Skip to main content

App Compliance in Latin America: ISV Guide to 5 Markets

Marina Campos
Marina CamposJuly 27, 20265 min. read
App Compliance in Latin America: ISV Guide to 5 Markets

An ISV (Independent Software Vendor, a software company that sells its product to other businesses) based in Berlin, Austin, or Tel Aviv closes a SaaS deal with a customer in Sao Paulo. The contract is signed. Then compliance asks: where is the data stored, who processes payments, what tax document does the client's finance team need, does the company have a legal entity in Brazil?

The answer to the last question is usually no. And that is where the real work begins.

This guide walks through the five largest markets in Latin America and builds the compliance matrix every ISV must resolve before selling: data protection, electronic invoicing, local entity requirements, and security certifications in Brazil, Mexico, Argentina, Colombia, and Chile.

Prerequisites: what the ISV needs before starting

The compliance structure for an app in Latin America does not start from scratch. Three foundations need to be in place before any regulatory step.

The first foundation is contractual. The ISV needs Terms of Service and a Privacy Policy that cover the processing of personal data of data subjects in Brazil, Mexico, Argentina, Colombia, and Chile. Translating the English document is not enough. Each country demands specific information: the purpose of processing, the legal basis, third-party sharing, retention periods, and a contact channel for the data protection officer.

The second foundation is technical. The app must implement role-based access controls, maintain audit logs for every operation involving personal data, and support selective data export and deletion for a single data subject. Without this, responding to an access request within the 15-calendar-day deadline that Brazil's LGPD requires is simply not feasible.

The third foundation is fiscal. The ISV must decide whether to operate with its own local entity in each country or use an intermediary that issues invoices in local currency and withholds taxes at source. This decision determines the entire compliance timeline.

Step 1: structure data protection in each country

Personal data protection is the requirement with the broadest cross-border reach. None of the five countries requires servers to be located within national territory, but all impose conditions on international data transfers.

Brazil: LGPD (Law 13.709/2018)

Brazil's General Data Protection Law has express extraterritorial reach. Article 3 of the LGPD establishes that the law applies to any processing operation that occurs in Brazilian territory, that aims to offer goods or services to individuals in Brazil, or whose data were collected in the country. An ISV selling SaaS to Brazilian companies is subject to the LGPD even without an office in Sao Paulo.

Four obligations deserve immediate attention from the ISV.

Appointment of a data protection officer. Article 41 of the LGPD requires every controller to designate a Data Protection Officer (DPO) and publicly disclose their identity and contact channel. ANPD Resolution 2/2022 simplifies the requirement for small businesses, but the obligation to maintain a channel accessible to data subjects and the ANPD remains.

Records of processing activities. Article 37 requires controllers and processors to maintain documented records of each processing activity: data categories, purposes, legal bases, recipients, and retention periods. The ANPD may request these records at any time.

Contractual clauses for international transfers. ANPD Resolution 19/2024 established standard contractual clauses for international data transfers. An ISV that processes Brazilian user data on servers outside Brazil must incorporate these clauses into its contracts with clients and with sub-processors (cloud providers, analytics tools, support platforms).

Incident notification. ANPD Resolution 4/2023 set a 2-business-day deadline to notify the ANPD of security incidents that may pose relevant risk to data subjects. The clock starts when the controller becomes aware of the incident, not on the date of the breach.

Mexico: LFPDPPP 2025

Mexico enacted a new Federal Law on Protection of Personal Data Held by Private Parties in March 2025, replacing the 2010 law and dissolving the INAI, transferring supervision to the Secretaria Anticorrupcion y Buen Gobierno.

The ISV needs three things in Mexico.

Privacy notice in Spanish. The Mexican privacy notice is the central document in the relationship with the data subject. It must describe the purposes of processing, distinguish which activities depend on consent and which are optional, and inform data subjects of their ARCO rights (access, rectification, cancellation, opposition). The response deadline for ARCO requests is 20 business days.

Consent for sensitive data. Sensitive data requires express and written consent, with an autograph or electronic signature. The consent standard was tightened by the 2025 law: consent obtained through deceptive practices, pre-checked boxes, or bundled authorizations is invalid.

International transfers based on consent. The Mexican framework does not have an adequacy decision mechanism or standard contractual clauses like Brazil's. International transfers operate under the model of prior data subject consent. The ISV must obtain this consent in a specific and documented manner.

Argentina: Law 25.326

Argentina operates under Personal Data Protection Law 25.326, enacted in 2000, which the European Commission recognized as providing an adequate level of protection. Three reform bills are pending in Congress in 2026 (S-0644/2025, 1948-D-2025, and 0904-D-2025), but none has been enacted as of July 2026.

Three practical obligations for the ISV.

Database registration with the AAIP. Every personal database must be registered with the Agencia de Acceso a la Informacion Publica, with annual renewal. The estimated cost per database is USD 50 to 200.

Express and documented consent. Data collection requires informed, express, and revocable consent with an audit trail. Unchecked checkboxes, clear language, and logging of the moment and form of consent are technical implementation requirements.

Sub-processor agreements. Every vendor that receives personal data (AWS, Stripe, email marketing tools) needs a Data Processing Agreement that establishes the limits of processing. Without a DPA, the ISV bears sole liability for any breach by the sub-processor.

Colombia: Law 1581 of 2012

Colombia regulates personal data protection through Statutory Law 1581 of 2012, supplemented by Decrees 1377 of 2013 and 886 of 2014. The Superintendencia de Industria y Comercio (SIC) is the enforcement authority.

The ISV needs four items in Colombia.

Privacy policy and notice. Every company that processes personal data in Colombia must maintain a privacy policy accessible to data subjects and an internal procedure for responding to inquiries and complaints.

Registration in the National Database Registry. Companies with assets exceeding 100,000 UVT (approximately USD 1.3 million) must register their databases in the RNBD and renew the registration annually between January 2 and March 31.

Model contractual clauses for international transfers. The SIC published External Circular 003/2025 in December 2025, introducing model contractual clauses for international data transfers and transmissions. Use is optional, but adherence makes the obligations binding.

Processor agreements. An ISV that contracts data processors in Colombia must enter into specific agreements defining security, confidentiality, and purpose-limitation obligations.

Chile: Law 21.719 (effective December 1, 2026)

Chile enacted a new data protection law in December 2024, Law 21.719, replacing Law 19.628 of 1999 and creating the Agencia de Proteccion de Datos Personales. The law enters full force on December 1, 2026.

The 24-month transition period ends this year. For an ISV planning to sell in Chile in 2026, the time to prepare is now. Five points deserve attention.

Data Protection Impact Assessment. The law requires a DPIA whenever processing presents high risk to data subjects' rights. This includes large-scale processing of sensitive data, profiling, and automated decision-making.

Breach notification. Security incidents that pose risk to data subjects' rights must be reported to the Agency without unjustified delay, with a descriptive record of the nature of the breach.

Data portability. The data subject has the right to receive a copy of their data in a structured, commonly used electronic format and to transfer it to another controller.

Security measures. The controller must adopt technical and organizational measures appropriate to the risk, considering the state of the art and the cost of implementation.

Penalties. Fines of up to 20,000 UTM (approximately USD 1.5 million) for the most serious infractions, potentially reaching 2% or 4% of annual revenue from sales and services in Chile for repeat offenses.

The regulatory analysis for Mexico, Argentina, Colombia, and Chile is based on public research and does not substitute local legal counsel. Consult the Distribution Counsel for independent verification of each regime before making contractual or fiscal decisions.

Step 2: resolve fiscal compliance and electronic invoicing

Every country in Latin America operates its own electronic invoicing system with real-time validation by the tax authority. The ISV does not issue a traditional paper invoice: it generates a digitally signed document, transmits it to the tax authority, receives authorization, and only then delivers it to the customer.

Brazil: NF-e and NFS-e

Brazil operates two electronic invoicing systems. The Nota Fiscal Eletronica (NF-e) covers goods and interstate transactions. The Nota Fiscal de Servicos Eletronica (NFS-e) covers services, including SaaS. Each municipality has its own ISS rules, creating over 5,000 potential regimes.

An ISV selling SaaS to Brazilian companies must issue NFS-e with tax withholding at source: ISS (2% to 5%, depending on the municipality), PIS (1.65%), and COFINS (7.6%) under the non-cumulative regime. A relevant fiscal distinction for the ISV: CIDE (10%) applies to SaaS and technical services. The exemption under section 1-A, article 2 of Law 10.168/2000 applies exclusively to pure software licenses without technology transfer, a fiscal category distinct from SaaS. Under the Tax Reform (LC 214/2025), PIS and COFINS are abolished in 2027 and replaced by CBS. ISS will be gradually replaced by IBS between 2029 and 2032, with full extinction in 2033. An ISV operating through the Nexforce Marketplace receives a domestic invoice from Nexforce in Brazilian reais, without needing to register as an NFS-e issuer.

Mexico: CFDI 4.0

The Comprobante Fiscal Digital por Internet (CFDI) is mandatory for all transactions. Since January 2026, the Mexican Tax Reform requires that CFDI reflect real and true transactions, under penalty of presumed falsity. The SAT may verify the reality of the transaction and, if it considers the CFDI false, publish the issuer's name in the Official Gazette.

Since May 2026, technology platforms operating in Mexico must grant the SAT permanent online access to tax and operational information, organize data by individual transaction, make it available within one business day after the transaction, and archive it for five years.

An ISV without a local entity in Mexico needs a fiscal representative or an authorized intermediary to issue CFDI with SAT validation.

Argentina: Factura Electronica ARCA

Argentina operates its electronic invoicing system through the ARCA (formerly AFIP) WebService wsfev1, under General Resolution 4.291. Starting September 2026, the CondicionIVAReceptorId field becomes mandatory for all invoices, and it will no longer be possible to issue receipts without reporting the recipient's VAT status.

The ISV needs a CUIT (tax ID) and a digital certificate to issue Argentine electronic invoices. Without a local entity, the path is an authorized fiscal intermediary.

Colombia: Factura Electronica DIAN

The DIAN requires the Factura Electronica de Venta with prior real-time validation, under Resolution 00165 of 2023 (version 1.9 of the Technical Annex). Each invoice must contain the CUFE (Unique Electronic Invoice Code), generated after DIAN validation, and a QR code.

To become an issuer, the ISV needs a Colombian NIT, a digital signature certificate, and DIAN test-environment qualification with submission of 2 invoices, 1 debit note, and 1 credit note. An ISV without a local entity needs a DIAN-authorized Technology Provider or an intermediary that issues on its behalf.

Chile: DTE SII

The Chilean Documento Tributario Electronico uses a clearance system: each invoice is sent to the SII, validated against the XML schema, and receives an SII Electronic Stamp (TED) that functions as a fiscal seal. The format is unique, with a maximum of 60 line items per document.

The ISV needs a Chilean RUT (tax ID), a digital certificate purchased from an SII-accredited provider, and software certification in the SII testing environment. The VAT rate is 19%. A foreign ISV without a permanent establishment may register through the SII simplified portal for digital services, but needs a legal representative in Chile to interact with the tax authority.

Step 3: decide on local entity versus distribution platform

The local-entity decision is the most structuring choice in the compliance timeline. Opening a branch or subsidiary in each of the five countries costs between USD 15,000 and 50,000 per country in the first year, including accounting, legal, and tax registration fees, plus recurring accounting and tax compliance costs.

The Nexforce Marketplace eliminates the need for a local entity in all five countries. An ISV distributing its SaaS through the Marketplace receives payments in Brazilian reais (BRL) in Brazil, without needing an Argentine CUIT, Chilean RUT, Colombian NIT, Mexican RFC, or its own Brazilian CNPJ for billing. Nexforce issues the domestic invoice in local currency to the end customer, withholds taxes at source, and manages fiscal compliance in each country.

What the Marketplace does not cover: data protection, localized terms of use, and security certifications. These requirements are the ISV's responsibility, regardless of the distribution channel.

Step 4: implement security certifications and compliance

Enterprise customers across Latin America are embedding security requirements into their software procurement processes. An ISV that cannot answer a security questionnaire loses deals before price negotiation begins.

Three certifications are relevant in the region.

ISO 27001. The most widely recognized certification. The Colombian DIAN requires ISO 27001, or a commitment to obtain it within 18 months, for authorized technology providers. Medium and large Brazilian customers include it as a knockout criterion in software procurement.

SOC 2. Companies selling into the Brazilian and Mexican financial sector face SOC 2 Type II reporting requirements, especially when processing financial data or credit card information.

LGPD readiness. Brazil's ANPD considers the existence of a documented compliance program as a mitigating factor when calculating fines (article 52, paragraph 1, item VII). A well-structured LGPD program reduces exposure to fines of up to BRL 50 million per infraction.

Verification: how to confirm compliance is complete

The table below summarizes the core requirements for each country, organized by compliance type. The ISV can use this matrix as an entry checklist.

RequirementBrazilMexicoArgentinaColombiaChile
Data protection lawLGPD (Law 13.709/2018)LFPDPPP 2025Law 25.326 (2000)Law 1581/2012Law 21.719 (eff. Dec/2026)
Mandatory DPOYes (art. 41)No (recommended)No (bills pending)No (but requires responsible area)Yes (public sector and large scale)
Database registrationRecommended (RDPA)NoMandatory (AAIP)Mandatory (RNBD, above 100,000 UVT)Recommended (operations registry)
International transferANPD standard clauses (Res. 19/2024)Data subject consentConsent or adequate countrySIC model clauses (Circular 003/2025)SCC or adequacy determination
Incident notification2 business days (ANPD)Affected parties (reasonable time)Recommended (reasonable time, AAIP)15 business days (SIC)Without unjustified delay (APDP)
Electronic invoicingNFS-e (municipal)CFDI 4.0 (SAT)Factura Electronica (ARCA, RG 4.291)Factura Electronica (DIAN, Res. 165/2023)DTE (SII, clearance)
VAT/Equivalent rateISS 2-5% (until 2029; CBS replaces PIS/COFINS 2027; IBS replaces ISS 2029-2033, LC 214/2025)VAT 16% (8% border)VAT 21%VAT 19%VAT 19%
Required certificationISO 27001 (recommended)ISO 27001 (recommended)ISO 27001 (recommended)ISO 27001 (mandatory for PST)ISO 27001 (recommended)
Local representative neededNoYes (FR or REP)Yes (CUIT + tax rep.)Yes (NIT + legal rep.)Yes (RUT + legal rep.)

Six questions the ISV should answer before activating the first customer in each country.

  1. Is the privacy notice published in Brazilian Portuguese, Mexican Spanish, Argentine Spanish, Colombian Spanish, and Chilean Spanish, with the information required by each local law?
  2. Is the data protection officer's contact channel accessible, and is someone monitoring data subject requests?
  3. Do client contracts include data processing agreements (DPA) and the standard contractual clauses for international transfers where required?
  4. Does the billing system issue electronic fiscal documents in the format required by each country, with real-time validation by the local authority?
  5. Does the company have a legal representative or authorized intermediary to interact with tax authorities in countries where it has no local entity?
  6. Does the incident response plan cover the notification timeline for each jurisdiction (2 business days in Brazil, immediate reporting in Chile, reasonable time in Argentina)?

Common mistakes in Latin American expansion

Three errors repeat across nearly every market entry process in the region.

Translating the GDPR privacy policy into Portuguese and assuming it covers the LGPD. The LGPD has 10 legal bases versus 6 under the GDPR, requires a DPO without a size exception, and imposes a 15-calendar-day deadline for responding to data subjects. A policy copied from Europe leaves the ISV exposed from the first customer.

Opening a local entity in each country before validating the product. The cost of opening and maintaining five entities in the first year exceeds USD 75,000 to 250,000. For [[[[[ISVs](/en/blog/aws-marketplace-isv-guide)](/en/blog/cloud-marketplace-isv-guide-aws-azure-gcp)](/en/blog/aws-marketplace-saas-practical-guide-isvs)](/en/blog/aws-marketplace-isv-guide)](/en/blog/cloud-marketplace-isv-guide-aws-azure-gcp) with an average ticket below USD 50,000 per customer, the structure does not pay for itself before year three. The Nexforce Marketplace eliminates this cost and lets the ISV validate product-market fit before deciding whether and where to establish a physical presence.

Ignoring regulatory updates. Mexico enacted the LFPDPPP 2025 in March, redesigned the data protection authority, and has not yet published implementing regulations. Colombia issued model contractual clauses in December 2025. Chile's law enters force in December 2026. The region is not static. Compliance is not a project with a delivery date; it is a continuous process.

Frequently asked questions

Does the ISV need a local server in each country? No. None of the five countries requires data residency within national territory. All, however, regulate international transfers and require contractual clauses or specific consent for sending data abroad.

Which security certification is mandatory to sell in the region? None is legally mandatory for SaaS sales, but ISO 27001 is required by Brazilian enterprise customers and SOC 2 is a de facto requirement in the Mexican and Brazilian financial sector.

Does the Nexforce Marketplace eliminate the need for local legal counsel? No. The Marketplace resolves the fiscal and local-entity side. The ISV still needs local legal counsel for terms of use, privacy policies, and DPA agreements adapted to each jurisdiction.

How long does it take to structure compliance across all five countries? Between 4 and 8 months, depending on the ISV's contractual and technical maturity. The longest lead time is obtaining security certifications, which can take 6 to 12 months.

Can the ISV sell to government clients in Latin America? Yes, but the public procurement process in each country requires prior registration with SICAF (Brazil), CompraNet (Mexico), or the local equivalent, plus the corresponding security certifications.

References and further reading

  • [Software importation guide for [[[[[ISVs](/en/blog/aws-marketplace-isv-guide)](/en/blog/cloud-marketplace-isv-guide-aws-azure-gcp)](/en/blog/aws-marketplace-saas-practical-guide-isvs)](/en/blog/aws-marketplace-isv-guide)](/en/blog/cloud-marketplace-isv-guide-aws-azure-gcp) (buyer perspective)](https://nexforce.ai/blog/importacao-software-guia-completo)
  • [Cloud marketplace guide for [[[[[ISVs](/en/blog/aws-marketplace-isv-guide)](/en/blog/cloud-marketplace-isv-guide-aws-azure-gcp)](/en/blog/aws-marketplace-saas-practical-guide-isvs)](/en/blog/aws-marketplace-isv-guide)](/en/blog/cloud-marketplace-isv-guide-aws-azure-gcp) (distribution channel)](https://nexforce.ai/blog/cloud-marketplace-isvs)
  • Law 13.709/2018 (LGPD Brazil) and ANPD Resolution 19/2024
  • Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (Mexico, DOF 20-mar-2025)
  • Law 25.326 (Argentina) and Decree 1558/2001
  • Statutory Law 1581 of 2012 (Colombia)
  • Law 21.719 (Chile, DOF 13-dec-2024, effective 1-dec-2026)
  • DIAN Resolution 00165 of 2023 (Colombia, electronic invoicing)
  • ARCA General Resolution 4.291 (Argentina, electronic invoicing)
  • SII, Documentos Tributarios Electronicos, Certification Manual (Chile)
Nexforce

Sell software in Latin Americawith no setup and saving 50%

Distribute your SaaS through the Nexforce platform scaling sales channels in a simple way

Run Simulation

Related articles