← Back to blog

Law 21.719 and public bodies: what Title IV requires of municipalities, ministries and State agencies

Public bodies have their own regime under Law 21.719, distinct from the one governing companies: Title IV allows data to be processed without consent when the body acts within its legal functions, but it adds further principles, places conditions on transfers between public bodies and bases the fine on the monthly remuneration of the head of the body.

GUIDE · LAW 21.719
Short answer

Public bodies in Chile are subject to Title IV of Law 21.719: article 20 declares lawful the processing they carry out to fulfill their legal functions, within the scope of their powers, and under those conditions they act as data controllers without needing to request the data subject's consent.

The essentials in 30 seconds

  • Article 20: processing is lawful when carried out to fulfill legal functions within the scope of the body's powers, and it does not require the data subject's consent.
  • Article 21: the principles of article 3 are supplemented by the general principles of State Administration, especially coordination, probity and efficiency, with a duty of interoperability.
  • Article 44: infringements by public bodies are sanctioned with a fine of 20% to 50% of the monthly remuneration of the head of the public body, not with the UTM fines under article 35.
  • Article 45: where individual liability of officials exists, the Office of the Comptroller General opens a summary investigation; a very serious infringement under article 34 quater is deemed a serious breach of administrative probity.

Public debate around Law 21.719 has focused almost entirely on companies: consent, UTM fines, compliance programs. The public sector has been left out of the picture, and that is a problem, because Title IV of the law builds a distinct regime for State bodies, with specific lawfulness rules, additional principles, conditions for sharing data between public bodies and a liability model different from the one that governs private entities. If you want the full picture, start with our guide to the data protection law in Chile.

This article explains that regime exactly as it is written in the text of the law, citing the relevant article in the same sentence as the statement. It is written for municipal legal departments, ministries, public agencies, internal audit teams and transparency officers, who are the ones who will have to translate these rules into concrete procedures before December 1, 2026, the date on which the law enters into force under its first transitional article.

How does Law 21.719 apply to public bodies?

Law 21.719 applies to public bodies in Chile through its Title IV. Article 20 sets out the general rule: the processing of personal data carried out by public bodies is lawful when it is done to fulfill their legal functions, within the scope of their powers, in accordance with the law and with that Title. Under those conditions, the body acts as data controller and does not require the data subject's consent.

That is the most important difference from the private sector, and it is worth understanding properly because it changes the implementation work. A company starts by asking which lawful basis supports each processing activity and, frequently, ends up at consent. A municipality or a public agency starts somewhere else: the question is not whether the resident gave authorization, but whether the processing falls within the legal function that the law assigns to the body. If a municipality collects data to grant a subsidy, to inspect business licenses or to administer a social registry, the enabling title is its legal competence, not a ticked box.

Under article 20, lawfulness requires three elements to be present:

That there is a legal function of the body justifying the processing; that the processing is carried out within the scope of its powers; and that it is done in accordance with the law and with the provisions of Title IV.

Beware of the easy reading. Not requiring consent does not mean processing data without limits. The principles of article 3 — lawfulness and fairness, purpose, proportionality, quality, accountability, security, transparency and information, and confidentiality — remain in force, and article 21 confirms this. Data subject rights also remain: the controller must acknowledge receipt and issue a decision within 30 calendar days, extendable only once for a further 30 calendar days, under article 11. A public body that processes data outside its competence, or uses it for a purpose other than the one for which it was collected, infringes the law just as any company would: article 33 expressly reaches controllers governed by public or private law.

The Law 21.719 regime in Chile: private company versus public body.
DimensionPrivate companyPublic body
Basis for processing dataThe data subject's consent or another legal ground or basis rendering the processing lawfulFulfillment of its legal functions, within the scope of its powers (article 20)
Is consent required?Yes, unless another legal ground or basis rendering the processing lawful appliesNo, when the processing is carried out to fulfill its legal functions (article 20)
Applicable principlesThe principles of article 3Those of article 3 plus the general principles of State Administration, especially coordination, probity and efficiency (article 21)
Who is liableThe data controller, whether a natural or legal person, governed by public or private law (article 33)The body, with administrative liability of the head of the body (article 44) and, where applicable, of officials (articles 45 and 46)
What is the fineUp to 5,000 UTM (minor), 10,000 UTM (serious) and 20,000 UTM (very serious), under article 3520% to 50% of the monthly remuneration of the head of the infringing public body (article 44)

What additional principles must a public body comply with?

Article 21 of Law 21.719 provides that the processing of data by public bodies is governed by the principles of article 3 and, in addition, by the general principles of State Administration, especially those of coordination, probity and efficiency. This is a more demanding floor than the one applying to the private sector, with concrete operational consequences for any Chilean public body.

The three additional principles translate as follows:

Under the principle of coordination, public bodies must achieve a high degree of interoperability and consistency, so as to avoid contradictions in the information stored and repeated requests for information or documents from data subjects. Under the principle of efficiency, duplication of procedures and formalities between bodies, and between them and data subjects, must be avoided. The principle of probity, inherent to the public servant's statute, runs through the entire handling of personal data and reappears later in the liability regime of articles 45 and 46.

In practical terms: Law 21.719 turns into a legal duty something that until now was framed as an aspiration of State modernization. If an agency already holds a citizen's document or record, asking for it again at the counter ceases to be a mere administrative nuisance and comes into tension with the principles of coordination and efficiency imposed by article 21. The same applies when two units of the same body maintain different versions of the same data: consistency of stored information is a legal requirement, not just good practice.

Article 21 adds that public bodies are subject, among others, to the provisions of articles 2, 14, 14 bis, 14 ter, 14 quater, 14 quinquies, 14 sexies and 15 bis. In other words, substantive obligations under the general regime — including the duty of information and transparency and the notification of breaches of security measures — also fall on the public sector. On breaches, one point is worth clarifying because the European standard is often imported incorrectly: Chilean law does not set a 72-hour deadline, but requires notification without undue delay and by the fastest means possible, under article 14 sexies.

Can a municipality transfer data to another public agency?

Yes, and article 22 of Law 21.719 expressly regulates this. Public bodies are empowered to communicate or transfer specific personal data, or all or part of their databases, to other public bodies, provided the transfer is necessary to fulfill their legal functions and that both bodies act within the scope of their powers.

The power comes with safeguards. Article 22 imposes conditions that should be written into any information-sharing agreement:

First, the transfer must be necessary to fulfill legal functions. Second, both bodies must act within the scope of their powers. Third, the transfer must be made for a specific processing purpose, not as an open or permanent handover with no defined purpose. Fourth, the receiving body may not use the data for other purposes. And fifth, the recipient may retain the data only for as long as necessary for the specific processing for which it was requested, after which the data must be deleted or anonymized.

Article 22 also allows transfers between public bodies where required exclusively for processing whose purpose is to grant benefits to the data subject, avoid duplicate formalities or prevent repeated requests for information. This scenario is the operational counterpart of the principles of coordination and efficiency in article 21: the law permits data sharing to make life simpler for the citizen and, at the same time, pushes in that direction.

The point most often neglected in implementations is the last one. Interoperability agreements frequently define well what is handed over and for what purpose, but say little about what happens afterwards. Law 21.719 requires the receiving body to delete or anonymize the data once the specific processing that justified the transfer ends. That means setting retention periods in each agreement and keeping evidence of deletion, a layer that many inter-agency exchange flows have yet to resolve.

Which State processing activities fall under a special regime?

Article 24 of Law 21.719 defines four areas in which the processing, communication or transfer of sensitive personal data carried out by the competent public bodies is subject exclusively to the special regime established in that same article. These are areas where the Chilean legislature recognized that the general rules do not fit the function.

The four areas under article 24 are:

a) Purposes of preventing, investigating, detecting or prosecuting criminal offenses, or of executing criminal penalties, including activities of protection and prevention against threats and risks to public security, the protection of victims and witnesses, criminal analysis and criminal information reporting; with respect to this data, the law states that article 25 does not apply. b) Matters directly related to national security, national defense and the country's foreign policy. c) Processing for the sole purpose of addressing an emergency or disaster situation declared in accordance with the law, and only while that declaration remains in force. d) Processing protected by rules of secrecy, reserve or confidentiality established in their respective laws.

On point d) there is a relevant clarification: it also covers data that, in compliance with a legal obligation, public bodies must transfer to another public body or to third parties, in which case the recipient must process it while maintaining the same obligation of secrecy, reserve or confidentiality. The duty of reserve travels with the data; it does not dissolve when the data changes hands.

This is worth stating clearly, because a mistaken reading circulates frequently: a special regime does not mean exclusion from Law 21.719. Bodies operating in these areas remain within the system; what changes is the rule applicable to those specific processing activities, and only in respect of sensitive personal data in the areas listed. A police force, a prosecution service or an emergency unit is not outside the law by virtue of what it is: its other processing activities — human resources, public services, administrative systems — are governed by the ordinary rules of Title IV. And in the case of point c), the special regime lives and dies with the emergency or disaster declaration: once that declaration is no longer in force, it ceases to apply.

Who is liable and how much is paid if a public body infringes the law?

Here is the most striking element of the whole of Title IV. Article 44 provides that infringements that public bodies may commit are defined in articles 34 bis, 34 ter and 34 quater — the same catalogue of minor, serious and very serious infringements that governs the private sector — but will be sanctioned with a fine of twenty to fifty percent of the monthly remuneration of the head of the infringing public body.

It is worth underlining what that means, because several readings in circulation transpose the UTM fines of article 35 to the public sector, and that is not the case. In a public body in Chile, the fine under article 44 is not expressed in UTM nor calculated on revenue: it falls on the monthly remuneration of a natural person, the head of the agency. The amount is determined taking into account the seriousness of the infringement, the nature of the data processed and the number of data subjects affected, in addition to mitigating and aggravating circumstances.

The same article 44 establishes the duty that underpins that liability: the head of the body must ensure that the body carries out its processing operations in accordance with the principles, rights and obligations of Title IV. It adds that public bodies must comply with the measures to remedy or prevent infringements indicated by the Personal Data Protection Agency, or with the compliance or infringement-prevention programs under article 49.

The chain of liability does not end there. Article 45 provides that, if the proceeding establishes that there is individual liability on the part of one or more officials, the Office of the Comptroller General, at the Agency's request, will open a summary investigation to determine it, or will do so within the proceeding already underway. Sanctions on officials are determined in accordance with the Administrative Statute. And if the proceeding establishes that an official is liable for any of the very serious infringements under article 34 quater, that conduct will be deemed a serious breach of administrative probity.

Article 46 closes the loop with the duty of secrecy. Officials who process personal data, especially sensitive data or data relating to the commission and sanctioning of criminal, civil, administrative and disciplinary infringements, must maintain secrecy or confidentiality regarding the information they learn in the exercise of their positions and refrain from using it for a purpose other than the body's legal functions, or for their own benefit or that of third parties. Infringements of that provision will be deemed a serious breach of the principle of administrative probity.

Two clarifications on the catalogue, because they are frequently repeated incorrectly. Recidivism in serious infringements does not appear as a very serious infringement in article 34 quater: it is an aggravating circumstance under article 36, which arises when the controller has been sanctioned on two or more occasions in the last thirty months for infringement of this law. And among the very serious conducts in article 34 quater there is one written with the State directly in mind: carrying out mass processing of personal data contained in electronic registries of criminal, civil, administrative and disciplinary infringements kept by public bodies, without legal authorization.

It is also worth bearing in mind the general statute of limitations rule under article 40: actions to pursue liability for infringements of the law lapse after four years counted from the occurrence of the act giving rise to the infringement — and, in the case of continuing infringements, from the day on which the infringement ceased — while sanctions imposed lapse after three years from the date on which the decision imposing them becomes final. The statute of limitations is interrupted by notification of the commencement of the administrative proceeding.

What regime applies to Congress, the Judiciary and autonomous bodies?

Articles 54 and 55 of Law 21.719 establish a separate regime for a limited group of institutions: the National Congress, the Judiciary, the Office of the Comptroller General, the Public Prosecutor's Office, the Constitutional Court, the Central Bank, the Electoral Service and the Electoral Courts, along with the other special courts created by law.

Article 54 declares lawful the processing these institutions carry out when it is done to fulfill their legal functions, within the scope of their powers, in accordance with the special rules of their respective organic laws and with the provisions of Title IV applicable to public bodies. The exception is narrow and precise: article 14 quinquies and articles 44 to 46 are excluded insofar as they concern the intervention of the Office of the Comptroller General in determining administrative liability. Their officials must maintain secrecy, and these institutions hold the status of data controllers and do not require the data subject's consent.

Article 55 governs how rights are exercised before them. Data subjects exercise their rights in accordance with rational and fair procedures, and before the bodies each institution designates. It also establishes a different avenue for complaints:

If the Office of the Comptroller General, the Public Prosecutor's Office, the Central Bank or the Electoral Service unjustifiably or arbitrarily denies the exercise of a right, or infringes any principle of article 3 or any duty under the law causing harm, the data subject may file a complaint with the Court of Appeals under the procedure of article 43.

The practical consequence for these institutions is that implementation does not consist of waiting for instructions. Since article 54 excludes, in their case, the intervention of the Office of the Comptroller General in determining administrative liability, and article 55 refers the exercise of rights to the procedures each institution establishes, they will have to define those internal procedures themselves and have them published and operational before December 1, 2026.

Implementing Title IV in your institution

At AlayIAtrust we support municipalities, ministries and public agencies in mapping their processing activities, reviewing data transfer agreements between public bodies and preparing data subject rights procedures ahead of December 1, 2026. Write to us and we will review your institution's starting point together.

Schedule an assessment

Frequently asked questions

Does a municipality need residents' consent to process their data?

No, when the processing is carried out to fulfill its legal functions within the scope of its powers. Article 20 of Law 21.719 declares such processing lawful and provides that the public body acts as data controller without requiring the data subject's consent. All other duties under the law remain fully in force.

When does Law 21.719 start to apply to public bodies in Chile?

From December 1, 2026, under the first transitional article. The law was published in the Official Gazette on December 13, 2024, but its entry into force was deferred. As of August 2026 it is not yet in force, so public bodies are in the preparation period, not under enforceable compliance.

Can a public agency hand over its entire database to another public body?

Yes. Article 22 of Law 21.719 allows public bodies to transfer specific data or all or part of their databases to other public bodies, provided this is necessary to fulfill their legal functions, that both act within the scope of their powers, and that the transfer is made for a specific processing purpose.

What must the receiving body do once the processing ends?

Delete or anonymize the data. Article 22 of Law 21.719 allows the receiving body to retain the data only for as long as necessary for the specific processing for which it was requested, and prohibits using it for other purposes. That retention period should be set out in writing in each information-sharing agreement.

Is the fine paid by the public body or by the head of the body?

Article 44 of Law 21.719 provides that infringements by public bodies are sanctioned with a fine of twenty to fifty percent of the monthly remuneration of the head of the infringing body. The UTM fines under article 35, which apply to the general liability regime, do not apply here.

What happens if an official uses personal data for personal gain?

Article 46 of Law 21.719 requires officials to maintain secrecy and to refrain from using data for any purpose other than the body's legal functions, or for their own benefit or that of third parties. Such an infringement is deemed a serious breach of the principle of administrative probity, with the consequences set out in the Administrative Statute.

Who investigates the individual liability of officials?

The Office of the Comptroller General. Article 45 of Law 21.719 provides that, at the Agency's request, it will open a summary investigation to establish individual liability, or will do so within the proceeding already underway. If an official is found liable for a very serious infringement under article 34 quater, there is a serious breach of administrative probity.

Are the police, prosecutors and Defense excluded from Law 21.719?

They are not excluded. Article 24 places certain processing of sensitive data under a special regime: criminal prosecution and public security, national security and defense, declared emergency or disaster, and data protected by legal secrecy or confidentiality. All their other processing is governed by the ordinary rules of Title IV.

Is recidivism in serious infringements a very serious infringement?

No. This is a common mistake. Recidivism does not appear in the catalogue of very serious infringements under article 34 quater of Law 21.719: it is an aggravating circumstance under article 36, which arises when the controller has been sanctioned on two or more occasions in the last thirty months for infringement of this law.

How long does a public body have to respond to a data subject request?

Article 11 of Law 21.719 requires acknowledging receipt and issuing a decision within 30 calendar days, extendable only once for a further 30 calendar days. These are calendar days, not business days: a common confusion that can leave a body out of time if it planned its procedure counting business days.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Records

Criminal records and personal data (article 25)

Sensitive data

Sensitive data under Law 21.719: what they are and how to protect them

Law 21.719

Law 21.719: the definitive guide to comply and avoid fines

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment