Kardu
Chile · Ley 21.719

The new data lawof Chile, explained simply

Law 21.719 replaces the old Law 19.628 and is Chile’s new personal data protection law. It takes full effect on December 1, 2026, with a new enforcement authority: the Personal Data Protection Agency.

This guide summarizes the law in plain language and does not replace legal advice. Always check the official text before making decisions.

What Law 21.719 is

It applies to any organization that processes personal data of people in Chile — private companies, government bodies, NGOs and independent professionals — and rests on three pillars.

ARSOP rights

Access, rectification, erasure, opposition and portability of data, for anyone whose data is processed in Chile.

Obligations for controllers

Documentation, security and transparency for whoever decides what happens to the data, and for whoever processes it on their behalf.

A new authority

The Personal Data Protection Agency oversees compliance and applies sanctions once the law is in full effect.

Timeline and deadlines

01 / December 13, 2024

Official publication

The law is published and legally in force, but the Agency cannot yet apply sanctions.

02 / 2025 – November 2026

Transition period

The previous Law 19.628 still applies while organizations prepare for the new rules.

03 / December 1, 2026

Full effect

The Agency starts enforcing: processing records become mandatory, 72-hour breach notification applies, and sanctions become active.

By the numbers

24 months

Grace period

72 hours

Deadline to report breaches

20K UTM

Maximum fine

5

ARSOP rights

Sanctions

The Personal Data Protection Agency classifies infringements into three categories. Fines are expressed in UTM (Chile’s monthly tax unit), not pesos, so the figures don’t go stale.

CategoryFineExamples
MinorUp to 5,000 UTMOutdated processing records, an inaccessible privacy policy, incomplete information when collecting data.
Serious5,000 to 10,000 UTMProcessing data without a legal basis, denying ARSOP requests, not reporting a breach, not appointing a DPO when required.
Very serious10,000 to 20,000 UTMNot reporting a breach within 72 hours, transferring data without a legal basis, obstructing the Agency’s oversight.

Law 21.719 vs. the GDPR

They share principles, rights and 72-hour breach notification. These are the differences that matter most in practice.

AspectLey 21.719GDPR
Maximum fineUp to 20,000 UTMUp to 4% of global turnover or €20M
Response deadline for requests30 calendar days, extendable to 601 month, extendable to 3
Breach notification72 hours to the Agency72 hours to the authority
Data subject identificationRUT-authenticated portalNo specific format mandated

What it means for your SME

The law has no size threshold: if your SME has web forms, a customer database, payroll or social media accounts, it is already processing personal data.

What changes with size is the level of rigor required. Most SMEs don’t need a formal DPO, but you do need an internal owner and a processing record. Whether your organization must appoint a DPO depends on specifics of your operation; it’s worth confirming with legal counsel.

7 minimum requirements

  • A privacy policy accessible on your website
  • A Records of Processing Activities (RAT)
  • An internal person responsible for compliance
  • Clear consent on your forms
  • A channel for ARSOP requests
  • A documented breach protocol
  • Data processing agreements (DPAs) with your vendors
How Kardu helps

One system for Chile and Europe

Kardu organizes your compliance evidence around ISO 27001 and maps it to whichever frameworks apply to you — including Law 21.719 — so you don’t duplicate work across jurisdictions.