Reconectando con el servidor
Mantén esta pestaña abierta: tu trabajo no se ha perdido.
No hemos podido reconectar
Recarga la página para continuar donde lo dejaste.
La sesión ha caducado
Vuelve a cargar la página para iniciar sesión de nuevo.
Ley 21.719 — Chile's new personal data protection law · Updated: julio de 2026
Ley 21.719 is Chile's new personal data protection law, aligned with the European GDPR standard. It takes effect in December 2026 and creates a supervisory authority for the first time — the Personal Data Protection Agency — with fines of up to 20,000 UTM and an infringement prevention model that acts as a mitigating factor.
To every public or private organisation processing personal data of people in Chile, whatever its size. Companies with European parents or subsidiaries already know the model: Ley 21.719 brings the GDPR's principles, rights and obligations to Chile.
See also the Spain–Latin America compliance calendar.
In December 2026, twenty-four months after publication. From that date the Personal Data Protection Agency can inspect and impose penalties.
Up to 5,000 UTM for minor infringements, 10,000 UTM for serious ones and 20,000 UTM for very serious ones, doubled for repeat offences.
A compliance programme (policies, controls, an officer, a channel, evidence) that the law itself recognises: holding a certified one mitigates liability. It's the data-protection equivalent of a criminal risk prevention model.
On nearly everything that matters: lawfulness and minimisation, data subject rights, controller and processor duties, breach notification, and an authority with enforcement powers. If you already comply with GDPR you're 80% of the way there — and if you don't, you can implement both on the same system.
This obligation is organised with an international management system standard. If your group is already certified, you have half the road done — and the same holds in the other countries where you operate.