Chile
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Chile is about to change completely. Today its 1999 privacy law says nothing at all about sending data abroad, and there is no privacy regulator. On 1 December 2026 a rewritten law switches on: transfers abroad will need a legal safeguard, and a new agency will be able to fine up to 4 percent of a company's Chilean sales. No industry has to keep data inside Chile.
Data governance in Chile
The eight things that decide how you handle data about people in Chile. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. From 1 December 2026 the rewritten law reaches any company anywhere that offers goods or services to people in Chile, or that watches their behaviour online, even with no office and no staff in the country. There is no size or revenue threshold. You do not need a local representative, but you must publish a working email address or similar contact point that both customers and the regulator can use.
The territorial scope rule is article 1 bis of the rewritten law: it covers processing by a controller or processor established in Chile, processing carried out on behalf of a Chilean-established controller, and processing by anyone not established in Chile whose activity is aimed at offering goods or services to people in Chile or at monitoring, tracking, profiling or predicting their behaviour. The last paragraph of article 14 requires a controller with no address in Chile to keep an up-to-date and working email address or equivalent contact channel for data subjects and for the Agency. That is far lighter than the European Union's requirement to appoint an established representative. The law in force until 30 November 2026 has no territorial scope clause at all.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten by Law 21.719, article 1 bis (territorial scope) and article 14 final paragraph, official consolidated text of the version in force from 1 December 2026
bcn.cl
“Cuando el responsable o mandatario no se encuentren establecidos en el territorio nacional pero sus operaciones de tratamiento de datos personales estén destinadas a ofrecer bienes o servicios a titulares que se encuentren en Chile”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.719, first transitional article — the rewrite starts on the first day of the twenty-fourth month after publication (published 13 December 2024, so 1 December 2026)
bcn.cl
Link checked 18 August 2026
Where the data is allowed to live
Today, yes, with nothing to sign: the privacy law in force in Chile right now does not mention sending data abroad at all. From 1 December 2026 that ends. After that date a transfer abroad is only lawful if the destination country has been declared adequate, or you have a contract or binding group rules with proper safeguards, or you fit a narrow exception. No industry in Chile has to keep a copy of data inside the country.
We searched for storage or residency mandates in banking, payments, insurance, securities, health, telecoms, government cloud, education, online gambling, mapping and defence, and found no rule requiring personal data to be stored in Chile. What the sectors do impose is different in kind: internet and telephone providers must keep one year of connection records available to prosecutors; health providers must keep patient files fifteen years and every entry in them counts as sensitive data; foreign financial technology firms must have an address in Chile to be registered; and organisations running essential services must alert the national cyber agency within three hours of a significant attack. From 1 December 2026, knowingly transferring data abroad in breach of the rules is one of the most serious categories of offence, punished by up to 20,000 monthly tax units, about 1.4 billion Chilean pesos or roughly 1.5 million US dollars, and up to 4 percent of annual Chilean sales for repeat offenders. No rule requiring data to stay in Chile was found in any sector, checked 18 August 2026, confidence medium for the sectors where the regulator's own rulebook could not be opened by machine.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 on the protection of private life, official consolidated text of the version in force to 30 November 2026 — the full text contains no provision on transfers abroad
bcn.cl
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, Title V, articles 27 to 29 (international transfer of personal data)
bcn.cl
“Cumpliéndose los requisitos que, de conformidad a esta ley, autorizan al tratamiento de datos, son lícitas las operaciones de transferencia internacional de datos en cualquiera de los siguientes casos”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 34 quater letter h — unlawful international transfer is a most-serious infringement
bcn.cl
“Realizar, a sabiendas, operaciones de transferencia internacional de datos en contravención a las normas previstas en esta ley.”
Link checked 18 August 2026
Sending data out of the country
From 1 December 2026 there are three main routes: send to a country the new agency has declared adequate, sign a contract or adopt binding group-wide rules that give people the same protection they have in Chile, or use an approved certification. If none of those fit, you can ask the agency to approve one specific transfer. Right now the agency does not exist, so there is no list of approved countries and no official model contract to copy.
Article 27 makes a transfer lawful where the destination is subject to a legal system with adequate protection, where contractual clauses or binding corporate rules with adequate guarantees are in place, or where sender and recipient adopt an approved compliance model or certification. Without those, a one-off, non-routine transfer is allowed on narrow grounds: the person's express consent, specific banking, financial or stock market transfers, obligations under ratified treaties, cooperation agreements between public bodies, an express legal authorisation, international judicial cooperation, performance of a contract with the person, and urgent medical or public health needs. Article 28 says the Agency will publish the list of adequate countries and model clauses on its website, and that clauses it approves need no further guarantee or authorisation. Two things matter operationally: the list is empty today because the Agency has not been constituted, and article 28 also allows the Agency to authorise a single transfer by reasoned decision. Article 29 lets the Agency inspect transfers, make recommendations, take precautionary measures and in qualified cases temporarily suspend the flow of data.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 28 — adequacy test, model clauses, binding corporate rules and one-off authorisations
bcn.cl
“La Agencia pondrá en su página web a disposición de los interesados un listado de países adecuados y modelos tipo de cláusulas contractuales y otros instrumentos jurídicos para la transferencia internacional de datos.”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 29 — the Agency may temporarily suspend transfers
bcn.cl
“La Agencia fiscalizará las operaciones de transferencia internacional de datos, pudiendo formular recomendaciones, adoptar medidas conservativas y en casos calificados, suspender temporalmente el envío de los datos.”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.719, fourth transitional article — the first members of the Agency's board were to be designated six months before the law starts
bcn.cl
Link checked 18 August 2026
The regulator, and whether it actually acts
Today, nobody. Chile has no privacy regulator: a person has to sue in a civil court, and the judge can fine between one and ten monthly tax units, roughly 70,000 to 700,000 Chilean pesos, or about 75 to 750 US dollars. A real regulator, the Personal Data Protection Agency, starts on 1 December 2026 with power to fine millions. As of 18 August 2026 we found no official confirmation that its three board members have been appointed, and the law wanted them named around 1 June 2026.
Under the law in force today, enforcement runs through the civil court of the controller's home district. The fine range is one to ten monthly tax units, or ten to fifty for breaches of the credit reporting rules. That is why enforcement is rated as waking rather than active: the text has existed since 1999 and produces almost no deterrent. From 1 December 2026 the Agency is a decentralised public service run by a three-member board, with its own investigation and sanction procedure, a public national register of sanctions and compliance, and the power to suspend a company's data processing for up to thirty days after repeated most-serious offences. Two other bodies already enforce in adjacent areas: the National Cybersecurity Agency, created by the 2024 framework law on cybersecurity, and the Financial Market Commission, which supervises banks, insurers, securities firms and registered financial technology providers. The Transparency Council supervises public bodies under the freedom of information law. We could not confirm the current staffing of the National Cybersecurity Agency because its website refused automated access on 18 August 2026.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as currently in force, articles 16 and 23 — claims go to the civil court and fines run from one to ten monthly tax units
bcn.cl
“podrá aplicar una multa de una a diez unidades tributarias mensuales”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, Title VI (articles 30 to 32 bis) creating the Personal Data Protection Agency and its three-member board, and article 38 (suspension of processing)
bcn.cl
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.719, fourth transitional article — first designation of the board due six months before the law starts, i.e. around 1 June 2026
bcn.cl
Link checked 18 August 2026
- Official sourceServicio de Impuestos Internos (Chilean tax authority)Monthly Tax Unit (Unidad Tributaria Mensual) values for 2026 — August 2026 = 71,649 Chilean pesos
sii.cl
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling, and they come from different laws. The floors: internet and phone companies keep one year of connection records, and hospitals and clinics keep patient files for at least fifteen years. The ceilings: from 1 December 2026 personal data may only be kept as long as the purpose needs, then it must be deleted or made anonymous, and unpaid debts may not be reported after five years. Where a specific law orders you to keep something, that beats the general delete-it rule.
Floor. The Code of Criminal Procedure requires public telecommunications companies and internet providers to hold, confidentially and at the disposal of prosecutors, an updated list of their authorised internet address ranges and a record of at least one year of the connection addresses their subscribers use, together with traffic data and subscriber addresses, and to destroy that material securely once the maximum period ends. Health providers must keep the patient file for at least fifteen years, and the whole file counts as sensitive data. Ceiling. The rewritten law's proportionality principle allows data to be kept only for as long as the purpose requires, after which it must be deleted or anonymised, unless a law says otherwise or the person consents to longer. Credit and commercial default data may not be communicated more than five years after the debt fell due, and may not be communicated at all once the debt is paid. The rewritten law resolves conflicts in favour of the specific legal duty: the deletion right does not apply where another legal obligation or a court decision requires the data to be kept.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Code of Criminal Procedure (Law 19.696), articles 218 bis and 222 — one-year retention of internet connection records
bcn.cl
“un registro, no inferior a un año, de los números IP de las conexiones que realicen sus abonados”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 20.584 on patients' rights, articles 12 and 13 — the clinical file is sensitive data and must be kept at least fifteen years
bcn.cl
“Los prestadores deberán conservar la ficha clínica por un período de al menos quince años.”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 3 letter c (proportionality) and article 18 (five-year limit on reporting debts)
bcn.cl
“Los datos personales pueden ser conservados sólo por el período de tiempo que sea necesario para cumplir con los fines del tratamiento, luego de lo cual deben ser suprimidos o anonimizados”
Link checked 18 August 2026
If something goes wrong
Count two clocks. If you run an essential service, a significant cyber attack must be reported to the national cyber agency within three hours, updated at seventy-two hours, and closed with a final report within fifteen days. Separately, from 1 December 2026, a personal data breach must be reported to the privacy agency by the fastest available means and without undue delay, with no fixed number of hours, and the affected people must also be told when sensitive data, data about children under fourteen or credit and banking data is involved.
The cybersecurity framework law sets the three-hour early alert from the moment you become aware of an attack or incident that may have significant effects, a seventy-two hour update with an initial assessment and any indicators of compromise, and a final report within fifteen calendar days of the early alert. An operator of vital importance whose essential service is actually disrupted must deliver the update within twenty-four hours instead of seventy-two. The personal data breach duty has no fixed deadline in hours, which sounds generous and is not: the wording is by the fastest possible means and without undue delay, and deliberately failing to report is a most-serious infringement. You must also keep an internal register of each breach describing what happened, the effects, the categories and approximate number of people affected and what you did about it. Where individual notice is impossible, notice must be published in a mass national medium.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.663, framework law on cybersecurity, article 9 — three-hour early alert, seventy-two hour update, fifteen-day final report
bcn.cl
“Dentro del plazo máximo de tres horas contado desde que se tiene conocimiento de la ocurrencia del ciberataque o incidente de ciberseguridad que pueda tener impactos significativos, se deberá enviar una alerta temprana sobre la ocurrencia del evento.”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 14 sexies — duty to report security breaches
bcn.cl
“El responsable deberá reportar a la Agencia, por los medios más expeditos posibles y sin dilaciones indebidas, las vulneraciones a las medidas de seguridad”
Link checked 18 August 2026
What catches people out
Five. (1) A child is anyone under fourteen and needs a parent's consent; teenagers aged fourteen to seventeen are treated as adults, except that sensitive data about under-sixteens still needs a parent. (2) If someone asks you to freeze their data you have two working days to answer, not thirty. (3) Unpaid debts vanish from credit reporting after five years and immediately once paid, and you have seven working days to pass on the news. (4) Congress, the courts, the central bank and other independent bodies write their own privacy rules and are outside the agency's reach. (5) Online gambling is not licensable in Chile at all.
The children's thresholds are unusual: under fourteen is a child, fourteen to seventeen is an adolescent processed under adult rules, and sensitive data about adolescents under sixteen needs parental consent. Rights requests generally get thirty calendar days, extendable once by thirty, but a request to temporarily block processing must be answered within two working days and, until you answer, you may not process that person's data at all. On credit data, the creditor must tell the credit register within seven working days of payment and downstream users must update within three days or block the record. On the fourth trap, the rewritten law puts the Senate, the Chamber of Deputies, the judiciary, the Comptroller General, the Central Bank, the Public Prosecutor, the Electoral Service and the National Television Council under a separate self-regulating regime, and the cybersecurity law says the same bodies are not subject to the cyber agency's supervision. On the fifth, the casino law states in terms that an operating permit never covers online games of chance, so anyone offering online betting to Chileans is operating outside the licensing system.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 16 quater — under fourteen is a child; sensitive data of under-sixteens needs parental consent
bcn.cl
“se consideran niños o niñas a los menores de catorce años, y adolescentes, a los mayores de catorce y menores de dieciocho años”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, article 11 (thirty days for rights, two working days for temporary blocking), articles 18 and 19 (credit data), Title VIII article 54 (Congress, courts and autonomous bodies)
bcn.cl
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.995 on games of chance in casinos, article 5
bcn.cl
“En ningún caso el permiso de operación comprenderá juegos de azar en línea.”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.663, article 53 — Congress, the judiciary, the Comptroller, the Central Bank, the Public Prosecutor, the Electoral Service and the National Television Council are outside the cyber agency's supervision
bcn.cl
Link checked 18 August 2026
What's changing next
One date dominates: 1 December 2026, when the rewritten privacy law starts and the new agency gets its powers. Before then the government has to name the agency's three board members and issue the regulations the law requires. For the first twelve months the agency may let small firms off with a written warning instead of a fine. Watch three switches the government can flip without asking anyone.
Dormant switches. First, the Agency alone decides which countries count as adequate and which model contracts are acceptable, so it can widen or narrow cross-border flows by publishing a list. Second, the Agency may suspend a specific data flow abroad as a precaution, and may suspend a company's processing entirely for thirty days after repeated most-serious offences, renewable indefinitely if the company does not comply. Third, the cybersecurity agency designates which companies are operators of vital importance, and that designation doubles the maximum fines and tightens the incident deadline from seventy-two to twenty-four hours. Also pending: the regulations the law requires, which were due within six months of publication, and one further transitional detail we could not resolve, namely that the official consolidated text shows the transitional article on appointing the board was amended with effect from 5 February 2026, and we could not identify the amending law. The date the substantive rules start was not amended.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.719, transitional articles one, two, four and six — start date, deadline for regulations, first board appointment and the twelve-month written-warning window for small firms
bcn.cl
“entrarán en vigencia el día primero del mes vigésimo cuarto posterior a la publicación de esta ley en el Diario Oficial”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten, articles 28, 29 and 38 — the adequacy list, precautionary suspension of transfers and suspension of processing
bcn.cl
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.663, articles 4 and 40 — designation of operators of vital importance and the doubled fine scale
bcn.cl
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Código Procesal Penal (ley N° 19.696), artículos 218 bis y 222
Act of parliament · Ley 19.696, Diario Oficial 12 October 2000, as amended
Telephone companies and internet providers must keep at least a year of subscriber connection records and hand them to prosecutors on request. The law does not say the records must sit in Chile, but they must be produced confidentially and on demand.
Enforced by Public Prosecutor's Office
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep logs — 1 yearAuthorised internet address ranges plus at least one year of subscriber connection records, traffic data and addresses, held confidentially for prosecutors and then securely destroyed.
- Secure the data
What it costs if you get it wrong
- Criminal liabilityRefusing or obstructing an interception order is the criminal offence of contempt of court
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Code of Criminal Procedure, articles 218 bis and 222
bcn.cl
“deberán mantener, en carácter reservado y bajo las medidas de seguridad correspondientes, a disposición del Ministerio Público, un listado actualizado de sus rangos autorizados de direcciones IP y un registro, no inferior a un año, de los números IP de las conexiones que realicen sus abonados”
Link checked 18 August 2026
Ley N° 20.584, que regula los derechos y deberes que tienen las personas en relación con acciones vinculadas a su atención en salud
Act of parliament · Ley 20.584, Diario Oficial 24 April 2012, as amended
Everything in a patient's clinical file counts as sensitive data, the file must be kept at least fifteen years, and access is limited to the professionals actually treating the patient. There is no requirement to hold it inside Chile.
Enforced by Ministry of Health
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 15 yearsThe clinical file must be kept for at least fifteen years.
- Extra vendor secrecy termsNobody outside the person's own care team may see the file, including the provider's own staff and administrators.
- Secure the data
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 20.584, articles 12 and 13
bcn.cl
“Los prestadores deberán conservar la ficha clínica por un período de al menos quince años.”
Link checked 18 August 2026
Ley N° 21.521, que promueve la competencia e inclusión financiera a través de la innovación y tecnología en la prestación de servicios financieros (Ley Fintec)
Act of parliament · Ley 21.521, Diario Oficial 4 January 2023
Foreign financial technology firms serving Chile must have an address in Chile and be on the regulator's register. Nothing in the law requires customer or transaction data to be stored in Chile.
Enforced by Financial Market Commission
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notifyCrowdfunding platforms, alternative trading systems, intermediaries, order routers, credit and investment advisers and custodians must be on the Financial Market Commission's register.
- Appoint a local representativeThe law requires a foreign company providing these services to have an address in Chile for that purpose. It is a local presence rule, not a data storage rule.
- Secure the dataOpen finance participants must meet the security and cyber standards the Commission sets by general rule.
- Get consentOpen finance data sharing runs on the customer's express consent.
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.521, article 5 (registration and Chilean address) and articles 16 to 27 (open finance system)
bcn.cl
“Las empresas internacionales que presten los servicios anteriormente descritos deberán tener domicilio en Chile para esos efectos.”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Ley N° 21.719, que regula la protección y el tratamiento de los datos personales y crea la Agencia de Protección de Datos Personales
Act of parliament · Ley 21.719, Diario Oficial 13 December 2024, rewriting Ley 19.628
Chile's rewritten general privacy law. It looks like Europe's: consent or another lawful basis, full individual rights, breach reporting, and transfers abroad only with adequacy, contractual safeguards or certification. It becomes enforceable on 1 December 2026 and there is no data residency requirement.
Enforced by Personal Data Protection Agency — not yet operational
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Government sign-off needed, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk
What it makes you do
- Get consent — from 1 December 2026
- Document a legitimate interest — from 1 December 2026
- Tell people what you do — from 1 December 2026A published privacy policy with twelve listed items, including whether data goes to a country without adequate protection.
- Let people see their data — from 1 December 2026Answer within 30 calendar days, extendable once by 30.
- Let people correct their data — from 1 December 2026
- Let people delete their data — from 1 December 2026
- Let people object — from 1 December 2026
- Let people take their data elsewhere — from 1 December 2026
- Limit automated decisions — from 1 December 2026Rights around decisions taken only by automated means, including profiling.
- Secure the data — from 1 December 2026
- Report breaches to the regulator — from 1 December 2026By the fastest possible means and without undue delay. No fixed hour count.
- Tell affected people — applies at: Sensitive data, data on children under 14, or credit and banking data, from 1 December 2026
- Assess high-risk projects — applies at: High-risk processing, from 1 December 2026
- Written vendor contract — from 1 December 2026
- Put a transfer safeguard in place — from 1 December 2026
- Delete data after a period — from 1 December 2026Delete or anonymise once the purpose is met, unless a law or the person's consent allows longer.
- Get a parent's consent for children — applies at: under 14; sensitive data of under-16s, from 1 December 2026
- Appoint a data protection officer — from 1 December 2026Voluntary, not mandatory. Required only if you adopt the optional compliance model, which counts as a mitigating factor.
- Publish a complaints contact — from 1 December 2026A foreign controller with no address in Chile must keep a working contact channel for people and for the Agency.
What it costs if you get it wrong
- Fixed maximum fine: 20,000 UTM (about CLP 1,432,980,000) — about $2 millionMost-serious infringements, including knowingly transferring data abroad in breach of the law
- Fixed maximum fine: 10,000 UTM (about CLP 716,490,000) — about $750 thousandSerious infringements
- Fixed maximum fine: 5,000 UTM (about CLP 358,245,000) — about $375 thousandMinor infringements; a written warning is also possible
- Percentage of global turnover: 2% or 4% of annual Chilean salesRepeat serious (2%) or most-serious (4%) infringements by a company that is not a small business
- Order to stop: 30 days, renewable indefinitely until complianceRepeated most-serious infringements within 24 months
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.719 as published, including the transitional articles
bcn.cl
“entrarán en vigencia el día primero del mes vigésimo cuarto posterior a la publicación de esta ley en el Diario Oficial”
Link checked 18 August 2026
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 as rewritten — official consolidated text of the version in force from 1 December 2026
bcn.cl
Link checked 18 August 2026
- Official sourceServicio de Impuestos Internos (Chilean tax authority)Monthly Tax Unit (Unidad Tributaria Mensual) values for 2026 — August 2026 = 71,649 Chilean pesos
sii.cl
Link checked 18 August 2026
Ley N° 19.628, sobre protección de la vida privada
Act of parliament · Ley 19.628, Diario Oficial 28 August 1999
The privacy law actually in force in Chile until 30 November 2026. It says nothing about sending data abroad, creates no regulator, and leaves enforcement to civil judges whose fines top out around 750 US dollars.
Enforced by Civil courts of first instance
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Get consent
- Let people see their data
- Let people correct their data
- Delete data after a period — 5 yearsUnpaid debts may not be reported more than five years after they fell due, and not at all once paid.
What it costs if you get it wrong
- Fixed maximum fine: 10 UTM (about CLP 716,490) — about $750General breach, imposed by a civil judge
- Fixed maximum fine: 50 UTM (about CLP 3,582,450) — about $4 thousandBreach of the credit reporting rules or late compliance with a court order
- Claims by individualsCompensation for financial and moral harm, claimed in court by the individual
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 19.628 on the protection of private life, official consolidated text of the version in force to 30 November 2026
bcn.cl
“podrá aplicar una multa de una a diez unidades tributarias mensuales”
Link checked 18 August 2026
- Official sourceServicio de Impuestos Internos (Chilean tax authority)Monthly Tax Unit (Unidad Tributaria Mensual) values for 2026 — August 2026 = 71,649 Chilean pesos
sii.cl
Link checked 18 August 2026
Ley N° 21.663, ley marco sobre ciberseguridad e infraestructura crítica de la información
Act of parliament · Ley 21.663, Diario Oficial 8 April 2024
Chile's cybersecurity framework law. Anyone providing an essential service, from electricity and water to banking, telecoms, transport, hospitals and managed technology services, must alert the national cyber agency within three hours of a significant attack. It imposes no storage location requirement.
Enforced by National Cybersecurity Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 3 hoursEarly alert within 3 hours; update at 72 hours, or 24 hours for an operator of vital importance whose essential service is disrupted; final report within 15 calendar days.
- Secure the data — applies at: Providers of essential services and operators of vital importance
- Register or notify — applies at: Operators of vital importance designated by the agency
- Independent audit — applies at: Operators of vital importance
What it costs if you get it wrong
- Fixed maximum fine: 20,000 UTM, or 40,000 UTM for an operator of vital importance (about CLP 2,865,960,000) — about $3 millionMost-serious infringements
- Fixed maximum fine: 10,000 UTM, or 20,000 UTM for an operator of vital importance — about $2 millionSerious infringements
Sources
- Official sourceBiblioteca del Congreso Nacional de Chile (Ley Chile)Law 21.663, articles 4, 8, 9 and 40 — essential services, incident reporting deadlines and fines
bcn.cl
“Dentro del plazo máximo de tres horas contado desde que se tiene conocimiento de la ocurrencia del ciberataque o incidente de ciberseguridad que pueda tener impactos significativos, se deberá enviar una alerta temprana sobre la ocurrencia del evento.”
Link checked 18 August 2026
- Official sourceLink may be brokenAgencia Nacional de CiberseguridadNational Cybersecurity Agency — own website
anci.gob.cl
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the three members of the Personal Data Protection Agency's board have been appointed
The law required the first designation around 1 June 2026. We could not open the Senate's appointment records or the official gazette's search, both of which need a browser to run scripts, and no other official page confirmed or denied it. Treated as not appointed, which is the cautious reading, but it is unproven.
Which law amended the fourth transitional article of Law 21.719 with effect from 5 February 2026
The official consolidated text shows that article carrying a February 2026 version date, but no annotation naming the amending law, and we could not run a search of the statute database. The article that fixes the 1 December 2026 start date is unamended, so the start date itself is safe.
Whether the implementing regulations required by Law 21.719 have been issued
They were due within six months of publication, that is by mid-June 2025. We could not search the official gazette to confirm publication.
The exact date the cybersecurity reporting duties began to bite, and the current staffing of the National Cybersecurity Agency
The framework law leaves commencement to a decree with force of law that we could not locate, and the agency's website blocked automated access on 18 August 2026.
Whether the Financial Market Commission restricts banks, insurers or securities firms from processing customer data abroad
Its rulebook, including the chapters on outsourcing and on information security, is delivered through a script-driven interface that could not be read automatically. Banking secrecy law and supervisory notification duties are likely to apply to offshore processing, but we are not asserting the detail without the text.
Whether any residency or sovereignty condition applies to cloud services bought by the Chilean state
We could not reach the digital government and public procurement rules on an official source. No statutory residency rule was found in the privacy or cybersecurity laws.
Whether restrictions on publishing detailed mapping and survey data still apply
The Military Geographic Institute's website refused automated access, so we could not verify the current position on cartographic approvals.
The status of the bill to license online gambling
The casino law clearly excludes online games from any operating permit. We could not verify the progress of any bill on an official congressional source, so nothing is asserted about it.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Put this next to another country
Chile versus
Compare