← Back to blog

Assignment of personal data in Chile: when you can share data with another company under article 15 of Law 21.719

The assignment of personal data in Chile will be subject to express rules once Law 21.719 takes effect: article 15 sets out four grounds for sharing data with another company, requires the assignment to be recorded in writing or through a suitable electronic means with a minimum content, and establishes that the assignee acquires the status of data controller for all legal purposes. Here is what you should review before signing.

GUIDE · LAW 21.719
Short answer

A company in Chile may assign personal data to another, under article 15 of Law 21.719, where it has the data subject's consent and the assignment fulfils the purposes of the processing, where the assignment is necessary to execute a contract to which the data subject is a party, where a legitimate interest exists, or where the law so provides.

The essentials in 30 seconds

  • Article 15 of Law 21.719: four legal grounds enable an assignment — the data subject's consent together with fulfilment of the purposes of the processing; necessity for the performance and execution of a contract to which the data subject is a party; a legitimate interest of the assignor or the assignee under the terms of letter d) of article 13; and where the law so provides.
  • If the consent obtained at the time of collection did not contemplate the assignment, it must be obtained before the assignment takes place and is deemed, for all legal purposes, a new processing operation.
  • Mandatory formality: the assignment must be recorded in writing or through any suitable electronic means, identifying the parties, the data covered by the assignment, the purposes envisaged for the processing, and any other background information or stipulations agreed between assignor and assignee.
  • Assigning data without consent where consent was required renders the assignment null and void and obliges the assignee to delete all data received, without prejudice to any applicable legal liabilities. Article 35 provides for fines of up to 5,000 UTM for minor infringements, up to 10,000 UTM for serious ones and up to 20,000 UTM for very serious ones; the classification depends on the specific infringement. The law takes effect on 1 December 2026.

Almost every company shares personal data with someone else. A bank sells a loan portfolio. An insurer forms an alliance with a retailer and both use the same database. A holding company centralises information from its subsidiaries. A commercial partner asks for the customer list for a joint campaign. All of those operations change their rules on 1 December 2026, when Law 21.719 takes effect and article 15 sets out in detail when and how one company may assign personal data to another in Chile. If you want the full picture, start with our guide to the data protection law in Chile.

The costliest confusion we see in practice is treating as one and the same two arrangements the law carefully keeps apart: the assignment under article 15 and processing through a third-party agent or processor under article 15 bis. This is not a lawyers' technicality. If you classify the operation incorrectly, you sign the wrong document, you inform the data subject incorrectly, and you can end up with two controllers where you thought you had one, or with a vendor that does not even know the law considers it a data controller.

This guide explains that distinction first, because without it the rest makes little sense, and then walks through what you need to review before signing: the four grounds that enable an assignment, the prior-consent rule, what the contract must say, who is answerable afterwards, and what happens when an assignment is made without the appropriate legal basis.

What is the difference between assigning data and engaging someone to process it?

The difference lies in who decides what the data is used for. In the assignment under article 15 of Law 21.719, once the assignment is completed the assignee acquires the status of data controller for all legal purposes. Under article 15 bis, a third-party agent or processor processes the data on the controller's behalf, and the controller retains control of the operation.

In business terms: when you engage a bulk email provider, a call centre, a cloud service or a debt-collection firm that carries out your instructions, you are normally looking at a processing arrangement. That vendor does not define purposes of its own, should not reuse the database for its own campaigns, and does not become the informational owner of anything. Your company remains the controller answerable to the data subject and to the Personal Data Protection Agency.

When, by contrast, you hand data to a partner so it can use it in its own business — an alliance in which each side runs separate campaigns, the sale of a loan portfolio, the migration of a database to the buyer of a business unit — the operation looks like an assignment. The recipient stops being an executor and becomes a controller with obligations of its own: the duty of information and transparency under article 14 ter, the duty of secrecy or confidentiality under article 14 bis, security measures under article 14 quinquies, handling of rights within the deadlines of article 11, and breach notification under article 14 sexies.

Three questions resolve most borderline cases. If all three answers point to the third party, you are most likely assigning rather than engaging a processor; where the operation is mixed or the allocation of decision-making is unclear, it is worth reviewing it with professional advice before signing.

  • Who defined the purpose of the use? If the third party defined it, that points to an assignment.
  • Can the third party use the data for its own business, beyond your instructions? If it can, that points to an assignment.
  • If the data subject complains, must the third party answer for its own decisions? If it must, that points to an assignment.
Assignment (article 15) versus processing by a third-party agent or processor (article 15 bis) under Law 21.719
CriterionAssignment — article 15Processing arrangement — article 15 bis
Who decides the purpose?The assignee, and its processing must be carried out in accordance with the purposes established in the assignment agreementThe controller; the processor processes the data on its behalf
Who is the data controller?The assignee acquires the status of controller for all legal purposes; the assignor retains it with respect to the operations it continues to carry outThe controller retains control of the operation; the third party acts as agent or processor on its behalf
Which document is used?An assignment agreement in writing or through a suitable electronic means, identifying the parties, the data, the purposes envisaged and any other background information or stipulationsA processing agreement or mandate, within the framework of article 15 bis, defining the scope of the processing carried out on the controller's behalf
What happens to the data?It comes to be processed by the assignee for the agreed purposes, in its capacity as controllerIt is processed on behalf of the controller, which retains control of the operation
If the legal basis is missingThe assignment will be null and void and the assignee must delete all data received, without prejudice to any applicable legal liabilitiesThe nullity rule of article 15 does not apply, but the processing still requires a lawful basis held by the controller (articles 12 and 13)

When can I assign personal data to another company in Chile?

Article 15 of Law 21.719 provides for four grounds. Data may be assigned with the data subject's consent and for the fulfilment of the purposes of the processing; where the assignment is necessary for the performance and execution of a contract to which the data subject is a party; where there is a legitimate interest of the assignor or the assignee under the terms of letter d) of article 13; and where the law so provides.

The first ground deserves a close reading, because it sets out two requirements rather than one. Consent alone is not enough: the assignment must also serve the fulfilment of the purposes of the processing. Broad consent drafted as a blank cheque will rarely enable any subsequent destination if that destination bears no relation to the purpose communicated to the data subject.

The second ground is narrower than it is usually made out to be. It requires necessity for the performance and execution of a contract to which the data subject is a party, not mere commercial convenience. Providing the customer's address to whoever will deliver their order may fit that contractual-performance logic — although in many cases that operator will act as a processor under article 15 bis rather than as an assignee — whereas sharing the full customer database with a partner that will make offers of its own hardly fits, because the data subject is not a party to that agreement between companies.

The third ground, legitimate interest, is the one that demands the most analysis. It refers back to letter d) of article 13, and using it seriously means putting in writing what interest is being invoked, why the assignment is necessary to satisfy it, and how the data subject's rights and reasonable expectations were weighed. The impact assessment under article 15 ter is a natural support where the assignment is large-scale or involves sensitive data. And the fourth ground, a statutory provision, is not presumed: you have to identify the specific rule that requires or authorises the disclosure.

Two warnings before moving on. The sensitive data covered by article 16 and following — health and human biological profile, biometric data, political or trade-union affiliation, beliefs or convictions, geolocation, sexual life and sexual orientation, data of children and adolescents and, distinctively in Chile, socio-economic status — are subject to a stricter regime and are not assigned so lightly. And data relating to criminal, civil, administrative and disciplinary infringements may, under article 25, only be processed by public bodies for the fulfilment of their legal functions, within the scope of their powers and in the cases expressly provided for by law, which puts pressure on much of the private-sector practice of background screening and makes it advisable to review such practices case by case with legal advice before including them in an assignment.

What happens if the original consent did not contemplate the assignment?

It has to be obtained before the assignment takes place. Article 15 of Law 21.719 states it clearly: if the consent obtained at the time of collection did not contemplate the assignment, it must be obtained before the assignment takes place, and it is deemed for all legal purposes a new processing operation.

That classification — a new processing operation — has concrete consequences that are often overlooked. It means the assignment needs its own lawful basis, its own declared purpose and its own compliance with the duty of information and transparency under article 14 ter. It also means it should be recorded as a separate operation in your inventory of processing activities, and that the data subject may exercise in respect of it the rights recognised in articles 10 and 11, including the right to object.

In operational terms, the order matters and cannot be reversed. First you identify the enabling ground, then you obtain consent where required, then you document the assignment, and only then do you transfer the data. Putting the paperwork right afterwards does not solve the underlying problem: the consequence set out in article 15 attaches to the assignment already carried out without the required consent, not to the absence of documents.

And that consequence is the most severe in the whole article. If an assignment takes place without the data subject's consent where such consent was required, the assignment will be null and void, and the assignee must delete all data received, without prejudice to any applicable legal liabilities. Translated into transaction language: the buyer of the portfolio is left without the asset, the assignor is exposed, and the deal unravels over a defect at origin that a prior review could have avoided.

What must a personal data assignment agreement say?

The assignment must be recorded in writing or through any suitable electronic means, and it must identify the parties, the data covered by the assignment, the purposes envisaged for the processing, and any other background information or stipulations agreed between assignor and assignee. That is what article 15 of Law 21.719 requires in Chile.

The minimum legal content is short, but meeting it in practice demands precision. "Customer data" identifies nothing. What holds up under scrutiny is an annex setting out the categories of data subjects and the specific fields being assigned, together with a purpose clause drafted so that it can be audited. Article 15 itself adds a restriction that is sometimes forgotten: processing by the assignee must be carried out in accordance with the purposes established in the assignment agreement. What is not in the contract, the assignee should not be doing.

It is worth building a little beyond the legal minimum, not out of formalism, but because afterwards no one remembers who was supposed to do what. These are the elements that prevent disputes in practice, and that are best tailored with professional advice to the type of operation:

  • Full identification of the parties, including the capacity in which they act (assignor and assignee, both controllers).
  • An annex of assigned data: categories of data subjects, specific fields, volume, and whether sensitive data is included.
  • The purposes envisaged, drafted in verifiable terms, with an express prohibition on uses not contemplated in the assignment agreement.
  • The enabling ground under article 15 relied upon and, where applicable, evidence of the consent obtained before the assignment takes place.
  • Agreed security measures for the transfer and subsequent storage, in line with the duty under article 14 quinquies.
  • The duty of secrecy or confidentiality under article 14 bis extended to the personnel of both parties.
  • A breach protocol: how the parties notify each other so that each can comply with article 14 sexies, which requires reporting to the Agency by the most expeditious means possible and without undue delay, without setting a deadline in hours.
  • A channel for handling rights: who answers each request under article 11 and how requests are routed between the parties within the 30 calendar days available to the controller.
  • Retention and deletion rules at the end of the contract, including copies and backups.
  • Audit and compliance evidence, specifying what each party may require from the other.

Who is answerable to the data subject after the assignment?

Both parties are, each for its own share. Article 15 of Law 21.719 provides that, once the assignment is completed, the assignee acquires the status of data controller for all legal purposes, and that the assignor also retains the status of controller with respect to the operations it continues to carry out.

That rule dismantles a common myth: assigning data does not transfer the problem. If your company assigns a database but continues processing that same data for its billing, its collections or its analytics, it remains the controller of those operations, with the duties set out in article 14 and following. What the assignment does is add a controller, not subtract one.

For the assignee, the consequence is equally concrete. From the moment it receives the data it must comply with the duty of information and transparency under article 14 ter towards data subjects it may never have spoken to, handle requests for access, rectification, deletion, objection and portability by responding no later than the 30 calendar days set out in article 11 — extendable once by up to a further 30 calendar days — and respond to temporary blocking requests within 2 business days, without being able to process that data until it resolves the request.

The chain of consequences is also described in the law. If the controller denies a request under article 11 or fails to respond within the legal deadline, the data subject may complain to the Agency in writing, in physical or electronic format, within 30 business days counted from receipt of the negative response or from the expiry of the controller's deadline, under article 41. In that procedure the Agency has 10 business days to determine whether the complaint meets the requirements to be admitted for processing — and it is deemed admitted if the Agency does not rule within that period — after which the controller has 30 calendar days, extendable by up to the same period, to respond. In parallel, article 47 obliges the controller to compensate the pecuniary and non-pecuniary damage it causes to the data subject where, in its processing operations, it infringes the principles of article 3 or the rights and obligations under the law and causes harm; the compensation claim may be brought once the decision upholding the complaint before the Agency is enforceable, or once the judgment is final and enforceable in the case of an illegality claim, and civil actions are subject to a five-year statute of limitations counted from the date on which the administrative decision or the court judgment imposing the relevant fine becomes enforceable. And article 39 creates a National Registry of Sanctions and Compliance, public, free of charge and electronic, whose entries remain accessible for five years.

How does this apply to a portfolio sale, an alliance or a corporate group?

The four situations that come up most often are approached with the same sequence: classify the operation, identify the ground under article 15, verify consent where required, and document the assignment. In Chile, under Law 21.719, none of them is resolved by invoking market custom, and each deserves its own legal review.

Portfolio sale. This is a textbook assignment, and usually the most sensitive one, because it involves volume and data on economic, financial, banking or commercial obligations. What has to be checked before signing is whether the consent under which that data was collected contemplated assignment to a third-party acquirer, or whether another enabling ground under article 15 applies. If consent was required and was not obtained beforehand, the assignment will be null and void and the assignee must delete everything it received. It is advisable to build that check into due diligence rather than leaving it as a last-minute legal annex.

Commercial alliance. The decisive question is whether the partner will use the data for its own business. If your company sends the joint campaign from its own platform and the partner never accesses the database, the operation resembles a processing arrangement. If the partner receives the database and makes its own offers, it resembles an assignment, and the data subject should have been informed that their information would reach that type of recipient.

Corporate group. Article 15 provides no special exception for corporate groups. The parent company and each subsidiary are separate legal entities and, where one hands data to another for its own purposes, the operation is structured as an assignment. Many holding companies will have to document internally what today runs on trust and shared system access.

A database shared with a partner. This is the scenario in which the two arrangements are most often confused, because simultaneous access says nothing in itself about the capacity in which each party acts. You have to determine whether the partner decides purposes — an assignment — or merely processes the data on your company's behalf — a processing arrangement under article 15 bis — and put it in writing before opening access.

An honest closing note on what is still undefined: article 14 septies provides that the standards or minimum conditions imposed on the controller in order to comply with the duties of information (article 14 ter) and security (article 14 quinquies) will be determined taking into account the type of data, whether the controller is a natural or legal person, the size of the entity or company according to the categories in article two of Law 20.416, the activity it carries out, and the volume, nature and purposes of the data it processes, and that they will be set by the Agency through a general instruction. As of July 2026 that general instruction has not yet been issued, so the specific detail of the standards remains pending. Importantly, that differentiation will calibrate the level of demand according to the case, but it does not make the obligations optional nor exempt anyone from complying with them. What you can do now is build the inventory of assignments and processing arrangements, decide how each data flow is classified, review the consents currently in place and put the contracts in order, because none of that depends on the instruction still to come.

Review your data assignments before 1 December 2026

At AlayIAtrust we build your company's inventory of data assignments and processing arrangements, define the lawful basis for each data flow, and prepare the assignment and processing agreements required by Law 21.719. If you plan to share data with partners, subsidiaries or portfolio buyers, let's talk before you sign.

Schedule an assessment

Frequently asked questions

Does the assignment of personal data always require the data subject's consent?

Not always. In Chile, article 15 of Law 21.719 permits the assignment of data with the data subject's consent and for the fulfilment of the purposes of the processing, but also where the assignment is necessary for the performance and execution of a contract to which the data subject is a party, where there is a legitimate interest of the assignor or the assignee under the terms of letter d) of article 13, or where the law so provides.

What happens if I assign data without the required consent?

Article 15 of Law 21.719 is explicit: if an assignment takes place without the data subject's consent where such consent was required, the assignment will be null and void, and the assignee must delete all data received, without prejudice to any applicable legal liabilities. In practice, your counterparty is left without the asset it believed it had acquired.

Is my software vendor an assignee or a processor?

Typically a processor. If the vendor processes data on your company's behalf, following its instructions and without defining purposes of its own, you are in the territory of article 15 bis of Law 21.719 and your company retains control of the operation as data controller. An assignment exists when the third party begins processing the data for its own purposes. If the allocation of decision-making is unclear, it is worth reviewing the contract with professional advice.

Can I assign data between companies within my own group without further formalities?

That is not a safe assumption. Article 15 of Law 21.719 provides no special exception for corporate groups: each legal entity is a separate data controller, so the parent company, subsidiary or affiliate that receives data for its own purposes acts as an assignee. You need one of the legal grounds under article 15 and a documented assignment with the purposes specified.

Is an assignment agreement signed by electronic means valid?

Yes. Article 15 of Law 21.719 requires the assignment to be recorded in writing or through any suitable electronic means. What matters is not only the medium, but that the document identifies the parties, the data covered by the assignment, the purposes envisaged for the processing, and any other background information or stipulations agreed between assignor and assignee.

Can I sell my customer database to another company in Chile?

Only if one of the grounds under article 15 of Law 21.719 enables that assignment. If the consent obtained at collection did not contemplate it, consent must be obtained before the assignment takes place, because the law treats it for all legal purposes as a new processing operation, with its own lawful basis, its own purpose and its own duty to inform.

What happens to the data subject's rights after the assignment?

They may be exercised against both companies. The assignee acquires the status of data controller for all legal purposes, and the assignor retains that status with respect to the operations it continues to carry out. The deadlines under article 11 of Law 21.719 apply to both: a response no later than 30 calendar days from submission of the request, extendable once by up to a further 30 calendar days.

Can I assign data about infringements or criminal records to a partner?

Particular caution is required here. Article 25 of Law 21.719 provides that data relating to criminal, civil, administrative and disciplinary infringements may only be processed by public bodies for the fulfilment of their legal functions, within the scope of their powers and in the cases expressly provided for by law. Private background-screening practices must be reviewed case by case with legal advice; this article is not a substitute for that analysis.

When do these assignment rules start to apply in Chile?

Law 21.719 was published in the Official Gazette on 13 December 2024 and takes effect on 1 December 2026, under its first transitional article. As of July 2026 the regime of article 15 is not yet in force, but the assignment agreements you sign today will remain in effect when the Personal Data Protection Agency begins to exercise its functions.

Does legitimate interest allow me to assign data for a third party's marketing?

Not automatically. A legitimate interest of the assignor or the assignee enables the assignment under the terms of letter d) of article 13 of Law 21.719, which requires a documented analysis of the interest invoked, of the necessity of the assignment, and of the data subject's rights and expectations. In addition, the data subject retains the rights set out in articles 10 and 11, including the right to object.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Contracts

DPAs with processors under Law 21.719

Lawful bases

Lawful bases and consent: when you need it

Law 21.719

Law 21.719: the definitive guide to comply and avoid fines

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment