< Back to all clusters
[TECHNOLOGY] · Chile · 2 sources

started · updated

Chile advances cybersecurity and data protection regulations

Chile is undergoing a significant period of regulatory transition regarding cybersecurity and data privacy. The implementation of the Framework Cybersecurity Law and the consolidation of the National Cybersecurity Agency (ANCI) are forcing both public and private institutions to strengthen their ability to prevent, detect, and respond to digital incidents.

Critical sectors, including energy, transport, health, telecommunications, and finance, face increased pressure to move beyond mere regulatory compliance toward operational resilience. Experts suggest that organizations must prove they can sustain operations during an attack rather than simply demonstrating the existence of security policies.

Simultaneously, the Personal Data Protection Law introduces requirements for Data Protection Impact Assessments (DPIA), particularly for the “massive or large-scale processing of data.” However, current legislation lacks a specific numerical threshold to define what constitutes “massive” processing. This ambiguity places the responsibility on organizations to justify their assessment decisions until the future Data Protection Agency provides clearer criteria, potentially modeled after international standards that consider data volume, variety, duration, and geographic scope.

Entities

Chile · Cybertrust · Genetec · National Cybersecurity Agency