← Back to blog

What counts as personal data under Law 21.719 (and what does not)

The question sounds basic and yet it is where half of all compliance projects break. If a company defines personal data wrongly, everything built on top of it — the record, the lawful bases, the security measures — is badly scoped from day one.

Fundamentals
Short answer

In Chile, Law 21.719 defines personal data as any information linked to or referring to an identified or identifiable natural person. A person is identifiable where their identity can be determined, directly or indirectly, through one or more identifiers such as a name or a national ID number.

The essentials in 30 seconds

  • It covers natural persons only: company data is not personal data.
  • It is enough that the person be identifiable, not that they be identified.
  • Indirect identification counts: an isolated data point can become personal when cross-referenced.
  • Anonymised data ceases to be personal data; pseudonymised data does not.
  • The list of sensitive data is closed and sits in article 2(g).

Law 21.719 replaced the definitions in Law 19.628, and the definition of personal data changed substantively. The old version referred to data relating to identified or identifiable persons; the new one adds the test for when someone is identifiable, which is where the gap used to be. If you want the full picture, start with our guide to the data protection law in Chile.

That precision has concrete economic effects. It determines whether an analytics database falls inside or outside the law's scope, whether a device identifier is personal data, and whether an internal “de-personalisation” process genuinely takes a company out of the Agency's reach.

This article walks through the Chilean legal definition and its three most consulted edges: indirect identifiability, sensitive data, and the boundary between anonymising and pseudonymising.

What is the legal definition of personal data in Chile?

Article 2(f), in the text introduced by Law 21.719, defines personal data as “any information linked to or referring to an identified or identifiable natural person”. Two elements of that phrase deserve attention.

The first is “natural person”. Chilean law does not protect data of legal entities. A company's tax ID, its commercial address or its turnover are not personal data. The data of the natural persons working there is, including a named corporate email address.

The second is “or identifiable”. The information need not state who the person is; it is enough that it allows reaching them. That element expands the law's scope far beyond names and ID numbers.

When is a person considered identifiable?

The same subparagraph (f) defines it: “A person shall be considered identifiable where their identity can be determined, directly or indirectly, in particular through one or more identifiers, such as a name, a national identity card number, or the analysis of elements specific to that person's physical, physiological, genetic, psychological, economic, cultural or social identity”.

The decisive word is “indirectly”. A data point that identifies nobody on its own can be personal data if, combined with other available information, it leads to a specific person.

The law adds the test for borderline cases: “In order to determine whether a person is identifiable, account shall be taken of all the objective means and factors that could reasonably be used for such identification at the time of the processing”.

That reasonableness standard is dynamic. A dataset that identifies nobody today can become identifiable tomorrow if another public dataset appears to complement it. That is why the assessment is not made once and filed away.

  • It is assessed at the time of processing, not in the abstract.
  • It considers means that could reasonably be used, not only your own.
  • Indirect identification counts the same as direct identification.

Which data is sensitive under Chilean law?

Article 2(g) sets a closed list, and it is worth quoting in full because many guides summarise it badly. Sensitive data is data referring to a person's physical or moral characteristics, or to facts or circumstances of their private life or intimacy, that reveal any of the categories the law enumerates.

Two categories on that list are specific to the Chilean context and surprise companies used to the European framework: socioeconomic status and trade association membership. Both appear expressly in the text.

The classification matters because it triggers concrete consequences: it requires a reinforced lawful basis, bears on the duty to carry out an impact assessment and, after a breach, obliges notifying the affected data subjects under article 14 sexies.

Sensitive data categories under article 2(g) of Law 21.719
CategoryCommon processing example
Ethnic or racial originDiversity and inclusion forms
Political, union or trade association membershipPayroll deductions, member registers
Socioeconomic statusSocial assessments, benefit brackets
Ideological or philosophical convictionsClimate or opinion surveys
Religious beliefsLeave requests or special diets
Health dataMedical leave, pre-employment examinations
Human biological profileGenetic studies, occupational medicine
Biometric dataAttendance control by fingerprint or face
Sex life, sexual orientation and gender identityHealth records, HR files

Are anonymising and pseudonymising the same thing?

No, and confusing them is the costliest conceptual error in the whole of compliance. The law defines them separately and assigns them opposite legal consequences.

Subparagraph (k) defines anonymisation as an “irreversible procedure by which personal data can no longer be linked or associated with a specific person, nor allow their identification, because the link with the information that connects, associates or identifies that person has been destroyed or removed”. And it closes with the key sentence: “Anonymised data ceases to be personal data”.

Subparagraph (l) defines pseudonymisation as processing carried out in such a way that the data can no longer be attributed to a data subject without using additional information, provided that such additional information is kept separately and is subject to technical and organisational measures.

The difference is reversibility. If a table exists somewhere that allows going back to the person, the data is pseudonymised and remains personal data, with all the obligations attached. Replacing an ID number with an internal identifier is pseudonymising, not anonymising.

  • Anonymisation: irreversible. The data leaves the law's scope.
  • Pseudonymisation: reversible with additional information. The data stays protected.
  • If you keep the key to reverse it, you did not anonymise.

What about IP addresses, cookies and publicly available data?

Technical identifiers come in through indirect identifiability. An IP address, a device identifier or a persistent cookie is personal data when, using the means that could reasonably be applied, it allows reaching a natural person. The analysis is case by case, not by category.

Publicly accessible sources deserve their own paragraph because they are the source of a frequent misunderstanding in Chile. Article 2(i) defines them as databases or sets of personal data whose access or consultation may be lawfully carried out by any person, and mentions the Official Gazette, media outlets and public registers.

The same subparagraph (i) closes with the rule that changes prior practice: “The processing of personal data from publicly accessible sources shall be subject to the provisions of this law”. Data being public does not take it outside Law 21.719 nor exempt you from having a lawful basis.

Do you know what personal data your company processes?

The inventory is the first step and the most underestimated. In 30 minutes we review where to start in your case.

Schedule an assessment

Frequently asked questions

What is personal data under Law 21.719?

Any information linked to or referring to an identified or identifiable natural person, under article 2(f). It covers everything from a name and ID number to elements of the person's physical, physiological, genetic, psychological, economic, cultural or social identity.

Is company data personal data in Chile?

No. The law protects data of natural persons. A company's tax ID, commercial address or financial statements are not personal data. The data of the natural persons linked to it is, such as an employee's name and corporate email.

Is an IP address personal data?

It can be. It depends on whether, using the objective means and factors that could reasonably be applied at the time of the processing, it allows determining the person's identity directly or indirectly. There is no single answer for every case.

What does it mean for a person to be identifiable?

That their identity can be determined, directly or indirectly, through one or more identifiers. The law requires taking account of all objective means and factors that could reasonably be used for that identification at the time of the processing.

What is the difference between anonymising and pseudonymising?

Reversibility. Anonymisation is irreversible and makes the data cease to be personal data, under article 2(k). Pseudonymisation keeps the possibility of re-identification using additional information held separately, so the data remains personal and remains protected.

Which data is sensitive under Chilean law?

Data revealing ethnic or racial origin, political, union or trade association membership, socioeconomic status, ideological or philosophical convictions, religious beliefs, health data, human biological profile, biometric data, and information on sex life, sexual orientation and gender identity.

Is socioeconomic status sensitive data?

Yes, and it is a particularity of Chilean law with no direct equivalent in the European framework. It is expressly listed in article 2(g), so processing such as social assessment or segmentation by income bracket requires the reinforced regime.

Can I freely use data from public sources?

No. Article 2(i) provides expressly that the processing of personal data from publicly accessible sources is subject to the provisions of the law. You still need a lawful basis and you remain subject to the article 3 principles.

Is an employee's corporate email personal data?

Where it is a named address, yes, because it identifies a specific natural person. A generic team mailbox with no reference to a person normally is not. The practical test is whether the mailbox points to someone identifiable.

Did the definition change from the previous Law 19.628?

Yes. Law 21.719 replaced the definition and introduced the indirect identifiability test and the standard of means that could reasonably be used. It also reformulated the list of sensitive data and added the definitions of anonymisation and pseudonymisation.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Sensitive data

Sensitive data under Law 21.719: what they are and how to protect them

Law 21.719

Law 21.719: the definitive guide to comply and avoid fines

Essential guide

Data Protection Law in Chile: the complete guide

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment