← Back to blog

Statute of limitations for infringements under Law 21.719: four years, three years and five years

The statute of limitations for infringements under Law 21.719 is not a single time limit: article 40 sets four years to pursue liability and three years for sanctions already imposed, while the civil action under article 47 lapses after five years. Here we explain how each one is counted, what changes for continuing infringements, and what it all means for your document retention policy.

GUIDE · LAW 21.719
Short answer

Chile's Law 21.719 sets two time limits in article 40: actions to pursue liability for infringements are subject to a four-year statute of limitations counted from the occurrence of the event, or from the day the infringement ceased if it is continuing, and sanctions already imposed lapse three years after the decision becomes final and enforceable.

The essentials in 30 seconds

  • Four years to pursue liability for the infringement, counted from the occurrence of the event (article 40).
  • For continuing infringements the clock starts on the day the infringement ceased, not on the day it began.
  • Three years for sanctions imposed, counted from the date the decision becomes final and enforceable.
  • Five years for the civil action under article 47: civil exposure outlives the closing of the administrative file.

Almost everything that turns up in search results about the statute of limitations for administrative infringements was written for other legal systems, where time limits are graded according to the seriousness of the conduct. That scheme does not apply in Chile. Law 21.719 has its own rule, concentrated in article 40, and it works on a different logic: a single time limit to pursue any infringement, whether minor, serious or very serious, and a separate time limit for sanctions already imposed. If you want the full picture, start with our guide to the data protection law in Chile.

The confusion is not a minor one. Those time limits determine how long your organization remains exposed to sanction proceedings, how long a fine imposed by the Personal Data Protection Agency can be enforced and, a point that is often left out, how long a data subject can bring a civil claim against you after the administrative case has ended. They also settle something very concrete for the records management team: how long it makes sense to keep the evidence proving that you complied.

The law takes effect on 1 December 2026, under its first transitory article, so these clocks are not yet running. This is precisely the moment to understand them properly and calibrate the retention policy before they start to count.

How long is the statute of limitations for infringements under Law 21.719 in Chile?

Actions to pursue liability for infringements of Law 21.719 lapse after four years in Chile, counted from the occurrence of the event that gave rise to the infringement. The same article 40 adds that for continuing infringements the period is counted from the day the infringement ceased, and that sanctions imposed lapse after three years counted from the date on which the decision imposing the sanction becomes final and enforceable.

It helps to read the rule as three independent clocks that start at different moments and measure different things. The first measures the time available to pursue liability for the infringement, through the administrative proceedings handled by the Personal Data Protection Agency. The second measures how long a sanction already imposed remains enforceable. The third, which lives in article 47 rather than article 40, measures the time the affected data subject has to claim compensation for damages.

One point that often gets lost: the four-year period in article 40 is a single term and is not graded according to the seriousness of the infringement. Law 21.719 classifies infringements as minor, serious and very serious in article 34, but that classification determines the fine range, a written warning or a fine of up to 5,000 UTM for minor infringements, up to 10,000 UTM for serious ones and up to 20,000 UTM for very serious ones under article 35, not the length of the statute of limitations. A minor infringement and a very serious one lapse after the same period.

The three clocks, in order of appearance:

  • Clock 1 — Enforcement: four years to pursue liability for the infringement (article 40).
  • Clock 2 — Sanction: three years for the sanction already imposed, counted from the date the decision becomes final and enforceable (article 40).
  • Clock 3 — Compensation: five years for the civil action for damages, counted from the date the administrative decision becomes final and enforceable or the judgment imposing the fine becomes final (article 47).
The three limitation periods applicable to an infringement of Law 21.719
What lapsesTime limitWhen the clock startsWhat interrupts it
Actions to pursue liability for infringements (art. 40)4 yearsFrom the occurrence of the event that gave rise to the infringement. For continuing infringements, from the day the infringement ceasedNotification of the commencement of the corresponding administrative proceedings
Sanctions imposed (art. 40)3 yearsFrom the date on which the decision imposing the sanction becomes final and enforceableArticle 40 provides for interruption in connection with notification of the commencement of administrative proceedings; it does not set a separate interruption rule for this period
Civil action for compensation for damages (art. 47)5 yearsFrom the date the administrative decision becomes final and enforceable or the judgment imposing the fine becomes finalLaw 21.719 does not set a special interruption rule for this action, which is heard under the summary procedure of articles 680 and following of the Code of Civil Procedure

When does the clock start if the infringement is a continuing one?

For continuing infringements the four-year period is counted from the day the infringement ceased, not from the day it began. That is the express rule of article 40 of Law 21.719 and, in practice, the single most important nuance in this whole area: non-compliance that persists over time does not begin to lapse while it is still occurring.

The consequence is counterintuitive for many teams. If processing that began without a lawful basis is still running six years later, and the conduct qualifies as continuing, the action will not have lapsed: the clock only starts once that processing ceases. Something similar can happen with a database that remains out of date, or with a channel for exercising rights that was never enabled. As long as the conduct persists, so does the exposure.

Law 21.719 does not define what a continuing infringement is, and here it is worth being candid: the classification will depend on how the Agency and the courts interpret it in each case. What you can do right now is identify which instances of non-compliance in your organization are, by nature, ongoing states rather than single acts. That distinction changes the risk calculation completely.

The following are examples of conduct from the statutory catalogue that can extend over time. Whether any of them actually qualifies as a continuing infringement will, in any event, depend on the particular case:

  • Processing personal data without the data subject's consent or without a legal basis or ground making the processing lawful, on a sustained basis (article 34 ter, letter a).
  • Processing personal data that is inaccurate, incomplete or out of date in relation to the purposes of the processing, unless updating it is the data subject's responsibility under the law or the contract (article 34 ter, letter d).
  • Failing to specify an up-to-date and operational postal address, email address or equivalent electronic means through which data subjects can make contact or exercise their rights (article 34 bis, letter b).
  • Persistently failing to comply with the general instructions issued by the Agency, in cases where this is not sanctioned as a serious or very serious infringement (article 34 bis, letter e).

What interrupts the statute of limitations for an infringement of Law 21.719?

The statute of limitations is interrupted by notification of the commencement of the corresponding administrative proceedings. That is what article 40 of Law 21.719 states, and it is the only interrupting event the rule mentions. Neither a complaint from a data subject, nor an informal query, nor a press report produces that effect: what the law recognizes is formal notification that proceedings have begun.

This has direct operational value. The notification date is a data point your organization must record precisely and preserve, because it marks the moment when elapsed time stops counting in the controller's favor. In a defense file, the difference between a notification in March and one in September can be the difference between an actionable infringement and a time-barred one.

It is worth distinguishing interruption from other dates that Law 21.719 uses for different purposes and that often get mixed into the analysis. None of the following is a limitation period, although all are counted in months or years and all are worth mapping:

  • Thirty months: the window for recidivism as an aggravating circumstance, which exists when the controller has been sanctioned on two or more occasions within that period for infringement of this law (article 36, letter a).
  • Twenty-four months: the period in which repeated very serious infringements allow the Agency to order, as an ancillary sanction, the suspension of processing operations and activities for up to thirty days (article 38).
  • Five years: the period during which entries in the National Registry of Sanctions and Compliance are publicly accessible, counted from the date the entry was made (article 39).
  • Ten business days: the deadline to pay the fine at the General Treasury of the Republic, counted from the date the Agency's decision becomes final (article 37).

Do sanctions imposed and civil action lapse after the same period?

No. Sanctions imposed lapse after three years counted from the date the decision imposing them becomes final and enforceable, under article 40 of Law 21.719, whereas the civil action for compensation lapses after five years counted from the date the administrative decision becomes final and enforceable or the judgment imposing the fine becomes final, under article 47. Where the trigger is the same, civil exposure extends two years beyond administrative exposure.

The second period is the one most often underestimated. Article 47 of Law 21.719 provides that the controller must compensate the financial and non-financial harm caused, and that the action is brought once the Agency's favorable decision becomes final and enforceable or the judgment becomes final, and is heard under the summary procedure of articles 680 and following of the Code of Civil Procedure. In practical terms: once the administrative front closes, the civil front opens and stays open for five years.

For a risk committee, that asymmetry changes the conversation. A company may have paid the fine, corrected the conduct and archived the case, and still be within the window in which an affected data subject can sue. If the infringement involved many people, and article 37 requires the harm caused and, in particular, the number of affected data subjects to be taken into account among the criteria for setting the fine, the aggregate civil exposure can comfortably exceed the administrative one.

The practical reading, in three sentences:

  • Paying the fine closes the administrative chapter, not the civil one.
  • The final and enforceable decision is the starting point of the five-year civil clock, not its end point.
  • The evidence that is useful for a civil defense is usually the same evidence used in the administrative proceedings: destroying it when the case closes is an expensive mistake.

How long should you keep your compliance evidence?

Law 21.719 does not set a retention period for compliance evidence, and any source that gives you an exact figure is making it up. What you can do is align your document policy with the periods in article 40 and article 47: if exposure can extend up to five years after a final and enforceable decision, the evidence should outlast that window.

Here a real tension appears, and it is worth naming plainly. Law 21.719 includes proportionality and purpose among the principles set out in its article 3. Keeping everything just in case, indefinitely, is itself a risk of infringement: processing personal data that is unnecessary in relation to the purposes of the processing, in breach of the proportionality principle, is classified as a serious infringement in article 34 ter, letter c.

A useful clarification: the catalogue of principles in article 3 of Law 21.719 does not include a principle called "storage limitation", as other legal systems do. In Chile the same idea is channeled through the principles of purpose and proportionality. The practical effect is similar, but citing the right provision matters when you have to justify an internal policy.

The way out is not to choose between keeping and deleting, but to separate two document universes. One is the personal data of data subjects, subject to proportionality and purpose. Quite another is the evidence that you complied: records of decisions, policy versions, minutes, responses to data subject requests, access logs. That second universe can have its own retention horizon and, in many cases, can be minimized or dissociated to reduce the volume of associated personal data.

Four concrete decisions for the retention policy:

  • Define an explicit evidentiary retention purpose, distinct from the original purpose of the processing, and document it.
  • Set the retention horizon for evidence using the longest applicable period as a reference: the five years under article 47 from a potential final and enforceable decision.
  • Minimize the content: keep the record of the act (date, decision, person responsible, lawful basis relied on) and not necessarily the full set of personal data involved.
  • Record precisely the dates that start or interrupt the clocks: occurrence of the event, cessation of continuing conduct, and notification of the commencement of proceedings.

What mistakes come up again and again about the statute of limitations under Law 21.719?

The most frequent mistake is applying time limits that are not Chilean. Much of the Spanish-language content on the statute of limitations for data protection infringements describes foreign regimes, in which time limits are graded according to the seriousness of the conduct. In Chile, article 40 of Law 21.719 sets a single four-year period to pursue liability, without distinguishing between minor, serious and very serious infringements.

The second mistake is counting the period from the moment the authority becomes aware of the event. Article 40 does not say that: it says from the occurrence of the event that gave rise to the infringement and, for continuing infringements, from the day the infringement ceased. The authority's awareness is not the starting point of the clock.

The third is treating the lapsing of the sanction as if it were a deadline to challenge it. The three years in article 40 are counted from the date the decision becomes final and enforceable and relate to the sanction already imposed. They have nothing to do with the procedures in articles 41, 42 and 43, which are governed by their own rules.

And a fourth mistake, very widespread although not strictly about the statute of limitations: it is often said that recidivism in serious infringements amounts to a very serious infringement. That is not the case. The catalogue of very serious infringements is in article 34 quater of Law 21.719 and does not include it; recidivism is an aggravating circumstance under article 36, letter a, which exists when the controller has been sanctioned on two or more occasions in the last thirty months for infringement of this law. The distinction matters because recidivism increases the fine range without changing how the conduct is classified.

  • Time limits graded by the seriousness of the infringement come from comparative law, not from Law 21.719.
  • The period is counted from the event, not from the moment the authority finds out.
  • The recidivism window (thirty months) and the repeated very serious infringements window (twenty-four months) are not limitation periods.
  • The lapsing of administrative liability does not, on its own, extinguish civil risk under article 47.

Review your time limits before they start running

Law 21.719 takes effect on 1 December 2026. Now is the time to calibrate your document retention policy, identify which instances of non-compliance would be continuing in nature, and put on record the evidence you will need if proceedings are ever opened. At AlayIAtrust we support Chilean organizations through that work. Let's talk.

Schedule an assessment

Frequently asked questions

After how many years do infringements of Law 21.719 lapse?

Actions to pursue liability for infringements of Law 21.719 in Chile lapse after four years, counted from the occurrence of the event that gave rise to the infringement. If the infringement is a continuing one, the period is counted from the day it ceased. This is set out in article 40.

And what about sanctions that have already been imposed?

Sanctions imposed lapse after three years, counted from the date on which the decision imposing the sanction becomes final and enforceable, under article 40 of Law 21.719. It is a different period from the four-year one: one looks at pursuing the conduct, the other at the sanction already decided.

What counts as a continuing infringement?

Law 21.719 does not define it, so its classification will be left to the Agency and the courts in each case. Broadly, it refers to non-compliance that extends over time for as long as the conduct persists. Its practical effect is decisive: the four-year period in article 40 is counted from the day the infringement ceased.

What interrupts the statute of limitations?

Notification of the commencement of the corresponding administrative proceedings interrupts the statute of limitations, under article 40 of Law 21.719. It is the only interrupting event the rule mentions. That is why the exact date of that notification should be recorded in the compliance file and preserved.

Does the lapsing of administrative liability leave the company free of civil risk?

No. Article 47 of Law 21.719 allows the data subject to claim compensation for financial and non-financial harm, and that action lapses after five years counted from the date the administrative decision becomes final and enforceable or the judgment imposing the fine becomes final. Civil risk outlives the closing of the administrative front.

Are the limitation periods found in foreign sources useful here?

Not for Chile. Much of the content available in Spanish describes foreign regimes, in which the statute of limitations is graded according to the seriousness of the infringement. In Chile, article 40 of Law 21.719 applies, with a single four-year period to pursue liability, whatever the classification of the conduct.

Does the four-year period change with the seriousness of the infringement?

No. Law 21.719 classifies infringements as minor, serious and very serious in article 34, and that classification determines the fine range under article 35, not the length of the statute of limitations. Article 40 sets a single four-year period to pursue liability.

How long should I keep compliance evidence?

Law 21.719 does not set a period. As a practical criterion, evidence proving compliance should outlast the periods in article 40, four and three years, and in article 47, five years, without conflicting with the purpose and proportionality principles in article 3, which limit the retention of personal data.

Are these periods already running today?

Not yet. Law 21.719 takes effect on 1 December 2026, under its first transitory article, and as of August 2026 it is not yet in force. The article 40 periods will operate once the law is in force and the Personal Data Protection Agency can exercise its sanctioning powers.

Is recidivism counted on the same clock as the statute of limitations?

No, it is a different period. Article 36, letter a of Law 21.719 treats recidivism as existing when the controller has been sanctioned on two or more occasions in the last thirty months for infringement of this law, and it operates as an aggravating circumstance, not as a very serious infringement. It has nothing to do with the four years in article 40.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Liability

Damages for misuse of personal data

Enforcement

Agency audits: what they will request and how to prepare

Sanctions

Fines and sanctions under Law 21.719

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment