Compliance officer, prevention officer or data protection officer? What each law requires of the company and of the person

The word compliance is used for three roles created by three different laws. Only one of the three, the officer before the UAF, is mandatory on its own. The other two become enforceable when the company adopts a prevention model, and each brings its own appointing authority, its requirements and its exposure.

Last updated:

They are three different roles. The compliance officer (oficial de cumplimiento) is mandatory for the reporting entities of Law 19.913. The crime prevention officer (encargado de prevención de delitos) is in charge of the voluntary model of Law 20.393. The data protection officer (delegado de protección de datos) is required if the company adopts the infringement prevention model of Law 21.719, which takes effect on December 1, 2026 unless the bill proposing to postpone it to 2027 succeeds. Separately, Law 21.663 requires a cybersecurity delegate from operators of vital importance and from institutions whose infrastructure, processes or functions the National Cybersecurity Agency identifies as essential.

Each role is born of a different law

The confusion is understandable: the vocabulary overlaps and the market offers all three under a single label. The laws that create them keep them apart.

Law 19.913 created the Financial Analysis Unit (Unidad de Análisis Financiero, UAF) and requires the entities it lists to report suspicious transactions to it; its officer is the company’s counterpart before that body. Law 20.393, rewritten by Law 21.595 (the Economic Crimes Law) in 2023, makes companies criminally liable for the offences in its catalogue when the failure to effectively implement an adequate prevention model favoured or facilitated their perpetration; the prevention officer is an element of that model. Law 21.719 rewrote Law 19.628 on personal data and introduced the data protection officer. The role your company needs depends, first, on whether it appears on the list of Law 19.913 and, second, on the model it decides to adopt.

Outside this comparison there is another statutory, sector-specific role: Law 21.663 requires operators of vital importance to appoint a cybersecurity delegate, the counterpart of the National Cybersecurity Agency (Article 8 letter i). The rule has been in force since March 1, 2025, and the duty arises for each company when the Agency classifies it as an operator of vital importance or identifies some of its infrastructure, processes or functions as essential, which then become subject to Article 8 (Article 4, final paragraph).

The compliance officer: Law 19.913 and the UAF

The only one of the three that the law imposes on its own, although under another name.

Article 3 of Law 19.913 lists a long series of obliged activities. Besides banks, financial institutions, the securities market, insurance and fund managers, it includes currency exchange houses, cash and valuables transport, casinos, gaming rooms and racetracks, free trade zones, customs agents, auction houses, real estate brokers, notaries and registrars, car dealers, weapons, precious metals and stones, professional sports organizations, shooting, hunting and fishing clubs, the sale of purebred horses, and those registered with the CMF under the Fintec Law that provide crowdfunding, alternative trading systems, custody or intermediation of financial instruments, or payment initiation. Entities supervised by the CMF that voluntarily register with the UAF are added. The full list is in Article 3, and it is checked against the company’s actual line of business, not its name. For all of them, the fourth paragraph sets the duty: "deberán designar un funcionario responsable de relacionarse con la Unidad de Análisis Financiero" (they must appoint an officer responsible for dealing with the Financial Analysis Unit). Article 40 adds registration in the UAF registry and notice of any relevant change in the entity’s legal situation.

The expression "oficial de cumplimiento" does not appear in the law; the UAF instructions coined it. For reporting entities in general, Circular No. 62 of March 19, 2025, in force since June 1, 2025, applies; for gaming casinos, from October 1, 2026, joint Circular UAF No. 63 / SCJ No. 150. Circular 62 asks that the officer hold a position of high responsibility, such as an area or division manager, with resources and access to all transactions; only natural persons and micro and small companies may appoint the natural person, a partner, an administrator or an executive. The UAF does not register as officer anyone convicted of money laundering, its predicate offences or the financing of terrorism, and a change of officer is reported to it within 10 business days. The distinction matters when reading the obligations. What the law sets is the officer, the reporting of suspicious transactions (Article 3), the five-year record of cash transactions above USD 10,000 and their delivery when the UAF requires it (Article 5), and the registration. The periodic reporting of those transactions, monthly, quarterly or half-yearly depending on the sector, is set by Circular 62 (letter D, d.1), and what the circular sets can change without going through Congress.

The sanctions run against the entity. Article 19 grades the infringements and Article 20 sets the fines: up to 800 UF for minor ones, up to 3,000 UF for less serious ones and up to 5,000 UF for serious ones, which include breaching the duties of Article 3. Repetition, that is, two or more infringements of the same nature with no more than twelve months between them, allows the fine to be raised up to threefold. Article 21 extends the same sanctions to the directors or legal representatives who concurred with their will in the infringement.

The crime prevention officer: Law 20.393

Not mandatory on its own, but a company without a model is exposed when that absence favours an offence.

Article 3 of Law 20.393 makes the legal entity criminally liable for the offences of Article 1 perpetrated in the course of its activity. The acts must be committed by, or with the intervention of, someone who holds a position, function or role in it or who provides it services managing its affairs before third parties. It is liable whenever the failure to effectively implement an adequate prevention model favoured or facilitated the act. It is not liable for an offence perpetrated exclusively against it. It is also liable, under the same requirements, for the act of a person linked to another legal entity with which it has ownership or shareholding relations. That other entity must provide it services managing its affairs before third parties or lack operational autonomy from it (Article 3, second paragraph). Article 4 defines the model by four elements, and the third is the person: one or more persons responsible for applying the protocols, with adequate independence, effective powers of direction and supervision, and direct access to management to inform it, render account and request measures beyond their remit. The legal entity provides them with the necessary resources and means, according to its size and economic capacity.

The law no longer says who appoints the officer, nor sets a term of office or a minimum profile: the 2023 rewrite replaced the fixed rules with a proportionality test, according to the company’s corporate purpose, line of business, size, complexity, resources and activities. Independence is the attribute the law returns to: Article 6 No. 3 counts the duly accredited autonomy of the crime prevention officer among the effective measures which, adopted before the formal charge, mitigate liability. The other three elements (risk identification; protocols with secure reporting channels and internal sanctions, incorporated into all employment and service contracts; and periodic evaluation by independent third parties) are explained in is the crime prevention model mandatory?.

The data protection officer: Law 21.719

Voluntary as a general rule, mandatory if the company adopts the infringement prevention model, and with the most detailed description of functions of the three.

Article 50 of Law 19.628, in the text set by Law 21.719, provides that the data controller may appoint a personal data protection officer. The appointment comes from the highest management or administrative authority, that is, the board, a managing partner or the highest authority of the company. The officer has autonomy from management in the matters of the law and meets requirements of suitability, capacity and specific knowledge. In micro, small and medium-sized companies the owner or its highest authorities are entitled to assume the tasks. The officer is allowed to perform other functions without conflict of interest, and a group under the same controller is entitled to appoint a single officer if all its entities operate under the same standards and the officer is accessible to all of them. The officer is bound to strict secrecy, and his or her functions, from advising the controller to an annual work plan with accountability, are in the same article.

The voluntary rule has one exception. Article 49 allows controllers to voluntarily adopt an infringement prevention model, whose programme contains, as its first element, the appointment of a data protection officer with defined means and powers. The requirement arises upon adopting the model, not only upon certifying it. The regulation, Supreme Decree No. 662 of 2025 of the Ministry of Finance, published on September 9, 2026, includes the officer in the programme submitted for certification. This whole regime takes effect on December 1, 2026, the date set by Law 21.719; a Government bill at its first stage in the Senate (Bulletin 18.623-07) proposes to postpone it to December 1, 2027. The role is developed in the data protection officer (DPO) and the model in the data infringement prevention model.

The three roles compared

FactorCompliance officer (UAF)Crime prevention officerData protection officer
LawLaw 19.913, Arts. 3 and 40; UAF Circular 62 (casinos: UAF Circular 63 / SCJ 150)Law 20.393, Art. 4 No. 3 and Art. 6 No. 3Law 19.628 as set by Law 21.719, Arts. 49 and 50; DS 662/2025
Mandatory?Yes, for the reporting entities of Art. 3No, but an adequate and effectively implemented model is what the law recognizes to exempt the companyNo, unless the company adopts the infringement prevention model (Art. 49); in force from December 1, 2026 (postponement bill to 2027 pending)
Who appointsThe entity, which registers the officer with the UAF; in casinos, from October 1, 2026, the boardThe law does not say; the legal entity gives the officer resources and direct access to managementThe board, the managing partner or the highest authority
RequirementsLaw: responsible before the UAF. Circular 62: position of high responsibility, except micro and small companies; no convictions for laundering, predicate offences or financing of terrorismAdequate independence, effective powers, direct access to management, resourcesAutonomy, suitability, capacity and specific knowledge, no conflict of interest
Other functionsThe law does not regulate it; the circular asks for independence and access to all transactionsYes, if independence and supervisory powers are realYes, expressly, without conflict of interest
Sanction if missingSerious infringement: fine of up to 5,000 UF, up to threefold if repeatedNone as such; the company loses the exemptionNone as such; the adopted model is incomplete and cannot be certified
Personal exposureFines on directors or representatives who concurred (Art. 21); offence of Arts. 6 and 7 for employees and service providersGeneral criminal law and, for economic crimes, Law 21.595Strict secrecy; the controller answers for the officer’s infringement and keeps a right of recourse

One person for two or three roles

None of the three laws forbids it; the company’s structure decides whether the arrangement withstands an audit or a criminal investigation.

  • Article 50 of Law 19.628 expressly allows other functions without conflict of interest, and Article 4 No. 3 of Law 20.393 requires independence and effective powers, without demanding exclusivity. Law 19.913 is silent, but Circular 62 asks the officer to hold a position of high responsibility, independence and access to all transactions.
  • The combination breaks down where one role would supervise the other or where the person runs the supervised process: a sales manager as prevention officer for bribery risk, or a head of technology as data protection officer for the systems he or she designs.
  • In a reporting entity the UAF officer is the fixed point. In small entities the other two roles may fall on the same person; as volume grows, the prudent course is to separate them, because the reports the circular requires absorb the officer’s time.
  • Whatever the arrangement, it is advisable that each role report directly to the board. Law 20.393 does not require it: it asks for direct access to management, and that reporting line is the simplest way to accredit the independence its Article 6 No. 3 rewards. For the data protection officer the rule is stricter: autonomy from management (Article 50 of Law 19.628) and, within the infringement prevention model, direct accountability to whoever appointed the officer (Article 8 of DS 662). If the board made the appointment, an officer who reports only through the general manager hardly meets that rule.

What the person who accepts the role is exposed to

Administrative fines fall, as a rule, on the company, but some reach individuals, and there are criminal risks besides, which are worth reviewing before accepting the role.

Under Law 19.913 the personal exposure is twofold. Article 21 extends the fines of Article 20 to the directors or legal representatives who concurred with their will in the infringement. In addition, Article 6 forbids reporting entities, their employees and those who provide them services from informing the person concerned or third parties that information has been requested by or sent to the UAF, and Article 7 punishes that breach with imprisonment (presidio menor in its medium to maximum degrees) and a fine of 100 to 400 UTM. The same penalty reaches whoever, being obliged to inform the UAF, maliciously destroys, alters or conceals the records they are required to deliver, or delivers false records. The compliance officer is more exposed because he or she handles the reports, but these offences require conduct of one’s own; accepting the role is not enough to commit them. Separately, Article 27 punishes money laundering even when the perpetrator did not know the illicit origin of the assets through inexcusable negligence, with the penalty reduced by two degrees.

Under Law 20.393 nothing in the text sanctions the prevention officer for the company’s offences; the natural person answers for what he or she did, under the Criminal Code and, if the offence is an economic crime, under the rules of Law 21.595 explained in are managers and directors criminally liable?. Under Law 19.628 the officer’s own duty is strict secrecy over the personal data learned in the role; a public official who breaches it is sanctioned under Articles 246 to 247 bis of the Criminal Code, and the controller answers for its officer’s infringement, with a right of recourse against the officer (Article 50).

How to draft the appointment so it survives an audit

An auditor, a certifier or a prosecutor will look for the elements the laws and circulars name. The appointment has to make each one visible.

  • The signatory: for the data protection officer, the board, the managing partner or the highest authority (Article 50 of Law 19.628). For the crime prevention officer the law does not name the body; a board resolution is advisable, because the legal entity must ensure the officer direct access to management and resources (Article 4 No. 3 of Law 20.393). In casinos, from October 1, 2026, the board appoints the UAF officer (UAF Circular 63 / SCJ 150).
  • The powers in writing: direction and supervision, the right to request measures beyond the officer’s remit and the duty to render account (Law 20.393); means, powers and resources proportionate to the company (Article 4 No. 3 of Law 20.393 and Articles 49 letter b) and 50 of Law 19.628).
  • The reporting line to the board and the conflict check: a direct reporting line to the board, stated in writing, and a record that the other functions of the position create no conflict of interest.
  • For a reporting entity: an officer in a position of high responsibility with access to all transactions (Circular 62, letter B), registered with the UAF under Article 40, with changes reported within 10 business days and named in the Prevention and Detection Manual.
  • The internal rules carried into contracts: Law 20.393 requires the protocols and internal sanctions to be expressly incorporated into all employment and service contracts, including those of top executives (Article 4 No. 2), and Article 49 of Law 19.628 requires the same for the data programme, or its inclusion in the internal regulations of Articles 153 and following of the Labour Code.
  • The supporting records: the annual work plan and its accountability for the data protection officer (Article 50 letter f), and the periodic evaluations by independent third parties that Law 20.393 makes the fourth element of the model (Article 4 No. 4).

Frequently asked questions

Is a compliance officer mandatory for every company in Chile?

No. Among the compliance roles, the law imposes on its own the officer responsible before the Financial Analysis Unit (Unidad de Análisis Financiero, UAF) on the entities listed in Article 3 of Law 19.913, which must also register with the UAF (Article 40). It also imposes the cybersecurity delegate on those the National Cybersecurity Agency classifies as operators of vital importance or whose infrastructure, processes or functions it identifies as essential (Articles 4 and 8 letter i of Law 21.663). A company in neither situation has, under these laws, no duty to appoint anyone, although the prevention model of Law 20.393 and the infringement prevention model of Law 19.628 require a responsible person once the company decides to adopt them.

Does Law 19.913 use the term "oficial de cumplimiento"?

It does not. Article 3 speaks of a "funcionario responsable de relacionarse con la Unidad de Análisis Financiero" and Article 40 of a "funcionario responsable ante la Unidad". The name comes from the UAF instructions: Circular No. 62 of March 19, 2025, in force since June 1, 2025, which repealed 24 earlier circulars and requires reporting entities to appoint a compliance officer and to keep a Prevention and Detection Manual (Manual de Prevención y Detección); for gaming casinos, from October 1, 2026, joint Circular UAF No. 63 / SCJ No. 150 applies.

Can the same person be prevention officer and data protection officer?

The law does not forbid it. Article 50 of Law 19.628 allows the data protection officer to perform other functions provided the controller ensures they create no conflict of interest, and Article 4 No. 3 of Law 20.393 requires adequate independence, effective powers and direct access to management, without demanding exclusivity. In practice the combination works in small and medium-sized companies and stops working when one of the functions requires full-time dedication or when one role would supervise the other.

Who must sign the appointment?

For the data protection officer, the board, the managing partner or the highest authority of the company (Article 50 of Law 19.628). For the crime prevention officer, Law 20.393 does not name the body; a board resolution is advisable. The entity registers the UAF officer in the registry of Article 40; in casinos, from October 1, 2026, the board appoints that officer.

What personal exposure does the person who accepts the role take on?

Administrative fines fall, as a rule, on the company, but not all the exposure is the company’s. Under Law 19.913 the fines extend to the directors or legal representatives who concurred with their will in the infringement (Article 21), and Articles 6 and 7 punish with imprisonment (presidio menor) the employee or service provider who informs the person concerned or third parties that information has been requested by or sent to the UAF, and whoever maliciously destroys or conceals the records they are required to deliver. Under Law 20.393 the natural person answers under general criminal law and, if the offence is an economic crime, under Law 21.595. The data protection officer is bound to strict secrecy; the controller answers for the officer’s infringement and keeps a right of recourse against the officer (Article 50).

Is the appointment of any use if the company has no prevention model?

Under Law 20.393 a prevention officer without a model is of little use: what the law recognizes to exempt the company is an adequate and effectively implemented model, of which the responsible person is one of four elements (Article 4). Under Law 19.628 the data protection officer is voluntary as a general rule and becomes mandatory if the company adopts the infringement prevention model of Article 49, which is the one certified before the Agency. That regime takes effect on December 1, 2026, a date that a Government bill at its first stage (Bulletin 18.623-07) proposes to postpone to December 1, 2027. Under Law 19.913 the officer is the minimum: the law also requires the reporting of suspicious transactions and the register of cash transactions, and the UAF instructions add their periodic reporting and the Prevention and Detection Manual.

Official sources

Transform Your Legal Challenges into Competitive Advantages

Discover how our innovative approach can drive your business

© 2026 AnguitaOsorio, all rights reserved.
Chile

Contact

Contáctanos

Phone:

+56 2 2760 4512

Location:

Cerro el Plomo 5420, office 1306, Las Condes, Metropolitan Region.