DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Chile

Chile Law 21.719 Compliance with ConsentX

Chile Personal Data Protection Law

Chile Law 21.719 significantly reforms Chile's personal data protection framework by replacing and modernising key provisions of Law No. 19.628. The law, formally titled "Regulates the Protection and Processing of Personal Data and Creates the Personal Data Protection Agency," establishes a comprehensive framework for the processing and protection of personal data and introduces stronger rights for individuals, new obligations for organisations and an independent data protection authority. Law 21.719 was published on 13 December 2024 and is currently scheduled to enter into force on 1 December 2026.
Region

Chile

Status

Enacted - effective 1 December 2026

Group

Latin America & Caribbean

Who must comply

Law 21.719 applies broadly to the processing of personal data by natural and legal persons, including public bodies. The law regulates the way personal data is processed and protected and requires processing activities to respect the rights and freedoms of individuals. It also establishes rules concerning international transfers, sensitive data, automated decision-making and the responsibilities of organisations processing personal data.

Penalties

Law 21.719 introduces a structured enforcement and sanctions framework administered by the new Personal Data Protection Agency. The law distinguishes between different categories of infringements and establishes administrative sanctions depending on the seriousness and circumstances of the violation. Organisations should therefore establish privacy governance, security controls and documented compliance processes before the new framework becomes effective.

Key obligations

  • Process personal data in accordance with the principles established by the law
  • Identify and document the lawful basis for processing
  • Provide transparent information about personal-data processing
  • Collect and use data for specified and legitimate purposes
  • Process only data that is adequate, relevant and necessary
  • Keep personal data accurate, complete and up to date
  • Apply appropriate security measures
  • Maintain confidentiality of personal data
  • Delete or anonymise data when it is no longer required for the applicable purpose, subject to legal exceptions
  • Respect data subject rights
  • Establish procedures for handling privacy requests
  • Conduct appropriate risk assessments for qualifying processing activities
  • Apply additional safeguards to sensitive personal data
  • Implement requirements relating to automated decision-making and profiling
  • Apply appropriate safeguards for international data transfers
  • Maintain records and documentation necessary to demonstrate compliance
  • Notify and manage qualifying personal data security incidents in accordance with the applicable requirements

These requirements are part of the new framework established by Law 21.719.

Principles of data processing

Law 21.719 establishes a number of core principles governing personal-data processing.

These include:

  • Lawfulness and fairness
  • Purpose limitation
  • Proportionality
  • Data quality
  • Transparency
  • Security
  • Confidentiality
  • Accountability

The law also establishes a responsibility principle under which organisations processing personal data are responsible for complying with the applicable principles, duties and obligations.

Consent requirements under Law 21.719

Consent is one of the legal bases for processing personal data under the new Chilean framework.

Where consent is relied upon, organisations should ensure that consent is obtained in accordance with the requirements established by the law and that individuals have sufficient information to understand the processing involved.

Law 21.719 also provides other lawful bases for processing in specified circumstances, meaning that organisations should not assume that consent is required for every processing activity.

For digital businesses, this makes it important to distinguish between processing activities that rely on consent and those that rely on another lawful basis.

Sensitive personal data

Law 21.719 provides stronger protection for sensitive personal data.

The definition includes information relating to areas such as health, biometric data, ethnic or racial origin, political or trade-union affiliation, religious or philosophical beliefs, sexual life, sexual orientation and gender identity.

Organisations processing sensitive information should therefore apply additional safeguards and verify that the applicable legal basis and conditions for processing are satisfied.

Data subject rights

Law 21.719 strengthens the rights available to individuals in relation to their personal data.

Depending on the circumstances, individuals will have rights including:

  • Access - obtain information about their personal data and its processing
  • Rectification - correct inaccurate or incomplete data
  • Deletion - request removal of personal data where applicable
  • Opposition - object to certain processing activities
  • Portability - obtain and transmit personal data in applicable circumstances
  • Additional rights relating to automated decision-making and profiling

The law specifically recognises the right to data portability among the new personal-data rights framework.

International data transfers

Law 21.719 establishes specific rules for the transfer of personal data to other countries.

Organisations transferring personal data internationally will need to assess the applicable legal basis and safeguards and ensure that transfers meet the requirements established by the new Chilean framework.

This makes international data-transfer governance an important part of compliance for organisations using global cloud, analytics, advertising and technology providers.

Security and data breaches

Organisations processing personal data must maintain appropriate security standards to protect information against unauthorised or unlawful processing, loss, leakage, accidental damage and destruction.

The new framework also establishes obligations relating to personal-data security incidents and provides a stronger institutional enforcement structure.

Personal Data Protection Agency

Law 21.719 creates the Personal Data Protection Agency, an autonomous public-law entity responsible for supervising compliance with Chile's personal data protection framework.

The Agency will have powers relating to supervision, enforcement and the protection of individuals' personal-data rights.

How ConsentX helps

Geo-aware consent management for Chilean visitors

Customisable privacy banners for different processing purposes

Consent and preference receipts to maintain evidence of user choices

Prior-script blocking to help control selected non-essential tracking technologies

Purpose-based consent controls for granular privacy preferences

Privacy preference centre for managing user choices

DSAR workflows to help organise data subject requests

Consent withdrawal mechanisms to support changing user preferences

Audit-ready records for consent and privacy interactions

Multi-jurisdictional controls for organisations operating across Chile and other privacy regimes

Get ready for Chile Law 21.719 with ConsentX

Prepare your website and digital properties for Chile's new personal-data protection framework. Manage consent preferences, privacy requests and compliance evidence from one central platform.

This page provides general information about Chilean data protection legislation and is not legal advice. Organisations should confirm their specific obligations with qualified Chilean privacy counsel.

How to comply with Law 21.719 using ConsentX

  1. 1

    Scan your website

    Run a free scan to identify cookies, trackers, scripts and other technologies operating on your website. Understand what information may be collected and which third parties may receive it.

  2. 2

    Configure a Chile-specific privacy experience

    Use ConsentX to configure a privacy banner and preference centre appropriate for visitors in Chile and the applicable processing activities.

  3. 3

    Present clear privacy choices

    Clearly communicate relevant processing purposes and give users an understandable way to manage applicable privacy preferences.

  4. 4

    Capture and document consent

    Where consent is the applicable legal basis, use ConsentX to capture user choices and maintain evidence of the consent interaction.

  5. 5

    Control tracking technologies

    Use prior-script blocking to help prevent selected non-essential tracking technologies from loading before the applicable privacy choice has been made.

  6. 6

    Record privacy preferences

    Maintain consent and preference receipts containing relevant information about the user's interaction with your privacy controls.

  7. 7

    Manage data subject requests

    Use ConsentX workflows to organise access, correction, deletion and other applicable privacy requests and maintain a central record of request handling.

  8. 8

    Prepare for multi-jurisdictional compliance

    Apply Chile-specific rules while maintaining separate configurations for GDPR, Argentina PDPL, Brazil LGPD, Mexico LFPDPPP and other applicable privacy frameworks.

Често задавани въпроси