← Back to blog

Compensation for personal data damages in Chile: civil liability under article 47 of Law 21.719

Beyond the administrative fine, Law 21.719 opens a civil route: compensation for personal data damages in Chile. Article 47 requires the data controller to compensate the pecuniary and non-pecuniary damage caused to the data subject, allows a claim to be filed once the Agency's decision has become final, and sets a five-year statute of limitations. This changes the risk calculus for any organization that processes data.

GUIDE · LAW 21.719
Short answer

Article 47 of Law 21.719 allows a data subject in Chile to claim compensation for pecuniary and non-pecuniary damage when the data controller breaches the principles of article 3, or the rights and obligations of the law, and causes harm. The claim may be filed once the Agency's decision is final and is subject to a five-year statute of limitations.

The essentials in 30 seconds

  • Article 47: the data controller must compensate the pecuniary and non-pecuniary damage caused to the data subject or subjects when, in its processing operations, it breaches the principles of article 3, or the rights and obligations set out in the law, and causes them harm.
  • The compensation claim may be filed once the decision that upheld the complaint before the Agency has become final, or once the judgment has become final and enforceable in the case of an illegality claim.
  • It is heard under the summary proceedings set out in articles 680 et seq. of the Code of Civil Procedure.
  • Civil actions arising from a breach of the law are subject to a five-year statute of limitations, counted from the date on which the administrative decision or the court judgment imposing the relevant fine becomes final.

Almost the entire conversation about Law 21.719 in Chile has revolved around a single number: the fine. Up to 20,000 UTM for the most serious breaches, a public register of sanctions, a Personal Data Protection Agency created by the law as the supervisory authority. It is a powerful headline, useful for unlocking budgets and setting priorities, but it leaves out the part of the law that in practice may end up costing more and that almost no one in the local market is discussing. If you want the full picture, start with our guide to the data protection law in Chile.

That part is article 47. Law 21.719 does not stop at administrative sanctions: it establishes its own civil liability regime, covering pecuniary and non-pecuniary damage, with a precise point at which a claim may be filed and a five-year statute of limitations. Put differently, the sanctioning decision can become the very basis that enables subsequent claims from one or many data subjects.

This article explains how that route works, how it differs from the fine and the public register, and what it means for the risk calculus of a CEO, a legal department, or a board. The law enters into force on December 1, 2026, so there is still time to prepare the only thing that genuinely provides a defense in court: evidence of compliance.

Can my company be sued for compensation over the misuse of personal data?

Yes. Article 47 of Law 21.719 provides that the data controller must compensate the pecuniary and non-pecuniary damage caused to the data subject or subjects when, in its processing operations, it breaches the principles of article 3, or the rights and obligations set out in the law, and causes them harm. This is a civil action, different in nature from any sanction the Agency may impose.

The wording deserves careful reading, because it defines the scope. Compensation is not triggered by any inconvenience: the text requires a breach of the rules, actual harm, and that the harm arose in the controller's processing operations. The breach may involve either the principles of article 3 — lawfulness and fairness, purpose, proportionality, quality, accountability, security, transparency and information, and confidentiality — or the rights and obligations that the law sets out elsewhere in its text.

Article 47 goes on to state that this compensation does not prevent the exercise of the other rights granted by the law. In other words, a data subject who sues gives up nothing: they may have previously filed a complaint with the Agency, may have obtained a favorable decision on their request, and may still claim for the harm suffered. The civil route adds to the others; it does not replace them.

For management, the consequence is direct. The question is no longer only how large a fine the Agency can impose, but how many affected data subjects sit behind a single incident and what damage they could prove. Article 47 expressly refers to the damage caused "to the data subject or subjects," in the plural, which opens the door to several affected individuals claiming over the same set of facts.

  • Requirement 1 — breach: failing to comply with a principle of article 3 or a right or obligation under Law 21.719.
  • Requirement 2 — harm: concrete damage suffered by the data subject, whether pecuniary or non-pecuniary.
  • Requirement 3 — that the damage arose in the data controller's processing operations.
  • Additional effect: the article 47 action does not prevent the exercise of the other rights the law grants the data subject.

What can the data subject recover: only pecuniary damage, or also non-pecuniary damage?

Both. Article 47 of Law 21.719 expressly mentions pecuniary and non-pecuniary damage. That second concept is precisely what makes this route especially relevant in privacy matters, because the typical harm from improper data processing rarely stops at an accounting loss.

Consider the usual scenarios in Chile: a breach that exposes health data, sensitive data used for a purpose the data subject never authorized, disclosure of a person's socioeconomic situation — a category Law 21.719 treats as sensitive data and one that is distinctive of the Chilean framework — or the communication of information about infractions where the action or the penalty was already time-barred, a scenario article 25 expressly prohibits. In several of those situations the data subject might have no obvious financial loss and still claim harm to their private life, their reputation, or their peace of mind.

Here it is worth being candid: Law 21.719 does not put a price on damage, nor does it set minimum or maximum compensation amounts. The amount will be determined by the court based on the evidence presented at trial. Any figure circulating today as a "standard compensation amount" in Chile is speculation, because the law is not yet in force and there is no case law under this regime.

What can be anticipated is the structure of the litigation. The claimant will seek to establish the breach — often relying on the earlier decision that already ruled on it — and then the existence and extent of the damage. The company will contest that second point, and also the connection between the breach and the alleged harm. That is where internal documentation stops being paperwork and becomes a defense.

  • Pecuniary damage: expenses, verifiable financial losses, costs incurred by the data subject as a result of the improper processing.
  • Non-pecuniary damage: harm to the data subject's private life, reputation, peace of mind, or dignity.
  • Law 21.719 sets no amounts: quantification is left to the court based on the evidence presented.

When can a claim be filed? The sequence almost no one explains

Not immediately. This is the most practically important point in article 47 of Law 21.719: the compensation claim may be filed once the decision that upheld the complaint before the Agency has become final, or once the judgment has become final and enforceable in the case of an illegality claim. There is, therefore, a prior stage.

That sequence matters for two opposing reasons. For a company it is partly good news: the article 47 action cannot be brought without a prior final decision in the terms the provision itself describes. How this specific route interacts with other actions available under the general legal framework is an open question, best reviewed case by case with legal advice and without rushing to conclusions. But it is also a serious warning, because it means the outcome of the proceeding before the Agency is no longer the end of the problem — it becomes the start of another one.

In rights protection matters, the typical path in Chile begins with article 41 of Law 21.719, which governs the data subject's complaint to the Agency when the data controller has denied a request under article 11 or failed to respond within the legal deadline. The law also provides for the administrative proceeding for breach of the law under article 42 and the judicial claim procedure under article 43. Article 47 itself refers to the illegality claim scenario, whose judgment must be final and enforceable before a civil claim can be brought.

Once that stage is closed, the civil case is heard under the summary proceedings set out in articles 680 et seq. of the Code of Civil Procedure. This is no minor detail for anyone planning ahead: summary proceedings are more concentrated than ordinary litigation, so a company will have little room to build its evidence as it goes. If the compliance evidence did not exist before the incident, it is unlikely to appear in time.

  • 1. The data subject exercises a data subject right. Article 11 of Law 21.719 requires the data controller to acknowledge receipt and issue a decision no later than 30 calendar days from the submission of the request, extendable once by up to a further 30 calendar days.
  • 2. If the company denies the request or fails to respond, the data subject files a complaint with the Agency. Article 41 requires it to be submitted in writing, in physical or electronic form, within 30 business days from receipt of the negative response or from the expiry of the controller's deadline.
  • 3. The Agency processes it: within the following 10 business days it determines whether the complaint meets the requirements to be admitted, and it is deemed admitted if no decision is issued within that period; once notified, the data controller has 30 calendar days, extendable by up to the same period, to respond; and only if there are substantial, relevant, and disputed facts may an evidentiary period of 10 business days be opened.
  • 4. If the decision upholds the complaint and becomes final — or if there was an illegality claim and the judgment becomes final and enforceable — the civil route becomes available.
  • 5. Only then does the data subject file the compensation claim, under summary proceedings pursuant to articles 680 et seq. of the Code of Civil Procedure.

How long is the limitation period for civil claims over personal data in Chile?

Five years. Article 47 of Law 21.719 provides that civil actions arising from a breach of the law are subject to a five-year statute of limitations, counted from the date on which the administrative decision or the court judgment imposing the relevant fine becomes final. The starting point is neither the date of the incident nor the date the data subject found out: it is the moment that decision becomes final.

One nuance in the wording is worth noting. To enable the claim, article 47 refers to the decision that upheld the complaint before the Agency, or to the final judgment in the illegality claim; for calculating the limitation period, it refers to the administrative decision or the court judgment imposing the relevant fine. How those two scenarios fit together in a specific case is something that practice and, in due course, the courts will have to clarify, so each situation should be reviewed with legal advice.

In any event, the way the period is calculated has a consequence that often goes unnoticed in risk committees. Considerable time can pass between the event — a breach, an improper data assignment, an unjustified refusal to delete data — and the start of the period: first the proceeding before the Agency, then any judicial claim, and only once that becomes final do the five years begin to run. A company's total window of exposure is therefore considerably longer than five years from the incident.

For a board in Chile, that translates into a concrete information governance obligation: the evidence that demonstrates compliance must survive that horizon. Records of data subject requests and the responses given, the register of security breaches, assignment and processing contracts, documented decisions on lawful bases, impact assessments. If those records are purged after two years under an internal policy, the company could reach the civil trial unable to prove what it actually did right.

Coordination between departments also needs planning. Legal usually keeps the files from the administrative proceeding; IT holds the logs and technical evidence; operations owns the data subject request workflows. If those pieces are not inventoried, the defense against an article 47 claim gets assembled at the last minute and with gaps.

  • Period: five years, under article 47 of Law 21.719.
  • Start of the period: from the date on which the administrative decision or the court judgment imposing the relevant fine becomes final.
  • Operational implication: compliance evidence retention policies must cover a horizon wider than the incident itself.

How does this compensation differ from the article 35 fine and the article 39 register?

They are three distinct consequences, each with its own logic. The article 35 fine under Law 21.719 is imposed by the Agency and paid to the State. The article 39 entry is reputational: the sanction is recorded in a public register. The article 47 compensation is set by a civil court and paid to the affected data subject. The law does not provide for one to replace another; on the contrary, article 47 expressly states that compensation does not prevent the exercise of the other rights granted by the law.

On fines, article 35 distinguishes by severity: minor breaches are penalized with a written warning or a fine of up to 5,000 UTM, serious breaches with a fine of up to 10,000 UTM, and the most serious with a fine of up to 20,000 UTM. The law provides for remedial measures within no more than 60 days and, if they are not implemented, a 50% surcharge. In the case of repeat breaches, the fine may reach up to three times the amount. The percentage of annual revenue — 2% for serious breaches and 4% for the most serious — applies only where the offender is not a smaller company (as defined in Law 20.416) and, in addition, repeats a serious or most serious breach.

Article 39 creates the National Registry of Sanctions and Compliance, administered by the Agency, public, electronic, and free to access. It lists sanctioned parties, indicating the severity, the conduct, any mitigating or aggravating factors, and the sanction imposed, and it also lists those holding valid certified prevention models. Entries remain public for five years. This is information that any client, bidder, or counterparty will be able to look up.

It is the chain of consequences that changes the risk calculus in Chile: a single breach can lead to a fine, be recorded in a public register, and, on top of that, enable civil claims from affected data subjects for the five years following the date the relevant decision becomes final. Assessing the worst-case scenario by looking only at the UTM cap underestimates the problem.

The three possible consequences of non-compliance under Law 21.719 in Chile
ConsequenceWho imposes itWhat is paid or sufferedRelevant time period
Administrative fine (article 35)The Personal Data Protection Agency, in the corresponding administrative proceedingWritten warning or a fine in UTM, paid to the State: up to 5,000 UTM (minor), up to 10,000 UTM (serious), and up to 20,000 UTM (most serious); up to three times the amount in the case of repeat breachesRemedial measures within no more than 60 days; if not implemented, a 50% surcharge
Entry in the National Registry of Sanctions and Compliance (article 39)The Agency, which administers the register — public, electronic, and free to accessNo payment: the sanctioned party is recorded along with the severity, the conduct, any mitigating or aggravating factors, and the sanction imposed. The impact is reputational and commercialEntries remain public for five years
Civil compensation (article 47)A civil court, on a claim by the data subject, under the summary proceedings of articles 680 et seq. of the Code of Civil ProcedurePecuniary and non-pecuniary damage actually caused to the data subject or subjects; paid to the data subject, not to the StateMay be filed once the decision upholding the complaint has become final, or once the judgment in the illegality claim is final and enforceable; subject to a five-year statute of limitations

How does a company prepare for this risk before December 1, 2026?

By documenting. The best defense against article 47 of Law 21.719 is being able to demonstrate, with verifiable records, that the company complied with the principles of article 3 and its legal duties. Since the civil route rests on a breach declared at an earlier stage, anything that prevents or defuses that declaration reduces both administrative and civil exposure at once.

There are four areas where, in the experience of Chilean organizations already adapting, the real risk concentrates. The first is handling data subject rights: article 11 requires acknowledging receipt and issuing a decision within 30 calendar days — not business days — extendable once by up to a further 30 calendar days, in writing and with records proving dispatch, date, and full content. If the request is denied, the data controller must give reasons for the refusal and inform the data subject that they have 30 business days to file a complaint with the Agency. A poorly reasoned refusal or silence is the natural starting point for an article 41 complaint.

The second area is data assignments. Article 15 of Law 21.719 permits assigning data with the data subject's consent and for the fulfillment of the processing purposes, and also where the assignment is necessary for the performance and execution of a contract to which the data subject is a party, where there is a legitimate interest of the assignor or the assignee under the terms of article 13(d), or where the law so provides. If the consent granted at the time of collection did not cover the assignment, it must be obtained before the assignment takes place and is treated, for all legal purposes, as a new processing operation. The assignment must be recorded in writing or through any suitable electronic means, identifying the parties, the data, and the intended purposes. If data is assigned without consent where such consent was required, the assignment is null and void and the assignee must delete all data received, without prejudice to any applicable legal liabilities.

The third area is security and breaches. Article 14 sexies requires reporting to the Agency, by the fastest available means and without undue delay, any breach of security measures resulting in accidental or unlawful destruction, leakage, loss, or alteration, or unauthorized disclosure or access, where there is a reasonable risk to the rights and freedoms of data subjects. Breaches must be recorded, and communicated to data subjects where they involve sensitive data, data of children under fourteen, or data on economic, financial, banking, or commercial obligations. This is worth clarifying because a lot of misinformation is circulating: Law 21.719 does not establish a 72-hour deadline; that standard belongs to the European regulation.

The fourth area tends to catch people off guard. Article 25 provides that data relating to the commission and sanctioning of criminal, civil, administrative, and disciplinary infractions may be processed only by public bodies in the performance of their statutory functions, within the scope of their powers, and in the cases expressly provided for by law. That puts pressure on private screening or background-checking practices that are common in Chile today, and it deserves a case-by-case review with legal advice before December 2026 — without rushing to conclusions, and taking into account each organization's activity and sector framework. The same article also prohibits the mass processing of personal data contained in the electronic infraction registers maintained by public bodies, and non-compliance constitutes a breach.

On the specific level of demand, transparency is in order: article 14 septies provides that the minimum standards or conditions for the information and security duties will be determined by considering the type of data, whether the data controller is a natural or legal person, the size of the entity under the categories of article 2 of Law 20.416, the activity it carries out, and the volume, nature, and purposes of the data processed; but those standards and the differentiated measures will be set by the Agency through a general instruction. As of July 2026 that detail does not yet exist, because it depends on a general instruction that has still to be issued. Two caveats: this differentiation does not make the obligations optional — the duty to inform and to safeguard data exists regardless, what is modulated is the applicable standard — and no market technical certification is mandatory under this law. The sensible approach is to move forward on what the law already requires clearly and leave room to adjust.

Finally, Law 21.719 offers a tool that plays directly on evidentiary ground. Article 48 requires adopting preventive actions and article 49 allows voluntarily adopting a compliance program with seven minimum elements, which the Agency certifies and supervises under article 51, with regulations approved by Supreme Decree No. 662 of 2025 of the Ministry of Finance and certification valid for three years. A certified prevention model grants no immunity and does not prevent an article 47 claim, but it constitutes structured evidence of diligence, and it is also recorded in the article 39 register.

  • Record every data subject request and the response given, with proof of dispatch, date, and full content (article 11).
  • Formalize assignments in writing or through a suitable electronic means, identifying the parties, the data, and the purposes (article 15), and distinguish an assignment from engaging a third-party agent under article 15 bis.
  • Maintain the register of breaches of security measures and the criteria used to assess the risk (article 14 sexies).
  • Review with legal counsel any processing of data on criminal, civil, administrative, or disciplinary infractions (article 25).
  • Define compliance evidence retention policies consistent with the five-year statute of limitations under article 47.

Review your civil exposure before December 1, 2026

At AlayIAtrust we help Chilean companies map their processing activities, organize how they handle data subject rights, and put in writing the compliance evidence that later holds up in court. If you want an assessment of your organization's article 47 risk, let's talk.

Schedule an assessment

Frequently asked questions

Can a data subject sue my company directly without first going through the Agency?

For the article 47 action under Law 21.719, no: the provision states that the compensation claim may be filed once the decision that upheld the complaint before the Agency has become final, or once the judgment is final and enforceable if there was an illegality claim. There is a prior stage.

Does the fine my company pays to the Agency offset the compensation owed to the data subject?

The law provides for no such offset. In Chile these are consequences of a different nature: the article 35 fine under Law 21.719 is imposed by the Agency and paid to the State; the article 47 compensation is set by a civil court and paid to the affected data subject. Both can arise from the same facts.

Can several data subjects sue over the same data incident?

Article 47 of Law 21.719 expressly refers to damage caused to the data subject or subjects, in the plural. A single final decision could therefore enable claims from multiple affected individuals, which in Chile means civil risk must be estimated across the entire universe of people involved.

Which court hears the claim, and under what procedure?

The civil courts. Article 47 of Law 21.719 provides that the compensation claim is heard under the summary proceedings set out in articles 680 et seq. of the Code of Civil Procedure, a more concentrated procedure than ordinary civil litigation, leaving little room to build your evidence during the trial itself.

When does the five-year limitation period start running?

From the date on which the administrative decision or the court judgment imposing the relevant fine becomes final, under article 47 of Law 21.719. It does not run from the incident or from when the data subject became aware of it, so a company's total exposure in Chile is longer than five years.

Is this civil liability already in force in Chile?

Not yet. Law 21.719 was published on December 13, 2024 and, under its first transitional article, enters into force on December 1, 2026. The same law creates the Personal Data Protection Agency as the supervisory authority. Until that date, article 47 does not apply.

Do smaller companies get any relief from this civil route?

The sixth transitional article of Law 21.719 allows the Agency to issue a written warning to smaller companies (as defined in Law 20.416) during the first twelve months after entry into force. It is a discretionary power, not immunity: the warning is still recorded and it does not remove article 47 civil liability.

Does having a certified prevention model stop me from being sued?

It does not. Articles 48 to 53 of Law 21.719 govern preventive actions and the voluntary compliance program that the Agency certifies and supervises, with regulations approved by Supreme Decree No. 662 of 2025 of the Ministry of Finance and certification valid for three years. Its value is evidentiary: it demonstrates documented diligence.

What evidence should be kept, and for how long?

Data subject requests and the responses to them, assignment and processing contracts, the security breach register, lawful bases, and impact assessments. Since article 47 of Law 21.719 sets a five-year limitation period counted from the final decision, retention policies in Chile must cover a longer horizon.

Can a data assignment without consent give rise to civil liability?

It can. Article 15 of Law 21.719 provides that an assignment carried out without the data subject's consent, where such consent was required, is null and void, and the assignee must delete all data received, without prejudice to any applicable legal liabilities. If it also caused harm, the article 47 discussion opens up.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Sanctions

Fines and sanctions under Law 21.719

Enforcement

Agency audits: what they will request and how to prepare

Compliance

Infringement Prevention Model: what it is and how it is certified

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment