Personal Data Protection Law 21.719 in Chile
Chile's new law governing how companies and entities process personal data. Here's what is already in force, what is coming, and how to prepare.
What Law 21719 is and who it applies to
Law N° 21.719, published on December 13, 2024 and in full effect on December 1, 2026, is Chile's new personal data protection framework. The Executive submitted a bill to postpone full effect to December 1, 2027, still pending in Congress. It replaces the previous regime of Law 19.628 and draws on the GDPR standard, adapted to the local regulatory reality.
It applies to any organization — public or private, for-profit or not — that processes personal data of individuals in Chile, regardless of size, sector or whether the data is stored domestically or abroad.
Key dates
- Dec 13, 2024Publication
The law is published in the Official Gazette after being passed by Congress.
- Jun 13, 2025Decree 662
The regulation detailing the operational aspects of the law is published.
- Dec 1, 2026Full effect
All obligations are enforceable and the Agency begins supervision. An Executive bill proposes postponing this date to December 2027 (pending).
What the law requires you to do
Beyond ARCO+ request handling, the law requires a set of operational obligations. These are the ones every legal or compliance team must have in place before December 1, 2026.
Maintain a Record of Processing Activities (RAT)
Document every personal data processing: legal basis, purpose, data categories, retention period and processors.
Read: What is a RAT and how to build oneRespond to ARCO+ requests within 30 calendar days
Receive, route and respond to Access, Rectification, Cancellation, Opposition, Portability and Blocking requests within the legal deadline.
Read: An ARCO+ request just landed on your deskRetain RUTs and other identifiers with legal basis
Every data point you retain needs a documented purpose and a defined retention period. RUTs can no longer be kept 'just in case'.
Read: Do you keep your clients' RUTs?Manage granular consents
Where the legal basis is consent, it must be free, informed, specific and revocable. Each purpose separately.
Notify security incidents to the Agency
Any incident affecting personal data must be reported within defined deadlines. Opacity is no longer an option.
The ARCO+ rights any individual can exercise
Law 21719 extends the classic ARCO rights (Access, Rectification, Cancellation, Opposition) with two new ones: Portability and Blocking. Any individual can exercise them against your organization, without needing a lawyer.
Access
Know what data you hold on me and what you use it for.
Rectification
Correct inaccurate, incomplete or outdated data.
Cancellation
Delete my data when it is no longer needed for the purpose.
Opposition
Object to processing based on legitimate interest or direct marketing.
Portability
Receive my data in a structured format and transfer it to another provider.
Blocking
Temporarily suspend processing while a dispute is resolved.
Fines and sanctions
The Personal Data Protection Agency has the power to impose tiered administrative sanctions by severity, plus proportional-to-revenue fines for repeat offenders.
- Minor offenses
- Up to 5,000 UTM (~ $350M CLP)
- Serious offenses
- Up to 10,000 UTM (~ $700M CLP)
- Very serious offenses
- Up to 20,000 UTM (~ $1,400M CLP)
- Repeat offenders (proportional to revenue)
- 2% – 4% of annual revenue
Who supervises
The Personal Data Protection Agency is the autonomous and independent body created by the law itself. It begins its supervisory functions from the first day of effect (December 1, 2026) and can act on its own initiative or following complaints from any data subject. The same bill that proposes postponing enforcement also proposes expanding its Board from 3 to 5 members (quorum of 3) and designating the first Board early to prepare secondary regulation; all still pending in Congress.
Compliance roadmap: what to do in each phase
Five standard phases to reach full compliance. The timing below is an example for a company starting about 3 months ahead: the phases are standard and dates adjust by company and industry.
- 1
Sanitize your database
Today + month 1- Purge data without a legal basis or with expired retention.
- Data mapping: inventory of processing activities, purposes and legal bases (RAT).
- Separate sensitive data in your architecture.
- 2
Set up ARCO+ request handling
Months 1–2- Entry channels for requests (form, email, in person).
- Response protocol within 30 calendar days.
- Trained team to route and respond.
- 3
Update documents and contracts
Months 2–3- Privacy policy and terms updated to the new law.
- Data breach notification protocol.
- Data processing annexes (Art. 15 bis) signed with every vendor.
- 4
Governance and audit
Months 3–4- Data Protection Officer (DPO) appointed and operating.
- Compliance prevention model (Art. 49 and Decree 662).
- Final compliance audit before full effect.
- 5
Operate from day one
From full effect- ARCO+ rights enforceable and civil liability from day one, with no postponement approved to date.
- Requests answered within deadline, with full traceability.
- RAT, consents and protocols running continuously with the Agency.
In total, a complete compliance effort takes 3 to 4 months. The sequence is standard: dates adjust by company and industry, but the order doesn't. Build yours with margin before the full-effect date and have operations ready for day one.
Start now.
Get ready for Law 21719.
Plans contracted before October 1, 2026 keep the Early-mover discount (-30%) for life.--
Law 21719 comes into full effect on December 1, 2026 — and getting ready takes months.
We'll reach out within one business day to schedule it.
Done! We'll review your request.
Check your inbox — we'll write to you within one business day to coordinate your demo.
In the meantime, you can review the plans or read the frequently asked questions.