Skip to content
Kardu
Chile · Ley 21.719

The new data lawof Chile, explained simply

Law 21.719 thoroughly reforms Law 19.628 and sets Chile’s new personal data protection framework. It’s due to take effect on December 1, 2026, with a new enforcement authority: the Personal Data Protection Agency.

Status as of September 2026: a bill in the Senate proposes postponing the law’s entry into force to December 1, 2027. Until it passes, the legal date is still December 1, 2026.

Updated September 2026. This guide summarizes the law in plain language and does not replace legal advice. Always check the official text before making decisions.

What Law 21.719 is

It applies to organizations established in Chile — private companies, government bodies, NGOs and independent professionals — and can also reach foreign organizations that offer goods or services to people in Chile or analyse their behaviour. It rests on three pillars.

Data subject rights

Access, rectification, erasure, objection, portability and blocking of processing. Temporary blocking must be answered within 2 business days.

Obligations for controllers

A lawful basis, transparency, security, data protection by design and control over whoever processes data on your behalf — and being able to prove it.

A new authority

The Personal Data Protection Agency oversees compliance and applies sanctions from the date the law takes effect.

Timeline and deadlines

01 / December 13, 2024

Official publication

The law is published in the Official Gazette. Its changes take effect 24 months later, so the Agency cannot sanction yet.

02 / 2025 – November 2026

Transition period

The previous Law 19.628 still applies while organizations prepare for the new rules.

03 / December 1, 2026

Takes effect

The new obligations take effect and the Agency starts enforcing and sanctioning. A bill going through parliament proposes moving this date to December 1, 2027.

By the numbers

24 months

Transition period

No delay

Breach notice

20K UTM

General fine cap

6

Data subject rights

Sanctions

The law classifies infringements into three categories, sanctioned by the Personal Data Protection Agency. Fines are expressed in UTM (Chile’s monthly tax unit), not pesos. If a company that isn’t small reoffends with a serious or very serious infringement, the fine can reach 2% or 4% of its annual revenue, if that figure is higher.

CategoryFineExamples
MinorUp to 5,000 UTMFailing to follow the Agency’s general instructions, and any infringement the law doesn’t classify as serious or very serious.
SeriousUp to 10,000 UTMProcessing data without a legal basis, not informing people as the law requires, obstructing the exercise of their rights, breaching data security or confidentiality.
Very seriousUp to 20,000 UTMKnowingly processing or sharing sensitive data or children’s data unlawfully, knowingly passing on false information about a person, deliberately concealing a security breach.

Law 21.719 vs. the GDPR

They share similar principles and rights, but differ on deadlines, fines and notifications. These are the differences that matter most in practice.

AspectLey 21.719GDPR
Maximum fineUp to 20,000 UTM; if a company that isn’t small reoffends, up to 2% or 4% of its annual revenueUp to €20M or 4% of global turnover, whichever is higher
Response deadline for requests30 calendar days, extendable once by 30 more; temporary blocking, 2 business days1 month, extendable to 3
Breach notificationWithout undue delay, via the most expeditious means72 hours to the authority
Notifying people affected by a breachIf it involves sensitive data, data about children under 14, or financial and commercial dataIf there’s a high risk to their rights and freedoms
Data subject identificationAuthentication per a procedure the Agency has yet to defineNo specific format mandated

What it means for your SME

The law has no size threshold: if your SME has web forms, a customer database, payroll or social media accounts, it is already processing personal data.

Appointing a data protection officer isn’t mandatory for every organization: it’s part of the infringement prevention model, which is voluntary and, if certified, mitigates sanctions. Nor is there a general obligation to keep a record of processing by that name, but an inventory of what you process is the most practical way to show you comply. If you’re unsure about your case, confirm with legal counsel.

7 practical steps to get started

  • A privacy policy accessible on your website
  • An inventory of what data you process, why and on what basis
  • A lawful basis identified for each processing activity
  • A channel for people to exercise their rights, answering blocking requests within 2 business days
  • A breach protocol that covers when to notify the people affected
  • Contracts with the vendors that process data on your behalf
  • Security measures and data protection by design

Frequently asked questions

Which companies are subject to Law 21.719?

The law has no size threshold: it covers private companies, government bodies, NGOs and independent professionals established in Chile, including SMEs with web forms, a customer database or payroll. It can also reach foreign organizations that offer goods or services to people in Chile or analyse their behaviour.

What's the deadline to comply with Law 21.719?

The law was published on December 13, 2024, with a transition period until December 1, 2026, when it takes effect and the Personal Data Protection Agency starts enforcing and sanctioning. As of September 2026 a bill going through parliament proposes postponing it to December 1, 2027; until it passes, the legal date is still 2026.

What happens if my company doesn't comply?

The law classifies infringements into three tiers: minor (up to 5,000 UTM), serious (up to 10,000 UTM) and very serious (up to 20,000 UTM). If a company that isn’t small reoffends with a serious or very serious infringement, the fine can reach 2% or 4% of its annual revenue.

Do I need a Data Protection Officer (DPO)?

It isn't mandatory for every organization. The officer is part of the infringement prevention model, which is voluntary and, if certified, mitigates sanctions. If you're unsure about your case, confirm with legal counsel.

How is Law 21.719 different from the GDPR?

They share similar principles and rights. The most practical differences: fines are set in UTM (with a revenue-based tier for repeat offences), temporary blocking must be answered within 2 business days, and breaches are notified without undue delay rather than within 72 hours, with affected people notified by type of data rather than level of risk.

When do Law 21.719 fines start applying?

From the date the law takes effect, currently December 1, 2026, when the transition period ends and the Personal Data Protection Agency can enforce and sanction. If the postponement bill passes, it would be December 1, 2027.

How Kardu helps

One system for Chile and Europe

Law 21.719 turns data protection into a matter of governance, risk and evidence. Kardu helps you see what applies to you, assign the measures and keep your evidence up to date, with ISO 27001 as a common base for Law 21.719 and the GDPR — without assuming one covers the other.