Uruguay’s Cybercrime Law Links New Offences to Faster Fraud Recovery

Uruguay’s 2024 cybercrime law does more than add offences to the Criminal Code. It gives financial institutions tools to share fraud information and temporarily immobilise suspicious funds.

Uruguay published Law No. 20.327 on 25 September 2024. The statute regulates the prevention and repression of cybercrime through four connected elements: new criminal offences, public education, inter-institutional fraud records and procedures for stopping unauthorised transfers.

For security and financial-crime teams, the most useful insight is that criminal classification and operational recovery are treated as part of the same system.

Digital conduct receives specific criminal treatment

The law adds a series of provisions to the Criminal Code covering conduct associated with unauthorised access, interference, damage, fraud, identity misuse and other technology-enabled offences.

Clearer offences help investigators and prosecutors describe what happened without forcing every digital event into a provision written for physical property or traditional deception.

Organisations still need evidence that can support those proceedings. Logs should establish identity, time, action and affected asset. Their integrity and chain of custody matter. A detection platform optimised only for short-term operational alerting may discard information before a victim or prosecutor knows it is needed.

Financial institutions can share fraud records

The law authorises banks and electronic-money issuers to create inter-institutional records containing information used to identify, manage and prevent unauthorised transactions and fraudulent operations.

It also permits relevant information to be shared with judicial authorities for complaints and mitigation. This creates a lawful pathway for coordinated detection, but it is not permission to build an uncontrolled blacklist.

Participating institutions need standards for accuracy, access, retention, dispute handling and security. False or stale information in a shared fraud record can cause serious harm to an innocent customer. Every match should be treated as a risk signal requiring proportionate review, not automatic proof of criminality.

Suspicious funds can be immobilised

When an institution receives reliable notice that funds entered an account through a transfer reported as unknown and unauthorised, it may stop withdrawal or onward transfer up to the amount in dispute.

The institution must inform the Central Bank of Uruguay within one business day. The measure is released if the originating customer does not provide evidence of a complaint to the competent authority within 48 hours, or if a judicial order confirming the immobilisation does not arrive within 30 days. Other statutory release conditions also apply.

This procedure creates a narrow window in which rapid reporting and coordination may prevent stolen funds from disappearing through additional accounts.

Customer support becomes part of incident response

The first reliable signal of authorised-payment fraud may be a customer call, not an automated alert. Front-line staff need to capture the transaction, time, destination and claim accurately and route it immediately.

Fraud, security, legal and operations teams should share a playbook that answers:

  • What qualifies as reliable notice?
  • Who can immobilise funds and how is the limit calculated?
  • When and how is the Central Bank notified?
  • What evidence must the customer provide within 48 hours?
  • How are the destination customer and affected institution contacted?
  • What event releases or extends the measure?

Education is part of the legal response

The law requires a national educational campaign covering personal finance, digital channels and threats including phishing, vishing, smishing, malware, trojans and social engineering.

That recognises a practical reality: technical security controls cannot eliminate fraud that manipulates people into authorising actions. Education should be paired with transaction warnings, step-up verification, cooling-off mechanisms and detection of unusual beneficiaries.

A readiness checklist for financial providers

  • Align fraud definitions and evidence fields with the new offences.
  • Preserve relevant logs for investigation and legal process.
  • Establish governed participation in inter-institutional records.
  • Build the one-business-day, 48-hour and 30-day steps into case management.
  • Train customer support to recognise unauthorised-transfer reports.
  • Test cross-institution communication during a simulated mule-account event.
  • Monitor false positives and provide a route for correction.

Uruguay’s law shows that cybercrime response is not complete when an alert is closed. The system should also preserve evidence, reduce repeat fraud and, where possible, interrupt the movement of the proceeds.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *