On September 15, 2026, Chile's Comisión para el Mercado Financiero (CMF) published the final, binding version of Norma de Carácter General (NCG) N° 576, amending NCG 540 to overhaul the consent management system that reporters to the Registro de Deuda Consolidada (REDEC) must operate. The rule binds every REDEC reportante, Chilean banks, cooperativas and credit originators among them, to digitized consent archives, debtor grant and revocation notices, an internal consent code, a Technical Annex of formats, and three operational APIs.

The norm consolidates feedback from two public consultations, the first between November 2 and December 23, 2025 (more than 200 comments from 22 entities) and the second between May 22 and June 15, 2026 (167 comments from 19 entities). The most consequential change against the consulted draft is the removal of the mandatory encrypted hash for consent storage, replaced by a principles-based, technologically neutral archive standard. The full text and the CMF's Informe Normativo are on the official CMF press release.

What replaced the hash, and why does it lower compliance cost?

The consulted draft required reporters to store consents behind an encrypted code (hash). The final NCG 576 drops that prescriptive mechanism and replaces it with a principles-based obligation: digitized consents must be stored through mechanisms guaranteeing confidentiality, integrity, authenticity, fidelity and verifiability over time. The CMF expects the technologically neutral framing to reduce implementation costs while preserving the evidentiary purpose the hash was meant to serve. Reporters can now choose the storage mechanism that fits their stack, provided it meets the five principles.

Which new debtor-facing duties apply, and through what channels?

Reporters must now notify the debtor whenever consent is granted or revoked, and the notification must carry the date, time, channel and internal consent code, improving transparency and traceability. A Technical Annex defines the required formats for digitized consents, and each consent must carry an assigned internal code that stays traceable across the full life of the reportable operation.

Debtors also gain a new self-service right: they can revoke a third party's authorization before its validity ends directly through the CMF's "Conoce tu Deuda" platform, a revocation path that did not exist in the consulted draft.

What must REDEC reporters integrate, and who can opt out?

Three APIs operationalize the interaction between reporters and the CMF around REDEC: API1 for REDEC information query (already in production), API2 for the CMF to request digitized consents from reporters, and API3 for reporters to send those consents. The norm puts API2 and API3 into the rulebook for the first time, giving reporters a fixed contract to build against.

The rule also creates an ordered exception regime: entities whose business model means they do not access consent-subject debtor information are released from the associated administration requirements, instead of being forced into a one-size-fits-all process. Reporters should assess early whether their model qualifies, since the exception removes a layer of duties rather than the whole framework.

Who is in scope, and how fast must they move?

REDEC reportantes include the major Chilean banks and credit-data reporters (Banco de Chile, BancoEstado, Santander Chile, BCI, Itaú, Scotiabank Chile), cooperativas such as Coopeuch, and other credit originators that feed the consolidated debt registry. Their consent-system, credit-risk and data-governance teams carry the implementation load.

The norm sets a gradual implementation schedule in its Vigencia section rather than a single cliff-edge date, so each duty (digitized archives, debtor notifications, internal codes, API2 and API3 integration, Conoce tu Deuda revocation) has its own phase-in timing. Reporters should pull that section and map each duty to its applicable date.

DutyConsulted draftFinal NCG 576 (September 15, 2026)
Consent storageEncrypted code (hash) requiredPrinciples-based, technologically neutral archive (confidentiality, integrity, authenticity, fidelity, verifiability)
Debtor notificationNot specifiedMandatory on grant and revocation (date, time, channel, internal code)
Consent formatNot standardizedTechnical Annex formats plus internal consent code
Third-party revocationNot availableDebtor revokes via "Conoce tu Deuda" before validity ends
Reporter to CMF integrationPartialThree APIs: API1 (query, live), API2 (CMF requests), API3 (reporters send)
Exception regimeOne-size-fits-allOpt-out for entities that do not access consent-subject data

Continuous, per-jurisdiction monitoring surfaces a rule like this the moment the CMF publishes it, before the phase-in clock starts running.

Subscribe to the free newsletter

Chile: data protection, ANCI OIV wave 2 and open finance resetLive
Monitor Chile's regulatory milestones.
Email report 2 news
You will receive an email report each time something new happens on this topic. Free, no account required.
Subscribe to the newsletter

Next steps for REDEC reporters: confirm your entity is in scope and whether the exception regime fits your business model; pull the Vigencia schedule and assign each duty (digitized archives, debtor notifications, internal codes, API2 and API3 integration) to its phase-in date; brief your data-governance, credit-risk and IT integration teams; and verify your consent archive mechanism satisfies the five principles the CMF now requires rather than the dropped hash. The full normative text and the CMF's Informe Normativo are on the institutional site.