Chile sets Law 21,719 for 2026
Chile’s Law 21,719 will take effect on Dec. 1, 2026, creating a new agency and fines of up to 20,000 UTM.
Chile’s Law No. 21,719, which regulates personal data protection and processing and creates the Personal Data Protection Agency, will take effect on Dec. 1, 2026. The law also adds breach notification requirements and a penalty regime that can reach 20,000 UTM, according to Chile’s National Congress Library.
Chile’s Law No. 21,719, which regulates personal data protection and processing and creates the Personal Data Protection Agency, is set to take effect on Dec. 1, 2026. Chile’s National Congress Library also said the law adds breach notification requirements and a penalty regime with fines of up to 20,000 UTM.
What changes with the new law?
Law No. 21,719 creates the Personal Data Protection Agency and sets specific rules for handling personal data in Chile. According to the National Congress Library, it also establishes breach notification obligations, which will require organizations to review internal procedures before the effective date.
What fines does it set?
The law creates a system of minor, serious and very serious violations, with fines that can reach 5,000, 10,000 and 20,000 UTM, respectively. According to Chile’s National Congress Library, the final amount depends on the severity of the violation and the conditions set out in the law itself.
How prepared are companies?
An article from G5 Noticias cites a study by Deloitte and the Santiago Chamber of Commerce saying 52% of the companies surveyed show a low level of readiness for the new regulation. The same text says, without independent official confirmation in the material provided, that 84% would not be ready to report incidents to the future agency or have a current privacy policy, and that 62% still had not trained their workers.
What tasks does the private sector anticipate?
A business guide from Sinfopac lists preparatory tasks such as data inventories, reviewing purposes and lawful bases, access controls, assessing technical and organizational security measures, and defining retention periods. Those steps appear as part of the work companies should complete before the law takes effect.
Sources
- Ley 21.719: cambios para empresas en Chilesinfopac.com· Sinfopac
- Ley Chile - Ley N.º 21.719bcn.cl· Biblioteca del Congreso Nacional de Chile
- Búsqueda por Categoría. Asesorías Parlamentariasbcn.cl· Biblioteca del Congreso Nacional de Chile
- Protección de datos y gestión contractual: el costo invisible del caos documentalg5noticias.cl· G5 Noticias
- Datos personales: un año para cerrar brechasdiarioestrategia.cl· Diario Estrategia



