Chile
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Chile — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Chile is about to change completely. Today its 1999 privacy law says nothing about sending data abroad, and there is no privacy regulator. On 1 December 2026 a rewritten law starts. From then, sending data abroad will need a legal safeguard. A new agency will be able to fine up to 4 percent of a company's Chilean sales. No industry has to keep data inside Chile.
Data governance in Chile
The eight things that decide how you handle data about people in Chile. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. From 1 December 2026 the rewritten law reaches any company anywhere that offers goods or services to people in Chile. It also reaches any company that watches their behaviour online. That is true even with no office and no staff in the country. There is no size or revenue limit. You do not need a local representative. But you must publish a working email address, or a similar contact point, that both customers and the regulator can use.
- What you have to do here:
- Tell people what you do
The rule on who is covered is article 1 bis of the rewritten law. It covers any company established in Chile that uses personal data, and any supplier established in Chile. It covers work done on behalf of a company established in Chile. And it covers anyone not established in Chile whose activity aims at people in Chile. That means offering them goods or services. It also means monitoring, tracking, profiling or predicting their behaviour. The last paragraph of article 14 covers a company with no address in Chile. It must keep an up-to-date, working email address, or an equivalent contact channel, for the people whose data it holds and for the Agency. That is much lighter than Europe's requirement to appoint an established representative. The law in force until 30 November 2026 says nothing at all about who it covers by territory.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten by Law 21.719, article 1 bis (territorial scope) and article 14 final paragraph, official consolidated text of the version in force from 1 December 2026
bcn.cl
“Cuando el responsable o mandatario no se encuentren establecidos en el territorio nacional pero sus operaciones de tratamiento de datos personales estén destinadas a ofrecer bienes o servicios a titulares que se encuentren en Chile”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.719, first transitional article — the rewrite starts on the first day of the twenty-fourth month after publication (published 13 December 2024, so 1 December 2026)
bcn.cl
Link checked 18 August 2026
Where the data is allowed to live
Today, yes, with nothing to sign. The privacy law in force in Chile right now does not mention sending data abroad. From 1 December 2026 that ends. After that date you may send data abroad only in three situations. The destination country has been officially declared safe enough. Or you have a contract, or binding group rules, with proper safeguards. Or you fit a narrow exception. No industry in Chile has to keep a copy of data inside the country.
- What you have to do here:
- Put a transfer safeguard in place
We looked for rules requiring data to stay in Chile in banking, payments, insurance, securities, health, telecoms, government cloud, education, online gambling, mapping and defence. We found none. What industries do impose is different. Internet and telephone providers must keep one year of connection records available to prosecutors. Health providers must keep patient files for fifteen years, and every entry counts as sensitive data. Foreign financial technology firms must have an address in Chile to be registered. Organisations running essential services must alert the national cyber agency within three hours of a significant attack. From 1 December 2026, knowingly sending data abroad in breach of the rules is one of the most serious offences. It is punished by up to 20,000 monthly tax units. That is about 1.4 billion Chilean pesos, or roughly 1.5 million US dollars. Repeat offenders can be fined up to 4 percent of annual Chilean sales. We found no rule requiring data to stay in Chile in any industry, checked 18 August 2026. Confidence is medium for the industries whose regulator's rulebook we could not read automatically.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 on the protection of private life, official consolidated text of the version in force to 30 November 2026 — the full text contains no provision on transfers abroad
bcn.cl
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, Title V, articles 27 to 29 (international transfer of personal data)
bcn.cl
“Cumpliéndose los requisitos que, de conformidad a esta ley, autorizan al tratamiento de datos, son lícitas las operaciones de transferencia internacional de datos en cualquiera de los siguientes casos”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 34 quater letter h — unlawful international transfer is a most-serious infringement
bcn.cl
“Realizar, a sabiendas, operaciones de transferencia internacional de datos en contravención a las normas previstas en esta ley.”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Chile.
Sending data out of the country
From 1 December 2026 there are three main routes. Send to a country the new agency has officially declared safe enough. Sign a contract, or adopt binding group-wide rules, that give people the same protection they have in Chile. Or use an approved certification. If none of those fit, you can ask the agency to approve one specific transfer. Right now the agency does not exist. So there is no list of approved countries and no official model contract to copy.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Government sign-off needed · Explicit consent
Article 27 allows a transfer in three cases. The destination is under a legal system that protects data well enough. Or contract clauses, or binding corporate rules, with adequate guarantees are in place. Or sender and recipient adopt an approved compliance model or certification. Without those, a one-off transfer that is not routine is allowed on narrow grounds. The person's express consent. Specific banking, financial or stock market transfers. Duties under ratified treaties. Cooperation agreements between public bodies. An express legal authorisation. International judicial cooperation. Performing a contract with the person. And urgent medical or public health needs. Article 28 says the Agency will publish the list of safe countries and the model clauses on its website. Clauses it approves need no further guarantee or authorisation. Two things matter day to day. The list is empty today, because the Agency has not been set up. And article 28 also lets the Agency approve a single transfer by reasoned decision. Article 29 lets the Agency inspect transfers, make recommendations, take precautionary measures, and in serious cases suspend the flow of data for a time.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 28 — adequacy test, model clauses, binding corporate rules and one-off authorisations
bcn.cl
“La Agencia pondrá en su página web a disposición de los interesados un listado de países adecuados y modelos tipo de cláusulas contractuales y otros instrumentos jurídicos para la transferencia internacional de datos.”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 29 — the Agency may temporarily suspend transfers
bcn.cl
“La Agencia fiscalizará las operaciones de transferencia internacional de datos, pudiendo formular recomendaciones, adoptar medidas conservativas y en casos calificados, suspender temporalmente el envío de los datos.”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.719, fourth transitional article — the first members of the Agency's board were to be designated six months before the law starts
bcn.cl
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
Today, nobody. Chile has no privacy regulator. A person has to sue in a civil court. The judge can fine between one and ten monthly tax units. That is roughly 70,000 to 700,000 Chilean pesos, or about 75 to 750 US dollars. A real regulator, the Personal Data Protection Agency, starts on 1 December 2026 with power to fine millions. As of 18 August 2026 we found no official confirmation that its three board members have been appointed. The law wanted them named around 1 June 2026.
Under the law in force today, enforcement runs through the civil court of the district where the company is based. The fine range is one to ten monthly tax units. For breaches of the credit reporting rules it is ten to fifty. That is why we rate enforcement as waking up rather than active. The text has existed since 1999 and deters almost nobody. From 1 December 2026 the Agency becomes a decentralised public service run by a three-member board. It gets its own investigation and penalty process. It gets a public national register of penalties and compliance. And it can stop a company using personal data for up to thirty days after repeated most-serious offences. Two other bodies already enforce in nearby areas. The National Cybersecurity Agency, created by the 2024 cybersecurity law. And the Financial Market Commission, which supervises banks, insurers, securities firms and registered financial technology providers. The Transparency Council supervises public bodies under the freedom of information law. We could not confirm the current staffing of the National Cybersecurity Agency, because its website refused automated access on 18 August 2026.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as currently in force, articles 16 and 23 — claims go to the civil court and fines run from one to ten monthly tax units
bcn.cl
“podrá aplicar una multa de una a diez unidades tributarias mensuales”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, Title VI (articles 30 to 32 bis) creating the Personal Data Protection Agency and its three-member board, and article 38 (suspension of processing)
bcn.cl
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.719, fourth transitional article — first designation of the board due six months before the law starts, i.e. around 1 June 2026
bcn.cl
Link checked 18 August 2026
- Official sourceServicio de Impuestos Internos (Chilean tax authority)Monthly Tax Unit (Unidad Tributaria Mensual) values for 2026 — August 2026 = 71,649 Chilean pesos
sii.cl
Link checked 18 August 2026
How long you must keep it — and when to delete it
Rules pull in both directions, and they come from different laws. On the keep-it side, internet and phone companies keep one year of connection records. Hospitals and clinics keep patient files for at least fifteen years. On the delete-it side: from 1 December 2026 you may keep personal data only as long as the purpose needs. After that you must delete it or make it anonymous. Unpaid debts may not be reported after five years. Where a specific law orders you to keep something, that beats the general delete-it rule.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Let people delete their data
MINIMUMS. The Code of Criminal Procedure covers public telecommunications companies and internet providers. They must hold, confidentially and available to prosecutors, an up-to-date list of their authorised internet address ranges. They must also hold a record of at least one year of the connection addresses their subscribers use, with traffic data and subscriber addresses. They must destroy that material securely once the maximum period ends. Health providers must keep the patient file for at least fifteen years, and the whole file counts as sensitive data. MAXIMUMS. The rewritten law says you may keep data only as long as the purpose requires. After that you must delete it or make it anonymous. The exceptions are a law saying otherwise, or the person agreeing to longer. Credit and commercial default data may not be shared more than five years after the debt fell due. It may not be shared at all once the debt is paid. The rewritten law settles clashes in favour of the specific legal duty. The right to have data deleted does not apply where another law, or a court decision, requires the data to be kept.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Code of Criminal Procedure (Law 19.696), articles 218 bis and 222 — one-year retention of internet connection records
bcn.cl
“un registro, no inferior a un año, de los números IP de las conexiones que realicen sus abonados”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 20.584 on patients' rights, articles 12 and 13 — the clinical file is sensitive data and must be kept at least fifteen years
bcn.cl
“Los prestadores deberán conservar la ficha clínica por un período de al menos quince años.”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 3 letter c (proportionality) and article 18 (five-year limit on reporting debts)
bcn.cl
“Los datos personales pueden ser conservados sólo por el período de tiempo que sea necesario para cumplir con los fines del tratamiento, luego de lo cual deben ser suprimidos o anonimizados”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Two clocks. If you run an essential service, you must report a significant cyber attack to the national cyber agency within three hours. You then update at seventy-two hours, and close with a final report within fifteen days. Separately, from 1 December 2026, you must report a personal data breach to the privacy agency by the fastest available means, without undue delay. No fixed number of hours is set. You must also tell the affected people when the breach involves sensitive data, data about children under fourteen, or credit and banking data.
- What you have to do here:
- Report cyber incidents · Report breaches to the regulator · Tell affected people
The 2024 cybersecurity law sets three deadlines. An early alert within three hours of you becoming aware of an attack or incident that may have significant effects. An update at seventy-two hours, with an initial assessment and any indicators of compromise. And a final report within fifteen calendar days of the early alert. An operator of vital importance whose essential service is actually disrupted must send the update within twenty-four hours instead of seventy-two. The personal data breach duty sets no deadline in hours. That sounds generous and is not. The wording is by the fastest possible means and without undue delay, and deliberately failing to report is a most-serious offence. You must also keep an internal register of each breach. It must describe what happened, the effects, the kinds and rough number of people affected, and what you did about it. Where you cannot notify people individually, you must publish notice in a national mass medium.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.663, framework law on cybersecurity, article 9 — three-hour early alert, seventy-two hour update, fifteen-day final report
bcn.cl
“Dentro del plazo máximo de tres horas contado desde que se tiene conocimiento de la ocurrencia del ciberataque o incidente de ciberseguridad que pueda tener impactos significativos, se deberá enviar una alerta temprana sobre la ocurrencia del evento.”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 14 sexies — duty to report security breaches
bcn.cl
“El responsable deberá reportar a la Agencia, por los medios más expeditos posibles y sin dilaciones indebidas, las vulneraciones a las medidas de seguridad”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five. (1) A child is anyone under fourteen and needs a parent's consent. Teenagers aged fourteen to seventeen are treated as adults, except that sensitive data about under-sixteens still needs a parent. (2) If someone asks you to freeze their data, you have two working days to answer, not thirty. (3) Unpaid debts vanish from credit reporting after five years, and immediately once paid. You have seven working days to pass on the news. (4) Congress, the courts, the central bank and other independent bodies write their own privacy rules and sit outside the agency's reach. (5) Online gambling cannot be licensed in Chile at all.
- What you have to do here:
- Get a parent's consent for children · Let people delete their data · Delete data after a period
The age limits are unusual. Under fourteen is a child. Fourteen to seventeen is an adolescent, handled under adult rules. But sensitive data about an adolescent under sixteen needs a parent's consent. Rights requests normally get thirty calendar days, which you can extend once by another thirty. A request to temporarily block use of someone's data must be answered within two working days. Until you answer, you may not use that person's data at all. On credit data, the creditor must tell the credit register within seven working days of payment. Anyone using that data downstream must update within three days, or block the record. On the fourth trap, the rewritten law lets several bodies write their own privacy rules. They are the Senate, the Chamber of Deputies, the judiciary and the Comptroller General. They also include the Central Bank, the Public Prosecutor, the Electoral Service and the National Television Council. The cybersecurity law says the same bodies are outside the cyber agency's supervision. On the fifth, the casino law says in terms that an operating permit never covers online games of chance. So anyone offering online betting to Chileans is operating outside the licensing system.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 16 quater — under fourteen is a child; sensitive data of under-sixteens needs parental consent
bcn.cl
“se consideran niños o niñas a los menores de catorce años, y adolescentes, a los mayores de catorce y menores de dieciocho años”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 11 (thirty days for rights, two working days for temporary blocking), articles 18 and 19 (credit data), Title VIII article 54 (Congress, courts and autonomous bodies)
bcn.cl
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.995 on games of chance in casinos, article 5
bcn.cl
“En ningún caso el permiso de operación comprenderá juegos de azar en línea.”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.663, article 53 — Congress, the judiciary, the Comptroller, the Central Bank, the Public Prosecutor, the Electoral Service and the National Television Council are outside the cyber agency's supervision
bcn.cl
Link checked 18 August 2026
What's changing next
One date dominates: 1 December 2026. That is when the rewritten privacy law starts and the new agency gets its powers. Before then the government has to name the agency's three board members and issue the regulations the law requires. For the first twelve months the agency may let small firms off with a written warning instead of a fine. Watch three powers the government can use without asking anyone.
Powers already held. First, the Agency alone decides which countries count as safe enough, and which model contracts are acceptable. So it can widen or narrow cross-border flows just by publishing a list. Second, the Agency may suspend a specific data flow abroad as a precaution. It may also stop a company using personal data entirely for thirty days after repeated most-serious offences. It can renew that indefinitely if the company does not comply. Third, the cybersecurity agency decides which companies are operators of vital importance. That label doubles the maximum fines and tightens the incident update deadline from seventy-two hours to twenty-four. Also pending: the regulations the law requires, which were due within six months of publication. One transitional detail we could not resolve. The official consolidated text shows the transitional article on appointing the board was amended, with effect from 5 February 2026. We could not identify the amending law. The date the main rules start was not amended.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.719, transitional articles one, two, four and six — start date, deadline for regulations, first board appointment and the twelve-month written-warning window for small firms
bcn.cl
“entrarán en vigencia el día primero del mes vigésimo cuarto posterior a la publicación de esta ley en el Diario Oficial”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, articles 28, 29 and 38 — the adequacy list, precautionary suspension of transfers and suspension of processing
bcn.cl
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.663, articles 4 and 40 — designation of operators of vital importance and the doubled fine scale
bcn.cl
Link checked 18 August 2026
What to do: Diarise 1 December 2026 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms rules
Official name: Código Procesal Penal (ley N° 19.696), artículos 218 bis y 222 · Ley 19.696, Diario Oficial 12 October 2000, as amended · Act of parliament
Telephone companies and internet providers must keep at least a year of subscriber connection records and hand them to prosecutors on request. The law does not say the records must sit in Chile, but they must be produced confidentially and on demand.
Enforced by Public Prosecutor's Office
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep logs — 1 yearAuthorised internet address ranges plus at least one year of subscriber connection records, traffic data and addresses, held confidentially for prosecutors and then securely destroyed.
- Secure the data
What it costs if you get it wrong
- Criminal liabilityRefusing or obstructing an interception order is the criminal offence of contempt of court
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Code of Criminal Procedure, articles 218 bis and 222
bcn.cl
“deberán mantener, en carácter reservado y bajo las medidas de seguridad correspondientes, a disposición del Ministerio Público, un listado actualizado de sus rangos autorizados de direcciones IP y un registro, no inferior a un año, de los números IP de las conexiones que realicen sus abonados”
Link checked 18 August 2026
Health data rules
Official name: Ley N° 20.584, que regula los derechos y deberes que tienen las personas en relación con acciones vinculadas a su atención en salud · Ley 20.584, Diario Oficial 24 April 2012, as amended · Act of parliament
Everything in a patient's clinical file counts as sensitive data. The file must be kept for at least fifteen years. Only the professionals actually treating the patient may see it. There is no requirement to hold it inside Chile.
Enforced by Ministry of Health
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 15 yearsThe clinical file must be kept for at least fifteen years.
- Extra vendor secrecy termsNobody outside the person's own care team may see the file, including the provider's own staff and administrators.
- Secure the data
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 20.584, articles 12 and 13
bcn.cl
“Los prestadores deberán conservar la ficha clínica por un período de al menos quince años.”
Link checked 18 August 2026
Finance data rules
Official name: Ley N° 21.521, que promueve la competencia e inclusión financiera a través de la innovación y tecnología en la prestación de servicios financieros (Ley Fintec) · Ley 21.521, Diario Oficial 4 January 2023 · Act of parliament
Foreign financial technology firms serving Chile must have an address in Chile and be on the regulator's register. Nothing in the law requires customer or transaction data to be stored in Chile.
Enforced by Financial Market Commission
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notifyCrowdfunding platforms, alternative trading systems, intermediaries, order routers, credit and investment advisers and custodians must be on the Financial Market Commission's register.
- Appoint a representativeThe law requires a foreign company providing these services to have an address in Chile for that purpose. It is a local presence rule, not a data storage rule.
- Secure the dataOpen finance participants must meet the security and cyber standards the Commission sets by general rule.
- Get consentOpen finance data sharing runs on the customer's express consent.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.521, article 5 (registration and Chilean address) and articles 16 to 27 (open finance system)
bcn.cl
“Las empresas internacionales que presten los servicios anteriormente descritos deberán tener domicilio en Chile para esos efectos.”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: Ley N° 21.719, que regula la protección y el tratamiento de los datos personales y crea la Agencia de Protección de Datos Personales · Ley 21.719, Diario Oficial 13 December 2024, rewriting Ley 19.628 · Act of parliament
Chile's rewritten general privacy law. It looks like Europe's. You need consent or another legal basis. People get full rights. Breaches must be reported. Data may go abroad only to a country officially declared safe enough, or with contract safeguards, or with a certification. It becomes enforceable on 1 December 2026. Nothing has to stay in Chile.
That is a long gap: the duty is real law today, but no penalty can follow until 1 December 2026. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Personal Data Protection Agency — not yet operational
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, To save someone’s life
What you have to do
- Get consent — from 1 December 2026
- Document a legitimate interest — from 1 December 2026
- Tell people what you do — from 1 December 2026A published privacy policy with twelve listed items, including whether data goes to a country without adequate protection.
- Let people see their data — from 1 December 2026Answer within 30 calendar days, extendable once by 30.
- Let people correct their data — from 1 December 2026
- Let people delete their data — from 1 December 2026
- Let people object — from 1 December 2026
- Let people take their data elsewhere — from 1 December 2026
- Limit automated decisions — from 1 December 2026Rights around decisions taken only by automated means, including profiling.
- Secure the data — from 1 December 2026
- Report breaches to the regulator — from 1 December 2026By the fastest possible means and without undue delay. No fixed hour count.
- Tell affected people — applies at: Sensitive data, data on children under 14, or credit and banking data, from 1 December 2026
- Assess high-risk projects — applies at: High-risk processing, from 1 December 2026
- Written vendor contract — from 1 December 2026
- Put a transfer safeguard in place — from 1 December 2026
- Delete data after a period — from 1 December 2026Delete or anonymise once the purpose is met, unless a law or the person's consent allows longer.
- Get a parent's consent for children — applies at: under 14; sensitive data of under-16s, from 1 December 2026
- Appoint a data protection officer — from 1 December 2026Voluntary, not mandatory. Required only if you adopt the optional compliance model, which counts as a mitigating factor.
- Publish a complaints contact — from 1 December 2026A foreign company with no address in Chile must keep a working contact channel for people and for the Agency.
What it costs if you get it wrong
- Fixed maximum fine: 20,000 UTM (about CLP 1,432,980,000) — about $2 millionMost-serious infringements, including knowingly transferring data abroad in breach of the law
- Fixed maximum fine: 10,000 UTM (about CLP 716,490,000) — about $750 thousandSerious infringements
- Fixed maximum fine: 5,000 UTM (about CLP 358,245,000) — about $375 thousandMinor infringements; a written warning is also possible
- Percentage of global turnover: 2% or 4% of annual Chilean salesRepeat serious (2%) or most-serious (4%) infringements by a company that is not a small business
- Order to stop: 30 days, renewable indefinitely until complianceRepeated most-serious infringements within 24 months
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.719 as published, including the transitional articles
bcn.cl
“entrarán en vigencia el día primero del mes vigésimo cuarto posterior a la publicación de esta ley en el Diario Oficial”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten — official consolidated text of the version in force from 1 December 2026
bcn.cl
Link checked 18 August 2026
- Official sourceServicio de Impuestos Internos (Chilean tax authority)Monthly Tax Unit (Unidad Tributaria Mensual) values for 2026 — August 2026 = 71,649 Chilean pesos
sii.cl
Link checked 18 August 2026
General data protection law
Official name: Ley N° 19.628, sobre protección de la vida privada · Ley 19.628, Diario Oficial 28 August 1999 · Act of parliament
The privacy law actually in force in Chile until 30 November 2026. It says nothing about sending data abroad, creates no regulator, and leaves enforcement to civil judges whose fines top out around 750 US dollars.
Enforced by Civil courts of first instance
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Get consent
- Let people see their data
- Let people correct their data
- Delete data after a period — 5 yearsUnpaid debts may not be reported more than five years after they fell due, and not at all once paid.
What it costs if you get it wrong
- Fixed maximum fine: 10 UTM (about CLP 716,490) — about $750General breach, imposed by a civil judge
- Fixed maximum fine: 50 UTM (about CLP 3,582,450) — about $4 thousandBreach of the credit reporting rules or late compliance with a court order
- Claims by individualsCompensation for financial and moral harm, claimed in court by the individual
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 on the protection of private life, official consolidated text of the version in force to 30 November 2026
bcn.cl
“podrá aplicar una multa de una a diez unidades tributarias mensuales”
Link checked 18 August 2026
- Official sourceServicio de Impuestos Internos (Chilean tax authority)Monthly Tax Unit (Unidad Tributaria Mensual) values for 2026 — August 2026 = 71,649 Chilean pesos
sii.cl
Link checked 18 August 2026
Cyber security rules
Official name: Ley N° 21.663, ley marco sobre ciberseguridad e infraestructura crítica de la información · Ley 21.663, Diario Oficial 8 April 2024 · Act of parliament
Chile's national cybersecurity law. If you provide an essential service, you must alert the national cyber agency within three hours of a significant attack. That covers electricity, water, banking, telecoms, transport, hospitals and managed technology services. It says nothing about where data must be stored.
Enforced by National Cybersecurity Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 3 hoursEarly alert within 3 hours. Update at 72 hours. That drops to 24 hours for an operator of vital importance whose essential service is disrupted. Final report within 15 calendar days.
- Secure the data — applies at: Providers of essential services and operators of vital importance
- Register or notify — applies at: Operators of vital importance designated by the agency
- Independent audit — applies at: Operators of vital importance
What it costs if you get it wrong
- Fixed maximum fine: 20,000 UTM, or 40,000 UTM for an operator of vital importance (about CLP 2,865,960,000) — about $3 millionMost-serious infringements
- Fixed maximum fine: 10,000 UTM, or 20,000 UTM for an operator of vital importance — about $2 millionSerious infringements
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.663, articles 4, 8, 9 and 40 — essential services, incident reporting deadlines and fines
bcn.cl
“Dentro del plazo máximo de tres horas contado desde que se tiene conocimiento de la ocurrencia del ciberataque o incidente de ciberseguridad que pueda tener impactos significativos, se deberá enviar una alerta temprana sobre la ocurrencia del evento.”
Link checked 18 August 2026
- Official sourceLink may be brokenAgencia Nacional de CiberseguridadNational Cybersecurity Agency — own website
anci.gob.cl
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the three members of the Personal Data Protection Agency's board have been appointed
We could not confirm whether the board has been appointed. The law required the first appointment around 1 June 2026. The Senate's appointment records and the official gazette search both need a browser to run scripts, so we could not read them. No other official page confirmed or denied it. We treat the board as not appointed, which is the cautious reading. It is unproven.
Which law amended the fourth transitional article of Law 21.719 with effect from 5 February 2026
The official consolidated text shows that article with a February 2026 version date. There is no note naming the amending law, and we could not search the statute database. The article that fixes the 1 December 2026 start date is unchanged, so the start date itself is safe.
Whether the implementing regulations required by Law 21.719 have been issued
We could not confirm whether these regulations have been published. They were due within six months of the law being published, that is by mid-June 2025. We could not search the official gazette. Check before you rely on this.
The exact date the cybersecurity reporting duties began to bite, and the current staffing of the National Cybersecurity Agency
We could not confirm the date this duty started. The cybersecurity law leaves the start date to a decree with force of law that we could not find. The agency's website blocked automated access on 18 August 2026.
Whether the Financial Market Commission restricts banks, insurers or securities firms from processing customer data abroad
We could not read the Commission's rulebook, including the chapters on outsourcing and on information security. It is delivered through a script-driven interface we could not read automatically. Banking secrecy law and duties to notify the supervisor probably apply when you use a supplier abroad. We are not stating the detail without the text.
Whether any residency or sovereignty condition applies to cloud services bought by the Chilean state
We could not reach the digital government and public procurement rules on an official source. We found no rule in the privacy or cybersecurity laws requiring data to stay in Chile.
Whether restrictions on publishing detailed mapping and survey data still apply
The Military Geographic Institute's website refused automated access, so we could not check the current position on map approvals. If you work with mapping data, check before you rely on this.
The status of the bill to license online gambling
The casino law clearly excludes online games from any operating permit. We could not check the progress of any bill against an official congressional source, so we say nothing about it here.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.