CiberLATAMbywhalemate

Chile sets rules for data breach prevention certification

Chile’s new data protection rules define certification, oversight and penalties for false or incomplete filings.

Whalemate Labs · AI-assisted researchPublished:2 min read

Chile has launched a new regulation that sets the rules for implementing and certifying models to prevent violations of personal data protection. Certification must be filed with the agency, lasts three years and can be supervised, while false, incomplete or clearly inaccurate information can lead to sanctions.

Chile has published a new regulation that sets the rules for implementing and certifying models to prevent violations of personal data protection. Certification must be requested from the agency, is valid for three years and can be supervised. Failing to meet the requirements or submitting false, incomplete or clearly inaccurate information can be sanctioned under the law.

What changes under this regulation?

The new framework organizes the process for organizations to certify models designed to prevent violations tied to data protection. According to FYCOM, certification does not happen automatically. It must be requested from the competent agency and remains subject to supervision throughout its validity period.

The publication of this regulation comes as Chile prepares for Law No. 21,719 on personal data protection and processing, which is scheduled to take effect in December 2026. According to Emol, that law will replace the current framework and add new obligations for organizations that collect, store or process personal data.

Who will the pending transition affect?

Law No. 21,719 applies to organizations that collect, store or process personal data, and it will replace the current system when it takes effect in December 2026. Emol reported that the change will require a review of internal processes, because its scope is no longer limited to a narrow view of data handling, but extends across the full chain of personal information management.

In parallel, a statement cited by The Clinic said the transitional rule for the first year of enforcement could extend the option of warnings instead of fines to all entities subject to the law during that period, not just small and midsize businesses. That point was reported as a regulatory change, although the available material does not identify the official text of the amendment.

What happens if the requirements are not met?

The regulation sets out consequences when requirements are not met or when false, incomplete or clearly inaccurate information is submitted. In those cases, the conduct may be sanctioned under the law, which makes the quality of the information submitted to the agency to obtain certification more sensitive.

FYCOM also said the certification is valid for three years and can be supervised, two factors that require compliance to be maintained over time, not only at the moment of application. With Law No. 21,719 getting closer to taking effect, the adjustment for Chilean organizations is no longer just about documenting policies, but about sustaining them under a formal system of control and verification.

Sources

View all