For more than twenty-five years, data protection in Chile was governed by Ley 19.628 of 1999, a law passed before the iPhone, Facebook or Amazon Web Services existed. It was one of the first data protection laws in Latin America but, by today's standards, it is also one of the most outdated. This situation is about to change.
Ley 21.719, published in December 2024, overhauls the old framework and creates a new, independent supervisory authority, the Agencia de Protección de Datos Personales (the Agency). After a two-year transition period, it is due to enter into force on 1 December 2026.
Anyone who has worked with the GDPR will find a lot of familiar ground in Chile's new framework: principles, legal bases, data subject rights, impact assessments and rules on international transfers. That is no coincidence. Like many other laws around the world, the Chilean law is an heir to the GDPR. That familiarity is useful for companies with a global presence, but it can be a red herring when the Chilean law takes its own path. In this article, we look at four points that we think will shape how companies approach compliance in Chile.
Legal Basis: Beyond Consent
The old law fell into the so-called consent-based category of data protection laws. That is, with a few exceptions, consent was at the centre of lawful data processing. As any practitioner can attest, that model is not very practical in real life. Consent is fragile: it has to be freely given, it can be withdrawn at any moment, and it fits poorly wherever there is an imbalance of power. And when everything requires consent, consent ends up meaning very little.
Ley 21.719 modernises this in two ways. First, consent itself becomes more flexible: it no longer has to be in writing and can be given verbally, electronically or through a clear affirmative act. Second, and more importantly, the law recognises several legal bases that allow processing without consent:
- Performance of a contract: processing needed to deliver what the customer ordered, pay an employee or run a supplier relationship, including the steps before a contract is signed.
- Legal obligations: processing required by tax, labour, social security or sector-specific rules.
- Legitimate interest: processing that serves a genuine interest of the company or a third party, as long as it does not affect the data subject's rights and freedoms.
- Defence of rights: processing needed to establish, exercise or defend a right before the courts or public bodies.
This is good news for companies which can now choose the legal basis that fits each situation. Data subjects benefit too: when consent is reserved for situations where a real choice exists, it means something again, instead of being a checkbox with empty words.
For international groups, however, the biggest benefit is organisational. Because the Chilean catalogue of legal bases will now largely track Article 6 of the GDPR, a legal basis structure designed at an EU headquarters can be carried over to the Chilean entity far more easily. A group that has already mapped its processing activities to legal bases under the GDPR can reuse most of that work instead of rebuilding it around consent. The fit is not perfect, but the starting point is significantly more convenient.
A Compliance Program the Regulator Can Certify
An original feature of the new law is the infraction prevention model (modelo de prevención de infracciones). This is a voluntary compliance program that includes:
- a data protection officer with real means and powers;
- a map of the data processed;
- identification of risky activities;
- internal protocols, reporting channels and internal sanctions.
The Agency can certify the model for three years. A certified model does not guarantee immunity from sanctions, but it counts as a mitigating circumstance if the company is later sanctioned.
This is good news for groups whose privacy programs are designed in the EU. Many of the building blocks of the Chilean model are either mandatory or common practice under the GDPR. A company that already runs a well-structured privacy program in the EU is therefore well placed to replicate it in Chile at a lower cost and, once the Agency is up and running, to seek certification. Some local adjustments will still be needed, but the heavy lifting will largely have been done already.
Breach Notification: The Category Decides
This is a point that may surprise GDPR-trained teams.
Controllers must report incidents to the Agency when there is a reasonable risk to data subjects. Notifying individuals, however, depends on the type of data affected. Where a reportable breach involves sensitive data, data of children under 14, or data on economic, financial, banking or commercial obligations, each affected person must be told what happened and what is being done about it.
This is a clear departure from the GDPR mindset, where communication to data subjects depends on the severity and likelihood of the risk rather than on the type of data.
No Office in Chile? The Law May Still Apply
The new law applies to controllers established in Chile, but also to controllers outside Chile that offer goods or services to people in Chile or monitor their behaviour, whether or not payment is involved. If you are an online store in Spain offering goods and services to people in Chile, or a pharmaceutical company in Germany conducting clinical trials in Chile, it may fall within the scope of the law.
Final Thoughts and a Caveat on Timing
While many sectors of society resent strict regulation because, in theory, it makes life harder for companies, aligning other countries’ rules with the GDPR standard can actually have the effect of reducing the workload for groups of companies, which can more easily roll out their global privacy program to their different entities.
The timetable, however, is less settled than it seemed. In May 2026, the Senate rejected the government's nominees for the Agency's board, so the new regulator has not yet been constituted and has not issued any guidance, model clauses or adequacy decisions. In September 2026, the government responded with a bill that would postpone entry into force by one year, to 1 December 2027, and restructure the Agency's board. At the time of writing, that bill has not been passed.
Whether the law applies in December 2026 or in December 2027, its substance is already known. A possible delay is best treated as extra preparation time.
If your organisation has operations, employees or customers in Chile and you want to know how the new law affects you, FIRST PRIVACY is happy to help.
Find the Spanish version of this article here.
No comments