Chile Law 21.719 Compliance with ConsentX
Chile Personal Data Protection Law
Chile
Enacted - effective 1 December 2026
Latin America & Caribbean
Who must comply
Law 21.719 applies broadly to the processing of personal data by natural and legal persons, including public bodies. The law regulates the way personal data is processed and protected and requires processing activities to respect the rights and freedoms of individuals. It also establishes rules concerning international transfers, sensitive data, automated decision-making and the responsibilities of organisations processing personal data.
Penalties
Law 21.719 introduces a structured enforcement and sanctions framework administered by the new Personal Data Protection Agency. The law distinguishes between different categories of infringements and establishes administrative sanctions depending on the seriousness and circumstances of the violation. Organisations should therefore establish privacy governance, security controls and documented compliance processes before the new framework becomes effective.
Key obligations
- Process personal data in accordance with the principles established by the law
- Identify and document the lawful basis for processing
- Provide transparent information about personal-data processing
- Collect and use data for specified and legitimate purposes
- Process only data that is adequate, relevant and necessary
- Keep personal data accurate, complete and up to date
- Apply appropriate security measures
- Maintain confidentiality of personal data
- Delete or anonymise data when it is no longer required for the applicable purpose, subject to legal exceptions
- Respect data subject rights
- Establish procedures for handling privacy requests
- Conduct appropriate risk assessments for qualifying processing activities
- Apply additional safeguards to sensitive personal data
- Implement requirements relating to automated decision-making and profiling
- Apply appropriate safeguards for international data transfers
- Maintain records and documentation necessary to demonstrate compliance
- Notify and manage qualifying personal data security incidents in accordance with the applicable requirements
These requirements are part of the new framework established by Law 21.719.
Principles of data processing
Law 21.719 establishes a number of core principles governing personal-data processing.
These include:
- Lawfulness and fairness
- Purpose limitation
- Proportionality
- Data quality
- Transparency
- Security
- Confidentiality
- Accountability
The law also establishes a responsibility principle under which organisations processing personal data are responsible for complying with the applicable principles, duties and obligations.
Consent requirements under Law 21.719
Consent is one of the legal bases for processing personal data under the new Chilean framework.
Where consent is relied upon, organisations should ensure that consent is obtained in accordance with the requirements established by the law and that individuals have sufficient information to understand the processing involved.
Law 21.719 also provides other lawful bases for processing in specified circumstances, meaning that organisations should not assume that consent is required for every processing activity.
For digital businesses, this makes it important to distinguish between processing activities that rely on consent and those that rely on another lawful basis.
Sensitive personal data
Law 21.719 provides stronger protection for sensitive personal data.
The definition includes information relating to areas such as health, biometric data, ethnic or racial origin, political or trade-union affiliation, religious or philosophical beliefs, sexual life, sexual orientation and gender identity.
Organisations processing sensitive information should therefore apply additional safeguards and verify that the applicable legal basis and conditions for processing are satisfied.
Data subject rights
Law 21.719 strengthens the rights available to individuals in relation to their personal data.
Depending on the circumstances, individuals will have rights including:
- Access - obtain information about their personal data and its processing
- Rectification - correct inaccurate or incomplete data
- Deletion - request removal of personal data where applicable
- Opposition - object to certain processing activities
- Portability - obtain and transmit personal data in applicable circumstances
- Additional rights relating to automated decision-making and profiling
The law specifically recognises the right to data portability among the new personal-data rights framework.
International data transfers
Law 21.719 establishes specific rules for the transfer of personal data to other countries.
Organisations transferring personal data internationally will need to assess the applicable legal basis and safeguards and ensure that transfers meet the requirements established by the new Chilean framework.
This makes international data-transfer governance an important part of compliance for organisations using global cloud, analytics, advertising and technology providers.
Security and data breaches
Organisations processing personal data must maintain appropriate security standards to protect information against unauthorised or unlawful processing, loss, leakage, accidental damage and destruction.
The new framework also establishes obligations relating to personal-data security incidents and provides a stronger institutional enforcement structure.
Personal Data Protection Agency
Law 21.719 creates the Personal Data Protection Agency, an autonomous public-law entity responsible for supervising compliance with Chile's personal data protection framework.
The Agency will have powers relating to supervision, enforcement and the protection of individuals' personal-data rights.
How ConsentX helps
Geo-aware consent management for Chilean visitors
Customisable privacy banners for different processing purposes
Consent and preference receipts to maintain evidence of user choices
Prior-script blocking to help control selected non-essential tracking technologies
Purpose-based consent controls for granular privacy preferences
Privacy preference centre for managing user choices
DSAR workflows to help organise data subject requests
Consent withdrawal mechanisms to support changing user preferences
Audit-ready records for consent and privacy interactions
Multi-jurisdictional controls for organisations operating across Chile and other privacy regimes
Get ready for Chile Law 21.719 with ConsentX
Prepare your website and digital properties for Chile's new personal-data protection framework. Manage consent preferences, privacy requests and compliance evidence from one central platform.
This page provides general information about Chilean data protection legislation and is not legal advice. Organisations should confirm their specific obligations with qualified Chilean privacy counsel.
How to comply with Law 21.719 using ConsentX
- 1
Scan your website
Run a free scan to identify cookies, trackers, scripts and other technologies operating on your website. Understand what information may be collected and which third parties may receive it.
- 2
Configure a Chile-specific privacy experience
Use ConsentX to configure a privacy banner and preference centre appropriate for visitors in Chile and the applicable processing activities.
- 3
Present clear privacy choices
Clearly communicate relevant processing purposes and give users an understandable way to manage applicable privacy preferences.
- 4
Capture and document consent
Where consent is the applicable legal basis, use ConsentX to capture user choices and maintain evidence of the consent interaction.
- 5
Control tracking technologies
Use prior-script blocking to help prevent selected non-essential tracking technologies from loading before the applicable privacy choice has been made.
- 6
Record privacy preferences
Maintain consent and preference receipts containing relevant information about the user's interaction with your privacy controls.
- 7
Manage data subject requests
Use ConsentX workflows to organise access, correction, deletion and other applicable privacy requests and maintain a central record of request handling.
- 8
Prepare for multi-jurisdictional compliance
Apply Chile-specific rules while maintaining separate configurations for GDPR, Argentina PDPL, Brazil LGPD, Mexico LFPDPPP and other applicable privacy frameworks.