Skip to main content

On-demand webinar coming soon...


On-demand webinar coming soon...

Chile's Data Protection Law

Chile's data protection law governs how organizations collect, process, share, and store personal data. It gives individuals rights over their information and sets legal obligations for every organization that handles it.


What Is Chile's Data Protection Law?

Chile's legal framework for personal data protection rests on two statutes. The Law No. 19.628 on the Protection of Private Life, which has been amended by Law No. 21.719, Regulating the protection and processing of personal data and creating the personal data protection agency, establishes baseline obligations for organizations that collect, store, or share personal information and gives individuals rights to access and correct their data. Law No. 21.719 was published in December 2024, which takes full effect on December 1, 2026.

Law No. 21.719 updates and strengthens the framework across consent collection, data subject rights, vendor management, and security obligations. Organizations operating in Chile, or processing personal data belonging to individuals in Chile, should understand both laws and prepare for the transition before the 2026 deadline.

These requirements work alongside broader privacy, legal, security, and governance programs that support responsible data handling.

Why Chile's Data Protection Law Matters

The shift from Law No. 19.628 to the incoming framework creates real compliance gaps for many organizations. Teams managing privacy operations across consent, rights requests, vendor relationships, and security controls will need to reassess their programs before December 1, 2026. Organizations that act early can reduce regulatory exposure, avoid operational disruption, and demonstrate trustworthiness to customers and partners.

Privacy, legal, security, compliance, and technology teams each carry pieces of this work. Coordinating those functions around a unified compliance program is where most of the practical challenge lies.

How to Comply With Chile's Data Protection Law in Practice

Organizations preparing for compliance typically address:

  • Mapping personal data flows and processing activities across systems
  • Updating privacy notices and consent practices to meet the new law's requirements (express, unequivocal, specific, previously informed, and free)
  • Building workflows to manage access, rectification, suppression, objection, objection to automated decisions, blocking of data, and portability requests.
  • Proving a legal basis for data processing. 
  • Implementing adequate technical and organizational security information measures, including data breach notification procedures, confidentiality, and information duty mechanisms.
  • Assessing vendors and third parties that process personal data on the organization's behalf
  • Documenting safeguards and controls for audit readiness

The December 2026 effective date for Law No. 21.719 makes early preparation more practical than a last-minute program build.

Related Laws & Standards

 

  • Chile Law No. 19.628 on the Protection of Private Life
  • Chile Law No. 21.719 (new data protection law, effective December 1, 2026)
  • General Data Protection Regulation (GDPR)
  • OECD Privacy Guidelines

 

How OneTrust Helps With Chile's Data Protection Law

OneTrust helps privacy and compliance teams operationalize requirements under Chile's data protection framework. Configurable workflows support rights request management, vendor assessments, and consent collection. Centralized data mapping keeps processing records current as systems change. Audit-ready evidence documentation supports regulatory inquiries and internal reviews.

Teams managing obligations under Law No. 19.628 today and preparing for the strengthened requirements of Law No. 21.719 can use OneTrust to coordinate privacy operations across legal, security, and technology functions.

[Explore OneTrust Privacy Automation →]

FAQs About Chile's Data Protection Law

Chile's data protection law refers to the specific legal obligations under statutes such as Law No. 19.628 and the incoming Law No. 21.719. Data privacy is the broader practice of collecting, using, and protecting personal information responsibly. The law sets the floor; a privacy program builds from there.

Data protection officers (DPOs) are not regulated under Law No. 19.628; however, they are introduced by Law No. 21.719 throughout the provisions of the infringement prevention model, which consists of compliance programs. 

Law No. 21.719 sets out the minimum requirements for an infringement prevention model and regulates its certification process and registration in a National Register of Sanctions and Compliance, which will be administered by the Agency. It will be mandatory to have a DPO if it is decided to adopt an infringement prevention model. 

 

Law No. 19.628 is the foundational statute currently in force. Law No. 21.719 replaces and substantially strengthens it. Until December 1, 2026, organizations must comply with 19.628. After that date, the new framework governs.