EnglishEspañol
Chile flag

Chile

Chile Data Privacy Laws: Ley 21.719 Reform, New Agency, and December 2026 Entry into Force

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 6 primary sources cited on this page. How we verify our legal content

Chile Data Privacy Laws: Ley 21.719 Reform, New Agency, and December 2026 Entry into Force

Frequently Asked Questions

When does Chile's new data protection law take effect?

Ley 21.719 was published in the Diario Oficial on December 13, 2024 and becomes fully enforceable on December 1, 2026. The 24-month transition period allows organizations to prepare and gives the government time to constitute the Agencia de Protección de Datos Personales. A government bill entered in the Senate on September 1, 2026 (Boletín 18.623-07) would push that date to December 1, 2027, but it is a pending bill, so December 1, 2026 remains the operative date.

Does Ley 21.719 repeal Ley 19.628?

No. Ley 21.719 amends Ley 19.628 (1999) from within, rewriting almost all of it and renaming it the Ley sobre Protección de los Datos Personales. Ley 19.628 in its 1999 form remains the law in force until December 1, 2026, when the consolidated version takes effect.

Does Chile have a data protection authority?

Yes, under the new law. Ley 21.719 creates the Agencia de Protección de Datos Personales as an autonomous, decentralized public law corporation that relates to the President through the Ministry of Economy, with investigative, regulatory, and sanctioning powers. Its three-member Directive Council is not yet seated: the Senate rejected the President's slate on May 20, 2026 for want of a two-thirds quorum, and the June 1, 2026 statutory deadline passed with no council appointed.

What are the maximum penalties for violating Chile's data protection law?

Very serious infractions carry fines of up to 20,000 UTM, about CLP 1.43 billion or roughly USD 1.55 million at September 2026 values. On a repeat offence the Agency may impose up to three times the amount assigned to the infraction, which lifts the ceiling to 30,000 UTM for a repeated serious infraction and 60,000 UTM for a repeated very serious one. For a company that is not a micro, small, or medium enterprise under Ley 20.416, Article 35 lets the fine reach whichever is greater of that tripled amount or a percentage of annual income from sales, services, and other business activity in the last calendar year: 2% for a repeated serious infraction and 4% for a repeated very serious one. Which percentage applies is set by the severity of the infraction, not by whichever figure is larger. Under Article 38 the agency may also suspend processing activities for up to 30 days where it has imposed fines for repeated very serious infractions within a 24-month period, and it may renew that suspension in successive periods of up to 30 days until the controller complies.

Is a Data Protection Officer required under Ley 21.719?

No. Article 50 says a controller may designate a delegado de protección de datos personales, and Article 49 makes the compliance programme it belongs to expressly voluntary. There is no mandatory appointment for public bodies either, and Chile did not adopt the GDPR large-scale-processing trigger. Appointing one inside a certified compliance programme is a mitigating circumstance under Article 36(5) that can reduce a fine.

Can personal data be transferred outside Chile?

Yes, under the new framework. Transfers are permitted to countries that the Agencia determines provide adequate protection, or with appropriate safeguards such as Standard Contractual Clauses (issued by the Ministry of Economy during the transition period) or binding corporate rules. Article 27 also allows a transfer that is specific and not habitual on a closed list of grounds, including the data subject's express consent to that transfer, contractual or pre-contractual necessity, treaty obligations, international judicial cooperation, and urgent medical or health measures.

Is data protection a constitutional right in Chile?

Yes. Article 19 No. 4 of Chile's Constitution guarantees the right to respect and protection of private life. A 2018 amendment added an explicit constitutional guarantee that the processing and protection of personal data shall be carried out in the manner and under the conditions established by law.

What data subject rights does Ley 21.719 provide?

The law provides access, rectification, erasure, objection, blocking (temporary suspension of processing), data portability, and the right to object to automated decision-making and profiling. Two limits matter in practice: portability applies only where the processing is automated and based on consent, and objection is available only in the three cases listed in Article 8. These expand the traditional ARCO rights (access, rectification, cancellation, opposition) that existed under Ley 19.628.

How are children's data protected under the new law?

The law creates a three-tier framework. Processing data of children under 14 always requires parental or guardian consent. For ages 14 to 15, parental consent is required for sensitive data but not for general personal data. For ages 16 and over, the standard adult rules of the law apply.

How does Chile's data protection law relate to its cybersecurity law?

Chile's Cybersecurity Framework Law, Ley 21.663, entered full effect in January 2025 and requires operators of essential services to report significant cybersecurity incidents to the National Cybersecurity Agency (ANCI). From March 2025, that reporting obligation applies. When Ley 21.719 enters force in December 2026, operators in essential sectors may face parallel notification obligations to both the APDP (under data protection law) and ANCI (under cybersecurity law).

Updates

Third-round corrections: the Agency's suspension power stated per Art. 38 (temporary, up to 24 months, renewable); Key Dates reordered chronologically.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Expanded to cover Ley 21.719 in full: eight data protection principles, ARCO+ rights, children's data rules, DPO framework, breach notification and Ley 21.663 intersection, cross-border transfer framework including Standard Contractual Clauses, full penalties analysis, Directive Council appointment status as of May 2026, and business compliance guide.

Reviewed and approved by an editor

Initial publication covering Ley 21.719 overview, constitutional foundation, agency establishment, and key compliance considerations.

Sources and References

  1. Ley 21.719 — Biblioteca del Congreso Nacional de Chile(bcn.cl).gov
  2. FPF Chile New Data Protection Law Context Overview(fpf.org)
  3. Ley 21.806 (D.O. 5 February 2026), art. 54 amending the Consejo Directivo timetable - Biblioteca del Congreso Nacional de Chile(bcn.cl).gov
  4. Ministerio de Economía - Gobierno propone ampliar plazo para implementar la nueva Ley de Protección de Datos (1 September 2026)(economia.gob.cl).gov
  5. Chambers Data Protection Privacy 2026 Chile(practiceguides.chambers.com)
  6. Ley 19.628 consolidated text in force from 1 December 2026 - Biblioteca del Congreso Nacional de Chile(bcn.cl).gov
  7. Senado de Chile - Desestiman propuesta de consejeros para la Agencia de Protección de Datos (20 May 2026)(senado.cl).gov
  8. Chile Mandatory Cybersecurity Incident Reporting Allende Brea(allende.com)
  9. Carey New Supervisory Authority Data Protection Agency Chile(protecciondedatos.carey.cl)
  10. Ministerio de Economía, Resolución Exenta RAEX N° 202503748 (10 December 2025) approving model contractual clauses for international transfers(economia.gob.cl).gov
Share: