Chile's Law 21.719 vs GDPR: what you're missing if you already comply with GDPR
7 min · September 2026 · Cesar Mella Diaz
Last updated: 30 September 2026
Complying with GDPR isn't complying with Law 21.719, but it helps
If your company operates in Europe and already runs a GDPR program, getting to Chile's Law 21.719 doesn't mean starting from zero. The underlying principles —data minimization, transparency, data subject rights, breach notification— are almost the same. But "almost the same" isn't "the same", and Chile's Personal Data Protection Agency doesn't automatically accept your GDPR compliance as valid in Chile.
This is what changes in practice.
The differences at a glance
| GDPR | Law 21.719 | |
|---|---|---|
| Deadline to answer data subject requests | 1 month, extendable by 2 more | 30 calendar days, extendable once by 30 more |
| Temporary blocking of data | Within the general deadline | 2 business days |
| Maximum fine | €20M or 4% of global turnover, whichever is higher | 20,000 UTM; if a company that isn't small reoffends, up to 2% or 4% of its annual revenue |
| Breach notice to the authority | Within 72 hours | Without undue delay, by the fastest means available |
| Breach notice to affected people | If there's a high risk to them | If it involves sensitive data, data about children under 14, or financial and commercial data |
| Compliance program | Part of accountability | Certifiable prevention model that counts as a mitigating factor |
Deadlines: temporary blocking is the exception that bites
GDPR gives you one month to answer an access, rectification or erasure request, extendable by two more months. Law 21.719 gives you 30 calendar days, extendable once by another 30.
But there's one exception worth keeping front of mind. When someone asks you to rectify or erase their data, or objects to its processing, they can also ask you to block it while you decide. That temporary blocking request has to state its grounds, and you have 2 business days to answer it. Blocking doesn't require you to delete anything: only to stop processing that data in the meantime.
If your internal process is calibrated to GDPR's weeks, adjust it for Chile. And treat blocking as a separate request with its own workflow, because two business days leave no room for it to get lost in a shared inbox.
Fines: UTM, but not only UTM
GDPR calculates its maximum fines as a percentage of global turnover: up to 4% or €20 million, whichever is higher. Law 21.719 sets them in UTM (Unidad Tributaria Mensual, a Chilean monetary unit): up to 5,000 UTM for minor infringements, 10,000 for serious ones and 20,000 for very serious ones. At the September 2026 UTM value, 20,000 UTM is over 1.4 billion Chilean pesos, a fraction of the European cap.
The gap narrows with repeat offences. If a company that isn't a small business commits another serious or very serious infringement, the fine can reach 2% or 4% of its annual revenue for the last year, depending on the severity, if that figure is higher than the UTM fine. And if it racks up very serious infringements within a 24-month period, the Agency can suspend its data processing operations for up to 30 days.
Security breaches: the playbook carries over, the notification rule doesn't
Both laws require you to notify breaches to the authority. GDPR sets a 72-hour deadline; Law 21.719 sets no hours, but requires you to do it without undue delay and by the fastest means available.
The important difference is when you also have to notify the people affected. GDPR requires it when the breach poses a high risk to them. Chilean law doesn't look at the level of risk but at the type of data: you have to notify each affected person when the breach involves sensitive data, data about children under 14, or economic, financial, banking or commercial data. If you can't reach each person, you have to publish a notice in a national media outlet.
In practice: you can reuse your incident response playbook, but not the rule that decides when to notify affected people. A leak of billing data that in Europe might stop at a notice to the authority requires notifying every affected customer in Chile.
International transfers: review your data flows to and from Chile
A company that already complies with GDPR usually has its data flows within Europe sorted out. Law 21.719 introduces its own international transfer regime in Chile, and it applies to data leaving Chile: to your European headquarters, to your cloud providers or to any other country. Data travelling the other way, from Europe to Chile, is still governed by GDPR.
A transfer is lawful if the destination country has an adequate level of protection according to the Agency, or if it's covered by contractual clauses, binding corporate rules or other instruments with adequate safeguards. The Agency has to publish the list of adequate countries and the model clauses on its website. Until then, take stock of which data leaves Chile, where it goes and under which contract.
Identifying the data subject: the Agency decides
Law 21.719 tasks the Agency with defining how a data subject exercising their rights is authenticated. Until it publishes that criterion, design your request channel so it can adapt. GDPR, by contrast, leaves identification up to each controller.
The infringement prevention model: what GDPR doesn't have
GDPR requires you to demonstrate that you comply (accountability), but it has no equivalent to this. Chilean law lets you voluntarily adopt an infringement prevention model: a compliance program with a defined set of minimum elements, including appointing a data protection officer. The regulation governing how it's implemented, certified and supervised was published in September 2026.
If the model is certified and the Agency sanctions you, it counts as a mitigating factor. It doesn't exempt you from liability, but it reduces your exposure. And here your GDPR program is a good starting point: the data inventory, records of processing and policies you already have are the foundation of that program.
What to do if you already comply with GDPR
Don't redo the work from scratch: use your data inventory, your records of processing and your breach playbook as the base. Then adjust what's specific to Chile:
- A 2-business-day workflow for temporary blocking requests.
- The rule for notifying affected people by type of data, not by level of risk.
- An inventory of the data transfers leaving Chile.
- The decision on whether certifying an infringement prevention model is worth it for you.
The most common mistake is assuming European compliance carries over automatically. The most expensive one is treating Law 21.719 as an isolated project without building on what you already have.
For the full picture of Law 21.719 —when it applies, sanctions and what it means for an SME— read Chile's Law 21.719: compliance guide.
Operating between Europe and Chile and want one system for both jurisdictions? Talk to us and we'll go through it together.

← Back to blog