Chile Personal Data Protection Law
Chile
Enacted - effective 1 December 2026
Latin America & Caribbean
Law 21.719 applies broadly to the processing of personal data by natural and legal persons, including public bodies. The law regulates the way personal data is processed and protected and requires processing activities to respect the rights and freedoms of individuals. It also establishes rules concerning international transfers, sensitive data, automated decision-making and the responsibilities of organisations processing personal data.
Law 21.719 introduces a structured enforcement and sanctions framework administered by the new Personal Data Protection Agency. The law distinguishes between different categories of infringements and establishes administrative sanctions depending on the seriousness and circumstances of the violation. Organisations should therefore establish privacy governance, security controls and documented compliance processes before the new framework becomes effective.
These requirements are part of the new framework established by Law 21.719.
Law 21.719 establishes a number of core principles governing personal-data processing.
These include:
The law also establishes a responsibility principle under which organisations processing personal data are responsible for complying with the applicable principles, duties and obligations.
Consent is one of the legal bases for processing personal data under the new Chilean framework.
Where consent is relied upon, organisations should ensure that consent is obtained in accordance with the requirements established by the law and that individuals have sufficient information to understand the processing involved.
Law 21.719 also provides other lawful bases for processing in specified circumstances, meaning that organisations should not assume that consent is required for every processing activity.
For digital businesses, this makes it important to distinguish between processing activities that rely on consent and those that rely on another lawful basis.
Law 21.719 provides stronger protection for sensitive personal data.
The definition includes information relating to areas such as health, biometric data, ethnic or racial origin, political or trade-union affiliation, religious or philosophical beliefs, sexual life, sexual orientation and gender identity.
Organisations processing sensitive information should therefore apply additional safeguards and verify that the applicable legal basis and conditions for processing are satisfied.
Law 21.719 strengthens the rights available to individuals in relation to their personal data.
Depending on the circumstances, individuals will have rights including:
The law specifically recognises the right to data portability among the new personal-data rights framework.
Law 21.719 establishes specific rules for the transfer of personal data to other countries.
Organisations transferring personal data internationally will need to assess the applicable legal basis and safeguards and ensure that transfers meet the requirements established by the new Chilean framework.
This makes international data-transfer governance an important part of compliance for organisations using global cloud, analytics, advertising and technology providers.
Organisations processing personal data must maintain appropriate security standards to protect information against unauthorised or unlawful processing, loss, leakage, accidental damage and destruction.
The new framework also establishes obligations relating to personal-data security incidents and provides a stronger institutional enforcement structure.
Law 21.719 creates the Personal Data Protection Agency, an autonomous public-law entity responsible for supervising compliance with Chile's personal data protection framework.
The Agency will have powers relating to supervision, enforcement and the protection of individuals' personal-data rights.
Prepare your website and digital properties for Chile's new personal-data protection framework. Manage consent preferences, privacy requests and compliance evidence from one central platform.
This page provides general information about Chilean data protection legislation and is not legal advice. Organisations should confirm their specific obligations with qualified Chilean privacy counsel.
Run a free scan to identify cookies, trackers, scripts and other technologies operating on your website. Understand what information may be collected and which third parties may receive it.
Use ConsentX to configure a privacy banner and preference centre appropriate for visitors in Chile and the applicable processing activities.
Clearly communicate relevant processing purposes and give users an understandable way to manage applicable privacy preferences.
Where consent is the applicable legal basis, use ConsentX to capture user choices and maintain evidence of the consent interaction.
Use prior-script blocking to help prevent selected non-essential tracking technologies from loading before the applicable privacy choice has been made.
Maintain consent and preference receipts containing relevant information about the user's interaction with your privacy controls.
Use ConsentX workflows to organise access, correction, deletion and other applicable privacy requests and maintain a central record of request handling.
Apply Chile-specific rules while maintaining separate configurations for GDPR, Argentina PDPL, Brazil LGPD, Mexico LFPDPPP and other applicable privacy frameworks.