CiberLATAMbywhalemate

Chile Tightens Data Breach Reporting

Law 21.719 adds 5-day breach notices, higher penalties and new internal compliance demands for banks and fintechs in Chile.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Chile's Personal Data Protection Law 21.719 adds new obligations for companies, including financial firms, with tighter notification deadlines, data governance requirements and a tougher sanctions regime. The change builds on existing duties to the CMF and the National CSIRT.

Chile’s Personal Data Protection Law 21.719 adds another layer of obligations for companies, including those in the financial sector. According to analysis released by the Santiago Chamber of Commerce and BigBuda, the law requires organizations to map data processing activities, identify legal bases, review breaches and carry out corrective actions, in addition to notifying a breach that creates a risk to rights and freedoms within a maximum of 5 business days from the moment it becomes known.

New reporting flow

That notice must go both to the future Data Protection Agency and to affected data subjects. In practice, the framework adds a dedicated reporting channel on top of the obligations already facing banks and fintechs before the CMF and the National CSIRT. The result is a more demanding notification regime for incidents tied to personal data and information security.

Sanctions and financial exposure

The same law sets out a penalty structure that can reach up to 5,000 UTM for minor violations, 10,000 UTM for serious violations, and 20,000 UTM or 4% of annual global sales for very serious violations, applying the higher amount. According to BigBuda’s summary of Garrigues’ analysis, this significantly raises the financial risk tied to security breaches and weak data management in banks and fintechs compared with the previous regime.

More internal compliance functions

The Santiago Chamber of Commerce also published a guide for SMEs on personal data protection with a 10-step methodology. Those steps include appointing an internal data protection lead, mapping processing activities and analyzing breaches. That structure suggests that even in smaller financial services businesses, such as fintechs and merchants that handle payment methods, a formal internal function dedicated to data and security compliance will be required.

What security framework is already in place?

The move lands on top of a regulatory environment that was already raising technical requirements. The sources available for this report include the CMF framework for information security and cybersecurity management, Chile’s Fintech Law, Law 21.663 on cybersecurity, and the National Congress Library’s guide on cybersecurity for state agencies and critical information infrastructure. Taken together, that framework points to stronger obligations for risk management, inventories of critical assets, registration and periodic reporting for regulated actors in Chile’s financial system.

Sanctions on Chile new update

Chile has tightened sanctions and reporting rules under Law 21.719, raising the cost of noncompliance for banks, fintechs and other companies that process personal data. The change includes higher fines and a more demanding notification process for breaches.

The law sets fines of up to 5,000 UTM for minor violations, 10,000 UTM for serious ones, and 20,000 UTM or 4% of annual global sales for the most serious violations, with the higher amount applying. It also requires reporting breaches that pose a risk to rights and freedoms within a maximum of 5 business days, both to the future Data Protection Agency and to affected data subjects.

Sources

View all