The new data lawof Chile, explained simply
Law 21.719 replaces the old Law 19.628 and is Chile’s new personal data protection law. It takes full effect on December 1, 2026, with a new enforcement authority: the Personal Data Protection Agency.
This guide summarizes the law in plain language and does not replace legal advice. Always check the official text before making decisions.
What Law 21.719 is
It applies to any organization that processes personal data of people in Chile — private companies, government bodies, NGOs and independent professionals — and rests on three pillars.
ARSOP rights
Access, rectification, erasure, opposition and portability of data, for anyone whose data is processed in Chile.
Obligations for controllers
Documentation, security and transparency for whoever decides what happens to the data, and for whoever processes it on their behalf.
A new authority
The Personal Data Protection Agency oversees compliance and applies sanctions once the law is in full effect.
Timeline and deadlines
01 / December 13, 2024
Official publication
The law is published and legally in force, but the Agency cannot yet apply sanctions.
02 / 2025 – November 2026
Transition period
The previous Law 19.628 still applies while organizations prepare for the new rules.
03 / December 1, 2026
Full effect
The Agency starts enforcing: processing records become mandatory, 72-hour breach notification applies, and sanctions become active.
24 months
Grace period
72 hours
Deadline to report breaches
20K UTM
Maximum fine
5
ARSOP rights
Sanctions
The Personal Data Protection Agency classifies infringements into three categories. Fines are expressed in UTM (Chile’s monthly tax unit), not pesos, so the figures don’t go stale.
| Category | Fine | Examples |
|---|---|---|
| Minor | Up to 5,000 UTM | Outdated processing records, an inaccessible privacy policy, incomplete information when collecting data. |
| Serious | 5,000 to 10,000 UTM | Processing data without a legal basis, denying ARSOP requests, not reporting a breach, not appointing a DPO when required. |
| Very serious | 10,000 to 20,000 UTM | Not reporting a breach within 72 hours, transferring data without a legal basis, obstructing the Agency’s oversight. |
Law 21.719 vs. the GDPR
They share principles, rights and 72-hour breach notification. These are the differences that matter most in practice.
| Aspect | Ley 21.719 | GDPR |
|---|---|---|
| Maximum fine | Up to 20,000 UTM | Up to 4% of global turnover or €20M |
| Response deadline for requests | 30 calendar days, extendable to 60 | 1 month, extendable to 3 |
| Breach notification | 72 hours to the Agency | 72 hours to the authority |
| Data subject identification | RUT-authenticated portal | No specific format mandated |
What it means for your SME
The law has no size threshold: if your SME has web forms, a customer database, payroll or social media accounts, it is already processing personal data.
What changes with size is the level of rigor required. Most SMEs don’t need a formal DPO, but you do need an internal owner and a processing record. Whether your organization must appoint a DPO depends on specifics of your operation; it’s worth confirming with legal counsel.
7 minimum requirements
- A privacy policy accessible on your website
- A Records of Processing Activities (RAT)
- An internal person responsible for compliance
- Clear consent on your forms
- A channel for ARSOP requests
- A documented breach protocol
- Data processing agreements (DPAs) with your vendors
Official sources
This guide is a summary. For the legal detail, consult these sources directly.
One system for Chile and Europe
Kardu organizes your compliance evidence around ISO 27001 and maps it to whichever frameworks apply to you — including Law 21.719 — so you don’t duplicate work across jurisdictions.