Is the Data Law postponed to 2027? What happens if your company is not ready by December 1, 2026
On that date the amendments of Law 21.719 to Law 19.628 become enforceable and the Personal Data Protection Agency can sanction. The question worth answering is which of your current data operations would already fall within an infringement category.
Last updated:
Law 21.719 enters into force on December 1, 2026, and from that date the Personal Data Protection Agency can impose fines of up to 5,000 UTM for minor infringements, 10,000 UTM for serious ones and 20,000 UTM for very serious ones (Article 35, Law 19.628). A Government bill before the Senate, under top-priority urgency, would postpone that start to December 1, 2027; until Congress passes it, the 2026 date stands.
The fine is not the whole exposure. Sanctions are recorded in a public registry (Article 39), civil liability toward data subjects runs separately (Article 34), and repeat infringements escalate the amounts. The company that prepares in time also gains something concrete: the law rewards it with express mitigating circumstances (Article 36).
Where the date comes from
Law 21.719 was published in the Official Gazette on December 13, 2024. Its first transitional article sets the entry into force of the amendments to Law 19.628 for the first day of the twenty-fourth month after publication: December 1, 2026. The same law ordered the enforcement apparatus to be ready in advance: the regulations within six months of publication, and the Board of the Agency appointed six months before entry into force (second and fourth transitional articles).
The postponement bill: what it proposes and what it does not touch
The bill the Government had announced (Message No. 110-374) entered the Senate on September 1, 2026 as bulletin 18.623-07, went to the Constitution Commission and carries top-priority urgency (urgencia suma), a fifteen-day legislative clock per chamber that the Government has already renewed twice, on September 8 and 22, while the commission prepares its first report. It proposes three changes. First, entry into force moves from December 1, 2026 to a fixed date: December 1, 2027. Second, the Agency's Board grows from three to five members, with a session quorum of three, partial renewal every two years, and the first appointment due at the latest twelve months before entry into force (or within ten days of publication if less than twelve months remain). Third, the option to close a first infringement with a written reprimand instead of a fine during the first twelve months, today reserved for smaller companies, extends to every regulated entity.
The context matters as much as the text. Three days earlier, on August 28, 2026, the Comptroller General completed the legal review (toma de razón) of Supreme Decree No. 662, the regulation for the Article 49 infringement prevention model, and the Diario Oficial published it on September 9, 2026. The implementation apparatus is finally moving; what the bill changes is when enforcement starts, not what is required.
Until the bill passes and the amendment is published, December 1, 2026 remains the enforceable date. And a postponement changes no substantive duty: the inventory, the lawful bases, the rights procedures and the security measures are the same work at either date. A company that freezes its preparation while waiting for a new deadline only spends a year losing the mitigating position the law grants to those who prepare early.
The infringements enforceable from that date
Article 34 of Law 19.628 classifies infringements as minor, serious and very serious, and Articles 34 bis to 34 quáter list them. These are not exotic scenarios: several describe routine practices in companies that never adapted their data operations.
Formal duties
Written reprimand or fine. They include failing the duty of information and transparency (Article 14 ter), lacking an updated and working contact channel for data subjects, and answering rights requests late or incompletely (Article 34 bis).
Processing without legal basis
They include processing personal data without consent or another lawful basis, or for a different purpose; disclosing data without consent where it is required; and hindering the exercise of access, rectification, erasure, objection or portability rights (Article 34 ter).
Knowing or fraudulent conduct
They include fraudulent processing; knowingly processing or disclosing sensitive data or children’s data against the law; deliberately omitting the notification of security breaches; and knowingly unlawful international data transfers (Article 34 quáter).
The caps are not the ceiling in every case. If the company does not remedy the causes within sixty days, the fine increases by 50%. Recidivism allows the Agency to apply up to three times the amount and, for companies above the small-business threshold of Law 20.416, up to 2% or 4% of annual revenue for repeated serious or very serious infringements (Article 35). The full regime is covered in sanctions and fines under Law 21.719.
The cost that does not appear in the fine
Article 39 of Law 19.628 creates the National Registry of Sanctions and Compliance: public, free to access and electronic. A sanction does not stay between the company and the Agency; it becomes verifiable by clients, banks, insurers and counterparties in due diligence. And Article 34 makes explicit that administrative liability runs without prejudice to civil or criminal liability toward the affected data subjects.
What the law grants to those who prepare
Article 36 lists express mitigating circumstances: unilateral remediation, cooperation with the Agency, absence of prior sanctions, self-reporting, and diligent compliance with data supervision duties evidenced by certification. That certification comes from the infringement prevention model of Article 49: a voluntary compliance program that requires, among other elements, designating a data protection officer. The Agency certifies it and lists certified entities in the public registry (Article 51).
The logic mirrors what Law 20.393 does in criminal matters: the program is voluntary, its effects are not. The company that documents prevention before the infringement occurs litigates from a different position than the one that improvises afterwards.
The rulebook for that model now exists. Supreme Decree No. 662 of the Ministry of Finance, published in the Diario Oficial on September 9, 2026, details what the compliance program must contain: a characterization of every processing activity (which a record of processing activities satisfies), a risk matrix graduated by infringement severity, protocols, an internal reporting channel that protects the whistleblower’s identity, internal sanctions, and a data protection officer, whose designation is mandatory within the model. Certification by the Agency lasts three years and is renewable, and implementation may begin before the entity is entered in the registry. The full breakdown is in the infringement prevention model.
What must be operating by December 1
- An inventory of data processing activities, each with an identified lawful basis: consent (Article 12) or one of the other sources of lawfulness (Article 13). How to choose between them is covered in consent or legitimate interest.
- Procedures and deadlines to answer access, rectification, erasure, objection and portability requests from data subjects.
- The duty of information and transparency covered: privacy policy available and a working contact channel (Article 14 ter).
- Security measures proportional to the processing (Article 14 quinquies) and a protocol to report breaches to the Agency without undue delay (Article 14 sexies).
- Contracts in force with data processors that set instructions, purposes and security measures.
- A documented decision on designating a data protection officer and adopting the Article 49 prevention model.
Frequently asked questions
When does Law 21.719 enter into force?
The date in force today is December 1, 2026: the first transitional article sets entry into force for the first day of the twenty-fourth month after publication (December 13, 2024). The Government sent the Senate a bill replacing that rule with a fixed date, December 1, 2027 (bulletin 18.623-07, entered on September 1, 2026 with top-priority urgency). Until Congress passes it and the amendment is published, December 1, 2026 governs.
What does the postponement bill propose?
The bill (Message No. 110-374, bulletin 18.623-07, in first reading before the Senate Constitution Commission with top-priority urgency) proposes three changes: it postpones entry into force to December 1, 2027; it expands the Agency's Board from three to five members, appointed at the latest twelve months before entry into force; and it extends to all companies, not only smaller ones, the Agency's power to issue a written reprimand instead of a fine during the first twelve months. It touches no substantive duty: it changes when enforcement starts, not what is required.
What are the maximum fines?
Up to 5,000 UTM for minor infringements, up to 10,000 UTM for serious ones and up to 20,000 UTM for very serious ones (Article 35, Law 19.628). If the company does not remedy the causes within sixty days, the fine increases by 50%. Recidivism allows up to three times the amount and, for companies above the small-business threshold, up to 2% or 4% of annual revenue.
Does the law also apply to SMEs?
Yes. Article 33 reaches every data controller, whether a natural or legal person, public or private. The law recognizes size differences in dosage: the Agency must set differentiated standards considering smaller companies (Article 14 septies), and revenue-percentage fines only apply to larger companies.
Is the infringement prevention model mandatory?
No, it is voluntary (Article 49). Its effects are not: diligent compliance evidenced by the Agency’s certification is a mitigating circumstance (Article 36 No. 5), and certified entities are listed in the National Registry of Sanctions and Compliance, a public registry (Articles 39 and 51). Its regulation (Supreme Decree No. 662, Ministry of Finance) was published in the Diario Oficial on September 9, 2026 and details the program elements, the data protection officer's role and the three-year renewable certification.
Official sources
- Law 21.719, first, second and fourth transitional articles (entry into force and enforcement setup): BCN/LeyChile
- Law 19.628 as amended by Law 21.719, Articles 12-14, 33-36, 39, 49 and 51 (lawful bases, duties, infringements, sanctions, registry, prevention model): BCN/LeyChile
- Bulletin 18.623-07 (Message No. 110-374), bill amending Law 21.719 (postponement to December 1, 2027, five-member Board, first-year written reprimand for all): Senado de Chile
- Supreme Decree No. 662 (2025), Ministry of Finance, regulation of the Article 49 infringement prevention model, published on September 9, 2026: Diario Oficial
Transform Your Legal Challenges into Competitive Advantages
Discover how our innovative approach can drive your business