Chile's Law 21.719 classifies infringements into three levels: minor (article 34 bis), serious (article 34 ter) and very serious (article 34 quater). The serious ones sanction processing or transferring data without a lawful basis; most very serious ones require intent, such as fraudulent processing or knowingly transferring sensitive data.
The essentials in 30 seconds
- Three levels of infringement: minor (article 34 bis), serious (article 34 ter) and very serious (article 34 quater).
- Article 35: minor, written reprimand or fine of up to 5,000 UTM; serious, up to 10,000 UTM; very serious, up to 20,000 UTM.
- Most very serious infringements require intent: six of their nine subparagraphs use the words fraudulent, maliciously, knowingly or deliberate.
- Recidivism is not a very serious infringement: it is an aggravating circumstance defined in article 36.
Almost every conversation about Law 21.719 in Chile begins and ends with the fines: 5,000, 10,000, 20,000 UTM. That is the easy part to remember and the least useful. What a legal or compliance team needs to know before December 2026 is not how much a sanction might cost, but which specific conduct in its day-to-day operations falls into each level of the catalog. And that catalog is written out, subparagraph by subparagraph, in three articles that are rarely read in full. If you want the full picture, start with our guide to the data protection law in Chile.
Articles 34 bis, 34 ter and 34 quater list the minor, serious and very serious infringements. The catalogs of serious and very serious infringements are closed lists of conduct; the system's only escape valve is subparagraph f) of the minor infringements, which covers any other non-compliance not classified as serious or very serious. Reading them in order reveals a fairly clear design, and it also explains why several claims circulating online about this regime simply are not in the text.
This article walks through the three complete lists, translates each subparagraph into business language with an everyday example, identifies the pattern that organizes each level and corrects two widely repeated errors. It closes by connecting each category with the sanction that corresponds to it under article 35.
How does Law 21.719 classify infringements in Chile?
Law 21.719 classifies infringements into three levels according to their severity: minor, serious and very serious. This is set out in article 34, and each level has its own catalog of conduct in articles 34 bis, 34 ter and 34 quater. Article 33 sets the general rule: liability falls on the data controller, whether a natural or legal person, governed by public or private law, that in its operations breaches the principles in article 3 and the rights and obligations under the law.
The logic of the scale is not arbitrary. Reading the three lists one after another reveals a fairly clear pattern, and that pattern is more useful than memorizing subparagraphs. Minor infringements penalize procedural failures: not informing, not having a place to receive a request, not responding on time. Serious infringements penalize substantive failures in the processing itself: using data without a lawful basis, for another purpose, in excess, out of date, or placing obstacles in the way of exercising rights. Very serious infringements mostly penalize improper exploitation: six of their nine subparagraphs require the conduct to be fraudulent, malicious, knowing or deliberate.
That progression matters in practice because it changes what the Personal Data Protection Agency will have to prove. For a serious infringement the fact alone suffices: processing data without a basis. For most very serious infringements a subjective element will also have to be proven. The same misused data may fall into the serious level or the very serious level depending on how it got there.
- Minor (article 34 bis): failures in information, contact channel, timely response and communication with the Agency.
- Serious (article 34 ter): processing or transferring without a lawful basis, changing the purpose, processing unnecessary or inaccurate data, and obstructing rights.
- Very serious (article 34 quater): six subparagraphs involving intent or bad faith, plus three without that marker: breaching the duty of secrecy over sensitive data, the mass processing of public records of infringements without legal authorization, and failure to comply with an Agency decision resolving a data subject's complaint.
| Level | Examples of conduct from the catalog | Does it require intent or bad faith? | Maximum sanction (article 35) |
|---|---|---|---|
| Minor — article 34 bis | Failing to inform in accordance with article 14 ter; not having an updated and functioning contact channel; responding incompletely or after the deadline; omitting mandatory communications to the Agency | No. Objective non-compliance suffices | Written reprimand or fine of up to 5,000 UTM |
| Serious — article 34 ter | Processing or transferring data without consent or another legal basis; using it for a different purpose; processing unnecessary, inaccurate or out-of-date data; obstructing the exercise of rights; processing children's and adolescents' data in breach of the law | No. None of its eight subparagraphs includes a marker of intent | Fine of up to 10,000 UTM |
| Very serious — article 34 quater | Fraudulent processing; maliciously using data for another purpose; knowingly transferring inaccurate information; breaching secrecy over sensitive data; deliberately omitting notice of a security breach; knowingly carrying out international transfers in breach of the law | Yes, in six of its nine subparagraphs. The remaining three carry no marker of intent | Fine of up to 20,000 UTM |
Which conduct constitutes minor infringements under article 34 bis?
Article 34 bis of Law 21.719 lists six minor infringements, and they all revolve around the same thing: the formal relationship with the data subject and with the Agency. Failing to inform, not having a functioning channel, not responding on time, not communicating what the law requires to be communicated. These are process failures, not judgment failures, and that is why they can be sanctioned with a written reprimand.
They should not be underestimated. In an inspection these are the easiest forms of conduct to prove, because a screenshot or the date on an email is enough. They are almost always the first to surface, and they usually coexist with more serious substantive problems.
These are the six subparagraphs, translated into day-to-day operations:
- Subparagraph a) — Failing to inform. Total or partial breach of the duty of information and transparency under article 14 ter. Example: a contact form that asks for tax ID, phone number and email without saying what they will be used for or how long they will be retained.
- Subparagraph b) — Having nowhere to receive requests. Lacking the specified postal address, email address or equivalent electronic means, updated and functioning, through which data subjects can get in touch or exercise their rights. Example: the privacy policy publishes an email address that bounces because the person in charge left the company a year ago.
- Subparagraph c) — Responding poorly or late. Failing to respond, responding incompletely or responding after the deadline to requests made by the data subject under this law. Example: an access request answered on day 45, when article 11 requires acknowledgment of receipt and a decision within 30 calendar days, extendable only once for a further 30 calendar days.
- Subparagraph d) — Failing to notify the Agency. Failing to send the Agency the communications mandatorily provided for in the law or its regulations. Example: leaving unsent a notice that the rules require to be filed and that stayed pending in someone's inbox.
- Subparagraph e) — Ignoring general instructions. Failing to comply with the general instructions issued by the Agency, in cases where such non-compliance is not sanctioned as a serious or very serious infringement. Example: not adjusting consent wording to a general criterion published by the Agency.
- Subparagraph f) — The catch-all clause. Committing any other infringement of the rights and obligations under the law that is not classified as serious or very serious. It is the system's only open door: any non-compliance that does not fit in 34 ter or 34 quater lands here as minor.
What are the serious infringements under article 34 ter?
The serious infringements under Law 21.719 are set out in article 34 ter and they strike at the heart of processing: doing it without a lawful basis, diverting it to another purpose, processing more data than necessary, processing incorrect data and placing obstacles in the way of the data subject's rights. Eight subparagraphs, no adverbs of intent. They are established by the fact itself.
That point is what most changes the internal conversation at a Chilean company. Bad faith does not have to be proven for conduct to fall into the serious level: if a marketing team uses a database collected for billing purposes, the infringement may be established even though nobody intended to break anything. Diligence and good faith may carry weight later, when calibrating the fine under the criteria in article 37, but they do not prevent the classification.
The catalog, subparagraph by subparagraph:
- Subparagraph a) — Processing without a lawful basis or changing the purpose. Processing personal data without the data subject's consent or without a legal ground or basis making the processing lawful, or processing it for a purpose other than the one for which it was collected. Example: using the customer database created for issuing invoices in a marketing campaign.
- Subparagraph b) — Transferring without authorization. Disclosing or transferring personal data without the data subject's consent in cases where such consent is required, or disclosing or transferring it for a purpose other than the one authorized. Example: sharing the email database with a business partner that will use it for its own prospecting.
- Subparagraph c) — Asking for too much. Processing personal data that is unnecessary in relation to the purposes of the processing, in breach of article 3, subparagraph c). Example: requiring marital status, occupation and number of dependents to subscribe to a newsletter.
- Subparagraph d) — Working with incorrect data. Processing personal data that is inaccurate, incomplete or out of date in relation to the purposes of the processing, unless updating it is the data subject's responsibility under the law or a contract. Example: keeping an already settled debt in an internal record that feeds commercial decisions.
- Subparagraph e) — Obstructing rights. Preventing or obstructing the legitimate exercise of the data subject's rights of access, rectification, erasure, objection or portability. Example: requiring the data subject to appear at a branch with documents the law does not ask for, in order to exercise something that could be handled by email.
- Subparagraph f) — Failing on temporary blocking. Failing to respond, responding late or denying the request without justified cause, in the case of substantiated requests for temporary blocking of processing. Example: leaving a blocking request unattended while the disputed data keeps circulating through the systems.
- Subparagraph g) — Children's and adolescents' data. Processing the personal data of children and adolescents in breach of the rules of this law. Example: an educational platform that collects and profiles minors' data without complying with the rules the law reserves for them.
- Subparagraph h) — Non-profit entities. Processing personal data without meeting the requirements established for non-profit private legal entities. The legal text goes on to set out the specific conditions for that scenario, so it is worth reading it directly before applying it to a specific case.
Which conduct constitutes very serious infringements under article 34 quater?
The very serious infringements under Law 21.719 are set out in article 34 quater and their distinguishing feature is intent. Six of their nine subparagraphs expressly incorporate a marker of intent in the legal text: fraudulent, maliciously, knowingly or deliberate. This is not a drafting detail, it is the element that separates a disorganized company from a company that took advantage, and it is probably the worst-explained nuance in the entire Chilean sanctions regime.
The three subparagraphs that lack that marker are explained by the intrinsic gravity of the conduct: breaching the duty of secrecy or confidentiality over sensitive data and over data relating to criminal, civil, administrative and disciplinary infringements; the mass processing of electronic records of infringements kept by public bodies without legal authorization; and failure to comply with an Agency decision resolving a data subject's complaint about the exercise of their rights.
The complete catalog:
- Subparagraph a) — Fraudulent processing. Processing personal data in a fraudulent manner. Example: building a database with information obtained by deception as to the real purpose of the collection.
- Subparagraph b) — Malicious diversion of purpose. Maliciously using personal data for a purpose other than the one consented to by the data subject or provided for in the law authorizing its processing. Example: deliberately reusing data from a job application process to build a commercial profile and sell it.
- Subparagraph c) — Knowingly transferring false information. Disclosing or transferring, knowingly, information about the data subject that is inaccurate, incomplete, imprecise or out of date. Example: reporting to a third party a record that the company already knows has been corrected.
- Subparagraph d) — Breaking secrecy over sensitive data. Breaching the duty of secrecy or confidentiality over sensitive personal data and data relating to the commission and sanction of criminal, civil, administrative and disciplinary infringements. Example: disclosing internally an employee's medical leave or disciplinary history.
- Subparagraph e) — Knowingly processing sensitive or minors' data in breach of the law. Processing, disclosing or transferring, knowingly, sensitive personal data or data of children and adolescents, in breach of the rules of this law. Example: targeting advertising using health data knowing there is no legal basis for doing so.
- Subparagraph f) — Deliberately concealing a security breach. Deliberately omitting the communication of breaches of security measures that may affect the confidentiality, availability or integrity of personal data. Example: detecting a leak and deciding not to report it to avoid the reputational cost.
- Subparagraph g) — Mass processing of infringement records. Carrying out mass processing of personal data contained in electronic records of criminal, civil, administrative and disciplinary infringements kept by public bodies, without legal authorization. Example: extracting and consolidating public sanction records to sell a reputation-scoring service.
- Subparagraph h) — Knowing international transfer. Knowingly carrying out international data transfer operations in breach of the rules of this law. Example: migrating a database to a foreign provider knowing that the required conditions are not met.
- Subparagraph i) — Disobeying an Agency decision. Failing to comply with an Agency decision resolving a data subject's complaint about the exercise of their rights. The legal text goes on to specify this scenario, so it is worth reviewing it directly. Example: the Agency orders a data item to be erased following a complaint and the data is still there months later.
What two things are commonly stated incorrectly about very serious infringements?
Two claims circulate frequently and neither is in the text of Law 21.719. The first is that repeating serious infringements turns the conduct into a very serious one. The second is that obstructing an Agency inspection is a very serious infringement. Neither appears in the catalog in article 34 quater, which is a closed list of nine subparagraphs.
As for recidivism, the correct location is elsewhere. Article 36 of Law 21.719 treats it as an aggravating circumstance and defines it precisely: it exists when the controller has been sanctioned on two or more occasions in the last thirty months for infringement of this law. The effect is on the amount, not on the classification. Where such recidivism applies, the law allows a fine of up to three times the corresponding amount; and if the offender is not a smaller enterprise under Law 20.416 and also commits repeat serious or very serious infringements — two conditions that must occur together — the fine may reach the higher of three times that amount or 2% of annual income from sales and services in the last calendar year in the case of serious infringements, and 4% in the case of very serious ones.
The distinction is not academic. A repeated serious infringement is still serious: it is sanctioned within the regime for serious infringements, aggravated. On its own it does not trigger the ancillary sanction of suspension under article 38, which requires fines for repeat very serious infringements within a twenty-four-month period.
As for obstructing an inspection, what does exist is something else. Article 34 bis, subparagraph e) sanctions as minor the failure to comply with the Agency's general instructions where it is not sanctioned as serious or very serious, and article 34 quater, subparagraph i) sanctions as very serious the failure to comply with an Agency decision resolving a data subject's complaint. These are different scenarios from obstructing an inspection, and they should not be cited as if they were the same thing.
- Recidivism is dealt with in article 36 as an aggravating circumstance, not in article 34 quater as an infringement.
- Recidivism aggravates the amount of the fine; it does not reclassify the conduct to a higher level.
- Obstruction of an inspection does not appear in the catalog of very serious infringements in article 34 quater.
- Failing to comply with a decision resolving a data subject's complaint is indeed very serious, under subparagraph i).
What sanction corresponds to each level of infringement?
Article 35 of Law 21.719 connects each level with its sanction: minor infringements are punished with a written reprimand or a fine of up to 5,000 UTM; serious ones with a fine of up to 10,000 UTM; and very serious ones with a fine of up to 20,000 UTM. These are ceilings, not fixed amounts, and that nuance is usually lost in the headlines.
The same article adds a practical consequence that is rarely discussed: together with the sanction, the Agency will indicate the measures needed to remedy the infringement, which must be adopted within no more than 60 days. If they are not adopted, a 50% surcharge is applied to the fine. In other words, the sanction does not end with payment.
To arrive at the specific amount, article 37 requires the Agency to apply eight criteria with prudent judgment: the seriousness of the conduct; the lack of diligence or care, in cases where that element is not taken into account in establishing the infringement; the harm caused, especially the number of data subjects affected; the economic benefit obtained, if any; whether the processing includes sensitive data or data of children and adolescents; the offender's financial capacity; sanctions previously applied by the Agency in the same circumstances; and any mitigating and aggravating circumstances that apply. The same article sets the rules on concurrence of infringements and requires the fine to be paid at the General Treasury of the Republic within ten business days from the date the decision becomes final.
On the favorable side, article 36 recognizes five mitigating circumstances: unilateral remedial actions and settlement agreements with the affected data subjects, cooperation with the Agency's administrative investigation, the absence of prior sanctions, self-reporting accompanied by the cessation or mitigation measures adopted, and having diligently complied with management and supervision duties, which is verified through the certificate issued under article 51. This last one is the only mitigating circumstance built before the incident, not after it.
Beyond the fine there are two effects worth keeping on the radar. Article 38 provides for a single ancillary sanction: where fines are imposed for repeat very serious infringements within a twenty-four-month period, the Agency may order the suspension of processing operations and activities for up to thirty days. That suspension does not affect data storage, may be partial or total, cannot be ordered where it would harm the rights of data subjects, and may be extended for successive periods of up to thirty days for as long as the order remains unfulfilled. And article 39 creates a National Registry of Sanctions and Compliance — public, free and electronic — where entries are publicly accessible for five years from the date they were made and which also records those adopting certified prevention models in force.
In the Chilean public sector the scale of conduct is the same but the sanction changes completely. Article 44 provides that infringements that public bodies may commit are defined in articles 34 bis, 34 ter and 34 quater, and are sanctioned with a fine of twenty to fifty percent of the monthly remuneration of the head of the offending public body. It is not a fine in UTM against the institutional budget: it falls on an individual.
Finally, time also runs. Article 40 establishes that actions to pursue liability are subject to a four-year statute of limitations counted from the occurrence of the act giving rise to the infringement, and from the cessation of continuing infringements; the limitation period is interrupted by notice of the commencement of administrative proceedings. Sanctions already imposed lapse after three years from the date the decision becomes enforceable. This should not be confused with the civil liability under article 47, which allows claims for pecuniary and non-pecuniary damage once the Agency's favorable decision becomes enforceable or the judgment becomes final, with a five-year limitation period counted from that moment.
- Minor: written reprimand or fine of up to 5,000 UTM.
- Serious: fine of up to 10,000 UTM.
- Very serious: fine of up to 20,000 UTM.
- A 50% surcharge on the fine if the remedial measures are not adopted within 60 days.
- Public bodies: fine of 20% to 50% of the monthly remuneration of the head of the body (article 44).
Check which level of infringement your operations are exposed to
At AlayIAtrust we map your processing activities against the catalog in articles 34 bis, 34 ter and 34 quater, and show you where you are exposed to a serious or very serious infringement before December 1, 2026. Write to us and we will arrange a review of your operations.
Schedule an assessmentFrequently asked questions
When can infringements of Law 21.719 start to be sanctioned?
Law 21.719 enters into force on December 1, 2026, under its first transitional article. Until that date the catalog in articles 34 bis, 34 ter and 34 quater is not in force and cannot be applied to conduct. The time before then is a preparation window, not a period of sanction exposure.
What is the real difference between a serious and a very serious infringement?
In Chile the central difference is the subjective element. The serious infringements in article 34 ter are established by objective non-compliance, such as processing data without a lawful basis. The very serious infringements in article 34 quater require, in six of their nine subparagraphs, a marker of intent: fraudulent, malicious, knowing or deliberate conduct.
What is the maximum fine for a very serious infringement?
Article 35 of Law 21.719 sets fines of up to 20,000 UTM for very serious infringements. If the offender also commits repeat very serious infringements and is not a smaller enterprise under Law 20.416 — both conditions together — the fine may reach the higher of three times that amount or 4% of its annual income from sales and services.
Is recidivism in serious infringements a very serious infringement?
No. Recidivism does not appear in the catalog of very serious infringements in article 34 quater of Law 21.719: it is an aggravating circumstance under article 36, which exists when the controller has been sanctioned on two or more occasions in the last thirty months for infringement of this law. It aggravates the fine, but does not reclassify the conduct.
Is obstructing an inspection a very serious infringement?
It does not appear as such in Law 21.719. The catalog in article 34 quater does not include obstruction of an inspection. What the law does provide for is failure to comply with the Agency's general instructions as a minor infringement, and failure to comply with a decision resolving a data subject's complaint as a very serious infringement.
Is a late response to a data subject request minor or serious?
It depends on which request it is. Failing to respond, responding incompletely or responding after the deadline to a data subject request is a minor infringement under article 34 bis, subparagraph c). Doing the same, or denying without justified cause, in the face of a substantiated request for temporary blocking of processing is a serious infringement under article 34 ter, subparagraph f).
What happens if a company commits several infringements at once?
Article 37 of Law 21.719 distinguishes two situations. If a single course of conduct gives rise to two or more infringements, or one is the means of committing another, a single fine is imposed based on the sanction for the most serious infringement. If two or more mutually independent infringing acts occur, the sanctions for each are cumulative.
Can my company's processing operations be suspended?
Yes, but in a narrow scenario. Article 38 of Law 21.719 allows the Agency to suspend processing operations for up to thirty days when fines are imposed for repeat very serious infringements within twenty-four months. The suspension does not affect data storage, may be partial or total, and cannot be ordered where it would harm the rights of data subjects.
Do smaller enterprises have a different regime?
They have a transitional window, not immunity. Under the sixth transitional article of Law 21.719, during the first twelve months in force the Agency may apply a written reprimand where a sanction against smaller enterprises under Law 20.416 would be appropriate. It is a discretionary power, and the reprimand is still recorded under article 39.
How are these infringements sanctioned in the Chilean public sector?
Public bodies are liable for the same conduct defined in articles 34 bis, 34 ter and 34 quater, but article 44 changes the sanction: a fine of twenty to fifty percent of the monthly remuneration of the head of the offending public body, rather than a fine in UTM against the institutional budget.
Official sources
This article is for information purposes only and does not constitute legal advice for a specific case.