Personal data protection

Law 21.719, the New Personal Data Protection Law

Law 21.719 is the new Chilean personal data protection law, published on December 13, 2024. This page summarizes what it replaces (the Law 19.628 regime), which security, transparency and demonstrable-accountability obligations it introduces for organizations processing data in Chile, and how it aligns with international standards such as the GDPR.

Last updated:

Law 21.719 is Chile\u2019s new personal data protection law: it rewrites Law 19.628, the statute in force today, creates the Personal Data Protection Agency, sets modern lawful bases and expanded rights, and backs it all with fines of up to 20,000 UTM recorded in a public registry.

This page brings together the essentials of Law 21.719 for companies: the main changes it introduces, the principles that govern data processing and the layout of the statute with its core topics, the rights of data subjects and the implementation timeline, and the obligations, deadlines and sanctions that apply. At the close are the key figures, the frequently asked questions and the official sources.

The law enters into force on December 1, 2026, and a Government bill before the Senate would postpone it to December 1, 2027. If you are working against that calendar, start with what must be operating by December 1, 2026.

Key Changes

The starting point is four changes that reorganize compliance relative to the previous regime.

Mandatory Legal Basis

All processing requires specific legal grounds

Enforceable Rights

Data subjects can exercise rights through formal procedures

Breach Notification

Breach notification without undue delay

Sanctioning Regime

Fines up to 20,000 UTM for violations

Behind these changes are the principles that the law turns into verifiable obligations.

Fundamental Principles

Eight binding principles requiring implementation through verifiable controls

Lawfulness

Requires valid legal basis and documentation to prove it. The controller must demonstrate compliance (accountability).

Purpose

Determined, explicit and lawful purposes. Further processing is limited to these declared purposes.

Security

Technical and organizational measures appropriate to the risk. Breach notification without undue delay.

View all 8 principles →

The principles take shape in a structure of topics that the law develops separately.

Regulatory Structure

The law organizes compliance obligations around guiding principles, data subject rights, and specific duties of the data controller.

Fundamental Principles

The law establishes eight principles governing personal data processing. These principles operate as verifiable obligations that the controller must implement and document.

Detailed analysis of each principle →

Data Subject Rights

The law recognizes specific rights enforceable through formal procedures. The controller must respond within established timeframes.

Rights fulfillment procedures →

Controller Obligations

The controller must comply with specific obligations: clear information, activity records, security measures and breach notification.

Detailed obligations →

Data Protection Officer

Article 50 lets the controller appoint a data protection officer (“may appoint”). The DPO oversees compliance and acts as the point of contact with the Agency.

DPO requirements and functions →

Among those topics, the rights of data subjects are detailed below.

Data Subject Rights

Rights enforceable through formal procedures. Response deadline: 15 business days.

Access

Obtain confirmation about processing and access processed data.

Rectification

Correct inaccurate data or update incomplete information.

Erasure

Delete data when the purpose ceases or consent is withdrawn.

Portability

Receive data in structured format for transfer to another controller.

Automated Decisions

Limit decisions based exclusively on automated processing.

See AI implications inside the company →

Fulfillment procedures →

All of the above fits within an application calendar with defined milestones.

Implementation Timeline

The law establishes a gradual implementation period toward its entry into force, currently set for December 1, 2026. A Senate bill (bulletin 18.623-07, under top-priority urgency) would postpone it to December 1, 2027; until it passes, the 2026 date governs.

  1. DEC 2024
    Enactment of the Law

    Official publication of Law 21.719 in the Official Gazette on December 13, 2024.

  2. 2025
    Transition Period

    Preparation phase and development of complementary regulations by the authority.

  3. DEC 2026
    Full Entry into Force

    Complete enforcement of Law 21.719 and operation of the Data Protection Agency.

Against that timeline, the concrete obligations, their deadlines and the associated sanctions come into focus.

Obligations, deadlines and sanctions

Compliance with Law 21.719 is structured around the controller's material obligations, tight legal deadlines and a sanctions regime scaled by severity.

Main obligations

  • Identify valid legal bases for each processing activity and document traceability (lawfulness and accountability).
  • Keep an up-to-date Record of Processing Activities (ROPA) available to the Agency.
  • Assess the appointment of a data protection officer, which Article 50 frames as optional (“may appoint”) and which must be a natural person. It is most advisable for public bodies and for large-scale or sensitive-data processing.
  • Implement technical and organizational measures appropriate to the risk, consistent with the security principle.
  • Sign data processing agreements (DPA) with processors regulating instructions, confidentiality and security.

Key deadlines

  • 15 business days to respond to data subject rights requests (access, rectification, deletion, opposition, portability).
  • Notification to the Agency, without undue delay, of security breaches that pose a risk to data subjects.
  • December 1, 2026: full entry into force and sanctions regime (a Senate bill would postpone this to December 1, 2027).

Sanctions

  • Minor infringements: fines up to 5,000 UTM.
  • Serious infringements: fines up to 10,000 UTM.
  • Very serious infringements: fines up to 20,000 UTM, plus corrective measures and publication of the sanction.

The scope of the law can be summed up in a few figures.

Key Figures of the New Legislation

Relevant data for implementing data protection regulations

24
Months
Implementation period from publication (December 2024)
8
Principles
Guiding principles of data processing
7
Rights
Strengthened data subject rights
2026
Effective Date
Year of full entry into force

Frequently asked questions

The most common questions about the law and its implementation.

What is Law 21.719?

It is the new Chilean personal data protection law, published on December 13, 2024. It replaces the regime of Law 19.628 and introduces a regulatory architecture aligned with international standards such as the General Data Protection Regulation.

When does Law 21.719 enter into force?

The Law contemplates a 24-month vacancy period, so its full entry into force is set for December 1, 2026. A Senate bill (bulletin 18.623-07, entered September 1, 2026 with top-priority urgency) would postpone it to December 1, 2027; until it passes and is published, the 2026 date governs. During the interim period, organizations must adapt processes and appoint Data Protection Officers where applicable.

What rights does it recognize for data subjects?

Access, rectification, deletion, opposition, portability and restriction of processing. Controllers must respond to requests within legal deadlines and keep records of evidence.

What is the Data Protection Officer (DPO)?

It is the figure responsible for supervising compliance within the organization, advising management and serving as the point of contact with the Agency. Its appointment is mandatory for public sector controllers and for organizations carrying out large-scale processing.

What sanctions does the law contemplate?

Fines that scale according to severity up to 20,000 UTM for very serious infringements. The Personal Data Protection Agency is the supervisory authority, with power to impose corrective measures and sanctions.

What obligations does the data controller have?

Principles of lawfulness, purpose, quality and security; duty to inform the data subject; maintenance of processing activity records; impact assessments where applicable; breach notification to the Agency; and DPO appointment in the cases provided for.

Official sources

Explore complementary practice areas and regulatory analysis from our team.

Law 19.628 (the current regime)

The data law in force today: its demands, commercial information and how Law 21.719 rewrites it.

Processing principles

The Article 3 principles that govern all personal data processing.

Data subject rights

Access, rectification, erasure, objection and portability: how they are exercised and answered.

Controller obligations

Information, security and breach-reporting duties of the data controller.

Breach notification

Who to report a security breach to and when (Article 14 sexies).

Data Protection Officer

What the DPO is, when it is required and what Article 50 demands.

Data Protection Agency

Regulatory, supervisory and sanctioning powers of the new authority.

Sanctions and fines

Minor, serious and very serious infringements: fines of up to 20,000 UTM (Article 35).

Infringement prevention model

The Article 49 compliance program and its regulation (Decree 662): elements, DPO, certification and mitigation.

Board liability

The company faces fines up to 20,000 UTM; the board answers on its duty of care.

International transfers

When data can be transferred outside Chile and under which safeguards.

Impact assessment

When the law requires an impact assessment and how it is carried out.

Postponed to 2027? The December 2026 date

The December 1, 2026 date and the bill postponing it to 2027: infringements, public registry and mitigating factors.

Consent or legitimate interest?

How to choose the lawful basis for each processing activity (Articles 12 and 13).

AI and personal data

Using AI with customer data: lawful basis, transfers and automated decisions.

Data Law diagnosis

Your company’s gaps against Law 21.719: processing activities, lawful bases and duties.

Cybersecurity Framework Law (21.663)

The framework law: ANCI, essential services, obligations and deadlines.

AI & Business

AI governance in business: risks and the applicable framework.

Transform Your Legal Challenges into Competitive Advantages

Discover how our innovative approach can drive your business

© 2026 AnguitaOsorio, all rights reserved.
Chile

Contact

Contáctanos

Phone:

+56 2 2760 4512

Location:

Cerro el Plomo 5420, office 1306, Las Condes, Metropolitan Region.