In Chile a data protection impact assessment is mandatory whenever processing is likely to produce a high risk to data subjects' rights, and it must be carried out before operations begin. Article 15 ter of Law 21.719 always requires one in four cases: profiling with legal effects, large-scale processing, monitoring of public areas, and sensitive data without consent.
The essentials in 30 seconds
- A DPIA (EIPD in Chile) is a prior analysis of the risks a processing activity poses to people.
- It is mandatory whenever the processing may produce a high risk to data subjects' rights, and article 15 ter always requires one in four listed cases.
- It is carried out before starting the processing, not afterward.
- It must be documented and reviewed whenever the processing changes.
- It is part of proactive accountability and builds on your RoPA.
Not every processing activity requires an impact assessment — but those that do require it before they begin, and omitting it is a gap that weighs heavily in an inspection. The good news: when properly focused, a DPIA is a decision-making tool, not a formality. If you do not yet have the big picture, start with the definitive guide to Law 21.719. If you want the full picture, start with our guide to the data protection law in Chile.
What a DPIA is
The Data Protection Impact Assessment —DPIA, known in Chile as EIPD (Evaluación de Impacto en Protección de Datos)— is a prior analysis that serves to anticipate and mitigate the risks that a processing activity may pose to people's rights. Instead of discovering the problem once it has already happened, the DPIA forces you to think it through beforehand: what could go wrong for data subjects and how do we prevent it?
When is it mandatory?
Article 15 ter of Law 21.719 sets a general rule and a closed list. The general rule: an assessment is required whenever the processing is likely, by its nature, scope, context, technology used or purposes, to produce a high risk to data subjects' rights. The list: four cases where an assessment is always required. They are worth reading precisely, because versions circulate that import article 35 of the European GDPR and do not match the Chilean text:
| Situation | DPIA required? | Basis |
|---|---|---|
| Systematic and exhaustive evaluation of personal aspects based on automated processing or decisions, such as profiling, producing significant legal effects | Yes, always | Article 15 ter letter a) |
| Massive or large-scale data processing | Yes, always | Article 15 ter letter b) |
| Processing involving systematic observation or monitoring of a publicly accessible area | Yes, always | Article 15 ter letter c) |
| Processing of sensitive and specially protected data under the consent exception scenarios | Yes, always | Article 15 ter letter d) |
| Any other processing that, by nature, scope, context, technology or purposes, may produce a high risk | Yes, under the general rule | Article 15 ter first paragraph |
| Routine, low-volume processing without high risk | No, unless the Agency's list includes it | Article 15 ter third paragraph |
When in doubt, carrying out the DPIA is the prudent choice: the cost of assessing it is low compared to that of a high-risk processing activity with no analysis. Sectors such as healthcare and banking need it frequently.
What a DPIA must contain
- Description of the processing: what data, about whom, for what purpose and by what means.
- Necessity and proportionality: is it really necessary to process that data for that purpose? is there a less invasive route?
- Identification of risks to data subjects' rights (improper access, loss, misuse, discrimination).
- Mitigation measures: technical and organizational controls to reduce each risk.
- Conclusion and follow-up: whether the residual risk is acceptable and how it will be reviewed over time.
How to carry it out step by step
- Identify whether it is triggered: use the table above when designing a new processing activity or reviewing an existing one in your RoPA.
- Describe the processing in detail (data flows, systems, third parties).
- Assess necessity and proportionality: discard data or purposes that add nothing.
- Map the risks and their likelihood and impact.
- Define mitigation measures and recalculate the residual risk.
- Document and decide: if the residual risk remains high, revisit the design before moving forward.
- Review the DPIA whenever the processing changes.
Common mistakes
- Doing it at the end, once the system is already built. The DPIA is privacy by design: it goes at the start.
- Treating it as a form to fill in, without real decisions about the design of the processing.
- Not involving IT and legal together: the risk is technical and legal at the same time.
- Not reviewing it when the purpose changes or a new vendor is added.
Do you have high-risk processing that has not been assessed?
We help you identify which activities require a DPIA and carry them out with a focus on decisions, not paperwork. A 30-minute assessment, no obligation.
Schedule an assessmentFrequently asked questions
What is a DPIA?
A Data Protection Impact Assessment (DPIA, known in Chile as EIPD) is a prior analysis that identifies and mitigates the risks that a processing activity may pose to people's rights. It is carried out before starting high-risk processing.
When is a DPIA mandatory under Law 21.719?
When a processing activity may involve a high risk: large-scale sensitive data, systematic monitoring, profiling, automated decisions with significant effects, or the use of new technologies. When in doubt, carrying it out is the prudent choice.
What must a DPIA contain?
A description of the processing and its purpose, an assessment of necessity and proportionality, the identification of risks to data subjects, mitigation measures and conclusions with follow-up.
Who carries out the DPIA?
The data controller, ideally with the Data Protection Officer (DPO) if one exists, and with the support of the technical and legal teams. It must be documented and reviewed whenever the processing changes.
Which article of Law 21.719 governs the impact assessment?
Article 15 ter, headed "Data protection impact assessment". It establishes the duty to carry one out before processing operations begin whenever the processing is likely to produce a high risk to data subjects' rights, and it lists four cases where one is always required.
When is a DPIA always required in Chile?
In the four cases of article 15 ter of Law 21.719: systematic and exhaustive evaluation based on automated decisions with significant legal effects; massive or large-scale processing; systematic observation or monitoring of a publicly accessible area; and processing of sensitive data under the consent exception scenarios.
Is the DPIA done before or after processing starts?
Before. Article 15 ter of Law 21.719 requires it to be carried out "prior to the start of the processing operations". An assessment produced once the system is already live does not discharge the duty: its purpose is to decide whether the processing may proceed and under which mitigations.
Is there an official list of processing requiring a DPIA?
It is foreseen but not yet published. Article 15 ter of Law 21.719 instructs the Personal Data Protection Agency to establish and publish an indicative list of the types of operations that do and do not require an impact assessment, together with the minimum guidance for carrying one out.
What must the assessment contain as a minimum?
Article 15 ter of Law 21.719 sets the criteria the Agency must reflect in its minimum guidance: a description of the processing operations, their purpose, an assessment of necessity and proportionality against that purpose, an assessment of the risks, and the mitigation measures.
Can I consult the Agency if the result shows high risk?
Yes. Article 15 ter of Law 21.719 allows controllers to consult the Personal Data Protection Agency where, in light of the assessment's outcome, the processing proves to be high risk, in order to obtain recommendations from that body before proceeding.
Official sources
- Law 21.719 on the protection and processing of personal data, creating the Personal Data Protection Agency — official text, Library of the National Congress of Chile
- Article 15 ter (data protection impact assessment) — consolidated text in force from 1 December 2026
This article is for information purposes only and does not constitute legal advice for a specific case.