← Back to blog

Differences between Law 21.719 and the GDPR: a guide for international companies.

The GDPR set the gold standard for privacy, and Law 21.719 aligns Chile with it. Learn the similarities, the key differences, and how to adapt your company to both frameworks.

Comparison between Chile's Law 21.719 and the European GDPR
Short answer

Chile's Law 21.719 draws on the European GDPR but does not copy it. It differs on three points that are often misreported: there is no 72-hour breach deadline, the Chilean sensitive data list includes socioeconomic situation, and the data protection officer is voluntary under article 50.

The essentials in 30 seconds

  • Law 21.719 is strongly inspired by the GDPR, but they are not identical.
  • They share principles, data subject rights, proactive accountability, impact assessments and breach notification.
  • The key differences are in territorial scope, the supervisory authority and the fines regime.
  • Fines: the GDPR reaches EUR 20M or 4% of global turnover; Law 21.719 reaches 20,000 UTM (up to 60,000 for recidivism) or a percentage of revenue in Chile.
  • Complying with the GDPR is a big advantage, but the Chilean law requires specific adaptations before December 1, 2026.

In the digital age, where data flows across borders, the protection of personal information has become a global concern and a legislative priority. Companies operating internationally face the challenge of complying with a range of privacy regulations, each with its own particularities. In this context, the European Union's General Data Protection Regulation (GDPR) has established a gold standard, influencing legislation around the world. With the enactment of its Law 21.719, Chile has taken a significant step to modernize its data protection framework, closely aligning it with the principles of the GDPR. If you want the full picture, start with our guide to the data protection law in Chile.

For companies with a presence or interests in Chile and Europe, understanding the similarities and, crucially, the differences between Law 21.719 and the GDPR is fundamental. It is not only about avoiding fines, but about building trust with customers and operating ethically in a global market. In this article we break down both regulations, offer a clear comparison table, and provide an essential guide so that international companies can effectively adapt to the Chilean requirements. For the full picture of the Chilean regulation, see our definitive guide to Law 21.719.

An overview: Law 21.719 and the GDPR

Before diving into the comparisons, it is essential to understand the essence of each regulation.

The GDPR: the global privacy standard

The General Data Protection Regulation (EU Regulation 2016/679) entered into force in May 2018 and is the strictest data privacy and security law in the world. Although it is a European Union law, its scope is extraterritorial, meaning that it affects any organization that processes the personal data of EU citizens, regardless of where it is located. Its fundamental principles include:

  • Lawfulness, fairness, and transparency: data must be processed lawfully, fairly, and transparently.
  • Purpose limitation: data must be collected for specified, explicit, and legitimate purposes.
  • Data minimization: only the data that is strictly necessary should be collected.
  • Accuracy: data must be accurate and kept up to date.
  • Storage limitation: data must be kept only for as long as necessary.
  • Integrity and confidentiality: data must be processed ensuring appropriate security.
  • Accountability: organizations are responsible for demonstrating compliance.

The GDPR grants individuals a set of robust rights, including the rights of access, rectification, erasure (the right to be forgotten), restriction of processing, data portability, and objection. In addition, it imposes strict obligations on data controllers and processors, such as the need to obtain explicit consent, carry out impact assessments (DPIA), and notify security breaches.

Law 21.719: Chile's response to modern privacy

Law 21.719, published on December 13, 2024, is the new Chilean regulation governing the protection and processing of personal data. This law updates the former Law No. 19.628 and seeks to align Chile with international standards, including principles and rights similar to those of the GDPR. Its main objectives are to strengthen the rights of data subjects and to establish a robust legal framework for the handling of their data by any entity that processes personal data within the national territory.

The guiding principles of Law 21.719 are very similar to those of the GDPR, including lawfulness, purpose, proportionality, quality, security, and accountability. The law also broadens and strengthens data subjects' rights, recognizing the data subject rights (Access, Rectification, Cancellation, and Objection) and the right to portability. A fundamental change is the creation of a Personal Data Protection Agency as the oversight body, with the power to monitor compliance and apply sanctions.

Key similarities

  • Fundamental principles: both share lawfulness, fairness, transparency, purpose limitation, minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
  • Data subjects' rights: both grant robust rights over personal data, including access, rectification, erasure, objection, and portability.
  • Explicit consent: in general, both require free, specific, informed, and unambiguous consent, especially for sensitive data.
  • Impact assessments: both require assessments for high-risk processing (DPIA under the GDPR, EIPD under Law 21.719).
  • Breach notification: the obligation to notify the supervisory authority and, in certain cases, the data subjects is common to both.
  • The role of the DPO / data officer: both provide for a data protection officer, with differences in whether it is mandatory and in its title.
  • International transfers: both regulate transfers to countries without an adequate level of protection, requiring safeguards.

Key differences

While the similarities are notable, the differences can have a significant impact on the compliance strategy of an international company:

  • Territorial scope: the GDPR has a more explicit and broader extraterritorial scope. Law 21.719 applies to processing carried out in Chile, although it may also have implications for foreign companies that process the data of people in Chile or that offer goods and services in the country.
  • Supervisory authority: the GDPR relies on the European Data Protection Board (EDPB) and authorities in each member state. Law 21.719 creates a new Personal Data Protection Agency as the sole national oversight authority.
  • Amount and calculation basis of fines: GDPR fines can reach up to 20 million euros or 4% of annual global turnover, whichever is higher. Law 21.719 sanctions most-serious violations with up to 20,000 UTM, extendable to up to 60,000 UTM only for recidivism; the 2% or 4% percentage is calculated only on revenue from sales and services in Chile and only for recidivism of companies that are not small businesses. We go deeper in Fines and sanctions under Law 21.719.
  • Legal basis: although both recognize several bases, the interpretation of each may vary. The GDPR is stricter in its definition of legitimate interest.
  • Sensitive data: both define special categories, but the specific lists have slight variations.
  • Implementation timelines: the GDPR has been in force since 2018. Law 21.719 was published on December 13, 2024, and compliance is mandatory from December 1, 2026.

Be careful comparing fines. A common mistake is to equate the GDPR's 4% (on global turnover) with Law 21.719. In Chile, the 2% or 4% percentage applies only in case of recidivism, only to companies that are not small businesses, and on revenue from sales and services in Chile, not on worldwide turnover. For most companies, the cap remains the UTM amount of the corresponding category.

Comparison table: Law 21.719 vs. GDPR

Law 21.719 and the GDPR: where they align and where the Chilean text says otherwise
FeatureLaw 21.719 (Chile)GDPR (European Union)
Entry into force1 December 2026, first day of the twenty-fourth month after publication (first transitory article)25 May 2018
Territorial scopeEstablishment in Chile, or offering goods or services to people in Chile or monitoring their behaviour (article 1 bis)Establishment in the EU, or offering goods or services or monitoring behaviour of people in the EU (article 3)
Data subject rightsSix: access, rectification, suppression, opposition, portability and blocking (article 4)Access, rectification, erasure, restriction, portability and objection
Response deadline30 calendar days, extendable once by 30 more (article 11)One month, extendable by two further months
Breach notificationWithout undue delay and by the most expedient means; no deadline in hours (article 14 sexies)72 hours to the supervisory authority, under article 33 of the GDPR
Notice to data subjectsOnly where it affects sensitive data, data of children under 14, or economic and financial data (article 14 sexies)Where the risk to rights is high
Sensitive dataIncludes socioeconomic situation, absent from the European catalogue (article 2 letter g)Special categories under article 9, without socioeconomic situation
Data protection officerVoluntary: the controller "may" appoint one (article 50)Mandatory in the situations set out in article 37
Maximum fine20,000 UTM for a very serious infringement; up to triple with recidivism, and 2% or 4% of annual revenue only if the company is also not a smaller enterprise (article 35)20 million euros or 4% of global annual turnover, whichever is higher
Impact assessmentMandatory for high risk, with four always-required cases (article 15 ter)Mandatory for high risk (article 35)
Certified prevention modelVoluntary, certifiable before the Agency and carrying mitigating effect (articles 49, 51 and 36 number 5)No direct equivalent; codes of conduct and certifications exist

Adaptations for international companies with a presence in Chile

For companies that already comply with the GDPR, adapting to Law 21.719 will be a smoother process, but not without challenges. Some key considerations:

  1. Data mapping and gap assessment: identify where the data you process in Chile is stored and compare your practices against Law 21.719.
  2. Review of legal bases: make sure you have a valid legal basis for each processing activity and that you can demonstrate it.
  3. Updating policies and notices: reflect the law's specific requirements, including the new Agency and the expanded rights of Chilean data subjects.
  4. Consent management: review your mechanisms to ensure they meet the law's standards, especially for sensitive data and transfers.
  5. Processes for rights: adapt your internal processes to handle data subject rights and portability requests within the deadlines.
  6. Security measures: ensure appropriate technical and organizational measures, including incident management and breach notification.
  7. Contracts with third parties: update the contracts with vendors that process data on your behalf.
  8. Training and awareness: train your staff in Chile on the law's requirements.
  9. The role of the DPO: assess the need to designate a data protection officer in Chile.
  10. Continuous monitoring: establish audits to keep your practices up to date and compliant.

Data transfers between Chile and the European Union deserve special attention: see our analysis of extraterritoriality and international transfers under Law 21.719.

Conclusion: a step forward in global data protection

Chile's Law 21.719 and the European GDPR represent two fundamental pillars in the global data protection landscape. While the GDPR has laid the groundwork and greatly influenced Chilean legislation, Law 21.719 establishes a robust framework adapted to the country's reality, with its own particularities.

For international companies, understanding these differences and similarities is not only a matter of legal compliance, but an opportunity to strengthen trust with their customers, operate more ethically, and consolidate their reputation in a market that is increasingly privacy-conscious. To align your privacy program with both frameworks, let's talk in an assessment.

Do you operate in Chile and Europe?

We help you align your GDPR program with Law 21.719. A 30-minute assessment.

Schedule an assessment

Frequently asked questions about Law 21.719 and the GDPR

Is Law 21.719 the same as the GDPR?

They are not identical, although Law 21.719 is strongly inspired by the GDPR. They share principles, data subject rights, proactive accountability, impact assessments and breach notification. The main differences are in the territorial scope, the design of the supervisory authority and the regime and calculation basis of the fines.

If I already comply with the GDPR, do I automatically comply with the Chilean law?

Not automatically, but you start with a big advantage. Complying with the GDPR covers a large part of the principles and obligations of Law 21.719. Even so, you must adapt policies and notices to the new Chilean Agency, review legal bases under the local law, adjust data subject rights processes and verify the safeguards for transfers to and from Chile.

Are the fines under Law 21.719 equivalent to those of the GDPR?

No. The GDPR reaches up to 20 million euros or 4% of annual global turnover, whichever is higher. Law 21.719 sanctions most-serious violations with up to 20,000 UTM, extendable to up to 60,000 UTM for recidivism; the 2% or 4% percentage is calculated only on revenue from sales and services in Chile and only for recidivism of companies that are not small businesses.

Does the Chilean law apply to foreign companies?

Law 21.719 applies to data processing carried out in Chile and may have implications for foreign companies that process the data of people in Chile or that offer goods and services in the country. The GDPR has a more explicit extraterritorial scope, but both can reach organizations outside their territory.

When does Law 21.719 take effect?

Law 21.719 was published on December 13, 2024, and compliance is mandatory from December 1, 2026, after a 24-month adjustment period. The GDPR, by contrast, has been in force since May 2018.

Did Chile copy the GDPR?

It drew on it, but the text differs on concrete points. Law 21.719 sets no deadline in hours for breach notification, includes socioeconomic situation among sensitive data, and makes appointing an officer voluntary. Citing GDPR rules as if they were Chilean is the most common error in this field.

Does the 72-hour breach rule apply in Chile?

No. The 72 hours belong to article 33 of the GDPR. Article 14 sexies of Law 21.719 requires reporting to the Agency by the most expedient means available and without undue delay, without setting a number of hours. It is a conduct standard that may prove stricter.

Is a DPO mandatory in Chile as in Europe?

No. Article 50 of Law 21.719 states that the controller "may" appoint a personal data protection officer. In Europe, article 37 of the GDPR makes it mandatory in three situations. In Chile it becomes required only within the voluntary prevention model of article 49.

Which sensitive data category does Chile have that Europe lacks?

Socioeconomic situation. Article 2 letter g) of Law 21.719 expressly includes it among sensitive data, alongside ethnic origin, political or union affiliation, religious beliefs, health, biometric data and sexual life and orientation. Article 9 of the GDPR does not cover it.

Are rights answered within the same deadline?

Not exactly. Article 11 of Law 21.719 sets thirty calendar days from the request being filed, extendable once by thirty further calendar days. The GDPR works with one month extendable by two additional months, which is a wider overall window.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Law 21.719

Law 21.719: the definitive guide to comply and avoid multimillion-dollar fines

Law 21.719

Extraterritoriality and international transfers under Law 21.719

Sanctions

Fines and sanctions under Law 21.719: what you need to know to avoid them

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment