A practical analysis of Law No. 21,459 on computer crimes and of the new cybersecurity framework regulation, and how they impact risk management, technology contracts and corporate criminal liability.
The entry into force of Law No. 21,459 (Ley N° 21.459), which established a new catalog of computer crimes, together with Law No. 21,663 (Ley N° 21.663), the Cybersecurity Framework Law (which creates the National Cybersecurity Agency, ANCI), has transformed how companies must manage their technology risks. This article summarizes the practical key points for boards, senior management and compliance teams.
A new catalog of offenses
Law No. 21,459 repealed the former Law No. 19,223 (Ley 19.223) and criminalized conduct such as unlawful access to computer systems, unlawful interception, attacks on the integrity of data and of systems, computer forgery, computer fraud and misuse of devices. For companies, this means that the conduct of third parties, as well as that of their own employees, can carry significant criminal consequences.
Impact on risk management
- Preservation of digital evidence: when an incident occurs, the way evidence is collected and preserved determines its evidentiary value. Having protocols in place beforehand is essential.
- Technology contracts: agreements with software, hosting and cloud service providers must properly allocate security responsibilities.
- Internal policies: a clear, well-known and enforced information security policy reduces exposure and strengthens the company’s position before regulators and courts.
Corporate criminal liability
Law No. 20,393 (Ley N° 20.393) added several computer crimes to the catalog of offenses that can trigger criminal liability for legal entities. Crime prevention models must therefore be updated to include technology risks, with controls, training and a prevention officer who actually oversees these matters.
Recommendation
We recommend that companies carry out a compliance diagnosis covering both the technical and the legal dimensions, and update their prevention models. A planned incident response not only reduces criminal risk; it also protects business continuity and the trust of clients and regulators.
This article is general and informational in nature and does not constitute legal advice for any specific case. If your company is facing an incident or needs to comply with these regulations, contact us for a specific analysis.