Chile sets 3-hour cyber alerts, fines up to 40,000 UTM
Chile now requires 3-hour alerts, 72-hour updates and penalties of up to 40,000 UTM under its new cyber laws.
Chile is moving on two regulatory fronts at once: Law 21,663 sets reporting deadlines and oversight powers tied to operational continuity, while the new data protection law raises internal requirements for companies and public agencies, with fines that can reach 40,000 UTM.
Tight reporting windows and more oversight of continuity
Law 21,663 sets a very specific response window for incidents with significant impact: an early alert within 3 hours, an update within 72 hours, and a final report within 15 days. It also gives the ANCI authority to demand proof that continuity and cybersecurity plans actually work, according to an analysis by Quarancle.
That shifts the regulatory debate. Having internal documents or plans written for audits is no longer enough. The expectation now also includes operational evidence that the measures were implemented and can hold up during an incident.
Higher fines and new internal requirements
At the same time, Tivit said the sanctions regime linked to Chile’s new cybersecurity and data protection laws can reach 40,000 UTM, equivalent to more than $2.8 billion in the most severe cases.
Quarancle’s analysis added that the new data protection law introduces concrete operational requirements such as security and privacy by design, continuous assessment, and the ability to show that measures were implemented, not just documented. Together, those obligations increase pressure on companies and public agencies to adjust internal processes, controls, and the traceability of their compliance measures.
Two regulatory fronts at once
Chile’s regulatory shift leaves organizations facing two parallel obligations. On one side, Law 21,663 defines how incidents must be reported and what must be provable before the authority. On the other, the data protection law raises the standard for how organizations design and verify the measures they adopt.
For both private companies and the public sector, the key issue is no longer just reacting to incidents or formalizing policies. They will also have to show that operational continuity and data protection work in practice, under a stricter oversight and penalty framework.
Sources
- Nueva Ley de Protección de Datos: El desafío estratégico y multas24horas.cl· 24horas
- Law 21.663 and data protection in Chilequarancle.com· Quarancle
- Multas de hasta $2.800 millones: el reto de las empresas ante las nuevas leyes de ciberseguridadlatam.tivit.com· Tivit
- Ciberseguridad de los organismos del Estado e infraestructura crítica de la informaciónbcn.cl· Biblioteca del Congreso Nacional de Chile



