Chile's Law 21.719 keeps the rules on the credit data known as DICOM: only certain debts may be reported, and not after five years or once they have been paid. From 1 December 2026 four things change: time-barred obligations are erased without a request, the performance of credit obligations may be reported, the express restriction on risk assessments disappears and the Agency imposes the sanctions.
The essentials in 30 seconds
- Title III of Law 19.628 remains in force: only certain debts may be reported, and not after five years or once they have been paid.
- Four changes from 1 December 2026: erasure of time-barred obligations on the controller's own initiative, the possibility of reporting the performance of obligations, the end of the express restriction on risk assessments, and sanctions imposed by the Agency.
- The fine for infringing articles 17 and 18 goes from a maximum of 50 UTM (monthly tax units) to the general tiers of up to 5,000, 10,000 and 20,000 UTM.
- This data may be used only to assess commercial risk and for the credit process (Law 20.575). It may not be required in recruitment processes.
- A breach that affects data on economic obligations and poses a reasonable risk to data subjects must also be communicated to them, not only to the Agency.
DICOM is the name by which a private credit report is known; it is not an institution or a registry created by law. The law never mentions it. What it regulates is the processing of data on economic, financial, banking and commercial obligations, in Title III of Law 19.628: three articles that say which debts may be communicated, for how long, and what happens when they are paid. If you want the full picture, start with our guide to the data protection law in Chile.
Law 21.719 rewrote almost all of Law 19.628, but on that title it performed minor surgery. This article separates what stays from what changes, and looks at it from both sides: that of the person who appears as reported, and that of the company that reports debts or consults reports in order to grant credit.
Which laws govern credit data in Chile?
Four main ones. They are usually cited as if they were one, and it is worth separating what each one says.
| Law | What it governs | Status |
|---|---|---|
| Law 19.628, Title III (articles 17 to 19) | Which debts may be communicated, for how long, and what happens when they are paid. | In force since 1999. Amended by Law 21.719 from 1 December 2026. |
| Law 20.575 | What this data may be used for and to whom it may be communicated. | Published on 17 February 2012. |
| Law 21.680 | The Consolidated Debt Registry, administered by the Financial Market Commission (CMF). | Published on 3 July 2024. In force since 1 April 2026. |
| Labour Code, article 2 | The prohibition on making hiring conditional on the absence of debts. | In force. |
From December 2026 they are joined by the rest of the data protection law: its principles, the data subject's rights, the duty of security and the sanctions regime also apply to anyone who processes credit data. In addition, Supreme Decree No. 950 of 1928 of the Ministry of Finance, which regulates the Commercial Information Bulletin (Boletín de Informaciones Comerciales), continues to apply in everything that does not contradict the law.
Which debts may be reported and which may not?
Article 17 works as a closed list. Information on economic, financial, banking or commercial obligations may be communicated only where they are recorded in one of these instruments:
- Protested bills of exchange and promissory notes.
- Cheques dishonoured for lack of funds, for having been drawn on a closed current account, or for another reason.
- The non-performance, and from December 2026 also the performance, of obligations arising from mortgage loans and from loans or credit granted by banks, finance companies, mortgage loan administrators, savings and credit cooperatives, public bodies, state-owned companies subject to ordinary legislation, and companies that administer credit for purchases in retail stores.
- Other monetary obligations determined by supreme decree, provided they are recorded in payment or credit instruments showing the debtor's express consent and their due date.
The same article prohibits communicating, even if they are unpaid, debts owed to electricity, water, telephone and gas companies; debts owed to motorway concession holders for the use of their infrastructure; education debts, including any debt incurred in order to receive a formal educational service; and debts incurred with healthcare providers for outpatient, hospital or emergency care.
Nor may the loans granted by the National Institute for Agricultural Development (INDAP) to its users be communicated, nor obligations that have been rescheduled, renegotiated or novated, or that are subject to some pending modality.
And there is a protection linked to employment: protests and arrears originating during the debtor's period of unemployment may not be published or communicated. The blocking is free of charge, but it is not available to anyone who has entries in the commercial information system during the year before the end of their employment relationship.
How long can a debt be reported?
Five years at most. Article 18 prohibits communicating this data «once five years have elapsed since the respective obligation became due». The table brings that time limit together with the others set by Title III.
| Situation | Rule | Article |
|---|---|---|
| Unpaid debt | May not be communicated after five years from when it became due. | 18 |
| Debt paid or extinguished | May not continue to be communicated. | 18 |
| Notice of payment | The creditor notifies the registry within the following seven business days. | 19 |
| Those who take the data from that registry | They must update it as soon as the payment is communicated or within the following three days. If they cannot, they block the data. | 19 |
| Time-barred obligation | Must be erased without anyone asking. Applies from 1 December 2026. | 17 |
| Unemployed debtor | Blocking, free of charge, of the protests and arrears originating during the period of unemployment. | 17 |
The time limit runs from when the obligation became due, not from when the creditor reported it. Reporting it late does not extend it. The only exception in article 18 is the information required by the courts in connection with pending proceedings. Notice of payment is given at the debtor's expense, after payment of the fee where applicable, and the debtor may choose to request the change personally with proof of payment (article 19).
There is a nuance in article 19 that explains why the reply is sometimes negative. Payment prevents the data from continuing to be communicated to third parties, but it does not turn it into expired data while the five years are still running. Put another way: after payment, the registry may not go on reporting that debt, but the data subject cannot demand that it delete the debt from its files before the time limit expires. The general routes for requesting the deletion of data are set out in the right to be forgotten in Chile.
What changes with Law 21.719?
Item 9 of the first article of Law 21.719 makes two substantive changes to article 17, and item 11 changes who imposes sanctions. The rest are formal adjustments: new headings, «data banks» that are now called «databases» and an updated cross-reference in article 19.
Time-barred obligations are erased on the controller's own initiative. A new paragraph orders controllers to erase from their records all information relating to time-barred obligations, «without the need for a request, a court order or an instruction from the data protection authority». Erasure thus becomes an express duty of the registry, not something the debtor has to ask for.
Performance may also be reported. Where article 17 spoke of the «non-performance» of obligations arising from mortgage loans and credit, it now says «the performance or non-performance». For those credit obligations, the law is no longer limited to arrears. The practical scope is not settled in the text: article 18 still prohibits communicating an obligation once it has been paid, and article 17 still excludes those with some pending modality.
The Agency imposes the sanctions. Today, infringements of these rules are heard by a civil court judge, with fines of ten to fifty UTM where articles 17 and 18 are infringed. From the entry into force, they are penalized under Title VII: the fines are imposed by the Personal Data Protection Agency, under the law's general tiers. The detail is in fines and sanctions.
| Subject | Until 30 November 2026 | From 1 December 2026 |
|---|---|---|
| Time-barred obligations | No specific rule in Title III. | Must be erased without a request, a court order or an instruction from the authority. |
| Payment behaviour on credit obligations | Non-performance only. | Performance or non-performance. |
| Commercial risk assessments | Only those based on objective information on arrears or protests (article 9). | Without that express restriction. Law 20.575 and article 8 bis on automated decisions apply. |
| Who imposes sanctions | The civil court judge. | The Personal Data Protection Agency. |
| Fine for infringing articles 17 and 18 | 10 to 50 UTM. | Up to 5,000, 10,000 or 20,000 UTM, depending on the seriousness of the infringement. |
| Controller's deadline to respond to a request | 2 business days. | 30 calendar days, extendable once by another 30. |
| Security breach | Law 19.628 provides for no duty to give notice. | If there is a reasonable risk to data subjects: notice to the Agency and also to those affected. |
Outside Title III there are four other changes that touch this industry. Article 13 letter a) confirms that this data may be processed without the data subject's consent, provided this is done in accordance with Title III. Article 2 letter g) includes socioeconomic situation among sensitive data. And article 14 sexies requires security breaches that pose a reasonable risk to data subjects to be reported to the Agency and, where they affect data relating to economic, financial, banking or commercial obligations, to be communicated to the data subjects themselves as well.
The fourth is the least discussed. The current text prohibits «any kind of prediction or commercial risk assessment that is not based solely on objective information relating to arrears or protests» (article 9). That sentence is not in the amended text. From December 2026, a risk score is subject to the general rules: the exclusive purpose set by Law 20.575 and article 8 bis, which recognizes the right not to be subject to automated decisions with legal or significant effects and, where they are permitted, to ask for an explanation, human intervention and a review of the decision.
What can credit data be used for?
For one purpose only. Law 20.575 provides that the processing of this data must respect the purpose principle, «which shall be exclusively the assessment of commercial risk and the credit process». It may be communicated only to established businesses, for the credit process, and to the entities that take part in commercial risk assessment.
The same law lists where it may not be required:
- In recruitment processes.
- In admission to pre-school, school or higher education.
- In emergency medical care.
- In applications for a public-sector post.
The Labour Code reinforces this in its article 2: no employer may make the hiring of workers conditional on the absence of economic, financial, banking or commercial obligations, nor require any declaration or certificate for that purpose. There are two exceptions: workers with power to represent the employer and general powers of administration, such as managers or attorneys-in-fact, and those in charge of the collection, administration or custody of funds or securities. Law 20.575, which is later, does not repeat those exceptions: its text says «in no case». More on this point in employee data.
Law 20.575 adds two obligations for those who distribute this information. They must keep a record of each access, with the name of whoever requested the information, the reason, the date and the time; the data subject may request that record free of charge every four months, covering the last twelve. And they must designate a natural person before whom data subjects can exercise their rights.
How is the Consolidated Debt Registry different?
It is an official registry, distinct from private credit reports. It was created by Law 21.680 and is administered exclusively by the Financial Market Commission. It brings together the information on credit obligations that must be reported by banks, insurance companies, credit card issuers, family allowance compensation funds and savings and credit cooperatives supervised by the Commission, among others. The law began to apply on the first day of the twenty-first month following its publication, that is, on 1 April 2026.
Three differences from Title III matter for data protection. To consult the registry, the entity needs the debtor's prior, express and unambiguous consent, unless it has another lawful basis under Title III of Law 19.628. The registry gives no access to obligations that became due or were extinguished more than five years ago, nor to those whose action is time-barred. And the rights granted to the debtor by that law exclude those of Law 19.628 in respect of the data stored in the registry, where they have the same scope: they are exercised through the channels of Law 21.680, not through those of the data protection law.
What must a company that reports or looks up debts review?
Banks, retail stores, cooperatives, debt collection companies and any business that sells on credit process credit data. With the change in the sanctions regime, seven points merit review before December 2026.
- What you report. Only the obligations that article 17 allows. Check that no excluded debts go out: utilities, healthcare, education, motorways or rescheduled obligations.
- The age of the debt. An automatic rule that stops communication five years after the obligation became due, and another that erases time-barred obligations without waiting for a complaint.
- Payment. A process that notifies the registry within the seven business days. A debtor who has paid and is still being reported is a predictable complaint.
- Why you look debts up. Only commercial risk assessment and the credit process. If the credit report appears in recruitment, take it out: Law 20.575 says it may be required there «in no case».
- Accuracy. Processing inaccurate, incomplete or outdated data is a serious infringement, unless updating it is the data subject's responsibility (article 34 ter letter d). Communicating it knowingly is a very serious one (article 34 quáter letter c).
- Risk scores. If an automated model approves or rejects credit, article 8 bis applies: the person may ask for an explanation, human intervention and a review of the decision.
- Security. A response plan that provides for notice to the data subjects, because for this data the law requires it in addition to the report to the Agency.
The starting point is the same as for any other processing: knowing what data you hold, where it comes from and who you send it to. If your organization is in the financial sector, Law 21.719 for banking sets out in detail what we implement, and the general order of work is in the compliance checklist.
Does your company report or look up debts?
We review with you which obligations you are communicating, how the time limits are counted, what use is made of credit reports, and whether your breach plan provides for the notice to data subjects that Law 21.719 requires.
Schedule an assessmentFrequently asked questions
What is DICOM under Chilean law?
The law does not use that name. DICOM is the trade name of a private report. What the law regulates is the processing of data on economic, financial, banking or commercial obligations, in articles 17 to 19 of Law 19.628.
How long does a debt stay on DICOM?
The information may not be communicated after five years counted from when the obligation became due (article 18 of Law 19.628). Law 21.719 does not change that time limit.
If I pay the debt, is it deleted straight away?
It can no longer be communicated. Article 18 prohibits continuing to report a paid obligation, and the creditor must notify the registry of the payment within the following seven business days (article 19). What the data subject cannot demand is that the registry delete the data from its files while the five years are still running.
Which debts cannot appear in a credit report?
Among others, electricity, water, telephone and gas debts; debts for motorways under concession; education debts; debts incurred with healthcare providers for outpatient, hospital or emergency care; obligations that have been rescheduled, renegotiated or novated; and arrears originating during a period of unemployment (article 17).
What changes for DICOM under Law 21.719?
Four things, from 1 December 2026: time-barred obligations must be erased without the need for a request; the performance of credit obligations, and not only their non-performance, may be reported; the express prohibition on risk assessments not based solely on arrears and protests ceases to be in the law; and infringements are penalized by the Personal Data Protection Agency under Title VII.
Can an employer ask me for a credit report in order to hire me?
No. Law 20.575 provides that this information may be required «in no case» in recruitment processes, and article 2 of the Labour Code prohibits making hiring conditional on the absence of debts. The Code exempts those who have power to represent the employer with general powers of administration and those who handle funds or securities, but Law 20.575 does not repeat that exception.
Is my consent needed to report a debt?
No. The communication of these debts rests on article 17 and, from 1 December 2026, article 13 letter a) states expressly that this data may be processed without consent, provided this is done in accordance with the rules of Title III. If those rules are not respected, that ground ceases to cover the processing.
Who imposes sanctions if a debt is reported when it should not be?
Today, the civil court judge, with a fine of ten to fifty UTM where articles 17 and 18 are infringed. From 1 December 2026, the Personal Data Protection Agency, with fines of up to 5,000, 10,000 or 20,000 UTM depending on the seriousness.
Does the Consolidated Debt Registry replace DICOM?
No. They are separate regimes. The Consolidated Debt Registry is an official registry created by Law 21.680 and administered by the Financial Market Commission. Private credit reports remain governed by Title III of Law 19.628 and by Law 20.575.
What happens if my financial data is leaked?
From 1 December 2026, where the breach affects data relating to economic, financial, banking or commercial obligations and poses a reasonable risk to data subjects, the controller must report it to the Agency and also communicate it to each affected data subject, in clear language, stating the data compromised, the possible consequences and the measures adopted. If it is not possible to notify each one, it must publish a notice in a mass media outlet (article 14 sexies).
Official sources
- Law 19.628 consolidated with the amendments of Law 21.719 (in force from 1 December 2026)
- Law 19.628 on the protection of private life — text currently in force, Library of the National Congress
- Law 21.719 — text as published, Library of the National Congress
- Law 20.575, establishing the purpose principle in the processing of personal data
- Law 21.680, creating a Consolidated Debt Registry
- Labour Code, article 2
This article is for information purposes only and does not constitute legal advice for a specific case.