In force: December 1, 2026
Personal Data Protection Law (Law 21.719)
Law 21.719 replaces a 1999 data protection framework and creates a new Agency with the power to investigate on its own initiative, suspend data processing, and impose fines of up to 20,000 UTM, with a surcharge of up to 4% of annual revenue in case of repeat infringement. It takes effect in just a few months.
Law 21.719 completely modernizes personal data protection in Chile, replacing 1999-era rules that no longer matched how companies collect, store, and use data today. Starting December 1, 2026, every company that processes data belonging to customers, employees, or vendors becomes subject to an active enforcement regime, not just general principles.
The new Personal Data Protection Agency can investigate on its own initiative, without a prior complaint, order a company to suspend data processing, and publish sanctions in a public registry. For many companies this law changes the compliance standard overnight, and the window to prepare before it takes effect is closing.
How we work
Compliance gap assessment
We evaluate how your company handles personal data today — customer, employee, and vendor data — and measure the real gap against Law 21.719's requirements before it takes effect.
Data Protection Officer (DPO) appointment
The law requires a DPO for public bodies and companies whose core activity involves large-scale processing of sensitive data or systematic monitoring of individuals; for everyone else it's voluntary, but advisable within any serious infringement-prevention model. We assess whether your company is required to appoint one and can act as your outsourced DPO.
Policies, consent, and vendor contracts
Drafting privacy policies, consent flows, procedures for exercising ARCO rights (Access, Rectification, Cancellation, Opposition) and data portability, and updating contracts with vendors who process data on the company's behalf.
Breach response protocol and training
Design of the internal protocol for responding to a security breach, including timelines and the procedure for reporting to the Agency, plus staff training on the new obligations.
Frequently Asked Questions
When does Law 21.719 take effect, and what happens if my company isn't ready?+
The law was published on December 13, 2024, and takes effect on December 1, 2026. From that date, the Personal Data Protection Agency can investigate on its own initiative and impose fines of up to 5,000 UTM for minor infringements, up to 10,000 UTM for serious infringements, and up to 20,000 UTM for very serious infringements — as of August 2026 values, that top figure equals roughly CLP $1.43 billion (approximately USD 1.57 million). In case of repeat serious or very serious infringements, companies that don't qualify as small can also face a fine of up to 2% or 4% of their annual revenue from sales and services in Chile, whichever is greater between that figure and triple the original fine. Not having been inspected before is no guarantee of being compliant: the new regime is active, not reactive.
Is my company required to appoint a Data Protection Officer (DPO)?+
It's mandatory for public bodies and for companies whose core activity involves large-scale processing of sensitive data or systematic monitoring of individuals. For other companies, appointing one is voluntary, but it's becoming an expected part of any serious infringement-prevention model. The assessment depends on the volume and type of data your company handles, not on its size.
What changes compared to the previous law (Law 19.628)?+
Law 19.628, from 1999, set out general principles with virtually no enforcement. Law 21.719 creates a real enforcement authority (the Agency), expands data subjects' rights (ARCO plus data portability), requires clearer legal grounds for processing data, and establishes a sanctions regime proportional to company revenue, not symbolic fixed amounts.
Let's talk about data protection
Tell us about your situation and we'll respond within 24 business hours.
Schedule a Meeting