Chile's Law 21.719 has no single implementing regulation. Its second transitional article required the regulations referred to in the law to be issued within six months of publication in the Official Gazette, and set one apart: the article 26 regulation, due six months after the law takes effect and requiring a prior report from the Agency.
The essentials in 30 seconds
- There is no single “regulation”: the law contemplates several distinct instruments.
- The second transitional article gave six months from publication (13 December 2024).
- The article 26 regulation runs separately: six months from the law taking effect.
- That regulation covers two specific things: data transfers between bodies, and anonymisation.
- Controller obligations apply from 1 December 2026 whether or not a regulation exists.
When a Chilean company asks about “the Law 21.719 regulation”, it is almost always asking for one thing: the manual that spells out exactly which security measures to implement, in what format to document the record of processing activities, and how many days each step takes. That document does not exist, and understanding why saves months. If you want the full picture, start with our guide to the data protection law in Chile.
Law 21.719 follows the technique of the European General Data Protection Regulation: it defines principles, duties and standards in the statute itself, and leaves to secondary legislation only what needs operational detail or coordination between State bodies. Most of compliance is read directly from the law.
This article separates three things that get confused constantly: which regulations the law orders to be issued, what deadlines it set for them, and which instruments have already been issued and are worth reviewing today.
Does Law 21.719 have a single implementing regulation?
No. Chile's Law 21.719 is not developed through a general regulation detailing article by article how to comply. What exists is a set of distinct instruments, each with its own subject matter, its own responsible ministry and, in one case, its own deadline.
This is the first source of confusion. Several guides published in Chile refer to “the law's regulation” as if it were a single text awaiting signature. The practical consequence of that idea is dangerous: it leads to postponing decisions that depend on no regulation at all.
The logic of Law 21.719 is the opposite. The article 3 principles, data subject rights, the security duty in article 14 quinquies, breach reporting in article 14 sexies and the sanctions regime are all developed in the statute. They are enforceable on their own.
- Principles and controller duties are in the law, not in a regulation.
- Secondary legislation was reserved for operational and State coordination matters.
- No single pending text “completes” the law before December 2026.
What deadline did the law set for issuing the regulations?
The second transitional article of Law 21.719 is explicit and sets two separate clocks. The first: the regulations referred to in the law “shall be issued within the six months following the publication of this law in the Official Gazette”. Publication took place on 13 December 2024, so that period runs from that date.
The second clock is the one almost nobody mentions. The same transitional article adds that the article 26 regulation “shall be issued within six months from the entry into force of this law, once the respective report of the Agency has been issued”. That is, it runs from 1 December 2026, not from publication.
The difference is not bureaucratic detail. It means that this particular instrument cannot exist before the law takes effect, because it requires the prior report of an Agency that must already be operating to issue it.
| Instrument | Counted from | Deadline | Prior requirement |
|---|---|---|---|
| Regulations referred to in the law (general rule) | Publication in the Official Gazette (13 December 2024) | 6 months | None stated in the law |
| Article 26 regulation | Entry into force of the law (1 December 2026) | 6 months | Prior report from the Agency |
What exactly does the article 26 regulation cover?
Article 26 defines its subject matter precisely, and it is worth reading literally because it is narrower than usually assumed. It governs “the conditions, modalities and instruments for the communication or transfer of personal data between public bodies and with private persons or organisations”.
The same article 26 adds a second matter that does concern any company: “This same regulation shall govern the procedures for the anonymisation of personal data, especially sensitive personal data”. That is the point worth following closely.
Anonymisation matters because the law itself, in article 2(k), provides that anonymised data ceases to be personal data. A validated anonymisation procedure takes that data out of the law's scope entirely. Until the regulation sets the standard, that decision rests with each company and must be defensible.
The regulation is issued by the Ministry General Secretariat of the Presidency, signed by the Minister of Finance and the Minister of Economy, Development and Tourism. It does not apply to transfers involving bodies covered by Title VIII.
- Subject 1: transfers of data between public bodies and with private parties.
- Subject 2: anonymisation procedures, especially for sensitive data.
- Three ministries sign it: Segpres, Finance and Economy.
- It excludes transfers involving Title VIII bodies.
Which instruments have already been issued and are worth reviewing?
Although the article 26 regulation cannot yet exist, complementary rules already published do affect concrete compliance decisions in Chile, and many companies are unaware of them because they are waiting for a text that will not arrive before December 2026.
The first is the supreme decree governing the Infringement Prevention Model and its certification, the figure set out in articles 48 to 53. It matters because a certified model bears on how liability is weighed before the Agency.
The second is the set of model contractual clauses for international transfers, published in the Official Gazette in December 2025. That instrument enables the simplest route to transfer data abroad without negotiating safeguards case by case.
Before treating the status of any of these instruments as settled, verify it in the Official Gazette, because the regulatory landscape keeps moving as the entry into force approaches.
What should a company do while the regulation is pending?
The same it would do if the regulation already existed, because the bulk of the obligations does not change. Law 21.719 requires the controller to demonstrate the lawfulness of its processing, and that burden is not suspended by the absence of secondary legislation.
The starting point is the record of processing activities. Without knowing what data the company processes, for what purpose and on what lawful basis, none of the following decisions can be made properly, and no future regulation will build that inventory for anyone.
The only area where the missing regulation creates real uncertainty is anonymisation. If the business model depends on treating anonymised data as outside the law, that decision must be documented with defensible technical criteria and revisited when the article 26 regulation is published.
- Building the record of processing activities depends on no regulation.
- Defining the lawful basis for each processing activity does not either.
- Security measures are governed by article 14 quinquies, already written.
- Document your anonymisation criteria and revisit them when the regulation lands.
Are you waiting for the regulation to start?
In 30 minutes we review which Law 21.719 obligations already apply to you today and which genuinely depend on pending legislation.
Schedule an assessmentFrequently asked questions
Does Law 21.719 have a regulation?
It has no single regulation developing it in full. The law contemplates several distinct regulatory instruments. The most cited is the article 26 regulation, which governs data transfers between bodies and anonymisation procedures, and whose deadline runs from the law's entry into force.
When was the Law 21.719 regulation due?
The second transitional article set six months from publication in the Official Gazette, which occurred on 13 December 2024, for the regulations referred to in the law. The article 26 regulation has a different deadline: six months from entry into force, after a prior report from the Agency.
Can I wait for the regulation before starting to comply?
It is not advisable. The article 3 principles, data subject rights, the security duty and the sanctions regime are developed in the law itself and are enforceable from 1 December 2026 whether or not a regulation exists. Waiting only shortens the time available to implement.
What happens if the regulation is not issued on time?
The law takes effect regardless. Missing the regulatory deadline does not suspend controller obligations or the enforcement powers of the Personal Data Protection Agency. It only leaves the specific matters the regulation was meant to cover without operational detail.
Does the article 26 regulation apply to private companies?
Partly. Its main subject is the communication or transfer of data between public bodies and with private persons or organisations, so it reaches private parties receiving State data. It also governs anonymisation procedures, which concern any company in Chile.
Who issues the article 26 regulation?
The Ministry General Secretariat of the Presidency, signed by the Minister of Finance and the Minister of Economy, Development and Tourism, after a prior report from the Personal Data Protection Agency, as article 26 itself states.
Is anonymisation governed by the regulation?
Yes. Article 26 provides that the same regulation shall govern the procedures for anonymising personal data, especially sensitive data. It is the regulatory matter with the greatest direct impact on companies working with analytics or aggregated data.
Is anonymised data still personal data in Chile?
No. Article 2(k) defines anonymisation as an irreversible procedure and states expressly that anonymised data ceases to be personal data. Pseudonymisation under article 2(l) is different: it keeps the data within the law's scope.
Is there other complementary legislation already published?
Yes. The decree governing the Infringement Prevention Model and its certification, and the model contractual clauses for international transfers published in the Official Gazette in December 2025. Verify their current status before relying on them.
Where is the regulation published once issued?
In the Official Gazette of the Republic of Chile, and it becomes available in the Ley Chile system of the Library of the National Congress. That is the only place worth checking for its text and effective date.
Official sources
- Law 21.719 — official text, Library of the National Congress
- Law 19.628 consolidated with the amendments of Law 21.719
- Official Gazette of the Republic of Chile
This article is for information purposes only and does not constitute legal advice for a specific case.