Latin America Chile

Chile Data Protection Law 21.719: What Changes in 2026

Chile's new data protection law (Ley 21.719): the December 1, 2026 start date, the new Agency, GDPR-style duties, and fines up to 20,000 UTM, with a readiness plan.

Regulation

Law No. 21.719 (published December 13, 2024), fully reforming Law No. 19.628; in force December 1, 2026

Max Penalty

Up to 5,000 UTM (minor), 10,000 UTM (serious), 20,000 UTM (very serious) per infringement, roughly USD 1.4M at the top tier, with higher caps for repeat conduct

Enforcing Authority

Agencia de Proteccion de Datos Personales (from December 2026); currently no dedicated authority

Official Source

www.bcn.cl

Executive Summary

  • Law 21.719, published December 13, 2024, rewrites Chile's 1999 privacy law (Ley 19.628) into a GDPR-grade regime and creates the country's first data protection authority, the Agencia de Proteccion de Datos Personales.
  • It enters into force December 1, 2026, with no grace period after that date: the Agency can sanction from day one, and the law itself says preparation happens in the two-year runway.
  • The new regime brings lawful bases beyond consent (including legitimate interest), ARCO-plus rights including portability, breach notification, DPIAs for high-risk processing, extraterritorial scope, and international-transfer rules.
  • Fines scale by severity: up to 5,000 UTM for minor, 10,000 UTM for serious, and 20,000 UTM for very serious infringements (a UTM is an inflation-indexed unit, making the top tier roughly USD 1.4 million), with sanctions recorded in a public register.
  • A certified compliance-prevention model (modelo de prevencion de infracciones) operates as a mitigating factor, an Anglo-style compliance-program credit unusual in the region.

Chile compressed twenty-five years of privacy-law evolution into one statute: from a 1999 law with no regulator straight to a GDPR-grade regime with a standalone Agency, fines to 20,000 UTM, a public sanctions register, and extraterritorial reach, effective December 1, 2026, with no post-launch grace period. The two-year runway was the grace period. Companies operating in Chile get a rare, dated certainty: the rules, the regulator, and the deadline are all published; the only variable is whether the program exists when the Agency opens its docket.

LawLey 21.719, published Dec 13, 2024
In forceDecember 1, 2026 (no cure/grace period)
RegulatorAgencia de Proteccion de Datos Personales (new)
Max fines5,000 / 10,000 / 20,000 UTM by severity
MitigationCertified infringement-prevention model

The two-year build, sequenced

Inventory and bases first. Map Chilean processing and assign lawful bases under the new law’s catalogue, flagging consent-dependent flows that could move to contract or legitimate interest with documentation, the same discipline as an LGPD basis register.

Build rights and breach plumbing. Portability and automated-decision rights need engineering lead time; breach notification needs a Chile branch in the incident runbook, alongside Brazil’s 3-day rule.

Paper the borders. Chile’s transfer rules follow the adequacy/safeguards pattern; regional flows through Argentina’s adequacy hub or Brazilian SCCs need reconciling per leg.

Adopt the prevention model early. Certification converts existing GDPR-style controls into a statutory mitigating factor, cheap insurance against a first-year Agency eager to set precedent.

Consent banners and tracker behavior for Chilean visitors will be the Agency’s easiest external check, as they are for every regulator: baseline yours now with a free scan.

Frequently Asked Questions

What applies until December 2026?

The current Ley 19.628 (1999): a thin regime with consent-centric rules, no dedicated regulator, and enforcement through the courts (habeas data actions) and sectoral bodies like the consumer protection agency (SERNAC) for commercial matters and the CMF for financial data. That weakness is exactly why the reform passed. But contracts, systems, and data practices built now will be judged under the new law in December 2026, so 'current law is lax' is a reason to start building, not to wait.

Who will the new law cover?

Controllers and processors established in Chile, plus, GDPR-style, foreign entities that offer goods or services to persons in Chile or monitor their behavior there. Public bodies are covered with sector adjustments. There are no volume thresholds. The law's definitions (personal data, sensitive data including biometric and health data, profiling) track the GDPR closely, and children's data receives heightened protection with the minor's best interest as a guiding principle.

What are the highest-risk obligations to build for?

Five stand out: (1) lawful-basis discipline, consent is no longer the only route, but every purpose needs a documented ground including balanced legitimate interest; (2) data subject rights including access, rectification, deletion, opposition, portability, and rights around automated decisions, on statutory clocks; (3) breach notification to the Agency without undue delay for incidents with material risk; (4) DPIAs for high-risk processing (profiling, sensitive data at scale, systematic monitoring); (5) international-transfer rules requiring adequacy, safeguards, or specific situations. Sensitive-data processing rules are stricter than the GDPR's in places, health and biometric data especially.

How do the fines and the sanctions register work?

Infringements are classified minor, serious, or very serious (Article 35 of the reformed Ley 19.628): up to 5,000 UTM, 10,000 UTM, and 20,000 UTM respectively, with a UTM being Chile's inflation-indexed tax unit (about USD 70), so the ceiling approaches USD 1.4 million, and repeated very serious conduct can raise exposure further, including suspension of processing. Sanctions are entered in the public National Register of Sanctions and Compliance, reputational exposure by design. Aggravating and mitigating factors include cooperation, self-reporting, and whether a certified prevention model was in place.

What is the certified prevention model and why adopt one?

Companies can adopt an infringement-prevention model, a documented compliance program with a designated prevention officer, risk mapping, controls, training, and audit, and have it certified. A certified model in operation is an express mitigating factor in sanctioning and signals diligence in the public register. It borrows from Chile's corporate criminal-liability compliance tradition (Ley 20.393), and for companies already running GDPR or LGPD programs, certification is mostly a packaging exercise over existing controls.

Regulatory Crosswalk

GDPRLGPDArgentina PDPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.