Chile Tightens Data Breach Reporting
Law 21.719 adds 5-day breach notices, higher penalties and new internal compliance demands for banks and fintechs in Chile.
Chile's Personal Data Protection Law 21.719 adds new obligations for companies, including financial firms, with tighter notification deadlines, data governance requirements and a tougher sanctions regime. The change builds on existing duties to the CMF and the National CSIRT.
Chile's Personal Data Protection Law 21.719 adds another layer of requirements for companies, including those in the financial sector. According to analysis released by the Santiago Chamber of Commerce and BigBuda, the law requires firms to map data processing activities, determine legal bases, review breaches and carry out corrective measures, in addition to notifying any breach that poses a risk to rights and freedoms within a maximum of 5 business days from the moment it becomes known.
New reporting flow
That notice must be sent both to the future Data Protection Agency and to affected data subjects. In practice, the scheme adds a dedicated reporting channel on top of the obligations already imposed on banks and fintechs before the CMF and the National CSIRT. The result is a stricter notification framework for incidents involving personal data and information security.
Penalties and financial exposure
The law also sets out a sanctions regime that can reach up to 5,000 UTM for minor violations, 10,000 UTM for serious violations, and 20,000 UTM or 4% of annual global sales for the most serious violations, whichever is higher. According to BigBuda's summary of Garrigues' analysis, this significantly raises the financial risk tied to security breaches and poor data management in banks and fintechs compared with the previous regime.
More internal compliance functions
The Santiago Chamber of Commerce also published a guide for SMEs on personal data protection with a 10-step methodology. Those steps include appointing an internal data protection officer, mapping processing activities and analyzing breaches. That framework suggests that even smaller financial services firms, such as fintechs and merchants that process payments, will need a formal internal function dedicated to data and security compliance.
Existing security framework
The move lands in a regulatory environment that had already been raising technical requirements. Sources available for this report include CMF rules on information security and cybersecurity management, Chile's Fintech Law, Cybersecurity Law 21.663 and the Congressional Library's guide on cybersecurity for state agencies and critical information infrastructure. Together, that framework points to stronger obligations around risk management, critical asset inventories, registration and periodic reporting for regulated players in Chile's financial system.
Sources
- Ley Fintech Chile: Guía 2026 para Empresasblackend.dev· Blackend Blog
- Robos y fraudes en el uso de tarjetas e instrumentos financierosbcn.cl· Biblioteca del Congreso Nacional de Chile (Ley Fácil)
- Ley 21.663 de ciberseguridad e ISO 27001 (Chile)normexus.com· Normexus
- Prepara tu eCommerce: ley de datos personales Chile 2026bigbuda.cl· BigBuda / Garrigues
- Ley de Protección de Datos Personales: guía de preparacióntecnoinver.cl· Tecnoinver
- CCS lanza guía esencial de protección de datos personales para pequeñas y medianas empresasccs.cl· Cámara de Comercio de Santiago (CCS)
- ¿Qué derechos tengo si soy víctima de un fraude bancario o de un uso indebido de mi tarjeta?odecu.cl· ODECU
- Chile: Normativa CMF para la Gestión de la Seguridad de la Información y Ciberseguridadecija.com· Ecija
- Ciberseguridad de los organismos del Estado e infraestructura crítica de la informaciónbcn.cl· Biblioteca del Congreso Nacional de Chile (Ley Fácil)



