Law 21.719 fines in Chile are not calculated with a formula: the Personal Data Protection Agency sets a ceiling based on severity — 5,000, 10,000 or 20,000 UTM — and then determines the amount by prudently applying the eight criteria of article 37 and the mitigating and aggravating circumstances of article 36. The cap is a maximum, not a floor.
The essentials in 30 seconds
- The caps in article 35: up to 5,000 UTM (minor), 10,000 UTM (serious) and 20,000 UTM (very serious).
- The Agency applies the eight criteria of article 37 prudently, not through an arithmetic formula.
- A prevention model certified under article 51 is an express mitigating circumstance under article 36.
- The fine is paid at the General Treasury of the Republic within ten business days from the date the decision becomes final.
The figure that circulates in almost all available content is the same one: up to 20,000 UTM. It is accurate, but it is only the ceiling. The question a board or a finance department actually asks is a different one: what determines whether you end up near that maximum or at a fraction of it, and how much of that difference is in the company's hands. If you want the full picture, start with our guide to the data protection law in Chile.
Law 21.719 answers that question in a specific provision, article 37, which lists eight criteria for determining the amount and requires the Personal Data Protection Agency to apply them prudently. Added to that are the mitigating and aggravating circumstances of article 36, the concurrence rules that apply when there are several infringements, and a surcharge that depends solely on how the company reacts afterwards.
This article works through the eight criteria one by one, separates those that are locked in by the facts from those that depend on the subsequent response, and clarifies two points where available content often gets it wrong: when the 2% or 4% of revenue threshold is reached, and what recidivism actually means.
How is a Law 21.719 fine calculated, and why is the cap not the amount?
A Law 21.719 fine is calculated in two moves. First, the Personal Data Protection Agency classifies the infringement according to its severity, and that sets a ceiling. Second, within that range it determines the specific amount by applying the eight criteria of article 37. The ceiling is not the price: it is the upper limit of a range whose lower end the law does not predetermine.
The word that governs the entire Chilean regime is "up to". Article 35 of Law 21.719 does not say that a very serious infringement is sanctioned with 20,000 UTM; it says it is sanctioned with a fine of up to 20,000 UTM. That distinction is what separates an alarmist reading from a risk assessment that can actually be used in a board committee. Two companies sanctioned for the same conduct can end up with different amounts, and the difference must be substantiated in the decision.
The severity classification is not discretionary either. Article 34 of Law 21.719 classifies infringements as minor, serious and very serious, and articles 34 bis, 34 ter and 34 quater contain the catalogs of conduct for each category. Processing personal data without the data subject's consent or without a legal basis or grounds making the processing lawful is serious; breaching the duty of secrecy or confidentiality over sensitive personal data is very serious; failing to respond, or responding incompletely or late, to a data subject request is minor. Two nuances are worth noting: the catalog of minor infringements closes with a residual clause — any other infringement of the rights and obligations under the law that is not classified as serious or very serious — and a late or unjustifiably denied response to well-founded requests for temporary blocking is classified as serious. The conduct defines the bracket, and the bracket defines the ceiling.
- Minor infringement (article 34 bis): written warning or fine of up to 5,000 UTM.
- Serious infringement (article 34 ter): fine of up to 10,000 UTM.
- Very serious infringement (article 34 quater): fine of up to 20,000 UTM.
What are the eight criteria of article 37, and which ones can your company influence?
Article 37 of Law 21.719 requires the Agency to prudently apply eight criteria to determine the amount: the severity of the conduct; whether the conduct was carried out with a lack of diligence or care, in cases where those elements are not already part of how the infringement is defined; the harm caused — particularly the number of affected data subjects; the economic benefit obtained, if any; whether the processing involves sensitive personal data or data of children and adolescents; the economic capacity of the offender; sanctions previously applied by the Agency in the same circumstances; and any mitigating and aggravating circumstances present.
The word "prudently" is not decorative. It means the Agency weighs the eight criteria as a whole and gives reasons for its decision, not that it adds them up using predefined weights. The law contains no arithmetic formula, no scoring table and no value per affected data subject: any estimate presented as an exact figure is over-reading the text. What you can anticipate is the direction in which each criterion pushes, and which of them remain open after an incident.
That is the useful distinction for a management team. Four criteria are captured by the facts as they stand: the number of affected data subjects, the economic benefit obtained, the nature of the data involved and your economic capacity. None of them can be negotiated the day after. The other four — prior diligence, the mitigating circumstances you can activate, your sanctions history and, in part, the severity classification of the conduct — depend on decisions your company makes before and after the incident.
The practical reading is that mitigation work happens in two distinct and non-interchangeable windows. The pre-incident window closes on its own: data governance, an inventory of processing activities, minimization, access control and, above all, a certified prevention model. The post-incident window opens with the incident and closes quickly: self-reporting, cessation and mitigation measures, redress for data subjects, and cooperation with the administrative investigation.
| Criterion (article 37) | What it means in practice | Can your company influence it? |
|---|---|---|
| 1. Severity of the conduct | Places the infringement within the catalog in articles 34 bis, 34 ter or 34 quater and sets the applicable ceiling. | Before: yes. How processing is designed affects which catalog the conduct falls under. After: no. |
| 2. Lack of diligence or care | Assesses negligence, in cases where that element is not already part of how the infringement is defined. | Before: yes. Evidence of controls and supervision is built in advance, not improvised. |
| 3. Harm caused, particularly the number of affected data subjects | Measures the actual damage and its reach: how many people were exposed and with what consequences. | Before: yes, through minimization and segmentation of databases. After: the number cannot be changed. |
| 4. Economic benefit obtained from the infringement | Considers whether the company obtained a gain attributable to the unlawful processing, if any. | No, once it has occurred. It is a fact established during the proceedings; the only option is not to monetize processing that lacks a lawful basis. |
| 5. Sensitive data or data of children and adolescents | Weighs on the amount when the processing involves those specially protected categories. | Before: yes, by deciding which categories of data you collect and retain. After: no. |
| 6. Economic capacity of the offender | Allows the amount to be adjusted to the sanctioned party's economic reality. | No. It is an objective fact about the company, not a variable in incident management. |
| 7. Sanctions previously applied by the Agency in the same circumstances | Seeks consistency with the standard the Agency has already set in comparable cases. | Indirectly. The public registry under article 39 makes it possible to know that standard and anticipate it. |
| 8. Mitigating and aggravating circumstances present | Brings the five mitigating circumstances and the aggravating circumstances of article 36 into the determination of the amount. | Yes, in both windows: certification comes beforehand; self-reporting, redress and cooperation come afterwards. |
Which mitigating and aggravating circumstances under article 36 really move the needle?
Article 36 of Law 21.719 recognizes five mitigating circumstances: unilateral redress actions and settlement agreements with affected data subjects; the cooperation the offender provides in the Agency's administrative investigation; the absence of prior sanctions; self-reporting to the Agency, communicating alongside it the cessation or mitigation measures adopted; and having diligently complied with management and supervision duties.
The fifth mitigating circumstance is the most relevant from a corporate governance standpoint and the least discussed. Article 36 specifies that diligent compliance with management and supervision duties is evidenced by the certificate issued under article 51, that is, by a certified and current infringement prevention model. It is the only mitigating circumstance that cannot be improvised: it requires a decision made in advance and sustained over time.
The other four mitigating circumstances are activated in the post-incident window. The law does not set a deadline for self-reporting, but by definition it means reporting the infringement on your own initiative and, in addition, communicating alongside it the cessation or mitigation measures adopted. Redress carries weight to the extent that it is real and verifiable for the affected data subjects. Cooperation is not graded in the statutory text, so the sensible approach is to document it: what information was provided, when, and how useful it was to the investigation.
On the aggravating side, article 36 defines recidivism as the situation of a controller that has been sanctioned on two or more occasions in the last thirty months for infringing this law. One point where available content often gets confused is worth clarifying: repeat serious infringements do not turn the conduct into a very serious one. The catalog in article 34 quater does not contemplate recidivism. The conduct remains classified as serious, with its 10,000 UTM cap, and recidivism operates on that basis by triggering the multipliers in article 35, not by reclassifying the infringement.
- Mitigating circumstances you can build before the incident: a prevention model certified under article 51 and the absence of prior sanctions.
- Mitigating circumstances you can build after the incident: self-reporting together with the cessation or mitigation measures adopted, redress for data subjects, and cooperation in the administrative investigation.
- Main aggravating circumstance: recidivism, understood as having been sanctioned on two or more occasions in the last thirty months.
What happens if a single course of conduct gives rise to several infringements?
A single fine is imposed. Article 37 of Law 21.719 establishes two concurrence rules: if one course of conduct gives rise to two or more infringements, or if one infringement is the means to commit another, a single fine applies, considering the sanction for the most serious infringement. Only where two or more infringing courses of conduct that are independent of one another are established do the sanctions for each accumulate.
The difference between the two scenarios is economically significant and is often overlooked in exposure-sizing exercises. Processing without a lawful basis that also leads to an improper disclosure and a late response to the data subject does not amount to three stacked fines if it all stems from the same course of conduct, or if some infringements were the means to another: the law requires considering the sanction for the most serious one and imposing a single fine.
The practical consequence for exposure analysis is that the correct exercise is not to count how many formal compliance failures your company has and multiply them by the cap. It is to identify how many genuinely independent infringing courses of conduct exist in your operation: different processing activities, with different purposes, at different times. That number, and not the list of findings from an audit, is what determines whether accumulation applies.
That said, the independence of each course of conduct is assessed case by case in the administrative proceedings, and there is as yet no Agency practice that would allow you to anticipate where that line will be drawn. A company with separate business lines that replicates the same consent defect in each of them is more exposed to accumulation than one where the defect stems from a single poorly made central decision. Documenting the traceability of processing decisions helps support the single-conduct argument where it applies.
When does the fine triple or reach 2% or 4% of revenue?
Only through recidivism, and the percentage-of-revenue threshold requires a second condition as well. Article 35 of Law 21.719 allows the Agency to apply a fine of up to three times the amount where the recidivism referred to in letter a) of article 36 is present. And if the offender is not a smaller-sized enterprise under Law 20.416 and also engages in recidivism involving a serious or very serious infringement, the fine may reach the more burdensome of triple the amount or 2% of annual revenue from sales and services in the last calendar year in the case of serious infringements, and 4% in the case of very serious ones.
This is where precision matters, because there is a widespread notion that any very serious infringement exposes the company to 4% of its revenue. That is not the case in Chile. The two conditions in article 35 are cumulative: the offender must not be a smaller-sized enterprise and must, in addition, engage in recidivism involving a serious or very serious infringement. A first sanction, however serious, stays within the 20,000 UTM cap, without prejudice to the surcharge that article 35 itself provides for if remedial measures are not adopted.
That surcharge does not depend on the original infringement but on what happens afterwards. Together with the sanction, the Agency specifies the measures the offender must adopt to remedy the infringement, within a period of no more than 60 days; if they are not adopted, article 35 provides for a 50% surcharge on the fine. It is the portion of the amount that is easiest to avoid and the one that says the most about the organization's real commitment.
For smaller-sized enterprises there is a narrow transitional rule. The sixth transitional article of Law 21.719 provides that, during the first twelve months from entry into force, where a sanction would apply to smaller-sized enterprises under Law 20.416, the Agency may apply a written warning. It is a power of the Agency, not automatic immunity or a permanent regime, and the warning is still recorded in the registry under article 39.
- Recidivism multiplier: up to three times the amount of the fine (article 35).
- Percentage of revenue: 2% (serious) or 4% (very serious), only if you are not a smaller-sized enterprise under Law 20.416 and you also engage in recidivism involving a serious or very serious infringement.
- 50% surcharge: if you fail to adopt, within a period of no more than 60 days, the remedial measures specified by the Agency.
- Transitional regime for smaller enterprises: a written warning is possible during the first twelve months of entry into force, as a power of the Agency.
When is the fine paid, and what other consequences does the sanction carry?
Fines under Law 21.719 are paid at the General Treasury of the Republic within a period of ten business days from the date the Agency's decision becomes final, under article 37. The proof of payment is then submitted to the Agency within ten business days from the date payment was made. For the decision to be final, the available challenges must have been exhausted or not pursued, including the judicial claim before the Court of Appeals governed by article 43.
The fine is not always the only consequence. Article 38 of Law 21.719 allows the Agency to order the suspension of the data processing operations and activities carried out by the controller, for up to thirty days, where fines are imposed for repeated very serious infringements within a twenty-four-month period. The suspension may be partial or total, does not affect the storage of the data, cannot be ordered where doing so would affect data subjects' rights and, if the controller fails to comply with what has been ordered, may be extended for successive periods of up to thirty days. Where the suspension affects an entity subject to the supervision of a public oversight body, the Agency must first bring the background information to that authority's attention. It is worth noting that article 38 contemplates suspension of processing solely as an ancillary sanction: it does not establish processing bans for a set period or publication of the sanctioning decision as additional sanctions.
Public visibility comes through a different route. Article 39 of Law 21.719 creates the National Registry of Sanctions and Compliance, public, free and electronic, administered by the Agency, which lists sanctioned controllers, distinguishing the severity of the infringement, the conduct infringed, the mitigating and aggravating circumstances, and the sanction imposed. Entries are publicly accessible for five years from the date the entry was made. The same registry lists those that adopt current certified prevention models, so the article 51 certificate has a reputational effect in addition to being a mitigating circumstance.
Finally, the administrative sanction does not close off exposure. Article 47 of Law 21.719 requires the controller to compensate both pecuniary and non-pecuniary damage; the action is brought once the Agency's favorable decision is enforceable or the judgment is final, and it is processed under the summary procedure in articles 680 et seq. of the Code of Civil Procedure. On timing, article 40 sets a four-year statute of limitations for actions to pursue infringement liability — counted from the occurrence of the act, or from the date the infringement ceased if it is a continuing infringement, and interrupted by notice of the start of administrative proceedings — and a three-year statute of limitations for the sanctions imposed. Civil actions under article 47, by contrast, are time-barred after five years counted from the date the decision or judgment imposing the fine becomes enforceable.
Size up your exposure before December 1, 2026
At AlayIAtrust we work with management teams, finance departments and boards to translate the sanctions regime of Law 21.719 into a realistic exposure figure and a prioritized mitigation plan. If you want to review your specific case, let's talk.
Schedule an assessmentFrequently asked questions
What is the maximum amount of a fine under Law 21.719 in Chile?
Article 35 of Law 21.719 sets caps by severity: minor infringements are sanctioned with a written warning or a fine of up to 5,000 UTM, serious infringements with a fine of up to 10,000 UTM and very serious infringements with a fine of up to 20,000 UTM. These are maximums, not automatic amounts.
Does the Agency apply a mathematical formula to calculate the fine?
No. Article 37 of Law 21.719 requires the Agency to apply eight criteria prudently, which means weighing them together and giving reasons for the outcome. The law contains no scoring table and no predefined value per affected data subject in the Chilean data protection regime.
Which criteria under article 37 can I no longer change once the incident occurs?
The harm caused and the number of affected data subjects, the economic benefit obtained, the presence of sensitive data or data of children and adolescents, and your economic capacity are fixed by the facts. Law 21.719 assesses them as they stand at the time of the infringement.
Does having a certified prevention model reduce the fine?
It is a mitigating circumstance. Article 36 of Law 21.719 recognizes as a mitigating circumstance having diligently complied with management and supervision duties, which is evidenced by the certificate issued under article 51. It is the only mitigating circumstance you can build before any incident occurs in Chile.
When can the fine reach 2% or 4% of revenue?
Only when two conditions apply at the same time: that the offender is not a smaller-sized enterprise under Law 20.416 and that it also engages in recidivism involving a serious or very serious infringement. In that case Law 21.719 allows the more burdensome figure to be applied, between triple the amount or 2% (serious) and 4% (very serious) of annual revenue from sales and services in the last calendar year.
What happens if a single course of conduct gives rise to several infringements?
Article 37 of Law 21.719 provides that if one course of conduct gives rise to two or more infringements, or if one infringement is the means to commit another, a single fine is imposed considering the sanction for the most serious infringement. Only infringing courses of conduct that are independent of one another accumulate sanctions.
What is the 50% surcharge in article 35?
Together with the sanction, the Agency specifies the measures needed to remedy the infringement, which must be adopted within a period of no more than 60 days. If the offender does not adopt them, Law 21.719 provides for a 50% surcharge on the fine. It is the portion of the amount that depends entirely on your subsequent conduct.
When and where is a Law 21.719 fine paid?
Fines are paid at the General Treasury of the Republic within ten business days from the date the Agency's decision becomes final. The proof of payment is then submitted to the Agency within ten business days from the date payment was made.
Does recidivism in serious infringements turn the conduct into a very serious one?
No. The catalog of very serious infringements in article 34 quater of Law 21.719 does not include recidivism. Recidivism is an aggravating circumstance under article 36, which exists when the controller has been sanctioned on two or more occasions in the last thirty months for infringing this law, and it triggers the multipliers in article 35.
Are smaller-sized enterprises exempt from fines?
They are not exempt. The sixth transitional article of Law 21.719 allows the Agency, during the first twelve months from entry into force, to apply a written warning where a sanction would apply to smaller-sized enterprises under Law 20.416. It is a power of the Agency, and the warning is still recorded under article 39.
Official sources
This article is for information purposes only and does not constitute legal advice for a specific case.