Skip to main content

On-demand webinar coming soon...

On-demand webinar coming soon...

Chile Data Protection Law

Operationalize Chile’s Data Protection Law With Continuous Governance 

Chile’s data protection framework is changing. Law No. 19.628 establishes the current baseline for personal data protection, while Law No. 21.719 strengthens requirements across consent, individual rights, vendor management, and security, taking full effect on December 1, 2026. OneTrust helps organizations prepare for the transition with continuous governance, connected workflows, and defensible evidence.

Chile Regulation Law diagram Chile Regulation Law diagram

Prepare for Chile’s 2026 data protection transition 

Compliance with Chile’s Data Protection Law is not a one-time documentation exercise. Organizations operating in Chile or processing Chilean resident data need a practical way to understand current obligations, prepare for new regulations, and keep privacy operations aligned as systems, vendors, and data uses change. OneTrust connects regulatory requirements to processing activities, owners, workflows, and evidence so teams can act before gaps become operational disruption.

Dashboard visualization shows data category distribution, consumer distribution, and risk breakdown for processing activities. The left chart lists categories such as personal identity, contact information, user account, background, employment, financial, government, device data, browsing information, social, and travel and expense. The top-right chart compares employees, contractors, customers, and prospective employees. The bottom-right chart presents risk levels labeled Medium, Zero, and Low with corresponding bar heights. The layout uses a clean interface with blue, yellow, and gray bars on a light background.

Maintain visibility across processing activities and risk 

Chile’s framework requires organizations to manage how personal data is collected, processed, shared, and protected. OneTrust centralizes data mapping, processing activity records, vendor relationships, and privacy risk assessments so privacy, legal, security, compliance, and technology teams can work from a shared view of data use, with out-of-the-box OnePIA risk assessment templates support Chile alongside a global evaluation of privacy requirements. Integrated discovery and business-led assessments help teams keep records current as activities change, prioritize high-risk processing, and document remediation decisions.

The image shows a minimalist interface with risk assessment cards on a light background. One vertical card displays an aggregated risk score of 8 with a red flag icon. Two horizontal cards present individual risk items with IDs 3515 and 1920, including fields such as Name, Type, and Criticality marked as High or Low with colored flag icons. The layout suggests a digital risk management or data governance dashboard focused on visualizing criticality levels.

Fulfill individual rights through connected workflows 

The incoming framework strengthens individual rights and consent expectations.

Law 21.719 establishes the following data protection rights, right of access, rectification, suppression, objection, objection to automated decisions, blocking of data, and portability rights.

OneTrust Privacy Automation supports configurable workflows for rights request intake, data discovery, matching, redaction, deletion, and response tracking. A centralized experience helps teams coordinate requests across systems and stakeholders, maintain consistent handling, and preserve the record of actions taken for audit and regulatory review.

User interface screen shows a consumer request workflow in the Legal/Privacy Review stage. The top navigation highlights steps including New, Request Fulfill, Legal/Privacy Review, Consumer Notification, and Complete. The Consumer Request Details section displays an info request for an employee in the United States. A Subtasks table lists tasks such as Get Emails and Redact, Review Reports, and Acknowledge Customer Request with corresponding system types, stages, and completion statuses.

Coordinate consent, vendors, and compliance evidence 

Operational readiness extends beyond rights requests.

Law 21.719 states that consent must be free, informed, and specific as to its purpose or purposes, and must also be expressed unequivocally, by means of a verbal or written statement, or expressed through equivalent electronic means, or by an affirmative act that clearly shows the will of the data subject.

OneTrust helps organizations manage consent and preferences, assess third parties that process personal data, and document safeguards and controls. Regulatory intelligence from DataGuidance can be brought into privacy workflows through expert-backed content, templates, and configurable processes, helping teams adapt their programs as requirements evolve.

Data Mapping screen

Why OneTrust

OneTrust enables organizations to comply with Chile’s Data Protection Law by providing continuous governance, control enforcement, and defensible evidence.

Unified Privacy Operations

Connect consent, processing activities, assessments, vendors, rights requests, and evidence in one platform instead of stitching together point solutions.

Embedded Regulatory Intelligence

Move from research to assigned actions, controls, and documented outcomes as requirements change.

AI-Powered Automation

Use AI to identify processing activities, scan documents, support assessment workflows, and reduce manual effort across privacy operations.

You May Also Like

Frequently Asked Questions

Chile’s data protection framework governs how organizations collect, process, share, store, and protect personal data. Law No. 19.628 is the current foundational statute, and Law No. 21.719 strengthens the framework and takes full effect on December 1, 2026.

OneTrust connects Chile-specific regulatory requirements to processing activities, owners, assessments, workflows, controls, and evidence. Teams can identify gaps, prioritize remediation, and maintain an operational readiness program ahead of the December 1, 2026 effective date.

Law 21.719 requires carrying out a DPIA whenever a type of processing, by its nature, scope, context, technology used, or purposes, is likely to result in a high risk to the rights of data subjects. Moreover, the data controller must adopt the technical and organizational measures both prior to and during the data processing. Therefore, DPIAs must be performed before beginning any given data processing.

OneTrust centralizes data discovery, records of processing activities, data owners, vendors, and privacy risk assessments. OneTrust PIA templates and connected workflows help teams identify high-risk processing, document decisions, and keep records current as systems and data uses change.

OneTrust helps organizations comply with Chile’s Data Protection Law by with legal-expert vetted guidance and regulatory updates and operational governance, control enforcement, and defensible evidence across processing activities, risk assessments, consent, privacy rights requests, data sharing across vendors, and regulatory intelligence. The platform helps teams maintain oversight as regulations, systems, vendors, and business operations change.

Operationalize Chile’s Data Protection Law with OneTrust

OneTrust is the AI-Ready Governance Platform™ that helps organizations maintain continuous privacy governance, coordinate accountability across teams, and produce defensible evidence as regulations and business operations change.