The new data lawof Chile, explained simply
Law 21.719 thoroughly reforms Law 19.628 and sets Chile’s new personal data protection framework. It’s due to take effect on December 1, 2026, with a new enforcement authority: the Personal Data Protection Agency.
Status as of September 2026: a bill in the Senate proposes postponing the law’s entry into force to December 1, 2027. Until it passes, the legal date is still December 1, 2026.
Updated September 2026. This guide summarizes the law in plain language and does not replace legal advice. Always check the official text before making decisions.
What Law 21.719 is
It applies to organizations established in Chile — private companies, government bodies, NGOs and independent professionals — and can also reach foreign organizations that offer goods or services to people in Chile or analyse their behaviour. It rests on three pillars.
Data subject rights
Access, rectification, erasure, objection, portability and blocking of processing. Temporary blocking must be answered within 2 business days.
Obligations for controllers
A lawful basis, transparency, security, data protection by design and control over whoever processes data on your behalf — and being able to prove it.
A new authority
The Personal Data Protection Agency oversees compliance and applies sanctions from the date the law takes effect.
Timeline and deadlines
01 / December 13, 2024
Official publication
The law is published in the Official Gazette. Its changes take effect 24 months later, so the Agency cannot sanction yet.
02 / 2025 – November 2026
Transition period
The previous Law 19.628 still applies while organizations prepare for the new rules.
03 / December 1, 2026
Takes effect
The new obligations take effect and the Agency starts enforcing and sanctioning. A bill going through parliament proposes moving this date to December 1, 2027.
24 months
Transition period
No delay
Breach notice
20K UTM
General fine cap
6
Data subject rights
Sanctions
The law classifies infringements into three categories, sanctioned by the Personal Data Protection Agency. Fines are expressed in UTM (Chile’s monthly tax unit), not pesos. If a company that isn’t small reoffends with a serious or very serious infringement, the fine can reach 2% or 4% of its annual revenue, if that figure is higher.
| Category | Fine | Examples |
|---|---|---|
| Minor | Up to 5,000 UTM | Failing to follow the Agency’s general instructions, and any infringement the law doesn’t classify as serious or very serious. |
| Serious | Up to 10,000 UTM | Processing data without a legal basis, not informing people as the law requires, obstructing the exercise of their rights, breaching data security or confidentiality. |
| Very serious | Up to 20,000 UTM | Knowingly processing or sharing sensitive data or children’s data unlawfully, knowingly passing on false information about a person, deliberately concealing a security breach. |
Law 21.719 vs. the GDPR
They share similar principles and rights, but differ on deadlines, fines and notifications. These are the differences that matter most in practice.
| Aspect | Ley 21.719 | GDPR |
|---|---|---|
| Maximum fine | Up to 20,000 UTM; if a company that isn’t small reoffends, up to 2% or 4% of its annual revenue | Up to €20M or 4% of global turnover, whichever is higher |
| Response deadline for requests | 30 calendar days, extendable once by 30 more; temporary blocking, 2 business days | 1 month, extendable to 3 |
| Breach notification | Without undue delay, via the most expeditious means | 72 hours to the authority |
| Notifying people affected by a breach | If it involves sensitive data, data about children under 14, or financial and commercial data | If there’s a high risk to their rights and freedoms |
| Data subject identification | Authentication per a procedure the Agency has yet to define | No specific format mandated |
What it means for your SME
The law has no size threshold: if your SME has web forms, a customer database, payroll or social media accounts, it is already processing personal data.
Appointing a data protection officer isn’t mandatory for every organization: it’s part of the infringement prevention model, which is voluntary and, if certified, mitigates sanctions. Nor is there a general obligation to keep a record of processing by that name, but an inventory of what you process is the most practical way to show you comply. If you’re unsure about your case, confirm with legal counsel.
7 practical steps to get started
- A privacy policy accessible on your website
- An inventory of what data you process, why and on what basis
- A lawful basis identified for each processing activity
- A channel for people to exercise their rights, answering blocking requests within 2 business days
- A breach protocol that covers when to notify the people affected
- Contracts with the vendors that process data on your behalf
- Security measures and data protection by design
Official sources
This guide is a summary. For the legal detail, consult these sources directly.
Frequently asked questions
Which companies are subject to Law 21.719?
The law has no size threshold: it covers private companies, government bodies, NGOs and independent professionals established in Chile, including SMEs with web forms, a customer database or payroll. It can also reach foreign organizations that offer goods or services to people in Chile or analyse their behaviour.
What's the deadline to comply with Law 21.719?
The law was published on December 13, 2024, with a transition period until December 1, 2026, when it takes effect and the Personal Data Protection Agency starts enforcing and sanctioning. As of September 2026 a bill going through parliament proposes postponing it to December 1, 2027; until it passes, the legal date is still 2026.
What happens if my company doesn't comply?
The law classifies infringements into three tiers: minor (up to 5,000 UTM), serious (up to 10,000 UTM) and very serious (up to 20,000 UTM). If a company that isn’t small reoffends with a serious or very serious infringement, the fine can reach 2% or 4% of its annual revenue.
Do I need a Data Protection Officer (DPO)?
It isn't mandatory for every organization. The officer is part of the infringement prevention model, which is voluntary and, if certified, mitigates sanctions. If you're unsure about your case, confirm with legal counsel.
How is Law 21.719 different from the GDPR?
They share similar principles and rights. The most practical differences: fines are set in UTM (with a revenue-based tier for repeat offences), temporary blocking must be answered within 2 business days, and breaches are notified without undue delay rather than within 72 hours, with affected people notified by type of data rather than level of risk.
When do Law 21.719 fines start applying?
From the date the law takes effect, currently December 1, 2026, when the transition period ends and the Personal Data Protection Agency can enforce and sanction. If the postponement bill passes, it would be December 1, 2027.
One system for Chile and Europe
Law 21.719 turns data protection into a matter of governance, risk and evidence. Kardu helps you see what applies to you, assign the measures and keep your evidence up to date, with ISO 27001 as a common base for Law 21.719 and the GDPR — without assuming one covers the other.