BlackTree Security · Infrastructure · Automation · AI

Chile’s Privacy Overhaul Has a 1 December 2026 Start Date

Chile is transforming an older database law into a modern accountability regime, created a dedicated regulator and given organisations until 1 December 2026 to make the change operational.

Chile published Law No. 21.719 on 13 December 2024. The legislation substantially rewrites Law No. 19.628, renames it as the law on the protection of personal data and creates a specialist Data Protection Agency.

The main amendments enter into force on 1 December 2026. This two-year implementation period is not excessive for an organisation that has never maintained an accurate processing inventory, structured rights workflow or evidence of lawful processing.

Rights must work through the system

The modernised law gives individuals rights of access, rectification, deletion, opposition, portability and blocking. These rights are personal, cannot be waived and must be exercisable without artificial friction.

The difficult part is rarely receiving a request. It is finding every relevant copy, validating the person, separating data that can be changed from data that must be retained, reaching processors and producing a consistent response.

Portability adds another technical requirement. Systems need a way to extract applicable data in a usable form without exposing other individuals, internal secrets or unrelated security information.

Consent is only part of the legal architecture

Consent remains important, especially for sensitive information, but the law provides a broader structure of permitted processing. An organisation should therefore avoid using a single consent banner as a substitute for analysing purpose, necessity and the correct legal basis.

The data inventory should connect each processing activity to its purpose, categories of people and data, recipients, retention rule, transfer locations, security measures and legal justification. If that evidence exists only in a lawyer’s spreadsheet, it will fall out of date as soon as a product team changes a workflow.

Sensitive data and children require stronger discipline

The law recognises special categories including health, biometric, genetic, political, religious and sexual-life information. It also includes specific protections for children and adolescents.

These categories should drive technical controls. Access restrictions, encryption, monitoring, retention and testing should reflect the harm that misuse could cause, not merely whether the database has been labelled “confidential”.

Automated decisions and profiling also require review. Teams need to identify where software evaluates people, what information influences the outcome and whether the decision creates legal or similarly significant effects.

A regulator changes the enforcement environment

Chile’s existing privacy framework lacked the kind of independent specialist authority found in many modern regimes. Law No. 21.719 creates an agency with powers to interpret, supervise and sanction.

This changes the evidence expected from controllers. A public privacy notice remains necessary, but it will not demonstrate that retention rules run, access permissions are reviewed or complaints reach the correct team. Organisations need operational records that connect policy to actual behaviour.

The law also introduces a formal infringement and penalty structure. Boards should treat privacy readiness as a measurable programme with ownership, milestones and testing rather than a final legal review shortly before commencement.

The implementation window should be used in stages

2025: discover and assign

Identify processing activities, systems, suppliers and international flows. Assign accountable business owners and create a remediation register.

Early 2026: build and integrate

Implement rights handling, retention, processor governance, incident assessment and privacy review in the product-development lifecycle. Update contracts and notices from the same source of truth.

Before December 2026: test

Run access, deletion and portability exercises. Simulate a breach involving sensitive data. Sample production systems to verify that written rules match actual settings.

Questions management should ask

  • Can the organisation explain why every material category of personal data is processed?
  • Can it honour all statutory rights across production systems and processors?
  • Are high-risk, sensitive and children’s-data activities identified before launch?
  • Do retention rules trigger deletion rather than merely describe it?
  • Can the incident team assess harm to people as well as harm to the company?
  • Is there evidence that controls operate continuously?

Chile has provided a fixed destination and a useful runway. The organisations that benefit will use it to redesign how data moves through products, not simply to rewrite how those products are described.

Official sources

This article provides general information and is not legal advice. Article updated in September 2026

Leave a Reply

Your email address will not be published. Required fields are marked *