In Chile, Law 21.719 requires reporting a breach to the Personal Data Protection Agency “without undue delay”, with no deadline in hours. Law 21.663 requires certain institutions to report to the National CSIRT within 3 hours, update at 72, and file a final report within 15 calendar days.
The essentials in 30 seconds
- Two separate laws, two separate bodies: the Agency and ANCI.
- Law 21.719 sets no 72-hour deadline: it requires reporting without undue delay.
- The 3 h / 72 h / 15 day scheme comes from article 9 of Law 21.663.
- Law 21.663 only reaches essential services and vital importance operators.
- One incident can require reporting to both, plus notifying data subjects.
Chile passed two laws in quick succession that touch but do not overlap. Law 21.663, the Cybersecurity Framework Law, created the National Cybersecurity Agency and an incident response system. Law 21.719 reformed personal data protection and created the Personal Data Protection Agency. If you want the full picture, start with our guide to the data protection law in Chile.
The practical problem appears on the day of the incident. The security team knows the cybersecurity deadlines, the legal team knows the data protection ones, and nobody is sure whether both apply. The short answer is that they do, when the conditions of each are met.
This article places both duties side by side, with the text of each law, so that the incident response protocol is written before the crisis rather than during it.
Who does each law apply to in Chile?
The difference in scope is the key point and it is constantly overlooked. Law 21.719 applies to any controller processing personal data, regardless of size or sector. A small professional services firm with a customer base is within scope.
Law 21.663, by contrast, has a narrow scope. Its article 4 applies it to institutions providing services classified as essential and to those classified as vital importance operators. It is not a general law for every company in the country.
Article 4 lists the activities that constitute an essential service when provided by private institutions: electricity generation, transmission or distribution; transport, storage or distribution of fuels; drinking water or sanitation; telecommunications; digital infrastructure; digital services and third-party managed IT services; land, air, rail or maritime transport; banking, financial services and payment means; social security benefits administration; postal and courier services; institutional healthcare provision; and pharmaceutical production or research.
Services provided by State Administration bodies, by the National Electrical Coordinator and those provided under public service concession are also essential services. The National Cybersecurity Agency may classify further services as essential by reasoned resolution.
What are the reporting deadlines under each law?
Here is the most repeated error in Chilean data protection content: attributing a 72-hour breach notification deadline to Law 21.719. That deadline is not in the data protection law. It comes from the European General Data Protection Regulation and, in Chile, partially coincides with one stage of the cybersecurity scheme.
Article 14 sexies of Law 21.719 requires reporting to the Agency “by the most expeditious means possible and without undue delay”. There is no number of hours. That standard is looser on paper and stricter in practice, because it requires justifying every hour of delay.
Article 9 of Law 21.663 does have a clock, and it is a three-stage scheme reported to the National CSIRT for cyberattacks and incidents with significant effects.
| Law 21.719 (personal data) | Law 21.663 (cybersecurity) | |
|---|---|---|
| Reported to | Personal Data Protection Agency | National CSIRT (National Cybersecurity Agency) |
| Who must report | Every personal data controller | Essential services and vital importance operators (art. 4) |
| Trigger | Security breach posing reasonable risk to rights and freedoms | Cyberattack or incident with significant effects |
| First deadline | Without undue delay, by the most expeditious means possible | 3 hours from becoming aware: early alert |
| Second deadline | Not applicable | 72 hours: update with severity, impact and indicators of compromise |
| Special deadline | Not applicable | 24 hours for a vital importance operator whose essential service is affected |
| Final report | Not a separate stage | 15 calendar days from the early alert |
| Notice to individuals | Yes, in three cases under art. 14 sexies | Not contemplated in art. 9 |
When must the affected individuals be notified?
This duty exists only in Law 21.719 and has no equivalent in article 9 of the cybersecurity law. Article 14 sexies restricts it to three specific data categories, and that precision is what almost no Chilean guide reproduces correctly.
Notice to data subjects applies where the breach concerns sensitive personal data, data of children under fourteen, or data relating to economic, financial, banking or commercial obligations. Outside those three cases the duty is to report to the Agency, not to issue public notice.
The law also sets how that notice must read: in clear and simple language, specifying the affected data, the possible consequences and the remedial or protective measures adopted. Where notifying each data subject is not possible, it is done by disseminating or publishing a notice.
- Sensitive personal data.
- Data of children under fourteen.
- Data on economic, financial, banking or commercial obligations.
Are the security measures each law requires the same?
They are similar, but Law 21.719 has its own catalogue and it is worth reading, because a security programme designed only against Law 21.663 can leave gaps under the data protection law.
Article 14 quinquies requires measures ensuring “the confidentiality, integrity, availability and resilience of data processing systems”, and expressly mentions pseudonymisation and encryption of personal data, the ability to guarantee those four properties on an ongoing basis, and the ability to restore availability and access to the data quickly after a physical or technical incident.
The standard is relative, not absolute. The law requires considering the state of the art, implementation costs, the nature, scope, context and purposes of the processing, and the likelihood and severity of the risks. The same measure may be sufficient for one company and insufficient for another.
How do you write a protocol covering both laws?
The most common design flaw is having two separate protocols, one owned by security and one by legal, triggered through different paths. In a real incident that separation costs hours, and under article 9 of Law 21.663 the first three hours are already a legal deadline.
A single protocol starts with a classification question at time zero: whether the incident affects personal data, whether the organisation falls within article 4 of Law 21.663, and whether the affected data falls into any of the three categories of article 14 sexies. Those three answers determine who must be notified and how urgently.
Record-keeping is an obligation in itself. Article 14 sexies requires recording these communications, describing the nature of the breach, its effects, the categories of data, the approximate number of affected data subjects and the measures adopted to manage it and prevent future incidents.
- Decide at minute zero whether personal data is involved.
- Know in advance whether the company falls under article 4 of Law 21.663.
- Prepare reporting templates beforehand: three hours is no time to draft from scratch.
- Record the whole incident: the record is an article 14 sexies obligation.
Does your incident protocol cover both laws?
In 30 minutes we check whether your response plan properly separates the two reporting duties and who executes each one on time.
Schedule an assessmentFrequently asked questions
Does Law 21.719 have a 72-hour breach notification deadline?
No. Article 14 sexies requires reporting to the Agency by the most expeditious means possible and without undue delay, without setting a number of hours. The 72-hour figure belongs to the reporting scheme in article 9 of Law 21.663 on cybersecurity, which is a different law with a different recipient.
What is the National CSIRT?
It is the computer security incident response team to which Law 21.663 requires reporting cyberattacks and incidents with significant effects. It sits within the National Cybersecurity Agency created by that law, and is distinct from the Personal Data Protection Agency.
Is my company subject to Law 21.663?
Only if it provides services classified as essential or was classified as a vital importance operator under article 4. The law lists activities such as energy, water, telecommunications, digital infrastructure, transport, banking, healthcare and pharmaceuticals. Law 21.719, by contrast, applies to any company processing personal data in Chile.
Can one incident trigger both laws?
Yes, and it is the most likely scenario in a regulated company. An attack that compromises systems and leaks customer data requires reporting to the National CSIRT under article 9 of Law 21.663 and to the Personal Data Protection Agency under article 14 sexies of Law 21.719.
What is the 24-hour deadline in Law 21.663?
It is a special deadline. Where the affected institution is a vital importance operator and the provision of its essential services is affected by the incident, the update must be delivered to the National CSIRT within a maximum of 24 hours from becoming aware, instead of the general 72.
What if the incident is still ongoing at 15 days?
Article 9 addresses it expressly: the final report is replaced by a status report at that point, and the final report is filed within fifteen calendar days from the date the incident has been managed.
Do affected customers have to be notified of a leak?
Only in three cases under article 14 sexies of Law 21.719: where the breach affects sensitive data, data of children under fourteen, or data on economic, financial, banking or commercial obligations. In other cases the duty is to report to the Agency, not to notify publicly.
Does complying with Law 21.663 mean complying with Law 21.719?
No. A robust cybersecurity programme helps a great deal with the security duty in article 14 quinquies, but Law 21.719 also requires a lawful basis, a record of processing activities, responses to data subject rights and transparency. They are different planes of the same problem.
Which security measures does Law 21.719 name expressly?
Article 14 quinquies mentions pseudonymisation and encryption of personal data, the ability to guarantee ongoing confidentiality, integrity, availability and resilience of systems, and the ability to restore availability and access to data quickly after a physical or technical incident.
When does each law apply in Chile?
Law 21.663 on cybersecurity is already operative and the National Cybersecurity Agency began activities in January 2025. The personal data obligations of Law 21.719 apply from 1 December 2026.
Official sources
- Law 21.719 — official text, Library of the National Congress
- Law 21.663 Cybersecurity Framework Law — official text
- Law 19.628 consolidated with the amendments of Law 21.719
- National Cybersecurity Agency
This article is for information purposes only and does not constitute legal advice for a specific case.