Personal data protection

DPIA (Data Protection Impact Assessment): What It Is and When It Is Mandatory

Law 21.719 requires assessing impact before starting high-risk processing. This guide explains when a DPIA is mandatory, the minimum content set by Article 15 ter and how to carry it out.

Last updated:

What is a DPIA?

The DPIA or Data Protection Impact Assessment is the analysis required by Article 15 ter of Law 19.628, introduced by Law 21.719, before starting any processing likely to produce high risk for data subjects' rights: it describes the processing, assesses its necessity and proportionality, identifies the risks and defines the mitigation measures.

This page explains when an impact assessment applies, its phases, the methodology and when the Agency must be consulted.

When a DPIA Is Mandatory

Article 15 ter requires the assessment before processing starts whenever high risk for data subjects is likely. It is always required in four cases:

  • Systematic and comprehensive evaluation of personal aspects based on automated processing or decisions, such as profiling, with significant legal effects on the data subject.
  • Massive or large-scale data processing.
  • Systematic observation or monitoring of a publicly accessible area.
  • Processing of sensitive and specially protected data under the consent exceptions.

The Personal Data Protection Agency will publish an indicative list of the operations that require an assessment. In practice, the most frequent scenarios look like this:

Systematic and Comprehensive Evaluation

  • Automated profiling
  • Scoring systems and automated decisions
  • Predictive behavior analysis

Large-Scale Sensitive Data

  • Massive health data processing
  • Biometric data for identification
  • Sexual orientation information

Systematic Observation

  • Video surveillance in public spaces
  • Continuous geolocation
  • Online behavior monitoring

Minimum content of a DPIA

Article 15 ter sets the floor: the Agency will issue guidance built on at least these elements.

  • Description of the processing operations and their purpose.
  • Assessment of the necessity and proportionality of the processing regarding that purpose.
  • Assessment of the risks for data subjects.
  • Mitigation measures for the identified risks.

The controller must document the assessment and keep it available: before the Agency, the DPIA is the central evidence of proactive accountability for high-risk processing.

Impact Assessment Phases

The assessment moves through successive phases.

  1. Systematic Processing Description

    Comprehensive documentation of the nature, scope, context, and purposes of the projected processing, including involved technologies.

    Key Elements

    • Data categories and sources
    • Technologies and algorithms used
    • Data flows and recipients
  2. Necessity and Proportionality Assessment

    Analysis of the legitimate purpose of processing and proportionality of means employed regarding pursued objectives.

    Proportionality Test

    • Suitability of means
    • Necessity (less intrusive alternatives)
    • Proportionality stricto sensu
  3. Risk Assessment

    Systematic identification and analysis of risks to data subjects' rights and freedoms, considering probability and impact.

    Risk Categories

    • Unauthorized access or disclosure
    • Unwanted modification
    • Disappearance, destruction, or loss
  4. Mitigation Measures

    Design and implementation of technical and organizational safeguards to reduce identified risks to acceptable levels.

    Types of Measures

    • Technical: encryption, pseudonymization
    • Organizational: policies, training
    • Legal: contracts, terms of use

A concrete working methodology rests on those phases.

Assessment Methodology and Tools

Effective DPIA requires structured methodologies and specialized tools that ensure comprehensive analysis and technically sound, legally robust results.

Data Flow Mapping

Visual representation of all personal data flows, from collection to deletion, identifying critical points and system interfaces.

Risk Matrix

Quantitative tool to assess probability and impact of each identified risk, enabling objective prioritization of mitigation measures.

Stakeholder Consultation

Structured consultation process with data subjects, technical experts, and representatives of relevant interest groups for the assessed processing.

Independent Validation

Review by external specialists to ensure objectivity, comprehensiveness, and technical quality of the conducted assessment.

Consulting the Data Protection Agency

If the assessment shows the processing is high-risk, the controller may consult the Personal Data Protection Agency for recommendations before starting it (Article 15 ter). Unlike the European regulation, Chilean law contemplates no mandatory prior consultation: it is voluntary and its recommendations guide the design of mitigation measures.

Article 15 ter
Voluntary consultation when the assessment confirms high risk
Dec 1, 2026
The DPIA obligation applies from the law's entry into force (postponement to 2027 before Congress)

DPIA and artificial intelligence

AI systems concentrate the legal triggers of the assessment.

A model that scores candidates, segments clients or automates decisions falls squarely within the first trigger of Article 15 ter: systematic evaluation based on automated processing with significant effects. Training and operating these systems also tends to involve large-scale processing. For most companies adopting AI, the DPIA is therefore not optional: it is the tool that documents why the use is necessary, proportionate and controlled. Our guide on AI and personal data covers the substantive rules.

The timing matters: the obligation applies from December 1, 2026 (a bill before the Senate would postpone it to December 1, 2027). If a high-risk system will be in production by entry into force, the assessment must exist first. See what must be operating by December 1, 2026.

Frequently asked questions

Short answers to the most frequent questions about the impact assessment.

What is a Data Protection Impact Assessment (DPIA)?

It is the prior analysis the controller must perform when processing entails high risk to data-subject rights. Its goal is to identify risks, assess their likelihood and impact, and set technical and organisational measures to mitigate them before processing begins.

When is a DPIA mandatory under Law 21.719?

When processing is likely to produce high risk for data subjects' rights. Article 15 ter always requires it in four cases: systematic and comprehensive evaluation based on automated processing or decisions with significant legal effects, such as profiling; massive or large-scale processing; systematic monitoring of a publicly accessible area; and sensitive data under the consent exceptions. The Agency will publish an indicative list of operations that require it.

What minimum content must the DPIA cover?

Description of processing and its purposes, assessment of necessity and proportionality, identification of risks to subjects, planned measures to address them and mechanisms for consulting stakeholders where appropriate. It must be documented and retained for supervision.

When should the Agency be consulted before processing?

When the assessment shows the processing is high-risk. The Article 15 ter consultation is voluntary: it allows the controller to obtain recommendations from the Personal Data Protection Agency before processing starts. Unlike the European regulation, Chilean law contemplates no mandatory prior consultation and no response period suspending the start.

What happens if high-risk processing starts without a DPIA?

It breaches an express obligation of Article 15 ter and leaves the company without its main evidence of proactive accountability. Facing an inspection or a breach, the missing DPIA worsens the controller's position, weakens its defence and compromises the lawful continuation of processing.

Transform Your Legal Challenges into Competitive Advantages

Discover how our innovative approach can drive your business

© 2026 AnguitaOsorio, all rights reserved.
Chile

Contact

Contáctanos

Phone:

+56 2 2760 4512

Location:

Cerro el Plomo 5420, office 1306, Las Condes, Metropolitan Region.