← Back to blog

Video Surveillance and Law 21.719: How to Use Security Cameras Without Breaching Data Protection

Images of identifiable people are personal data, and video surveillance under Law 21.719 requires your company to justify, disclose and limit every camera it installs. Here is the practical guide to getting it right.

GUIDE - LAW 21.719

The essentials in 30 seconds

  • Images of identifiable people are personal data: your cameras are processing data and fall under Law 21.719.
  • Facial recognition uses biometric data, considered sensitive, and demands a much higher standard of protection.
  • You don't always need consent: in practice, the basis usually invoked for security video surveillance is a balanced legitimate interest, provided you meet proportionality and disclosure requirements.
  • Without visible signage, defined retention periods and excluded areas (restrooms, changing rooms), your CCTV system does not comply.

Video surveillance has become part of the landscape: cameras at the building entrance, in the retail sales floor, in the warehouse, in the office hallways. The problem is that almost no one treats them as what they legally are. Every time a camera captures a person who can be recognized, your company is processing personal data, and under Law 21.719 that stops being a technical detail and becomes an enforceable obligation. If you want the full picture, start with our guide to the data protection law in Chile.

The new law updates Chile's data protection framework, which was previously governed solely by Law 19.628. It was published in December 2024 and reaches full effect in December 2026, following a transition period. It also creates the Personal Data Protection Agency, an authority with powers to audit and impose sanctions. For anyone operating cameras, the message is clear: the image of an identifiable person is data, and you must justify why it is captured, disclose it, limit it and keep it only as long as necessary.

In this guide we explain, in practical and honest terms, how to fit your video surveillance within Law 21.719: which lawful basis applies, how proportionality and data minimization work, what the duty to inform requires, how long you can retain footage, where you must never record, and how to handle third-party access and requests from the people being recorded. We don't promise guaranteed compliance, but we do offer a clear path to stop improvising.

Why a Camera Processes Personal Data (and When It Becomes Sensitive Data)

The starting point is understanding that the image of a person who can be identified, directly or indirectly, is personal data. It doesn't matter whether the recording is live or stored, or whether the person is a customer, an employee or someone simply walking down the sidewalk. If an individual can be recognized from that image, your CCTV system is a processing of personal data and is subject to the principles of Law 21.719: lawfulness and fairness, purpose, proportionality, quality, accountability, security, transparency and disclosure, and confidentiality.

There is a shift in category that many companies don't see coming. An ordinary camera captures images; a facial recognition system extracts biometric features to identify or verify a person. Those biometric data are sensitive data under Chilean law, in the same family as health, racial or ethnic origin, beliefs or convictions, and socioeconomic status. Processing sensitive data requires a far more demanding standard of protection and a much stronger justification.

In practice, this means that installing cameras for security is one thing, and activating biometric analytics or facial recognition is another matter entirely. The latter should not be done automatically or as a trend: it requires careful assessment, a solid legal basis and, in many cases, reviewing whether the objective can be achieved through less invasive means.

  • Personal data: any image from which a person can be identified.
  • Sensitive data: the biometric features that facial recognition uses to identify or verify.
  • Rule of thumb: the greater the ability to uniquely identify, the higher the legal requirement.

Lawful Basis: When Legitimate Interest Is Enough and When It Isn't

One of the most widespread myths is that you always need people's consent in order to record. Law 21.719 recognizes consent as a lawful basis, but not as the only one. There are other bases that can enable processing, such as compliance with a legal obligation, the performance of a contract or relationship to which the data subject is a party, and the legitimate interest of the controller, provided it is weighed against the rights and freedoms of the affected individuals.

For video surveillance aimed at protecting people and property, the basis that usually fits best is legitimate interest. Protecting a store, a building or its workers is a legitimate objective, but invoking that basis is not a blank check: it requires a genuine balancing exercise. You must ask yourself whether the camera is necessary for that purpose, whether there is a less intrusive route, and whether the impact on people's privacy is reasonable against the security benefit. It's wise to document that assessment, because the accountability principle requires you to be able to demonstrate that you made the decision diligently. That said, the law does not designate a single basis for cameras: rather than an automatic rule, legitimate interest is the criterion that usually fits in practice, and you must justify and document it case by case.

Consent, on the other hand, is fragile in contexts where there is no real freedom to refuse, such as the employment relationship: asking an employee to consent to being recorded can hardly be regarded as fully free consent, because a relationship of dependence exists. That is why, in HR settings and in spaces open to the public, relying on a well-balanced legitimate interest, rather than on forced consent, is usually the right approach. Facial recognition, because it processes sensitive data, demands an even more robust justification and should not rest on a loose interpretation of legitimate interest.

Proportionality and Minimization: Record Only What Is Necessary, Not Everything Possible

Proportionality and minimization are probably the principles most often breached in practice. Minimizing means processing only the data you truly need for your purpose, not one bit more. Applied to cameras, this translates into concrete design decisions: where you point each lens, what angle it covers, whether you capture audio (which is almost never necessary and worsens the intrusion), and whether the resolution or analytics you use are proportional to the risk you want to control.

A common mistake is covering more than necessary. A camera meant to monitor the store's checkout should not frame the entire sidewalk or the neighboring business's entrance; a warehouse camera should not permanently point at an employee's workstation to monitor their performance, because that is no longer a security purpose. Each camera must have a defined and honest purpose, and its scope must be tailored to that purpose.

Minimization also applies to time and access. Not all staff need to view the footage, and not all images should be kept indefinitely. The more you limit who accesses the footage, for what, and for how long, the easier it is to argue that your system is proportional.

  • Define the purpose of each camera before installing it, not after.
  • Adjust the framing so it doesn't capture other people's spaces or public areas unnecessarily.
  • Avoid audio unless there is a clear and indispensable justification.
  • Reserve advanced analytics and facial recognition only for cases with solid justification.

Duty to Inform: Visible Signage Is Not Optional

The principle of transparency and disclosure requires that people know they are being recorded before entering the monitored area. In video surveillance, this takes the form of signage: clear, visible signs placed at entrances and at points where anyone can notice them without effort. A hidden or unmarked camera is, in practice, unfair processing.

The sign is only the first layer of information. It should briefly state that the area is under video surveillance, who the data controller is and how to obtain more information. The second, more detailed layer can live in your privacy policy or in a document available on request, where you explain the purpose of the cameras, the lawful basis, the retention period, whether the images are shared with third parties and how to exercise the rights of access, rectification, erasure, objection and portability (in addition to blocking).

In the workplace, the duty to inform is even stricter: workers must clearly know where the cameras are, for what purpose and with what scope. Informing properly is not just a legal requirement; it also reduces conflict and strengthens trust within the organization.

  • A visible sign at every entrance to the monitored area.
  • Basic information: the monitored area, the controller and how to learn more.
  • Expanded information available: purpose, lawful basis, retention, third parties and how to exercise rights.
  • In workplaces, notify workers before activating the cameras.

Footage Retention, Prohibited Areas and Third-Party Access

Footage should not be kept forever. The purpose and proportionality principles require keeping it only for as long as is reasonably necessary to fulfill the security purpose. Chilean law does not set a specific number of days on this matter, so the key is to define a prudent, limited period, document it and respect it: once that period passes, the images should be deleted, ideally automatically, unless a specific incident justifies keeping a particular recording as evidence.

There are places where you simply must not record, because the expectation of privacy is so high that no security purpose can justify it: restrooms, changing rooms, locker rooms, nursing rooms and rest areas intended for privacy. Installing cameras there is disproportionate by definition. Nor is it appropriate to covertly monitor workers at their stations in order to check their performance; the legitimate focus of video surveillance is security, not permanent workplace control.

Third-party access must also be handled with judgment. Providing footage to a security provider, the police or a third party requires a basis that justifies it and, where appropriate, a data processing agreement setting out the conditions and responsibilities. And if a breach of security measures occurs that causes destruction, leakage, loss or alteration of the footage, the controller must notify the Agency without undue delay and by the most expedient means, and also notify the affected individuals when the incident may affect their rights, with particular care if sensitive data is involved.

  • Define and document a limited retention period, with deletion ideally automated once it expires.
  • Never install cameras in restrooms, changing rooms, locker rooms or rest areas.
  • Do not use video surveillance as a covert tool to monitor work performance.
  • Regulate third-party access with a data processing agreement and a basis that justifies it.

Checklist to Bring Your Video Surveillance Into Compliance

If you have cameras running and you're not sure whether they comply, you don't need to start from scratch: you need to get organized. Most problems are solved by reviewing purpose, disclosure, retention and access, and documenting everything so you can demonstrate it to the Agency. The accountability principle not only asks you to do things right, but to be able to prove it.

Use this list as a starting point for an internal review. It doesn't replace a professional assessment, but it helps you spot the most common gaps before they become a risk.

Remember that the law reaches full effect in December 2026: the transition period is precisely there to get these systems in order calmly, not to leave them for last.

  • Inventory all cameras and define, in writing, the purpose of each one.
  • Check the framing: make sure none capture public areas, neighboring properties or prohibited zones.
  • Determine the lawful basis (usually legitimate interest) and document the balancing exercise.
  • Install visible signage at all entrances to monitored areas.
  • Publish the expanded information in your privacy policy and communicate it to workers.
  • Set a reasonable retention period with deletion, ideally automated, once it expires.
  • Restrict who can access the footage and keep a record of those accesses.
  • Formalize data processing agreements with the third parties that operate or access the system.
  • Assess any use of facial recognition with particular rigor: it is sensitive data.
  • Prepare a procedure to respond to requests from recorded individuals and to notify breaches.

Bring your video surveillance into compliance before December 2026

At AlayIAtrust we help companies, retailers and buildings in Chile get their CCTV systems in order under Law 21.719: lawful basis, signage, footage retention, excluded areas and facial recognition assessment. Schedule an assessment and you'll know exactly what to adjust, with no empty promises or scaremongering.

Schedule an assessment

Frequently asked questions

Do I need people's consent to have security cameras?

Not always. Consent is one of the lawful bases, but not the only one. For video surveillance aimed at protecting people and property, the basis that usually applies is the controller's legitimate interest, provided it is weighed against the rights of the affected individuals and you comply with disclosure, minimization and proportionality. In workplace contexts, forced consent is rarely valid, so it is preferable to rely on a well-justified legitimate interest.

How long can I keep footage from my cameras?

Chilean law does not set a specific number of days for this. The criterion is to keep the images only for as long as is reasonably necessary for the security purpose, and then delete them. In practice, it's advisable to define a prudent, limited period, document it and schedule deletion, ideally automated, once it expires, unless a specific incident justifies keeping a particular recording as evidence.

Is facial recognition legal under Law 21.719?

Facial recognition processes biometric data, which in Chile is sensitive data. This does not prohibit it outright, but it significantly raises the standard: it requires a solid justification, a clear legal basis and a serious assessment of whether the objective can be achieved through less invasive means. It should not be activated automatically or rest on a loose interpretation of legitimate interest. When in doubt, the prudent course is not to use it until you have specialized advice.

What should the video surveillance sign say?

As a first layer of information, the sign must be visible at entrances and state that the area is under video surveillance, who the data controller is and how to obtain more information. The second, more detailed layer lives in your privacy policy or in a document available on request, and includes the purpose, the lawful basis, the retention period, whether the images are shared with third parties and how to exercise the rights of access, rectification, erasure, objection and portability.

Can a recorded person ask me for access to the images they appear in?

Yes. The law recognizes the rights of access, rectification, erasure, objection and portability, which include access. A person can request information about the processing of their image and, depending on the case, access the recordings they appear in, with the applicable limitations to protect the rights of third parties who also appear in the video. It's advisable to have a defined procedure to receive and respond to these requests within reasonable timeframes and to keep a record of how they are handled.

What happens if my camera footage is stolen or leaked?

That constitutes a breach of security measures. The controller must notify the Personal Data Protection Agency without undue delay and by the most expedient means possible, and notify the affected individuals when the incident may affect their rights, with particular care if sensitive data is involved. This is why it is essential to have security measures and an incident response plan in place before the problem occurs.

You may also be interested in

Sensitive data

Sensitive data under Law 21.719: what they are and how to protect them

Lawful bases

Lawful bases and consent: when you need it

HR

Employee data: a privacy guide for HR

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment