In Chile, Law 21.719 defines personal data as any information linked to or referring to an identified or identifiable natural person. A person is identifiable where their identity can be determined, directly or indirectly, through one or more identifiers such as a name or a national ID number.
The essentials in 30 seconds
- It covers natural persons only: company data is not personal data.
- It is enough that the person be identifiable, not that they be identified.
- Indirect identification counts: an isolated data point can become personal when cross-referenced.
- Anonymised data ceases to be personal data; pseudonymised data does not.
- The list of sensitive data is closed and sits in article 2(g).
Law 21.719 replaced the definitions in Law 19.628, and the definition of personal data changed substantively. The old version referred to data relating to identified or identifiable persons; the new one adds the test for when someone is identifiable, which is where the gap used to be. If you want the full picture, start with our guide to the data protection law in Chile.
That precision has concrete economic effects. It determines whether an analytics database falls inside or outside the law's scope, whether a device identifier is personal data, and whether an internal “de-personalisation” process genuinely takes a company out of the Agency's reach.
This article walks through the Chilean legal definition and its three most consulted edges: indirect identifiability, sensitive data, and the boundary between anonymising and pseudonymising.
What is the legal definition of personal data in Chile?
Article 2(f), in the text introduced by Law 21.719, defines personal data as “any information linked to or referring to an identified or identifiable natural person”. Two elements of that phrase deserve attention.
The first is “natural person”. Chilean law does not protect data of legal entities. A company's tax ID, its commercial address or its turnover are not personal data. The data of the natural persons working there is, including a named corporate email address.
The second is “or identifiable”. The information need not state who the person is; it is enough that it allows reaching them. That element expands the law's scope far beyond names and ID numbers.
When is a person considered identifiable?
The same subparagraph (f) defines it: “A person shall be considered identifiable where their identity can be determined, directly or indirectly, in particular through one or more identifiers, such as a name, a national identity card number, or the analysis of elements specific to that person's physical, physiological, genetic, psychological, economic, cultural or social identity”.
The decisive word is “indirectly”. A data point that identifies nobody on its own can be personal data if, combined with other available information, it leads to a specific person.
The law adds the test for borderline cases: “In order to determine whether a person is identifiable, account shall be taken of all the objective means and factors that could reasonably be used for such identification at the time of the processing”.
That reasonableness standard is dynamic. A dataset that identifies nobody today can become identifiable tomorrow if another public dataset appears to complement it. That is why the assessment is not made once and filed away.
- It is assessed at the time of processing, not in the abstract.
- It considers means that could reasonably be used, not only your own.
- Indirect identification counts the same as direct identification.
Which data is sensitive under Chilean law?
Article 2(g) sets a closed list, and it is worth quoting in full because many guides summarise it badly. Sensitive data is data referring to a person's physical or moral characteristics, or to facts or circumstances of their private life or intimacy, that reveal any of the categories the law enumerates.
Two categories on that list are specific to the Chilean context and surprise companies used to the European framework: socioeconomic status and trade association membership. Both appear expressly in the text.
The classification matters because it triggers concrete consequences: it requires a reinforced lawful basis, bears on the duty to carry out an impact assessment and, after a breach, obliges notifying the affected data subjects under article 14 sexies.
| Category | Common processing example |
|---|---|
| Ethnic or racial origin | Diversity and inclusion forms |
| Political, union or trade association membership | Payroll deductions, member registers |
| Socioeconomic status | Social assessments, benefit brackets |
| Ideological or philosophical convictions | Climate or opinion surveys |
| Religious beliefs | Leave requests or special diets |
| Health data | Medical leave, pre-employment examinations |
| Human biological profile | Genetic studies, occupational medicine |
| Biometric data | Attendance control by fingerprint or face |
| Sex life, sexual orientation and gender identity | Health records, HR files |
Are anonymising and pseudonymising the same thing?
No, and confusing them is the costliest conceptual error in the whole of compliance. The law defines them separately and assigns them opposite legal consequences.
Subparagraph (k) defines anonymisation as an “irreversible procedure by which personal data can no longer be linked or associated with a specific person, nor allow their identification, because the link with the information that connects, associates or identifies that person has been destroyed or removed”. And it closes with the key sentence: “Anonymised data ceases to be personal data”.
Subparagraph (l) defines pseudonymisation as processing carried out in such a way that the data can no longer be attributed to a data subject without using additional information, provided that such additional information is kept separately and is subject to technical and organisational measures.
The difference is reversibility. If a table exists somewhere that allows going back to the person, the data is pseudonymised and remains personal data, with all the obligations attached. Replacing an ID number with an internal identifier is pseudonymising, not anonymising.
- Anonymisation: irreversible. The data leaves the law's scope.
- Pseudonymisation: reversible with additional information. The data stays protected.
- If you keep the key to reverse it, you did not anonymise.
What about IP addresses, cookies and publicly available data?
Technical identifiers come in through indirect identifiability. An IP address, a device identifier or a persistent cookie is personal data when, using the means that could reasonably be applied, it allows reaching a natural person. The analysis is case by case, not by category.
Publicly accessible sources deserve their own paragraph because they are the source of a frequent misunderstanding in Chile. Article 2(i) defines them as databases or sets of personal data whose access or consultation may be lawfully carried out by any person, and mentions the Official Gazette, media outlets and public registers.
The same subparagraph (i) closes with the rule that changes prior practice: “The processing of personal data from publicly accessible sources shall be subject to the provisions of this law”. Data being public does not take it outside Law 21.719 nor exempt you from having a lawful basis.
Do you know what personal data your company processes?
The inventory is the first step and the most underestimated. In 30 minutes we review where to start in your case.
Schedule an assessmentFrequently asked questions
What is personal data under Law 21.719?
Any information linked to or referring to an identified or identifiable natural person, under article 2(f). It covers everything from a name and ID number to elements of the person's physical, physiological, genetic, psychological, economic, cultural or social identity.
Is company data personal data in Chile?
No. The law protects data of natural persons. A company's tax ID, commercial address or financial statements are not personal data. The data of the natural persons linked to it is, such as an employee's name and corporate email.
Is an IP address personal data?
It can be. It depends on whether, using the objective means and factors that could reasonably be applied at the time of the processing, it allows determining the person's identity directly or indirectly. There is no single answer for every case.
What does it mean for a person to be identifiable?
That their identity can be determined, directly or indirectly, through one or more identifiers. The law requires taking account of all objective means and factors that could reasonably be used for that identification at the time of the processing.
What is the difference between anonymising and pseudonymising?
Reversibility. Anonymisation is irreversible and makes the data cease to be personal data, under article 2(k). Pseudonymisation keeps the possibility of re-identification using additional information held separately, so the data remains personal and remains protected.
Which data is sensitive under Chilean law?
Data revealing ethnic or racial origin, political, union or trade association membership, socioeconomic status, ideological or philosophical convictions, religious beliefs, health data, human biological profile, biometric data, and information on sex life, sexual orientation and gender identity.
Is socioeconomic status sensitive data?
Yes, and it is a particularity of Chilean law with no direct equivalent in the European framework. It is expressly listed in article 2(g), so processing such as social assessment or segmentation by income bracket requires the reinforced regime.
Can I freely use data from public sources?
No. Article 2(i) provides expressly that the processing of personal data from publicly accessible sources is subject to the provisions of the law. You still need a lawful basis and you remain subject to the article 3 principles.
Is an employee's corporate email personal data?
Where it is a named address, yes, because it identifies a specific natural person. A generic team mailbox with no reference to a person normally is not. The practical test is whether the mailbox points to someone identifiable.
Did the definition change from the previous Law 19.628?
Yes. Law 21.719 replaced the definition and introduced the indirect identifiability test and the standard of means that could reasonably be used. It also reformulated the list of sensitive data and added the definitions of anonymisation and pseudonymisation.
Official sources
- Law 21.719 — official text, Library of the National Congress
- Law 19.628 consolidated with the amendments of Law 21.719
This article is for information purposes only and does not constitute legal advice for a specific case.