Dupouy Méndez Abogados

Compliance & Corporate Governance

Law 21.719: What Companies in Chile Must Do Before December 1, 2026

Law 21.719: What Companies in Chile Must Do Before December 1, 2026
Rodrigo Dupouy Bunster
Rodrigo Dupouy Bunster

September 5, 2026 · 7 min read

Key takeaways

  1. 1Law 21.719 ends Chile's largely symbolic enforcement of data protection: starting December 1, 2026, a dedicated agency will have real sanctioning power.
  2. 2With only three months left, companies need to build a record of their data processing activities, review their lawful bases, and update contracts with vendors that process data on their behalf.
  3. 3The risk is no longer just reputational: repeated serious violations can cost up to 4% of a company's annual revenue.

Chile has a new Personal Data Protection Law. Law No. 21.719, published in the Official Gazette on December 13, 2024, replaces the old Law No. 19.628 of 1999 — until now one of the most outdated data protection frameworks in the region — and will enter into force on December 1, 2026, after a 24-month transitional period. For companies operating in Chile, that date is far more than an administrative formality: it marks the shift from a regime with virtually no real enforcement to one with a dedicated regulator, genuine sanctioning powers, and fines that can reach a percentage of a company's annual revenue.

With only three months left before it takes effect, companies — especially those that process customer, employee, or vendor data — should understand what is changing and what they need to implement beforehand.

What the new law creates

Law 21.719 creates the Agency for the Protection of Personal Data (Agencia de Protección de Datos Personales, or APDP), a new public body empowered to oversee compliance, issue guidance to companies, and impose administrative sanctions. This replaces the previous framework, under which enforcement of Law 19.628 fell, in a limited and partial way, to the Council for Transparency (Consejo para la Transparencia) — with no dedicated authority and no meaningful sanctioning regime.

Alongside this new institutional framework, the law modernizes the core concepts of Chilean data protection law, aligning them — with its own nuances — with standards such as the EU's General Data Protection Regulation (GDPR): stricter lawful bases for processing, new rights for data subjects, and concrete documentation obligations for data controllers.

Lawful bases for processing

Under the new law, processing personal data requires a valid lawful basis. Among those the law recognizes are the data subject's consent — which must be freely given, informed, specific as to its purpose, prior, and unambiguous —, compliance with a legal obligation, the performance of a contract or pre-contractual measures requested by the data subject, the controller's legitimate interest, and the exercise or defense of legal claims before courts or public authorities.

Legitimate interest deserves particular attention because, unlike consent, it cannot simply be invoked: the company must be able to document an assessment weighing the purpose pursued, the necessity of the processing, its impact on data subjects, and the safeguards adopted. In practice, this means legitimate interest cannot be used as a catch-all basis — it requires prior documentation to support its validity.

New rights and deadlines for data subjects

The law strengthens the traditional access, rectification, erasure, and objection rights (known in Chile as "derechos ARCO") and adds a right to data portability. Companies must respond to these requests within 30 calendar days of receipt, extendable once for up to 30 additional calendar days.

The law also provides for a temporary data-blocking mechanism for certain requests, with a 2-business-day deadline, and allows data subjects to file a complaint with the Agency if unsatisfied with the response, within 30 business days of the request.

This means companies need, before December 2026, a formal and traceable channel for receiving and processing these requests: responding "in good faith" by email, with no logging or deadline tracking, will no longer be enough.

Operational obligations for companies

Beyond general principles, the law imposes concrete compliance duties. The first is the Record of Processing Activities (RAT): a documented inventory of what data is processed, for what purpose, under what lawful basis, and with what security measures. The second is impact assessments, required for high-risk processing activities affecting data subjects' rights, such as large-scale processing of sensitive data or systematic profiling of individuals.

The law also contemplates a Data Protection Officer, though appointing one is not automatically mandatory for every company — it depends on the volume, nature, and risk of the processing involved. Even so, every organization should formally designate who is responsible for responding to the Agency and to data subjects, whether or not the strict DPO requirement applies. Added to this are contracts with data processors — external vendors that process data on the company's behalf, such as payroll providers, marketing platforms, or cloud storage — which must be bound by agreements governing that processing.

Finally, when an incident compromises personal data, the company must notify the Agency without undue delay and by the most expeditious means available. Unlike the GDPR, the law does not set a fixed hour-based deadline, but it does require the company to be able to demonstrate that no unjustified delay occurred. When a breach involves sensitive data, the personal data of minors under 14, or financial data, affected data subjects must also be notified directly.

Enforcement and penalties

The sanctioning regime is the most significant deterrent compared with Law 19.628. Violations are classified as minor (fines of up to 5,000 UTM), serious (up to 10,000 UTM), and very serious (up to 20,000 UTM) — the UTM (Unidad Tributaria Mensual) being a Chilean monthly tax unit used to index fines and other obligations. In cases of repeated serious or very serious violations, the fine may instead be calculated as a percentage — 2% to 4% — of the company's annual revenue in Chile. The Agency may also order corrective measures and, in the most serious cases, temporary suspensions of up to 30 days. Violations expire after 4 years, and sanctions already imposed expire after 3 years from the date the ruling becomes final.

One relevant detail for small and medium-sized businesses: during the law's first 12 months in force (i.e., roughly until December 2027), the Agency has the authority to issue a written warning instead of a fine for certain violations — in practice, a more flexible adjustment period for SMEs. This does not exempt them from compliance, but it does soften the immediate sanctioning risk for those adapting in good faith.

A necessary caveat

It's worth being clear about the current state of this matter: Law 21.719 has not yet entered into force, and the Agency for the Protection of Personal Data is not yet operating with full enforcement powers, so there is, as of now, no consolidated administrative or judicial case law interpreting its provisions. Any analysis of its practical application is, for now, preventive and doctrinal in nature, and should be treated with that caution.

What a company should do today

With only three months left before the law takes effect, the room to adapt calmly has already narrowed considerably. A realistic compliance plan, on this timeline, should prioritize building a real inventory of the company's data processing activities — the input for the RAT —, reviewing the lawful basis underlying each one, updating or drafting contracts with vendors acting as data processors, and formally designating an internal privacy lead, regardless of whether the strict DPO requirement applies. Delaying this work beyond the next three months leaves the company exposed right as the Agency begins to actively enforce the law.

Related service

Data Protection

How we can help

Our team is ready to advise you on your most complex legal challenges.

Schedule a Meeting