← Back to blog

What is the infringement prevention model under Law 21.719 and how is it certified?

Law 21.719 defines its own compliance program in articles 48 to 53. Here we explain, without frills, what each of the seven minimum elements of article 49 requires, how certification before the Agency works and which concrete deliverables you need to have in place before 1 December 2026.

GUIDE · LAW 21.719
Short answer

Chile's Law 21.719 infringement prevention model is a compliance program that companies may voluntarily adopt to prevent infringements of the personal data protection law. Article 49 sets seven minimum elements, and the Personal Data Protection Agency certifies the model under article 51, with a validity of three years.

The essentials in 30 seconds

  • Article 49: seven minimum elements that every prevention model must contain, starting with the appointment of a data protection officer.
  • Article 48 requires companies to take preventive action; article 49 lets them formalize it voluntarily in a certifiable model, which connects with the mitigating circumstances of article 36.
  • The Agency certifies and supervises the model under article 51; according to the regulation approved by Supreme Decree No. 662 of 2025 of the Ministry of Finance, the certificate is valid for three years.
  • Valid certified models are entered in the National Registry of Sanctions and Compliance created by article 39, which is public, electronic and free of charge. Law 21.719 enters into force on 1 December 2026.

Of everything Law 21.719 brings with it, there is one piece almost nobody has explained in detail and that is probably the most useful for a legal or compliance department: the infringement prevention model. It is not an imported best practice or a foreign reference framework. It is a compliance program that Chilean law itself defines, with minimum contents set out in article 49 and a certification before the Personal Data Protection Agency governed by article 51. If you want the full picture, start with our guide to the data protection law in Chile.

That difference matters. When the legislator describes element by element what a compliance program must contain, there is no longer room for debate about the minimum scope. A board can hold management to account against a concrete list of seven items, and internal audit can check that each deliverable exists without inventing criteria of its own.

In this guide we look at what the model is, why it is voluntary but advisable, what each of the seven items of article 49 requires in a company's day-to-day practice, how certification works and its three-year validity, what Supreme Decree No. 662 of 2025 added and how all of this connects with the record of processing activities, the impact assessment and the data protection officer.

What is the infringement prevention model under Law 21.719?

The infringement prevention model under Law 21.719 is the personal data compliance program that Chilean law itself regulates in articles 48 to 53. It is a documented set of roles, procedures and controls whose purpose is to prevent the organization from committing the infringements described in articles 34 bis, 34 ter and 34 quater.

The distinctive feature in Chile is that the legislator did not stop at recommending good practice. It spread the subject across a full block of articles: article 48 establishes the duty to adopt actions aimed at preventing those infringements; article 49 describes the voluntary model and its seven minimum contents; article 50 governs the powers of the data protection officer; article 51 assigns certification and supervision to the Agency; article 52 deals with the validity of certificates and article 53 with their revocation.

It is worth fixing the calendar before going any further. Law 21.719 was published in the Official Gazette on 13 December 2024 and will enter into force on 1 December 2026, under its first transitional article. As of July 2026 the law is not yet in force, although the regulation on the prevention model has already been issued and a later reform brought forward the setup of the Agency. In other words: there is time, but the real work of building the model takes months, not weeks.

A prevention model is not the same as a privacy policy published on a website, nor as an information security manual. Three features set it apart.

  • It has minimum contents set by law: if one of the seven items of article 49 is missing, the model does not meet the requirements.
  • It is internally enforceable: the resulting internal rules are incorporated into employment contracts or into the internal regulations, with disciplinary consequences.
  • It can be certified and supervised by the authority: the Agency certifies and supervises it under article 51.

Is adopting a prevention model mandatory or voluntary?

It is voluntary, but it is not a matter of indifference. Article 48 of Law 21.719 does impose a duty: data controllers must adopt actions aimed at preventing the infringements of articles 34 bis, 34 ter and 34 quater. Article 49 adds that they may voluntarily adopt a prevention model consisting of a compliance program. In short: preventing is mandatory; formalizing that prevention in a certifiable model is an option.

That decision is usually taken at board level, and the honest conversation is one about risk management. Adopting the model connects with the mitigating circumstances of article 36 of Law 21.719, because it lets you back up diligence with documentary evidence rather than with statements. It also has a concrete reputational component: article 51 provides that the Agency include in the National Registry of Sanctions and Compliance those entities holding a valid certification, and that registry, created by article 39, is public, electronic and free to access. Any client, bidder or counterparty can consult it.

It is worth sizing up the opposite scenario without exaggerating. Article 35 grades the penalties: minor infringements are punished with a written warning or a fine of up to 5,000 UTM, serious ones with a fine of up to 10,000 UTM and very serious ones with a fine of up to 20,000 UTM. Corrective measures must be completed within no more than 60 days, with a 50% surcharge on the fine if they are not, and repeat offending can raise the fine to up to three times the amount of the infringement.

The percentage of revenue deserves a clarification, because it is often repeated incorrectly. It only comes into play when the offender is not one of the smaller companies (as defined in Law 20.416) under article two of that law and, in addition, repeats a serious or very serious infringement: in that case the fine may reach whichever is more burdensome, either triple the amount or 2% (serious infringements) and 4% (very serious infringements) of annual revenue from sales and services in the last calendar year. It is not true that every company automatically risks that percentage.

For smaller companies there is an additional nuance that is also often reported incorrectly. The sixth transitional article provides that, during the first twelve months after the law enters into force, when a penalty applies to companies classified as smaller companies (as defined in Law 20.416), the Agency may impose as a penalty a written warning stating the seriousness of the infringement, the infringing conduct and the mitigating and aggravating circumstances. It is a power, not automatic immunity; that warning is still entered in the registry of article 39 and does not release the company from substantive compliance.

  • Preventing is a duty (article 48). Adopting and certifying the model is a decision (article 49).
  • The legal benefit plays out in the mitigating circumstances of article 36, not in an exemption from liability.
  • The commercial benefit plays out in the National Registry of Sanctions and Compliance (article 39), which is public and free of charge.

What are the seven minimum elements of article 49?

Article 49 of Law 21.719 requires the model to contain at least seven elements: a) the appointment of a data protection officer; b) the definition of that officer's means and powers; c) identification of the type of information the entity processes; d) identification of the activities or processes that create or increase risk; e) specific protocols, rules and procedures; f) mechanisms for internal reporting and for reporting to the authority; and g) internal administrative penalties and complaint procedures.

Taken one by one, each item translates into a recognizable deliverable. Item a) requires formally appointing a data protection officer, with minutes or a resolution naming that person; it is not enough for someone to informally keep an eye on privacy. Item b) is what stops that appointment from being decorative: the officer's means and powers must be defined, meaning budget, headcount, access to information, independence and a reporting line to senior management.

Item c) requires identifying the type of information the entity processes, the territorial scope in which it operates, the category, class or types of data or databases it manages and a profile of the data subjects. In practice, this is an inventory or record of processing activities together with a map of data flows, including cross-border ones. Item d) calls for identifying the activities or processes, whether routine or occasional, in which the risk of committing those infringements arises or increases: recruitment, collections, marketing, video surveillance, one-off campaigns, integrations with suppliers.

Item e) brings the diagnosis down to operations: specific protocols, rules and procedures so that everyone involved in those processes carries out their tasks in a way that prevents infringement. This is where consent procedures live, along with the handling of ARSOP data subject rights — which under article 11 require acknowledging receipt and responding no later than thirty calendar days from the filing of the request, extendable once by up to thirty additional calendar days — and the procedures for engaging processors. Item f) requires internal compliance reporting mechanisms and mechanisms for reporting to the authority in the case of article 14 sexies, that is, notifying breaches to the Agency by the fastest possible means and without undue delay whenever there is a reasonable risk to the rights and freedoms of data subjects. Item g) closes the loop with internal administrative penalties and procedures for reporting or sanctioning those who fail to comply.

The seven minimum elements of article 49 of Law 21.719 and their concrete deliverable
Item of art. 49What it requiresConcrete deliverableResponsible area
a)Appoint a data protection officerAppointment minutes or resolution and a letter of appointment setting out the profile and responsibilitiesBoard or general management
b)Define the officer's means and powersOfficer's charter: annual budget, headcount, access rights, independence and reporting lineGeneral management with HR and Finance
c)Identify the information processed, territorial scope, data categories and data subjectsRecord of processing activities (RoPA) with a data map, databases and cross-border flowsData protection officer with process owners and IT
d)Identify activities or processes that create or increase riskProcessing risk matrix by process and, where applicable, an impact assessmentRisk or internal audit with the officer
e)Establish specific protocols, rules and proceduresManual of operational policies and procedures: consent, ARSOP, security, processors and suppliersOfficer with Legal and Operations
f)Mechanisms for internal reporting and for reporting to the authority (art. 14 sexies)Breach management procedure with escalation matrix, incident log and notification templates for the Agency and for data subjectsInformation security with the officer
g)Internal administrative penalties and complaint proceduresWhistleblowing channel, classification of misconduct and penalty matrix in the internal regulations, documented disciplinary procedureHR with Legal and internal audit

How is the model incorporated into employment contracts or the internal regulations?

Article 49 of Law 21.719 requires the internal rules resulting from the model to be expressly incorporated as an obligation into the employment or service contracts of all workers and service providers of the entity, including its most senior executives. The alternative offered by the same provision is to incorporate them into the internal regulations, governed by articles 153 and following of the Labor Code, with the publicity measures of article 156 of that same code.

This requirement is the one most often overlooked and the one that most quickly leaves an otherwise well-drafted model incomplete. A privacy manual that lives on the intranet does not create enforceable obligations; a contractual clause or a rule in the internal regulations does. And the explicit reference to the most senior executives is not decorative: it closes the door on liability being pushed only downward in the organization.

In practice there are two routes, and the choice depends on the size and turnover of the company. Amending contracts one by one is workable in small organizations and gives individual traceability, but it becomes unmanageable with large headcounts or high turnover. Bringing the matter into the internal regulations covers the entire workforce at once and can be updated in a single step, provided the publicity formalities of article 156 of the Labor Code are met.

One point that often remains loose: the service providers and suppliers that process data on the company's behalf. The provision refers to employment or service contracts, so the data processing annex in contracts with third parties is not an extra, it is part of complying with article 49. It should also be aligned with the processing through a third-party agent or processor governed by article 15 bis.

  • Contractual route: a data protection annex or clause in every employment and service contract, including those of the most senior executives.
  • Regulatory route: a specific chapter in the internal regulations under articles 153 and following of the Labor Code, with the publicity required by article 156.
  • Supplier route: a data processing annex plus security and breach notification obligations in contracts with processors (article 15 bis).

How is the model certified before the Agency and how long does the certification last?

Certification is granted by the Personal Data Protection Agency. Article 51 of Law 21.719 provides that the Agency certify that the prevention model meets the legal requirements, supervise it and include in the National Registry of Sanctions and Compliance those entities holding a valid certification. Under the regulation, that certificate is valid for three years.

That same article 51 referred the definition of requirements, modalities and procedures to a regulation, and entrusted its issuance to the Ministry of Finance, with the signature of the General Secretariat of the Presidency and the Ministry of Economy. That regulation exists: it was approved by Supreme Decree No. 662 of 2025 of the Ministry of Finance and went through the legality review before the Office of the Comptroller General of the Republic. It governs the implementation, certification, registration and supervision of prevention models, sets the three-year validity of the certificate and provides for its registration, identifying the data controller, its legal representative, the date and the term of validity.

The registry deserves attention of its own. Article 39 creates the National Registry of Sanctions and Compliance, created and administered by the Agency, electronic, public and free to access. It records sanctioned parties — with the seriousness of the infringement, the infringing conduct, the mitigating and aggravating circumstances and the penalty imposed — and also those holding valid certified prevention models. Entries remain public for five years. In practice, it is an open-access reputational traffic light.

On duration, two honest warnings. First, certification is not a one-off formality: article 51 includes supervision by the Agency and article 53 governs revocation of the certification, so a model that stops operating can lose its certificate before its three years are up. Second, no certification guarantees compliance or prevents penalties; it attests that the model meets the requirements, not that the company will never break the law.

It is also worth clearing up a frequent confusion. The only certification contemplated by Law 21.719 is this one, that of the prevention model before the Agency, and it is voluntary. Technical standards such as ISO 27001 or frameworks such as NIST can be excellent sources of controls and evidence of security, but they are not required by this Chilean law and do not replace the seven minimum elements of article 49.

  • Who certifies: the Personal Data Protection Agency (article 51).
  • What is certified: that the model meets the required conditions, whose minimum content is set by article 49.
  • How long it lasts: three years, under the regulation approved by Supreme Decree No. 662 of 2025.
  • Where it is recorded: the National Registry of Sanctions and Compliance (article 39), public and free of charge.
  • How it is lost: through revocation under article 53.

How does the model relate to the RoPA, the impact assessment and the data protection officer?

The model is not a project running parallel to what you are already doing for Law 21.719: it is the framework that organizes those deliverables and gives them a verifiable structure. The processing inventory feeds item c) of article 49, the impact assessment helps document item d) and the data protection officer is item a) itself, with powers governed by article 50.

The record of processing activities, or RoPA, is the base input. Item c) of article 49 requires identifying the type of information processed, the territorial scope of operation, the category, class or types of data and databases managed and a profile of the data subjects. Without that inventory there is no way to sustain the items that follow: you cannot identify risky processes if you do not know what data flows through them.

The impact assessment, governed by article 15 ter of Law 21.719, is the natural tool for documenting item d) in the most sensitive processing operations. Think of biometrics — whose processing requires, under article 16 ter, informing the data subject of the biometric system used, the specific purpose, the period during which the data will be used and how to exercise their rights — of health or socioeconomic data, of data on children and adolescents under article 16 quater, or of geolocation under article 16 sexies, which requires informing of the type of data, the purpose, the duration and whether it will be shared with a third party for a value-added service.

The officer, in turn, is the operational hub. Beyond being item a) of article 49, this is the person who in practice sustains the duties of articles 14 bis to 14 sexies: secrecy or confidentiality, information and transparency, protection by design and by default, security measures and breach management. It is worth recalling that article 14 septies instructs the Agency to determine, through a general instruction, the minimum standards or conditions for the duties of information (article 14 ter) and security (article 14 quinquies), taking into account the type of data, whether the controller is a natural or legal person, the size of the entity under article two of Law 20.416, the activity and the volume, nature and purposes of the data. That means the model of a twenty-person company and that of a bank need not look the same, even though both must cover the same seven items.

The practical reading is simple: if you have already built the RoPA, appointed the officer and have breach and ARSOP rights procedures in place, a good part of the model is built. What is usually missing is the formalization — appointments, the officer's charter, incorporation into contracts or internal regulations and the disciplinary regime — and the organized evidence to submit for certification.

  • RoPA → item c): inventory of processing activities, databases, territorial scope and profile of data subjects.
  • Impact assessment (article 15 ter) → item d): risk by process, especially for sensitive, biometric, children and adolescents and geolocation data.
  • Data protection officer (article 49 item a and article 50) → governance of the model and support for the duties of articles 14 bis to 14 sexies.

Want to build a certifiable prevention model before December 2026?

At AlayIAtrust we work alongside Chilean companies to design the infringement prevention model under Law 21.719: processing inventory, risk matrix, breach and ARSOP rights procedures, governance for the data protection officer and a file ready to submit for certification. Write to us and we will assess your organization's starting point together.

Schedule an assessment

Frequently asked questions

Is the infringement prevention model mandatory in Chile?

No. Article 49 of Law 21.719 states that data controllers may adopt it voluntarily. What is mandatory is the duty of article 48: to adopt actions aimed at preventing the commission of the infringements of articles 34 bis, 34 ter and 34 quater. The model is the orderly, certifiable way of fulfilling that duty.

When will I be able to certify the model before the Agency?

Law 21.719 will enter into force on 1 December 2026 in Chile, and the certification of article 51 is granted by the Personal Data Protection Agency under the regulation approved by Supreme Decree No. 662 of 2025 of the Ministry of Finance. The sensible thing today is to build the model so that the file is ready when the time comes.

How long does the prevention model certification last?

The certification is valid for three years, under the regulation approved by Supreme Decree No. 662 of 2025. Article 52 of Law 21.719 governs the validity of certificates and article 53 the revocation of the certification, so keeping it requires the model to stay in operation and up to date, not merely to obtain it once.

Where is a certified model recorded?

In the National Registry of Sanctions and Compliance of article 39 of Law 21.719, created and administered by the Agency, electronic, public and free to access. Article 51 provides that the Agency include there the entities holding a valid certification; the regulation specifies that the data controller, its legal representative and the term of validity be identified.

Does holding a certified model exempt a company from penalties?

No. No model guarantees immunity or perfect compliance. Its practical effect in Chile is twofold: it can provide evidence of diligence in view of the mitigating circumstances of article 36 of Law 21.719, and it leaves a public record of the valid certification in the registry of article 39. The company remains liable for its substantive infringements.

Do I need a data protection officer in order to have a model?

Yes. Item a) of article 49 of Law 21.719 requires the appointment of a data protection officer as the first minimum element, and item b) requires defining that officer's means and powers. Article 50 governs the officer's powers. Without an officer with real resources, the model does not meet the requirements of article 49.

Does an ISO 27001 certification work instead of the article 49 model?

It does not replace it. The only certification contemplated by Law 21.719 is that of the prevention model before the Agency, governed by article 51, and it is voluntary. Standards such as ISO 27001 provide useful controls and evidence of security, but they are not required by this Chilean law and do not substitute the seven minimum elements of article 49.

What does Supreme Decree No. 662 of 2025 regulate?

It approves the regulation provided for in article 51 of Law 21.719, issued by the Ministry of Finance. It establishes the requirements, modalities and procedures for the implementation, certification, registration and supervision of prevention models. It also sets the three-year validity of the certificate and went through the legality review before the Office of the Comptroller General of the Republic.

Can smaller companies also certify their model?

Yes. Article 49 of Law 21.719 allows data controllers to adopt the model voluntarily, without distinguishing by size. In addition, the sixth transitional article empowers the Agency to apply, during the first twelve months in force, a written warning to smaller companies (as defined in Law 20.416); that warning is still recorded.

Must the model appear in employment contracts?

Yes. Article 49 of Law 21.719 requires the internal rules of the model to be expressly incorporated as an obligation into the employment or service contracts of all workers and service providers, including the most senior executives, or else into the internal regulations governed by articles 153 and following of the Labor Code.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Enforcement

Agency audits: what they will request and how to prepare

Sanctions

Fines and sanctions under Law 21.719

Governance

Is a DPO mandatory in Chile? The Data Protection Officer

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment