Whistleblowing | Workplace Compliance

Law 21.719 on Personal Data Protection (Chile)

A Chilean law that replaces the country's 1999 data protection regime with a GDPR-style framework, granting individuals enforceable rights over their personal data and creating a dedicated regulator with the power to investigate and fine. The law requires organizations to report data breaches without undue delay, and sets internal reporting and complaint procedures as mandatory content of its certified compliance model.

Region: Chile/
Sector: Public & Private/
Effective date: 12/01/2026/
Last regulatory update: 09/09/2026/
Mandatory:Yes/
Schedule a Consultation

Table of contents

    What Is Law 21.719?

    Law 21.719 is a comprehensive data protection framework governing how personal data is collected, processed, stored, and transferred in Chile. It was published in the Diario Oficial on 13 December 2024 and enters into force on 1 December 2026, bringing Chile broadly in line with the European Union's General Data Protection Regulation.

    Structurally, the law works by amendment. Rather than standing alone, Law 21.719 rewrites the content of Law 19.628 of 1999, which is why Chilean practitioners cite the substantive provisions as articles of Law 19.628 as amended.

    The law creates six enforceable rights for individuals: access, rectification, erasure, objection, portability, and blocking. The right of blocking, which allows a data subject to require temporary suspension of processing, is a notable divergence from the GDPR and has no direct European equivalent.

    Entities affected include private companies and public bodies alike. Public bodies are covered, but under a specific regime set out in Title IV, so the framework applying to them is not identical to the one governing private organizations. 

    Schools, universities, and other educational institutions are covered, and are particularly exposed because they process data concerning children and adolescents at scale.

    The law also reaches beyond Chile's borders. Organizations established elsewhere fall within scope if they offer goods or services to people in Chile, or monitor their behavior, an extraterritorial reach modeled directly on the GDPR.

    Chilean practitioners generally read the law's compliance architecture as a parallel to Law 20.393 on corporate criminal liability, which established the country's familiar modelo de prevención de delitos. The logic is the same: an organization that can evidence a functioning internal prevention system is treated more favorably when something goes wrong. 

    The difference is that Law 20.393 concerns criminal liability, while the data protection model operates as a mitigating circumstance in administrative sanctioning rather than a defense.

    Who Is Responsible for Law 21.719?

    Enforcement sits with the Agencia de Protección de Datos Personales, a new autonomous public body created by the law and governed by a three-member council nominated by the Executive and confirmed by the Senate. 

    The Agencia supervises compliance, issues binding general instructions, resolves complaints from data subjects, publishes model contractual clauses and adequacy lists for international transfers, and imposes sanctions.

    It also certifies and supervises infringement prevention models, and maintains the National Register of Compliance and Sanctions, a public record of both sanctioned organizations and certified compliance programs.

    As of September 2026, the Agencia's governing council has not been appointed. The statutory timetable envisaged installation roughly six months before entry into force, but the Senate declined the Executive's nominations in May 2026 and no replacement slate has been confirmed.

    The implementing picture has moved in one respect and remains open in others. Decree 662/2025, the regulation governing infringement prevention models, was published in the Diario Oficial on 9 September 2026. It sets the requirements, modalities, and procedures for implementing, certifying, registering, and supervising the models referred to in Article 49. Two legislative proposals are separately in play. 

    • Bill 18.060-07 proposes substantive amendments to the law, including a narrower definition of sensitive data and removal of the standalone blocking right. 
    • Bill 18.623-07, introduced by the Executive in September 2026 and carrying fast-track urgency, proposes to postpone entry into force by one year and to restructure the Agencia's governing council.

    Neither bill has been enacted. The official text of Law 21.719 continues to provide for entry into force on 1 December 2026, and the burden of demonstrating compliance rests with the organization regardless of the regulator's readiness.

    What Are the Possible Penalties Under Law 21.719?

    The law grades infringements as minor, serious, and very serious. Maximum fines are 5,000 UTM for minor infringements, 10,000 UTM for serious infringements, and 20,000 UTM for very serious infringements. At August 2026 values, that is approximately €334,000, €668,000, and €1.34 million. The UTM is indexed monthly.

    Repeat infringements may attract substantially higher penalties, with fines capable of being trebled and, for organizations that do not qualify as small businesses under Law 20.416, calculated as a percentage of annual revenue:

    • Up to 2% for serious infringements and up to 4% for very serious ones. In cases of repeated very serious infringements within a 24-month period, the Agencia may additionally order suspension of processing operations for up to 30 days, renewable. 
    • A 50% surcharge applies where an organization fails to remedy the infringing conduct within the period set by the Agencia. Sanctioned organizations are listed on the public National Register of Compliance and Sanctions.

    There is no separate compliance deadline for smaller organizations. During the first twelve months after entry into force, however, the Agencia may impose a written warning in place of a fine where the organization qualifies as a smaller enterprise under Law 20.416. The obligations begin on the same date for everyone; what the transitory rule softens is the sanction, and only for the first year.

    Breach reporting sits squarely within this regime. Omitting the security breach notifications required by the law is classified as a serious infringement. Omitting them deliberately is classified as very serious.

    What Does Law 21.719 Require?

    Report data breaches without undue delay. Organizations must notify the Agencia, by the most expeditious means available and without undue delay, of any security breach causing the destruction, leak, loss, or unlawful alteration of personal data, or unauthorized access to it, wherever a reasonable risk to individuals' rights and freedoms arises. Organizations must also keep a record of breaches and of the action taken in response.

    Affected individuals must be notified directly in three defined situations: where the breach involves sensitive data, where it involves data concerning children under fourteen, or where it involves data relating to economic, financial, banking, or commercial obligations.

    The law sets no fixed hour count. The Chilean standard is sin dilaciones indebidas, without undue delay. The 72-hour figure frequently cited in commentary comes from the GDPR and does not appear in the Chilean text.

    Secure data and verify that the measures work. Organizations must adopt measures assuring confidentiality, integrity, availability, and resilience, and must run regular processes to verify and evaluate the effectiveness of those measures. Privacy by design and by default applies as a standing duty, as does confidentiality across employees and subcontractors.

    Assess the impact of high-risk processing. Where processing is likely to present a high risk to the rights of data subjects, Article 15 ter requires a data protection impact assessment before processing begins. It points in particular at large-scale processing, systematic monitoring of individuals, and certain processing of sensitive data.

    Demonstrate lawful processing. Organizations must hold the evidence establishing the lawfulness of their processing, and publish a transparent processing policy covering purposes, data categories, recipients, retention periods, international transfers, and any automated decision-making.

    Apply a reinforced standard to children's and adolescents' data. All processing of data concerning people under eighteen must serve their best interests and respect their progressive autonomy. 

    Parental or legal representative consent is required for all personal data of children under fourteen, and for sensitive data of adolescents under sixteen. Adolescents aged sixteen and seventeen consent on their own behalf, including for sensitive data. This tiered structure matters in practice for schools and universities, where the same institution routinely holds data across all three brackets.

    Establish internal reporting and complaint procedures where a prevention model is adopted. The law offers organizations a route to demonstrable compliance through a certified infringement prevention model. Adopting one is voluntary. 

    Where an organization does adopt one, Article 36(5) recognizes diligent fulfillment of direction and supervision duties as a mitigating circumstance in sanctioning, verified through the certificate issued under Article 51. Decree 662/2025 governs how models are implemented, certified, registered, and supervised, with certification valid for three years.

    Training and awareness sit within the decree's wider compliance framework and among the Data Protection Officer's functions, rather than as a separate item in that list.

    The minimum contents of a model are:

    • Appointment of a Data Protection Officer with defined powers
    • Identification of the data handled and a documented risk assessment of processing activities
    • Specific protocols, rules, and procedures to prevent infringements
    • Internal reporting mechanisms, reporting channels to the Agencia, and complaint procedures
    • Internal disciplinary consequences for staff who breach the rules
    • Incorporation of these obligations into employment contracts or internal workplace regulations

    Two points are commonly misstated and worth stating plainly. Appointing a Data Protection Officer is not a standalone obligation in Chile, and there is no equivalent of GDPR Article 37. It becomes mandatory only where an organization adopts a prevention model, because the DPO is required content of that model.

    The position on processing records is similar but not identical. Chile imposes no general record of processing activities requirement comparable to GDPR Article 30. 

    Within a compliance program, however, Decree 662/2025 requires a detailed characterization of processing activities, covering matters such as data categories, legal bases, international transfers, and retention periods, and expressly provides that this characterization may be carried out through a record of processing activities. 

    Outside a model, the breach log, the evidence of lawful processing, and any required impact assessments remain mandatory for every organization.

    Why Is Law 21.719 Important?

    Law 21.719 represents the most significant shift in Chilean data governance in twenty-five years. It converts data protection from a largely unenforced statutory principle into a supervised regime with meaningful financial consequences, in a market where most organizations have never operated under a modern framework.

    For multinational organizations, the practical effect is convergence. An operation already aligned to the GDPR will recognize most of what Chile now requires, with blocking rights and the tiered consent regime for young people as the main additions to work through. For organizations that have only ever operated under the 1999 law, including much of the Chilean education sector, the change is substantial and the timeline is short.

    The law's design also reflects a wider regulatory pattern. Rather than prescribing controls in detail, it rewards organizations that can demonstrate a functioning internal compliance system, and it treats the ability to detect and escalate problems internally as evidence of good faith. That is the same logic underpinning whistleblower regulation across the EU, the US, and the Middle East, which means the underlying infrastructure serves more than one obligation at once.

    How Does FaceUp Help Comply with Law 21.719?

    While FaceUp cannot help with all Law 21.719 requirements, such as risk and impact assessments, processing policies, or regulatory filings, it supports the reporting layer: how people inside an organization raise a data protection problem, and what record exists afterward.

    Decree 662/2025 gives that layer a defined shape. A certified prevention model must include internal mechanisms for reporting potential infringements to the Data Protection Officer, with the possibility of protecting the reporter's identity, alongside the routes for notifying the Agencia and affected individuals. 

    The regulation expressly allows these mechanisms to be integrated into existing organizational reporting channels, provided the implementation complies with the law and the regulation. It does not require any particular technology or platform.

    For organizations already running FaceUp as their internal reporting channel, that is the connection. The same environment can take reports of suspected personal data infringements from employees, students, parents, and third parties, anonymously if the reporter chooses, through web forms, hotlines, and mobile apps.

    Reports concerning personal data can be routed to the Data Protection Officer or data protection lead, so the response begins without an internal escalation chain. Case management then logs every report, action, decision, and deadline with a timestamp, which can support the record of breaches and remedial actions the law requires organizations to keep.

    In practice, this means personal data concerns surface early enough to act on, and the organization has a documented account of what it did about them.

    Quick Facts

    Implementing regulation

    Applies to

    Private companies processing personal data in Chile, including schools and universities; public bodies, under the specific regime in Title IV; and organizations outside Chile that offer goods or services to, or monitor the behavior of, people in Chile

    Penalties

    • Up to 20,000 UTM (approx. EUR 1.34 million) for very serious infringements
      Fines trebled for repeat infringements, or up to 4% of annual revenue for larger organizations
    • Suspension of processing for up to 30 days, renewable, for repeated very serious infringements within 24 months
    • 50% surcharge where the infringing conduct is not remedied in time

    The FaceUp Solution

    FaceUp is an anonymous reporting and compliance platform designed to help businesses meet whistleblowing regulations worldwide, including those in the US, EU, UK, and UAE.

    • Fully Anonymous Reporting

      Give staff multiple secure channels to report their concerns, complete with an anonymous two-way chat.

      • Mobile-First Accessibility

      • No IP storage, no device IDs, encrypted submissions

      • Customizable forms, categories, routing rules, and more

      Explore Reporting
    • Customizable Case Management

      Create an easily verifiable audit trail through a customizable case management system with automatic routing.

      • Supports multiple locations, subsidiaries, or units

      • Entity-specific routing and access permissions

      • Optional notifications via email, Teams, or Slack

      Explore Case Management
    • FaceUp - Risk & Compliance Analytics

      Real-Time Data Analytics

      Identify trends, repeated issues, and escalation risks early with customizable visual real-time dashboards.

      • Filter by category, region, channel, and more

      • Share without revealing sensitive information

      • ISO 27001 and SOC 2-certified local servers

      Explore Analytics

    Explore how FaceUp can help your organization