The Infringement Prevention Model of the Data Law

The infringement prevention model is the voluntary compliance program of Article 49 of Law 19.628: the tool the data law offers companies to prevent infringements, mitigate fines and prove data governance before the new Agency. Its regulation, Supreme Decree No. 662, now defines exactly what it must contain.

Last updated:

Status
Supreme Decree No. 662 was published in the Diario Oficial on September 9, 2026. The Law 21.719 amendments enter into force on December 1, 2026; a Senate bill (bulletin 18.623-07, top-priority urgency) would postpone them to December 1, 2027 (as of September 14, 2026).

The infringement prevention model is a compliance program that any data controller, whether an individual or a legal entity, public or private, may adopt voluntarily (Article 49 of Law 19.628, as amended by Law 21.719, and Article 1 of the regulation). Its purpose is concrete: organizational measures that prevent the infringements the law sanctions.

Voluntary does not mean irrelevant. Diligent compliance evidenced by certification is an express mitigating circumstance when the Agency sets a fine (Article 36 No. 5), and certified entities enter the National Registry of Sanctions and Compliance, a public registry that clients, banks and counterparties can check. The same logic that Law 20.393 applies in criminal matters: the program is optional, its effects are not.

Since September 9, 2026, the standard is no longer abstract. Supreme Decree No. 662 of the Ministry of Finance, the regulation mandated by Article 51, details in 20 articles what the program must contain, how the officer operates within it, and how the Agency certifies, registers, supervises and revokes.

One name, two different models

Chilean compliance practice already knows a “prevention model”: the crime prevention model of Law 20.393, which shields the company from criminal liability. This one is different. The infringement prevention model belongs to the data law, prevents administrative infringements rather than crimes, and its reward is a mitigated fine and a public certification, not a criminal exemption.

The two programs coexist without duplicating everything. The regulation expressly allows the internal reporting mechanisms of the data program to be integrated into reporting channels the organization already operates for other matters, provided they meet the requirements of Law 19.628 and the regulation (Article 3 g). A company with a working ethics channel builds on it; it does not start over.

The elements of the program (Article 3 of the regulation)

Article 3 lists the minimum content of every compliance program. The regulation scales the standard: protocols must weigh the operations the controller actually runs, the quantity and type of data it processes, and the company’s size and economic capacity.

Art. 3 a), b), c)

Controller and officer, identified

The program identifies the controller and its legal representative, designates a data protection officer, and defines the means and powers the officer will hold.

Art. 3 d)

Characterization of processing

What data the company processes and how: eleven minimum items, from sensitive-data categories and lawful bases to international transfers, deletion terms and automated decisions. A record of processing activities satisfies this element.

Art. 3 e)

A risk matrix graduated by sanction

The company maps the processes that raise the risk of committing the infringements of Articles 34 bis, ter and quáter, and builds its risk matrix considering how the law grades the corresponding sanctions.

Art. 3 f)

Protocols that prevent, not decorate

Specific rules and procedures so that everyone involved in processing can plan and execute their tasks in a way that prevents infringements, proportional to the company’s operations, data and size.

Art. 3 g), i)

Reporting and internal whistleblowing

Expedited, permanently accessible internal reporting mechanisms, plus a channel to report infringements before the officer. The whistleblower may request identity reserve and cannot suffer any adverse measure for reporting.

Art. 3 h)

Internal sanctions

Internal administrative sanctions and the procedures to apply them when someone breaches the data rules or the program itself. Public bodies indicate the sanctions the law makes applicable to their officials.

The program does not live in a binder. The internal rules it generates must be expressly incorporated as an obligation into the employment and services contracts of all workers and providers, top executives included, and into the internal workplace regulations where applicable (Article 4). The controller must also communicate the program, and every update, to everyone in the organization (Article 5).

The officer inside the model

Appointing a data protection officer is voluntary in general, but mandatory within the adoption and certification of a compliance program (Article 6). The appointment belongs to the highest governing authority, the board, a managing partner or the top authority of the entity, and the officer reports directly to whoever appointed them, with autonomy from management (Article 8).

The regulation makes the figure workable at every scale: the officer may be an employee or an external provider under a services contract, one natural person may serve several controllers, a business group under the same controller may share a single officer, and in micro, small and medium-sized companies the owner may personally assume the role (Articles 7 and 8). The company must publish the officer’s contact details on its website and keep the Agency informed (Article 11).

Certification: three years, a public registry, and grounds to lose it

The Agency certifies programs that meet the law and the regulation, at the interested party’s request (Article 15). Certificates last three years and are renewable. Certified entities enter the National Registry of Sanctions and Compliance, where certificates are publicly accessible (Article 17), and implementation may begin before the entity is entered in the registry (Article 18).

What the company gains

  • An express mitigating circumstance when the Agency sets a fine (Article 36 No. 5).
  • A verifiable data-governance credential in a public registry, visible in any due diligence.
  • A working structure, officer, inventory, matrix and protocols, for duties the law imposes anyway.

How certification is lost

  • Revocation by the Agency if the controller stops meeting the requirements (Article 20).
  • Revocation if the controller is sanctioned for infringements under Articles 34 bis, ter or quáter.
  • Re-applying requires reliably proving that the grounds for revocation were remedied.

One publicity rule deserves attention: the company may only advertise that its program is certified through a direct, plain reference to the National Registry (Article 5). Seals, badges and marketing claims beyond that reference are outside what the regulation authorizes.

Does it make sense to wait for the postponement?

The Law 21.719 amendments enter into force on December 1, 2026, with a Senate bill that would move them to December 1, 2027. The regulation, however, is already published, and Article 18 allows implementation to begin before registry entry. The underlying work does not change with the date: the processing inventory, the risk matrix, the protocols and the officer are the same effort in 2026 and in 2027. The company that builds the program early reaches the Agency’s first supervision cycle holding the mitigating position; the one that waits spends that time accumulating exposure.

Frequently asked questions

Is the infringement prevention model mandatory?

No. Article 49 of Law 19.628 and Article 1 of the regulation define it as a compliance program that any data controller may adopt voluntarily. Its effects, however, are not voluntary: diligent compliance evidenced by the Agency’s certification is an express mitigating circumstance (Article 36 No. 5), and certified entities appear in the National Registry of Sanctions and Compliance, a public registry.

What does the regulation (Supreme Decree No. 662) require?

Article 3 of the regulation lists the program’s minimum elements: identification of the controller, designation of a data protection officer with sufficient means and powers, a characterization of processing activities (which a record of processing activities satisfies), a risk matrix graduated by infringement severity, specific protocols, internal reporting mechanisms, internal sanctions, and a reporting channel before the officer that protects the whistleblower’s identity.

Does the model require appointing a data protection officer?

Yes. Appointing the officer is voluntary as a general rule, but it becomes mandatory within the adoption and certification of a compliance program (Article 6 of the regulation). The appointment belongs to the highest governing authority, such as the board or a managing partner, and the officer may be in-house or external. In micro, small and medium-sized companies, the owner or top management may personally assume the role.

How is the model certified and how long does certification last?

The Personal Data Protection Agency certifies the model at the interested party’s request (Article 15 of the regulation). Certificates last three years, are renewable, and enter the entity in the National Registry of Sanctions and Compliance, which is publicly accessible. The Agency may revoke certification on stated grounds, among others when the controller stops meeting the requirements or is sanctioned for infringements under Articles 34 bis, ter or quáter (Article 20).

Is it the same as the crime prevention model of Law 20.393?

No. The crime prevention model of Law 20.393 prevents criminal offenses, and its absence exposes the company to criminal liability. The infringement prevention model prevents administrative infringements of the data law, and its certified adoption mitigates the Agency’s fines. They are different programs, under different statutes and with different consequences, although the regulation allows internal reporting to be integrated into channels the organization already runs.

Can I implement the model before the Agency is operating?

Yes, and it pays off. Article 18 of the regulation allows implementation to begin before the Agency enters the entity in the registry, in full subjection to the law. The underlying work, such as the processing inventory, the risk matrix and the protocols, is the same with or without a postponed entry into force, and the company that documents it early reaches certification with the program already running.

Official sources

Explore complementary practice areas and regulatory analysis from our team.

Law 21.719 Data Protection

The Law 21.719 framework on its way into force: principles, rights, duties and sanctions.

Law 19.628 (the current regime)

The data law in force today: its demands, commercial information and how Law 21.719 rewrites it.

Processing principles

The Article 3 principles that govern all personal data processing.

Data subject rights

Access, rectification, erasure, objection and portability: how they are exercised and answered.

Controller obligations

Information, security and breach-reporting duties of the data controller.

Breach notification

Who to report a security breach to and when (Article 14 sexies).

Data Protection Officer

What the DPO is, when it is required and what Article 50 demands.

Data Protection Agency

Regulatory, supervisory and sanctioning powers of the new authority.

Sanctions and fines

Minor, serious and very serious infringements: fines of up to 20,000 UTM (Article 35).

Board liability

The company faces fines up to 20,000 UTM; the board answers on its duty of care.

International transfers

When data can be transferred outside Chile and under which safeguards.

Impact assessment

When the law requires an impact assessment and how it is carried out.

The December 2026 deadline

The December 1, 2026 date and the bill postponing it to 2027: infringements, public registry and mitigating factors.

Consent or legitimate interest?

How to choose the lawful basis for each processing activity (Articles 12 and 13).

AI and personal data

Using AI with customer data: lawful basis, transfers and automated decisions.

Data Law diagnosis

Your company’s gaps against Law 21.719: processing activities, lawful bases and duties.

Cybersecurity Framework Law (21.663)

The framework law: ANCI, essential services, obligations and deadlines.

AI & Business

AI governance in business: risks and the applicable framework.

Transform Your Legal Challenges into Competitive Advantages

Discover how our innovative approach can drive your business

© 2026 AnguitaOsorio, all rights reserved.
Chile

Contact

Contáctanos

Phone:

+56 2 2760 4512

Location:

Cerro el Plomo 5420, office 1306, Las Condes, Metropolitan Region.