← Back to blog

Law 21.719 in questions and answers: 30 queries answered, each with its article

Thirty frequently asked questions about Chile's data protection law, answered in a few lines and with the exact article that supports each answer.

Quick reference guide
Short answer

Chile's Law 21.719 enters into force on 1 December 2026 and applies to any person or organization that processes the data of natural persons. It establishes eight principles, recognizes six rights for the data subject and creates the Personal Data Protection Agency, which may impose fines of up to 20,000 UTM (monthly tax units). Here are thirty frequently asked questions, each with its article.

The essentials in 30 seconds

  • The legal date of entry into force is 1 December 2026. The bill that proposes postponing it is still pending and is not law.
  • It applies to any person or organization that processes the data of natural persons, including from abroad if it offers goods or services in Chile.
  • There are eight principles (article 3) and six data subject rights (article 4).
  • The deadline to respond to a request is 30 calendar days, extendable only once by a further 30.
  • The Personal Data Protection Agency supervises compliance; fines reach 5,000, 10,000 or 20,000 UTM depending on the severity.

Much of what is asked about Law 21.719 has a short answer and an article that supports it. The problem is that those answers circulate mixed up with those of the European regulation, and that is where the errors come from: principles the Chilean law does not name, deadlines in hours that do not exist, obligations that are voluntary. If you want the full picture, start with our guide to the data protection law in Chile.

This page brings together thirty questions, arranged by topic. Each answer cites the article of Law 19.628 as amended by Law 21.719, which is the text in force from December 2026, and links to the guide where the topic is developed. At the end there is a table with the figures and deadlines worth knowing by heart.

Who does Law 21.719 apply to, and from when?

Six questions on the scope of the law. They are the ones that decide whether everything else concerns you.

When does Law 21.719 enter into force?

The legal date is 1 December 2026. The first transitory article set the entry into force for the first day of the twenty-fourth month after publication, which took place on 13 December 2024. There is a bill that proposes moving it to 2027, but it is still pending in the Senate and is not law.

Who does the law apply to?

To every natural or legal person, including public bodies, that processes personal data (article 1). There are no exceptions by size or by sector: a company that sells only to other companies also processes the data of individuals.

Does a foreign online shop with no offices in Chile have to comply with the law?

Yes, where its operations are intended to offer goods or services to people who are in Chile, whether or not they are charged, or to monitor their behaviour (article 1 bis letter c). It must also keep an email address or other means of contact operational for data subjects and for the Agency (article 14). The details are in the guide to extraterritoriality.

Does the law protect company data?

No. It protects the data of natural persons (article 1), and the data subject is always a natural person (article 2 letter ñ). A company's registered name or RUT (tax ID number) is not personal data; the name, email address and job title of the people who work there are.

Which processing falls outside the law?

Two kinds. Processing carried out in the exercise of the freedoms to express opinions and to inform, and processing by natural persons in connection with their personal activities (article 1). The media are, however, subject to the law when they process data for a purpose other than expressing opinions and informing.

What happens to the data of a deceased person?

Their heirs may exercise the rights the law recognizes for the data subject. They may not access the data or request its rectification or erasure where the deceased person had expressly prohibited it or where a law so provides (article 4).

What is personal data and who is responsible for it?

The definitions are in article 2. They determine what information is protected and who is required to protect it.

Are a name and a RUT (tax ID number) personal data?

Yes. Personal data is any information linked or relating to an identified or identifiable natural person, and the law mentions the name and the national ID number as identifiers (article 2 letter f). A company's RUT is not, because it identifies a legal person. There are more examples in what is personal data.

What is sensitive data?

Data that reveals ethnic or racial origin, political, trade union or trade association affiliation, socioeconomic situation, ideological or philosophical convictions, religious beliefs, health, biological profile, biometric data, sexual life, sexual orientation and gender identity (article 2 letter g). As a rule, it may only be processed with express consent (article 16). See sensitive data.

For the purposes of the law, who is considered a child?

Those under fourteen. Adolescents are those over fourteen and under eighteen (article 16 quáter). Processing children's data requires the consent of their parents, of their legal representatives or of whoever has their personal care, unless the law expressly authorizes or mandates it. Adolescents are governed by the rules for adults, except for their sensitive data before the age of sixteen. See minors' data.

What is the difference between a controller and a processor?

The controller decides the purposes and means of the processing (article 2 letter n). The processor, which the law also calls a third-party agent (tercero mandatario), processes the data on behalf of the controller and in accordance with its instructions (articles 2 letter x and 15 bis). If it uses the data for a purpose other than the one it was engaged for, it becomes a controller for all legal purposes. See contracts with processors.

Is anonymized data still personal data?

No. Anonymization is an irreversible procedure and «anonymized data ceases to be personal data» (article 2 letter k). Pseudonymized data does remain personal data, because it can be attributed to its data subject again by using additional information (letter l).

Can data from publicly accessible sources be used freely?

No. The processing of data from publicly accessible sources «shall be subject to the provisions of this law» (article 2 letter i): it needs a lawful basis and must respect the principles. In addition, the data subject may object where there is no other legal ground for processing it (article 8 letter c).

What are the principles of the law?

This is where it is easy to go wrong, because the Chilean names are not the European ones.

How many principles does Law 21.719 have?

Eight, all in article 3: lawfulness and fairness, purpose, proportionality, quality, accountability, security, transparency and information, and confidentiality. It is common to see them reduced to six or seven, which is the list in the European regulation. Each one is explained in the eight principles.

Which principle requires processing only the data that is strictly necessary?

The proportionality principle (article 3 letter c): the data «must be strictly limited to what is necessary, adequate and relevant in relation to the purposes of the processing». The same principle limits the retention period. In the European regulation the equivalent idea is called minimization; the Chilean law does not use that word.

Which principle requires answering for compliance and being able to demonstrate it?

The accountability principle (article 3 letter e): those who process data are legally responsible for complying with the principles, obligations and duties of the law. It is complemented by the duty to demonstrate the lawfulness of the processing, which the law repeats in articles 3 letter a), 12 and 13. In practice it is demonstrated with policies, records and evidence of controls.

Which principle prevents data from being used for something other than what was disclosed?

The purpose principle (article 3 letter b). Data is collected for specific, explicit and lawful purposes, and may not be processed for purposes other than those disclosed. There are four exceptions: purposes compatible with the original ones, a contractual or pre-contractual relationship that justifies it, a new consent or a law that so provides.

What rights does the data subject have, and how long is there to respond?

The rights are in articles 4 to 9 and the procedure is in articles 10 and 11.

What does ARSOP stand for?

It is the Spanish acronym for access, rectification, erasure (supresión), objection and portability. Article 4 adds a sixth right, blocking. It replaces the old acronym ARCO, which did not include portability. The full process is in how to respond to ARSOP requests.

If a customer asks for their data to be deleted, which right are they exercising?

The right of erasure (article 7). It applies in six cases, including where the data is no longer necessary, where consent has been revoked and there is no other ground, or where the processing is unlawful. It does not apply, among other cases, where the data is needed to comply with a legal obligation or to perform a contract with the data subject. See the right to be forgotten in Chile.

How long is there to respond to a rights request?

Thirty calendar days from the date the request is filed, extendable only once by a further thirty calendar days (article 11). The controller must also acknowledge receipt. Failing to respond, or responding after the deadline, is a minor infringement (article 34 bis letter c). It is a serious infringement to prevent or obstruct the exercise of the right (article 34 ter letter e) and also to fail to respond in time to a reasoned request for temporary blocking (letter f).

What deadline does a public body have to respond?

The same. Article 23 refers to the procedure in article 11, with the request addressed to the head of the service: thirty calendar days, extendable by a further thirty. The rights, however, are narrower: access, rectification and objection, and erasure in one case only. Today, while the old text of Law 19.628 remains in force, the deadline to respond is two business days (article 16 of the current text). See public bodies.

Can a fee be charged for handling a request?

Rectification, erasure and objection are always free of charge. Access is free at least once per quarter; only if the data subject requests access or portability more than once in the quarter may the direct costs be charged (article 10).

Can a person refuse to have an algorithm decide for them?

Yes. Article 8 bis recognizes the right not to be subject to decisions based on the automated processing of data, including profiling, where they produce legal effects or significantly affect the person. There are three exceptions: a contract, prior and express consent, and a law. Even in those cases, the person retains the right to an explanation, to human intervention and to a review of the decision. See AI and data protection.

What obligations does anyone who processes data have?

Four questions where the usual answer is wrong or incomplete.

Is the data subject's consent always required?

No. Consent is the general rule (article 12), but article 13 allows data to be processed without it in five cases: economic and commercial obligations, a legal obligation, a contract with the data subject or pre-contractual measures, legitimate interest and the defence of a right. Choosing the right basis matters more than collecting signatures. See lawful bases.

Is it mandatory to have a data protection officer?

Not as a general rule: article 50 says the controller «may» appoint one. It becomes mandatory when the organization adopts a compliance programme, because article 49 requires it as the first element and article 6 of Decree 662 confirms it. See data protection officer.

How soon must a security breach be reported?

Law 21.719 does not set a number of hours: it requires reporting to the Agency «by the most expeditious means possible and without undue delay» where there is a reasonable risk to data subjects (article 14 sexies). The deadline of 72 hours that is usually cited comes from the European GDPR and, in Chile, from Law 21.663 on cybersecurity, whose report goes to the National CSIRT and not to the Agency. See breach notification.

When is an impact assessment mandatory?

Where the processing is likely to result in a high risk to the rights of data subjects, and always in four cases: systematic and exhaustive evaluation of personal aspects, based on automated processing or decisions, that produces significant legal effects; mass or large-scale processing; systematic monitoring of a publicly accessible area; and processing of sensitive data under the exceptions to consent (article 15 ter). Failing to carry it out when it is required is a very serious infringement (article 34 quáter letter k). See impact assessment.

Who supervises compliance and what are the sanctions?

Infringements, sanctions and procedures are in Title VII, which begins at article 33.

Which body supervises compliance with the law and imposes sanctions?

The Personal Data Protection Agency, an autonomous corporation under public law created by article 30. Its powers to supervise, to determine infringements and to sanction are in article 30 bis, letters c), d) and e). See what the Agency does.

How much are the fines?

Minor infringements are sanctioned with a written warning or a fine of up to 5,000 UTM; serious ones, with up to 10,000 UTM, and very serious ones, with up to 20,000 UTM (article 35). In the event of a repeat infringement, the fine may be tripled. For a company that is not a smaller company (micro, small or medium-sized enterprise) and that reoffends with a serious or very serious infringement, it may reach 2% or 4% of its annual revenue. For public bodies the sanction is different: a fine of 20% to 50% of the monthly remuneration of the head of the service (article 44). See fines and sanctions.

Are sanctions made public?

Yes. Article 39 creates the National Registry of Sanctions and Compliance, which is public, free of charge and electronic, and in which the sanctioned controller, the conduct, the mitigating and aggravating circumstances and the sanction are recorded. The entries are publicly accessible for five years.

Can a person claim compensation for the misuse of their data?

Yes. Article 47 requires the controller to compensate the pecuniary and non-pecuniary damage it causes by infringing the law. The action is heard in summary proceedings and may be brought once the Agency's decision upholding the complaint is final or, if there was an illegality claim, once the judgment is final. See compensation for damages.

Which figures and deadlines are worth knowing by heart?

If you have to sit an assessment, prepare a training session or review an internal procedure, these are the figures most often confused.

Figures and deadlines in Law 21.719, with the article where each is found
ItemValueWhere to find it
Entry into force1 December 2026First transitory article of Law 21.719
Principles8Article 3
Data subject rights6Article 4
Deadline to respond to a request30 calendar days, extendable once by a further 30Article 11
Response to a request for temporary blocking2 business daysArticle 11
Data subject's deadline to file a complaint with the Agency30 business daysArticles 11 and 41
ChildrenUnder 14 years of ageArticle 16 quáter
Fine cap for minor, serious and very serious infringements, without repeat infringement5,000, 10,000 and 20,000 UTMArticle 35
Repeat infringementTwo or more sanctions in the last 30 monthsArticle 36
Publicity of the sanction5 years in the public registryArticle 39
Limitation period for infringements4 yearsArticle 40
Maximum duration of proceedings before the Agency6 monthsArticles 41 and 42

Always check the unit: the law alternates between calendar days and business days, and a common mistake is to write the article 11 response deadline in business days. If you want to see how these figures turn into a work plan, continue with the compliance checklist or see how we implement Law 21.719.

Need to move from answers to a plan?

In a 30-minute assessment we review which Law 21.719 obligations you already have covered and which are missing, and we leave you with a realistic order of priorities for reaching December 2026.

Schedule an assessment

Frequently asked questions

Does Law 21.719 replace Law 19.628?

It does not repeal it: it amends it article by article. That is why the text in force from 1 December 2026 continues to be published under number 19.628, and the articles cited on this subject, such as 14 ter or 34 quáter, belong to that law in its amended version. The differences are in Law 19.628 vs Law 21.719.

Has the entry into force of Law 21.719 been postponed?

No. There is a bill, Bill 18.623-07, which proposes moving it to 1 December 2027. As of 6 October 2026 it was still at its first constitutional stage in the Senate. Until it is approved and published, the legal date is 1 December 2026.

What must a privacy policy state?

What article 14 ter lists, in twelve letters: the policy and its version; the identity of the controller and of its legal representative; the contact channel; the categories of data, the universe of persons, the recipients, the purposes and the lawful basis, with the legitimate interest where applicable; the security measures; the data subject's rights and the right to resort to the Agency; international transfers; the retention period; the source of the data; the right to withdraw consent; and automated decisions.

Can personal data be sent outside Chile?

Yes, in the cases set out in article 27: where the destination country offers an adequate level of protection, where there are contractual clauses, binding corporate rules or other instruments with adequate safeguards, or where the parties adopt a compliance model or a certification mechanism. Failing that, specific and non-habitual transfers are possible, such as those made with the data subject's express consent, and the Agency may also authorize a particular case by reasoned resolution (article 28).

Does the law treat SMEs differently?

On four points. The Agency must set the standards for complying with the information and security duties taking into account the size of the company and the volume of data (article 14 septies). In micro, small and medium-sized enterprises the owner may personally take on the tasks of the data protection officer (article 50). During the first year in force the Agency may sanction them with a written warning (sixth transitory article of Law 21.719). And the cap of 2% or 4% of annual revenue, which the law reserves for a company that reoffends with a serious or very serious infringement, does not reach smaller companies (article 35).

Does the law require keeping a record of processing activities (RoPA)?

No. The law does not mention it. What it requires of everyone is to publish the information in article 14 ter, which largely coincides with that of a record. Decree 662 asks anyone who adopts a compliance programme for a characterization of their processing operations and allows it to be done by means of a record. There is a ready-made format in the RoPA template.

How long can personal data be kept?

Only for as long as necessary to fulfil the purposes of the processing; after that it must be erased or anonymized. Keeping it for longer requires legal authorization or the data subject's consent (article 3 letter c). The law does not set a general retention period in years: each controller defines it according to the purpose and the legal obligations that apply to it.

Where can the official text of the law be read?

In the Library of the National Congress. The articles in force from December 2026 are under Law 19.628 in its updated version. The transitory provisions, which set the entry into force and the rules for the first year, are in the text of Law 21.719 as published. Both links appear in the sources of this article.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Law 21.719

Law 21.719: the definitive guide to comply and avoid fines

Fundamentals

The 8 principles of Law 21.719

Rights

How to respond to ARSOP rights requests: process and deadlines

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment