mechanisms or technological developments: Web applications, mobile applications, among others, that DIAs implement so that consumers or clients can access their credit history information; s) Order for rectification or data update: Order issued by an EA, the Superintendency, or the Defender to a DIA, in which it attests that the credit history data of a client or consumer have been rectified or updated, modified, or eliminated on a specific date, with the object that the DIA rectifies or updates them in its corresponding database. This order refers to cases of rectification, update, modification, or elimination of information, established in article 14 letter e) of the Credit History Law; t) Consultation Points: Kiosks or offices enabled by Data Information Agencies so that consumers or clients can access their credit history information; u) Backup: Copy of the original data made in order to have a means for its recovery in case of partial or total loss of these; v) Superintendency: Superintendency of the Financial System; w) Cloud computing technologies: Refers to the model of delivery of processing, storage, software, and other resources services through the Internet, instead of storing them locally on a device, server, or physical data center; and (2) x) Data Processing: Any operation or set of operations or automated or non-automated technical procedures, within a database, that allow collecting, storing, organizing, elaborating, selecting, extracting, confronting, sharing, communicating, transmitting, or canceling data of consumers or clients, related to their credit history.

CHAPTER II AUTHORIZATION AND REGISTRATION OF DATA INFORMATION AGENCIES

Authorization Art. 4.- The provision of credit history information services for persons will be carried out exclusively by DIAs, which must be previously authorized by the Superintendency to exercise this activity. Without prejudice to what is established in the applicable legal framework, DIAs that decide to merge, transform, change their name, or any other relevant fact, must notify the Superintendency sixty business days in advance. Likewise, DIAs may provide the service of credit risk profile rating of a person, consumer, or client, provided that it is guaranteed that this service does not violate the rights of persons, considers the principles for the protection of consumer and client rights contemplated in the Credit History Law.

Minimum Capital Art. 5.- DIAs must have a minimum social capital in accordance with what is stipulated in article 8 of the Credit History Law.

Authorization Request Art. 6.- Any legal entity, public or private, interested in operating a DIA for the provision of credit history information services for persons, must

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 4 of 37 CNBCR-16/2021 NRP-30 TECHNICAL STANDARDS FOR THE AUTHORIZATION, REGISTRATION, AND OPERATION OF DATA INFORMATION AGENCIES AND CREDIT HISTORY INFORMATION SERVICES Approval: 06/11/2021 Validity: 23/11/2021

present to the Superintendency an authorization request, signed by the legal representative, attaching the following information and documentation: a) Request made on plain paper or form that must contain the following information: i. Name or corporate name of the applicant; ii. Type of society or association involved; iii. Date of its registration in the corresponding public registry, with indications of the volume, folio, and entry respectively; iv. Names of its directors, legal representative, and general attorney, if any; v. Legal domicile of the applicant; vi. Trade name of the DIA; vii. Exact address of the commercial establishment, telephone number, postal, and email address, if any; and viii. Tax identification number. b) Copy of the public deed of Constitution of the Society or association involved and of the reforms, if any, duly registered in the corresponding Registry, in the case of private DIAs, its constitutive deed must contain as its main purpose the collection of data information on the credit history of persons; c) Certification of the respective Registry, where the validity and registration data of the legal entity are recorded, as well as the names of the directors, legal representative, and attorney, if any; d) Certified photocopy of the Unique Identity Document, valid passport, or residence card as applicable, and photocopy of the Tax Identification Number or its Graphic Representation of its directors, legal representative, and general attorney, if any. (1) e) Certificate of police background, issued by the National Civil Police, of the directors, legal representative, and general attorney, if any; f) Certificate of criminal background, issued by the General Directorate of Penal Centers of the Ministry of Justice and Public Security, of the directors, legal representative, and general attorney, if any; g) Deposit of format of credit history service contracts at the Superintendency and the Defender, as well as any subsequent modifications to them; h) Number, location, and schedule of services of consultation points and complaint resolution centers; i) Description of the procedure or system established for customer service in accordance with what is established in the Credit History Law; j) Description of the procedure for rectification and data update in accordance with what is established in the Credit History Law; k) Appointment of the external auditor, registered at the Superintendency;

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 5 of 37 CNBCR-16/2021 NRP-30 TECHNICAL STANDARDS FOR THE AUTHORIZATION, REGISTRATION, AND OPERATION OF DATA INFORMATION AGENCIES AND CREDIT HISTORY INFORMATION SERVICES Approval: 06/11/2021 Validity: 23/11/2021

l) Organizational chart of the DIA with indication of the position and name of administrators and directors, specifying the position to be performed regarding support staff; m) Financial, tax, and municipal solvency of the society; n) General operating program, which must include at least the following: i. Description of computing systems and information collection and processing processes, attaching the inventory and description of the computer systems and databases that the DIA will use in its operations, as well as the description of the computer platform on which they have been developed; ii. Backup procedures manual and description of security policies and controls applied to computer systems and databases in accordance with the [Reference Missing in Source - likely NBCR-23]; iii. Description of the characteristics of the products and services to be provided, as well as the amount of the charge to be made for them. For this, they must present the detail of the parameters used to determine said amount; iv. Service provision policies with which it intends to operate; v. Detail of security and control measures, in order to avoid improper handling of information; vi. Organizational chart and job manual and functions for each area of the DIA; and vii. Contingency plan in case of disaster. Additionally to the documentation indicated in the previous letters, DIAs must present the business continuity plan and information security policies, in accordance with what is established in the [Reference Missing in Source - likely NBCR-24], approved by the Central Bank, through its Committee of Norms.

Authorization Procedure to Operate Art. 7.- Upon receipt of the authorization request, in accordance with what is established in article 6 of these Standards, the Superintendency will proceed to verify compliance with the requirements established in the Credit History Law and these Standards, having a period not exceeding sixty calendar days in accordance with article 11 of said Law, for the authorization or denial of the authorization of the corresponding entry. If the request is not accompanied by the complete and duly formatted information detailed in article 6 of these Standards, the Superintendency, due to the lack of necessary requirements, may require applicants to present the missing documents within a period of ten business days counted from the day following the notification, a period that may be extended at the request of the applicants, when there are reasons justifying it.

The Superintendency in the same notice will indicate to the applicants that, if they do not complete the information within the aforementioned period, it will proceed without further procedure to archive the request, leaving them free to present a new request.

If after the analysis of the documentation presented, in accordance with article 6 of these Standards, the Superintendency has observations or when the documentation or information presented is not sufficient to establish the facts or information intended to be accredited, the Superintendency may warn the interested party in operating a DIA once to remedy the deficiencies communicated or present additional documentation or information requested. The interested party in operating a DIA will have a maximum period of ten business days counted from the day following the respective notification, to remedy the observations or present the additional information requested. The Superintendency may, through a reasoned and founded resolution, extend by up to another ten business days the period indicated in the previous paragraph, when the nature of the observations or deficiencies warned requires it.

Extension Period Art. 8.- The interested party in operating a DIA may present to the Superintendency a request for extension of the periods indicated in the fifth paragraph of article 7 of these Standards, before the expiration of said period, must express the grounds on which it bases its request, proposing, if applicable, the pertinent proof. The extension period cannot exceed ten business days and will begin to count from the next business day after the expiration date of the original period.

Suspension of the Period Art. 9.- The sixty calendar day period indicated in the first paragraph of article 7 of these Standards, will be suspended for the days that elapse between the notification of the requirement to complete information or documentation referred to in the second and fifth paragraphs of article 7 of these Standards, until the date when the interested parties present the esc

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 6 of 37 CNBCR-16/2021 NRP-30 TECHNICAL STANDARDS FOR THE AUTHORIZATION, REGISTRATION, AND OPERATION OF DATA INFORMATION AGENCIES AND CREDIT HISTORY INFORMATION SERVICES Approval: 06/11/2021 Validity: 23/11/2021

[Text ends abruptly in source document]