Decree 662, published in Chile's Official Gazette on 9 September 2026, is the regulation governing the infringement prevention models of Law 21.719. Adopting one is voluntary. Its article 6 keeps the data protection officer optional as a general rule, but makes the appointment mandatory from the moment a controller adopts a compliance programme. The Agency grants certification and certificates last three years.
The essentials in 30 seconds
- Decree 662 of the Ministry of Finance was published in the Official Gazette on 9 September 2026: 20 articles in two titles, with Title II split into three paragraphs.
- Adopting an infringement prevention model remains voluntary for any data controller.
- Its article 6 makes appointing a data protection officer mandatory from the moment a compliance programme is adopted.
- The Agency certifies at the applicant's request, and certificates are valid for three years.
- Certified entities are entered in the National Register of Sanctions and Compliance, which is publicly accessible.
Law 21.719 added articles 49 to 53 to Law 19.628, creating the infringement prevention model: a compliance programme that any data controller may adopt voluntarily and whose adoption, according to the regulation's own recitals, may works as a mitigating factor before the Agency. What was missing was the regulation setting out how it is implemented, certified and registered. It is now published. If you want the full picture, start with our guide to the data protection law in Chile.
Decree 662 of the Ministry of Finance appeared in Chile's Official Gazette on 9 September 2026. It is a short, operational text: it defines the minimum elements of the programme, devotes eight articles to the data protection officer, and sets the procedure for certification, registration, supervision and revocation.
This article walks through it article by article, with particular care at the point where the market will get it wrong in both directions: what exactly happened to the voluntary nature of the data protection officer.
What is Decree 662 and what does it regulate?
It is worth reading the full official title, because it defines the scope precisely: «Approves the regulation governing the requirements, modalities and procedures for the implementation, certification, registration and supervision of the infringement prevention models referred to in article 49 which Law No. 21.719 adds to Law No. 19.628».
The mandate comes from the final paragraph of article 51 that Law 21.719 added to Law 19.628: it instructed a regulation issued through the Ministry of Finance, signed by the Minister Secretary General of the Presidency and the Minister of Economy, Development and Tourism, to set the requirements, modalities and procedures for implementation, certification, registration and supervision. The decree is dated 13 June 2025 and was published in the Official Gazette on 9 September 2026.
The structure is 20 articles across two titles, with Title II split into three paragraphs. Title I holds the general provisions, with the purpose of the regulation and the rules of subsidiary application. Title II covers compliance programmes and is split into three sections: elements and publicity of the programme, the data protection officer, and approval, certification, registration, implementation and supervision.
Article 1 sets the tone for everything that follows. Data controllers, whether natural or legal persons, public or private, «may voluntarily adopt and implement an infringement prevention model consisting of the adoption of a compliance programme». No one is required to have one.
That same article 1 closes with a warning worth underlining: adopting and implementing a compliance programme does not displace the duty of every controller to take action to prevent infringements and, more generally, to comply with the law. The model is an additional layer, not a substitute for compliance. Article 2 completes the picture: the definitions in article 2 of Law 19.628 apply, and the rules of Law 19.880 apply to acts and procedures involving the Agency.
- It is mandated by the final paragraph of article 51 that Law 21.719 adds to Law 19.628.
- It is signed by Finance, the Secretariat General of the Presidency, and Economy, Development and Tourism.
- Date of the decree: 13 June 2025. Publication in the Official Gazette: 9 September 2026.
- 20 articles in two titles, with Title II divided into three sections.
- Adopting the model is voluntary and does not replace the general duties of the law.
Article 6: the officer stays voluntary, unless you certify
This is the point that organises the whole regulation, and it must be quoted verbatim. Article 6 reads: «The data controller may appoint a personal data protection officer, an appointment that shall be mandatory in the context of the adoption and certification of a compliance programme».
Both hasty readings are wrong. It is not true that Decree 662 has made the data protection officer mandatory in Chile: the general rule remains article 50 of the law, which uses the verb «may». Nor is it complete to keep saying, without qualification, that the officer is voluntary: since 9 September 2026 there is one scenario in which the appointment is mandatory, and it is the one the controller itself opens by deciding to adopt a compliance programme: article 49 of the law requires the officer as a minimum component of the programme, so the duty arises on adoption and does not wait for certification.
The decree is consistent with that reading in its recitals, where it describes the data protection officer as the person «whose appointment is mandatory in the context of the infringement prevention model», and mentions the effect the adoption of the model may have as a mitigating factor for the penalties the Agency imposes when exercising its supervisory and sanctioning powers.
The scope is not negotiable either. Article 6 specifies that, in that case, the officer must exercise the powers of article 50 of the law and of the regulation «in respect of all data processing operations carried out by the controller that appoints them». A model cannot be certified with an officer of partial scope, limited to one division or one business line.
And there is an evidentiary consequence that is easy to miss. Article 10 requires the officer to be appointed on the basis of specialised knowledge of the applicable data protection rules, experience in the field and professional skills; it further requires that the officer always hold up-to-date knowledge of the applicable rules, of the decisions and rules issued by the Agency, and of the relevant case law. And it closes: the controller «must be able to demonstrate the suitability of the officer» within the certification procedure. Suitability has to be provable, not merely asserted.
- Article 7: the officer may be an employee of the controller or external; where a legal person provides the service, the contract must name the individual who will act as officer.
- Article 8: the officer is appointed by the most senior management or administrative authority —the board, a managing partner or the head of the entity— and reports directly to it, with autonomy from management.
- Article 9: the controller must provide means, powers and material resources proportionate to the size and economic capacity of the entity, to its processing operations and to its risks, and must avoid conflicts of interest.
- Article 11: the officer's contact details must be published on the website or an equivalent means of information, and always communicated to the Agency.
- Article 12: the officer is bound by strict secrecy and confidentiality.
- Article 13: the eleven listed functions include advising on the impact assessment of article 15 ter, acting as the contact point with the Agency, and drawing up an annual work plan with reporting at least once a year.
| Controller's situation | Must an officer be appointed? | Rule |
|---|---|---|
| Does not adopt an infringement prevention model | No. It is an option, not a duty | Article 50 of the law: «may» |
| Adopts and certifies a compliance programme | Yes. The appointment is mandatory | Art. 6 of the regulation |
| Micro, small or medium-sized enterprise that certifies | Yes, and the owner or senior management may personally take on those tasks | Art. 8, third paragraph |
| Corporate group or entities under the same controlling party | Yes, and a single officer may serve them all if they operate under the same standards | Art. 8, fourth paragraph |
| Public body that establishes an officer | Must appoint an official from the body's existing staff | Art. 7, second paragraph |
What must the compliance programme contain?
Article 3 of the regulation sets ten minimum elements, from letter a) to letter j), and clarifies that the programme is a set of instruments that any data controller may adopt, whether a natural or legal person. The first three letters are identification: details of the controller and its legal representative, appointment of the officer under article 8, and definition of that officer's means and powers.
Letter d) is the most demanding and the most laborious: characterisation of the personal data the controller processes, of the categories of data and databases it administers, and of the processing operations it carries out, with eleven items of minimum information. It ends with a sentence worth reading closely: «This characterisation may be carried out by means of a record of processing activities».
That nuance matters because in Chile it is often repeated that the record of processing activities is a statutory obligation, when that instrument comes from article 30 of the European General Data Protection Regulation. What Law 19.628 requires as a general rule are the twelve blocks of information in article 14 ter. Here, by contrast, the record appears in its real role: an accepted means —not the only one— of documenting the characterisation in letter d) within a compliance programme.
Letter e) introduces the risk matrix. The controller must identify the processing activities or processes, routine or occasional, in whose context the risk of committing the infringements of articles 34 bis, 34 ter and 34 quáter of the law arises or increases, determine those of highest risk and include them in the matrix, which «must be developed taking into account the graduation of the penalties provided for in the law». That graduation is what distinguishes minor infringements, with fines of up to 5,000 UTM, serious ones of up to 10,000 UTM, and very serious ones of up to 20,000 UTM.
Letters f) to i) are about governance. Specific protocols, rules and procedures, established taking into account the processing operations, the volume and type of data, and the size and economic capacity of the entity. Internal reporting mechanisms with prompt and permanently available channels, which may be integrated into existing whistleblowing channels. Internal administrative penalties and their procedures. And a channel for reporting to the officer that guarantees the confidentiality of the reporter's identity, who may not be subjected to any adverse measure because of the report.
Letter g) adds the mechanisms for reporting to the authority or to data subjects in order to comply with the duty in article 14 sexies of the law, plus the self-reporting mechanisms of article 36 No. 4. This deserves a precision: that duty requires notifying breaches «without undue delay» and sets no deadline in hours; the scheme of 3 and 72 hours and 15 calendar days belongs to article 9 of Law 21.663 on Cybersecurity and is reported to the national CSIRT, not to the Agency.
Two practical duties sit outside article 3. Article 4 requires the programme's internal rules to be expressly incorporated as an obligation in the employment or service contracts of all workers and service providers, including the most senior executives, and in the internal regulations of articles 153 and following of the Labour Code, with the publicity measures of article 156. Article 5 requires the programme —and its amendments— to be disseminated, and adds a strict publicity rule: the controller may state that its programme is certified only «by direct, plain and simple reference» to the National Register of Sanctions and Compliance.
- Type of personal data processed, stating whether it includes sensitive data or special categories.
- Territorial scope of the processing, under article 1 bis of Law 19.628.
- Categories, classes or types of databases administered, and categories of data subjects.
- Purposes of the operations and the source of the data, stating whether it comes from publicly accessible sources.
- Lawful basis, and the legitimate interest where processing relies on subparagraph d) of article 13.
- Categories of third parties to whom data is expected to be disclosed or transferred, including recipients in third countries or international organisations.
- International transfers, identifying the country or organisation and the means used to comply with article 27.
- Retention periods or conditions for erasure by category of data.
- Existence of automated decisions or profiling, with meaningful information on the logic applied and the expected consequences for the data subject.
Certification, public register and three-year validity
Article 14 lists the powers of the Personal Data Protection Agency over these models: it may certify, register and supervise them, as well as revoke certification and apply the penalties the law provides. And it specifies that the Agency will certify models that meet the requirements set out in the law and in the regulation: this is not a discretionary quality assessment, it is a verification of requirements.
Article 15 describes the procedure. It starts at the applicant's request and is handled under the rules of Law 19.880 and any further rules the Agency issues by general instruction. To examine the application and the supporting material, the Agency may contract third-party services under the general rules of Law 19.886. In its final act it rules on the application and, if it grants certification, orders the model to be entered in the register.
The most important operational figure in that article is the term: «Certificates issued by the Agency shall be valid for three years», renewable at the applicant's request under the same procedure. Certification is not a one-off milestone; it is a cycle to be maintained.
Article 17 governs the register. The Agency enters entities holding a valid certification in the National Register of Sanctions and Compliance, identifying the controller that adopted the model and its legal representative —in centralised services, the head of service— and stating the date the certification was entered and its expiry date. The register allows public access to the certificates issued, and at the controller's request the Agency must issue a certificate of the certification and its registration.
Article 18 settles a reasonable doubt: implementation of the model is carried out by each controller and «may begin before the date on which the Agency enters the entity» in the register. There is no need to wait for the certificate to start operating the programme, always in full compliance with the law, the regulation and any other applicable administrative rules.
| Stage | What the regulation says | Rule |
|---|---|---|
| Start | At the applicant's request, before the Personal Data Protection Agency | Art. 15 |
| Procedure | Rules of Law 19.880 and the general instructions issued by the Agency | Art. 15 |
| External support | The Agency may contract third-party services under Law 19.886 | Art. 15 |
| Validity | Three years, renewable at the applicant's request | Art. 15 |
| Register | Entry in the National Register of Sanctions and Compliance, with entry and expiry dates | Art. 17 |
| Publicity | Public access to certificates; written confirmation at the controller's request | Art. 17 |
| Implementation | May begin before the Agency enters the entity in the register | Art. 18 |
Revocation, supervision and an Agency still without a Board
Article 16 lists five grounds on which a certification ceases to be valid: revocation by the Agency, death of a controller who is a natural person, dissolution of the legal person, a final court ruling, and voluntary cessation of the activity covered by the certified model. In that last case the controller must notify the Agency within thirty days of the cessation.
The same article resolves the problem of appearances. Cessation of validity on any of those grounds «shall not be enforceable against third parties until it is removed from the register», and the Agency must order that removal together with the decision revoking the certification, or within five working days of becoming aware of the ground. As long as the entry remains published, the third party who relied on it is protected.
Revocation is in article 20 and has two scenarios. First, that the controller breaches or ceases to meet any of the requirements the law or the regulation set for certifying the model. Second, that, in breach of article 48 of the law, it is penalised for one of the infringements in articles 34 bis, 34 ter or 34 quáter. The procedure may be opened on the Agency's own initiative or at a party's request. To certify again, the controller must meet every requirement and, in addition, provide conclusive evidence that the ground has been remedied, submitting the record of the organisational and operational measures adopted to prevent the same infringement; the decision on the new application must address those measures specifically.
Article 19 completes the picture with supervision: the Agency may supervise compliance with the models it has certified, request all necessary information —which the officer must make available fully and promptly— and penalise, under Law 19.628, any failure to provide it or the provision of false, incomplete or manifestly erroneous information. Controllers may be excused where the information is covered by a duty of secrecy or confidentiality, by identifying the rule that establishes it and evidencing the ground.
One honest question remains: can you certify today? Not yet, and the regulation sets no date for that procedure to open. The Personal Data Protection Agency still has no Board of Directors in place: on 19 May 2026 the Senate rejected the proposed board members, by 19 votes in favour and 12 against, where two thirds of sitting senators were required. Before the law takes effect, the Board may only exercise the functions in subparagraphs a), b), g) and h) of article 30 bis and those of article 30 ter, and any general instructions or rules it issues will only become binding once the law takes effect. Since article 15 refers precisely to the Agency's general instructions, the procedure exists on paper but has no one to administer it yet.
In parallel, on 1 September 2026 Bill 18.623-07 was introduced in the Senate, proposing to move the entry into force of Law 21.719 to 1 December 2027, to increase the Board from three to five members and to bring forward their first appointment. It is a bill at its first constitutional stage, not a law: the legal date in force today remains 1 December 2026.
The practical conclusion does not change because of either fact. The compliance programme is built the same way —characterisation, risk matrix, protocols, channels, a suitable officer— and article 18 allows it to be implemented before any registration. What certification adds is a public, verifiable signal in the register, and the mitigating effect the decree itself acknowledges. That comes later; the documentary work can start now.
- Revocation ordered by the Agency.
- Death of the controller, where a natural person.
- Dissolution of the legal person.
- A final court ruling.
- Voluntary cessation of the activity covered by the model, with notice to the Agency within thirty days.
Considering certifying your infringement prevention model?
We review with you which elements of article 3 of Decree 662 you already have documented, what is missing in the characterisation and the risk matrix, and what appointing an officer with demonstrable suitability involves.
Schedule an assessmentFrequently asked questions
What is Decree 662?
It is the Ministry of Finance regulation governing the requirements, modalities and procedures for the implementation, certification, registration and supervision of the infringement prevention models in article 49 that Law 21.719 adds to Law 19.628. It was published in Chile's Official Gazette on 9 September 2026 and contains 20 articles.
Is an infringement prevention model mandatory?
No. Article 1 of the regulation states that data controllers, public or private, «may voluntarily adopt and implement» a prevention model consisting of a compliance programme. What is mandatory for everyone, with or without a model, is to take action to prevent infringements and to comply with Law 19.628.
Is a data protection officer mandatory in Chile?
As a general rule, no: article 50 of the law says the controller «may» appoint one. But article 6 of Decree 662 adds an exception: the appointment «shall be mandatory in the context of the adoption and certification of a compliance programme». In other words, if you decide to certify your model, the officer is no longer optional.
How long does certification of a prevention model last?
Three years. Article 15 provides that certificates issued by the Agency are valid for three years and may be renewed at the applicant's request, under the same procedure by which they were obtained. The register states the entry date and the expiry date of each certification.
Who certifies the model and how is the application handled?
The Personal Data Protection Agency certifies, at the applicant's request. The procedure is governed by Law 19.880 and by the general instructions the Agency issues. To examine the application, the Agency may contract third-party services under the general rules of Law 19.886.
Where can I check whether a company's programme is certified?
In the National Register of Sanctions and Compliance that the Agency will administer. Under article 17, it enters entities holding a valid certification, identifies the controller and its legal representative, states the entry date and the expiry date, and allows public access to the certificates issued.
Can I implement the programme before it is certified?
Yes. Article 18 provides that implementation is carried out by each controller and may begin before the Agency enters the entity in the National Register of Sanctions and Compliance, in full compliance with the law, the regulation and any other applicable administrative rules.
What happens if the Agency revokes the certification?
Article 20 allows a reasoned revocation if the controller ceases to meet the requirements, or if it is penalised for infringements of articles 34 bis, 34 ter or 34 quáter in breach of article 48 of the law. To certify again, the controller must meet every requirement and provide conclusive evidence that the ground has been remedied.
Can I advertise that my programme is certified?
Only in one way. Article 5 allows the certification to be advertised and reported «by direct, plain and simple reference» to the National Register of Sanctions and Compliance. It does not authorise broader claims about the organisation's level of compliance.
Does Decree 662 change the date Law 21.719 takes effect?
No. The legal date in force remains 1 December 2026. On 1 September 2026 Bill 18.623-07 was introduced in the Senate proposing to move it to 1 December 2027, but it is at its first constitutional stage and is not law until it is published in the Official Gazette.
Official sources
- Decree 662, Ministry of Finance — official text, Library of the National Congress
- Law 21.719 — text as published, Library of the National Congress
- Law 19.628 consolidated with the amendments of Law 21.719
- Bill 18.623-07 — progress of the bill amending Law 21.719, Senate
- Official Gazette of the Republic of Chile
This article is for information purposes only and does not constitute legal advice for a specific case.