Chile compressed twenty-five years of privacy-law evolution into one statute: from a 1999 law with no regulator straight to a GDPR-grade regime with a standalone Agency, fines to 20,000 UTM, a public sanctions register, and extraterritorial reach, effective December 1, 2026, with no post-launch grace period. The two-year runway was the grace period. Companies operating in Chile get a rare, dated certainty: the rules, the regulator, and the deadline are all published; the only variable is whether the program exists when the Agency opens its docket.
| Law | Ley 21.719, published Dec 13, 2024 |
|---|---|
| In force | December 1, 2026 (no cure/grace period) |
| Regulator | Agencia de Proteccion de Datos Personales (new) |
| Max fines | 5,000 / 10,000 / 20,000 UTM by severity |
| Mitigation | Certified infringement-prevention model |
The two-year build, sequenced
Inventory and bases first. Map Chilean processing and assign lawful bases under the new law’s catalogue, flagging consent-dependent flows that could move to contract or legitimate interest with documentation, the same discipline as an LGPD basis register.
Build rights and breach plumbing. Portability and automated-decision rights need engineering lead time; breach notification needs a Chile branch in the incident runbook, alongside Brazil’s 3-day rule.
Paper the borders. Chile’s transfer rules follow the adequacy/safeguards pattern; regional flows through Argentina’s adequacy hub or Brazilian SCCs need reconciling per leg.
Adopt the prevention model early. Certification converts existing GDPR-style controls into a statutory mitigating factor, cheap insurance against a first-year Agency eager to set precedent.
Consent banners and tracker behavior for Chilean visitors will be the Agency’s easiest external check, as they are for every regulator: baseline yours now with a free scan.