Jurisdiction Guides / Americas
Chile Privacy & Data Protection Laws
Every regime below can apply to a business handling Chile residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Chile's operative regime until December 2026 is Law 19.628, a 1999 statute that predates every modern data-protection model: it permits processing on a broad statutory-authorization basis, has no dedicated supervisory authority (enforcement runs through ordinary civil courts), no administrative fines, and no extraterritoriality clause — so a foreign business without a Chilean establishment is generally outside its practical reach. Data protection was elevated to a constitutional right in 2018 (Law 21.096) without changing this operating framework. This is being replaced in full: Law 21.719, published December 13, 2024, enters into force December 1, 2026 with a GDPR-style targeting test, a new Personal Data Protection Agency, and a sanctions regime — see the pending entry below, and plan against that rather than against Law 19.628 if your compliance horizon runs past 2026.
On the Horizon — Proposed, Not Yet Law · 1
A GDPR-style rebuild of Chilean data protection. It applies to controllers and processors operating from Chile, to processors handling data on behalf of a Chile-based controller, and — extraterritorially — to controllers or processors located outside Chile whose processing targets people in Chile by offering goods or services to them or monitoring their behavior. It introduces lawful bases beyond consent (contract performance, legitimate interest), a defined category of sensitive data, data-subject rights including access, rectification, deletion and portability, breach notification, and a tiered fine regime running to 20,000 UTM for very serious infringements. The creation of an independent Personal Data Protection Agency is the structural change: Chile moves from court-only enforcement to a supervisory authority with administrative sanctioning power.
Status: Published December 13, 2024 with a 24-month vacancy period. As enacted it enters into force December 1, 2026, at which point it replaces Law 19.628 in full and the new Agencia de Proteccion de Datos Personales assumes enforcement, including the sanctions regime. That date is now contested. Boletin 18.623-07, a presidential Mensaje (N° 110-374) to the Senate dated August 31, 2026, would amend the first transitory article to replace the 24-month vacancy with a fixed entry-into-force date of December 1, 2027 (Articulo unico, numeral 2). The same bill enlarges the Agency's Consejo Directivo from three to five members, requires the first councillors to be appointed at least twelve months before entry into force, and removes the small-business-only limitation on written admonition in the sixth transitory article. The postponement is NOT law: until Boletin 18.623-07 is passed and published, December 1, 2026 remains the operative date and businesses serving Chilean customers should keep building against it. VERIFIED against the bill text (Camara de Diputados document, prmID 18854). The Senate tramitacion record for Boletin 18.623-07 shows the bill entering the Senate on September 1, 2026 as its first constitutional tramite, still 'en tramitacion' with no vote as of September 11, 2026 - which leaves under three months to the operative date. Still not confirmable: whether the bill carries an urgencia. Press reports describe it as filed with 'suma urgencia', but no urgencia appears on the Senate record, and urgency is designated by separate oficio - treat the claim as unconfirmed.
Other Americas jurisdictions