Which Chilean regulations apply to a company entering the market: data protection for everyone, cybersecurity and fintech only inside their perimeters.
An honest scoping guide with handoffs to the detailed framework guides, for market entrants and their home-country advisors.
Which Chilean Regulations Apply to Your Company
An honest scoping guide for market entrants: one framework reaches everyone, the rest apply only inside defined perimeters. What each law actually covers, who it binds and where to read the detail. Written for general counsel, compliance leads and the advisors who accompany them.
One framework reaches every market entrant: data protection under Law 21.719, enforceable from December 1, 2026, applies by activity across the economy. The others are perimeter-based: cybersecurity duties under Law 21.663 concentrate on designated operators, and fintech rules under Law 21.521 require CMF registration only for regulated financial services.
This guide walks the three perimeters in that order, adds the corporate-crime baseline every company shares, and closes with a scoping method that avoids building compliance you do not need and missing the duties you do.
Data protection: the framework that reaches everyone
Law 21.719 applies by activity across the economy and is enforceable from December 1, 2026.
There is no size threshold and no sector filter: any company that processes personal data of people in Chile falls within the law, and Article 1 bis extends it to companies with no Chilean establishment when they offer goods or services into the market or monitor behavior in the country. Even selling into Chile without an entity carries data duties. Three reasons put it on the entry timeline from day one:
- Fines scale. Up to 20,000 UTM for the most serious infringements and, for large companies with repeat infringements, up to 2% or 4% of annual revenue. Building compliance late costs more than building it at entry. The Law 21.719 guide lays out the full framework.
- The DPO question. The prevention model and the data protection officer are voluntary under the law, but deciding on them early shapes data governance from the first process instead of forcing a redesign later.
- International transfers matter to a foreign parent. A group moves data across borders from day one: payroll, CRM, group reporting. The law devotes a full title to when transfers are lawful; the international transfers guide walks the available mechanisms.
Data protection is the only framework where the honest answer is "yes, it applies to you". The next two are the opposite case.
Cybersecurity: perimeter-based duties
Law 21.663 binds two defined categories, and most entrants are in neither.
The framework law reaches providers of essential services and, within that universe, the operators of vital importance (OIV) that the National Cybersecurity Agency (ANCI) qualifies. The duties differ by category:
Essential services (Article 4)
State bodies, public-service concessionaires and private companies in listed activities: electricity, fuels, drinking water, telecommunications, digital infrastructure, transport, banking and payment means, healthcare, among others. They owe the general duties of Article 7 and the incident-reporting duty of Article 9. The Law 21.663 guide covers the framework.
Operators of vital importance (Article 5)
A qualified subset designated by ANCI resolution when the service depends on networks and information systems and its disruption would have a significant public impact. They add the reinforced duties of Article 8: an information-security management system, certified continuity plans and a cybersecurity delegate.
If your activity is not on the Article 4 list, the law imposes no direct duties on you today, although ANCI can add services by reasoned resolution. If it is on the list, the duties are enforceable even without OIV status: the guide on applying without OIV status walks that middle category. Entrants in finance, energy, telecommunications or healthcare should scope this early, because their sector regulators add a layer of their own.
Fintech: a licensing perimeter, not a technology label
Law 21.521 regulates enumerated financial services, not companies that use technology.
Article 2 regulates the commercialization of specific services: crowdfunding platforms, alternative transaction systems, credit and investment advisory, custody of financial instruments, and order routing and intermediation; the open-finance title adds payment initiation providers. Article 5 reserves their professional provision to companies registered with the CMF. The perimeter test is therefore about what you operate, not what you build:
- Outside the perimeter. A software company selling core banking, onboarding or analytics tools to banks provides technology, not a listed financial service. The bank remains the regulated party, although it will usually pass CMF-driven requirements down by contract. The CMF regulatory map orders that layer.
- Inside the perimeter. A company that itself operates payment initiation, investment or crowdfunding services must register with the CMF before operating. The Fintech Law guide covers the registry, the proportional supervision and the deadlines.
- The sequence consequence. If you are inside, the regulatory track runs ahead of the corporate one: Article 5 requires even international providers to take Chilean domicile for these purposes, so registration planning and the entity decision move together.
The corporate-crime baseline
One framework needs no perimeter test. Law 20.393 makes legal entities criminally liable for a catalog of offenses committed within their activity, a catalog that Law 21.595 on economic crimes expanded substantially. It reaches companies operating in Chile regardless of where the parent sits, and the prevention model is the mitigation tool the statute itself contemplates. This page only scopes it: the economic crimes guide and the corporate compliance practice explain the rest.
A scoping method that avoids both errors
Overstating applicability wastes money; understating it hands the finding to a regulator. Four steps avoid both.
- Inventory activities, not org charts
The perimeters attach to what the company does (processing data, providing a listed service), not to what the company is or how large it plans to become.
- Test each perimeter against the statutory definitions
Article 4 of Law 21.663 and Article 2 of Law 21.521 are lists. Read them against the activity inventory and record the conclusion, so the analysis survives personnel changes.
- Plan the universal duties on the entry timeline
Data protection applies regardless, so its milestones (lawful bases, transfer mechanism, breach readiness) belong on the same calendar as incorporation and hiring.
- Revisit at each expansion
A new product or sector can cross a perimeter that the entry analysis correctly ruled out. Scoping is repeated, not archived.
The regulatory scan is the closing workstream of the entry sequence mapped in the Doing Business in Chile guide. With the scope settled, each framework has its own guide for the detail.
Frequently asked questions
Does Chilean data protection law apply to a foreign company with no Chilean entity?
It can. Article 1 bis extends the law’s territorial scope to controllers not established in Chile when their processing is aimed at offering goods or services to data subjects in the country, or at monitoring their behavior. Selling into the market from abroad can therefore trigger data duties even before any incorporation.
How do we know whether we are an operator of vital importance (OIV)?
You do not self-assess into the category. The National Cybersecurity Agency qualifies OIV by resolution, among essential-service providers whose operation depends on networks and information systems and whose disruption would have a significant public impact (Article 5). The practical first question is different: whether your activity appears in the essential-services list of Article 4. Most entrants find it does not.
Does using cloud providers in Chile change our regulatory position?
Contracting cloud or managed IT services does not, by itself, bring your company inside Law 21.663; the regulated party may be the provider of digital infrastructure or third-party managed IT services (Article 4). Your data protection duties as controller follow you regardless of where the servers sit, and hosting personal data outside Chile opens the international-transfers analysis of the data law.
Do the fintech rules apply to a software company that sells to banks?
No. Law 21.521 regulates providing the financial services enumerated in Article 2, such as crowdfunding platforms or order routing, not selling technology to regulated entities. A vendor whose client is a bank stays outside the perimeter, although the bank will usually pass its own CMF-driven requirements down by contract. The analysis changes only if the vendor itself operates the financial service.
Does Chilean corporate criminal liability reach a foreign parent company?
The subject of liability is the legal entity to which the offense is attributed under Law 20.393, in practice the Chilean subsidiary or branch that operates locally. A foreign parent is not automatically liable for its subsidiary’s conduct in Chile. The penalties still matter to the parent: fines, debarment and even dissolution land on its Chilean investment.
When should regulatory scoping happen in the entry sequence?
Before the corporate steps are locked in. If a regulated financial service is part of the plan, CMF registration defines the timeline and the vehicle. For everyone else, scoping runs in parallel with entity formation: data protection duties are planned on the entry calendar, and the cybersecurity and fintech perimeters are tested once against the statutory definitions, then revisited at each expansion.
Official sources
Transform Your Legal Challenges into Competitive Advantages
Discover how our innovative approach can drive your business