Mujeres Testing Latam
Back to Knowledge
LegalOctober 2025·Mujeres Testing Latam

Personal Data Protection (Chile) — Law 21,719

Practical guide to Law 21,719: data types, principles, people’s rights, companies’ duties, fines and how to prepare.

Informative summary based on Law No. 21,719 (Library of the National Congress of Chile). It does not replace the official text nor constitutes legal advice.

Law No. 21,719

It takes effect on December 1, 2026 and will affect all companies, institutions and professionals that handle personal information in Chile.

Goal: ensure every person controls their data and that organizations use it with transparency, security and responsibility.

Protected data types

Personal data

Information about an identifiable person: name, ID, address, email, phone, history. Require a valid legal basis or informed consent.

Sensitive data

Reveal intimate aspects: ethnicity, political views, beliefs, health, sex life, biometrics. Require express consent and stronger security.

Anonymized data

Do not allow identifying the person. Not personal data if re-identification is irreversible, but still require good security practices.

Minors’ data

Special protection for children and adolescents. Their processing requires consent from parents or guardians.

Biometric data

Unique physical or behavioral traits (fingerprints, face, voice, DNA). Restricted to legitimate purposes with reinforced security.

Fundamental principles

  • Lawfulness and fairness: process data legally, fairly and transparently, being able to prove it.
  • Purpose: collect them for specific, explicit and lawful purposes.
  • Proportionality: only strictly necessary data; once the purpose is met, delete or anonymize it.
  • Quality: accurate, up-to-date and relevant data.
  • Accountability: those who process data are legally responsible for compliance and proving it.
  • Security: protect against unauthorized access, loss or leaks.
  • Transparency and confidentiality: the owner must know how and who uses their data; those with access keep it secret.

People’s rights

  • Access: know whether their data is processed and learn its origin, purpose and recipients.
  • Rectification: correct, update or complete inaccurate data.
  • Erasure: delete data no longer needed or processed unlawfully.
  • Objection: object to processing based on legitimate interest or direct marketing.
  • Not be subject to automated decisions: with the right to human intervention.
  • Portability: receive a copy in a structured electronic format and transfer it.
  • Blocking: temporarily suspend processing while a request is reviewed.

Companies’ duties

  • Lawfulness, transparency and information: act on a legal basis and inform the owner clearly.
  • Purpose and use limitation, data accuracy and updating.
  • Erasure or anonymization when data is no longer needed.
  • Security: appropriate technical and organizational measures.
  • Report breaches: notify the Agency and, if there is risk, the data owners.
  • Proactive accountability: complying is not enough, you must prove it (records, policies, assessments).
  • Confidentiality, even after the relationship with the owner ends.

International scope: the law also applies to foreign companies that process data of people residing in Chile, even without a domicile in the country. They must keep an operational contact channel (Article 14) and comply with the same principles and obligations.

Fines and sanctions

Minor

Missing information, delays or minor errors. Fine up to 5,000 UTM or a warning.

Serious

Using data without consent, without adequate security or without reporting leaks. Fine up to 10,000 UTM.

Very serious

Misuse of sensitive or minors’ data, or repeated breaches. Up to 20,000 UTM and 30-day suspension.

Every sanction is recorded in a public National Registry of Sanctions. In case of repeat offenses, fines may triple and, for large companies, reach up to 4% of annual revenue.

How to prepare from now

  • Review what personal data you collect and for what purpose.
  • Update your privacy policy and make sure it is clear.
  • Train your team on responsible data handling.
  • Appoint a data protection officer or lead.
  • Assess risks if you use digital tools or AI that process personal information.
  • Implement security, backup and incident-notification measures.

This document is an informative summary and does not constitute legal advice. For official details, consult the Library of the National Congress of Chile.

Save or share this content

Download it as PDF or Markdown to save or share it.