Skip to the content
Global Data RulesData governance rules, country by country

Chile

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: MediumEnforcement: Waking up

Chile is about to change completely. Today its 1999 privacy law says nothing at all about sending data abroad, and there is no privacy regulator. On 1 December 2026 a rewritten law switches on: transfers abroad will need a legal safeguard, and a new agency will be able to fine up to 4 percent of a company's Chilean sales. No industry has to keep data inside Chile.

Data governance in Chile

The eight things that decide how you handle data about people in Chile. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. From 1 December 2026 the rewritten law reaches any company anywhere that offers goods or services to people in Chile, or that watches their behaviour online, even with no office and no staff in the country. There is no size or revenue threshold. You do not need a local representative, but you must publish a working email address or similar contact point that both customers and the regulator can use.

High confidenceNational rulesTell people what you do

Where the data is allowed to live

Today, yes, with nothing to sign: the privacy law in force in Chile right now does not mention sending data abroad at all. From 1 December 2026 that ends. After that date a transfer abroad is only lawful if the destination country has been declared adequate, or you have a contract or binding group rules with proper safeguards, or you fit a narrow exception. No industry in Chile has to keep a copy of data inside the country.

High confidenceYes, with paperworkAllowlistPut a transfer safeguard in place

Sending data out of the country

From 1 December 2026 there are three main routes: send to a country the new agency has declared adequate, sign a contract or adopt binding group-wide rules that give people the same protection they have in Chile, or use an approved certification. If none of those fit, you can ask the agency to approve one specific transfer. Right now the agency does not exist, so there is no list of approved countries and no official model contract to copy.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemeGovernment sign-off neededExplicit consent

The regulator, and whether it actually acts

Today, nobody. Chile has no privacy regulator: a person has to sue in a civil court, and the judge can fine between one and ten monthly tax units, roughly 70,000 to 700,000 Chilean pesos, or about 75 to 750 US dollars. A real regulator, the Personal Data Protection Agency, starts on 1 December 2026 with power to fine millions. As of 18 August 2026 we found no official confirmation that its three board members have been appointed, and the law wanted them named around 1 June 2026.

Medium confidenceWaking up

How long you must keep it — and when to delete it

There is a floor and a ceiling, and they come from different laws. The floors: internet and phone companies keep one year of connection records, and hospitals and clinics keep patient files for at least fifteen years. The ceilings: from 1 December 2026 personal data may only be kept as long as the purpose needs, then it must be deleted or made anonymous, and unpaid debts may not be reported after five years. Where a specific law orders you to keep something, that beats the general delete-it rule.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logsLet people delete their data

If something goes wrong

Count two clocks. If you run an essential service, a significant cyber attack must be reported to the national cyber agency within three hours, updated at seventy-two hours, and closed with a final report within fifteen days. Separately, from 1 December 2026, a personal data breach must be reported to the privacy agency by the fastest available means and without undue delay, with no fixed number of hours, and the affected people must also be told when sensitive data, data about children under fourteen or credit and banking data is involved.

High confidenceReport cyber incidentsReport breaches to the regulatorTell affected people

What catches people out

Five. (1) A child is anyone under fourteen and needs a parent's consent; teenagers aged fourteen to seventeen are treated as adults, except that sensitive data about under-sixteens still needs a parent. (2) If someone asks you to freeze their data you have two working days to answer, not thirty. (3) Unpaid debts vanish from credit reporting after five years and immediately once paid, and you have seven working days to pass on the news. (4) Congress, the courts, the central bank and other independent bodies write their own privacy rules and are outside the agency's reach. (5) Online gambling is not licensable in Chile at all.

High confidenceChildren's dataGet a parent's consent for childrenLet people delete their dataDelete data after a period

What's changing next

One date dominates: 1 December 2026, when the rewritten privacy law starts and the new agency gets its powers. Before then the government has to name the agency's three board members and issue the regulations the law requires. For the first twelve months the agency may let small firms off with a written warning instead of a fine. Watch three switches the government can flip without asking anyone.

Medium confidencePartly in force

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Código Procesal Penal (ley N° 19.696), artículos 218 bis y 222

Act of parliament · Ley 19.696, Diario Oficial 12 October 2000, as amended

In forceYes — store it anywhere

Telephone companies and internet providers must keep at least a year of subscriber connection records and hand them to prosecutors on request. The law does not say the records must sit in Chile, but they must be produced confidentially and on demand.

In force since 12 October 2000

Enforced by Public Prosecutor's Office

Transfer model: No restriction · Accepted routes: Nothing required

High confidence
Health and social care

Ley N° 20.584, que regula los derechos y deberes que tienen las personas en relación con acciones vinculadas a su atención en salud

Act of parliament · Ley 20.584, Diario Oficial 24 April 2012, as amended

In forceYes — store it anywhere

Everything in a patient's clinical file counts as sensitive data, the file must be kept at least fifteen years, and access is limited to the professionals actually treating the patient. There is no requirement to hold it inside Chile.

In force since 1 October 2012

Enforced by Ministry of Health

Transfer model: No restriction · Accepted routes: Nothing required

High confidence
Finance

Ley N° 21.521, que promueve la competencia e inclusión financiera a través de la innovación y tecnología en la prestación de servicios financieros (Ley Fintec)

Act of parliament · Ley 21.521, Diario Oficial 4 January 2023

In forceYes — store it anywhere

Foreign financial technology firms serving Chile must have an address in Chile and be on the regulator's register. Nothing in the law requires customer or transaction data to be stored in Chile.

In force since 4 January 2023

Enforced by Financial Market Commission

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Ley N° 21.719, que regula la protección y el tratamiento de los datos personales y crea la Agencia de Protección de Datos Personales

Act of parliament · Ley 21.719, Diario Oficial 13 December 2024, rewriting Ley 19.628

Partly in forceYes, with paperwork

Chile's rewritten general privacy law. It looks like Europe's: consent or another lawful basis, full individual rights, breach reporting, and transfers abroad only with adequacy, contractual safeguards or certification. It becomes enforceable on 1 December 2026 and there is no data residency requirement.

In force since 13 December 2024But only enforceable from 1 December 2026

Enforced by Personal Data Protection Agency — not yet operational

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk

High confidence

Ley N° 19.628, sobre protección de la vida privada

Act of parliament · Ley 19.628, Diario Oficial 28 August 1999

In forceYes — store it anywhere

The privacy law actually in force in Chile until 30 November 2026. It says nothing about sending data abroad, creates no regulator, and leaves enforcement to civil judges whose fines top out around 750 US dollars.

In force since 28 August 1999

Enforced by Civil courts of first instance

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Ley N° 21.663, ley marco sobre ciberseguridad e infraestructura crítica de la información

Act of parliament · Ley 21.663, Diario Oficial 8 April 2024

In forceYes — store it anywhere

Chile's cybersecurity framework law. Anyone providing an essential service, from electricity and water to banking, telecoms, transport, hospitals and managed technology services, must alert the national cyber agency within three hours of a significant attack. It imposes no storage location requirement.

In force since 8 April 2024

Enforced by National Cybersecurity Agency

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Who you would hear from

  • Agencia de Protección de Datos Personales

    General privacy law, from 1 December 2026

    Created by Law 21.719 and takes its powers on 1 December 2026. It has no website of its own yet, so the sponsoring ministry is linked. The law required the first three board members to be designated about six months before the start date, that is around 1 June 2026; as of 18 August 2026 we found no official record that this happened. Until it is constituted there is no adequacy list and no official model contract for transfers abroad.

  • Juzgados de letras en lo civil

    The only route for privacy complaints until 30 November 2026

    Functioning, but the remedy is a private lawsuit with fines of one to ten monthly tax units, roughly 75 to 750 US dollars, which is why the regime is treated as effectively unenforced.

  • Agencia Nacional de Ciberseguridad (ANCI)

    Cyber incidents, essential services and operators of vital importance

    Created by Law 21.663 and hosts the national incident response team. Its own website refused automated access on 18 August 2026, so its current staffing and the exact date its reporting duties commenced were taken from the statute rather than confirmed from the agency itself. Treat the operational rating as medium confidence.

  • Comisión para el Mercado Financiero (CMF)

    Banks, insurers, securities markets and registered financial technology providers

    Live and issuing rules. Its rulebook is served through a script-driven interface that automated fetching could not read on 18 August 2026, so its outsourcing and cloud requirements are listed as unconfirmed rather than asserted.

  • Ministerio Público

    Recipient of telecoms and internet connection records in criminal investigations

  • Ministerio de Salud

    Clinical records, patient data standards

  • Consejo para la Transparencia

    Freedom of information and public bodies' handling of personal data under the old regime

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether the three members of the Personal Data Protection Agency's board have been appointed

    The law required the first designation around 1 June 2026. We could not open the Senate's appointment records or the official gazette's search, both of which need a browser to run scripts, and no other official page confirmed or denied it. Treated as not appointed, which is the cautious reading, but it is unproven.

  • Which law amended the fourth transitional article of Law 21.719 with effect from 5 February 2026

    The official consolidated text shows that article carrying a February 2026 version date, but no annotation naming the amending law, and we could not run a search of the statute database. The article that fixes the 1 December 2026 start date is unamended, so the start date itself is safe.

  • Whether the implementing regulations required by Law 21.719 have been issued

    They were due within six months of publication, that is by mid-June 2025. We could not search the official gazette to confirm publication.

  • The exact date the cybersecurity reporting duties began to bite, and the current staffing of the National Cybersecurity Agency

    The framework law leaves commencement to a decree with force of law that we could not locate, and the agency's website blocked automated access on 18 August 2026.

  • Whether the Financial Market Commission restricts banks, insurers or securities firms from processing customer data abroad

    Its rulebook, including the chapters on outsourcing and on information security, is delivered through a script-driven interface that could not be read automatically. Banking secrecy law and supervisory notification duties are likely to apply to offshore processing, but we are not asserting the detail without the text.

  • Whether any residency or sovereignty condition applies to cloud services bought by the Chilean state

    We could not reach the digital government and public procurement rules on an official source. No statutory residency rule was found in the privacy or cybersecurity laws.

  • Whether restrictions on publishing detailed mapping and survey data still apply

    The Military Geographic Institute's website refused automated access, so we could not verify the current position on cartographic approvals.

  • The status of the bill to license online gambling

    The casino law clearly excludes online games from any operating permit. We could not verify the progress of any bill on an official congressional source, so nothing is asserted about it.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Put this next to another country

Chile versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.