← Data protection · Law 21.719

FREQUENTLY ASKED QUESTIONS

Frequently asked questions about Law 21.719

What your company needs to know to comply with Chile's Personal Data Protection Law: who it applies to, people's rights, deadlines, consent, breaches and penalties.

This is general, informational guidance. It is not legal advice; for your specific case, check with your legal or compliance team.

Frequently asked questions

Does Law 21.719 apply to my company?
Yes. It applies to any company that processes personal data, regardless of size or industry. If you have a customer base, a payroll or a contact form, you are processing personal data and the law reaches you just as it does a large listed company.There is no small-business exemption. What may vary case by case is the detail of certain measures, not the obligation to comply.
When does Law 21.719 take effect?
It was published on December 13, 2024 and takes full effect on December 1, 2026. Until then, a transition period governed by the former Law 19.628 is in force.On that same date the Personal Data Protection Agency, the new body that oversees and sanctions, begins to operate.
What rights can people exercise over their data?
Access, rectification, erasure, objection and portability, plus temporary blocking. These rights are known as ARSOP. Anyone can ask to see their data, correct it, have it deleted, object to a use, or take it in a portable format to another provider.These rights are enforceable from day one, so your company needs a clear channel to receive and answer them.
How long do I have to answer a rights request?
You have 30 calendar days from when the request comes in, extendable by another 30 when the case is complex.Exercising the right is generally free; access and portability may carry a direct cost only if requested more than once in the same quarter. A blocking request runs on a much shorter deadline, a few business days.
What does valid consent look like? Is a pre-ticked box enough?
No. Consent must be free, specific, informed and unambiguous, which rules out pre-ticked boxes and silence. The person has to take a clear affirmative action.For sensitive data, such as health or union membership, consent must also be explicit, and the burden of proving you obtained it falls on you.
What is the RAT and am I required to keep one?
The RAT is the Record of Processing Activities, the inventory of what data you process, for what purpose, on what legal basis and for how long you keep it. Yes, keeping it is mandatory.More than a document you sign once, it is the tool with which you show that you know and control what your company does with the information.
What do I have to do if I suffer a data breach?
Contain the incident immediately and notify the Agency without undue delay. When the breach affects sensitive data, children's data or financial obligations, you must also notify the people affected.Having a notification template ready in advance is what lets you meet the deadline when the incident happens under pressure.
What are the fines for breaching Law 21.719?
Infringements are graded as minor, serious and very serious, with ceilings of 5,000, 10,000 and 20,000 UTM respectively. Those amounts are the legal ceiling, not the fine applied by default.The actual amount depends on the size of the company, the severity and whether it is a repeat offense. Having a certified Infringement Prevention Model works as a mitigating factor.
What is a DPIA and when is it mandatory?
The DPIA is the Data Protection Impact Assessment, a prior risk analysis the law requires before starting high-risk processing, such as profiling or large-scale data processing.Its purpose is to detect what could go wrong with that data before you touch it, not after.
Can I store or process data on servers outside Chile?
Yes, as long as the destination country offers an adequate level of protection or there are safeguards such as standard contractual clauses. You must inform the data subject of that transfer.Once the Agency publishes its list of countries with an adequate level, that will be the reference criterion for assessing each destination.

Glossary

Terms from Law 21.719 that appear in these answers.

ARSOP
The data subject's rights over their data: access, rectification, erasure, objection and portability, plus temporary blocking.
RAT
Record of Processing Activities. The inventory of what data the company processes, for what, on what legal basis and for how long it keeps it.
DPIA
Data Protection Impact Assessment. A prior, mandatory risk analysis before starting high-risk processing.
DPO
Data Protection Officer. The person in charge of overseeing compliance and acting as the point of contact with the Agency and with data subjects.
Sensitive data
Data revealing aspects such as health, racial origin, religious beliefs, union or political membership, sex life or biometric data. Its processing requires explicit consent.
Controller and processor
The controller decides why and how data is processed; the processor handles it on the controller's behalf and under its instructions, governed by a contract (DPA).
Data breach
Any destruction, loss, leak, alteration or unauthorized access to personal data. It must be reported to the Agency without undue delay.