Chile is about to switch on one of the most significant regulatory changes in its digital economy. Law N° 21.719 — published in the Diario Oficial on 13 December 2024 — comes into force on 1 December 2026. Formally it amends the old data protection law N° 19.628, but in practice it replaces almost all of it: companies that process personal data of people in Chile are facing genuinely new legislation.
The law deliberately follows the European model. As a report by the Library of the Chilean National Congress (Serie Informes N° 12-25, by Víctor Soto Martínez) points out, its consent standard, catalogue of rights, duties for data controllers, and sanction system closely mirror the EU’s General Data Protection Regulation (GDPR).
A new regulator with real teeth
The law creates the Agencia de Protección de Datos Personales, a decentralized public agency led by a three-member council appointed by the President with Senate approval for six-year, non-renewable terms. The Agency issues binding instructions, supervises compliance, resolves complaints from data subjects, sanctions infringements, and maintains a public National Register of Sanctions and Compliance.
New rights, stricter consent
Individuals gain enforceable rights of access, rectification, erasure, objection, temporary blocking of processing, and data portability. Consent becomes the general legal basis for processing and must be free, informed, specific, prior, and unequivocal — and it is always revocable. A closed list of exceptions (legal obligations, contract execution, and similar grounds) allows processing without consent, but the burden of proving lawfulness sits with the data controller.
Controllers also take on GDPR-style duties: published transparency information, adequate security measures, breach notification to the Agency, impact assessments for high-risk processing, and the option to appoint a data protection officer and certify a compliance program with the Agency.
Fines that reach 4% of annual revenue
Infringements are graded as minor, serious, or very serious, with fines of up to 5,000, 10,000, and 20,000 UTM respectively (Chile’s monthly tax unit — the top of that scale is well over a million US dollars). For large companies, serious and very serious infringements can instead be fined up to 2% or 4% of annual revenue. Repeat offenses can triple the fine, and failing to implement corrective measures within 60 days adds a 50% surcharge.
Importantly, the law applies extraterritorially: it also covers organizations established outside Chile whose processing is aimed at offering goods or services to people in the country.
Why this matters for AI projects
Chile is simultaneously discussing an AI bill (Boletín N° 16.821-19) modeled on the EU AI Act — and compliance with it is expected to be supervised by the same new Agency. Clean data governance is becoming the entry ticket for AI and automation initiatives that touch the Chilean market.
If your workflows, CRM, or AI systems process personal data of people in Chile, the transition window is closing: December 2026 is around the corner. Mapping your data flows, legal bases, and security measures now is far cheaper than retrofitting them under a regulator’s deadline.