Legal-Updates
Legal-Updates

Data Protection Update in Chile: Q4 2025

Chile data protection 2025 entered a decisive phase in the final quarter of the year, as the country';s landmark personal data protection reform moved from legislative text into operational reality. Businesses operating in Chile - whether locally incorporated or serving Chilean residents from abroad - now face a materially different compliance environment than they did twelve months ago. This guide covers the key regulatory developments of Q4, the practical obligations they create, the enforcement signals emerging from the new supervisory authority, and the steps companies should take to align their operations with the current framework.

Chile';s new data protection law: what changed in Q4

Chile';s reformed personal data protection statute - commonly referred to as the New Data Protection Law - was enacted after years of parliamentary debate and represents the most significant overhaul of the country';s privacy framework since the original Law No. 19,628 on the Protection of Private Life. The Q4 period brought several critical milestones in the law';s implementation cycle.

The most consequential development was the formal establishment of the Agencia de Protección de Datos Personales (the Agency), the independent supervisory authority created under the reform. The Agency';s mandate covers registration of data controllers, investigation of complaints, issuance of binding guidance, and imposition of administrative sanctions. Its creation marks a structural shift: Chile moves from a largely self-regulatory model - where enforcement depended on civil litigation - to a dedicated public enforcement regime with real investigative powers.

The reform also introduced a tiered classification of personal data. Ordinary personal data, sensitive personal data, and a newly defined category of biometric and health-related data each carry distinct processing requirements. Controllers handling sensitive categories must now document a specific legal basis for each processing activity, maintain a record of processing operations, and implement enhanced security measures. The Q4 guidance issued by the Agency clarified that legacy consent obtained under the old framework does not automatically satisfy the new standard.

A further change concerns data subjects'; rights. The reformed law codifies rights of access, rectification, deletion, portability, and objection in terms broadly aligned with international standards. The Q4 period saw the Agency publish its first procedural guidance on how data subjects may lodge complaints and how controllers must respond within the statutory timeframes.

The new supervisory authority and its early enforcement signals

The Agencia de Protección de Datos Personales began accepting formal complaints in Q4, and its early public statements provide a clear indication of enforcement priorities. The Agency has signalled that it will focus initial scrutiny on three areas: the adequacy of consent mechanisms used by digital platforms and e-commerce operators; the security practices of companies handling health and financial data; and the cross-border transfer practices of multinational groups with Chilean operations.

Controllers should note that the Agency has the power to conduct inspections on its own initiative, not only in response to complaints. It may request documentation, interview staff, and access processing systems. Failure to cooperate with an inspection is itself a sanctionable act under the reform. The Agency has also indicated that it will publish a register of data controllers, and that registration will be a prerequisite for lawful processing in certain categories.

The sanction regime introduced by the reform is graduated. Minor infringements attract lower administrative fines, while serious and very serious infringements - including unlawful processing of sensitive data, failure to implement adequate security measures, and obstruction of the Agency';s investigations - attract substantially higher penalties. The law also provides for reputational consequences: the Agency may publish the names of sanctioned entities on its website. For companies with consumer-facing operations in Chile, this reputational dimension may be as significant as the financial penalty itself.

In practice, founders and compliance officers should consider that the Agency';s initial enforcement actions will set precedents that shape the entire market';s understanding of acceptable practice. Early engagement with the Agency';s guidance documents - rather than waiting for a complaint or inspection - is the more defensible posture.

If your organisation is assessing its current exposure under the new framework, we can help structure the compliance review correctly the first time. Contact us at info@vlolawfirm.com.

Key obligations for data controllers and processors in Chile

The reformed framework draws a clear distinction between data controllers - entities that determine the purposes and means of processing - and data processors - entities that process data on behalf of a controller. Both categories carry obligations, but the controller bears primary legal responsibility.

For controllers, the Q4 period crystallised several immediate obligations. First, every controller must be able to demonstrate a valid legal basis for each processing activity. The reform recognises consent, contractual necessity, legal obligation, vital interests, public interest, and legitimate interests as potential bases, but each carries conditions. Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes and bundled consent clauses do not meet the standard.

Second, controllers must maintain a record of processing activities. This internal register must document the categories of data processed, the purposes, the legal basis, the retention periods, and the categories of recipients. The Agency may request this register at any time during an inspection. Many companies operating in Chile under the old framework had no such documentation, and building it from scratch requires a structured data mapping exercise.

Third, controllers must appoint a data protection contact point - in some cases a formally designated data protection officer - and communicate that contact to the Agency and to data subjects. The Q4 guidance clarified the thresholds that trigger the mandatory officer requirement, which include large-scale processing of sensitive data and systematic monitoring of individuals.

For processors, the reform requires that all processing be governed by a written contract with the controller. That contract must specify the subject matter, duration, nature, and purpose of the processing, the type of personal data involved, and the obligations and rights of the controller. Processors that engage sub-processors must ensure equivalent contractual protections flow down the chain.

A common mistake among foreign companies entering the Chilean market is treating their standard EU or US data processing agreements as sufficient. Chilean law has its own specific requirements, and a contract drafted for another jurisdiction may leave gaps that create liability under the local framework.

Cross-border data transfers: the new adequacy and safeguard framework

One of the most practically significant aspects of the reform for international businesses is the new regime governing cross-border transfers of personal data. Under the old Law No. 19,628, transfers abroad were largely unregulated beyond a general requirement that the recipient country offer comparable protection. The reform replaces this with a structured framework that mirrors, in broad terms, the approach taken in the European Union';s General Data Protection Regulation.

Under the new framework, a transfer to a third country is permissible if: the destination country has been recognised by the Agency as offering an adequate level of protection; the transfer is covered by appropriate safeguards such as standard contractual clauses approved by the Agency; or the transfer falls within one of the enumerated exceptions, including explicit consent of the data subject, necessity for contract performance, or vital interests.

The Agency has not yet published a formal adequacy list as of Q4, but it has indicated that it will assess third countries against criteria including the existence of an independent supervisory authority, the availability of enforceable data subject rights, and the existence of international commitments on data protection. Companies transferring data to jurisdictions that are unlikely to receive an adequacy decision - including certain markets in Asia and Latin America - should begin preparing standard contractual clauses or binding corporate rules as alternative safeguards.

A non-obvious requirement that surfaces frequently in practice is the obligation to inform data subjects about cross-border transfers at the time their data is collected. Privacy notices that simply state "your data may be transferred internationally" without specifying the destination countries or the safeguards in place will not satisfy the reformed law';s transparency requirements.

Multinational groups with Chilean subsidiaries or branches should also review their intra-group data transfer arrangements. Transfers from a Chilean entity to a parent company or affiliate in another country are subject to the same rules as transfers to unrelated third parties. Many groups have not formalised these arrangements, and the Q4 enforcement signals suggest that intra-group transfers will be an area of scrutiny.

Practical scenarios: how the changes affect different business models

Scenario one: an e-commerce platform with Chilean customers

A regional e-commerce operator based in Colombia that sells to Chilean consumers and processes their payment and delivery data is subject to the reformed Chilean law by virtue of targeting Chilean residents. In Q4, this operator must review its consent mechanisms on the Chilean-facing website, ensure its privacy notice meets the new transparency standards, and assess whether its payment processor has a compliant data processing agreement in place. If the operator uses a cloud infrastructure provider located outside Chile, it must also verify that the cross-border transfer to that provider is covered by an appropriate safeguard. The operator should register with the Agency once the registration portal is operational and designate a contact point for data subject requests.

Scenario two: a financial services firm processing health and financial data

A Chilean fintech that uses open banking data and, in some products, health-related information to assess creditworthiness is processing both ordinary and sensitive personal data. Under the reformed framework, the fintech must document a specific legal basis for processing health data - consent alone may not be sufficient if the processing is necessary for the performance of a contract or required by financial regulation. The firm must implement enhanced security measures for the sensitive data categories, conduct a data protection impact assessment before launching new products that involve large-scale processing of sensitive data, and ensure its data retention policies reflect the principle of storage limitation. The Agency';s Q4 guidance on sensitive data processing is directly relevant to this model.

Frequently asked questions

Does the reformed Chilean data protection law apply to foreign companies with no physical presence in Chile?

The reformed law applies to any entity that processes personal data of individuals located in Chile, regardless of where the controller is established. This extraterritorial scope is modelled on international standards and means that a company based in Europe, the United States, or elsewhere that collects data from Chilean residents - through a website, an app, or a service contract - is subject to Chilean law. The practical enforcement of this extraterritorial reach depends on the Agency';s capacity and on whether the foreign entity has assets or representatives in Chile, but the legal obligation exists regardless. Foreign companies should not assume that distance provides a compliance exemption.

How long do companies have to comply with the new obligations, and what are the costs involved?

The reformed law includes transitional periods for certain obligations, and the Agency has indicated a phased approach to enforcement during the initial period of the framework';s operation. However, the core obligations - including the requirement to have a valid legal basis for processing, to maintain a record of processing activities, and to honour data subject rights - are in force. The cost of compliance varies significantly by company size and complexity. For a small or medium-sized business with straightforward processing activities, a compliance programme typically involves a data mapping exercise, a privacy notice update, and a review of vendor contracts. For larger organisations or those processing sensitive data at scale, the investment is more substantial and may include technology upgrades, staff training, and the appointment of a data protection officer. Professional fees for a structured compliance review generally start from the low thousands of USD.

What should a company do if it receives a data subject request or a complaint from the Agency?

A data subject request - for access, rectification, deletion, portability, or objection - must be acknowledged promptly and responded to within the timeframe specified in the reformed law, which is measured in calendar days from receipt. Controllers should have an internal process in place before a request arrives, not after. If the Agency initiates a complaint investigation or an inspection, the controller must cooperate fully and provide the requested documentation within the deadlines set by the Agency. Failure to respond or to produce records is an aggravating factor in any subsequent sanction decision. Companies that have not yet built their compliance documentation - particularly the record of processing activities - are at a structural disadvantage if an investigation begins. Engaging legal counsel early in the process, before responding to the Agency, is strongly advisable.

Conclusion

Chile';s data protection reform is now an operational reality, not a future event. The Q4 period confirmed that the Agency is active, that enforcement priorities are taking shape, and that the obligations on controllers and processors are concrete and immediate. Companies that treat compliance as a documentation exercise rather than a substantive operational change will be exposed when inspections begin in earnest.

VLO Law Firms advises international clients on data protection matters in Chile. We can assist with compliance gap assessments, data processing agreement drafting, cross-border transfer safeguards, and engagement with the Agencia de Protección de Datos Personales. To request a consultation, contact: info@vlolawfirm.com