Article 16 sexies of Law 21.719 will allow geolocation data to be processed in Chile under the same lawful bases as articles 12 and 13, without requiring consent as the only route, but it will require clear, sufficient and timely information about the type of data, the purpose, the duration and any transfer to third parties.
The essentials in 30 seconds
- Article 16 sexies: geolocation may be processed under the lawful bases of articles 12 and 13. Consent is not the only route, and it pays to document which one you are relying on.
- Three information duties: the type of geolocation data that will be processed, the purpose and duration of the processing, and whether the data will be disclosed or transferred to a third party for the provision of a value-added service.
- Effective date: 1 December 2026 (first transitional article). As of July 2026 the law is not yet in force, so there is still room to put your house in order.
- Requests to delete location history: 30 calendar days to acknowledge receipt and issue a decision, extendable once by up to 30 additional calendar days (article 11).
Almost no Chilean company thinks it processes geolocation data, and almost all of them do. The app that shows the nearest branch, the GPS installed in the fleet, the courier whose position is shared with the customer in real time, the sensor that measures foot traffic in the store, the corporate phone carried by the technician in the field. All of those flows will fall under a short article of Law 21.719 that almost nobody has explained in detail so far. If you want the full picture, start with our guide to the data protection law in Chile.
Article 16 sexies does not prohibit anything. Nor does it add location to the catalogue of sensitive data or require explicit consent in every case. What it does is more uncomfortable and more useful: it requires you to state precisely what you collect, why, for how long and who you share it with. That level of detail is exactly what most Chilean privacy notices lack today.
In this guide we go through the text of the article, the lawful bases that will enable the processing, the three specific information duties, how to apply proportionality when tracking is continuous, the employment scenario of the field worker, and what to do with accumulated histories. At the end there is a checklist to work through before 1 December 2026.
What exactly does article 16 sexies say about geolocation data?
Article 16 sexies of Law 21.719 says two things. First, that the processing of a data subject's personal geolocation data may be carried out under the same lawful bases set out in articles 12 and 13. Second, that the data subject must be informed in a clear, sufficient and timely manner about three specific points. That is all, and its brevity is deceptive. Keep in mind that the rule will apply from 1 December 2026: today is time for preparation, not yet for enforcement.
The provision sits in the part of the law that sets special rules for certain categories of data, alongside sensitive data, the biometric data of article 16 ter and the data of children and adolescents of article 16 quater. Unlike those cases, the law did not add geolocation to the catalogue of sensitive data or subject it to a reinforced consent regime: it added a specific layer of information. A reasonable reading is that location was not treated as inherently sensitive, although it is unusually revealing: where you are says where you live, where you work, which doctor you see and who you meet.
The practical consequence is that in Chile location will be processed under the general rules on lawfulness plus an information layer of its own. And that layer is not satisfied by a generic line along the lines of "we use your location to improve the service". You have to be specific, and specificity is verifiable.
The sectors affected are broader than they may seem:
- Mobile apps that use location for search, delivery, safety, advertising or usage analytics.
- Vehicle fleets with telematics and GPS: transport, distribution, technical services, rental.
- Home delivery and last mile, where the courier's position is shared with the end customer.
- Retail with in-store traffic analytics, people counting or movement heat maps.
- Tracking of field workers through a corporate phone, tablet or routing application.
Do you need the user's consent to process their location?
Not necessarily. Article 16 sexies of Law 21.719 refers expressly to the lawful bases of articles 12 and 13, which means consent is one route, but not the only one. This is the point that causes the most confusion, because many teams assume that any geolocation will require an explicit "I accept".
Article 12 contains the general rule on processing, built around the data subject's consent. Article 13 provides for lawful bases other than consent. For geolocation, choosing between them is not cosmetic: it determines how you ask, what happens if the data subject objects, and how solid your position is if the Agency asks.
The golden rule is that the lawful basis is decided before the first line of code is written, not after the product is in production. And it is put in writing. If your application mixes several uses of location, for example showing nearby stores and also feeding an advertising segmentation model, each use will probably have a different lawful basis and should be capable of being switched on or off separately.
Three practical rules worth setting from the start:
- One purpose, one lawful basis, one written record. If you cannot name the one you are relying on, you are not ready to collect the data yet.
- If you choose consent, make withdrawing it as simple as giving it and make sure withdrawal actually stops the capture: it is the cleanest way to uphold the principles of lawfulness and fairness and of accountability in article 3.
- Do not reuse location collected for one purpose for a new purpose without first reviewing the lawful basis and the information given to the data subject.
What specific information does article 16 sexies require before switching location on?
Article 16 sexies of Law 21.719 requires you to inform, in a clear, sufficient and timely manner, about three things: the type of geolocation data that will be processed, the purpose and duration of the processing, and whether the data will be disclosed or transferred to a third party for the provision of a value-added service. All three, not two.
Broken down, this calls for a level of precision that most current notices do not reach. "Type of data" is not "location": it is whether you mean a single position or a full journey, fine GPS precision or approximate cell-tower precision, foreground location or background location as well. "Duration" is not "for as long as you use the service": it is a period or an objective criterion for ending it. And transfers to third parties leave no room for ambiguity: if the journey passes through a mapping, routing or analytics provider that adds value to the service, you have to say so.
These duties coexist with the general duty of information and transparency in article 14 ter. Article 16 sexies does not replace it; it complements it with requirements specific to location. Note as well that, under article 14 septies, the Agency will set out through a general instruction the minimum standards or conditions of the duty to inform, taking into account, among other factors, the size of the entity under Law 20.416.
Where this takes shape in practice:
- In apps: a dedicated screen shown before the operating system's permission dialog. The native iOS or Android permission authorizes the device's technical access; on its own it does not satisfy the information duty of article 16 sexies.
- In fleets: an information annex given to drivers and managers, detailing the device, the frequency and the retention period.
- In delivery: information for the courier about the tracking and, separately, information for the customer about what they see and for how long.
- In retail: visible signage at the store entrance where traffic analytics are in place, with a link or QR code to the full details.
- For employees: written information incorporated into the employment documentation, not a stray internal email.
How do you apply proportionality and protection by default when tracking is continuous?
Continuous location is the most intrusive scenario possible and is almost never necessary. Law 21.719 sets out the principle of proportionality in article 3 and turns it into an operational duty in article 14 quater, which requires appropriate technical and organizational measures to be applied by design, before and during the processing, and to guarantee by default that only the specific and strictly necessary data are processed.
Article 14 quater is explicit about the variables that must be controlled by default: the amount of data collected, the extent of the processing, the retention period and its accessibility. Translated into a geolocation system, those four variables have concrete, measurable levers.
Sampling frequency is the first. A record every 30 seconds and one every 10 minutes serve the same logistical purpose in many cases, and the second creates considerably less risk surface. Precision is the second: if your purpose is to know which district the vehicle is in, you do not need maximum-accuracy coordinates. The third is the geofence: instead of tracking the full journey, recording only entry and exit events for relevant zones reduces the data processed without losing operational value. The fourth is switching off: outside working hours, outside the shift, outside the active order, capture is suspended.
On top of that comes accessibility. The fact that the data exists does not mean the whole team should see it. Restricting detailed history to a specific role, and leaving the rest of the organization with aggregated or pseudonymized views, is consistent with protection by design and by default, and it also reduces the impact of any breach.
An honest warning: no configuration guarantees compliance. What does exist is a documented decision. If you record why you chose that frequency, which less intrusive alternative you ruled out and why, you have a defense. If you do not record it, you have an opinion.
- Sampling: define the minimum interval that supports the purpose and justify it in writing.
- Precision: use the coarsest level that works (district, zone, radius) before resorting to fine coordinates.
- Geofences: prefer entry and exit events over continuous tracking whenever feasible.
- Time window: switch capture off outside working hours, shift or active order.
- Access: limit who sees the detailed history and log those accesses.
| Use case | Typical purpose | What to inform (art. 16 sexies) | Proportionality limit |
|---|---|---|---|
| Mobile app with location | Show nearby points, calculate routes, verify coverage area | Whether it is single-point or continuous location, foreground or background; specific purpose; duration of the processing and of the history; transfers to mapping or routing providers | Location only while the feature is in use; no background capture unless the purpose is declared; permission revocable at any time |
| Vehicle fleet with GPS | Asset security, route efficiency, fuel and maintenance control | Type of telematics captured, frequency, retention period of the history, whether it is shared with an insurer or fleet management provider | Data tied to the vehicle rather than the person; spaced-out sampling; no capture outside working hours or during authorized personal use |
| Home delivery | Real-time order tracking and assignment of deliveries | For the courier: what is tracked and for how long. For the customer: which position they see and until when | Active tracking only during the order; customer visibility ends with the delivery; fine-grained history kept for a short period |
| In-store traffic analytics | Measure footfall, dwell time and movement for store layout design | Presence of the system, type of data captured, purpose, duration and whether a third-party analytics provider processes the information | Prefer aggregated and pseudonymized counting; avoid individual identification and matching with purchase data without a declared lawful basis |
| Field worker | Visit assignment, staff safety, evidence of services performed | Device and application used, what is recorded, purpose, duration, internal access and transfers to third parties | Only during working hours; no location during breaks or off shift; no use for purposes not declared beforehand |
Can you track field workers by GPS?
Yes, within clear limits and with prior information. Law 21.719 does not prohibit tracking field workers, but article 16 sexies will require you to inform them of the type of data, the purpose, the duration and any transfers, and article 14 quater requires the system to be designed to process by default only the strictly necessary data. Workplace geolocation is not an open licence to monitor.
The most useful operational distinction is between monitoring a resource and monitoring a person. A GPS unit that reports where the company vehicle is pursues a reasonable security and logistics purpose. The same GPS used to reconstruct a worker's entire day, including their breaks and their route home, pursues something else. The first purpose is defensible; the second is unlikely to survive a proportionality test under article 3 of the law.
Three limits worth setting in writing before installing any system: tracking operates only during working hours; the data is not used for purposes other than those declared; and access to the history is restricted to defined roles, with a record of who consulted what.
Formalization matters. Law 21.719 does not replace Chilean employment rules, so the system must be reflected in the employment documentation and communicated with the appropriate internal publicity. One useful point: article 48 requires data controllers to adopt actions aimed at preventing infringements, and article 49 also allows them to voluntarily adopt a prevention model whose internal rules must be expressly incorporated as an obligation in employment or service contracts, or in the internal regulations governed by articles 153 and following of the Labor Code, with the publicity measures of its article 156. That is the natural vehicle for setting down geolocation rules.
For processing that involves systematic tracking of individuals, relying on the impact assessment provided for in article 15 ter is a sensible decision: it is the document that shows you thought before installing.
How long can you keep location histories?
Law 21.719 does not set a specific period for geolocation histories. It sets something more demanding: article 16 sexies requires you to inform about the duration of the processing, and article 14 quater requires you to limit by default the retention period and the accessibility of the data. In other words, you define the period, you declare it and then you have to comply with it.
The real problem for Chilean companies is not the period, it is that there never was one. Fleet databases with four years of journeys, app event tables that are never purged, backups nobody can locate. A location history spanning several years is a liability, not an asset: it adds little operational value and multiplies the damage of any incident.
The practical approach is to tier it. Fine-grained detail is useful for immediate operations and can live for weeks; aggregated data is useful for analysis and can live longer without identifying anyone. When the period is up, deletion has to be effective and must also reach backups and copies held in third-party systems.
On rights: if a data subject asks for their location history to be deleted, article 11 gives you thirty calendar days from the date the request is filed to acknowledge receipt and issue a decision, extendable once by up to thirty additional calendar days. These are calendar days, not business days, and you must keep records proving the response was sent, its date and its full content. If you deny the request, the refusal must be reasoned and must state that the data subject has thirty business days to complain to the Agency.
On incidents: if a database of location histories is leaked, article 14 sexies requires you to report it to the Agency by the fastest means possible and without undue delay whenever there is a reasonable risk to the rights and freedoms of data subjects, and to keep a record of those communications. Direct communication to the data subjects is required in the cases listed in that same article, among them sensitive data; if your location history makes it possible to infer information of that nature, assume the most demanding scenario.
Checklist to work through before 1 December 2026:
- Build an inventory of every point where your organization captures location: apps, devices, sensors, integrations and providers.
- Define and document the lawful basis for each purpose, under articles 12 and 13.
- Draft the information block required by article 16 sexies: type of data, purpose, duration and transfers to third parties.
- Separate the purposes so the data subject can accept one and refuse another.
- Set the minimum sampling frequency and precision that support each purpose, and justify them in writing.
- Assess replacing continuous tracking with geofences or discrete events.
- Schedule automatic shutdown outside working hours, shift or active order.
- Define separate retention periods for fine-grained and aggregated data, and automate the purge.
- Restrict who can access the detailed history and log those accesses.
- Formalize workplace geolocation rules in the employment documentation.
- Prepare the procedure for responding to data subject requests within thirty calendar days, with a record of every response.
- Include location histories in your breach management procedure under article 14 sexies.
Does your app or your fleet capture location without you knowing whether it complies?
At AlayIAtrust we review real geolocation flows: what you capture, under which lawful basis, what you disclose and how long you keep it. The result is a concrete, prioritized action plan with deadlines, so you reach 1 December 2026 with your documentation in order. Let's talk, no strings attached.
Schedule an assessmentFrequently asked questions
Is geolocation data considered sensitive data under Law 21.719?
No. Law 21.719 does not include geolocation in the catalogue of sensitive data, but it devotes an article of its own to it, article 16 sexies, with specific information duties. In practice, if location makes it possible to infer health, beliefs or union membership, that outcome could fall under the sensitive data regime.
From when do I have to comply with article 16 sexies?
Law 21.719 will come into force on 1 December 2026, under its first transitional article. As of July 2026 it is not yet in force, so you still have room to inventory your location flows, adjust your notices and shorten retention periods before the Agency can start enforcing.
Is the iOS or Android location permission enough to comply?
It is not enough. The operating system permission authorizes the device's technical access, but article 16 sexies requires you to inform about the type of geolocation data, the purpose, the duration and whether there will be transfers to third parties. That is met with your own layer of prior information, not just the phone's native dialog.
What if I share location with a mapping or routing provider?
You have to disclose it. Article 16 sexies requires you to state whether the data will be disclosed or transferred to a third party for the provision of a value-added service. In addition, if that provider processes data on your behalf, it should be framed as a processor under article 15 bis, with written instructions and obligations.
Can I track the company vehicle outside working hours?
Only if you have a legitimate, declared purpose for that period, which is hard to sustain when the vehicle is parked and the working day is over. The principle of proportionality in article 3 and the duty of protection by design and by default in article 14 quater point towards suspending capture outside working hours.
How long can I keep location history?
Law 21.719 does not set a specific period for geolocation histories. You define one, you inform the data subject as article 16 sexies requires, and then you comply with it. Article 14 quater also requires you to limit by default the retention period and the accessibility of that data.
What should I do if a user asks to delete their location history?
You must acknowledge receipt and issue a decision within thirty calendar days from the date the request is filed, extendable once by up to thirty additional calendar days, under article 11. These are calendar days, not business days. Keep a record of the response sent, its date and its full content.
Do I need an impact assessment to process geolocation?
Law 21.719 provides for the impact assessment in article 15 ter. For continuous tracking of individuals, employee monitoring or in-store traffic analytics, carrying one out is a reasonable decision: it documents the need, the less intrusive alternatives you ruled out and the mitigation measures you ultimately adopted.
What does my company risk if it does not meet these duties?
Article 35 sets fines of up to 5,000 UTM for minor infringements, 10,000 UTM for serious ones and 20,000 UTM for very serious ones, plus measures to remedy them within a period of no more than sixty days. During the first twelve months, the Agency may issue a written warning to smaller companies, which is still recorded.
Is an infringement prevention model useful for organizing geolocation?
It helps. Article 49 allows companies to voluntarily adopt a prevention model with a data protection officer, risk identification and internal protocols. For geolocation, that model is the natural place to set sampling, retention and access rules, and to have them incorporated into contracts or into the internal regulations.
Official sources
This article is for information purposes only and does not constitute legal advice for a specific case.