Jorge Tisné and Martin Ramos

Chile
  

One year has passed since the new Personal Data Protection Act came into legal force.

December 16, 2025

Bofill Mir - There is one year left before Law No. 21,719 comes into force, substantially amending Law No. 19,628, which will henceforth be known as the Personal Data Protection Law ("LPDP").

The new regulatory framework represents a profound transformation of the Chilean personal data protection system, aligning it with international standards and significantly raising the requirements applicable to those who process personal data. This implies rethinking the way organisations manage, safeguard and document their processing operations.

With the LPDP coming into force in December 2026, companies that handle personal data will need to review and adjust their internal processes, contracts, policies and security measures in order to move towards full compliance with the new standards.

Main obligations for companies:

  • Identify their role in the processing of personal data, to determine whether they act as data controller or data processor, or fulfil both roles.
  • Ensure that each personal data processing operation has a valid legal basis.
  • Have clear and accessible mechanisms in place so that data subjects can exercise their rights of access, rectification, erasure, objection, blocking and portability.
  • Regularise relations with those agents or processors who have been entrusted with the processing of personal data on behalf of the data subject.
  • Adopt technical and organisational measures for protection by design and by default, ensuring compliance with the principles and duties imposed by the LPDP.
  • Carry out Data Protection Impact Assessments in the cases expressly established by the LPDP.
  • Regularise the international transfer of data to the enabling circumstances and requirements established in the LPDP.

Oversight and Sanctions
For the first time in Chile, a specialized agency has been created to ensure compliance with regulations on personal data protection, called the Personal Data Protection Agency (the "Agency").
  • The Agency may provide administrative interpretations of the Personal Data Protection Law (LPDP), monitor its compliance, and impose sanctions in case of violations.
  • The LPDP includes a broad catalog of infractions classified as minor, serious, and very serious, with fines reaching up to 20,000 UTM (approximately USD 1,440,000) for very serious infractions.
  • In the event of a repeat offense (within 30 months), the Agency may impose a fine of up to three times the amount assigned to the original infraction.
  • In the case of large companies, the fine for repeat offenses of serious or very serious nature may reach the higher of: (i) three times the amount of the originally assigned fine; or (ii) 2% or 4% of the offender’s annual income in the last calendar year, respectively.
Violation Prevention Model
To prevent violations, the LPDP provides for the voluntary implementation of a violation prevention model, which will serve as a mitigating factor when registered with the new Agency. This model includes, among other elements:
  • The appointment of a Data Protection Officer (DPO).
  • The identification of the type of personal data the entity processes.
  • The identification of the entity’s activities or processes.
  • The establishment of specific protocols, rules, and procedures for the prevention of breaches, as well as internal reporting mechanisms and those for reporting to the relevant authority.
  • The existence of internal administrative sanctions, as well as reporting procedures for cases of non-compliance with the prevention system.
With half of the legal vacancy period now over, and only one year remaining before the LPDP comes into effect, organizations must review their level of compliance in detail and adjust their data processing procedures to the requirements of the new law.

bofillmir.com

Other news

Latin Counsel

Suscribe to our newsletter;

 

Our social media presence