← Back to blog

Criminal records and personal data in Chile: what article 25 of Law 21.719 requires of background checks

Asking every applicant for a criminal record certificate is a deeply ingrained habit in the Chilean market. Article 25 of Law 21.719 puts it under strain: it reserves the processing of data on criminal, civil, administrative and disciplinary offences for public bodies, in the cases expressly provided by law. Here we review the framework for criminal records as personal data in Chile, the publication periods, the prohibition on bulk processing, and what your company can do before 1 December 2026.

GUIDE · LAW 21.719
Short answer

A private company in Chile has no general authorization to process data on criminal offences: article 25 of Law 21.719 reserves that processing for public bodies, in the cases expressly provided by law. Requesting a certificate from every applicant therefore requires checking whether a specific rule authorizes it.

The essentials in 30 seconds

  • Article 25: data on criminal, civil, administrative and disciplinary offences may only be processed by public bodies, to carry out their statutory functions and in the cases expressly provided by law.
  • Five years: the public-access period for civil, administrative and disciplinary offences when the law orders their publication without setting a period.
  • Bulk processing of the electronic offence registries kept by public bodies is prohibited; breaching that prohibition constitutes an infringement.
  • 1 December 2026: Law 21.719 enters into force, with fines of up to 20,000 UTM for the most serious infringements (article 35).

Some HR practices go unquestioned simply because they have worked for decades. Asking every applicant for a criminal record certificate, reviewing it before the offer and then filing it in the employee's folder is one of them. In most Chilean companies it is just another administrative step, as routine as asking for a CV or a degree certificate. If you want the full picture, start with our guide to the data protection law in Chile.

Article 25 of Law 21.719 forces a fresh look at that routine. The rule does not govern the paperwork: it governs the data. And it provides that data relating to criminal, civil, administrative and disciplinary offences may only be processed by public bodies, to carry out their statutory functions, within the scope of their powers and in the cases expressly provided by law. It is a rule about who may process the data, not a mere formality.

This article explains what that rule says, how the publication periods work by type of offence, why the law prohibits the bulk processing of electronic offence registries, and what your company can review before 1 December 2026, the date the law enters into force. It is not an opinion on a specific case: it is the framework HR, legal and compliance need to have a conversation with the facts on the table, and then validate their situation with professional advice.

Can a company request an applicant's criminal record certificate in Chile?

Law 21.719 does not give private companies a general authorization to process data on criminal offences. Article 25 reserves that processing for public bodies, to carry out their statutory functions, within the scope of their powers and in the cases expressly provided by law. That is the starting point for any analysis.

Two things that are often confused are worth separating. The fact that the data subject can obtain their own certificate and choose to show it does not, in itself, make the company receiving it a party authorized to process that data. The law does not govern the paperwork behind the document; it governs the operations: collecting, assessing, storing, disclosing, retaining. Each of them is processing, and each needs a basis.

That is where the tension with common market practice lies. Background checks have been built on a habit — it has always been done — rather than on a rule authorizing it for the company's activity. The most reasonable reading of article 25 suggests that the basis must be found in a legal authorization, not in an industry habit, a consent form or a clause in the employment contract.

This does not mean no company may ever verify a background. There are activities governed by sector-specific rules that require or authorize doing so for certain positions or functions, and article 25 itself permits processing in the cases expressly provided by law. The honest conclusion is that the answer depends on your activity and on the specific role, and that this analysis should be carried out case by case with legal advice before December 2026, not improvised in the middle of a selection process.

  • Is there a legal rule applicable to your activity or to that specific role that requires or authorizes knowing an applicant's background?
  • What exact operation are you carrying out: do you only verify and discard, or do you also store and retain the document?
  • Can you explain the decision to the Agency on a legal basis, or only by reference to market custom?

What exactly does article 25 say about offence data?

Article 25 of Law 21.719 does five things at once, and usually only the first is quoted. Beyond reserving the processing of this data for public bodies, it sets a data-quality duty for disclosures, a time limit on disclosing them, a duty of secrecy for those working in the public sector, and an express prohibition on bulk processing. It is also worth noting that this data does not fall within the catalogue of sensitive data in article 16 and following: it has its own, distinct rule.

The quality duty is demanding. In their disclosures, public bodies must ensure that the information disclosed or made public is accurate, sufficient, up to date and complete. All four conditions are cumulative: data that is correct but out of date, or up to date but incomplete, does not meet the standard. When it comes to offences, a partial disclosure can be as damaging as an inaccurate one.

The time limit is the rule that most surprises HR teams in Chile. Article 25 provides that this data may not be disclosed or made public once the relevant action is time-barred under the statute of limitations, or once the penalty or sanction imposed has been served or has become time-barred, which must be declared or verified by the competent public authority. In other words, there is a point beyond which the data can no longer circulate, and that point depends on an official declaration or verification, not on the judgement of whoever is consulting.

All of the above applies without prejudice to the entry, maintenance and consultation of this information in the registries kept by public bodies under express provision of law, in the manner and for the period set out in that law. And those working in public bodies are required to keep this information secret; it must be kept as restricted information. For a company, the practical reading is a cautious one: if public officials themselves are bound by secrecy, it is hard to argue that the same data can circulate freely in a corporate file.

  • Who may process it: only public bodies, to carry out their statutory functions, within the scope of their powers and in the cases provided by law.
  • Quality: information disclosed or made public must be accurate, sufficient, up to date and complete.
  • Expiry: it may not be disclosed or made public once the action is time-barred or the penalty or sanction has been served or become time-barred, following a declaration or verification by the competent authority.
  • Secrecy: those working in public bodies must keep secrecy; the information is restricted.
  • Prohibition: bulk processing of the data contained in the electronic offence registries is not permitted.

How long does this data stay public, depending on the type of offence?

Where the law provides that this information must be made public through a sanctions registry or a publication on a website, without setting a period, article 25 of Law 21.719 fills the gap with two rules. For criminal offences, the publication periods are governed by the specific rules applicable to that type of offence. For civil, administrative and disciplinary offences, the information remains accessible to the public for a period of five years.

The distinction matters for two different audiences. For HR, because it marks how long a sanction record can legitimately keep circulating from the official source. For compliance, because a sanction against the company itself has a defined and limited window of public visibility, which makes it possible to plan communications rather than improvise them.

One detail that is often overlooked: the public accessibility of a registry does not authorize building a private copy of it. The fact that data can be consulted for five years means it can be consulted, not that it can be extracted, accumulated and reused for another purpose. That difference is exactly what the prohibition on bulk processing protects.

Rules under article 25 of Law 21.719 by type of offence: who may process it, how long it stays public, and what is prohibited
Type of offenceWho may process it (art. 25)How long it stays publicWhat is prohibited
CriminalOnly public bodies, to carry out their statutory functions, within the scope of their powers and in the cases expressly provided by lawWhere the law orders publication without setting a period, the periods are governed by the specific rules applicable to this type of offenceDisclosing it or making it public once the action is time-barred, or once the penalty has been served or become time-barred, following a declaration or verification by the competent authority
CivilOnly public bodies, on the same terms as article 25Five years of public access, where the law orders publication without setting a periodDisclosing it or making it public after the action becomes time-barred or the sanction has been served or become time-barred, with a prior declaration or verification by the authority
AdministrativeOnly public bodies, on the same terms as article 25Five years of public access, where the law orders publication without setting a periodCirculating it beyond that period, or after the sanction has been served or become time-barred, as declared or verified by the competent authority
DisciplinaryOnly public bodies, on the same terms as article 25Five years of public access, where the law orders publication without setting a periodDisclosing it outside that period or after the sanction has been served or become time-barred, following a declaration or verification by the authority
Electronic offence registries (all four types)The public bodies that keep them under express provision of law, in the manner and for the period set out in that lawAs provided in the law creating each registryBulk processing of the personal data contained in those registries; breaching this constitutes an infringement

Why does Law 21.719 prohibit the bulk processing of offence registries?

Because making a registry public serves a specific, limited purpose, and accumulation defeats it. Article 25 of Law 21.719 prohibits, in Chile, the bulk processing of personal data contained in the electronic registries of criminal, civil, administrative and disciplinary offences kept by public bodies, and provides that breaching that prohibition constitutes an infringement.

The logic is straightforward. A public registry exists so that someone can look up a specific case for a legitimate purpose. When that same data is downloaded at scale and cross-referenced, it stops being a lookup and becomes a permanent profile that follows the person long after the sanction has been served. The result sits badly with the expiry rule in article 25 itself: the data can no longer be disclosed from the official source, yet it lives on in a private database.

For the recruitment and background-screening market this has a concrete consequence. A service offering instant background checks built on its own database, assembled from public registries, is in direct tension with that prohibition. Before hiring a provider of this kind, it is worth asking where their data comes from and on what legal basis they process it, and reviewing the contract with legal advice.

The risk is not theoretical. Article 35 classifies infringements as minor, serious and most serious: minor ones carry a written warning or a fine of up to 5,000 UTM, serious ones a fine of up to 10,000 UTM, and most serious ones a fine of up to 20,000 UTM, and in the event of a repeat infringement the amount may be applied up to three times over. Added to this is article 39, which creates a National Registry of Sanctions and Compliance that is public, free of charge and electronic, with entries public for five years. On the civil side, article 47 requires the data controller to compensate the pecuniary and non-pecuniary damage it causes to data subjects where, in its processing operations, it breaches the principles of article 3, the rights and the obligations under the law and causes them harm; that action is brought once the decision upholding the claim before the Agency is final — or once the judgment is final, in the case of an illegality claim — is heard under summary proceedings, and is subject to a five-year statute of limitations.

  • Do not download or accumulate public offence registries to build your own databases.
  • Ask your screening providers for the source and the legal basis of the data they supply.
  • Remember that data you may consult is not data you may reuse for another purpose.
  • Bear in mind that breaching the prohibition constitutes, by express wording, an infringement.

What risks does HR take on by keeping criminal record certificates in the employee's file?

The biggest risk is not only requesting the document: it is retaining it without need and without a time limit. Storage is processing, and it brings with it the principles of article 3 of Law 21.719 — lawfulness and fairness, purpose, proportionality, quality, accountability, security, transparency and information, and confidentiality — as well as the rule in article 25 applied to every subsequent operation.

The critical point is usually purpose. If the certificate was requested to assess an application and the application has been decided, the purpose is spent. Keeping the document three years later, just in case, is hard to defend against the purpose and proportionality principles. In the audits we run, the employee's file and recruitment inboxes are the two places where the most documentation piles up with no current purpose.

On top of this come duties that apply to every data controller: the duty of secrecy or confidentiality under article 14 bis, the duty of information and transparency under article 14 ter, protection by design and by default under article 14 quater, and the security measures under article 14 quinquies. If that documentation is breached, article 14 sexies requires reporting the breach to the Agency by the fastest available means and without undue delay where there is a reasonable risk to the rights and freedoms of data subjects, as well as recording it; and communicating it to data subjects where it involves sensitive data, data of children under fourteen, or data on economic, financial, banking or commercial obligations. Chilean law does not set a 72-hour deadline for that report: it requires acting without undue delay.

This is worth saying plainly: the level of detail of those minimum standards has not yet been defined. Article 14 septies provides that the minimum standards or conditions for the information and security duties will be determined taking into account the type of data, whether the controller is a natural or legal person, the size of the entity according to the categories in article two of Law 20.416, the activity it carries out and the volume, nature and purposes of the data it processes, and that the Agency will set them by general instruction. As of July 2026 that general instruction does not yet exist, so the sensible course is to work from the principles rather than wait for a closed checklist. And an important clarification: this differentiation adjusts the standard required according to size and context; it does not make the obligations optional.

Finally, the applicant or employee has a say. Articles 10 and 11 recognize the rights of access, rectification, erasure, objection and portability, and article 11 requires acknowledging receipt and responding no later than within 30 calendar days from the date the request is filed, a period extendable once by up to a further 30 calendar days. If the company refuses, it must give reasons and inform the data subject that they have 30 business days to file a claim with the Agency; article 41 governs that rights protection procedure, which can also be initiated where the company simply fails to respond within the statutory period.

  • Purpose spent: once the selection process is decided, the reason for keeping the certificate disappears.
  • Retention with no time limit: the employee's file is the most common accumulation point.
  • Lack of access control: restricted documentation visible to more people than necessary.
  • Scattered copies: emails, shared folders and parallel spreadsheets outside any inventory.
  • No record of the decision: no one can explain in writing on what basis the data was requested.

What can your company do before 1 December 2026?

Four concrete moves, in this order: check whether a rule authorizes your activity, limit the purpose, avoid unnecessary retention, and refrain from building your own databases out of public registries. All four can be carried out now, with the team you already have, and none of them requires waiting for Law 21.719 to enter into force on 1 December 2026.

The first is legal work, not operational work. It means identifying, role by role, whether there is a sector-specific rule requiring or authorizing background checks, and putting that analysis in writing. If none turns up, the finding is valuable too: it tells you the practice rests on habit and needs redesigning. Either way, a conversation with specialist advisors avoids rushed decisions in an area where article 25 is demanding.

The second and third are about process. Define exactly what the data is for, who may see it and for how long; then do the uncomfortable exercise of deleting whatever no longer serves any function. The law also provides for impact assessments in article 15 ter: it is worth reviewing with advisors whether your processing requires one and, in any event, it is a useful instrument for documenting risks and decisions.

The fourth involves third parties. If you work with recruitment consultancies or screening providers, distinguish between a data assignment (transfer of controllership) under article 15 and a processing mandate under article 15 bis, where a third-party agent or processor handles data on behalf of the controller and the controller retains control. In an assignment, the assignee acquires the status of data controller for all legal purposes and the assignor retains that status for the operations it continues to carry out; in addition, the assignment must be recorded in writing or through any suitable electronic means, identifying the parties, the data covered by the assignment and the intended purposes. And if an assignment takes place without the data subject's consent where that consent was required, the assignment is null and void and the assignee must delete all data received, without prejudice to any applicable legal liability.

We close with the note of caution this topic deserves. Article 25 of Law 21.719 sets a clear framework on who may process offence data in Chile, but its application to a specific role, in a specific industry, depends on sector-specific rules that have to be reviewed one by one. This article gives you the map; the specific route is charted with professional advice and put in writing.

  • Check and document whether a rule authorizes your activity or the specific role.
  • Limit the purpose: define what the data is used for, who has access and for how long.
  • Eliminate unnecessary retention: once the purpose is spent, the document should not still be there.
  • Do not build your own databases out of public offence registries.
  • Formalize your data assignments and processing mandates in writing with consultancies and screening providers.

Review your background-check process before December 2026

At AlayIAtrust we help HR, legal and compliance teams assess whether their hiring process rests on a sufficient legal basis, redesign how documents are collected and retained, and put decisions in writing before Law 21.719 enters into force. Let's talk about your specific case.

Schedule an assessment

Frequently asked questions

Does Law 21.719 prohibit requesting a criminal record certificate in Chile?

Law 21.719 contains no prohibition worded in those terms. What article 25 does is reserve the processing of data on criminal offences for public bodies, to carry out their statutory functions and in the cases expressly provided by law. Without an authorization of that kind, a private company is left without a clear basis to justify the processing, so the case is worth reviewing with legal advice.

Is the applicant's consent enough to process their criminal record?

Consent under article 12 is the general lawfulness rule, but article 25 of Law 21.719 answers a prior question: who may process this data in Chile. If the law reserves that processing for public bodies, it is hard to argue that the applicant's authorization overrides that reservation. On top of that, in a selection process the imbalance between company and candidate weakens the value of such consent.

What about private security or transport companies?

There are activities governed by sector-specific rules that require or authorize checking the background of certain individuals. Article 25 of Law 21.719 allows processing in the cases expressly provided by law, so the right question is whether your activity and that specific role are covered by such a rule. It is worth reviewing this with legal advice and documenting the analysis in writing.

Can I keep the criminal record certificate in the employee's file?

Retaining the document is a processing operation and requires the same basis as collecting it, as well as compliance with the purpose and proportionality principles of article 3 of Law 21.719. Keeping it out of habit, with no defined retention period and no current use, is one of the most exposed points in any HR process in Chile.

What is the bulk processing prohibited by article 25?

Article 25 of Law 21.719 prohibits the bulk processing of personal data contained in the electronic registries of criminal, civil, administrative and disciplinary offences kept by public bodies in Chile. Breaching that prohibition constitutes an infringement, so downloading those registries to build your own databases falls outside what is permitted.

How long do a company's administrative sanctions remain public?

When the law orders the information to be published in a sanctions registry or on a website without setting a period, article 25 of Law 21.719 provides that civil, administrative and disciplinary offences remain accessible to the public for five years. For criminal offences, the publication periods are governed by the specific rules applicable to that type of offence.

Can a company hire an external provider to run background checks?

Hiring a third party does not create an authorization the company does not have. It is also worth distinguishing the arrangement: in a data assignment (transfer of controllership), article 15 of Law 21.719 provides that the assignee acquires the status of data controller and the assignor retains that status for the operations it continues to carry out; where it is a processing mandate under article 15 bis, control remains with the company. Always ask the provider for the source and the legal basis of its data.

What penalties does a company risk if it mishandles this data in Chile?

Article 35 of Law 21.719 classifies infringements as minor, serious and most serious: minor ones carry a written warning or a fine of up to 5,000 UTM, serious ones a fine of up to 10,000 UTM, and most serious ones a fine of up to 20,000 UTM. In the event of a repeat infringement, the amount may be applied up to three times over. In addition, article 39 creates a public, free-of-charge National Registry of Sanctions and Compliance, with entries public for five years.

When does all of this apply, and what leeway do smaller companies have?

Law 21.719 enters into force on 1 December 2026 in Chile. Its sixth transitional article allows the Agency, during the first twelve months, to issue a written warning where a sanction would otherwise be imposed on smaller companies (as defined in Law 20.416). This is a power of the Agency, not an immunity, and the warning is still recorded under article 39.

Can an applicant ask for their criminal record certificate to be deleted?

They can exercise that right. Articles 10 and 11 of Law 21.719 recognize the rights of access, rectification, erasure, objection and portability. The company must acknowledge receipt and respond no later than within 30 calendar days, extendable once by up to a further 30 calendar days. If it refuses, it must give reasons and inform the data subject that they have 30 business days to file a claim with the Agency.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Sensitive data

Sensitive data under Law 21.719: what they are and how to protect them

HR

Employee data: a privacy guide for HR

Law 21.719

Law 21.719: the definitive guide to comply and avoid fines

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment