All the regulation we cover
Original analysis of the Chilean rules that govern doing business: each law with its own hub and the practical questions it raises, kept current as the rules move.
Reconstruction Law
What the approved law contains: three time-limited windows, tax cuts and new operating rules.
- Substitute 10% Tax: The 8-month window to release accumulated FUR and STUT profits at a single 10% rate.
- Donations at 50% Tax: One year to pass the company to the family at half the donations tax.
- Foreign Assets Amnesty: The 12-month regime to regularize foreign assets at a 10% or 7% rate.
- Corporate Tax Cut: The 27% to 23% schedule, the full owner credit and what to model before deciding in 2026.
Law 21.719 Data Protection
The framework enforceable from December 1, 2026: principles, rights, duties and sanctions.
- Processing principles: The Article 3 principles that govern all personal data processing.
- Data subject rights: Access, rectification, erasure, objection and portability: how they are exercised and answered.
- Controller obligations: Information, security and breach-reporting duties of the data controller.
- Breach notification: Who to report a security breach to and when (Article 14 sexies).
- Data Protection Officer: What the DPO is, when it is required and what Article 50 demands.
- Data Protection Agency: Regulatory, supervisory and sanctioning powers of the new authority.
- Sanctions and fines: Minor, serious and very serious infringements: fines of up to 20,000 UTM (Article 35).
- Board liability: The company faces fines up to 20,000 UTM; the board answers on its duty of care.
- International transfers: When data can be transferred outside Chile and under which safeguards.
- Impact assessment: When the law requires an impact assessment and how it is carried out.
- The December 2026 deadline: The December 1, 2026 entry into force: enforceable infringements, public registry and mitigating factors.
- Consent or legitimate interest?: How to choose the lawful basis for each processing activity (Articles 12 and 13).
- AI and personal data: Using AI with customer data: lawful basis, transfers and automated decisions.
Data Protection Officer
What the DPO is, when it is required and what Article 50 demands.
- In-house or outsourced DPO?: The hard-to-assemble hybrid profile, its costs and the DPO-as-a-Service model.
- What the DPO does: The ten concrete functions of the officer under Law 21.719.
- Autonomy and independence: Why the DPO cannot be judge and party, and the conflicts of interest it manages (Article 50).
Law 21.663 Cybersecurity Framework
The framework law: ANCI, essential services, obligations and deadlines.
- Vital Importance Operators: OIV qualification: criteria, reinforced obligations and challenge routes.
- OIV list: Who was qualified as OIV and what being on the list entails.
- Does it apply without being an OIV?: Essential services owe duties even without OIV status (Articles 7 and 9).
- National Cybersecurity Policy: The 2023-2028 policy pillars and their relation to Law 21.663.
- Cybersecurity: financial sector: How Law 21.663 coexists with CMF regulation for supervised entities.
- Cybersecurity: energy sector: Cybersecurity obligations for energy infrastructure.
- Cybersecurity: corporate sector: The company’s criminal and organizational exposure to cyber incidents.
Law 21.595 Economic Crimes
Offense catalog, penalties and their impact on corporate liability.
- Law 20.393: What Law 20.393 is, which offenses it covers and how the company is exempted.
- Corporate criminal liability: When the company is criminally liable, which penalties it faces and how it defends itself.
- Manager and director liability: When an executive is personally liable and why the company answers separately (Art. 5).
- Fines and day-fines: How fines are calculated under the day-fine system of Law 21.595.
- Is the prevention model mandatory?: Not mandatory by name, but it decides criminal liability (Article 3).
Ley Karin (Law 21.643)
Prevention, investigation and sanction of sexual harassment, workplace harassment and violence.
- The regulation and the protocol: What Decree 21 requires: protocol contents, deadlines and who investigates.
- Internal investigation or Labor Directorate?: The Article 211-C choice: investigate in-house or refer to the Inspectorate.
- Employer liability: The company three fronts of exposure: fines, tutela and constructive dismissal.
- Sanctions and fines: The Article 506 scale and the judicial exposure: tutela claims and constructive dismissal.
CMF Regulation
The CMF regulatory map on cybersecurity and fintec: RAN 20-10, NCG 454, 502 and 524.
- RAN 20-10: banking cybersecurity: Information security and cybersecurity management for banks.
- NCG 454: financial cybersecurity: Operational risk and cybersecurity management for supervised entities.
- NCG 461: corporate disclosure: Sustainability and corporate governance disclosure in the annual report.
- NCG 502: Fintec Law registration: Registration and obligations of financial service providers under Law 21.521.
- NCG 524: amendments to NCG 502: The 2024 adjustments to the fintec registration regime.
Fintec Law (21.521)
The framework for technology-based financial services and open finance.
- Do I need CMF registration?: When the Fintec Law requires registration and the cost of operating without it.
AI & Business
AI governance in business: risks and the applicable framework.
- Implementing AI in your company: Adopting AI in compliance with data, cybersecurity and governance duties.
Antitrust
The competition framework, outside the clusters.
DL 211
Anticompetitive conduct, merger control, leniency and the FNE and TDLC procedure.
Transform Your Legal Challenges into Competitive Advantages
Discover how our innovative approach can drive your business