Skip to the content
Global Data RulesData governance rules, country by country

Chile

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Chile — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Waking up

Chile is about to change completely. Today its 1999 privacy law says nothing about sending data abroad, and there is no privacy regulator. On 1 December 2026 a rewritten law starts. From then, sending data abroad will need a legal safeguard. A new agency will be able to fine up to 4 percent of a company's Chilean sales. No industry has to keep data inside Chile.

Data governance in Chile

The eight things that decide how you handle data about people in Chile. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. From 1 December 2026 the rewritten law reaches any company anywhere that offers goods or services to people in Chile. It also reaches any company that watches their behaviour online. That is true even with no office and no staff in the country. There is no size or revenue limit. You do not need a local representative. But you must publish a working email address, or a similar contact point, that both customers and the regulator can use.

What you have to do here:
Tell people what you do

Where the data is allowed to live

Today, yes, with nothing to sign. The privacy law in force in Chile right now does not mention sending data abroad. From 1 December 2026 that ends. After that date you may send data abroad only in three situations. The destination country has been officially declared safe enough. Or you have a contract, or binding group rules, with proper safeguards. Or you fit a narrow exception. No industry in Chile has to keep a copy of data inside the country.

What you have to do here:
Put a transfer safeguard in place

What to do: Get the paperwork for one of the routes below signed before any data leaves Chile.

Sending data out of the country

From 1 December 2026 there are three main routes. Send to a country the new agency has officially declared safe enough. Sign a contract, or adopt binding group-wide rules, that give people the same protection they have in Chile. Or use an approved certification. If none of those fit, you can ask the agency to approve one specific transfer. Right now the agency does not exist. So there is no list of approved countries and no official model contract to copy.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Government sign-off needed · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

Today, nobody. Chile has no privacy regulator. A person has to sue in a civil court. The judge can fine between one and ten monthly tax units. That is roughly 70,000 to 700,000 Chilean pesos, or about 75 to 750 US dollars. A real regulator, the Personal Data Protection Agency, starts on 1 December 2026 with power to fine millions. As of 18 August 2026 we found no official confirmation that its three board members have been appointed. The law wanted them named around 1 June 2026.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

Rules pull in both directions, and they come from different laws. On the keep-it side, internet and phone companies keep one year of connection records. Hospitals and clinics keep patient files for at least fifteen years. On the delete-it side: from 1 December 2026 you may keep personal data only as long as the purpose needs. After that you must delete it or make it anonymous. Unpaid debts may not be reported after five years. Where a specific law orders you to keep something, that beats the general delete-it rule.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Let people delete their data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Two clocks. If you run an essential service, you must report a significant cyber attack to the national cyber agency within three hours. You then update at seventy-two hours, and close with a final report within fifteen days. Separately, from 1 December 2026, you must report a personal data breach to the privacy agency by the fastest available means, without undue delay. No fixed number of hours is set. You must also tell the affected people when the breach involves sensitive data, data about children under fourteen, or credit and banking data.

What you have to do here:
Report cyber incidents · Report breaches to the regulator · Tell affected people

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five. (1) A child is anyone under fourteen and needs a parent's consent. Teenagers aged fourteen to seventeen are treated as adults, except that sensitive data about under-sixteens still needs a parent. (2) If someone asks you to freeze their data, you have two working days to answer, not thirty. (3) Unpaid debts vanish from credit reporting after five years, and immediately once paid. You have seven working days to pass on the news. (4) Congress, the courts, the central bank and other independent bodies write their own privacy rules and sit outside the agency's reach. (5) Online gambling cannot be licensed in Chile at all.

What you have to do here:
Get a parent's consent for children · Let people delete their data · Delete data after a period

What's changing next

One date dominates: 1 December 2026. That is when the rewritten privacy law starts and the new agency gets its powers. Before then the government has to name the agency's three board members and issue the regulations the law requires. For the first twelve months the agency may let small firms off with a written warning instead of a fine. Watch three powers the government can use without asking anyone.

What to do: Diarise 1 December 2026 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms rules

Official name: Código Procesal Penal (ley N° 19.696), artículos 218 bis y 222 · Ley 19.696, Diario Oficial 12 October 2000, as amended · Act of parliament

In forceYes — store it anywhere

Telephone companies and internet providers must keep at least a year of subscriber connection records and hand them to prosecutors on request. The law does not say the records must sit in Chile, but they must be produced confidentially and on demand.

In force since 12 October 2000

Enforced by Public Prosecutor's Office

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Health and social care

Health data rules

Official name: Ley N° 20.584, que regula los derechos y deberes que tienen las personas en relación con acciones vinculadas a su atención en salud · Ley 20.584, Diario Oficial 24 April 2012, as amended · Act of parliament

In forceYes — store it anywhere

Everything in a patient's clinical file counts as sensitive data. The file must be kept for at least fifteen years. Only the professionals actually treating the patient may see it. There is no requirement to hold it inside Chile.

In force since 1 October 2012

Enforced by Ministry of Health

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Finance

Finance data rules

Official name: Ley N° 21.521, que promueve la competencia e inclusión financiera a través de la innovación y tecnología en la prestación de servicios financieros (Ley Fintec) · Ley 21.521, Diario Oficial 4 January 2023 · Act of parliament

In forceYes — store it anywhere

Foreign financial technology firms serving Chile must have an address in Chile and be on the regulator's register. Nothing in the law requires customer or transaction data to be stored in Chile.

In force since 4 January 2023

Enforced by Financial Market Commission

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: Ley N° 21.719, que regula la protección y el tratamiento de los datos personales y crea la Agencia de Protección de Datos Personales · Ley 21.719, Diario Oficial 13 December 2024, rewriting Ley 19.628 · Act of parliament

Partly in forceYes, with paperwork

Chile's rewritten general privacy law. It looks like Europe's. You need consent or another legal basis. People get full rights. Breaches must be reported. Data may go abroad only to a country officially declared safe enough, or with contract safeguards, or with a certification. It becomes enforceable on 1 December 2026. Nothing has to stay in Chile.

In force since 13 December 2024In force now, but not enforced until 1 December 2026

That is a long gap: the duty is real law today, but no penalty can follow until 1 December 2026. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Personal Data Protection Agency — not yet operational

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life

General data protection law

Official name: Ley N° 19.628, sobre protección de la vida privada · Ley 19.628, Diario Oficial 28 August 1999 · Act of parliament

In forceYes — store it anywhere

The privacy law actually in force in Chile until 30 November 2026. It says nothing about sending data abroad, creates no regulator, and leaves enforcement to civil judges whose fines top out around 750 US dollars.

In force since 28 August 1999

Enforced by Civil courts of first instance

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Cyber security rules

Official name: Ley N° 21.663, ley marco sobre ciberseguridad e infraestructura crítica de la información · Ley 21.663, Diario Oficial 8 April 2024 · Act of parliament

In forceYes — store it anywhere

Chile's national cybersecurity law. If you provide an essential service, you must alert the national cyber agency within three hours of a significant attack. That covers electricity, water, banking, telecoms, transport, hospitals and managed technology services. It says nothing about where data must be stored.

In force since 8 April 2024

Enforced by National Cybersecurity Agency

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Agencia de Protección de Datos Personales

    General privacy law, from 1 December 2026

    Created by Law 21.719 and takes its powers on 1 December 2026. It has no website of its own yet, so we link the sponsoring ministry. The law required the first three board members to be named about six months before the start date, that is around 1 June 2026. As of 18 August 2026 we found no official record that this happened. Until it is set up there is no list of approved countries and no official model contract for sending data abroad.

  • Juzgados de letras en lo civil

    The only route for privacy complaints until 30 November 2026

    Working, but the only remedy is a private lawsuit. Fines run from one to ten monthly tax units, roughly 75 to 750 US dollars. That is why the old law is treated as barely enforced.

  • Agencia Nacional de Ciberseguridad (ANCI)

    Cyber incidents, essential services and operators of vital importance

    Created by Law 21.663 and hosts the national incident response team. Its own website refused automated access on 18 August 2026. So we took its current staffing, and the exact date its reporting duties started, from the statute rather than from the agency itself. Treat the operational rating as medium confidence.

  • Comisión para el Mercado Financiero (CMF)

    Banks, insurers, securities markets and registered financial technology providers

    Live and issuing rules. So we list its outsourcing and cloud requirements as unconfirmed rather than state them.

  • Ministerio Público

    Recipient of telecoms and internet connection records in criminal investigations

  • Ministerio de Salud

    Clinical records, patient data standards

  • Consejo para la Transparencia

    Freedom of information and public bodies' handling of personal data under the old regime

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether the three members of the Personal Data Protection Agency's board have been appointed

    We could not confirm whether the board has been appointed. The law required the first appointment around 1 June 2026. The Senate's appointment records and the official gazette search both need a browser to run scripts, so we could not read them. No other official page confirmed or denied it. We treat the board as not appointed, which is the cautious reading. It is unproven.

  • Which law amended the fourth transitional article of Law 21.719 with effect from 5 February 2026

    The official consolidated text shows that article with a February 2026 version date. There is no note naming the amending law, and we could not search the statute database. The article that fixes the 1 December 2026 start date is unchanged, so the start date itself is safe.

  • Whether the implementing regulations required by Law 21.719 have been issued

    We could not confirm whether these regulations have been published. They were due within six months of the law being published, that is by mid-June 2025. We could not search the official gazette. Check before you rely on this.

  • The exact date the cybersecurity reporting duties began to bite, and the current staffing of the National Cybersecurity Agency

    We could not confirm the date this duty started. The cybersecurity law leaves the start date to a decree with force of law that we could not find. The agency's website blocked automated access on 18 August 2026.

  • Whether the Financial Market Commission restricts banks, insurers or securities firms from processing customer data abroad

    We could not read the Commission's rulebook, including the chapters on outsourcing and on information security. It is delivered through a script-driven interface we could not read automatically. Banking secrecy law and duties to notify the supervisor probably apply when you use a supplier abroad. We are not stating the detail without the text.

  • Whether any residency or sovereignty condition applies to cloud services bought by the Chilean state

    We could not reach the digital government and public procurement rules on an official source. We found no rule in the privacy or cybersecurity laws requiring data to stay in Chile.

  • Whether restrictions on publishing detailed mapping and survey data still apply

    The Military Geographic Institute's website refused automated access, so we could not check the current position on map approvals. If you work with mapping data, check before you rely on this.

  • The status of the bill to license online gambling

    The casino law clearly excludes online games from any operating permit. We could not check the progress of any bill against an official congressional source, so we say nothing about it here.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.