← Back to blog

Law 21.719 compliance standards and company size: does the law require the same from an SME as from a large company?

Article 14 septies is one of the least cited and most frequently asked-about provisions of Chile's new framework: it is the one that allows the compliance standards for two Law 21.719 duties to be graded according to company size and four other factors. Here we review it with the statutory text in hand, including — candidly — what has not yet been defined.

GUIDE · LAW 21.719
Short answer

Chile's Law 21.719 does not impose the same standard on a large company and a small one: its article 14 septies grades the minimum conditions of the information and security duties according to five factors, size among them. The Agency must specify them by general instruction; all other obligations apply equally to everyone.

The essentials in 30 seconds

  • Article 14 septies: five factors determine the standards or minimum conditions for two specific duties, the duty of information and transparency (article 14 ter) and the security duty (article 14 quinquies).
  • The size of the entity is measured using the categories in the second article of Law 20.416, on smaller companies, and not by an internal perception of the business.
  • Those differentiated standards and measures will be determined by the Agency through a general instruction: as of the date of this article, that instruction has not yet been issued, so the specific detail does not exist yet.
  • Sixth transitory article: during the first twelve months from the entry into force, where a sanction is applicable to smaller companies (as defined in Law 20.416), the Agency may impose a written reprimand. It is a power, not an immunity, and the reprimand is still recorded in the registry under article 39.

It is probably the most repeated question in Chilean board meetings and compliance committees since Law 21.719 was published: whether a twelve-person company will have to build the same data protection structure as a bank or a private health insurer. The short answer is not in everything, but the useful answer requires opening the statutory text, because the law does differentiate — although it differentiates less than many assume, and in a very specific place in the text. If you want the full picture, start with our guide to the data protection law in Chile.

That place is article 14 septies. It is a brief, technical provision, almost invisible in public conversation, and it is the one that expressly establishes that the standards or minimum conditions for two duties will be determined taking into account the size of the entity, among other factors. It also contains a point worth stating plainly: the detail of those standards was left to a general instruction from the Agency which, as of the date of this article, has not yet been issued.

In this article we review what article 14 septies actually grades, what its five factors are, which obligations do not shift a single millimeter based on size, why it is so often confused with the regime of the sixth transitory article for smaller companies, and how to make defensible decisions today without waiting for a document that has not yet been published.

Does Law 21.719 require the same from a large company and a small one?

Not in everything, and the difference lies in a rarely cited article. Chile's Law 21.719 will apply in full to both the large and the small company, but its article 14 septies provides that the standards or minimum conditions imposed on the controller to comply with two duties — the duty of information and transparency and the security duty — will be determined taking into account, among other factors, the size of the entity. The obligation to comply is not graded; the level of demand with which those two duties are met is. Put differently: differentiation does not make any obligation under the law optional.

In practice, two mistaken and opposing readings circulate. The first holds that the law is identical for everyone and that an SME will have to replicate the compliance architecture of a large corporation, which produces paralysis and unrealistic budgets. The second holds that Law 21.719 is not really aimed at SMEs and that it is enough to wait, which produces unnecessary exposure precisely as the law is set to enter into force on 1 December 2026 under its first transitory article.

Both readings fail for the same reason: they confuse the standard with the duty. Law 21.719 does not create one catalogue of obligations for large companies and another for small ones. It creates a single set of duties and allows the standard for two of them to be determined using criteria proportionate to the controller's reality. Distinguishing this is the first step to properly sizing a compliance project in Chile.

  • What is graded: the standards or minimum conditions for complying with the duty of information and transparency (article 14 ter) and the duty to adopt security measures (article 14 quinquies).
  • What article 14 septies does not reach: the principles in article 3, the rights and deadlines in articles 10 and 11, the duty of secrecy in article 14 bis, protection by design and by default in article 14 quater, breach reporting in article 14 sexies, and the data assignment (transfer of controllership) rules in article 15. This is without prejudice to the principle of proportionality in article 3, which informs all processing.
  • What is not yet written: the detail of each standard, because article 14 septies itself provides that those standards and the differentiated measures will be determined by the Agency through a general instruction.

What factors does article 14 septies use to define the standard that applies to you?

Five, and they are listed in the text itself. Article 14 septies of Law 21.719 requires consideration of the type of data involved; whether the controller is a natural or legal person; the size of the entity or company according to the categories in the second article of Law 20.416; the activity it carries out; and the volume, nature and purposes of the personal data it processes.

Here is the part almost nobody underlines: size is one of five factors, not the dominant criterion. A small company that processes health data, biometric data or data on children and adolescents concentrates a high level of risk despite its size, and the factors of data type, activity and purposes push its standard upward. Conversely, a mid-sized company whose processing is limited to an internal payroll and a narrow register of corporate clients will have a considerably simpler profile.

That is why the operational question is not only how many employees you have or how much you bill, but what data you process, on how many people, for what purpose, and how central data is to your business model. The five factors work in combination: reading them separately leads to wrong conclusions in both directions. It is also worth remembering that the final weighting of these factors will be specified in the general instruction issued by the Agency.

The five factors of article 14 septies of Law 21.719 and their practical translation into compliance scope.
Factor under article 14 septiesWhat it meansPractical scoping decision
Type of dataDistinguishes ordinary data from the sensitive data covered by article 16 and following: health and biological profile, biometric data, data on children and adolescents, geolocation, sexual life and sexual orientation, beliefs or convictions, political or trade union affiliation, racial or ethnic origin, and socio-economic situation.If you process sensitive data, treat that database with a higher standard even if your company is small. Measures such as role-based access control, encryption or query traceability are risk management decisions, not a closed legal checklist: assess them for your case and avoid applying a flat standard across the entire inventory.
Natural or legal personRecognizes that an independent professional and a company do not have the same organizational capacity or the same internal control structure.Define who is accountable, by name. The law does not require a data protection officer, but designating an internal role and putting article 15 bis processing arrangements in writing makes diligence easier to evidence; if you are a natural person, at least document the criterion adopted and the measures applied.
Size of the entity (second article, Law 20.416)Refers to the legal categories in Law 20.416, which sets out special rules for smaller companies.Determine which Law 20.416 category your company falls into and put it in writing: this is the data point that will bear on both the differentiated standard under article 14 septies and the regime under the sixth transitory article.
Activity carried outA sector whose core business is processing data — health, education, financial services, insurance, digital platforms, debt collection — is not in the same position as one where data is incidental to the sale of a good.If data is part of the product, prioritize the impact assessment under article 15 ter where applicable and the article 15 bis processing contracts with suppliers; if it is incidental, start with information to the data subject and access control.
Volume, nature and purposesLooks at how many data subjects are involved, what type of processing you carry out and for what purpose: profiling, automated decisions or transfers to third parties weigh more than a narrow internal register.Prioritize by risk concentration: first inventory the databases with the most data subjects and the most intrusive purposes, and tailor the article 14 ter information to each real purpose rather than to generic wording.

Why does the specific standard not exist yet?

Because the law itself left it to the authority. Article 14 septies of Law 21.719 provides that these standards or minimum conditions and the differentiated measures will be determined by the Agency through a general instruction. As of the date of this article, that general instruction has not been issued, which is consistent with the timetable: the Personal Data Protection Agency is created by this very law, which only enters into force on 1 December 2026 under its first transitory article.

This is worth stating clearly, because the market is full of categorical claims about a supposed official standard for SMEs. No such document exists today. Any table promising the exact list of security measures required of a Chilean micro-enterprise is getting ahead of an administrative decision that has not yet been made. That does not invalidate preparatory work, but it does require distinguishing between what the law already says and what a consultant assumes.

What you can take as settled is the framework: the duties will be enforceable from the entry into force, the grading factors are set out in the statutory text, and the Agency will have authority to specify them. The absence of the general instruction does not suspend or soften the duties; it simply leaves the controller with the burden of justifying its own criterion in the meantime.

  • In force from 1 December 2026: the duty of information and transparency under article 14 ter and the duty to adopt security measures under article 14 quinquies, enforceable against every controller.
  • Already in the statutory text: the five factors of article 14 septies, which you can apply as your own prioritization methodology.
  • Not yet in existence: the Agency's general instruction detailing the standards or minimum conditions and the differentiated measures.

Which Law 21.719 obligations do not change according to company size?

Almost all the others. The differentiation in article 14 septies of Law 21.719 concerns the standards for two duties; outside that perimeter, the text does not establish a different regime according to company size. Neither the principles, nor data subjects' rights, nor the deadlines, nor the data assignment rules have a reduced version for SMEs in Chile.

The most relevant case in day-to-day operations is rights. Article 11 requires the controller to acknowledge receipt and issue a decision no later than 30 calendar days from submission of the request, extendable only once by up to a further 30 calendar days. These are calendar days, not business days, and the deadline is identical for a micro-enterprise and for a holding company. If the request is for temporary blocking, the response is due within 2 business days and, until it is resolved, that data cannot be processed. And if the controller denies the request, it must give reasons for the refusal and inform the data subject that they have 30 business days to complain to the Agency.

The same applies downstream. Under article 41, where the controller has denied the request or has not responded within the legal deadline, the data subject may complain to the Agency in writing within thirty business days counted from receipt of the negative response or from expiry of the controller's deadline. The Agency must decide within the following ten business days whether to admit the complaint for processing — and it is deemed admitted if it does not rule within that term; once admitted, the controller has thirty calendar days, extendable by up to the same period, to respond. That procedure contains no shortened track based on company size: the administrative burden of responding properly is the same for everyone.

  • Principles under article 3: lawfulness and fairness, purpose, proportionality, quality, accountability, security, transparency and information, and confidentiality.
  • Rights and deadlines under articles 10 and 11: access, rectification, erasure, objection and portability, plus blocking, with 30 calendar days extendable only once by up to a further 30 calendar days.
  • Duty of secrecy or confidentiality under article 14 bis and the duty of protection by design and by default under article 14 quater.
  • Breaches under article 14 sexies: reporting to the Agency by the most expeditious means possible and without undue delay where there is a reasonable risk to data subjects' rights and freedoms, recording the incidents, and notifying data subjects where the breach concerns sensitive data, data on children under fourteen, or data on economic, financial, banking or commercial obligations.
  • Data assignment (transfer of controllership) under article 15: it must be recorded in writing or through any suitable electronic means, identifying the parties, the data assigned and the intended purposes; the assignee acquires the status of controller and the assignor retains it with respect to the operations it continues to carry out.
  • Engaging a third-party agent or processor under article 15 bis and the impact assessment under article 15 ter, as applicable to the processing.
  • Special rules on sensitive data under article 16 and following. And one restriction worth reviewing with counsel where background-screening practices exist: article 25 provides that data relating to criminal, civil, administrative and disciplinary infringements may only be processed by public bodies for the performance of their statutory functions, within the scope of their powers and in the cases expressly provided for by law.
  • Civil liability under article 47: the controller must compensate the pecuniary and non-pecuniary damage it causes data subjects where, in its processing operations, it breaches the principles in article 3 or the rights and obligations under the law and causes them harm. Civil actions arising from an infringement are subject to a statute of limitations of five years counted from the date the administrative decision or judgment imposing the relevant fine becomes final.

Does the sixth transitory article mean SMEs face no sanctions in the first year?

No, and this is the most frequent confusion in the Chilean market. The sixth transitory article of Law 21.719 provides that, during the first twelve months from the entry into force, where a sanction is applicable to smaller companies (as defined in Law 20.416), the Agency may impose a written reprimand. It is a power of the authority, not an immunity or a suspension of obligations.

The distinction is clean: article 14 septies governs the compliance standard, that is, how demandingly two duties must be met. The sixth transitory article governs the applicable sanction, that is, what the Agency may do if you fail to comply. These are two different planes, and confusing them leads to poor decisions, because a company can fall within that transitional sanctioning regime and still be in breach of duties that generate data subject complaints and potential civil liability.

There is also a detail that is often overlooked: the written reprimand is still recorded. Article 39 creates the National Registry of Sanctions and Compliance, administered by the Agency, public, electronic and free to access, with entries that remain public for five years. For a company that bids for public contracts or sells to corporate clients, that visibility may weigh more than the amount of a fine.

Size reappears in a third place, in the sanctioning regime under article 35. The general caps — a written reprimand or a fine of up to 5,000 UTM for minor infringements, up to 10,000 UTM for serious ones and up to 20,000 UTM for very serious ones — apply to everyone. What does not apply to everyone is the sanction calculated on annual revenue: 2% for serious infringements and 4% for very serious ones applies only where the infringer is not a smaller company (as defined in Law 20.416) and, in addition, repeats a serious or very serious infringement. The same article allows remedial measures to be ordered within a period of no more than 60 days, with a 50% surcharge if they are not complied with, and in the event of repeat infringement the fine may reach up to three times the amount.

  • Compliance standard (article 14 septies): defines how demandingly the information and security duties must be met, and is graded by five factors that the Agency will specify through a general instruction.
  • Applicable sanction (article 35 and the sixth transitory article): defines what happens if you fail to comply, and takes size into account at two specific points.
  • Publicity of the sanction (article 39): not graded by size; even a written reprimand is recorded, and entries remain public for five years.

How can you move forward today without waiting for the Agency's general instruction?

By applying proportionality to risk and documenting your criterion. If article 14 septies of Law 21.719 ties the grading to the five factors you already know, you can use those same factors as your own methodology: classify your processing activities, prioritize the higher-risk ones and record why you decided what you decided. That is consistent with the accountability principle in article 3, which requires being able to evidence compliance and not merely assert it.

The order of work we recommend to mid-sized companies and SMEs in Chile is deliberately boring, because it works: first know what data you hold, then decide where to place the effort, and only at the end buy tools. Most projects that fail start with the tool and never reach the inventory. And one useful warning: no market technical certification is mandatory under this law; it can help as a good-practice benchmark, but it does not replace analysis of the legal duties.

If your organization wants to go a step further, the law offers a voluntary route. Article 48 requires preventive actions to be adopted and article 49 allows the voluntary adoption of a compliance program with seven minimum elements, which the Agency certifies and supervises under article 51, with regulations approved by Supreme Decree No. 662 of 2025 of the Ministry of Finance and certification valid for three years. Article 39 also records in the public registry those holding valid certified prevention models, so that compliance can become a commercial asset and not just a cost.

When the general instruction is published, the sensible course will be to review the standard adopted and adjust it. But a company that reaches December 2026 with an orderly inventory, real and specific information for data subjects, signed processing contracts, a request-response procedure with the article 11 deadline under control, and a written risk criterion will be in a strong position to evidence compliance against the standard the Agency defines. This article is informational and does not constitute legal advice for a specific case: each processing activity should be assessed with professional support.

  • Inventory your processing activities: what data, on how many data subjects, for what purpose, where it is hosted and who has access.
  • Flag high-risk databases by applying the data-type factor: start with the sensitive data covered by article 16 and following.
  • Formally classify your company under the second article of Law 20.416 and keep that supporting record in writing.
  • Close out what is not graded by size: a request-response procedure with the 30 calendar day deadline under article 11 (and 2 business days for blocking), a breach protocol under article 14 sexies, and processing contracts under article 15 bis.
  • Tailor the article 14 ter information to your real purposes, not to a generic template.
  • Write an internal criterion memorandum: what measures you adopted, why they are proportionate to the risk, and what remains subject to review once the Agency issues the general instruction.

Define the standard that applies to your company, with the statutory text in hand

At AlayIAtrust we build your processing inventory, apply the five factors of article 14 septies to your specific case, and deliver a prioritized plan with the criterion documented, ready to adjust once the Agency issues its general instruction. Let's talk before 1 December 2026.

Schedule an assessment

Frequently asked questions

Does Law 21.719 require the same from an SME as from a large company?

Not in everything. Chile's Law 21.719 will apply in full to both, but its article 14 septies allows the standards or minimum conditions for the information and security duties to be graded according to five factors, including the size of the entity under Law 20.416. The other obligations have no separate regime based on size.

Which duties can be graded under article 14 septies?

Only two. Article 14 septies of Law 21.719 concerns the information duty (article 14 ter) and the security duty (article 14 quinquies). It does not authorize lowering the duty of secrecy under article 14 bis, protection by design and by default under article 14 quater, or breach reporting under article 14 sexies.

Where is company size defined for the purposes of Law 21.719?

In the second article of Law 20.416, which sets out special rules for smaller companies in Chile. Article 14 septies of Law 21.719 expressly refers to those categories, so classification does not depend on an internal perception of the business but on an already existing legal criterion.

Do the standards differentiated by company size already exist?

No. Article 14 septies establishes that these standards or minimum conditions and the differentiated measures will be determined by the Agency through a general instruction. As of the date of this article that instruction has not been issued, so the specific detail does not yet exist and it is advisable to move forward with your own criteria of proportionality to risk.

Can an SME wait for the general instruction to be issued?

That is not advisable. Law 21.719 enters into force on 1 December 2026 under its first transitory article, and the information and security duties will be enforceable from that date, with or without a general instruction. The sensible course is to implement measures proportionate to the risk and document in writing the criterion used to define them.

What does the sixth transitory article say about smaller companies?

That during the first twelve months from the entry into force of Law 21.719, where a sanction is applicable to smaller companies (as defined in Law 20.416), the Agency may impose a written reprimand. It is a power of the authority, not an immunity, and the reprimand is still recorded in the registry under article 39.

Does a written reprimand leave a public trace?

Yes. Article 39 of Law 21.719 creates the National Registry of Sanctions and Compliance, administered by the Agency, public, electronic and free to access. Entries remain public for five years, so a written reprimand will also be visible to clients, counterparties and public tender processes in Chile.

Does the sanction calculated on annual revenue apply to SMEs?

The 2% of annual revenue for serious infringements and 4% for very serious ones applies only where the infringer is not a smaller company (as defined in Law 20.416) and, in addition, repeats a serious or very serious infringement. The UTM caps in article 35 of Law 21.719 do apply to every controller.

Does company size change the deadlines for responding to ARSOP rights requests?

No. Article 11 of Law 21.719 sets a single deadline for everyone: the controller must acknowledge receipt and issue a decision no later than 30 calendar days from submission of the request, extendable only once by up to a further 30 calendar days. These are calendar days, not business days, and the deadline is not graded by size.

How do I show my standard is sufficient if the general instruction does not exist?

By documenting the analysis: what data you process, on how many data subjects, for what purpose, which Law 20.416 category you fall into, and what measures you adopted against each risk. The accountability principle in article 3 of Law 21.719 requires being able to evidence compliance before the Agency, not merely assert it.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Security

Security measures under Law 21.719

Compliance

Infringement Prevention Model: what it is and how it is certified

Law 21.719

Law 21.719: the definitive guide to comply and avoid fines

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment