Chile’s Personal Data Protection Law 21.719 has been published in the Official Journal, comprehensively reforming the country’s 1999 data protection law. The new rules take effect after a 24-month transition period.
Key points
- Creates a Personal Data Protection Agency.
- Introduces GDPR-style principles, security duties and breach notification.
- Requires DPIAs and sets transfer rules.
- Introduces turnover-linked fines, from 1 December 2026.
UK organisations with Chilean customers, employees or operations should use the transition period to prepare, as the new law is closely aligned with the GDPR but has its own requirements.
Source: Ley 21.719 (Biblioteca del Congreso Nacional de Chile)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.