Chile Tightens Data Breach Reporting
Law 21.719 adds 5-day breach notices, higher penalties and new internal compliance demands for banks and fintechs in Chile.
Chile's Personal Data Protection Law 21.719 adds new obligations for companies, including financial firms, with tighter notification deadlines, data governance requirements and a tougher sanctions regime. The change builds on existing duties to the CMF and the National CSIRT.
Chile’s Personal Data Protection Law 21.719 adds another layer of obligations for companies, including those in the financial sector. According to analysis released by the Santiago Chamber of Commerce and BigBuda, the law requires organizations to map data processing activities, identify legal bases, review breaches and carry out corrective actions, in addition to notifying a breach that creates a risk to rights and freedoms within a maximum of 5 business days from the moment it becomes known.
New reporting flow
That notice must go both to the future Data Protection Agency and to affected data subjects. In practice, the framework adds a dedicated reporting channel on top of the obligations already facing banks and fintechs before the CMF and the National CSIRT. The result is a more demanding notification regime for incidents tied to personal data and information security.
Sanctions and financial exposure
The same law sets out a penalty structure that can reach up to 5,000 UTM for minor violations, 10,000 UTM for serious violations, and 20,000 UTM or 4% of annual global sales for very serious violations, applying the higher amount. According to BigBuda’s summary of Garrigues’ analysis, this significantly raises the financial risk tied to security breaches and weak data management in banks and fintechs compared with the previous regime.
More internal compliance functions
The Santiago Chamber of Commerce also published a guide for SMEs on personal data protection with a 10-step methodology. Those steps include appointing an internal data protection lead, mapping processing activities and analyzing breaches. That structure suggests that even in smaller financial services businesses, such as fintechs and merchants that handle payment methods, a formal internal function dedicated to data and security compliance will be required.
What security framework is already in place?
The move lands on top of a regulatory environment that was already raising technical requirements. The sources available for this report include the CMF framework for information security and cybersecurity management, Chile’s Fintech Law, Law 21.663 on cybersecurity, and the National Congress Library’s guide on cybersecurity for state agencies and critical information infrastructure. Taken together, that framework points to stronger obligations for risk management, inventories of critical assets, registration and periodic reporting for regulated actors in Chile’s financial system.
Sanctions on Chile new update
Chile has tightened sanctions and reporting rules under Law 21.719, raising the cost of noncompliance for banks, fintechs and other companies that process personal data. The change includes higher fines and a more demanding notification process for breaches.
The law sets fines of up to 5,000 UTM for minor violations, 10,000 UTM for serious ones, and 20,000 UTM or 4% of annual global sales for the most serious violations, with the higher amount applying. It also requires reporting breaches that pose a risk to rights and freedoms within a maximum of 5 business days, both to the future Data Protection Agency and to affected data subjects.
Sources
- Ley Fintech Chile: Guía 2026 para Empresasblackend.dev· Blackend Blog
- Robos y fraudes en el uso de tarjetas e instrumentos financierosbcn.cl· Biblioteca del Congreso Nacional de Chile (Ley Fácil)
- Ley 21.663 de ciberseguridad e ISO 27001 (Chile)normexus.com· Normexus
- Prepara tu eCommerce: ley de datos personales Chile 2026bigbuda.cl· BigBuda / Garrigues
- Ley de Protección de Datos Personales: guía de preparacióntecnoinver.cl· Tecnoinver
- CCS lanza guía esencial de protección de datos personales para pequeñas y medianas empresasccs.cl· Cámara de Comercio de Santiago (CCS)
- ¿Qué derechos tengo si soy víctima de un fraude bancario o de un uso indebido de mi tarjeta?odecu.cl· ODECU
- Chile: Normativa CMF para la Gestión de la Seguridad de la Información y Ciberseguridadecija.com· Ecija
- Ciberseguridad de los organismos del Estado e infraestructura crítica de la informaciónbcn.cl· Biblioteca del Congreso Nacional de Chile (Ley Fácil)



