CiberLATAMbywhalemate

Chile's Law 21,719 on Personal Data

Chile’s Law 21,719 takes effect Dec. 1, 2026, creating a new agency, stronger rights, fines up to 20,000 UTM, and GDPR-like rules.

Whalemate Labs · AI-assisted researchPublished:36 min read

Chile’s Law No. 21,719 takes effect on Dec. 1, 2026, and overhauls the country’s personal data protection regime. The law effectively replaces Law No. 19,628, ends the old model of weak penalties and no dedicated oversight, and creates a Personal Data Protection Agency with control, investigation, and direct sanction powers. It also sets a two-year transition period for companies and public agencies to update processes, contracts, forms, governance, and response mechanisms for data subject rights.

Research reviewed for this report shows the reform applies to any organization that processes personal data belonging to people located in Chile, whether public or private, regardless of company size or where systems are hosted. The law broadens the definition of personal data, adds eight processing principles, strengthens data subject rights under the ARSOPB framework, and introduces a specific right against automated decisions, including explanation and human review requirements. Operationally, it requires organizations to show how data is collected, stored, used, and shared, which is especially sensitive for companies handling large volumes of information, e-commerce, SaaS, healthcare, finance, and cross-border operations.

The penalty regime also changes scale. The sources consulted describe minor, serious, and very serious violations, with fines of up to 5,000, 10,000, and 20,000 UTM, respectively. They also note that repeat serious or very serious violations can triple the base caps and, for some large companies, lead to proportional sanctions of between 2% and 4% of annual sales and service revenue. The law also adds a specific obligation to notify breaches to the agency within 72 hours of the controller becoming aware of the incident, with notice to data subjects when risk is high. The material contains no IOCs or malware elements because this is a regulatory reform, not a technical campaign.

In international comparisons, several analyses say the new Chilean law moves closer to GDPR standards, but keeps its own logic on issues such as international transfers. The research indicates that Chile does not fully adopt the European essential equivalence test, instead using a standard of similar or higher safeguards, with authority review for certain jurisdictions. That makes the law relevant for foreign entities, especially Brazilian ones, that process data of Chilean residents through e-commerce, SaaS, digital health, logistics, or fintech. The full body of material points to a structural reform with a fixed effective date, a new regulator, traceability requirements, and an adjustment window that closes in December 2026.

Executive summary

Chile’s Law No. 21,719 takes effect on Dec. 1, 2026, and introduces a structural change in personal data protection in Chile, with direct impact on public and private organizations that process information about people located in the country, including foreign companies operating from Brazil. The material reviewed shows the law effectively replaces the previous framework under Law No. 19,628, creates a specialized authority with oversight and sanction powers, and sets a two-year transition period for operational alignment.

The reform is not just about higher penalties. It also resets the compliance baseline. The research consolidates eight processing principles, expands the data subject rights catalog to the ARSOPB family, adds opposition to automated decisions, requires traceability in how data is handled, and obliges organizations to prove the full chain of collection, use, storage, and sharing. For sectors with high data volume, such as finance, healthcare, SaaS, and e-commerce, the regulatory jump is material.

On sanctions, the sources agree on a tiered system for minor, serious, and very serious violations, with fines of up to 5,000, 10,000, and 20,000 UTM. Several analyses add that repeat serious or very serious violations can raise the ceiling to three times the base, with references to a practical maximum of 60,000 UTM or, for certain companies not considered small, fines equal to 2% or 4% of annual revenue. The file also introduces the possibility of suspension of processing in certain cases and differentiated limitation periods of 3, 4, and 5 years.

The most sensitive technical dimension involves breaches, profiling, and automated decisions. The law requires notification to the Personal Data Protection Agency within 72 hours of the controller becoming aware of the incident, and notice to data subjects when risk is high. Several sources also note that certain high-risk processing activities will require impact assessments and additional controls in an environment that analysts compare with European rules, though with important differences in international transfers.

There are no signs of exploitation, malware, attacker infrastructure, or published IOCs in the material. The value of this research is regulatory and operational. The deadline is not a threat campaign, but a countdown to compliance that is already running for any organization processing personal data of Chilean residents, including cross-border providers in Brazil.

Context and background

Law No. 21,719 appears in the material as the deepest reform of Chile’s personal data protection regime in decades. Several analyses say it replaces and modernizes Law No. 19,628, in force since 1999, which is described as lacking its own enforcement body and effective penalties. Tecnom.ai characterizes those earlier sanctions as almost symbolic, a view several authors use to explain why the reform is treated as an institutional turning point.

The legislative process was also long. ESG Hoy says the bill began in 2017, was published in the Official Gazette on Dec. 13, 2024, and left a two-year implementation period before it takes effect. Exige tu Seguro and other outlets agree that the transitory first article sets Dec. 1, 2026, as the full application date, with a transition for companies and public agencies. In parallel, the AGPD urged caution about any delay and publicly noted that, as of August 2026, the effective date remained tied to that schedule.

The immediate backdrop is a legal architecture that shifts the center of gravity. Before, personal data disputes depended more on isolated litigation and fragmented oversight. Now, the new agency is empowered to investigate on its own initiative, handle complaints, and impose sanctions directly. The Universidad Central de Chile and Actualidad Jurídica highlight that shift as a move from a reactive model to one based on active accountability by data controllers.

The material also places the law in a broader regional conversation. Several texts present it as converging with GDPR-type standards, especially on data subject rights, impact assessments, breaches, and institutional oversight. At the same time, others stress that the Chilean law does not simply copy the European model, particularly on international transfers, where it keeps a logic of similar or higher standards rather than the GDPR’s essential equivalence test.

Table of key facts

Date Event Source Confidence
2017 The reform bill began its legislative process ESG Hoy confirmed
Dec. 13, 2024 Law No. 21,719 was published in the Official Gazette ESG Hoy, Exige tu Seguro, IA Governance confirmed
Nov. 25, 2024 Doctrinal sources mention the law’s promulgation DOE Actualidad Jurídica confirmed
Dec. 1, 2026 Full effective date of Law No. 21,719 Exige tu Seguro, PressLatam, Paramodigital confirmed
Dec. 1, 2026 General application period begins for public-sector obligations Alayia Trust confirmed
2026 AGPD calls for careful review of any delay ESG Hoy, TrendTIC, EstadoDiario confirmed
2026 The Personal Data Protection Agency is created Exige tu Seguro, PressLatam, BPM Ingeniería confirmed
2026 Data subject rights are expanded to ARSOPB Exige tu Seguro, SuperPyME confirmed
2026 A sanction regime of up to 20,000 UTM is set PressLatam, Anami, Actualidad Jurídica DOE confirmed
2026 Breach notification within 72 hours is introduced Cifrid, Ley 21.663.info, IA Governance confirmed
2026 Rules on profiling and automated decisions are introduced DOE Actualidad Jurídica confirmed
2026 Anonymization is defined as an irreversible process R&V Soluciones Legales confirmed
2026 Publicly accessible sources are removed as an independent lawful basis Universidad Central de Chile confirmed
2026 Limitation periods of 3, 4, and 5 years are set Alayia Trust confirmed

Operation timeline

Date Event Actor/vector Verified source
2017 Start of the reform bill Chilean legislative process ESG Hoy
Dec. 13, 2024 Publication in the Official Gazette Chilean state ESG Hoy, Exige tu Seguro
Aug. 2026 Possible delay discussed, with no approved reform Chilean government and industry groups TrendTIC, EstadoDiario, AGPD
Dec. 1, 2026 The law takes effect and general application begins Public and private organizations Exige tu Seguro, PressLatam
Dec. 1, 2026 Special duties for public bodies begin Chilean public sector Alayia Trust
From Dec. 1, 2026 onward New oversight and sanction framework activates Personal Data Protection Agency Exige tu Seguro, BPM Ingeniería
2017Start billDec 13, 2024Publicationofficial2026Delayed indebateDec 1, 2026Validityfull
Law 21,719, regulatory milestones — Brief timeline of Chile's data protection reform.

Attack chain and TTPs

This research does not describe a technical intrusion, phishing campaign, or software exploit. The material focuses on the regulatory framework of Law No. 21,719 and its compliance impact. There is therefore no classic attack chain, no exploitation sequence, and no forensic artifact that could be mapped to an incident response case.

The closest thing to an operational chain is the sequence of obligations the law activates for any personal data processing activity. First, the organization must identify a valid legal basis. Then it has to document purposes, minimization, security, transparency, and accountability. Later, it must enable rights exercise mechanisms, response within deadlines, documentary traceability, breach notification, and, for high-risk processing, impact assessments and additional controls.

That flow matters because it turns compliance into evidence. A published privacy policy is no longer enough. The sources consulted stress that the authority and data subjects will be able to demand proof of how each decision was made, under what basis, who was involved, and what security measure supported the processing. In that sense, the law’s operational chain looks more like continuous traceability than a simple compliance statement.

Regulatory TTP Description Source
Lawful basis Processing must rely on a valid basis, including consent Confidata, Universidad Central de Chile
Rights management Access, rectification, deletion, objection, portability, and blocking Exige tu Seguro, SuperPyME
Objection to automated decisions The data subject may request explanation and human review Exige tu Seguro, DOE Actualidad Jurídica
Breach notification Notice to the Agency within 72 hours of awareness Cifrid, IA Governance
Impact assessment Required for certain high-risk processing activities DOE Actualidad Jurídica, IA Governance
Documentary traceability The organization must prove how it processes data from customers, employees, vendors, or applicants PressLatam, Plutto
Suspension of processing The Agency may order it in certain cases Alayia Trust
Lawful basisConsent or otherARSOPB rightsAccess and objection72h breachesTo the AgencyEvidenceTraceability and DPIA
Compliance flow under Law 21.719 — Operational sequence of bases, rights, breaches, and evidence.

Regional impact

Regional overview

The entry into force of Law No. 21,719 in Chile has regional impact because it extends its reach to foreign organizations that process data about people in Chile, especially from Brazil. The consolidated material shows the effect is not limited to the Chilean local market, but also reaches e-commerce, SaaS, logistics, digital health, fintech, and any cross-border operation involving data from Chilean residents.

There is also a regulatory convergence with GDPR, but not full identity. The Chilean approach requires principles, rights, security, transparency, a specialized authority, and breach notification, while international transfers follow its own logic of similar or higher standards. For regional teams, that means reviewing transfer matrices, contracts, safeguards, and recipient-country criteria.

Chile

Chile is the core of the report’s legal analysis. Law No. 21,719 takes effect on Dec. 1, 2026, effectively replaces Law No. 19,628, and creates the Personal Data Protection Agency as an autonomous public-law body with powers to audit on its own initiative, investigate complaints, and directly sanction violations. The change is institutional and operational, because it requires proof of processing, not just a statement about it.

Article 3 sets out eight principles, lawfulness and loyalty, purpose, proportionality, quality, accountability, security, transparency and information, and confidentiality. The law also expands the classic rights catalog into the ARSOPB scheme, adds objection to automated decisions, and redefines treatment of data obtained from open sources, since it removes publicly accessible sources as an independent lawful basis.

On sanctions, the law distinguishes minor, serious, and very serious violations. Base fines reach 5,000, 10,000, and 20,000 UTM, with a written warning available in minor cases and suspension of processing under Article 38. Cifrid and other business summaries add that repeat serious or very serious violations can increase the fine up to three times, and some analyses place the practical ceiling at 60,000 UTM or up to 4% of annual revenue for large companies.

Breach notification also changes the standard. Cifrid says notice to the Agency must be made within 72 hours of the controller learning of the incident, with notice to data subjects when risk is high. The law also adds impact assessment obligations for high-risk processing, specific rules on profiling and automated decisions, and response deadlines for data subject requests that, according to SuperPyME, run from receipt acknowledgment to a decision within 30 calendar days, with one possible extension.

Brazil

Brazil appears in the material as the main neighboring country exposed to the practical extraterritorial reach of Law No. 21,719. Sinfopac, IA Governance, PCKZ Legal, AZ Abogados, Somos Forma, Francisco Moroso, Araya & Cía, and GDPRI all agree that any Brazilian organization processing data of Chilean people or residents, including SaaS, e-commerce, digital health, and logistics support, falls within the Chilean regime.

The relevance for Brazil is not abstract. The file says Brazilian companies will need to align governance, conditional access, processing records, impact assessments, and breach response with the Chilean authority. IA Governance adds that the Chilean regime requires a DPO, a record of processing activities, DPIA, and 72-hour notification, which means internal processes must be reviewed even if the company already complies with Brazilian frameworks or the GDPR itself.

International transfers are also central. GDPRI and the analysis by Actualidad Jurídica on Oliver Ortiz say Chile uses a logic of similar or higher standards, unlike the European essential-equivalence test. That affects data flows to and from Brazil when the operation includes data about Chilean people, because compatibility no longer depends only on contracts, but also on how the Chilean authority assesses the recipient country.

The impact is stronger in regulated sectors. Salutexa projects it onto healthcare and telemedicine, while DOE Actualidad Jurídica and ComplianceLatam do the same for fintech, advanced analytics, and automated scoring. For Brazil, the issue is not only Chilean legal exposure, but also the need to unify processes across jurisdictions with close, but not identical, standards.

Countries with no specific verifiable facts

No additional verifiable facts were identified in the research for Argentina, Paraguay, Bolivia, Peru, Colombia, Mexico, the United States, or Uruguay.

Technical indicators

No exploitable technical indicators were published in the material. There are no hashes, domains, IPs, malicious URLs, offensive TTPs, or malware samples. The file is regulatory and compliance-focused, so the available traceability is limited to publication dates, authorities, sanctions, deadlines, and processing obligations.

Analysis for security teams

For security, privacy, and compliance teams, the main finding is that Law No. 21,719 requires a shift from declarative controls to demonstrable controls. The priority is no longer just to publish policies, but to prove lawful bases, consent flow, purposes, retention, security measures, rights traceability, and incident response. Documentation stops being an accessory and becomes operational evidence.

The first workstream is the processing inventory. Organizations should identify what personal data they process, for what purposes, on what legal bases, where it is stored, and with which third parties it is shared. That includes customers, employees, vendors, and applicants, as well as biometric, health, or financial data where present. Arco.Legal and Paramodigital make clear that server location does not take processing outside the law’s reach.

The second workstream is rights governance. The material stresses that the controller must acknowledge valid requests and respond within 30 calendar days, with one possible extension. That requires a request-handling workflow, requester authentication, deadline tracking, and decision traceability. Sinfopac adds that this must coexist with technical controls for access, rectification, objection, and deletion.

The third workstream is security and incident response. The 72-hour breach-notification requirement means detection, classification, and escalation need to be tightly defined. If the organization also operates under Cybersecurity Law No. 21,663, it must coordinate a dual reporting obligation, one to the cybersecurity ecosystem and another to the Personal Data Protection Agency when the incident affects personal data.

The fourth workstream is algorithmic risk. The doctrinal sources on profiling, automated decisions, and impact assessments suggest that finance, healthcare, retail, and any high-volume scoring operation will need to review models, variables, explainability, and human oversight. In environments with AI or advanced analytics, the regulatory question becomes whether the processing can be justified, documented, and audited.

The fifth workstream is third parties and transfers. If the organization operates from Brazil or contracts services outside Chile, a standard contract is not enough. It is necessary to review whether the destination country meets similar or higher standards under the Chilean framework and whether the transfer requires a ruling from the authority. In practice, this forces mapping of vendors, sub-processors, cloud services, and data centers through a cross-border lens.

Frequently asked questions

When does Law 21,719 take effect, and how much time is there to adapt?

Law No. 21,719 takes effect on Dec. 1, 2026, and includes a two-year transition period from publication. That period applies to companies and public agencies, and it also affects foreign companies that process data about people in Chile, according to Exige tu Seguro, PressLatam, and the rest of the reviewed material.

What changes for a company that processes data in both Chile and Brazil?

The company falls under the Chilean regime if it processes data of Chilean people or residents, even if it operates from Brazil. The report links here the extraterritorial scope, governance duties, and international transfer rules, which require reviewing DPO, records, impact assessments, and safeguards compatible with the Chilean standard.

What specific penalties does the law provide, and how do they increase?

The law distinguishes minor, serious, and very serious violations, with base fines of up to 5,000, 10,000, and 20,000 UTM. Cifrid and other summaries add that repeat serious or very serious violations can multiply those caps by up to three, and some analyses place the practical ceiling at 60,000 UTM or at 2% to 4% of annual revenue for large companies.

How does the Chilean law compare with the European GDPR model?

It resembles GDPR in its principles, data subject rights, specialized authority, impact assessments, and breach notification. But international transfer treatment does not replicate the European essential-equivalence standard. The material says Chile uses a logic of similar or higher standards, and the authority can intervene in the assessment.

What operational obligations appear for security and incidents?

The law requires breach notification to the Agency within 72 hours of the controller becoming aware of the incident, plus notice to data subjects when risk is high. It also adds documentary traceability, response to data subject requests within 30 days, stronger controls for sensitive data, and impact assessments for high-risk processing.

Why does the report focus on finance, healthcare, and SaaS?

Because the research shows those sectors concentrate sensitive data, automation, cross-border transfers, and large-scale processing. ComplianceLatam, Salutexa, IA Governance, and the analysis on automated scoring all agree that the most demanding obligations of the new law converge there, from security and governance to explainability and breach notification.

Material limitations

The file does not contain evidence of an intrusion campaign, malware, technical vulnerability, or offensive actor, so it was not possible to reconstruct a real attack chain or list IOCs. There are also no additional verifiable facts for Argentina, Paraguay, Bolivia, Peru, Colombia, Mexico, the United States, or Uruguay. Some peso-equivalent figures and certain statements about financial information are attributed by their sources as estimates or opinions, so they were preserved as such and not treated as conclusive facts.

Exposure matrixSensitive datahealth and biometricsAlgorithmsprofiling and DPIATransferssimilar standardsPenaltiesup to 20,000 UTMAgencyaudits and penalizesBreachs72 hours and notice
Regulatory matrix and risks — Elements of the reform that increase operational exposure.

Graphics

Base fines in UTM5,00010,00020,000MinorwarningSeriousbase fineSeverelegal cap
Sanction scale under Law 21,719 — Base caps and aggravating factors reported by the sources reviewed.

Sources

View all