CiberLATAMbywhalemate

Chile Keeps Delay of Law 21,719 Pending

The delay of Law 21,719 is still moving through Congress, and enforcement remains set for Dec. 1, 2026.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

The delay of Law 21,719 is still moving through Congress, and enforcement remains set for Dec. 1, 2026, while the opposition pushes to shorten the timeline or roll it out in stages.

Update October 4, 2026: As of October 1, the delay bill had not yet begun parliamentary discussion, and Pedro Araya expected debate to start in the second week of October. The opposition also added concrete proposals to shorten the delay or phase it in.

The delay to Chile’s Personal Data Law 21,719 is still moving through the legislative process, and until it is approved and published, enforcement remains set for Dec. 1, 2026. At the same time, the political debate has brought in alternatives to cut the one-year extension proposed by the executive branch, but none of them has changed the legal calendar yet.

What changes with the bill in the Senate?

CSiTI says the change is not in force yet because the bill is still moving through Congress. Until it is approved and published, companies should not assume the delay has already been settled. In that context, the firm’s analysis says the key point for companies and public agencies is not to reset compliance plans based on an announcement that has not been enacted.

As of Oct. 1, 2026, the delay bill had not yet started its legislative process. Pedro Araya, chair of the Senate Constitution Committee, said debate was expected to begin during the second week of October.

What date does the delay propose?

According to a BioBioChile column, the bill would not only push the effective date to Dec. 1, 2027, but also expand the board of the Personal Data Protection Agency from three to five members and move up the appointment of its first board member. That information, however, should be checked against the official text of the message.

The debate also includes a narrower approach from the opposition. Opposition senators proposed reducing the executive branch’s one-year delay to six months, or applying the law in phases, although those options remain political positions and not approved changes.

What compliance obligations still apply?

CSiTI links Supreme Decree 662 to a diligence standard that could be documented through an infringement prevention model. In its analysis, the firm also explains that the new regulation on implementation and certification of those models is meant to organize how compliance is demonstrated, even if the delay is approved later.

For small and midsize companies, the bill would not change the substantive obligations in Law 21,719, but mainly the point at which penalties for noncompliance would begin. Another private analysis adds that, during the initial period, the agency could issue a written warning instead of a fine to any company, although that would be an authority’s discretion and not an automatic guarantee.

What about international data transfers?

A specialized legal analysis says the delay bill would not change the regime for international data transfers. Under that reading, the matter would continue to depend on a provisional instrument until the Personal Data Protection Agency regulates it.

The interpretation appears in a Diario Financiero column and does not represent an already effective legal change, but rather a reading of the bill while it continues through Congress.

What are private-sector signals saying?

Emol reported that 72% of companies in Chile say they are not prepared for the new Personal Data Protection Law, although the methodology behind that measurement is not available in the result reviewed. At the same time, Portal Innova, citing GlobalLogic, said the delay is meant to give more time to set up the new institutional framework and help public and private organizations adapt.

G5 Noticias, in a column by a regional Sophos representative, raised risks tied to delaying the law, a cybersecurity-sector business reaction that serves as a gauge of market concern. Meanwhile, The Clinic published remarks from Diego Morandé, who said the law applies to anyone who handles data, from the building custodian to a multinational company.

Another report says the proposal would increase the future Personal Data Protection Agency’s board from three to five members, set a quorum of three members, and advance the appointment of the first board no later than 12 months before the law takes effect. That same reading says the bill would also change the transitional penalty regime, with a written warning for all regulated entities during the first year instead of limiting it to smaller companies.

DSN Group also said that in May 2026 the Senate rejected the government’s nominees for the agency’s board, so the regulator would still not be constituted and would not have issued guidance, model clauses, or adequacy decisions. That claim requires additional official verification.

Sources

View all