On September 15th, 2026, Chile’s Financial Market Commission (CMF, for its initials in Spanish) published amendments to General Rule No. 540 (NCG 540), which governs the operation of the Consolidated Debt Registry (REDEC, for its initials in Spanish), as well as its Information System Manual (MSI REDEC, for its initials in Spanish). Alongside these changes, the CMF introduced a new REDEC Technical Annex, which details the Application Programming Interface (API) services made available by the regulator for the operation of the registry. These APIs serve as a technological bridge that allows financial institutions to communicate automatically with the CMF’s database.
The final version of the regulation follows two public consultation processes. The first, conducted between November 2 and December 23, 2025, received more than 200 comments from 22 entities. The second, held between May 22 and June 15, 2026, generated 167 comments from 19 entities.
The amendments are intended to strengthen reporting entities’ practices for managing debtor consent when accessing information contained by REDEC, both in their dealings with debtors and in their reporting obligations to the CMF. The changes are designed to promote greater accountability in the collection, recordkeeping, and reporting of consent.
Key Changes
- Debtor Notifications
Reporting entities must notify debtors as soon as consent is granted or revoked. The notification must include the date and time of the action, the channel through which the consent was granted or revoked, and the internal code assigned to that consent.
- Preservation of Consent Records
The initial proposal requiring the use of encrypted hash codes has been replaced with a principles-based, technology-neutral framework. Consent records must be retained for at least five years and must ensure integrity, authenticity, fidelity, confidentiality, and verifiability.
- Consent Management System
Reporting entities must implement an individual digital or document management system capable of storing, managing, and generating reports on the validity and status of granted and revoked consents.
- Revocation of Third-Party Authorizations
The regulation formalizes the right of debtors, established under Law No. 21,680, to revoke authorizations previously granted to third parties before their expiration date through the CMF’s “Conoce tu Deuda” platform.
- API Integration
The new REDEC Technical Annex formally establishes three API services provided by the CMF. API 1: Access to REDEC information subject to debtor consent (already operational), API 2: Requests by the CMF for digitalized consent records and API 3: Submission of those records by reporting entities, subject to specific requirements regarding format, maximum file size, and encryption.
- Exception Regime
Entities whose business model does not require access to debtor information subject to consent may opt into an exception regime that exempts them from consent-management requirements. These entities must notify the CMF annually, no later than August of each year.
Implementation Phase
The regulation will be implemented gradually. Requirements related to debtor notifications will be put into practice one month after publication. Obligations concerning the use of consent-related APIs will come into force in the third month following publication.
In addition, the submission of the regulatory files RDC30 and RDC31, reflecting the corresponding amendments, will begin with the reporting period immediately following publication. The updated RDC01 and RDC02 reporting requirements will take effect three months after publication.
Information updated as of September 2026.