By León Lanis, Paralegal
The entry into force of Law No. 21.719 will mark a structural change in the way businesses operating in Chile manage personal data. More than a regulatory update, the new regime introduces a stronger accountability framework, enhanced data subject rights and obligations that will need to be embedded into the day-to-day operations and governance of organisations.
Chile is approaching one of the most significant changes to its regulatory framework for privacy and data protection. Law No. 21.719, published in December 2024, substantially amends the existing personal data protection framework and establishes the Personal Data Protection Agency. The new regime is due to enter into force on 1 December 2026, leaving organisations with a limited period in which to assess their current arrangements and implement the necessary compliance measures.
The change is not simply a matter of updating a privacy notice or revising consent forms. The new legislation introduces a considerably more developed data protection framework that will affect how businesses collect, use, store, disclose and transfer personal data.
From consent to accountability
One of the central features of the new regime is the recognition of a number of principles that must underpin the processing of personal data.
The legislation incorporates, among others, the principles of lawfulness and fairness, purpose limitation, proportionality, data quality, accountability, security, transparency and confidentiality. Of particular importance is the principle of accountability, under which those carrying out data processing must be able to demonstrate compliance with their obligations under the legislation.
This represents an important shift in perspective.
The question for businesses will no longer be limited to “do we have authorisation to process this data?”. It will also be “can we demonstrate that our processing is lawful, necessary, proportionate, secure and consistent with the purpose for which the data was collected?”
New rights and greater expectations for data subjects
Law No. 21.719 significantly expands the rights available to data subjects. In addition to the traditional rights of access, rectification and cancellation, the new regime expressly recognises rights including objection, portability and blocking, subject to the conditions established by the legislation.
The right to data portability deserves particular attention from organisations handling significant volumes of information or operating digital businesses. Exercising this right may require technical and organisational capabilities that allow certain data to be provided in a structured format and, where the statutory requirements are met, transferred to another controller.
Accordingly, responding to data subject rights should not be regarded solely as a matter for the legal or privacy function. In many organisations, it will require coordination between Legal, Compliance, IT, Cybersecurity, HR, Marketing and the relevant business units.
The impact on service providers and processors
Another important aspect of the new regime is the regulation of relationships between controllers and third parties that process personal data on their behalf.
The legislation expressly addresses the role of the processor, who must process personal data in accordance with the controller’s instructions and the terms of the relevant engagement. Certain matters must also be addressed contractually, including the subject matter and duration of the processing, its purposes, and the categories of data and data subjects involved.
This is particularly relevant to business models that rely on cloud providers, SaaS platforms, technology providers, outsourcing arrangements, payroll providers, CRM systems, marketing automation and other technology services.
The implementation of the new regime should therefore prompt businesses to look beyond their own databases and assess who has access to personal data, under what conditions, and for what purposes.
International transfers: a particularly significant challenge
For businesses forming part of international groups or using infrastructure and service providers located outside Chile, one of the most significant aspects of the new framework will be the regime governing international transfers of personal data.
Law No. 21.719 establishes mechanisms under which such transfers may be permitted, including where the recipient is located in a country providing an adequate level of protection or where appropriate safeguards are in place, such as certain contractual clauses or binding corporate rules.
Organisations will therefore need to understand their international data flows and determine when a particular arrangement constitutes an international transfer and which legal mechanism supports it.
This will be particularly relevant for multinational companies, corporate groups and Chilean businesses relying on international technology providers. In such circumstances, privacy is no longer a purely domestic issue, but part of international data governance.
Who will be subject to the new framework?
The territorial scope of Law No. 21.719 also warrants careful consideration.
The legislation is not limited to organisations incorporated in Chile. Among other circumstances, it may apply to controllers or processors located outside Chile where they offer goods or services to data subjects in Chile or monitor their behaviour.
This approach is particularly relevant to technology companies, digital platforms and businesses operating cross-border models.
In other words, the absence of a legal entity in Chile does not necessarily mean that an organisation falls outside the scope of Chilean data protection law.
The real challenge: moving from documents to governance
For organisations, one of the greatest challenges will be avoiding an approach to the new regime that is purely documentary.
An updated privacy notice is important, but it does not, by itself, constitute a data protection programme.
Effective compliance requires an organisation to understand what personal data it processes, why it uses it, the applicable legal basis, where it is stored, who can access it, with whom it is shared, how long it is retained and what safeguards are in place to protect it.
This information provides the basis for identifying compliance gaps and determining which legal, contractual, organisational and technical measures are required.
This approach is particularly important given the accountability requirements introduced by the new framework. Organisations will need to be able to demonstrate effective compliance, rather than simply produce a collection of policies and contractual documents.
What should businesses be doing now?
With the new regime scheduled to enter into force in December 2026, this is an appropriate time for organisations to begin assessing their level of readiness.
The first step should be to understand the organisation’s data processing activities, its principal risks, and the interaction between its operations, technology, service providers and regulatory obligations.
Following that assessment, businesses can establish their priorities for compliance and remediation. These will vary significantly depending on the organisation’s business model and risk profile. The considerations applicable to a technology company, mining business, financial institution, retailer or multinational corporate group will not necessarily be the same.
The new framework should therefore not be approached through a one-size-fits-all solution. A data protection programme should reflect the organisation’s business model, operational reality and risk profile.
A new chapter for data protection in Chile
Law No. 21.719 represents a significant shift in Chile’s approach to personal data protection. Its impact will extend beyond the legal function to technology, cybersecurity, human resources, marketing, procurement and the broader governance of organisations.
The period before the legislation enters into force provides businesses with an opportunity to move from a reactive approach to a model of privacy governance embedded within the business.
At HGG, we support organisations in assessing and managing regulatory and technology-related risks, including Data Protection, Privacy Governance, international data transfers, controller–processor relationships and technology compliance, with a cross-border perspective that enables us to address privacy challenges arising from operations across multiple jurisdictions.
The question is no longer whether data protection will be relevant to the business. The question is whether the organisation will be prepared to demonstrate that it is managing it appropriately.
