Chile Keeps Delay of Law 21,719 Pending
The delay of Law 21,719 is still moving through Congress, and enforcement remains set for Dec. 1, 2026.
The delay of Law 21,719 is still moving through Congress, and enforcement remains set for Dec. 1, 2026, while the opposition pushes to shorten the timeline or roll it out in stages.
Update October 4, 2026: As of October 1, the delay bill had not yet begun parliamentary discussion, and Pedro Araya expected debate to start in the second week of October. The opposition also added concrete proposals to shorten the delay or phase it in.
The delay to Chile’s Personal Data Law 21,719 is still moving through the legislative process, and until it is approved and published, enforcement remains set for Dec. 1, 2026. At the same time, the political debate has brought in alternatives to cut the one-year extension proposed by the executive branch, but none of them has changed the legal calendar yet.
What changes with the bill in the Senate?
CSiTI says the change is not in force yet because the bill is still moving through Congress. Until it is approved and published, companies should not assume the delay has already been settled. In that context, the firm’s analysis says the key point for companies and public agencies is not to reset compliance plans based on an announcement that has not been enacted.
As of Oct. 1, 2026, the delay bill had not yet started its legislative process. Pedro Araya, chair of the Senate Constitution Committee, said debate was expected to begin during the second week of October.
What date does the delay propose?
According to a BioBioChile column, the bill would not only push the effective date to Dec. 1, 2027, but also expand the board of the Personal Data Protection Agency from three to five members and move up the appointment of its first board member. That information, however, should be checked against the official text of the message.
The debate also includes a narrower approach from the opposition. Opposition senators proposed reducing the executive branch’s one-year delay to six months, or applying the law in phases, although those options remain political positions and not approved changes.
What compliance obligations still apply?
CSiTI links Supreme Decree 662 to a diligence standard that could be documented through an infringement prevention model. In its analysis, the firm also explains that the new regulation on implementation and certification of those models is meant to organize how compliance is demonstrated, even if the delay is approved later.
For small and midsize companies, the bill would not change the substantive obligations in Law 21,719, but mainly the point at which penalties for noncompliance would begin. Another private analysis adds that, during the initial period, the agency could issue a written warning instead of a fine to any company, although that would be an authority’s discretion and not an automatic guarantee.
What about international data transfers?
A specialized legal analysis says the delay bill would not change the regime for international data transfers. Under that reading, the matter would continue to depend on a provisional instrument until the Personal Data Protection Agency regulates it.
The interpretation appears in a Diario Financiero column and does not represent an already effective legal change, but rather a reading of the bill while it continues through Congress.
What are private-sector signals saying?
Emol reported that 72% of companies in Chile say they are not prepared for the new Personal Data Protection Law, although the methodology behind that measurement is not available in the result reviewed. At the same time, Portal Innova, citing GlobalLogic, said the delay is meant to give more time to set up the new institutional framework and help public and private organizations adapt.
G5 Noticias, in a column by a regional Sophos representative, raised risks tied to delaying the law, a cybersecurity-sector business reaction that serves as a gauge of market concern. Meanwhile, The Clinic published remarks from Diego Morandé, who said the law applies to anyone who handles data, from the building custodian to a multinational company.
Another report says the proposal would increase the future Personal Data Protection Agency’s board from three to five members, set a quorum of three members, and advance the appointment of the first board no later than 12 months before the law takes effect. That same reading says the bill would also change the transitional penalty regime, with a written warning for all regulated entities during the first year instead of limiting it to smaller companies.
DSN Group also said that in May 2026 the Senate rejected the government’s nominees for the agency’s board, so the regulator would still not be constituted and would not have issued guidance, model clauses, or adequacy decisions. That claim requires additional official verification.
Sources
- La ley se aplaza, los riesgos noportalinnova.cl· Portal Innova
- Ley 21.719: la fecha legal sigue en diciembre 2026 y tus contratistas...califix.cl· Califix
- Ley de datos personales: senadores proponen prórroga de seis meses frente al año que pide el Gobiernopauta.cl· Pauta
- Chile y EEUU: transferencias de datos más allá de la postergación de la Ley 21.719df.cl· Diario Financiero
- Chile's New Data Protection Law: What Really Changesdsn-group.com· DSN Group
- Ley 21.719 de datos personales: guía para empresaslexalert.cl· LexAlert
- Diego Morandé ante la nueva ley de Datos Personales: “Aplica a todo aquel que trate datos, desde el conserje del edificio hasta una transnacional”theclinic.cl· The Clinic
- De las normas que no norman a los vacíos que legislanbiobiochile.cl· BioBioChile
- El 72% de las empresas en Chile reconoce no estar preparada para la nueva Ley de Datos Personalesemol.com· Emol
- La Ley 21.719 se Posterga: Qué Cambia, Qué No y Qué Hacer con el Año Adicionalcsiti.cl· CSiTI
- GlobalLogic: la nueva ley de datos personales abre una carrera para que las empresas revisen sus sistemas de IAportalinnova.cl· Portal Innova
- Ley de Protección de Datos: Los riesgos ocultos de su postergacióng5noticias.cl· G5 Noticias
- Protección de datos: Nuevo reglamento sobre implementación y certificación de modelos de prevención de infraccionesfycom.cl· FYCOM
- Ley 21.719 de datos personales: qué cambia para tu PYMEabaco360.cl· Ábaco360
- Protección de datos personales: gobierno ingresa proyecto que ...akademia360.cl· Akademia360
- Protección de datos personales: oposición pide reducir el plazo de postergación de la ley que propuso el gobiernolatercera.com· La Tercera
- Postergación de la vigencia de la ley de datos personales: ¿Año de alivio o de mayor incertidumbre?opinion.cooperativa.cl· Cooperativa Opinión
- Datos personales: un año para cerrar brechasdiarioestrategia.cl· Diario Estrategia



