Ley N° 21.719 · Chile

Chile’s data protection law has no threshold. It applies to you.

The complete documentation framework to reach 1 December 2026 with the programme built: 38 editable deliverables, from the processing inventory to the certification file.

64

days until it takes effect

1 December 2026

38

editable deliverables

8

phases

155

assessment controls

Why it matters

No applicability threshold, and fines of up to 20,000 UTM

Ley N° 21.719 applies to every organisation that processes personal data, with no threshold of size, revenue or headcount. Size does not decide whether it applies: it grades two duties and sets the ceiling for the fine.

105 of 155 controls admit no grading

Art. 14 septies allows differentiating the minimum standard only for informing the data subject and securing the data. Everything else is required equally, whatever the size.

The sanctions regime of article 35

Minor

5,000

UTM

$358,245,000

Serious

10,000

UTM

$716,490,000

Very serious

20,000

UTM

$1,432,980,000

A surcharge of up to 50% applies if the measures ordered by the Agency are not adopted within 60 days. Repeat offences within 30 months allow up to three times the amount. For companies that are not small and reoffend on serious or very serious counts, the ceiling becomes 2% or 4% of annual revenue.

Peso reference calculated with the UTM of August 2026.

Free self-assessment

How far is your organisation from compliance?

Answer the questions that apply to your organisation and get your blocking findings, your estimated exposure and a four-wave action plan in Word. Free, in Spanish.

Take the self-assessment (in Spanish)
What it includes

Eight phases in order of dependency

This is not an order of convenience. You cannot assign lawful bases to processing that is not inventoried, nor assess the impact of processing that has not yet been identified.

  1. 1

    Assessment and classification

  2. 2

    Inventory and lawful bases

  3. 3

    Documentation framework

  4. 4

    Operating procedures

  5. 5

    Third parties and transfers

  6. 6

    Impact assessment

  7. 7

    Prevention model and certification

  8. 8

    Monitoring and continual improvement

What exactly you receive

Editable Word and Excel templates, written end to end around a worked example organisation. You replace the details and approve them.

26

documents

Policies, procedures, matrices and reports. From the processing inventory to the regulatory interoperability map.

10

operational artifacts

What gets used daily: registers, data subject response templates, processing annexes and supplier questionnaires.

2

instruments

The conformity assessment with its 155 controls across 15 domains, and the reassessment with progress measurement.

Precision

Four things that circulate and that the statute does not say

The text of the law is the only source of this framework. Market guides, including those of trade associations, contain documented inaccuracies.

What gets repeated What the law says
“Small companies are exempt, or nearly so” The law has no applicability threshold. Only two duties are graded, and art. 14 septies is what grades them.
“Breach reporting has a 72-hour deadline” Art. 14 sexies requires reporting “by the most expeditious means possible and without undue delay”. There is no numeric deadline.
“The reporting threshold is significant harm” Art. 14 sexies sets the threshold at “reasonable risk to the rights and freedoms of data subjects”, which is lower.
“Putting data transfers in writing is advisable” Art. 15, final paragraph, provides that a transfer “shall be recorded in writing or through any suitable electronic means”.

What this toolkit is not

  • It is not legal advice. The deliverables are management instruments; legal validation is your organisation’s counsel’s responsibility.

  • It does not certify. Only the Agency issues the art. 51 certificate. The toolkit prepares the file you submit.

  • It does not include the data protection officer as a service, the indicator dashboard or the training sessions. Those are a continuing service and do not fit in a downloadable file.

Frequently asked questions

Which companies does Ley 21.719 apply to?

All of them. The law applies to every organisation that processes personal data, with no threshold of size, revenue or headcount. Size does not decide whether the law applies: it only grades two duties — informing the data subject and securing the data, under art. 14 septies — and sets the ceiling for fines. Of the 155 controls in the assessment, 105 admit no grading at all.

Is it true that small companies are exempt?

No. That is one of the most widely repeated misconceptions in the Chilean market. The law has no applicability threshold. What art. 14 septies allows is differentiating the minimum standard of two specific duties, not exempting anyone from the law. And the size classification that governs is the one in article two of Ley N° 20.416, which measures revenue in UF — not art. 505 bis of the Labour Code, which counts employees and does not apply to data protection.

When does it take effect, and how much time is left?

It takes effect on 1 December 2026, under the first transitional article. The law has been published since 13 December 2024, so the preparation window is already running. The fact that the Agency is not yet constituted does not prevent assessing or building: what you must evidence after an incident are the measures adopted, not the date the regulator came into being.

How large are the fines?

Art. 35 sets three bands: minor up to 5,000 UTM, serious up to 10,000 UTM and very serious up to 20,000 UTM — approximately CLP 358,245,000, 716,490,000 and 1,432,980,000. There is a surcharge of up to 50% if the measures ordered by the Agency are not adopted within 60 days, and repeat offences within 30 months allow up to three times the amount. For companies that are not small and reoffend, the ceiling becomes 2% or 4% of annual revenue.

Is it true that there are 72 hours to report a breach?

No. Art. 14 sexies sets no numeric deadline: it requires reporting «by the most expeditious means possible and without undue delay». The 72-hour figure comes from the European regulation and has been carried over by analogy, but it is not in the Chilean text. Nor is the threshold «significant harm»: the law sets it at «reasonable risk to the rights and freedoms of data subjects», which is lower.

What is the art. 49 prevention model, and why certify it?

It is the only economic incentive the law establishes expressly. Art. 36 No. 5 recognises as a mitigating factor having diligently fulfilled the duties of direction and supervision, «which shall be verified by the certificate issued in accordance with article 51». The toolkit prepares the model and the certification file; the certificate is issued by the Agency, not by us.

Does it also serve the Crime Prevention Model?

Largely. Twenty of the programme's deliverables also serve the model under Ley N° 20.393, as reformed by Ley N° 21.595 on economic crimes. The processing inventory, the processor register, the incident procedures and the consolidated compliance file are built once and evidence both fronts.

What about the parts that are not yet regulated?

Seven matters are delegated to secondary regulation that has not yet been issued: minimum standards by size, the list of processing operations requiring an impact assessment, the methodology for that assessment, authentication costs, model processing contracts, the certification regulation, and the constitution of the Agency. The toolkit works from the statutory text and comparative good practice, and flags in each case what remains subject to future rules. None of that prevents building: the law is already published.

Does buying the toolkit put me in compliance?

No, and it is worth saying plainly. The toolkit is the documentation framework: it saves you the drafting, usually the longest phase. It does not save you inventorying your actual processing, assigning lawful bases, appointing owners or operating the procedures. Art. 14 quinquies, final paragraph, places on the controller the burden of evidencing «the existence and the functioning» of the measures after an incident: a framework built and then abandoned evidences existence, not functioning.

Is this legal advice?

No. The deliverables are compliance management instruments. Legal validation of their content is the responsibility of each organisation's legal counsel. Snap Compliance publishes the documentation framework; it does not act as counsel nor replace one.

Another question? Write to us at toolkits@snap-compliance.com

Few months are left and the order of the phases cannot be skipped

This toolkit is in preparation. Leave us your email and we will let you know as soon as it is published.

This toolkit does not constitute legal advice. The regulatory data corresponds to the text of Ley N° 19.628 as consolidated by Ley N° 21.719, published on 13 December 2024.