Law 21.719, the New Personal Data Protection Law
Law 21.719 is the new Chilean personal data protection law, published on December 13, 2024. This page summarizes what it replaces (the Law 19.628 regime), which security, transparency and demonstrable-accountability obligations it introduces for organizations processing data in Chile, and how it aligns with international standards such as the GDPR.
Last updated:
Law 21.719 is Chile\u2019s new personal data protection law: it rewrites Law 19.628, the statute in force today, creates the Personal Data Protection Agency, sets modern lawful bases and expanded rights, and backs it all with fines of up to 20,000 UTM recorded in a public registry.
This page brings together the essentials of Law 21.719 for companies: the main changes it introduces, the principles that govern data processing and the layout of the statute with its core topics, the rights of data subjects and the implementation timeline, and the obligations, deadlines and sanctions that apply. At the close are the key figures, the frequently asked questions and the official sources.
The law enters into force on December 1, 2026, and a Government bill before the Senate would postpone it to December 1, 2027. If you are working against that calendar, start with what must be operating by December 1, 2026.
Key Changes
The starting point is four changes that reorganize compliance relative to the previous regime.
Mandatory Legal Basis
All processing requires specific legal grounds
Enforceable Rights
Data subjects can exercise rights through formal procedures
Breach Notification
Breach notification without undue delay
Sanctioning Regime
Fines up to 20,000 UTM for violations
Behind these changes are the principles that the law turns into verifiable obligations.
Fundamental Principles
Eight binding principles requiring implementation through verifiable controls
Lawfulness
Requires valid legal basis and documentation to prove it. The controller must demonstrate compliance (accountability).
Purpose
Determined, explicit and lawful purposes. Further processing is limited to these declared purposes.
Security
Technical and organizational measures appropriate to the risk. Breach notification without undue delay.
The principles take shape in a structure of topics that the law develops separately.
Regulatory Structure
The law organizes compliance obligations around guiding principles, data subject rights, and specific duties of the data controller.
Fundamental Principles
The law establishes eight principles governing personal data processing. These principles operate as verifiable obligations that the controller must implement and document.
Data Subject Rights
The law recognizes specific rights enforceable through formal procedures. The controller must respond within established timeframes.
Controller Obligations
The controller must comply with specific obligations: clear information, activity records, security measures and breach notification.
Data Protection Officer
Article 50 lets the controller appoint a data protection officer (“may appoint”). The DPO oversees compliance and acts as the point of contact with the Agency.
Among those topics, the rights of data subjects are detailed below.
Data Subject Rights
Rights enforceable through formal procedures. Response deadline: 15 business days.
Access
Obtain confirmation about processing and access processed data.
Rectification
Correct inaccurate data or update incomplete information.
Erasure
Delete data when the purpose ceases or consent is withdrawn.
Portability
Receive data in structured format for transfer to another controller.
Automated Decisions
Limit decisions based exclusively on automated processing.
All of the above fits within an application calendar with defined milestones.
Implementation Timeline
The law establishes a gradual implementation period toward its entry into force, currently set for December 1, 2026. A Senate bill (bulletin 18.623-07, under top-priority urgency) would postpone it to December 1, 2027; until it passes, the 2026 date governs.
- DEC 2024Enactment of the Law
Official publication of Law 21.719 in the Official Gazette on December 13, 2024.
- 2025Transition Period
Preparation phase and development of complementary regulations by the authority.
- DEC 2026Full Entry into Force
Complete enforcement of Law 21.719 and operation of the Data Protection Agency.
Against that timeline, the concrete obligations, their deadlines and the associated sanctions come into focus.
Obligations, deadlines and sanctions
Compliance with Law 21.719 is structured around the controller's material obligations, tight legal deadlines and a sanctions regime scaled by severity.
Main obligations
- Identify valid legal bases for each processing activity and document traceability (lawfulness and accountability).
- Keep an up-to-date Record of Processing Activities (ROPA) available to the Agency.
- Assess the appointment of a data protection officer, which Article 50 frames as optional (“may appoint”) and which must be a natural person. It is most advisable for public bodies and for large-scale or sensitive-data processing.
- Implement technical and organizational measures appropriate to the risk, consistent with the security principle.
- Sign data processing agreements (DPA) with processors regulating instructions, confidentiality and security.
Key deadlines
- 15 business days to respond to data subject rights requests (access, rectification, deletion, opposition, portability).
- Notification to the Agency, without undue delay, of security breaches that pose a risk to data subjects.
- December 1, 2026: full entry into force and sanctions regime (a Senate bill would postpone this to December 1, 2027).
Sanctions
- Minor infringements: fines up to 5,000 UTM.
- Serious infringements: fines up to 10,000 UTM.
- Very serious infringements: fines up to 20,000 UTM, plus corrective measures and publication of the sanction.
The scope of the law can be summed up in a few figures.
Key Figures of the New Legislation
Relevant data for implementing data protection regulations
Frequently asked questions
The most common questions about the law and its implementation.
What is Law 21.719?
It is the new Chilean personal data protection law, published on December 13, 2024. It replaces the regime of Law 19.628 and introduces a regulatory architecture aligned with international standards such as the General Data Protection Regulation.
When does Law 21.719 enter into force?
The Law contemplates a 24-month vacancy period, so its full entry into force is set for December 1, 2026. A Senate bill (bulletin 18.623-07, entered September 1, 2026 with top-priority urgency) would postpone it to December 1, 2027; until it passes and is published, the 2026 date governs. During the interim period, organizations must adapt processes and appoint Data Protection Officers where applicable.
What rights does it recognize for data subjects?
Access, rectification, deletion, opposition, portability and restriction of processing. Controllers must respond to requests within legal deadlines and keep records of evidence.
What is the Data Protection Officer (DPO)?
It is the figure responsible for supervising compliance within the organization, advising management and serving as the point of contact with the Agency. Its appointment is mandatory for public sector controllers and for organizations carrying out large-scale processing.
What sanctions does the law contemplate?
Fines that scale according to severity up to 20,000 UTM for very serious infringements. The Personal Data Protection Agency is the supervisory authority, with power to impose corrective measures and sanctions.
What obligations does the data controller have?
Principles of lawfulness, purpose, quality and security; duty to inform the data subject; maintenance of processing activity records; impact assessments where applicable; breach notification to the Agency; and DPO appointment in the cases provided for.
Official sources
Related services
Explore complementary practice areas and regulatory analysis from our team.
Law 19.628 (the current regime)
The data law in force today: its demands, commercial information and how Law 21.719 rewrites it.
Processing principles
The Article 3 principles that govern all personal data processing.
Data subject rights
Access, rectification, erasure, objection and portability: how they are exercised and answered.
Controller obligations
Information, security and breach-reporting duties of the data controller.
Breach notification
Who to report a security breach to and when (Article 14 sexies).
Data Protection Officer
What the DPO is, when it is required and what Article 50 demands.
Data Protection Agency
Regulatory, supervisory and sanctioning powers of the new authority.
Sanctions and fines
Minor, serious and very serious infringements: fines of up to 20,000 UTM (Article 35).
Infringement prevention model
The Article 49 compliance program and its regulation (Decree 662): elements, DPO, certification and mitigation.
Board liability
The company faces fines up to 20,000 UTM; the board answers on its duty of care.
International transfers
When data can be transferred outside Chile and under which safeguards.
Impact assessment
When the law requires an impact assessment and how it is carried out.
Postponed to 2027? The December 2026 date
The December 1, 2026 date and the bill postponing it to 2027: infringements, public registry and mitigating factors.
Consent or legitimate interest?
How to choose the lawful basis for each processing activity (Articles 12 and 13).
AI and personal data
Using AI with customer data: lawful basis, transfers and automated decisions.
Data Law diagnosis
Your company’s gaps against Law 21.719: processing activities, lawful bases and duties.
Cybersecurity Framework Law (21.663)
The framework law: ANCI, essential services, obligations and deadlines.
AI & Business
AI governance in business: risks and the applicable framework.
Transform Your Legal Challenges into Competitive Advantages
Discover how our innovative approach can drive your business