< Back to situation

[REVISION HISTORY]

Chilean personal data protection law implementation

Updated 2 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-04 00:04 UTC → 2026-09-04 23:34 UTC · added removed

Chile is considering a delay in the implementation of Law No. 21.719, the new Personal Data Protection Law. Originally set to take effect on December 1, 2026, the government has cited difficulties in establishing the necessary regulatory infrastructure, specifically the lack of an operational Data Protection Agency (APDP) following the Senate's rejection of proposed council candidates. By late August, the government proposed postponing the law’s implementation until December 1, 2027. This extension is intended to allow public agencies and private entities more time to prepare and to ensure the Data Protection Agency is fully functional. The proposal includes plans to strengthen the agency by increasing its Board of Directors from three to five members and expediting the appointment process to facilitate the development of secondary regulations. As of August 31, early September 2026, the proposed postponement aims a new legislative project seeks to provide all organizations, including startups and small businesses, time formalize these modifications. This project proposes that the five members of the Board of Directors must have exclusive dedication to elevate their standards for managing personal information. Experts recommend that entities prioritize basic controls, such as identifying what data roles. While proponents argue the delay is collected, how it necessary to ensure the Agency is used, properly installed and who has access. Compliance strategies include ensuring data usage has a legitimate purpose, obtaining specific consent capable of setting standards before inspections begin, critics suggest the move could extend the ‘grace period’ for additional processing, and establishing strict access permissions to mitigate digital risks. compliance for five years or more, potentially weakening privacy rights. Implementation challenges remain significant. A survey by the University of Chile indicated that only 29.11% of surveyed organizations have a clear data protection strategy, while over 54% do not perform impact assessments. The law introduces strict standards for managing sensitive information, such as biometric data, information and imposes significant economic sanctions for non-compliance. Penalties non-compliance, with penalties for violations can reach repeat offenders reaching up to 4% of a company’s annual revenue for repeat offenders. revenue.

Versions

  1. 2026-09-04 23:34 UTC Chilean personal data protection law implementation
  2. 2026-09-04 00:04 UTC Chilean personal data protection law implementation
  3. 2026-09-01 18:29 UTC Chilean personal data protection law implementation

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.