Chile
Chile Data Privacy Laws: Ley 21.719 Reform, New Agency, and December 2026 Entry into Force
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 6 primary sources cited on this page. How we verify our legal content

Chile governs personal data under Ley 21.719, a comprehensive reform enacted in August 2024 that rewrites and renames Ley 19.628 rather than repealing it. The new law introduces a dedicated supervisory authority, GDPR-aligned rights, and penalties up to 20,000 UTM, with full enforcement starting December 1, 2026.
Quick Answer: Chile's Data Protection Transition
Chile is midway through a fundamental shift in how personal data is regulated. For nearly 25 years, the country operated under Ley 19.628 (1999), the first comprehensive data protection statute in Latin America. That law had no data protection authority, no framework for international transfers, and minimal enforcement mechanisms, leaving individuals largely dependent on private litigation to vindicate their rights.
Ley 21.719, enacted in August 2024 and published in the Diario Oficial on December 13, 2024, changes all of that. Technically it is an amending statute. Its first permanent article introduces modifications into Ley 19.628 and renames that law the Ley sobre Protección de los Datos Personales, so from December 1, 2026 the operative text is the consolidated Ley 19.628 and the article numbers cited throughout this guide are articles of that consolidated law. The rewrite draws heavily from the European Union's General Data Protection Regulation (GDPR). It creates a new supervisory authority, expands data subject rights, introduces multiple lawful bases for processing, establishes cross-border transfer rules, and imposes meaningful penalties.
Full enforcement begins December 1, 2026. Organizations that process personal data belonging to Chilean residents, whether located inside or outside Chile, should be actively preparing now.
Ley 19.628: The Foundation (1999)
Chile's original data protection law, Ley 19.628 sobre Protección de la Vida Privada (Law on the Protection of Private Life), entered into force in August 1999. At the time, it was a pioneering statute in Latin America and helped establish the concept of personal data protection across the region.
Over time, however, the law's limitations became impossible to ignore. The most glaring gap was the absence of a supervisory authority. There was no dedicated government body empowered to investigate complaints, issue guidance, or levy fines. Enforcement depended almost entirely on individuals bringing civil actions in the courts, a costly and impractical route for most data subjects.
Other shortcomings included a narrow set of lawful bases for processing (consent dominated, with limited alternatives), no provisions governing international data transfers, no right to data portability, and penalties so low as to be economically irrelevant. Legislative efforts to modernize the law began as early as 2017, but the process stretched eight years before Congress finally passed the reform in August 2024.
Constitutional Fundamental Right: Article 19 No. 4
Data protection in Chile enjoys explicit constitutional status. Article 19 No. 4 of the Constitución Política de la República de Chile guarantees the right to respect and protection of private life and the honor of the person and their family.
A constitutional reform enacted in 2018 strengthened this foundation by adding an express guarantee that the processing and protection of personal data shall be carried out in the manner and under the conditions established by law. This amendment elevated data protection to the same tier as other fundamental rights protected under Article 19, giving it constitutional weight that constrains both government and private actors.
The constitutional grounding is more than symbolic. It means that challenges to data processing practices can be raised before constitutional courts, and that any legislative or regulatory measure restricting data protection rights must meet a heightened standard of justification.

Ley 21.719: The Reform in Full
Enactment and Timeline
Chile's Congress approved Ley 21.719 on August 26, 2024, ending eight years of legislative debate. The President promulgated the law and it was published in the Diario Oficial on December 13, 2024.
The law does not take effect immediately. It provides a 24-month transition period, calculated from the date of publication, giving organizations time to adapt and giving the government time to build out the new regulatory agency. Full enforcement begins on December 1, 2026.
During the transition, the existing Ley 19.628 remains operative as the current law. The new agency is being constituted, and the Ministry of Economy has begun issuing implementing instruments, including Standard Contractual Clauses for international data transfers.
Scope and Territorial Reach
The law applies to the processing of personal data by any natural or legal person, including public bodies, whether the processing is automated or not. Article 1 subjects all such processing to the law, and Article 2(o) defines tratamiento as any operation, set of operations, or technical procedure, automated or not, that collects, processes, stores, communicates, transmits, or uses personal data.
Chile did not enact the GDPR condition that the data form part of a filing system, so unstructured non-automated processing sits inside the law.
Ley 21.719 has extraterritorial reach. It applies to controllers and processors located outside Chile when they offer goods or services to data subjects in Chile, or when they monitor the behavior of individuals on Chilean territory. This GDPR-style territorial extension means that foreign businesses serving Chilean customers cannot avoid the law simply by not having a physical presence in the country.
Article 1 excludes only two things: processing carried out in the exercise of the freedoms to express opinion and to inform regulated by the laws referred to in Article 19 No. 12 of the Constitution, and processing by natural persons in relation to their own personal activities. The media carve-out is narrow. Where a media organization processes data for any purpose other than opining and informing, the law applies to it in full.
National security is not an exclusion. Article 24 places the processing of sensitive data by competent public bodies for criminal enforcement, national security, defense and foreign policy, declared emergencies, and matters covered by statutory secrecy under a special regime. Those bodies remain bound by the Article 3 principles and by Article 19 No. 4 of the Constitution, and the Agencia may issue instructions on how those guarantees apply to them.
The Eight Data Protection Principles
Ley 21.719 introduces eight explicit data protection principles that govern all processing operations:
Lawfulness and Loyalty: Data must be processed on a legitimate legal basis and in a manner that is fair to data subjects.
Purpose Limitation: Data may only be collected for specified, explicit, and legitimate purposes and may not be processed in ways incompatible with those purposes.
Proportionality: Only data that is adequate, relevant, and limited to what is necessary for the stated purpose may be collected and processed.
Data Quality: Personal data must be accurate, complete, and kept up to date. Controllers must take reasonable steps to ensure that inaccurate data is erased or rectified.
Security: Controllers must implement appropriate technical and organizational measures to protect data against unauthorized access, alteration, loss, or destruction, taking into account the state of the art, costs, and the nature of the data.
Transparency and Information: Data subjects must be clearly informed about the identity of the controller, the purposes of processing, the recipients of data, and the rights available to them.
Confidentiality: Persons who process data must treat it with confidentiality and may not use it for unauthorized purposes.
Accountability: Controllers are responsible for demonstrating compliance with the law and must be able to document and justify their data processing practices.
Legal Bases for Processing
One of the most consequential changes in Ley 21.719 is the move from a consent-centric model to a multi-basis framework, similar to the GDPR approach. The recognized lawful bases are:
- Consent of the data subject (freely given, specific, informed, and unambiguous)
- Contract performance or pre-contractual measures at the request of the data subject
- Legal obligation imposed on the controller
- Economic, financial, banking, or commercial obligations owed to or by the data subject
- Legitimate interests of the controller or third parties, provided those interests are not overridden by the rights of the data subject
- Legal proceedings or the establishment, exercise, or defense of legal claims
Consent for sensitive data requires an explicit affirmative act. Controllers bear the burden of proving that valid consent was obtained and must make withdrawal as easy as giving consent.
Sensitive Data Categories
Article 2(g) designates a heightened protection category for sensitive data, covering data that reveals:
- Ethnic or racial origin
- Political, union, or trade-association affiliation
- Socio-economic situation
- Ideological or philosophical convictions
- Religious beliefs
- Health data
- Human biological profile
- Biometric data
- Sex life, sexual orientation, and gender identity
Socio-economic situation is the Chilean category with no GDPR analogue, and it pulls a large volume of ordinary commercial, credit, and marketing processing into the sensitive-data regime. Read it alongside Article 13(a), which permits processing of data on economic, financial, banking, or commercial obligations, including data on the subject's socio-economic situation, where the processing follows the rules in Título III.
Processing sensitive data requires explicit consent as a default rule. Exceptions exist for data voluntarily made public by the subject, non-profit organizations pursuing legitimate interests among their members, vital interests (life and health), legal proceedings, and processing required by law.
Data Subject Rights (ARCO+ Framework)
The reform preserves and significantly expands the traditional ARCO rights (access, rectification, cancellation/erasure, opposition) and adds new rights aligned with the GDPR. Under Ley 21.719, data subjects have:
Right to Access: Confirm whether personal data is being processed and obtain a copy, including information about the source of the data, the recipients, the purpose, and the retention period.
Right to Rectification: Request correction of inaccurate, outdated, or incomplete data. The controller must act within a prescribed period and notify third parties to whom the data was communicated.
Right to Erasure: Request deletion of data when the original purpose has been fulfilled, consent has been withdrawn, processing is unlawful, or a legal obligation requires erasure.
Right to Object: Oppose processing in the three cases Article 8 lists: where the legal basis is the controller's legitimate interests, where processing is exclusively for direct marketing including profiling, and where the data came from a publicly accessible source and there is no other legal basis. Article 11(d) requires the request to state the ground relied on, and where that ground is legitimate interests the data subject must briefly justify the request and the controller may keep processing if it shows overriding compelling legitimate grounds. Objection does not lie against scientific, historical, or statistical research necessary for a public function or an activity of public interest.
Right to Block: Obtain temporary suspension of processing while a rectification, erasure, or objection request is pending, and, in the Article 7 erasure cases, as an alternative to erasure itself (Article 8 ter). This is Chile's counterpart to the GDPR right to restriction of processing rather than a right the GDPR lacks. Under Article 11 the controller must answer a blocking request within two working days and may not process the data in the meantime.
Right to Data Portability: Receive personal data in an electronic, structured, generic, and commonly used format that allows transfer to another controller. Article 9 sets two conditions that must both be met: the processing is carried out by automated means, and it is based on the data subject's consent. Unlike the GDPR, processing based on a contract does not trigger portability in Chile.
Right Not to Be Subject to Automated Decision-Making: Object to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects.
Controllers must respond to data subject requests within prescribed timeframes, and non-compliance constitutes a sanctionable infraction.
Rules for Children's Data
Ley 21.719 creates a three-tier framework for processing personal data of minors, distinguishing by age:
- Under 14 years: Parental or guardian consent is required for all processing of personal data.
- Ages 14 to 15: Parental or guardian consent is required specifically for processing of sensitive data; general personal data may be processed on other legal bases.
- Ages 16 and over: The general adult rules of the law apply.
This graduated approach reflects recognition that adolescents have developing capacity for informed decision-making, while ensuring heightened protection for the youngest data subjects.
Data Protection Impact Assessments
Controllers engaged in processing activities that are likely to result in a high risk to the rights and freedoms of data subjects must carry out a Data Protection Impact Assessment (DPIA) before commencing the activity. The general test turns on the nature, scope, context, technology used, and purposes of the processing. Separately, Article 15 ter always requires an assessment in four cases: systematic and exhaustive evaluation of personal aspects based on automated processing or decisions, including profiling, producing significant legal effects; massive or large-scale processing of data of any kind, not only sensitive data; processing that involves systematic observation or monitoring of a publicly accessible area; and processing of sensitive and specially protected data under the exceptions to consent.
The DPIA must assess the necessity and proportionality of the processing, the risks to data subjects, and the measures planned to address those risks. Where the assessment shows the processing to be high risk, the controller may consult the Agencia to obtain recommendations (Article 15 ter, final paragraph). Chilean law imposes no mandatory prior consultation and no bar on proceeding without one, unlike the GDPR.
Data Protection by Design and Default
Controllers must implement technical and organizational measures both at the time of designing processing systems and at the time of the actual processing, ensuring that data protection principles are embedded by default. This means that, by default, only the personal data necessary for each specific purpose is processed, minimizing the volume of data collected, the extent of processing, the storage period, and access.
Transparency Disclosures and the Breach Register
Chile did not enact a GDPR-style record of processing activities. Two documentation duties apply instead.
Article 14 ter requires the controller to keep a defined set of information permanently available to the public on its website or an equivalent channel. That set includes the data processing policy with its date and version, the identity of the controller and its legal representative, the contact channel for data subject requests, the categories of data processed, the recipients, the purposes and the legal basis for each processing operation, the security measures adopted, the rights available and the route to complain to the Agencia, any transfer to a third country and whether that country offers an adequate level of protection, retention periods, the source of the data, the right to withdraw consent, and the existence of automated decision-making with meaningful information about the logic applied.
Article 14 sexies requires a separate internal register of security-breach communications, recording the nature of each breach, its effects, the categories of data and approximate number of data subjects affected, and the measures taken.
The Agencia de Protección de Datos Personales
Structure and Oversight
Article 30 creates the Agencia de Protección de Datos Personales (APDP) as an autonomous public law corporation of a technical character, decentralized, with its own legal personality and assets. It is not independent of the executive branch. The same article provides that the agency relates to the President of the Republic through the Ministry of Economy, Development and Tourism, and its councillors are nominated by the President and ratified by the Senate, so the legislature is structurally involved as well.
The agency is governed by a Directive Council of three Councilors. The President of the Republic nominates the candidates, who must be ratified by two thirds of the Senate before assuming office. The three nominees (Joselyn Biermann, Roberto Godoy, and Matías Larraguibel) were proposed by the executive for terms of 6, 4, and 2 years respectively.
On May 20, 2026 the Senate plenary rejected that slate. The proposal did not reach the two-thirds quorum required for ratification, so the Sala set the President's message aside. As of September 2026 the agency still has no Directive Council.
The statutory deadline has already passed. Artículo cuarto transitorio of Ley 21.719, as amended by Article 54 of Ley 21.806 (Diario Oficial, February 5, 2026), requires the first designation of the councillors to be made six months before the law enters into force, which means by June 1, 2026. The presidential proposal must be made in a single act in the window running from 80 to 60 days before that deadline, and if the Senate does not rule on it by the deadline the proposal is deemed accepted without further procedure. Councillors count as appointed from the Senate's agreement or from the lapse of that deadline. Until the law is in force the Council may exercise only the functions in Article 30 bis (a), (b), (g) and (h) and Article 30 ter, and any general instruction it issues binds only once the law takes effect. Members of the SEGPRES ministerial advisory commission created by decreto N° 12 of 2025 may not sit on the first Council.
Agency Powers
Once operational, the agency will have broad regulatory, investigative, and sanctioning powers:
- Regulatory: Issue binding instructions, approve codes of conduct and certification mechanisms, publish adequacy determinations for international transfer purposes, and develop implementing regulations.
- Investigative: Receive and process complaints from data subjects, initiate ex officio investigations, conduct audits and inspections of controllers and processors, and require the production of information and documents.
- Sanctioning: Issue warnings, reprimands, and cease-and-desist orders; impose administrative fines; order the rectification, erasure, or blocking of data; and order the temporary suspension of processing activities for up to 24 months, renewable (Art. 38); it has no power of permanent suspension.
- International cooperation: Work with foreign data protection authorities, facilitate cross-border complaint handling, and enter into cooperation agreements.
The agency also maintains the National Register of Sanctions and Compliance, where sanctions are recorded for five years. This public registry creates reputational consequences for repeat violators beyond the financial penalties.
Judicial Review
Sanctions imposed by the agency are subject to judicial review before the Courts of Appeals, providing a procedural safeguard for affected parties.

Data Breach Notification
Notification Obligations
When a security incident affecting personal data occurs, Ley 21.719 imposes a two-track notification obligation.
First, the controller must notify the Agencia de Protección de Datos Personales through the most expeditious means possible and without undue delay when the incident creates a reasonable risk to the rights and freedoms of data subjects.
Second, the controller must also notify the affected data subjects directly when the breach involves sensitive data, data of children under 14, or data relating to economic, financial, banking, or commercial obligations. Article 14 sexies attaches no separate high-risk threshold to that second duty. The notice must use plain language and identify the data affected, the possible consequences, and the remedial measures adopted, and it must reach each affected person individually, or by publication in a mass national medium if individual notice is impossible.
The law does not establish a fixed number of hours within which notification must occur, unlike the GDPR's 72-hour rule. The agency is expected to issue specific guidance on acceptable timeframes during the transition period.
Cybersecurity Law Coordination
Chile's data breach notification obligations under Ley 21.719 operate alongside the country's Cybersecurity Framework Law, Ley 21.663, which entered full effect in January 2025. Ley 21.663 requires operators of essential services and critical information infrastructure to report significant cybersecurity incidents to the National Cybersecurity Agency (ANCI) as of March 2025. Organizations in sectors such as energy, healthcare, and financial services may therefore face parallel breach notification obligations to both the APDP and ANCI.
Cross-Border Data Transfers
The Prior Regime
Under Ley 19.628, there were no provisions governing cross-border transfers of personal data. Organizations transferred data internationally without a legal framework addressing adequacy or safeguards, creating significant uncertainty.
The New Framework
Ley 21.719 introduces a layered framework for international transfers, drawing from the GDPR model.
Adequacy: Transfers are freely permitted to countries or international organizations that the agency determines provide an adequate level of personal data protection. The agency will publish and maintain a list of adequate jurisdictions.
Appropriate Safeguards: In the absence of an adequacy determination, transfers may proceed where the controller implements appropriate safeguards, including:
- Standard Contractual Clauses as approved or issued by the agency (the Ministry of Economy issued initial Standard Contractual Clauses during the transition period)
- Binding corporate rules for multinational group transfers
- Certification mechanisms or compliance programs approved by the agency
Derogations: Article 27 allows a transfer without an adequacy decision and without appropriate safeguards only where the transfer is specific and not habitual, so these grounds cannot carry routine or recurring flows. The listed grounds are the data subject's express consent to a specific, determined transfer; specific banking, financial, or stock-exchange transfers made under the laws that govern them; obligations under international treaties ratified by Chile and in force; cooperation, information-exchange, or supervision agreements signed by public bodies for the exercise of their functions; transfers expressly authorized by law for a determined purpose; international judicial cooperation; the conclusion or performance of a contract between the data subject and the controller, or pre-contractual measures taken at the data subject's request; and urgent medical or health measures. Chilean law has no public-interest derogation of the kind GDPR Article 49 provides.

Penalties Under Ley 21.719
Infraction Classification
Ley 21.719 establishes a three-tier classification of infractions, each carrying graduated penalties. The UTM is a monthly indexed unit reset by the Servicio de Impuestos Internos, so the conversions below are a snapshot: they use the September 2026 value of 1 UTM = CLP 71,721 and an observed rate of about CLP 927 per US dollar.
Minor infractions (infracciones leves): A written reprimand or a fine of up to 5,000 UTM (about CLP 359 million, roughly USD 387,000). Minor infractions include technical non-compliance such as incomplete privacy notices.
Serious infractions (infracciones graves): Fines of up to 10,000 UTM (about CLP 717 million, roughly USD 774,000). Serious infractions include failure to comply with data subject rights requests, inadequate security measures, and processing without a valid legal basis.
Very serious infractions (infracciones gravísimas): Fines of up to 20,000 UTM (about CLP 1.43 billion, roughly USD 1.55 million). Very serious infractions include large-scale processing of sensitive data without consent, major security failures leading to breaches, and repeated non-compliance after agency orders.
Aggravated Penalties for Repeat Offenders
Reincidencia arises when the controller has been sanctioned on two or more occasions in the last 30 months for breaching this law (Article 36(a)). Where it applies, Article 35 lets the Agency impose a fine of up to three times the amount assigned to the infraction committed. That multiplier alone lifts the ceiling to 30,000 UTM for a repeated serious infraction and 60,000 UTM for a repeated very serious one.
A second arm applies to a controller that is not a micro, small, or medium enterprise as defined in artículo segundo of Ley 20.416. Where such a company reoffends, the fine may reach whichever is greater of that tripled amount or:
- Repeated serious infractions: 2% of annual income from sales, services, and other business activity in the last calendar year
- Repeated very serious infractions: 4% of annual income from sales, services, and other business activity in the last calendar year
Two points are easy to get wrong. The comparison is against the tripled figure, not against the base 20,000 UTM ceiling. And because Ley 20.416 defines micro, small, and medium enterprises together, medium-sized companies sit outside the revenue arm as well.
Additional Sanctions
Beyond financial penalties, the agency may issue formal warnings and public reprimands (recorded in the National Register), order the cessation of unlawful processing, require the erasure or correction of unlawfully processed data, and suspend processing activities for up to 30 days where it has imposed fines for repeated very serious infractions within a 24-month period. That 24-month window is not the same as the 30-month reincidencia window that drives the fine multiplier. The suspension does not reach data the controller has already stored, may be partial or total, cannot be ordered where it would harm data subjects, and may be renewed indefinitely in successive periods of up to 30 days if the controller does not comply with the suspension order.
Public sector entities are subject to the same substantive standards, though the penalty mechanisms account for their public nature.
Data Protection Officers
Ley 21.719 creates no mandatory DPO, for anyone. Article 50 provides that a controller may designate a delegado de protección de datos personales, and Article 49 makes the compliance programme in which that role sits expressly voluntary. Chile did not enact the GDPR Article 37 large-scale-processing trigger, so there is no threshold at which an appointment becomes compulsory.
The pull is a penalty discount rather than a duty. The delegado is the first required element of the voluntary compliance programme, and holding the certificate issued under Article 51 is a statutory mitigating circumstance under Article 36(5) that the Agency weighs when it sets a fine.
Public bodies are not required to appoint one either. Artículo quinto transitorio of Ley 21.719 says only that a public body that does establish a delegado must fill the role with an official already on its staff, which presupposes the choice.
Where a DPO is appointed, the individual must possess specialist knowledge of data protection law and practice, act independently without conflicts of interest, have sufficient resources and support from senior management, and serve as the primary contact point for the Agencia and for data subjects exercising their rights.
Micro, small, and medium-sized enterprises may fulfill the DPO function through their owners or senior leadership rather than through a dedicated position.
Transition Period and Implementation Timeline
Key Dates
| Event | Date |
|---|---|
| Ley 21.719 approved by Congress | August 26, 2024 |
| Published in Diario Oficial | December 13, 2024 |
| Ministry of Economy issues Standard Contractual Clauses | 2025 (transition period) |
| Ley 21.806 amends the Council appointment timetable | February 5, 2026 |
| Directive Council nominees heard by joint Senate commissions | May 13, 2026 |
| Senate rejects the three Directive Council nominees | May 20, 2026 |
| Statutory deadline for the first Council designation (lapsed) | June 1, 2026 |
| Government bill to postpone entry into force to December 2027 (Boletín 18.623-07) | September 1, 2026 |
| Full entry into force, unchanged unless that bill passes | December 1, 2026 |
What Happens During the Transition
During the 24-month window, several parallel processes are underway.
The agency has not been constituted. The government proposed three candidates for the Directive Council and the Senate rejected them on May 20, 2026. Since Ley 21.806 amended the timetable, the law required the first designation to be made six months before entry into force, that is by June 1, 2026, so that deadline has lapsed with no council in place.
Ley 19.628 remains the operative law. Complaints and enforcement during the transition period continue under the existing framework, with its limited enforcement mechanisms.
The Ministry of Economy and other government bodies are developing implementing instruments. Standard Contractual Clauses for international transfers were issued during 2025. The agency, once constituted, will issue binding instructions, adequacy determinations, guidance on DPIAs, and other regulatory materials.
Recent Developments (2025 to 2026)
December 2024: Ley 21.719 published in the Diario Oficial, starting the 24-month countdown to enforcement.
2025: Ministry of Economy issues Standard Contractual Clauses for international data transfers, providing organizations with an early compliance tool for cross-border transfers.
January 2025: Chile's Cybersecurity Framework Law, Ley 21.663, enters full effect. From March 2025, essential service operators are required to report significant cybersecurity incidents to the ANCI, creating a parallel notification regime that intersects with Ley 21.719's breach notification obligations.
February 2026: The change to the appointment timetable rides in the general public-sector pay-adjustment bill entered in the Chamber of Deputies on January 6, 2026 (Boletín 18.036-05), whose Articles 54 and 55 carry it. That bill is enacted as Ley 21.806 and published in the Diario Oficial on February 5. Article 54 rewrites artículo cuarto transitorio of Ley 21.719, moving the first designation of the Directive Council from within the 60 days before entry into force to six months before it, and adding a rule that a slate the Senate fails to rule on by that deadline is deemed accepted.
May 2026: On May 20 the Senate plenary rejects the President's proposal of Joselyn Biermann, Roberto Godoy, and Matías Larraguibel. The slate did not reach the two-thirds quorum required for ratification, so the Sala set the message aside.
June 2026: The June 1 statutory deadline for designating the first Directive Council passes with no council appointed.
September 2026: A government bill, Boletín 18.623-07, is entered in the Senate on September 1 as a presidential mensaje in the first constitutional trámite, carrying suma urgencia, and the Ministry of Economy announces it the same day. It would postpone the entry into force of Ley 21.719 from December 1, 2026 to December 1, 2027, raise the Directive Council from three to five members with a quorum of three, and bring the first appointment forward. The bill is pending. Until it is enacted, December 1, 2026 remains the operative date.
Business Compliance Guide
Organizations processing personal data of Chilean residents should use the remaining months before December 2026 to take these steps:
Data Mapping: Identify all categories of personal data collected and processed, document purposes, legal bases, retention periods, and data flows including transfers to processors and third parties.
Transparency Disclosures: Publish and keep current the Article 14 ter information set on your website, and maintain the internal register of security-breach communications required by Article 14 sexies. Chile has no GDPR-style record of processing activities, so a ROPA is a useful internal tool here, not a legal requirement.
Legal Bases Review: Audit existing consent mechanisms and identify alternative legal bases where processing rests on inadequate grounds. Update privacy notices to reflect all required disclosures.
Data Subject Rights Procedures: Implement operational workflows for responding to access, rectification, erasure, portability, objection, and automated decision-making requests within the required timeframes.
International Transfers: Review all cross-border data flows. Where adequacy determinations are not available, implement Standard Contractual Clauses or other approved safeguards.
Security Measures: Assess technical and organizational security measures against the law's requirements. Implement a breach detection and notification procedure that can respond to incidents without undue delay.
DPIA Process: Identify processing activities that require a DPIA and conduct assessments before December 2026. Where an assessment shows high risk, you may ask the agency for recommendations, but no prior consultation is required.
DPO Consideration: No organization is required to appoint a delegado de protección de datos. Decide whether appointing one inside a voluntary compliance programme is worth the mitigating credit it earns under Article 36(5).
Processor Agreements: Review and update contracts with data processors to include mandatory clauses on confidentiality, security, purpose limitation, and incident notification to meet regulatory deadlines.
Children's Data: Verify that any processing of data belonging to users under 16 complies with the tiered age-based consent requirements under the law.
For information on how Chile regulates audio and video recording, see Chile Recording Laws.
This article is for informational purposes only and does not constitute legal advice. Data protection laws are subject to change; consult a qualified attorney for advice specific to your situation.
Frequently Asked Questions
When does Chile's new data protection law take effect?
Ley 21.719 was published in the Diario Oficial on December 13, 2024 and becomes fully enforceable on December 1, 2026. The 24-month transition period allows organizations to prepare and gives the government time to constitute the Agencia de Protección de Datos Personales. A government bill entered in the Senate on September 1, 2026 (Boletín 18.623-07) would push that date to December 1, 2027, but it is a pending bill, so December 1, 2026 remains the operative date.
Does Ley 21.719 repeal Ley 19.628?
No. Ley 21.719 amends Ley 19.628 (1999) from within, rewriting almost all of it and renaming it the Ley sobre Protección de los Datos Personales. Ley 19.628 in its 1999 form remains the law in force until December 1, 2026, when the consolidated version takes effect.
Does Chile have a data protection authority?
Yes, under the new law. Ley 21.719 creates the Agencia de Protección de Datos Personales as an autonomous, decentralized public law corporation that relates to the President through the Ministry of Economy, with investigative, regulatory, and sanctioning powers. Its three-member Directive Council is not yet seated: the Senate rejected the President's slate on May 20, 2026 for want of a two-thirds quorum, and the June 1, 2026 statutory deadline passed with no council appointed.
What are the maximum penalties for violating Chile's data protection law?
Very serious infractions carry fines of up to 20,000 UTM, about CLP 1.43 billion or roughly USD 1.55 million at September 2026 values. On a repeat offence the Agency may impose up to three times the amount assigned to the infraction, which lifts the ceiling to 30,000 UTM for a repeated serious infraction and 60,000 UTM for a repeated very serious one. For a company that is not a micro, small, or medium enterprise under Ley 20.416, Article 35 lets the fine reach whichever is greater of that tripled amount or a percentage of annual income from sales, services, and other business activity in the last calendar year: 2% for a repeated serious infraction and 4% for a repeated very serious one. Which percentage applies is set by the severity of the infraction, not by whichever figure is larger. Under Article 38 the agency may also suspend processing activities for up to 30 days where it has imposed fines for repeated very serious infractions within a 24-month period, and it may renew that suspension in successive periods of up to 30 days until the controller complies.
Is a Data Protection Officer required under Ley 21.719?
No. Article 50 says a controller may designate a delegado de protección de datos personales, and Article 49 makes the compliance programme it belongs to expressly voluntary. There is no mandatory appointment for public bodies either, and Chile did not adopt the GDPR large-scale-processing trigger. Appointing one inside a certified compliance programme is a mitigating circumstance under Article 36(5) that can reduce a fine.
Can personal data be transferred outside Chile?
Yes, under the new framework. Transfers are permitted to countries that the Agencia determines provide adequate protection, or with appropriate safeguards such as Standard Contractual Clauses (issued by the Ministry of Economy during the transition period) or binding corporate rules. Article 27 also allows a transfer that is specific and not habitual on a closed list of grounds, including the data subject's express consent to that transfer, contractual or pre-contractual necessity, treaty obligations, international judicial cooperation, and urgent medical or health measures.
Is data protection a constitutional right in Chile?
Yes. Article 19 No. 4 of Chile's Constitution guarantees the right to respect and protection of private life. A 2018 amendment added an explicit constitutional guarantee that the processing and protection of personal data shall be carried out in the manner and under the conditions established by law.
What data subject rights does Ley 21.719 provide?
The law provides access, rectification, erasure, objection, blocking (temporary suspension of processing), data portability, and the right to object to automated decision-making and profiling. Two limits matter in practice: portability applies only where the processing is automated and based on consent, and objection is available only in the three cases listed in Article 8. These expand the traditional ARCO rights (access, rectification, cancellation, opposition) that existed under Ley 19.628.
How are children's data protected under the new law?
The law creates a three-tier framework. Processing data of children under 14 always requires parental or guardian consent. For ages 14 to 15, parental consent is required for sensitive data but not for general personal data. For ages 16 and over, the standard adult rules of the law apply.
How does Chile's data protection law relate to its cybersecurity law?
Chile's Cybersecurity Framework Law, Ley 21.663, entered full effect in January 2025 and requires operators of essential services to report significant cybersecurity incidents to the National Cybersecurity Agency (ANCI). From March 2025, that reporting obligation applies. When Ley 21.719 enters force in December 2026, operators in essential sectors may face parallel notification obligations to both the APDP (under data protection law) and ANCI (under cybersecurity law).
Updates
Third-round corrections: the Agency's suspension power stated per Art. 38 (temporary, up to 24 months, renewable); Key Dates reordered chronologically.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Expanded to cover Ley 21.719 in full: eight data protection principles, ARCO+ rights, children's data rules, DPO framework, breach notification and Ley 21.663 intersection, cross-border transfer framework including Standard Contractual Clauses, full penalties analysis, Directive Council appointment status as of May 2026, and business compliance guide.
Reviewed and approved by an editor
Initial publication covering Ley 21.719 overview, constitutional foundation, agency establishment, and key compliance considerations.
Sources and References
- Ley 21.719 — Biblioteca del Congreso Nacional de Chile(bcn.cl).gov
- FPF Chile New Data Protection Law Context Overview(fpf.org)
- Ley 21.806 (D.O. 5 February 2026), art. 54 amending the Consejo Directivo timetable - Biblioteca del Congreso Nacional de Chile(bcn.cl).gov
- Ministerio de Economía - Gobierno propone ampliar plazo para implementar la nueva Ley de Protección de Datos (1 September 2026)(economia.gob.cl).gov
- Chambers Data Protection Privacy 2026 Chile(practiceguides.chambers.com)
- Ley 19.628 consolidated text in force from 1 December 2026 - Biblioteca del Congreso Nacional de Chile(bcn.cl).gov
- Senado de Chile - Desestiman propuesta de consejeros para la Agencia de Protección de Datos (20 May 2026)(senado.cl).gov
- Chile Mandatory Cybersecurity Incident Reporting Allende Brea(allende.com)
- Carey New Supervisory Authority Data Protection Agency Chile(protecciondedatos.carey.cl)
- Ministerio de Economía, Resolución Exenta RAEX N° 202503748 (10 December 2025) approving model contractual clauses for international transfers(economia.gob.cl).gov