Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · August 1, 2026

Six Latin American economies rewrote their identity rules in 21 months

Six of Latin America's seven largest economies rewrote their identity rules between March 2025 and December 2026. Chile's regime binds 1 December.

By DiditUpdated
Didit Blog card. Eyebrow reads Latin America, IDV Regulation, 2026. Headline: Six economies rewrote identity rules in 21 months. To the right, a dotted globe of the Americas carries six blue markers.

Chile's full regime, Mexico's biometric national ID and Brazil's adequacy bridge to the European Union all landed inside the same window. The remaining deadlines converge on December 2026.

The short version

Fraud is the driver, and it is measured

INTERPOL's Global Financial Fraud Threat Assessment, published March 2026, put global fraud losses at $442 billion for 2025 and recorded cases across the Americas up 40% in a year.

Chile's regime binds on 1 December 2026

Law 21.719 was published on 13 December 2024 and takes full force on 1 December 2026, creating a dedicated data protection agency where Chile previously had none.

Mexico now has a biometric national ID

A decree published in the Diario Oficial de la Federación on 16 July 2025 makes the CURP carrying fingerprints and a photograph the mandatory national identification document.

Brazil and the EU recognised each other

Commission Implementing Decision (EU) 2026/179, adopted 26 January 2026, lets personal data move between the two without additional transfer instruments, covering more than 670 million people.

Biometric data is sensitive by law

Chile, Peru, Mexico and Colombia all treat biometric data as a special category requiring a stricter basis than ordinary personal data. Brazil's binding rules are expected.

The adaptation windows are shrinking

Chile gave just under two years between publication and full force. Mexico's 2025 federal data protection law was published on 20 March 2025 and took effect the following day.

Fraud cases across the Americas rose 40% in a year, and the rewrites followed

INTERPOL's Global Financial Fraud Threat Assessment, published in March 2026, put global fraud losses at $442 billion for 2025 and recorded fraud cases across the Americas up 40% in a single year. It also found that schemes using artificial intelligence were roughly 4.5 times more profitable than those without. The identity rules described below are the regulatory response to that.

That last figure is the one that explains the timing. Fraud that scales cheaply is fraud that arrives faster than legislation normally moves, and the laws in this post were written by governments watching the same INTERPOL series.

It is worth being precise about what these rules are and are not. Most of them are data protection statutes rather than anti-fraud statutes. They govern how an organisation may collect and hold a face scan or a fingerprint, and only some of them require verification at all. The connection to fraud runs the other way: as verification becomes more common, the data it produces becomes more sensitive, and the law follows the data.

That is the proportionality question underneath the whole region's rewrite. Identity checks keep being attached to new contexts, and each time the open question is whether the harm justifies the friction and the collection. Latin America has answered it differently in different markets, which is why a single regional compliance posture does not exist.

Six of the seven largest economies rewrote their rules between March 2025 and December 2026

Between March 2025 and 1 December 2026, Mexico, Peru, Argentina, Brazil, Chile and Colombia all replaced, reformed or began enforcing rules governing identity and personal data. Only one of Latin America's seven largest economies sat out the period. The last of the changes, Chile's Law 21.719, takes full force on 1 December 2026.

The window opened in Mexico. The federal data protection law published on 20 March 2025 replaced the 2010 statute and took effect the following day, and the long-standing transparency and data protection regulator INAI was dissolved, with enforcement moved to a body under the federal anti-corruption authority. Nine days later Peru's rewritten data protection regulation took effect, requiring data protection officers and setting a breach notification duty that runs from the moment the facts are confirmed.

Two changes since then matter most for anyone moving verification data across borders. Mexico's biometric CURP decree, published on 16 July 2025, is covered in section 04. And on 26 January 2026 the European Commission adopted Implementing Decision (EU) 2026/179, recognising Brazil as providing adequate protection for personal data, with Brazil adopting a reciprocal decision. The European Commission describes the result as covering more than 670 million people, and it means verification data can move between the European Union and Brazil without standard contractual clauses or other transfer instruments.

The same pattern is visible on other continents. Nine markets across Asia rewrote their identity rules in fourteen months, and the European Union's Anti-Money Laundering Regulation now attaches ongoing monitoring duties to customers a firm already has.

Biometric data is now a special category in every major market

Chile's Law 21.719 names biometric data as sensitive data, alongside health, geolocation and financial data, from 1 December 2026. Peru's 2025 regulation, Mexico's federal law and Colombia's Law 1581 of 2012 all treat biometric data as a special category. The practical effect is the same everywhere: a face scan needs a stronger legal basis than a name and an email address.

Sensitive is a term of art worth glossing. It means the data cannot be processed on the ordinary bases that cover most business activity, and usually requires explicit consent or a specific statutory permission, along with tighter security and, in several of these regimes, a documented assessment of the risk before processing starts. Colombia has required prior explicit authorisation since 2012, which in practice means consent bundled into general terms and conditions does not satisfy the requirement.

Brazil is the market to watch. Its national data protection authority, the ANPD, ran a public consultation on facial recognition and biometric processing in June 2025, and binding rules are expected. Until they land, biometric processing in Brazil is governed by the general provisions of the Lei Geral de Proteção de Dados rather than by a dedicated instrument.

There is a tension in the region worth naming rather than resolving. The same governments tightening the rules on holding biometric data are, in several cases, the governments building mandatory biometric credentials. Mexico is doing both at once. Neither position is inconsistent on its own terms, but a company operating there has to satisfy both at the same time.

Mexico made a biometric credential the country's mandatory identity document

A decree published in Mexico's Diario Oficial de la Federación on 16 July 2025 amended the Ley General de Población so that the CURP containing fingerprints and a photograph becomes the mandatory national identification document, of universal and obligatory acceptance throughout Mexico, issued in both physical and digital form.

The CURP, the Clave Única de Registro de Población, has existed for years as an administrative population registry key. The decree changes what it is. Article 91 Sexies defines it as the single source of identity for a person, and as the mechanism allowing that person to be associated with any record held by authorities and by private parties, for cross-checking, alerts and lookups across databases.

Two limits are worth stating plainly, because the direction of travel invites overstatement. First, the decree does not by itself impose a sanctionable duty on private companies to run CURP verification on their customers; implementing regulations were still pending at the time of writing, and the obligation described in Article 91 Sexies is framed around the CURP's status and reach rather than as a standing verification requirement with penalties attached. Second, the decree text specifies fingerprints and a photograph. Reporting that the credential carries iris data was not borne out by the decree text reviewed for this post.

What is not in doubt is the direction. Mexico is building a state credential intended to be the default identity artefact, and the decree obliges the interior ministry to integrate biometric data into the population registry, including through a programme for children and adolescents to be established within 120 days of the decree taking effect. Verification flows operating in Mexico should expect to read and validate that credential as it scales.

The time between publication and enforcement is collapsing

Chile published Law 21.719 on 13 December 2024 and set it to bind on 1 December 2026, just under two years later. Mexico published its replacement federal data protection law on 20 March 2025 and brought it into force the following day. The gap between those two approaches is the single most useful planning fact in the region.

A long runway is not a promise that the next one will be long. The pattern across the region has been for adaptation windows to shorten, which is an argument for building ahead of an instrument rather than waiting for its final text. A company that treats Chile's remaining months as the planning horizon for the whole region will be late somewhere else.

Chile

Just under two years

Law 21.719 published in the Diario Oficial on 13 December 2024, binding 1 December 2026. Long enough to build a programme, appoint the roles and run the assessments before the agency exists to ask about them. Most of that window has now been spent.

Mexico

One day

The federal data protection law was published on 20 March 2025 and took effect the next day, replacing the 2010 statute and dissolving INAI. There was no adaptation window at all. Companies operating in Mexico moved to a new regime and a new enforcement body simultaneously.

No single market is strictest on everything

Across the six Latin American economies that rewrote their identity rules between March 2025 and December 2026, the tightest rule sits in a different country for each obligation. Peru has the fastest breach clock, Chile the broadest extraterritorial reach, Colombia the strictest consent standard for biometric data, Mexico the only mandatory state credential.

Confirm specifics with local counsel before relying on any row: several of these instruments have implementing regulations still pending, and the region's regulators are new enough that enforcement practice is not yet settled.

MarketCore instrumentAuthorityKey date
ChileLaw 21.719, amending Law 19.628Agency for the Protection of Personal Data, newFull force 1 December 2026
MexicoFederal data protection law 2025, replacing the 2010 statute; Ley General de Población as amendedBody under the federal anti-corruption authority; INAI dissolvedLaw in force 21 March 2025; CURP decree 16 July 2025
BrazilLei Geral de Proteção de DadosANPD, independentEU mutual adequacy 26 January 2026
PeruLaw 29733 and the 2025 regulationNational authority under the justice ministryRegulation in force March 2025
ArgentinaLaw 25.326, reform pendingAgency for Access to Public InformationReform bills before Congress
ColombiaLaw 1581 of 2012, reform draftingSuperintendency of Industry and CommerceReform in the pipeline

On the money laundering side the picture is comparatively settled. The Financial Action Task Force's June 2026 statement lists Bolivia, Venezuela and Haiti as jurisdictions under increased monitoring, the status usually described as the grey list. No major Latin American economy is currently listed, which is a materially better position than the region held a decade ago.

Key takeaways

  • The rules changed almost everywhere that matters. Six of Latin America's seven largest economies replaced, reformed or began enforcing identity and data rules between March 2025 and December 2026.
  • Chile is the near-term deadline. Law 21.719 binds on 1 December 2026, creating an agency where none existed and reaching companies outside Chile that process Chilean residents' data.
  • Mexico built a state credential and a new privacy regime at the same time. The CURP with fingerprints and a photograph is now the mandatory national identification document, while the 2025 federal law arrived with a one-day adaptation window.
  • Brazil is now inside the European data area. Implementing Decision (EU) 2026/179 lets verification data move between the European Union and Brazil without additional transfer instruments.
  • Build to the strictest constraint per dimension. Peru's breach clock, Chile's reach, Colombia's consent standard and Mexico's credential are each the tightest in one dimension. One programme can satisfy all six markets.

Using Didit for Latin America's identity rules

Two of the changes in this post create work a verification provider can carry. Mexico's biometric CURP becomes a credential that onboarding flows have to read and validate rather than simply record: ID Verification at $0.15 per check and NFC Reading at $0.15 per check cover reading a chip or coded credential and checking that what it returns is genuine. Argentina's crypto Travel Rule obligation, which requires originator and beneficiary identity data to travel with a virtual asset transfer, is what Travel Rule at $0.02 per transaction addresses. Where a market's rules make you re-check customers you already have rather than only new ones, Ongoing AML Monitoring runs at $0.07 per user per year and AML Screening at $0.20 per check. Current module prices are listed on the pricing page.

Most of what this post describes is not verification work at all, and it stays with you. Didit does not choose the legal basis on which you process a face scan under Chile's Law 21.719 or Colombia's Law 1581, does not run the risk assessments those regimes require before high-risk processing begins, does not notify Peru's authority when facts about a breach are confirmed, and does not appoint your data protection officer. Verification helps you collect and check identity to the standard these rules expect; the legal basis, the assessments, the notifications and the records remain your organisation's responsibility.

Common questions

When does Chile's new data protection law take effect?

1 December 2026. Law 21.719 was published in Chile's Diario Oficial on 13 December 2024 and amends Law 19.628, creating a dedicated Agency for the Protection of Personal Data. The Biblioteca del Congreso Nacional records the amended law as entering into force on 1 December 2026.

Is Mexico's biometric CURP mandatory?

The decree published in Mexico's Diario Oficial de la Federación on 16 July 2025 makes the CURP containing fingerprints and a photograph the mandatory national identification document, of universal and obligatory acceptance across the country, available in physical and digital form. Article 91 Sexies defines the CURP as the single source of identity, allowing a person to be associated with any record held by authorities and by private parties.

Does Brazil's LGPD apply to companies outside Brazil?

Yes. Brazil's Lei Geral de Proteção de Dados applies where processing relates to offering goods or services to people in Brazil. Since 26 January 2026, Commission Implementing Decision (EU) 2026/179 and Brazil's reciprocal decision allow personal data to move between the European Union and Brazil without additional transfer instruments.

Which Latin American countries are on the FATF grey list?

According to the Financial Action Task Force statement of June 2026, Bolivia, Venezuela and Haiti are under increased monitoring. No major Latin American economy is currently listed.

Is biometric data treated as sensitive in Latin America?

In every major market. Chile's Law 21.719 names biometric data as sensitive data from 1 December 2026. Peru's 2025 data protection regulation, Mexico's federal law and Colombia's Law 1581 all treat biometric data as a special category requiring a stricter basis than ordinary personal data. Brazil's national authority ran a public consultation on biometric processing and binding rules are expected.

Related reading

Sources

  1. Ley 21.719, que regula la protección y el tratamiento de los datos personales — Biblioteca del Congreso Nacional de Chile · published 13 December 2024, in force 1 December 2026
  2. Decreto por el que se reforma la Ley General de Población — Diario Oficial de la Federación, Mexico · 16 July 2025
  3. Ley General de Población, texto vigente — Cámara de Diputados, Mexico · consolidated text
  4. Commission Implementing Decision (EU) 2026/179 on the adequate protection of personal data by Brazil — Official Journal of the European Union · 26 January 2026
  5. EU and Brazil adopt mutual adequacy decisions — European Commission · 26 January 2026
  6. Global Financial Fraud Threat Assessment 2026 — INTERPOL · March 2026
  7. Jurisdictions under increased monitoring, June 2026 — Financial Action Task Force · June 2026

Who wrote this

Tuan Nguyen — Growth · Didit

Writes about identity verification, fraud and compliance at Didit.

Last reviewed 29 Jul 2026 against the sources above

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page