Logo de la Comisión para el Mercado Financiero (CMF)
Versión español

CMF issues regulation strengthening REDEC’s consent management system

The regulation underwent two public consultations. It considers technological neutrality when managing consents, as well as gradual implementation to allow entities to have the necessary time prior to its entry into force.

September 15, 2026 - The Financial Market Commission (CMF) issued today the final version of the regulation strengthening consent management system for reporting entities under the Consolidated Debt Registry (REDEC, for its Spanish acronym) set forth in General Rule No. 540.

This proposal aims to strengthen debtor protection, promote better practices among reporters, and facilitate the CMF's supervisory work. It is an initiative part of the REDEC's continuous improvement framework and reflects commitment with regulatory transparency and efficiency.

The final version is the result of two public consultation processes. The first one, held between November 2 and December 23, 2025, received over 200 comments from 22 entities. The second consultation took place between May 22 and June 15, 2026, with 167 comments from 19 entities. Said feedback was key to perfect this regulatory project, covering issues regarding technological aspects, implementation timeframes, and information to be submitted to the CMF.

The regulation's key aspects include:

  • Consent Preservation: Reporting entities are required to store digitized consent forms using mechanisms that ensure their confidentiality, integrity, authenticity, accuracy, and verifiability over time. This approach replaces the initial requirement for an encrypted code (hash) - which was previously subject to public consultation - with a principles-based, technologically neutral framework expected to reduce implementation costs for reporting entities.
  • Debtor Notification: A requirement is now in place to notify debtors when consent is granted or revoked. This notification must include the consent date, time, channel, and internal code, thereby improving process transparency and traceability.
  • Digital Consent and Internal Code: A Technical Annex defines the required formats for digital consents, and an internal code must be assigned to ensure effective traceability throughout the entire duration of the reportable transaction.
  • Exception Provision: An orderly exception provision is established for those entities that, due to their business model, decide not to access debtor information subject to consent - thereby exempting them from administrative requirements associated with such information.
  • Integration Through APIs: Regulatory provisions establish the terms of three APIs to facilitate interaction between reporting entities and the CMF regarding the REDEC: API1 for retrieving information from the REDEC, which is currently in development; API2 for digital consent requests issued by the CMF; and API3 for reporting entities to submit such consents.
  • Revocation of Authorized Third Parties: Establishes a procedure to allow debtors to revoke authorization granted to a third party through the CMF's "Know Your Debt" platform before the authorization expires.

The regulation will be implemented gradually, as indicated in the "Validity" section, which facilitates the operational adoption of the new requirements by supervised entities.

The complete text of the regulation is available on the CMF website, along with a Regulatory Report that outlines the main provisions and assesses its impact.