Model contractual clauses are a standard contract text approved in Chile by the Undersecretariat of Economy through exempt resolution RAEX202503748, published in the Official Gazette on December 19, 2025, which companies add to their contracts to transfer personal data abroad with documented safeguards under Law 21.719.
The essentials in 30 seconds
- Exempt resolution RAEX202503748 of the Undersecretariat of Economy and Smaller Enterprises, published in the Official Gazette on December 19, 2025.
- They were drafted on the basis of the model contractual clauses of the Ibero-American Data Protection Network (RIPD).
- Law 21.719 takes effect on December 1, 2026: as of July 2026, that leaves a little over four months to get contracts signed.
- They work alongside the processing agreement under article 15 bis, but they neither replace it nor cover the rest of the law's duties.
If your company uses a CRM hosted in the United States, a European mailing platform, a cloud provider with servers outside the country, or shares customer databases with its parent company, it is already carrying out international transfers of personal data. For years that happened without a specific Chilean instrument to back it up. If you want the full picture, start with our guide to the data protection law in Chile.
That changed in December 2025. The Undersecretariat of Economy and Smaller Enterprises approved the Model Contractual Clauses applicable to international transfers of personal data through exempt resolution RAEX202503748, published in the Official Gazette on December 19, 2025. It is a standard contract text, available for more than six months now, that any company can incorporate into its contracts.
The interesting part is the timing: Law 21.719 takes effect on December 1, 2026, yet this instrument already exists. In a landscape where much of the detail depends on regulations and guidance that have not yet been issued, the model contractual clauses are one of the few genuinely actionable pieces available today.
What are the model contractual clauses approved in Chile?
They are a standard contract, drafted and approved by the authority, that two parties sign when one sends personal data from Chile abroad. Instead of negotiating safeguard by safeguard with every provider, you adopt a text that has already been validated and add the annexes describing your specific case.
The instrument was approved by the Undersecretariat of Economy and Smaller Enterprises through exempt resolution RAEX202503748, published in the Official Gazette on December 19, 2025. It was not written from scratch: it was built on the model contractual clauses of the Ibero-American Data Protection Network (RIPD), the same reference other authorities in the region have used. That matters because it makes the conversation easier with multinational providers that already know equivalent frameworks.
The underlying logic is simple and worth understanding before you sign anything: when data leaves Chile, it also becomes subject to the law of the receiving country, and the controller's practical control becomes harder to exercise. The contract is the vehicle that makes the obligations travel with the data. If the foreign provider commits contractually to processing the information only for the agreed purposes, to maintaining confidentiality, to applying security measures and to cooperating when a Chilean data subject exercises their rights, protection does not dissolve at the border.
One note of caution: this text does not describe, clause by clause, a closed set of content you can take for granted. Before signing, review the official text published in the Official Gazette and work through it with your legal counsel, because every operation requires completing different annexes.
- What they are: a standard contract text approved by the Chilean authority and made available to companies.
- Where they come from: the model of the Ibero-American Data Protection Network (RIPD).
- When they were approved: exempt resolution RAEX202503748, Official Gazette of December 19, 2025.
- What they are for: documenting safeguards in international transfers of personal data from Chile.
Why were they issued before Law 21.719 takes effect?
To provide legal certainty and avoid automatic non-compliance. Law 21.719 takes effect on December 1, 2026 and creates the Personal Data Protection Agency (articles 30 and following), but that institutional framework is still being built: a later reform brought forward its installation.
The concrete risk was this: December 2026 arrives, the law starts to apply, and the Agency has still not issued the specific rules that enable cross-border flows. Many Chilean companies that send data abroad every day — payroll, customers, support tickets, marketing campaigns — would have been left without a formal mechanism to back perfectly legitimate operations. Issuing a standard contract ahead of time is meant to avoid that gap.
There is a second, more practical reason: renegotiating contracts takes time. A data protection annex with a global cloud provider is not signed in a week; it goes through their legal teams, internal reviews and sometimes a parent company in another time zone. Having the text available since December 2025 gives your company close to twelve months to do that work calmly rather than at the last minute.
- Provide legal certainty to companies while the specific rules do not yet exist.
- Prevent Law 21.719 taking effect from triggering automatic non-compliance in flows that are already running.
- Allow real time for contract negotiation with providers and parent companies before December 1, 2026.
In which concrete situations are these clauses useful?
They are useful whenever personal data of people in Chile leaves the country, regardless of the size of the flow or whether the destination is an independent third party or a company in the same group. The most frequent scenarios are the cloud provider, the CRM or mailing platform, the parent company abroad, regional subsidiaries and remote technical support.
Before choosing the role each party will sign under, you have to settle a prior question: who decides the purposes and the means of the processing? Whoever decides is the controller; whoever merely follows instructions on behalf of another is the processor, in line with article 15 bis of Law 21.719. That assessment defines everything else and is where most mistakes are made, especially in corporate groups where the parent company sometimes gives the orders and sometimes only provides a shared service.
| Scenario | Who is usually the controller | Who is usually the processor | What to review before signing |
|---|---|---|---|
| Cloud provider (hosting, storage, backups) | Your company in Chile | The foreign provider | Location of the data centers, authorized sub-processors, security measures and the breach notification protocol |
| CRM or mailing platform (SaaS) | Your company in Chile | The SaaS provider | Permitted purposes, use of data to train models or improve the product, retention periods and return or deletion at the end of the contract |
| Parent company abroad that sets global policies | It may be a controller together with the Chilean subsidiary | Depends on the case: it is not always a processor | Who really decides the purposes, what data is consolidated globally and on what lawful basis it is shared |
| Subsidiary or related company in another country | Each entity for its own processing | The one that only follows the other's instructions | That a real written contract exists and not just membership in the same group; intra-group policies and access traceability |
| Remote technical support or help desk with access to databases | Your company in Chile | The foreign support provider | Scope of access, profiles and credentials, session logging, the duty of secrecy under article 14 bis and the prohibition on copying data |
How are they implemented in practice, step by step?
The process does not start as a legal exercise; it starts as an inventory. You cannot protect a flow you do not know exists, and experience shows that almost every company underestimates how many international transfers it actually has running. The work sequence is as follows.
A piece of field advice: start with your critical providers, not with the full list. Five well-drafted contracts with the parties that concentrate the largest volume and the most sensitive data are worth more than forty generic annexes signed in a rush. And if you work with sensitive data under article 16 — health, socioeconomic status, or biometric data regulated by article 16 ter — that is your mandatory starting point.
- 1. Identify your transfers using the record of processing activities: what data leaves, where it goes, for what purpose and for how long.
- 2. Map providers and group entities, including the sub-processors your provider hires in turn.
- 3. Define each party's role: controller, processor, or two independent controllers. This determines which version of the clauses applies.
- 4. Incorporate them into the contract, either as clauses within the main agreement or as a signed annex incorporated by reference.
- 5. Complete the descriptive annexes: categories of data and of data subjects, purposes, retention periods and technical and organizational measures.
- 6. Keep evidence: the signed contract with its date, the version of the text adopted, negotiation emails and the internal analysis that justified the role assigned.
- 7. Schedule a periodic review and include an update clause, so you can adapt to whatever the Agency instructs after December 1, 2026.
How do they relate to the processor under article 15 bis?
They are two different layers that almost always live in the same document. Article 15 bis of Law 21.719 governs processing carried out through a third-party agent or processor, that is, whoever processes data on behalf of the controller following its instructions. That relationship must be governed by contract, whether it happens inside Chile or across the border.
The model contractual clauses, by contrast, deal specifically with the international element of the flow. If your payroll provider is in Santiago, you need the article 15 bis processing agreement but not the transfer clauses. If that same provider processes from Bogotá, you need both: the processing agreement and the cross-border safeguard. In practice they are signed together, in a single data protection annex.
It is worth remembering that the processing agreement does not release the controller from its own duties. The duty of secrecy or confidentiality under article 14 bis, the duty of information and transparency under article 14 ter, the duty of protection by design and by default under article 14 quater, the security measures under article 14 quinquies and the notification of breaches to the Agency under article 14 sexies remain yours. On that last point, it helps to be clear about the Chilean standard: article 14 sexies requires reporting to the Agency by the fastest means available and without undue delay whenever there is a reasonable risk to the rights and freedoms of data subjects, and also notifying the data subjects themselves when the case involves sensitive data, data of children under fourteen, or economic, financial, banking or commercial obligations. The foreign provider helps you comply; it does not take on those duties in your place.
That is why the annex must include concrete operational commitments: that the processor notifies you immediately of any breach, that it hands over the information you need to build the record required by article 14 sexies, and that it cooperates when a data subject exercises their rights before you.
- Article 15 bis: governs the controller-processor relationship, with or without an international transfer.
- Model contractual clauses: cover the fact that the data leaves Chile.
- With a foreign provider that processes on your behalf, you need both layers in the same annex.
- Neither of them shifts to the provider your duties under articles 14 bis, 14 ter, 14 quater, 14 quinquies and 14 sexies.
What do the model contractual clauses NOT solve?
They do not turn unlawful processing into lawful processing. If you have no lawful basis to process that data in Chile — consent under article 12 or another of the grounds in article 13 — signing transfer clauses does not fix the underlying problem: it only documents how data moves that you may not be entitled to process at all. The correct order is lawfulness first, transfer second.
They also do not cover the rest of compliance. The rights under article 10 — access, rectification, erasure, objection and portability — must be answered within thirty calendar days under article 11, extendable only once for up to another thirty calendar days, and that deadline runs for you even if the data sits on a server in Ireland. The law also requires you to keep records proving that the response was sent, its date and its full content. The same applies to the impact assessment under article 15 ter, to the record of activities and to security measures. A signed annex is not a compliance program.
It is also worth clarifying what is not an alternative. Law 21.719 does not require third-party technical security certifications; the only certification it contemplates is that of the infringement prevention model before the Agency (article 51), which is voluntary and connects to the National Registry of Sanctions and Compliance under article 39. Your provider displaying international certificates is good evidence of diligence, not a substitute for contractual safeguards.
And it has to be said honestly: there is public legal debate about the scope of these clauses and about the Undersecretariat of Economy's authority to approve them before the Agency is fully operational. There are well-founded opinions on both sides and this is not the place to settle the matter. The reasonable stance in the meantime is a pragmatic one: use them as a layer of documented safeguards and not as a certification of compliance, keeping the contract open to adjustments once the authority sets its definitive criteria.
- They do not replace the lawful basis for processing the data (articles 12 and 13).
- They do not cover responding to the rights under article 10, whose deadline is 30 calendar days under article 11, extendable only once.
- They do not replace the impact assessment under article 15 ter where it applies.
- They are not equivalent to the certification of the prevention model before the Agency (article 51), which is voluntary.
- On their own, they do not guarantee that the Agency will validate your compliance in an inspection.
- They do not shield you from the penalties under article 35 if the non-compliance lies elsewhere in the process.
Do you need to put your international transfers in order before December 2026?
At AlayIAtrust we help legal, compliance and IT teams map their cross-border flows, define each party's role and incorporate the model contractual clauses into their existing contracts. Let's talk about your specific case.
Schedule an assessmentFrequently asked questions
Since when have the model contractual clauses been available in Chile?
They have been available since December 2025. The Undersecretariat of Economy approved them through exempt resolution RAEX202503748, published in the Official Gazette on December 19, 2025. You can incorporate them into your contracts today, even though Law 21.719 only takes effect on December 1, 2026.
Is it mandatory to use the model contractual clauses?
The clauses were made available to companies to give legal certainty to their international transfers, not as an imposed form. Their practical value is that they let you document safeguards today, without waiting for the Personal Data Protection Agency to issue its own rules on cross-border flows in Chile.
Do they work for transferring data to the United States, the European Union or any country?
They are designed for transfers from Chile to any destination, regardless of the level of protection in the receiving country: the safeguard travels inside the contract. Even so, the definitive regime for international data transfers will depend on what the Personal Data Protection Agency specifies once the law takes effect.
Can I sign them now if Law 21.719 is not yet in force?
Yes, and it is the most advisable course. Signing now avoids renegotiating against the clock in late 2026. Since Law 21.719 takes effect on December 1, 2026, the contracts you sign this year can be aligned from day one, with no last-minute changes.
What do I do if my cloud provider refuses to sign them?
Keep a written record of the attempt and assess alternatives: the provider's own data protection annex or its standard clauses, together with a documented risk assessment. Its technical security certifications are not required by Law 21.719 and are not equivalent to compliance, but evidence of the analysis is always better than silence.
Do they replace the contract with the processor under article 15 bis?
No. Article 15 bis of Law 21.719 governs the processing that a third-party agent or processor carries out on behalf of the controller, whether or not there is an international transfer. The model clauses cover the cross-border flow; it is best to integrate them with the processing agreement rather than use them as a replacement for it.
Can the clauses be modified or negotiated?
Their practical strength lies in using them without altering the core text. You can add annexes describing the operations, the categories of data, the retention periods and the security measures, along with your commercial clauses. If you contradict the approved text, you lose much of the legal certainty argument.
What evidence should I keep for each transfer?
Keep the signed contract or annex with a certain date, the record of processing activities showing the transfer, the analysis of each party's role, the security measures agreed and the traceability of communications. In an inspection in Chile, a well-organized file is worth more than good intentions.
Do they apply when I send data to my parent company abroad?
Yes. An intra-group flow is an international transfer like any other: belonging to the same holding does not exempt it. The first step is to define who decides the purposes and the means of the processing and who merely follows instructions, because that determines the role each entity will sign under in the clauses.
What will happen when the Agency issues its own rules?
It is reasonable to expect the Personal Data Protection Agency to specify the regime for international data transfers once it is up and running. That is why it is worth including a review clause that lets you update annexes and adhere to the instruments the authority recognizes, without renegotiating the entire contract from scratch.
Official sources
- Law 21.719 on the protection and processing of personal data — official text, Library of the National Congress of Chile
- Ministry of Economy, Development and Tourism — Undersecretariat of Economy and Smaller Enterprises
This article is for information purposes only and does not constitute legal advice for a specific case.