Chile’s data protection law has no threshold. It applies to you.
The complete documentation framework to reach 1 December 2026 with the programme built: 38 editable deliverables, from the processing inventory to the certification file.
64
days until it takes effect
1 December 2026
38
editable deliverables
8
phases
155
assessment controls
No applicability threshold, and fines of up to 20,000 UTM
Ley N° 21.719 applies to every organisation that processes personal data, with no threshold of size, revenue or headcount. Size does not decide whether it applies: it grades two duties and sets the ceiling for the fine.
105 of 155 controls admit no grading
Art. 14 septies allows differentiating the minimum standard only for informing the data subject and securing the data. Everything else is required equally, whatever the size.
The sanctions regime of article 35
Minor
5,000
UTM
$358,245,000
Serious
10,000
UTM
$716,490,000
Very serious
20,000
UTM
$1,432,980,000
A surcharge of up to 50% applies if the measures ordered by the Agency are not adopted within 60 days. Repeat offences within 30 months allow up to three times the amount. For companies that are not small and reoffend on serious or very serious counts, the ceiling becomes 2% or 4% of annual revenue.
Peso reference calculated with the UTM of August 2026.
Free self-assessment
How far is your organisation from compliance?
Answer the questions that apply to your organisation and get your blocking findings, your estimated exposure and a four-wave action plan in Word. Free, in Spanish.
Eight phases in order of dependency
This is not an order of convenience. You cannot assign lawful bases to processing that is not inventoried, nor assess the impact of processing that has not yet been identified.
-
1
Assessment and classification
-
2
Inventory and lawful bases
-
3
Documentation framework
-
4
Operating procedures
-
5
Third parties and transfers
-
6
Impact assessment
-
7
Prevention model and certification
-
8
Monitoring and continual improvement
What exactly you receive
Editable Word and Excel templates, written end to end around a worked example organisation. You replace the details and approve them.
26
documents
Policies, procedures, matrices and reports. From the processing inventory to the regulatory interoperability map.
10
operational artifacts
What gets used daily: registers, data subject response templates, processing annexes and supplier questionnaires.
2
instruments
The conformity assessment with its 155 controls across 15 domains, and the reassessment with progress measurement.
Four things that circulate and that the statute does not say
The text of the law is the only source of this framework. Market guides, including those of trade associations, contain documented inaccuracies.
| What gets repeated | What the law says |
|---|---|
| “Small companies are exempt, or nearly so” | The law has no applicability threshold. Only two duties are graded, and art. 14 septies is what grades them. |
| “Breach reporting has a 72-hour deadline” | Art. 14 sexies requires reporting “by the most expeditious means possible and without undue delay”. There is no numeric deadline. |
| “The reporting threshold is significant harm” | Art. 14 sexies sets the threshold at “reasonable risk to the rights and freedoms of data subjects”, which is lower. |
| “Putting data transfers in writing is advisable” | Art. 15, final paragraph, provides that a transfer “shall be recorded in writing or through any suitable electronic means”. |
What this toolkit is not
-
It is not legal advice. The deliverables are management instruments; legal validation is your organisation’s counsel’s responsibility.
-
It does not certify. Only the Agency issues the art. 51 certificate. The toolkit prepares the file you submit.
-
It does not include the data protection officer as a service, the indicator dashboard or the training sessions. Those are a continuing service and do not fit in a downloadable file.
Frequently asked questions
Which companies does Ley 21.719 apply to?
Is it true that small companies are exempt?
When does it take effect, and how much time is left?
How large are the fines?
Is it true that there are 72 hours to report a breach?
What is the art. 49 prevention model, and why certify it?
Does it also serve the Crime Prevention Model?
What about the parts that are not yet regulated?
Does buying the toolkit put me in compliance?
Is this legal advice?
Another question? Write to us at toolkits@snap-compliance.com
Few months are left and the order of the phases cannot be skipped
This toolkit is in preparation. Leave us your email and we will let you know as soon as it is published.
This toolkit does not constitute legal advice. The regulatory data corresponds to the text of Ley N° 19.628 as consolidated by Ley N° 21.719, published on 13 December 2024.