Chile Data Protection Law
Chile Data Protection Law
Chile’s data protection framework is changing. Law No. 19.628 establishes the current baseline for personal data protection, while Law No. 21.719 strengthens requirements across consent, individual rights, vendor management, and security, taking full effect on December 1, 2026. OneTrust helps organizations prepare for the transition with continuous governance, connected workflows, and defensible evidence.
Compliance with Chile’s Data Protection Law is not a one-time documentation exercise. Organizations operating in Chile or processing Chilean resident data need a practical way to understand current obligations, prepare for new regulations, and keep privacy operations aligned as systems, vendors, and data uses change. OneTrust connects regulatory requirements to processing activities, owners, workflows, and evidence so teams can act before gaps become operational disruption.
Chile’s framework requires organizations to manage how personal data is collected, processed, shared, and protected. OneTrust centralizes data mapping, processing activity records, vendor relationships, and privacy risk assessments so privacy, legal, security, compliance, and technology teams can work from a shared view of data use, with out-of-the-box OnePIA risk assessment templates support Chile alongside a global evaluation of privacy requirements. Integrated discovery and business-led assessments help teams keep records current as activities change, prioritize high-risk processing, and document remediation decisions.
The incoming framework strengthens individual rights and consent expectations.
Law 21.719 establishes the following data protection rights, right of access, rectification, suppression, objection, objection to automated decisions, blocking of data, and portability rights.
OneTrust Privacy Automation supports configurable workflows for rights request intake, data discovery, matching, redaction, deletion, and response tracking. A centralized experience helps teams coordinate requests across systems and stakeholders, maintain consistent handling, and preserve the record of actions taken for audit and regulatory review.
Operational readiness extends beyond rights requests.
Law 21.719 states that consent must be free, informed, and specific as to its purpose or purposes, and must also be expressed unequivocally, by means of a verbal or written statement, or expressed through equivalent electronic means, or by an affirmative act that clearly shows the will of the data subject.
OneTrust helps organizations manage consent and preferences, assess third parties that process personal data, and document safeguards and controls. Regulatory intelligence from DataGuidance can be brought into privacy workflows through expert-backed content, templates, and configurable processes, helping teams adapt their programs as requirements evolve.
OneTrust enables organizations to comply with Chile’s Data Protection Law by providing continuous governance, control enforcement, and defensible evidence.
Connect consent, processing activities, assessments, vendors, rights requests, and evidence in one platform instead of stitching together point solutions.
Move from research to assigned actions, controls, and documented outcomes as requirements change.
Use AI to identify processing activities, scan documents, support assessment workflows, and reduce manual effort across privacy operations.
Chile’s data protection framework governs how organizations collect, process, share, store, and protect personal data. Law No. 19.628 is the current foundational statute, and Law No. 21.719 strengthens the framework and takes full effect on December 1, 2026.
OneTrust connects Chile-specific regulatory requirements to processing activities, owners, assessments, workflows, controls, and evidence. Teams can identify gaps, prioritize remediation, and maintain an operational readiness program ahead of the December 1, 2026 effective date.
Law 21.719 requires carrying out a DPIA whenever a type of processing, by its nature, scope, context, technology used, or purposes, is likely to result in a high risk to the rights of data subjects. Moreover, the data controller must adopt the technical and organizational measures both prior to and during the data processing. Therefore, DPIAs must be performed before beginning any given data processing.
OneTrust centralizes data discovery, records of processing activities, data owners, vendors, and privacy risk assessments. OneTrust PIA templates and connected workflows help teams identify high-risk processing, document decisions, and keep records current as systems and data uses change.
OneTrust helps organizations comply with Chile’s Data Protection Law by with legal-expert vetted guidance and regulatory updates and operational governance, control enforcement, and defensible evidence across processing activities, risk assessments, consent, privacy rights requests, data sharing across vendors, and regulatory intelligence. The platform helps teams maintain oversight as regulations, systems, vendors, and business operations change.
Operationalize Chile’s Data Protection Law with OneTrust
OneTrust is the AI-Ready Governance Platform™ that helps organizations maintain continuous privacy governance, coordinate accountability across teams, and produce defensible evidence as regulations and business operations change.