← Back to blog

Suspension of processing under Law 21.719: when the Agency will be able to halt your company's operations

Almost every conversation about Law 21.719 revolves around fines expressed in UTM. But for many companies the greater risk is not paying: it is having to stop. Article 38 will allow the Agency to suspend data processing operations for up to thirty days, with the possibility of extension if the order is not complied with. Here is exactly when it applies, what it reaches and what it does not.

GUIDE · LAW 21.719
Short answer

Chile's Personal Data Protection Agency will be able to suspend your company's processing operations, but only as an ancillary sanction under article 38 of Law 21.719, when fines are imposed for repeated very serious infringements within a twenty-four-month period. The suspension will last up to thirty days, may be partial or total, and does not affect data storage.

The essentials in 30 seconds

  • It applies only where fines are imposed for repeated very serious infringements within a twenty-four-month period, and it is a discretionary power: the law says the Agency "may".
  • It lasts up to thirty days, may be partial or total, and does not affect data storage.
  • It may not be ordered where doing so would affect the rights of data subjects.
  • If the company fails to comply, the measure may be extended indefinitely for successive periods of up to thirty days.

When a board reviews the sanctions regime of Law 21.719 in Chile for the first time, the conversation stops at the numbers: up to 20,000 UTM for a very serious infringement and, in the event of recidivism, a fine of up to three times that amount under article 36. That is a reasonable concern, but an incomplete one. There is a consequence almost no one sizes up properly and which, in certain business models, weighs more than any fine: the possibility that the Agency orders data processing operations to stop. If you want the full picture, start with our guide to the data protection law in Chile.

That measure is set out in article 38 and is called an ancillary sanction. Ancillary means it does not travel alone: it appears once fines have already been imposed for repeated very serious infringements. It is not a risk arising from a first failure or an isolated incident. It is the point reached by a company that was sanctioned, did not correct course and went on to do the same thing again.

This article explains the exact conditions under which the suspension of processing under Law 21.719 will apply, how long it can last, what falls outside its scope, and why the real operational risk lies not in the initial thirty days but in what happens afterwards if the company fails to comply.

Can the Agency suspend my company's data processing?

Yes, but under strict conditions. In Chile, Law 21.719 will allow the Personal Data Protection Agency to order the suspension of data processing operations and activities as an ancillary sanction under article 38, and only where fines are imposed for repeated very serious infringements within a twenty-four-month period. It is not the outcome of an isolated complaint. It is worth keeping the starting point in mind: the law will enter into force on 1 December 2026, under its first transitional article, so everything that follows describes a regime that is not yet in effect.

To understand where this measure fits, it helps to see the full structure of the regime. Article 33 provides that a data controller, whether a natural or legal person, governed by public or private law, that in its operations infringes the principles of article 3 and the rights and obligations set out in the law, will be sanctioned under that Title. Article 34 classifies infringements, according to their seriousness, as minor, serious and very serious. Article 35 assigns the principal sanctions: a written reprimand or a fine of up to 5,000 UTM for minor infringements, a fine of up to 10,000 UTM for serious ones and up to 20,000 UTM for very serious ones.

Article 35 adds a tier that summaries tend to leave out. If the infringing party is not a smaller-sized company under Law 20.416 and, in addition, reoffends in a serious or very serious infringement — these are two cumulative conditions — the fine may reach the more onerous of either triple the amount or 2% of annual revenue from sales and services in the last calendar year in the case of serious infringements, and 4% in the case of very serious ones.

Suspension is a different matter. It is added to the fine, it does not replace it, and its logic is therefore not revenue-driven but corrective: the law seeks to ensure that a controller who has already been sanctioned and persists stops processing data until it corrects what the Agency has ordered. Three clarifications pin the point down:

  • It is ancillary: it presupposes fines already imposed and does not operate on its own.
  • It is discretionary: article 38 says the Agency "may" order it, not that it must.
  • It is conditional: it requires repeated very serious infringements within a twenty-four-month window.

When does the suspension of processing under Law 21.719 apply?

It applies when three elements are present at the same time: that fines are imposed, that they are for very serious infringements, and that those very serious infringements are repeated within a twenty-four-month period. If any of the three is missing, article 38 of Law 21.719 does not authorize suspension, however serious the individual case may be.

Very serious infringements are listed in article 34 quater and involve high-intensity conduct: processing personal data fraudulently; maliciously using it for a purpose other than the one consented to by the data subject or provided for by law; knowingly communicating or transferring untrue, incomplete, inaccurate or outdated information about the data subject; breaching the duty of secrecy or confidentiality regarding sensitive data and data relating to the commission and punishment of criminal, civil, administrative and disciplinary offenses; knowingly processing, communicating or transferring sensitive data or data of children and adolescents in breach of the law; deliberately failing to report breaches of security measures; carrying out mass processing of data contained in electronic infringement registries kept by public bodies without legal authorization; and knowingly carrying out international data transfers in breach of the law. The vocabulary stands out: fraud, malice, knowingly, deliberately. Repetition of this conduct is the gateway to suspension.

One frequent confusion is worth clearing up here: recidivism in serious infringements does not turn those infringements into very serious ones. Recidivism is an aggravating circumstance under article 36, arising where the controller has been sanctioned on two or more occasions in the last thirty months for infringing this law, and its effect falls on the amount of the fine, not on how the conduct is classified. These are two different time windows and two different effects: thirty months for increasing the fine under article 36, twenty-four months for enabling suspension under article 38.

The suspension under article 38 of Law 21.719, element by element
ElementWhat article 38 provides
When it appliesWhere fines are imposed for repeated very serious infringements within a twenty-four-month period. It is a discretionary power: the provision states that the Agency "may" order it.
What is suspendedThe data processing operations and activities carried out by the controller. It may be partial or total.
DurationUp to a term of thirty days.
What it does not reachIt does not affect the storage of data by the controller.
Express limitIt may not be ordered where doing so would affect the rights of data subjects.
Obligation during the measureThe controller must adopt the measures needed to bring its operations into line with the requirements of the decision.
ExtensionIf it fails to comply, the measure may be extended indefinitely for successive periods of up to thirty days, until it complies with what was ordered.
Entity with a sector regulatorThe Agency must first bring the background information to the attention of that regulatory authority, in order to safeguard users' rights.

What does the suspension reach and what is expressly excluded?

The suspension under article 38 falls on processing operations and activities, may be partial or total, and extends for up to a term of thirty days. Law 21.719 also sets two explicit limits that are often overlooked and that completely change the risk analysis: it does not affect the storage of data by the controller, and it may not be ordered where doing so would affect the rights of data subjects.

The first limit has immediate practical consequences. Suspending processing is not the same as ordering deletion or preventing retention: the data remains in the company's systems. What stops are the operations, that is, the use. The second limit is even more relevant and deserves a careful reading. The text is brief — the measure may not be ordered where doing so would affect the rights of data subjects — and it does not list scenarios. A reasonable reading, which will need to be tested against the Agency's first decisions, is that suspension cannot end up harming the very people the law protects, for example if it prevented a data subject from exercising rights of access, rectification, erasure, objection or portability.

The fact that suspension may be partial is the other key to reading the provision. The Agency is not required to shut down the entire operation: the rule allows it to narrow the measure to the specific processing activity that gave rise to the very serious infringements. How that calibration will be used in practice cannot yet be anticipated, since there are no sanctions proceedings under way under this law; what the text does provide is the possibility of a narrow measure rather than a full stop. During that period, the controller must adopt the measures needed to bring its operations into line with the requirements of the decision. Suspension is not a passive punishment: it is a mandatory work window.

What happens if your company fails to comply with the order during the suspension?

This is the toughest part of article 38 and the one that rarely appears in summaries. If the controller does not comply with the measure, the suspension may be extended indefinitely for successive periods of up to thirty days, until it complies with what was ordered. The initial thirty days are not a ceiling: they are a first stretch.

That word, indefinitely, is what should feed into the board's operational continuity analysis. The cost of a fine can be provisioned, disputed and, eventually, challenged in court under the appeal procedure before the Court of Appeals set out in article 43. A suspension renewed every thirty days for as long as the company fails to demonstrate that it has brought its operations into line cannot be provisioned: it is simply endured. In business models where data processing is the operation — digital platforms, collections, scoring, marketing, healthcare, financial services — exposure depends exclusively on the company's own ability to comply within each period.

There is a special rule where the company is subject to a sector regulator. If the suspension affects an entity supervised by a public supervisory body, Law 21.719 requires the Agency to first bring the background information to the attention of that regulatory authority, in order to safeguard users' rights. It is a coordination mechanism, not an exemption: the supervised entity is not outside the scope of article 38, but its sector regulator joins the conversation before the measure takes effect. For banks, insurers, private health insurers, utilities and other regulated entities, this means the suspension will be decided in a two-authority setting.

Does article 38 provide for other ancillary sanctions, such as a prohibition or publication?

No. Article 38 of Law 21.719 provides solely for the suspension of processing operations and activities as an ancillary sanction. It is common to find summaries that also attribute to it a "prohibition on processing for a set period" or the "publication of the sanctioning decision". Neither appears in that provision, and the difference matters when sizing up the real risk.

Publicity does exist, but it arrives by another route: the National Registry of Sanctions and Compliance under article 39, created and administered by the Agency. That registry is public, free of charge and electronically accessible, and it records sanctioned controllers, distinguishing the seriousness of the infringement, the conduct infringed, the mitigating and aggravating circumstances, and the sanction imposed. Entries are publicly accessible for five years from the date the entry was made.

That time detail is the one usually underestimated. A fine is paid to the General Treasury of the Republic within ten business days from the date the Agency's decision becomes final, and that is the end of it. The entry in the article 39 registry stays with the company for five years, visible to clients, tender processes, counterparties and due diligence exercises. It is also worth not confusing time limits: under article 40, actions to pursue liability are subject to a four-year statute of limitations counted from the occurrence of the act — or from when the infringement ceased, in the case of a continuing infringement — while sanctions imposed are subject to a three-year statute of limitations from the date the decision becomes enforceable. The same registry has a positive and little-publicized side: it also records those who adopt certified prevention models in force.

To have the full map, it helps to distinguish four consequences that operate on different planes and over different timeframes:

  • Principal sanction: a written reprimand or a fine depending on the seriousness of the infringement, under articles 34 and 35, applying the determination criteria that the Agency must weigh prudentially under article 37.
  • Ancillary sanction: the suspension of processing under article 38, only for repeated very serious infringements within twenty-four months.
  • Publicity: the entry in the National Registry of Sanctions and Compliance under article 39, publicly accessible for five years.
  • Civil liability: compensation for pecuniary and non-pecuniary damage under article 47, an action brought once the Agency's favorable decision becomes enforceable or the judgment becomes final, and processed under the summary procedure.

How do you keep from reaching a suspension of processing?

You prevent it by avoiding the repetition of very serious infringements, which is the only condition that enables the measure. Put another way: under Law 21.719, suspension is not avoided in the room where the sanctions proceeding takes place; it is avoided much earlier, in how the company reacts to the first sanction and in the evidence it can show of having corrected course.

The first cut-off point is in article 35 itself: together with the sanction, the Agency sets out corrective measures, which must be adopted within no more than sixty days, and if they are not adopted the fine is increased by 50%. That deadline is the real fork in the road. The company that corrects within those sixty days closes the cycle; the one that does not accumulates the surcharge, becomes exposed to the aggravating circumstance of recidivism under article 36, and starts building the track record that makes suspension possible.

The second point is the preventive structure. Article 36 recognizes as mitigating circumstances unilateral remedial actions and settlement agreements with the affected data subjects, the cooperation the infringing party provides in the Agency's administrative investigation, the absence of prior sanctions, self-reporting to the Agency together with notice of the cessation or mitigation measures adopted, and having diligently complied with management and supervision duties, which is verified through the certificate issued under article 51. That last mitigating circumstance is what turns the infringement prevention model into something more than a document: it is how diligence is evidenced before the authority.

For smaller-sized companies under Law 20.416 there is a transitional rule that should be read precisely. The sixth transitional article provides that, during the first twelve months from entry into force, where a sanction is warranted in respect of those companies, the Agency may apply a written reprimand. It is a power of the authority, not automatic immunity, and the reprimand is still recorded under article 39.

The law will enter into force on 1 December 2026, so today, in August 2026, no company has repeated very serious infringements under Law 21.719. The twenty-four-month window under article 38 will only start running with the first sanctions proceedings. That is exactly the moment to work on the conduct covered by article 34 quater: governance of sensitive data and of data of children and adolescents, control of purposes, discipline in reporting breaches of security measures, and clear rules for international transfers. Not to be alarmed by the thirty days, but to never have to argue about them.

Review where your real exposure lies before December

At AlayIAtrust we work with boards and risk teams to identify which processing activities could qualify as very serious infringements under article 34 quater and what preventive structure makes it possible to evidence diligence before the Agency. Write to us and let's talk about your company's situation.

Schedule an assessment

Frequently asked questions

Can the Agency suspend data processing over a single very serious infringement?

No. Article 38 of Law 21.719 requires fines for repeated very serious infringements within a twenty-four-month period. A single very serious infringement, however grave, triggers the fine of up to 20,000 UTM under article 35 and the corrective measures, but not the suspension of processing.

How long can the suspension of processing under Law 21.719 last?

The suspension is ordered for up to a term of thirty days. However, if the controller does not comply with the order, article 38 allows it to be extended indefinitely for successive periods of up to thirty days, until it complies. In practice, the duration will depend on the company's own ability to bring itself into line.

Does the suspension require deleting the data the company already holds?

No. Article 38 of Law 21.719 expressly states that the suspension does not affect the storage of data by the controller. What stops are the processing operations and activities, that is, the use of the data. Retention of the information continues during the measure.

Does the suspension always halt the company's entire operation?

Not necessarily. Article 38 allows the suspension to be partial or total, so the Agency can narrow the measure to the specific processing activity that gave rise to the very serious infringements. Since the law is not yet in force, there is no administrative practice yet to anticipate how often each option will be used.

Is there any case in which the Agency cannot order the suspension?

Yes. Law 21.719 provides that the suspension may not be ordered where doing so would affect the rights of data subjects. It is an express limit in article 38: if halting processing would harm the people the law protects, the measure does not apply. It is one of its least publicized aspects.

What must the company do while the suspension is in force?

During the suspension period the controller must adopt the measures needed to bring its operations into line with the requirements of the Agency's decision. It is not a passive waiting period: it is an obligation to correct, and compliance is what determines whether the measure is lifted or extended.

What if my company is supervised by a sector regulator?

Law 21.719 sets a special rule: where the suspension affects an entity subject to supervision by a public supervisory body, the Agency must first bring the background information to the attention of that regulatory authority, in order to safeguard users' rights. This is prior coordination between authorities, not an exemption from the measure.

Does article 38 provide for publication of the sanctioning decision?

No. Article 38 of Law 21.719 provides only for suspension as an ancillary sanction. Publicity arrives by another route: the National Registry of Sanctions and Compliance under article 39, which is public, free of charge and electronically accessible, and keeps entries publicly accessible for five years.

Can recidivism in serious infringements lead to suspension?

Not directly. Recidivism is an aggravating circumstance under article 36, arising where the controller has been sanctioned on two or more occasions in the last thirty months for infringing this law, and its effect falls on the amount of the fine. Suspension under article 38 requires repeated very serious infringements within twenty-four months.

From when can the suspension of processing be applied in Chile?

Law 21.719 will enter into force on 1 December 2026, under its first transitional article. From that date sanctions proceedings may begin and, with them, the twenty-four-month window of article 38 will start running. Today, in August 2026, no company has accumulated infringements under this law.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Sanctions

Fines and sanctions under Law 21.719

Infringements

Serious and very serious infringements: the full catalogue

Compliance

Infringement Prevention Model: what it is and how it is certified

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment