← Back to blog

The 8 principles of Law 21.719, one by one

The principles are not decorative preamble to Law 21.719: they are the standard against which the Agency will measure any processing. Article 42 states expressly that sanction proceedings are opened for breach or violation of the article 3 principles.

Fundamentals
Short answer

Chile's Law 21.719 establishes eight principles in article 3: lawfulness and fairness, purpose, proportionality, quality, accountability, security, transparency and information, and confidentiality. They sit in subparagraphs (a) to (h) and are the direct basis of the Agency's sanctions regime.

The essentials in 30 seconds

  • There are eight, not six or seven: subparagraphs (a) to (h) of article 3.
  • The lawfulness principle imposes a burden of proof on the controller, not just a duty.
  • Proportionality includes a time limit: data is kept only as long as necessary.
  • The confidentiality duty survives the end of the relationship with the data subject.
  • Article 42 allows sanctions for breaching these principles directly.

Several lists of “the principles of the data protection law” circulating in Chile actually reproduce those of the European General Data Protection Regulation. They are similar but do not match: article 3 of Law 21.719 has its own wording, its own order and its own count. If you want the full picture, start with our guide to the data protection law in Chile.

The precision matters because these principles are not doctrine. Article 42 defines the administrative procedure for infringement as the one determining infringements “for breach or violation of the principles established in article 3”. They are the entry point to the fines regime.

What follows is each principle with what it literally requires and what it means in the operations of a Chilean company.

Lawfulness and fairness: why is this the hardest principle?

Subparagraph (a) of article 3 states that personal data may only be processed lawfully and fairly, and adds a sentence that changes everything: “The controller shall be able to demonstrate the lawfulness of the personal data processing it carries out”.

That second sentence reverses the burden of proof. Processing data correctly is not enough: you must be able to demonstrate it to the Agency, with documentation, when they ask. A company can be complying in fact and still be exposed simply because it has no way to evidence it.

In practice this is what makes the record of processing activities the first deliverable of any implementation in Chile. Without that inventory, demonstrating lawfulness does not exist.

Purpose: can I use the data for something other than what I disclosed?

Subparagraph (b) requires data to be collected for specified, explicit and lawful purposes, and processing to be limited to those purposes. The general rule is that data may not be processed for purposes other than those disclosed at collection.

The law itself opens four listed exceptions, and they are worth knowing because they are more generous than usually assumed: processing for purposes compatible with those originally authorised; the existence of a contractual or pre-contractual relationship between the data subject and the controller justifying processing for a different purpose, provided it falls within the purposes of the contract or is consistent with prior negotiations; a fresh consent from the data subject; and where the law so provides.

The second exception is the most useful in real operations, and also the easiest to overstretch. The limit is that the new use must stay within the purposes of the contract or of the prior dealings.

  • Purposes compatible with those originally authorised.
  • A contractual or pre-contractual relationship justifying the different purpose.
  • Fresh consent from the data subject.
  • Where the law so provides.

Proportionality: how long can I keep the data?

Subparagraph (c) has two layers usually read as one. The first concerns quantity: the data processed must be strictly limited to what is necessary, adequate and relevant in relation to the purposes of the processing.

The second concerns time, and it is the one that hits legacy systems hardest. Data “may be retained only for the period of time necessary to fulfil the purposes of the processing, after which it must be deleted or anonymised”. A longer period requires legal authorisation or the data subject's consent.

This turns the retention policy into an obligation derived from a principle, not an optional good practice. Keeping everything indefinitely “just in case” breaches article 3(c).

Quality and accountability: what do these two add?

Subparagraph (d) requires data to be accurate, complete, current and relevant in relation to its provenance and the purposes of the processing. It is the principle connecting to the right to rectification: when a data subject corrects a record, the controller is not only fulfilling a request but also meeting its own obligation.

Subparagraph (e) provides that those who process personal data are legally responsible for complying with the principles of the article and with the obligations and duties imposed by the law. It anchors proactive accountability: the law does not ask whether harm occurred, it asks whether there was compliance.

Security: what level does the principle require?

Subparagraph (f) requires the controller to guarantee adequate security standards, protecting data against unauthorised or unlawful processing and against loss, leakage, accidental damage or destruction.

The standard is explicitly relative: “Security measures must be appropriate and commensurate with the processing to be carried out and with the nature of the data”. There is no single control list valid for every company in Chile.

This principle is later developed in article 14 quinquies, which does name concrete measures such as pseudonymisation and encryption. The principle sets the duty; article 14 quinquies grounds it.

Transparency and confidentiality: why do they close the list?

Subparagraph (g), transparency and information, is the most demanding in wording. It requires providing the data subject with all information necessary to exercise their rights, including policies and practices on processing, and requires these to be “permanently accessible and available to any interested party in a precise, clear, unequivocal and free manner”.

The word “permanently” is where compliance usually fails. A privacy policy published once and never updated does not meet the standard, because the test is not having informed but keeping the information available and current.

Subparagraph (h), confidentiality, closes with a duty that outlives the relationship: the controller and anyone with access to the data must keep it secret, and “this duty subsists even after the relationship with the data subject has ended”. It also requires establishing adequate controls and measures to preserve that secrecy, which reaches supplier contracts and employee agreements.

The eight principles of article 3 of Law 21.719 and their core requirement
LetterPrincipleCore requirement
(a)Lawfulness and fairnessProcess lawfully and be able to demonstrate it
(b)PurposeSpecified, explicit and lawful purposes; no drift without cause
(c)ProportionalityOnly necessary data, only for the necessary time
(d)QualityAccurate, complete, current and relevant data
(e)AccountabilityLegal responsibility for compliance with the law
(f)SecurityStandards commensurate with the processing and the data
(g)Transparency and informationPermanently accessible, clear and free information
(h)ConfidentialitySecrecy that survives the end of the relationship

Would your processing activities hold up against all eight principles?

In 30 minutes we review your main processing activities against article 3 and identify where the evidence is missing.

Schedule an assessment

Frequently asked questions

How many principles does Law 21.719 have?

Eight. They sit in subparagraphs (a) to (h) of article 3: lawfulness and fairness, purpose, proportionality, quality, accountability, security, transparency and information, and confidentiality. Several guides published in Chile reproduce the European lists, which do not match this article.

Can a company be sanctioned just for breaching a principle?

Yes. Article 42 defines the administrative procedure for infringement as the one determining infringements for breach or violation of the article 3 principles, in addition to the rights and obligations the law establishes.

What does demonstrating the lawfulness of processing mean?

That the controller must be able to show, with documentation, that each processing activity has a valid lawful basis and complies with the law. The burden is on the controller, not the Agency. In practice it rests on the record of processing activities and documented decisions.

Can I use customer data for a new purpose?

Only in the cases opened by article 3(b): purposes compatible with the original ones, a contractual or pre-contractual relationship justifying it within the purposes of the contract, fresh consent from the data subject, or where the law so provides. Outside those cases, no.

How long can I keep personal data?

Only for the period necessary to fulfil the purposes of the processing. After that it must be deleted or anonymised, under article 3(c). Keeping it longer requires legal authorisation or the data subject's consent.

Does the security principle require a specific technical standard?

No. Article 3(f) requires measures that are appropriate and commensurate with the processing and the nature of the data. Article 14 quinquies develops it by mentioning pseudonymisation and encryption, but the standard remains relative to each organisation's risk.

What does transparency require beyond a privacy policy?

That the information be permanently accessible and available to any interested party in a precise, clear, unequivocal and free manner, and that the controller adopt measures to facilitate the data subject's access to that information and to any communication about the processing.

Does the confidentiality duty end when the customer leaves?

No. Article 3(h) states expressly that the duty of secrecy subsists even after the relationship with the data subject has ended. It reaches the controller and everyone who has had access to the data.

Do the principles also apply to small businesses in Chile?

Yes. Article 3 does not distinguish by company size. What the law does grade, in article 14 septies, are the compliance standards for certain duties according to the volume and risk of the processing, but the principles apply to everyone.

Are the Law 21.719 principles the same as the GDPR ones?

They are from the same family but not identical in number or wording. The Chilean law combines lawfulness and fairness in one subparagraph, adds quality and confidentiality as standalone principles, and its article 3 should be read directly rather than translated from the European text.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Law 21.719

Law 21.719: the definitive guide to comply and avoid fines

Lawful bases

Lawful bases and consent: when you need it

Essential guide

Data Protection Law in Chile: the complete guide

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment