Introduction: A Landmark Ruling on Consumer Privacy
In a significant move reinforcing consumer protection standards in Peru, the National Institute for the Defense of Competition and the Protection of Intellectual Property (Indecopi) has issued a stern warning to the financial sector. The regulatory body has imposed a fine of 74.88 Tax Units (UIT)—amounting to approximately S/ 411,840—against the Banco Internacional del Perú (Interbank).
The sanction, delivered via Final Resolution 033-2026/CC3, stems from the bank’s systematic failure to prove that it had obtained prior, informed, and explicit consent from consumers before bombarding them with unsolicited telemarketing calls. This ruling serves as a stark reminder that in the digital age, a customer’s phone number is not an open invitation for aggressive commercial outreach.
The Core Facts: What Led to the Sanction?
The investigation conducted by Indecopi centered on the widespread practice of "cold calling" used by financial institutions to push credit cards, personal loans, and insurance products. Under the current Consumer Protection and Defense Code, any entity attempting to reach a consumer for commercial purposes via telephone, text message, or electronic communication must be able to demonstrate, with legal certainty, that the recipient has explicitly opted into such communications.
Interbank’s failure was twofold. First, they failed to provide the necessary records proving prior authorization. Second, they attempted to justify their actions by arguing that the customer’s existing banking relationship—holding a credit card or a savings account—constituted implied consent for promotional offers. Indecopi firmly rejected this interpretation, establishing a clear boundary: having a financial contract with a bank does not waive a consumer’s right to privacy regarding unsolicited advertising.
Chronology of the Investigation and Enforcement
The case against Interbank was not the result of a single consumer complaint but rather the culmination of a sophisticated, data-driven investigation.
- Initial Monitoring: Indecopi launched an initiative to monitor the "commercial aggressiveness" of financial institutions, noting an uptick in consumer grievances regarding unwanted calls.
- Data Science Application: To process the sheer volume of telemarketing activities, the regulator employed artificial intelligence and advanced data science tools. These systems scanned vast archives of recorded telephone calls to flag interactions that contained purely commercial content.
- Verification Phase: Once the AI identified potential non-compliant calls, human analysts reviewed the recordings to verify whether any "opt-in" had been secured prior to the initiation of the call.
- Issuance of Resolution 033-2026/CC3: Following the audit, Indecopi’s Commission identified that in numerous instances, the bank was initiating sales pitches immediately upon connection, without verifying if the user had signed a consent form or checked a digital authorization box.
- The Ruling: The Commission determined that Interbank’s practices constituted a breach of consumer protection laws, resulting in the current penalty.
The Fallacy of "Mid-Call Consent"
One of the most critical aspects of this case was Interbank’s attempt to validate their calls by asking for permission during the initial moments of the conversation. The bank argued that by presenting an offer and then asking if the user wanted to hear more, they were operating within the legal framework.
Indecopi’s ruling dismantled this defense. The Commission clarified that "consent" must be "prior, informed, and unequivocal." By the time a representative is already on the line selling a product, the privacy violation has already occurred. The authorization must exist in the bank’s database before the call is placed. Attempting to secure consent during a conversation that was initiated without permission is a classic example of an aggressive commercial method that undermines the spirit of the law.
Implications for the Financial Sector
This ruling sends a seismic shockwave through the Peruvian financial landscape. Banks and fintechs have historically viewed their client lists as a gold mine for cross-selling. However, the Indecopi decision suggests that this era of unchecked outreach is coming to an end.
1. Re-evaluating Opt-In Protocols
Financial institutions are now forced to audit their databases to ensure that every phone number on their "call list" is tagged with a timestamped, verifiable record of consent. Generic "terms and conditions" that include a hidden clause about "receiving offers from partners or affiliates" may no longer suffice under the strict scrutiny of the regulator.
2. The Role of Artificial Intelligence in Regulation
The fact that Indecopi utilized AI to catch these violations is a game-changer. It demonstrates that the regulator is no longer reliant solely on the slow, reactive process of individual consumer complaints. Instead, they can now proactively monitor the industry, making the cost of non-compliance significantly higher and the probability of being caught much greater.
3. The Definition of "Aggressive Methods"
The regulator has clearly defined that "commercial aggressiveness" is not just about the frequency of calls, but about the lack of respect for the consumer’s choice. If a company cannot prove they have permission to call, the act of calling itself is deemed aggressive and, therefore, sanctionable.
Official Responses and Next Steps
As of the latest reports, this decision represents a first-instance administrative ruling. In the complex landscape of Peruvian administrative law, this does not mark the end of the road for the financial institution.
- The Right to Appeal: Interbank maintains the right to appeal this decision to the Specialized Chamber for Consumer Protection at Indecopi. Should they choose to appeal, the case will undergo a higher-level review, which could result in the fine being upheld, reduced, or overturned.
- Indecopi’s Stance: The regulator has remained firm, emphasizing that the protection of the consumer is paramount. Their communication highlights that the rule exists to empower citizens to decide for themselves which businesses are permitted to enter their personal space.
Supporting Data: Understanding the UIT
The fine of 74.88 UIT (S/ 411,840) is calculated based on the Unidad Impositiva Tributaria (UIT), a value used in Peru to standardize fines and tax thresholds. Because the UIT is adjusted annually to account for inflation, these fines are designed to remain punitive regardless of economic fluctuations. A fine of this magnitude is not merely a "cost of doing business" but a significant financial penalty intended to deter future violations.
Conclusion: A New Standard for Privacy
The sanction against Interbank is a milestone in the protection of digital and telephonic privacy in Peru. It establishes that technological capabilities—such as automated dialers and big data profiling—do not grant companies the right to bypass the fundamental requirement of consent.
For the average consumer, this is a victory. It reinforces the right to be left alone and mandates that if a company wants to pitch a product, they must first earn the right to the consumer’s attention. As Interbank contemplates its next move, the rest of the financial industry is watching closely. The message from Indecopi is clear: the era of the "unsolicited pitch" is being reined in, and the consumer’s digital footprint is no longer fair game for aggressive marketing.
Looking forward, we can expect a shift in how financial institutions handle customer data. We will likely see a surge in "consent renewal" campaigns, where banks will reach out—legally, this time—to ask customers to update their communication preferences. Whether this case leads to a permanent change in corporate culture or merely a refinement of legal tactics remains to be seen. However, one thing is certain: the regulator is using the full weight of modern technology to ensure that the law is not just a suggestion, but a strictly enforced boundary.
