← Back to blog

Complaints before the Personal Data Protection Agency: what happens and how to respond (article 41 of Law 21.719)

A complaint before the Personal Data Protection Agency does not come out of nowhere: it arises from an article 11 request that you denied or left unanswered. Article 41 of Law 21.719 sets specific deadlines for the data subject, for the Agency and for your company, and it includes the possibility of suspending processing while the case is being handled. This is the full procedure and what you need to have ready before 1 December 2026.

GUIDE · LAW 21.719
Short answer

A complaint before the Personal Data Protection Agency is available in Chile when the data controller denied an article 11 request or failed to respond within the deadline. The data subject has 30 business days to file it; Law 21.719 gives your company 30 calendar days, extendable, to reply once the complaint is admitted for processing.

The essentials in 30 seconds

  • Article 11: your company must acknowledge receipt and issue a decision within 30 calendar days from the date the request is submitted, extendable only once for up to a further 30 calendar days.
  • Article 41(a): the data subject will have 30 business days to file a complaint with the Agency, counted from the negative response or from the expiry of your deadline.
  • Article 41(c): the Agency will have 10 business days to determine admissibility and, if it does not rule within that period, the complaint is deemed admitted for processing.
  • Article 41(d) and (e): 30 calendar days, extendable for up to the same period, for your written defense, plus a possible evidentiary period of 10 business days.

Almost all Law 21.719 compliance work concentrates on the front end of the process: what data you process, on what lawful basis, with what security measures. But the moment a Chilean company becomes genuinely exposed is far more mundane. Someone writes in asking for a copy of their data or its deletion, that request gets lost in an inbox, and once the article 11 deadline expires without a response, the data subject is entitled to take the matter to the authority. If you want the full picture, start with our guide to the data protection law in Chile.

That door is the administrative rights protection procedure under article 41. It is not an investigation opened on the Agency's own initiative, nor a court claim: it is an adversarial procedure before the Personal Data Protection Agency, with defined stages and deadlines, in which your company appears as the opposing party and has to prove what it did. And it carries an element almost no one mentions: the Agency will be able to suspend processing before ruling on the merits.

Here we walk through the full procedure with the deadlines set out in the text of the law, its connection to the article 11 deadline, and what is worth having in place before 1 December 2026, the date the law enters into force. The goal is not to alarm: it is that on the day a notification from the Agency arrives, your team knows exactly which file to open.

What is a complaint before the Personal Data Protection Agency, and when can a data subject file one?

It is the administrative rights protection procedure through which Law 21.719 will allow a data subject, in Chile, to challenge the data controller's conduct in response to an article 11 request. Article 41 makes it available in two scenarios: where the data controller has denied the request, or where it failed to respond within the legal deadline.

It is worth being clear about the nature of this procedure, because it gets confused with other things. It is not an investigation the Agency opens on its own initiative, nor a claim for damages. It is an adversarial procedure, triggered by a specific individual, in which your company is identified as the data controller and has to explain in writing what it did with a specific request. The entire discussion revolves around a case file: the request, your response, and the supporting evidence for both.

The two entry points under article 41 differ in their logic and also in how hard they are to defend:

The practical difference is enormous. With a denial you have something to defend: a stated basis, a lawful basis for processing, an applicable exception. With silence there is nothing to argue on the merits, because the breach is the absence of a response itself. That is why most avoidable complaints are lost in the second scenario. Remember, too, that temporary blocking has its own rule under article 11: you respond within 2 business days and, until the matter is resolved, you cannot process that data.

  • Denial: you ruled on the request, but rejected in whole or in part the exercise of a right of access, rectification, erasure, objection or portability.
  • Silence: you let the article 11 deadline lapse without ruling, whether because the request never reached the right team, because no one logged it, or because it was handled as just another commercial complaint.

How long does the data subject have to complain, and what must the filing contain?

Article 41(a) of Law 21.719 grants the data subject 30 business days, counted from receipt of the negative response or from the expiry of the data controller's deadline. The complaint must be filed in writing, in physical or electronic format, and must meet three content requirements that the Agency will review when examining admissibility.

The three required elements are:

The starting point for counting the deadline is what tends to be disputed most in practice, and it depends on your own records. Article 11 requires the response to be in writing and requires supporting records proving delivery, the date and the full content of what was communicated. If the data subject maintains they never received your response and you cannot prove those three elements, you will have no way of showing that the deadline started running when you claim, and the reasonable expectation is that the dispute will be resolved on the evidence the data subject provided.

It is worth insisting on the unit of measurement, because Law 21.719 alternates between business days and calendar days, and that detail shifts calendar weeks. The data subject's deadline to complain is in business days. Your company's deadline to answer an article 11 request is in calendar days. Writing that distinction into your internal procedure avoids the most common and most expensive mistake in this whole workflow.

  • Precisely identify the decision being challenged, that is, the specific refusal or the failure to respond that is being complained about.
  • Attach all the evidence on which the complaint is based: the original request, the response received, proof of delivery.
  • State a postal address or an email address where notifications in the procedure will be served.

Can the Agency suspend data processing while the complaint is being handled?

Yes, and this is the operational risk that is rarely mentioned. Article 41(b) of Law 21.719 provides that, at the time the complaint is filed, upon the data subject's reasoned request and in justified cases only, the Agency will be able to suspend the processing of the data covered by the complaint, having first heard the data controller.

Pause on when this can happen: at the time of filing. Not at the end, not after arguing over who is right, not once an infringement has been established. If the processing in question underpins a live business process — a customer base, a collections operation, a marketing workflow, a register that feeds automated decisions — suspension could hit operations long before there is any ruling on the merits. It is a discretionary power of the Agency, subject to a reasoned request and to justified cases, not an automatic effect of the complaint.

The counterweight is the safeguard that subparagraph (b) itself gives the data controller: the Agency must hear it before deciding. That prior opportunity to be heard is your chance to show why the measure would be disproportionate, and it is worth little if no one receives the notification or if the team needs three weeks to gather basic information. Being heard meaningfully means being able to answer four things within days:

One thing should be said honestly: the text of the law does not set how long that suspension may last, nor does it detail how the opportunity to be heard is conducted. That will be left to the Agency in each specific case and to the instructions it issues. What is controllable today is not the authority's decision, but your ability to react quickly and with documents when you are asked to state your position.

  • What the purpose of the processing in question is and what its lawful basis is.
  • What the exact scope of the data covered by the complaint is: which records, in which systems, since when.
  • What concrete impact the suspension would have on operations and on third parties, with verifiable facts rather than general assertions.
  • What less onerous measures would address the data subject's concern, such as flagging the record, restricting a specific use, or segregating the data while the complaint is being handled.

How does the article 41 procedure progress, and what deadlines does your company face?

Once the complaint is received, the Agency has 10 business days to determine whether it meets the requirements to be admitted for processing, and if it does not rule within that period the complaint is deemed admitted. Once admitted, it notifies the data controller, who has 30 calendar days, extendable for up to the same period, to respond. An evidentiary period of 10 business days may then be opened.

The effect of silence at the admissibility stage deserves close reading, because it runs against the intuition of many legal teams. Article 41(c) of Law 21.719 provides that, if the Agency does not rule within the 10 business days, the complaint is deemed admitted for processing. Where the Agency does decide not to admit it, the decision must be reasoned and notified to the data subject. The operational conclusion is simple: you cannot plan on the assumption that the authority will filter out poorly drafted complaints before they reach your desk.

At the defense stage, subparagraph (d) allows you to attach all the evidence you consider relevant, and that is where the case is won or lost. Subparagraph (e) adds that, once that deadline expires, whether or not the data controller responded, and only where there are substantial, relevant and disputed facts, the Agency will be able to open an evidentiary period of 10 business days in which the parties may submit all forms of evidence. Two nuances matter: the procedure moves forward even if you do not respond, and opening an evidentiary period is discretionary, not automatic.

In fact, where the defense is purely documentary and consistent — the request came in on this date, receipt was acknowledged, a response was sent on that date with this content and this proof of delivery — it is entirely possible that there are no disputed facts to prove. An orderly case file does not just improve your chances: it can shorten the procedure.

Stages, responsible parties and deadlines in the administrative rights protection procedure under article 41 of Law 21.719 (Chile).
StageWho actsExact deadlineWhat happens if it is missed
Prior request by the data subject (article 11)The data controller30 calendar days from the date the request is submitted, extendable only once for up to a further 30 calendar daysThe data subject becomes entitled to complain directly to the Agency for failure to respond
Filing of the complaint (subparagraph a)The data subject30 business days from the negative response or from the expiry of the data controller's deadlineFiled out of time, it does not meet the requirements to be admitted for processing
Request to suspend processing (subparagraph b)The data subject requests it with reasons; the Agency decidesAt the time the complaint is filed, in justified cases only and having first heard the data controllerIf the data controller does not respond when heard, it loses its chance to show the measure is disproportionate
Admissibility review (subparagraph c)The Agency10 business days from receipt of the complaintIf the Agency does not rule within that period, the complaint is deemed admitted for processing
Data controller's defense (subparagraph d)The data controller, after being notified30 calendar days, extendable for up to the same periodThe procedure continues regardless: the Agency moves forward whether or not the data controller responded
Evidentiary period (subparagraph e)The Agency opens it; both parties may submit evidence10 business days, only where there are substantial, relevant and disputed factsWithout evidence from your side, the Agency rules on the evidence the data subject provided

Why does answering an article 11 request badly or late open this door?

Because the article 41 complaint has no other origin. Article 11 of Law 21.719 requires the data controller, in Chile, to acknowledge receipt and issue a decision no later than 30 calendar days from the date the request is submitted, extendable only once for up to a further 30 calendar days. Once that deadline is exhausted without a response, the data subject will be able to complain directly to the Agency.

That same article 11 requires the response to be in writing and requires supporting records proving delivery, the date and the full content of what was communicated. And if you decide to deny the request, it adds two duties: give reasons for the refusal and inform the data subject that they have 30 business days to complain to the Agency. In other words, your own denial letter explains to the data subject how to escalate the case. That is not a flaw in the law, it is by design: transparency of the channel is part of compliance.

That is why answering badly is as risky as not answering at all. A late, generic or partial response leaves the company in a position similar to silence, with the aggravating factor that there is now a document of its own that the authority will be able to read. These are the failures that most often turn a routine request into a complaint:

Seen this way, article 41 is less a new threat than the natural consequence of a weak internal workflow. A company that responds on time, in writing, with reasons and with supporting records is unlikely to end up in this procedure; and if it does, it arrives with the case already built.

  • Counting the deadline in business days when article 11 speaks of calendar days, which produces a breach even though the team believes it answered within time.
  • Extending more than once, when the law allows a single extension of up to 30 calendar days; or extending without keeping an internal record of the fact and of its communication to the data subject.
  • Denying without reasons, using a standard formula that does not explain why the right does not apply in that specific case.
  • Omitting from the denial the notice that the data subject has 30 business days to complain to the Agency.
  • Responding through an informal channel, with no record proving delivery, date and full content of the response.

How does a Chilean company prepare to answer a complaint without improvising?

With four pieces that are built before the first complaint ever exists: a single intake channel, a complete register of requests, verifiable proof of delivery and content for every response, and a case file assembled per matter. None of them is technologically complex; all of them fail when they are left until the day the notification arrives.

Concretely, this is what is worth having up and running before 1 December 2026:

It also helps to know that article 41 is not the only route. Law 21.719 also provides for the administrative procedure for breach of the law under article 42 and the judicial review procedure under article 43, each with its own rules. And article 47 provides that the claim for compensation for pecuniary and non-pecuniary damage may be brought once the decision upholding the complaint before the Agency is final and enforceable — or once the judgment is final and enforceable, in the case of an illegality claim — and will be heard under the summary proceedings of articles 680 and following of the Code of Civil Procedure. In other words, a complaint badly handled at the administrative stage can be the first link in a longer chain.

Let's close with what cannot be known today. Law 21.719 enters into force on 1 December 2026, and the detail of several minimum standards — the information and security duties differentiated according to the type of data, whether the data controller is a natural or legal person, the size of the company under Law 20.416, the activity it carries out, and the volume, nature and purposes of the data — will be determined by the Agency through a general instruction, under article 14 septies. As of July 2026 that detail does not yet exist, and anyone offering you certainty there is getting ahead of themselves. Important: that differentiation does not make the obligations optional, it only adjusts the standard by which they are met. What is in the text, and what you can prepare for, are the deadlines: the 30 calendar days under article 11 and the whole article 41 sequence. Start there, and review the design of your procedure with legal counsel before the law takes effect.

  • A single, visible channel for access, rectification, erasure, objection and portability requests, published on the website and known to customer service, sales and human resources.
  • A register of requests with the date received, identification of the data subject, the right invoked, the due date calculated in calendar days, and the current status.
  • Acknowledgement of receipt plus response and reasoned denial templates that already include the notice of the 30 business days to complain to the Agency.
  • Records proving delivery, date and full content of every response, stored in a way that will withstand external review months later.
  • A designated person to receive notifications from the Agency and an internal reaction deadline, particularly with a view to being heard before any suspension of processing.
  • A case file per matter, ready to attach to your written defense: original request, communications, decision, legal reasoning and supporting evidence.

Have your requests and complaints procedure ready before 1 December 2026

At AlayIAtrust we help Chilean companies build the full workflow: a single intake channel for data subject rights requests, response and reasoned denial templates, a register with proof of delivery, and a defense file ready for a complaint before the Agency. Let's talk about where your operation stands.

Schedule an assessment

Frequently asked questions

When can a data subject file a complaint with the Personal Data Protection Agency?

A data subject will be able to file a complaint in the two scenarios set out in article 41 of Law 21.719 in Chile: when the data controller has denied an article 11 request, or when it failed to respond within the legal deadline. That prior request is the precondition: without it, there is no rights protection complaint.

What is the data subject's deadline to file the complaint?

Article 41(a) of Law 21.719 grants 30 business days, counted from the moment the data subject receives the negative response or from the expiry of the data controller's deadline. The complaint must be filed in writing, in physical or electronic format, together with the supporting evidence it relies on.

What must the complaint include?

Under article 41(a), the filing must identify the decision being challenged, attach all the evidence on which it is based, and state a postal address or an email address where notifications will be served. Those are the elements the law requires and that the Agency will review when examining admissibility.

What happens if the Agency does not rule on admissibility within 10 business days?

The complaint is deemed admitted for processing. Article 41(c) of Law 21.719 gives the Agency 10 business days to determine whether the requirements are met and, if it does not rule within that period, the legal effect is that the procedure moves forward and your company will be notified to respond.

How long does the company have to respond to the complaint?

Once the complaint has been admitted for processing and the data controller notified, article 41(d) grants it 30 calendar days, extendable for up to the same period, to respond and attach whatever evidence it considers relevant. Once the deadline expires, the Agency continues the procedure whether or not a response was filed.

Can the Agency suspend data processing before ruling on the merits?

Yes. Article 41(b) of Law 21.719 allows the Agency, at the time the complaint is filed and upon the data subject's reasoned request, in justified cases only, to suspend the processing of the data covered by the complaint. It must first hear the data controller before deciding. This is a discretionary power, not an automatic effect.

Are the 30 days under article 11 business days or calendar days?

They are calendar days. Article 11 of Law 21.719 requires the data controller to acknowledge receipt and issue a decision no later than 30 calendar days from the date the request is submitted, extendable only once for up to a further 30 calendar days. Confusing them with business days creates breaches.

Is an evidentiary period always opened in this procedure?

No. Article 41(e) states that the Agency may open an evidentiary period of 10 business days only where there are substantial, relevant and disputed facts. It is a discretionary power: when the company's defense is documentary and consistent, the matter could be resolved without additional evidence.

Is this procedure the same as an investigation for breach of the law?

No. Law 21.719 distinguishes the rights protection procedure under article 41 from the administrative procedure for breach of the law under article 42 and the judicial review procedure under article 43. They are separate routes with their own requirements, and a single set of facts could give rise to more than one.

From when will it be possible to file a complaint with the Agency in Chile?

Law 21.719 enters into force on 1 December 2026, under its first transitional article. Until that date this rights protection procedure does not apply and the Agency does not operate as the supervisory authority, so today, in July 2026, the work is preparatory.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Rights

How to respond to ARCO rights requests: process and deadlines

Enforcement

Agency audits: what they will request and how to prepare

Sanctions

Fines and sanctions under Law 21.719

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment