Chile';s data protection framework is undergoing its most significant transformation in decades. The country';s new Personal Data Protection Law - Ley N° 21.719 - has moved from enactment into the active implementation phase, bringing with it a new supervisory authority, expanded individual rights and substantially higher penalties for non-compliance. For international businesses operating in Chile or processing data of Chilean residents, the first quarter of this year has produced concrete regulatory guidance, early enforcement signals and procedural rules that demand immediate attention. This guide covers the key legislative developments, the emerging role of the new regulator, enforcement trends and the practical steps businesses should take now.
Ley N° 21.719 replaces the previous Law N° 19.628, which had governed personal data processing in Chile since the late 1990s. The old law was widely criticised for its limited scope, weak enforcement mechanisms and absence of a dedicated supervisory authority. The new law addresses each of these gaps in a comprehensive way.
The core change is the introduction of a purpose-limitation principle. Controllers must now identify a specific, explicit and legitimate purpose for each processing activity before data is collected. Processing for purposes incompatible with the original purpose is prohibited unless the data subject provides fresh consent or another legal basis applies. This mirrors the approach taken in the European Union';s General Data Protection Regulation and signals Chile';s alignment with international standards.
The law also introduces a formal legal-basis framework. Consent remains a valid basis but must be freely given, specific, informed and unambiguous. Legitimate interest is now recognised as a basis, subject to a balancing test that weighs the controller';s interest against the rights and reasonable expectations of the data subject. Controllers relying on legitimate interest must document their assessment and be prepared to demonstrate it to the regulator.
Data subject rights have been significantly expanded. Individuals now hold rights of access, rectification, deletion, portability, objection and restriction of processing. Each right carries a defined response deadline - generally thirty calendar days from receipt of the request. Failure to respond within that window is treated as a deemed refusal and can trigger a complaint to the supervisory authority.
The most consequential institutional development is the creation of the Agencia de Protección de Datos Personales (the Agency). The Agency is an autonomous public body with investigative, sanctioning and advisory powers. It is operationally independent from the Ministry of Economy, which previously handled data protection complaints in a limited capacity.
The Agency';s mandate covers all sectors of the economy, including financial services, health, telecommunications and digital platforms. It has authority to conduct inspections, request documentation, issue binding orders and impose administrative fines. The fine structure is tiered: minor infringements attract lower penalties, serious infringements carry mid-range fines, and very serious infringements - such as unlawful processing of sensitive data or systematic obstruction of data subject rights - can result in fines expressed as a multiple of the controller';s annual revenue or in absolute monetary units, whichever is higher.
In the first quarter of this year, the Agency published its first set of procedural regulations governing complaint handling. These regulations set out the stages of the administrative procedure, the rights of respondents to submit evidence and the timelines for each phase. Controllers facing a complaint now have a defined window - typically fifteen business days - to submit an initial response and supporting documentation. The Agency has indicated that cooperation and early remediation will be considered mitigating factors in penalty assessments.
The Agency also released preliminary guidance on data breach notification. Under Ley N° 21.719, controllers must notify the Agency of a qualifying breach within seventy-two hours of becoming aware of it. Notification to affected data subjects is required when the breach is likely to result in high risk to their rights and freedoms. The Agency';s guidance clarifies what constitutes "becoming aware" and sets out the minimum content of a notification - including the nature of the breach, categories of data affected, likely consequences and measures taken or proposed.
Ley N° 21.719 significantly tightens the rules around sensitive personal data. The law defines sensitive data broadly to include health information, biometric data used for unique identification, genetic data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sexual orientation and gender identity.
Processing sensitive data requires explicit consent as a baseline. The law permits processing on other grounds only in narrowly defined circumstances - for example, where processing is necessary to protect the vital interests of the data subject, or where the data has been manifestly made public by the data subject. Controllers in the health sector, financial services and human resources functions must audit their current processing activities against these tighter standards.
A non-obvious requirement that has caught several multinational employers off guard is the treatment of employee data. Employment relationships do not automatically justify processing sensitive data about workers. Employers must identify a specific legal basis for each category of sensitive data they collect - for example, health data collected for occupational safety purposes requires a distinct justification from health data collected for payroll administration of sick leave. The Agency has signalled that employment-related data processing will be an early enforcement priority.
Biometric data used for access control - fingerprint readers, facial recognition systems at entry points - falls squarely within the sensitive data category. Controllers using these systems must obtain explicit consent or identify another qualifying legal basis, implement appropriate technical safeguards and document their data protection impact assessment. Many organisations that deployed biometric access systems under the old law have not yet completed this documentation exercise.
Chile';s new law introduces a structured regime for international data transfers. Transfers to third countries are permitted where the destination country offers an adequate level of protection, as determined by the Agency, or where the controller implements appropriate safeguards.
Appropriate safeguards include standard contractual clauses approved by the Agency, binding corporate rules for intra-group transfers, and certification schemes recognised under the law. In the first quarter of this year, the Agency published a draft list of countries it considers to offer adequate protection, inviting public comment. The draft list draws heavily on the EU';s adequacy decisions but is not identical to it. Controllers should not assume that a country deemed adequate by the European Commission will automatically appear on Chile';s list.
A common mistake made by foreign companies with Chilean subsidiaries is treating data transfers to the parent company';s jurisdiction as automatically lawful because the parent is based in a country with strong data protection laws. Under Ley N° 21.719, the adequacy determination is made by the Chilean Agency, not by reference to the parent jurisdiction';s own assessment. Until the Agency finalises its adequacy list, controllers should implement standard contractual clauses for all outbound transfers as a precautionary measure.
The law also requires that data subjects be informed of international transfers at the time their data is collected. Privacy notices must identify the destination country or countries, the legal basis for the transfer and the safeguards in place. Many existing privacy notices in Chile do not meet this standard and require urgent revision.
If your organisation is reviewing its cross-border transfer arrangements or updating its privacy notices for the Chilean market, contact info@vlolawfirm.com. We can assist with documents and filings and help structure the compliance programme correctly from the outset.
Ley N° 21.719 introduces a formal accountability framework. Controllers must maintain a record of processing activities - a document that maps each processing operation, its purpose, legal basis, data categories, retention periods and any transfers. This record must be kept up to date and made available to the Agency on request.
Data protection impact assessments (DPIAs) are mandatory for processing activities that are likely to result in high risk to data subjects. The law identifies specific categories of processing that presumptively require a DPIA: large-scale processing of sensitive data, systematic monitoring of publicly accessible areas, processing involving automated decision-making with significant effects on individuals, and processing of data relating to vulnerable populations including minors.
The Agency';s first-quarter guidance on DPIAs clarifies the methodology controllers should follow. A DPIA must describe the processing, assess necessity and proportionality, identify risks and specify the measures taken to address them. Where a DPIA reveals a residual high risk that cannot be mitigated, the controller must consult the Agency before commencing processing. This prior consultation mechanism is new to Chilean law and has no direct equivalent under the previous regime.
Controllers must also appoint a data protection officer (DPO) in certain circumstances. The obligation applies to public bodies, to controllers whose core activities involve large-scale processing of sensitive data, and to controllers engaged in large-scale systematic monitoring of individuals. The DPO must have expert knowledge of data protection law and practice, must be given the resources necessary to carry out their tasks and must not receive instructions regarding the exercise of their functions. Appointing a DPO who lacks genuine independence - for example, a general counsel who also makes data processing decisions - does not satisfy the requirement.
In practice, founders and compliance teams should consider the DPO appointment question early, because finding a qualified candidate with knowledge of Chilean law and the new regulatory framework takes time. Many organisations are currently using external DPO service providers while building internal capacity.
The Agency has not yet issued formal sanctions decisions in the first quarter of this year, but it has opened several preliminary investigations and issued information requests to controllers in the retail, financial services and technology sectors. These early actions provide useful signals about enforcement priorities.
Scenario one: a retail company with a loyalty programme. A large retailer operating a loyalty card scheme collects purchase history, location data from in-store tracking and inferred preferences. Under the old law, a broad consent clause in the loyalty card terms was generally sufficient. Under Ley N° 21.719, the retailer must identify a specific legal basis for each processing purpose, provide a layered privacy notice, honour data subject rights requests within thirty days and maintain a record of processing activities. If the retailer uses purchase data to build profiles for targeted advertising by third parties, it must assess whether this constitutes a compatible purpose or requires fresh consent. The Agency';s early guidance suggests that sharing data with third-party advertisers will be scrutinised closely.
Scenario two: a technology company processing data of Chilean users from abroad. A software-as-a-service company headquartered outside Chile provides services to Chilean businesses and processes personal data of Chilean employees and customers. Ley N° 21.719 applies to controllers and processors established outside Chile if they process data of individuals located in Chile in connection with the offering of goods or services, or the monitoring of their behaviour. The company must designate a representative in Chile, comply with the law';s substantive requirements and respond to data subject rights requests within the statutory deadlines. Failure to designate a local representative is itself an infringement and may attract penalties.
A common mistake among foreign technology companies is assuming that compliance with EU or US data protection standards automatically satisfies Chilean requirements. While the new Chilean law draws inspiration from international frameworks, it contains specific procedural and institutional requirements - including the local representative obligation and the Agency';s own adequacy determinations - that require separate compliance steps.
What are the most significant practical risks for businesses that have not yet updated their compliance programmes?
The most immediate risk is exposure to administrative penalties from the Agency, which has broad investigative powers and has signalled active enforcement. Beyond fines, controllers face reputational damage from public enforcement decisions, which the Agency is required to publish. Controllers that cannot demonstrate a record of processing activities, a valid legal basis for each processing operation and a functioning data subject rights procedure are particularly exposed. The absence of a data breach notification procedure is also a high-risk gap, given the seventy-two-hour notification deadline. Businesses should conduct a gap analysis against the requirements of Ley N° 21.719 as a priority.
How long does it realistically take to build a compliant data protection programme in Chile, and what does it cost?
The timeline depends heavily on the size and complexity of the organisation. A small company with limited data processing activities can complete a basic compliance programme - covering a record of processing activities, updated privacy notices, a data subject rights procedure and a breach response plan - in approximately two to three months with appropriate legal and technical support. Larger organisations with complex data flows, international transfers and sensitive data processing should budget four to six months for a thorough programme. Professional fees for legal advice and DPO services vary by scope; organisations should expect costs in the low to mid thousands of USD for a basic programme and significantly more for complex multinational structures.
Should a company appoint an internal DPO or use an external provider?
Both approaches are permitted under Ley N° 21.719, provided the DPO has the required expertise and genuine independence. An internal DPO offers deeper organisational knowledge and is more accessible to staff on a day-to-day basis, but the appointment must be structured carefully to avoid conflicts of interest - the DPO cannot also hold a role that involves making data processing decisions. An external DPO service provider offers specialist expertise and clear independence, which can be particularly valuable for smaller organisations or those in the early stages of building a compliance function. In either case, the DPO';s contact details must be published and communicated to the Agency.
Chile';s data protection landscape has changed fundamentally. Ley N° 21.719 and the establishment of the Agencia de Protección de Datos Personales create a modern, enforceable framework that demands active compliance rather than passive adherence to broad consent clauses. The first quarter of this year has brought concrete procedural rules, early enforcement signals and regulatory guidance that clarify what the Agency expects. Businesses that act now - auditing their processing activities, updating their legal bases and privacy notices, implementing data subject rights procedures and preparing breach response plans - will be far better positioned than those that wait for a formal enforcement action to prompt action.
VLO Law Firms advises international clients on data protection matters in Chile. We can assist with gap analyses, drafting records of processing activities, updating privacy notices, structuring cross-border transfer arrangements and advising on DPO appointments. To request a consultation, contact: info@vlolawfirm.com