Legal-Updates
Legal-Updates

Data Protection Update in Chile: Q2 2026

Chile';s data protection framework is undergoing its most significant transformation in over two decades. The country';s new Personal Data Protection Law - commonly referred to as the New PDPL - has moved from enactment into active implementation, reshaping obligations for every organisation that processes personal data in Chile. For international businesses, the stakes are concrete: new consent requirements, a dedicated supervisory authority, and meaningful administrative penalties are now operational realities rather than future prospects. This guide covers the key legislative changes, regulatory guidance, enforcement signals, and practical steps that compliance teams and business leaders need to understand for chile data protection 2026.

The new Personal Data Protection Law: what changed and why it matters

Chile';s original data protection statute, Law No. 19,628 on the Protection of Private Life, dated from the late 1990s. It was widely regarded as outdated relative to modern data flows, lacking an independent supervisory authority and providing only limited remedies. The New PDPL - enacted as Law No. 21,719 - fundamentally restructures the framework. It introduces a rights-based architecture modelled in part on international standards, including explicit rights of access, rectification, deletion, portability and objection.

The most structurally significant change is the creation of the Agencia de Protección de Datos Personales (the Agency). This independent body is responsible for supervising compliance, issuing binding guidance, conducting investigations, and imposing sanctions. Its establishment marks Chile';s transition from a self-regulatory model to one with genuine public enforcement. The Agency has been progressively staffing up and issuing preliminary guidance, and businesses should treat its communications as authoritative signals of enforcement priorities.

The New PDPL also introduces a tiered classification of personal data. Ordinary personal data, sensitive personal data - including health, biometric, financial and ideological information - and children';s data each attract different processing conditions. Processing sensitive data now requires explicit, specific and informed consent as a baseline, with narrow exceptions for legal obligations and vital interests. A common mistake among foreign operators is assuming that consent obtained under prior practice remains valid; in most cases, consent must be refreshed to meet the new standard.

The law applies extraterritorially where data subjects are located in Chile, regardless of where the data controller or processor is established. This mirrors the approach taken in other modern frameworks and means that foreign companies serving Chilean customers cannot treat the New PDPL as a domestic Chilean concern only.

Key regulatory guidance issued in recent months

The Agency has been active in issuing preliminary guidance and interpretive documents since becoming operational. Several thematic areas have received particular attention, and businesses should review these outputs carefully.

On consent, the Agency has clarified that bundled or pre-ticked consent is not valid under the New PDPL. Consent must be freely given, specific to each processing purpose, informed and unambiguous. Where consent is the legal basis, controllers must be able to demonstrate that it was obtained in compliance with these requirements. The Agency has indicated that it will scrutinise consent mechanisms as a priority area in early supervisory activity.

On data transfers outside Chile, the Agency has begun the process of identifying countries and international organisations that offer an adequate level of protection. Until adequacy determinations are finalised, cross-border transfers require either explicit consent, standard contractual clauses approved by the Agency, or binding corporate rules. Businesses that routinely transfer Chilean personal data to group entities or service providers abroad should map these flows and put appropriate transfer mechanisms in place without delay.

On data breach notification, the New PDPL imposes a mandatory notification obligation. Controllers must notify the Agency within a prescribed period following discovery of a breach that poses a risk to data subjects'; rights. Notification to affected individuals is also required where the breach is likely to result in high risk. The Agency has signalled that it will treat delayed or incomplete notifications as an aggravating factor in any subsequent enforcement action.

In practice, founders and compliance officers should consider that the Agency';s guidance documents, while not yet consolidated into a single code, collectively define the operational standard against which compliance will be measured. Monitoring the Agency';s official publications is not optional for businesses with material Chilean data processing activities.

Enforcement signals and early supervisory activity

Although the New PDPL';s full enforcement regime is still in its early phase, the Agency has begun exercising its supervisory powers. Several preliminary investigations have been opened, primarily in the financial services, telecommunications and retail sectors. These sectors were selected because they involve large-scale processing of sensitive financial data and because consumer-facing data practices in these industries had attracted complaints under the prior regime.

The New PDPL establishes a graduated sanctions framework. Infringements are classified as minor, serious or very serious, with maximum fines calibrated accordingly. Very serious infringements - such as unlawful processing of sensitive data or systematic obstruction of data subject rights - attract the highest tier of penalties. While exact statutory figures are set out in the law itself, the practical point for businesses is that the penalty levels represent a material financial exposure, particularly for larger organisations whose turnover is used as a reference point for calculating proportionate sanctions.

A non-obvious requirement is that the Agency can also order remedial measures, including suspension of processing activities, as an interim step during an investigation. This power is significant because it can disrupt business operations before any final determination of liability. Businesses should therefore treat an Agency inquiry as a serious operational matter, not merely a legal formality.

Early enforcement signals suggest that the Agency is particularly focused on: transparency and privacy notice quality; the validity of consent mechanisms; and the handling of data subject rights requests. Organisations that have not updated their privacy notices to reflect the New PDPL';s requirements, or that lack documented procedures for responding to access and deletion requests within the statutory timeframes, are exposed.

If your organisation has received a preliminary inquiry from the Agency or is uncertain about its compliance posture, reaching out to specialist counsel early is advisable. We can help structure the setup correctly the first time and assist with preparing responses to regulatory inquiries. Contact us at info@vlolawfirm.com.

Practical compliance priorities for businesses operating in Chile

The transition to the New PDPL requires a structured compliance programme rather than a series of ad hoc fixes. The following areas represent the highest-priority actions for most organisations.

Data mapping and inventory. The New PDPL requires controllers to maintain records of processing activities. This obligation mirrors Article 30 of the GDPR and is a prerequisite for demonstrating compliance. A common mistake is treating data mapping as a one-time exercise; it must be a living document updated as processing activities change.

Legal basis review. Every processing activity must rest on a valid legal basis under the New PDPL. The available bases include consent, contractual necessity, legal obligation, vital interests, public interest and legitimate interests. Many organisations that relied on a broad legitimate interests basis under the prior regime will need to reassess whether that basis is available and properly documented under the new framework.

Privacy notices. Notices must be updated to include all information required by the New PDPL, including the identity and contact details of the controller, the purposes and legal bases for processing, data retention periods, information about cross-border transfers, and a clear description of data subject rights. Notices must be written in plain language accessible to the intended audience.

Data subject rights procedures. The New PDPL sets specific timeframes for responding to access, rectification, deletion, portability and objection requests. Organisations must have documented internal procedures, designated responsible staff, and technical capabilities to fulfil these requests within the required periods. Many underestimate the operational effort required to respond to portability requests, which involve providing data in a structured, commonly used and machine-readable format.

Data processing agreements. Where personal data is processed by third-party service providers acting as processors, the New PDPL requires a written data processing agreement that specifies the subject matter, duration, nature and purpose of processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller. Existing vendor contracts should be reviewed and updated.

Data protection officer. The New PDPL requires certain categories of controller to appoint a Data Protection Officer (DPO). The obligation applies to public bodies and to private organisations that carry out large-scale processing of sensitive data or systematic monitoring of data subjects. Even where a formal DPO appointment is not legally required, designating an internal compliance lead with clear responsibility for data protection is strongly advisable.

Consider two practical scenarios. A multinational retailer operating e-commerce in Chile collects customer data including purchase history, browsing behaviour and payment information. Under the New PDPL, it must maintain a processing record, ensure its consent mechanism for marketing communications meets the new standard, and have a documented procedure for handling deletion requests from Chilean customers - even if its data infrastructure is based abroad. Separately, a financial services firm processing credit data on Chilean individuals must classify that data as sensitive financial information, apply the heightened processing conditions, and ensure that any transfers to overseas credit bureaux are covered by an adequate transfer mechanism.

Cross-border data transfers: the current position

Cross-border data transfers are one of the most operationally complex areas under the New PDPL, particularly for multinational groups that centralise data processing in regional hubs outside Chile.

The New PDPL prohibits transfers of personal data to third countries or international organisations that do not provide an adequate level of protection, unless one of the permitted derogations applies. The Agency is responsible for assessing adequacy, and this process is ongoing. Until adequacy decisions are issued for specific destinations, organisations must rely on alternative transfer mechanisms.

The principal alternative mechanisms are: explicit consent of the data subject (which must meet the full consent standard and is therefore impractical as a general transfer mechanism for large-scale processing); standard contractual clauses in a form approved or recognised by the Agency; and binding corporate rules for intra-group transfers, subject to Agency approval. The Agency has indicated that it will publish model standard contractual clauses, but these had not been finalised as of the period covered by this update.

A practical complication is that many organisations have existing data transfer agreements based on mechanisms from other jurisdictions - for example, EU standard contractual clauses. The extent to which these will be recognised or accepted by the Agency as equivalent has not yet been definitively resolved. Businesses should seek specific legal advice on whether existing transfer mechanisms are sufficient under the New PDPL or whether Chilean-specific documentation is required.

Many underestimate the lead time required to implement binding corporate rules. The approval process involves submitting detailed documentation to the Agency, and approval is not guaranteed or automatic. Organisations that rely on intra-group transfers as a core part of their data architecture should begin this process as early as possible.

FAQ

What is the most significant practical risk for foreign companies under Chile';s New PDPL?

The most significant risk for foreign companies is the extraterritorial scope of the New PDPL combined with the establishment of an active supervisory authority. Unlike the prior regime, which lacked meaningful enforcement infrastructure, the Agency now has the power to investigate, sanction and order remedial measures against any organisation processing data of individuals located in Chile, regardless of where the organisation is based. Foreign companies that have not updated their consent mechanisms, privacy notices and data transfer arrangements to comply with the New PDPL are exposed to enforcement action, including fines and orders to suspend processing. The risk is heightened for organisations in sectors the Agency has identified as priorities, including financial services, telecommunications and retail.

How long does it take to build a compliant data protection programme under the New PDPL, and what does it cost?

The timeline depends heavily on the size and complexity of the organisation';s data processing activities. A small business with limited data flows can typically complete a basic compliance programme - covering data mapping, legal basis review, privacy notice updates and data subject rights procedures - within two to three months with appropriate professional support. Larger organisations with complex processing activities, multiple vendors and cross-border transfers should budget six to twelve months for a thorough programme. Professional fees for legal and compliance support vary by scope; organisations should expect meaningful investment at the outset, with ongoing costs for monitoring regulatory developments and maintaining documentation. The cost of non-compliance - including potential fines, reputational damage and operational disruption from enforcement action - generally exceeds the cost of a proactive compliance programme.

Should a business appoint a Data Protection Officer even if it is not legally required to do so?

Even where the formal DPO obligation does not apply, appointing or designating a responsible individual for data protection is strongly advisable. The New PDPL places significant ongoing obligations on controllers, including maintaining processing records, responding to data subject rights requests within statutory timeframes, managing data breach notifications, and keeping pace with Agency guidance. Without a designated person accountable for these obligations, compliance tends to be reactive and inconsistent. In practice, the Agency is likely to view the absence of any internal data protection governance as an indicator of systemic non-compliance. For organisations with material data processing activities in Chile, a DPO or equivalent role - whether internal or outsourced - is a sound investment regardless of strict legal obligation.

Conclusion

Chile';s data protection landscape has changed fundamentally with the New PDPL and the establishment of the Agency. Organisations that process personal data relating to individuals in Chile - whether domestic or foreign - now operate under a framework with real supervisory teeth and meaningful compliance obligations. The priority areas are clear: consent, transparency, data subject rights, cross-border transfers and breach notification. Acting now, rather than waiting for enforcement to arrive, is the rational approach.

VLO Law Firms advises international clients on data protection matters in Chile. We can assist with compliance programme design, privacy notice drafting, data transfer mechanism implementation, DPO support, and regulatory inquiry responses. To request a consultation, contact: info@vlolawfirm.com