In Chile, Law 21.719 does not require you to appoint a Data Protection Officer: article 50 states that the data controller "may" appoint one. It becomes mandatory only if the organization adopts the infringement prevention model of article 49, which is itself voluntary; article 6 of Decree 662, published on 9 September 2026, confirms it.
The essentials in 30 seconds
- Law 21.719 provides for the figure of the Data Protection Officer (DPO).
- It is not mandatory in Chile: article 50 states that the controller "may" appoint one. There is no legal threshold by volume or by data category.
- It becomes required in one case only: if the organization adopts the infringement prevention model of article 49, whose letter a) requires it as a minimum component. Article 6 of that model's regulation —Decree 662, published on 9 September 2026— confirms it: the appointment "shall be mandatory in the context of the adoption and certification of a compliance programme".
- It can be internal or external (DPO as a service). For many SMEs, external is more efficient.
- Even when it is not mandatory, appointing someone responsible is the best way to demonstrate proactive accountability.
"Do I have to hire someone just for this?" That is the first reaction of many companies when they hear about the DPO. The short answer is: it depends —and it is worth understanding what it depends on, because appointing (or not) a Data Protection Officer has concrete effects in an audit. If you want the full legal picture, start with the definitive guide to Law 21.719. If you want the full picture, start with our guide to the data protection law in Chile.
What the DPO (Data Protection Officer) is
The Data Protection Officer —DPO for short— is the person or service that ensures the organization processes personal data in accordance with the law. It is not a purely technical nor a purely legal role: it is a bridge between senior management, the areas that process data (marketing, HR, sales, IT), the data subjects and the Personal Data Protection Agency.
It is the Chilean equivalent of the DPO under the European GDPR. If you are interested in the comparison, we cover it in Law 21.719 vs GDPR.
Does Law 21.719 require you to have a DPO?
No. Article 50 of Law 21.719 opens the figure with a verb worth reading literally: the data controller "may" appoint a personal data protection officer. It is a power, not a duty, and Chilean law sets no threshold —not by data volume, not by category, not by company size— that would turn it into an obligation.
This is worth stating plainly, because the opposite circulates widely: the "sensitive data at large scale" and "systematic monitoring" criteria come from article 37 of the European GDPR, not from Law 21.719. Anyone citing them as Chilean law is importing a rule that does not apply here. Nor is there a special duty for public bodies: article 21 lists the provisions that apply to them and article 50 is not among them.
There is one single case where appointing one stops being optional, and it is indirect. If the organization chooses to adopt the infringement prevention model of article 49 —a voluntary compliance programme that the Agency can certify—, that model must contain, at minimum, under letter a), the appointment of a data protection officer, and under letter b), the definition of their means and powers. Put differently: the model is voluntary, but if you adopt it, the officer comes with it.
Since 9 September 2026 that is also written into the model's own regulation: Decree 662 of the Ministry of Finance, published in the Official Gazette that day. Its article 6 settles it in a single sentence: "the data controller may appoint a personal data protection officer, an appointment that shall be mandatory in the context of the adoption and certification of a compliance programme". The same regulation requires, in its article 10, that the officer hold specialized knowledge, experience and professional skills, and that the controller be able to demonstrate their suitability in the certification procedure. We break it down in what Decree 662 says.
None of this is operating yet: the decree set no date of entry into force, Law 21.719 starts to apply on 1 December 2026 and the Agency still has no Board in place.
Not being mandatory does not make it irrelevant. Article 36 number 5 treats as a mitigating circumstance having diligently fulfilled the duties of direction and supervision, evidenced by the certificate of article 51 —which certifies precisely that prevention model. In a sanction, the difference is concrete.
What article 50 says, point by point
It helps to keep straight what the text says and what it does not, because most of what circulates about the Chilean DPO blends the two. This table summarises article 50 of Law 21.719 and its single mandatory point of contact, article 49:
| Question | What the official text says | Article |
|---|---|---|
| Is appointing one mandatory? | No. The data controller "may" appoint a personal data protection officer. | Article 50 |
| Is there a threshold by volume or data type? | It does not exist in Chilean law. That criterion belongs to article 37 of the European GDPR. | Article 50 |
| When does it become required? | Only if the prevention model is adopted: the appointment "shall be mandatory in the context of the adoption and certification of a compliance programme". | Article 49 letter a) · Decree 662, article 6 |
| Who must appoint them? | The highest management or administrative authority: the board, a managing partner or the head of the service. | Article 50 |
| Can the owner take the role personally? | Yes. In micro, small and medium-sized enterprises the owner or top authorities may personally assume the tasks. | Article 50 |
| One officer for a whole group? | Yes, if the entities operate under the same standards and policies and the officer is accessible to all of them. | Article 50 |
| Can they hold other duties? | Yes, while preserving independence; the controller must ensure there is no conflict of interest. | Article 50 |
| Are they bound by secrecy? | Yes, strict secrecy over the data they learn. The controller answers for the officer's breaches of that duty. | Article 50 |
Does your sector process sensitive data or carry out profiling? Review the specific approach for health, banking and finance or SMEs.
Internal vs external DPO
The law does not require the DPO to be an employee. It can be internal (someone on your team) or external (a specialized service, known as DPO as a service). Each option has its place:
- Internal DPO: knows the organization from the inside. It makes sense in large companies, with enough volume and complexity to justify a dedicated role.
- External DPO: brings specialized expertise without the cost of a full-time role, with independence and an up-to-date view of the regulatory framework. It is usually the most efficient option for SMEs and the mid-market.
In both cases there are three conditions the role must meet to be valid: expert knowledge, autonomy (the outcome of their analysis must not be dictated to them) and a direct line to senior management.
What functions the DPO performs
- Overseeing compliance with Law 21.719 within the organization.
- Advising the areas that process data and senior management.
- Acting as the point of contact with the Personal Data Protection Agency and with data subjects.
- Coordinating the handling of ARCO rights and breach management.
- Ensuring the Record of Processing Activities (RPA) and the impact assessments (DPIA) are maintained.
- Promoting a culture of privacy: training and internal policies.
What you lose if you do not appoint one
Failing to appoint one is not in itself an infringement of Law 21.719: it does not appear in the catalogues of articles 34 bis, 34 ter or 34 quáter. What you lose is defence. Without an officer there is no article 49 prevention model, without the model there is no article 51 certificate, and without that certificate the mitigating circumstance of article 36 number 5 —having diligently fulfilled the duties of direction and supervision— falls away. Against fines reaching 20,000 UTM for a very serious infringement under article 35, that mitigation matters; see the detail in fines and sanctions.
And even when the DPO is not mandatory, its absence shows: rights not answered on time, breaches managed in a rush and a record of processing activities that no one keeps up to date. The role exists, precisely, so that someone holds compliance as a responsibility and not as "what we do when we can."
How to get started
The first step is not to hire someone, but to know whether you need one and to what extent. That is resolved with an assessment: what data you process, at what scale and with what risk. From there you decide whether an internal DPO, an external one or, at least, a designated person responsible with a clear plan is the right fit. We also cover it in the compliance checklist, front number 1: governance.
Not sure whether your company needs a DPO?
In a 30-minute assessment we evaluate your data processing and tell you whether one is required —internal or external— and where to start. No commitment.
Schedule an assessmentFrequently asked questions
Is a DPO mandatory in Chile under Law 21.719?
No, with one exception. Article 50 of Law 21.719 states that the controller "may" appoint one: it is a power, and Chilean law sets no thresholds of volume or data category. The exception appears when the organization adopts the prevention model of article 49, which requires the officer as a minimum component; article 6 of that model's regulation —Decree 662, published in the Official Gazette on 9 September 2026— confirms it: the appointment "shall be mandatory in the context of the adoption and certification of a compliance programme". If the organization does not adopt that programme, the officer remains voluntary.
Can the DPO be external?
Yes. The DPO can be an internal employee or an external service (DPO as a service). What matters is that they have expert knowledge, autonomy to carry out their role, sufficient resources and a direct line to senior management. For many SMEs, an external DPO is more efficient than creating the role internally.
What functions does the DPO perform?
Overseeing compliance with Law 21.719, advising the organization, acting as the point of contact with the Personal Data Protection Agency and with data subjects, coordinating the handling of ARCO rights and breach management, and ensuring the record of processing activities and impact assessments are maintained.
What does my company risk if it does not appoint a DPO when required?
When the appointment is required, not having a DPO is a compliance gap that may lead to a sanction and weakens the company's defense in an audit. Even when it is not mandatory, its absence usually translates into a lack of coordination: rights not answered on time, poorly managed breaches and an outdated record of processing activities.
Does Law 21.719 require companies to have a DPO?
No. Article 50 of Law 21.719 states that the data controller "may" appoint a personal data protection officer. It is a power, not a duty. Chilean law sets no thresholds of volume, data category or company size that would turn that power into an obligation.
Is it true that a DPO is required when sensitive data is processed at large scale?
That criterion is not in Law 21.719. It comes from article 37 of the European GDPR and is often repeated as if it were Chilean law. In Chile the appointment is voluntary under article 50, regardless of the volume or the category of the data being processed.
When does a data protection officer become mandatory in Chile?
In a single scenario, and indirectly. If the organization adopts the infringement prevention model of article 49 of Law 21.719, its letter a) requires appointing an officer as a minimum element of the programme. The model is voluntary, but adopting it brings the officer with it.
Who must appoint the officer within the company?
Article 50 of Law 21.719 requires the appointment to be made by the highest management or administrative authority of the controller: the board, a managing partner or the head of the company or service. It cannot be left to middle management or delegated downwards.
Can the owner of a small business act as their own data protection officer?
Yes. Article 50 of Law 21.719 expressly allows the owner or top authorities of micro, small and medium-sized enterprises to personally assume the tasks of the data protection officer, without creating a separate position or hiring a third party.
Is there any point in appointing one if the law does not require it?
Yes, when a sanction is at stake. Article 36 number 5 of Law 21.719 treats as a mitigating circumstance having diligently fulfilled the duties of direction and supervision, evidenced by the article 51 certificate on the prevention model, whose first component is precisely the officer.
Official sources
- Law 21.719 on the protection and processing of personal data, creating the Personal Data Protection Agency — official text, Library of the National Congress of Chile
- Article 50 (powers of the officer) and article 49 (infringement prevention model) — consolidated text applicable from 1 December 2026
- Decree 662, Ministry of Finance — regulation on infringement prevention models, published in the Official Gazette on 9 September 2026
This article is for information purposes only and does not constitute legal advice for a specific case.