Insurance and Reinsurance Alert - February 2026
For more information, contact:
Themes
IMPACT OF LEGISLATIVE DECREE NO. 1741 ON THE INSURANCE SECTOR
Legislative Decree No. 1741, published on February 13, 2026, introduces a specific but substantive amendment to Article 12-A of Law No. 30096 – the Computer Crimes Law – in order to clarify the scope of the criminal exception applicable to activities carried out by regulated sectors, including the insurance market, more clearly defining the typical scope of the crime of acquiring, possessing, or illicitly trafficking computer data. With this, the reform seeks to prevent legitimate practices necessary for the operation of formal markets—such as the processing, transfer, and analysis of data carried out by supervised entities, in accordance with sectoral regulatory frameworks and personal data protection regulations—from being misinterpreted as criminally relevant conduct, thus restoring legal certainty and a proper balance with the operational continuity of authorized activities.
1. Regulatory Context and Identified Problem
Article 12-A, originally incorporated by Legislative Decree No. 1700, criminalizes the acquisition, possession, or trafficking of illegally obtained computer data, conduct that often constitutes a relevant input for the commission of crimes such as extortion, digital fraud, and other forms of cybercrime. However, the previous wording of its third paragraph created a risk of expansive interpretation that could encompass—unforeseen by the legislator—legitimate data processing, transfer, and circulation activities carried out by supervised entities in the regular course of their operations.
In the case of the insurance sector, the processing of personal and financial data is a structural and necessary function for underwriting policies, risk assessment and pricing, claims management, fraud investigation and prevention, as well as for reinsurance operations. These activities are strictly regulated by the Superintendency of Banking, Insurance and AFP (SBS) and subject to the standards of the personal data protection regulations, so any criminal ambiguity could generate legal uncertainty and an inhibitory effect on ordinary processes authorized by sectoral regulation.
2. Content of the Amendment Regarding the Insurance Sector
Legislative Decree No. 1741 expressly specifies that the acquisition, possession, or transfer of information by entities within the insurance system does not constitute the crime of illicit data trafficking, provided that:
- These operations are inherent to their business;
- They are carried out within the framework of current sector regulations; and
- They are subject to the supervision of the competent authority.
These clarifications operate as an exclusion of criminal liability, meaning that such conduct is not criminally relevant, as long as it remains within the legal purposes and limits of the insurance sector.
Specifically, the amended Article 12-A establishes the following in its third paragraph:
“The acquisition, possession, exchange, or processing of computer data is exempt from criminal liability when such conduct is carried out with the express authorization of the data subject, in accordance with Law No. 29733, the Personal Data Protection Law, in compliance with a judicial or administrative order issued in accordance with the law, or in the legitimate exercise of fundamental rights, legally recognized functions, or activities carried out in the stock market, financial, pension, or insurance sectors, provided that there is no purpose of illicit exploitation or improper commercialization of the information.”
3. Scope and Practical Implications for the Insurance Market
This amendment strengthens the legal certainty of the insurance sector by clearly distinguishing between the illicit trafficking of computer data (illegal markets, stolen or unauthorized databases) and the legitimate processing of information inherent to insurance activity.
It also reduces the risk of criminalizing regulated practices, such as the exchange of information with reinsurers, adjusters, experts, brokers, or technology providers, provided that such operations are carried out in accordance with applicable regulations and the principles of purpose limitation and proportionality.