{
 "jurisdiction_id": "CL",
 "jurisdiction": "Chile",
 "url": "https://dataprotection.gi/jurisdictions/chile/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 47,
  "sub_modules": 57,
  "source_register": 13
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/chile/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Statute enacted and constitutionally validated, but the regulator is not yet operational and the implementing regulation is not yet finalized; current in-force law (Ley 19.628) is materially weaker than the incoming regime.",
   "claims": [
    {
     "statement": "<cite index=\"42-1,42-2\">The Agencia de Protección de Datos Personales is an autonomous, technical, decentralized public-law corporation with its own legal personality and patrimony, relating to government through the Ministry of Economy, and is governed by a directive council made up of three counsellors.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"41-1\">Under a January 2026 public-sector adjustment law, the Agency's Consejo Directivo must be designated before 1 June 2026, requiring the presidential nomination to occur between March and April.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/d-a-de-la-pdp-en-chile-estamos-preparados-para-la-entrada-en-vigor-de-la-normativa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"6-1\">Ley N.º 21.719, which regulates the protection and treatment of personal data and creates the Agencia de Protección de Datos Personales, enters into force on 1 December 2026.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/los-desaf-os-ante-las-regulaciones-tecnol-gicas-en-chile-una-oportunidad-para-la-autorregulaci-n",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Ley N.º 19.628 sobre protección a la vida privada (1999) remains the current operative statute governing personal data processing in Chile until Ley 21.719 takes effect, as confirmed by multiple 2025-2026 legal commentaries referencing its continued applicability pending the reform's entry into force.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-reglamento-de-seguridad-privada-de-la-ley-n-21-659-y-la-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"34-1\">On 13 June 2025 the Ministry of Finance issued Decreto Supremo N.º 662, approving the Regulation governing requirements, modalities and procedures for the implementation, certification, registration and supervision of Infraction Prevention Models, which remains in the process of legality review before the Contraloría General de la República.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/se-dictan-nuevos-modelos-de-prevenci-n-de-infracciones-que-modifican-la-ley-de-protecci-n-de-datos-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"53-2\">Ley 21.719 establishes special regimes for biometric data; data relating to children and adolescents; data used for historical, statistical, scientific or research purposes; and geolocation data.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"23-3\">The regulation applies to subjects constituted in Chilean territory, to those carrying out data-processing operations established in national territory, and to those offering goods or services in Chile, whether through their activities or by application of a contract or international law.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"2-8,2-9\">A parliamentary-motion bill (Boletín N.º 18.060-07), currently in first constitutional procedure, proposes to perfect aspects of Ley N.º 21.719, including limiting the law's scope of application with respect to the extraterritorial rule.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/d-a-de-la-pdp-en-chile-estamos-preparados-para-la-entrada-en-vigor-de-la-normativa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"11-9,11-10\">The law establishes leve, grave and gravísima infringement tiers with a certification-based Infraction Prevention Model recognized by the Agency as a mitigating factor, and certified models are entered into a national registry administered by the Agency.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/chile/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Expanded lawful bases and sensitive-data regime are enacted but not yet effective (1 Dec 2026); current regime is narrower.",
   "claims": [
    {
     "statement": "<cite index=\"28-15\">Ley 19.628 only recognizes as sources of lawful processing legal authorization and the express and written consent of the data subject.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-nuevo-entorno-regulatorio-de-la-proteccion-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"23-1\">The new law recognizes international/domestic transfer scenarios and lawful processing hypotheses including legitimate interest, vital interest, formulation/exercise/defense of a right, legal duty compliance, banking/financial/stock-market transactions, international obligations or cooperation agreements, express legal authorization, international judicial cooperation, contract necessity or precontractual measures, and urgent medical or health measures.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"53-1\">Regarding sensitive personal data, as a general rule its processing must be carried out with the express consent of the data subject, without prejudice to exceptions.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"53-1\">Sensitive data may be processed without express consent when it has been made manifestly public and its use relates to the published purposes, when a legitimate interest is involved, when a vital interest is involved, for the formulation, exercise or defense of a right, and in compliance with a legal duty.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"28-2,28-3\">Data must be retained only for the period necessary to fulfil the purposes of processing, after which it must be deleted or anonymised, and processing for a longer period requires legal authorization or the data subject's consent.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-nuevo-entorno-regulatorio-de-la-proteccion-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/chile/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights expansion enacted but not yet effective; current ARCO regime under Ley 19.628 is narrower and lacks portability/blocking/ADM-opposition rights.",
   "claims": [
    {
     "statement": "<cite index=\"31-1\">Data subjects must be permitted the full exercise of their rights of access, rectification, suppression or opposition, and portability, unless a legal limitation exists.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-reglamento-de-seguridad-privada-de-la-ley-n-21-659-y-la-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"23-5\">Regarding data subject rights, in addition to those currently recognized in Ley N.º 19.628 — access, rectification, and cancellation (now termed suppression) and opposition — the new law adds blocking, portability, and opposition to automated decisions.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"23-5\">The rights catalogue is extended to include blocking and opposition to automated decisions.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"23-5\">Portability is added as a new data subject right not previously recognized under Ley 19.628.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"11-13\">An administrative procedure is established under which, if within 30 calendar days following the filing date (extendable once) the request is denied in whole or in part or no response is given, the data subject may file a claim with the Agencia de Protección de Datos Personales.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/chile/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability and breach/security duties are enacted but not yet effective; DPO is only conditionally mandatory and no formal RoPA is required, both material divergences from GDPR.",
   "claims": [
    {
     "statement": "<cite index=\"10-10\">The future law recognizes the principle of accountability, indicating that those who process personal data must, in the event of non-compliance with principles, obligations or other provisions, take responsibility for possible infringements of the regulation.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/la-normativa-sobre-protecci-n-de-datos-personales-en-chile-por-d-nde-partir-",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"22-9,22-10\">Where processing involves systematic observation or monitoring of a publicly accessible area, an impact assessment must be carried out, considering the description of the processing operations, the purpose, and the evaluation of necessity and proportionality, and thus the risks and mitigation measures.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-reglamento-de-seguridad-privada-de-la-ley-n-21-659-y-la-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"4-3,4-4\">A major novelty of Ley N.º 21.719 is the introduction of the data protection delegate figure, a role that is in principle voluntary, applying only to entities that adopt an infraction prevention model.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/la-figura-del-dpo-seg-n-la-ley-n-21-719-en-qu-rea-debe-ubicarse",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"4-1\">Decree N.º 662's Article 8 establishes that the DPO must report directly to the authority that designated them, and that authority must be the entity's highest directive or administrative authority.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/la-figura-del-dpo-seg-n-la-ley-n-21-719-en-qu-rea-debe-ubicarse",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"12-8\">Unlike the GDPR, the future law does not require controllers to maintain a formal record of processing activities (Article 30 GDPR equivalent), though a transparency duty requires publishing categories of data processed, the general description of the data subjects, recipients, purposes, legal basis, and, for legitimate-interest processing, what those interests are.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/la-normativa-sobre-protecci-n-de-datos-personales-en-chile-por-d-nde-partir-",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"35-12,35-14\">The controller must guarantee adequate security standards, protecting data against unauthorized or unlawful processing and against loss, leakage, accidental damage or destruction; upon a security incident, it falls to the controller or processor to demonstrate the existence and functioning of security measures adopted based on risk levels and available technology.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-nuevo-entorno-regulatorio-de-la-proteccion-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"38-1\">Regarding the security duty and specifically the obligation to report security breaches, no fixed deadline is indicated, as in the case of the GDPR (72 hours); instead the law states it must be done by the most expeditious means possible and without undue delay.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/donde-estan-los-datos-algunas-reflexiones-sobre-el-proyecto-de-ley-de-datos-chileno-del-boletin-n-o-11-144-07",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"35-2\">Data subjects must additionally be notified when the breach affects sensitive personal data, data of children under 14 years of age, or data relating to economic, financial, banking or commercial obligations.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-nuevo-entorno-regulatorio-de-la-proteccion-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"28-2\">Data must be retained only for the period necessary to fulfil the purposes of the processing, after which it must be cancelled or anonymised.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-nuevo-entorno-regulatorio-de-la-proteccion-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/chile/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer-mechanism framework is enacted but not yet effective and awaits Agency ratification of model clauses; adequacy in/out and localisation dimensions are unaddressed in available sources.",
   "claims": [
    {
     "statement": "<cite index=\"23-1\">International data transfer is possible when there are adequate levels of data protection in the recipient country; when contractual clauses, binding corporate rules or another similar legal instrument are complied with; when a compliance model or certification mechanism exists; when there is express consent of the data subject; when carried out in the context of specific banking, financial or stock-market transfers; when international obligations acquired or cooperation agreements are complied with; when there is express legal authorization; when it occurs in the context of international judicial cooperation; when necessary for the conclusion or execution of a contract or precontractual measures; and when necessary to adopt urgent medical or health measures.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"21-15\">In December 2025, via an exempt resolution of the Undersecretariat of Economy and Small Business, model contractual clauses for international transfers were approved, based on the model approved by the Ibero-American Data Protection Network, to be ratified once the Agencia de Protección de Datos Personales is installed.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/d-a-de-la-pdp-en-chile-estamos-preparados-para-la-entrada-en-vigor-de-la-normativa",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/chile/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial-sector overlay is well documented and currently in force; other sectoral overlays (telecoms, education, insurance) show no dedicated findings.",
   "claims": [
    {
     "statement": "<cite index=\"40-2\">Ley N.º 21.521 (the Fintech Law) establishes a special regulation of the Open Finance System, setting rules and principles for an exchange system among financial service providers based on clients' express consent, remote automated access, and high security standards.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/los-desaf-os-de-la-protecci-n-de-datos-personales-en-el-sfa-de-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"40-1\">The Comisión para el Mercado Financiero issued Norma de Carácter General N.º 514 in 2024, applicable to IPI, IPC, PSBI and PSIP entities, requiring API security processes including monitoring, safeguards, maintenance of an updated event registry for five years, and secure deletion of information once legal retention periods expire.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/los-desaf-os-de-la-protecci-n-de-datos-personales-en-el-sfa-de-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"16-4\">The compliance program must include incorporating these obligations into the employment contracts of workers, employees and service providers, or as a specific obligation in the entity's internal regulation on order, hygiene and safety.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/la-ley-de-datos-personales-y-el-rol-de-la-auditor-a-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The current regulation on personal data concerning economic, financial, banking or commercial obligations is maintained, permitting reporting of default on obligations such as mortgages and loans subject to specific rules retained under the new regime.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/chile/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No dedicated adtech-specific regime found; general DP-law rights (opposition/profiling) provide only indirect coverage.",
   "claims": [
    {
     "statement": "<cite index=\"23-5\">The new law adds a right of opposition to automated decisions to the ARCO rights catalogue, relevant to profiling-based marketing activities.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/chile/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Core ADM-opposition and biometric provisions are enacted but not yet effective; AI-labelling bill remains a proposal; genetic-data and surveillance-carveout coverage is unconfirmed.",
   "claims": [
    {
     "statement": "<cite index=\"23-5\">The rights of data subjects are expanded to include opposition to automated decisions, alongside blocking and portability.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"3-12\">The compliance program must also specify retention periods and the existence of automated decisions or profiling, indicating their logic and expected effects for data subjects.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/se-dictan-nuevos-modelos-de-prevenci-n-de-infracciones-que-modifican-la-ley-de-protecci-n-de-datos-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"18-5\">A draft bill defines synthetic content as any image, video, audio or graphic representation that, using personal data or distinctive elements of a natural person's identity, has been created or substantially modified using AI systems such that it could be mistaken for an authentic representation, and would impose labelling obligations on those who develop, operate or make such AI systems available.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-proyecto-de-ley-sobre-el-sello-obligatorio-y-rastreable-de-la-ia-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"53-2\">Special regimes are established for biometric data, among other differentiated categories.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/chile/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "A children's-data regime and an under-14 breach-notification threshold are enacted but not yet effective; no dedicated age-verification/parental-consent/profiling-ban mechanism was confirmed.",
   "claims": [
    {
     "statement": "<cite index=\"35-2\">Data subjects must be notified when breaches affect data of children under 14 years of age, establishing an operative age threshold within the breach-notification regime.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-nuevo-entorno-regulatorio-de-la-proteccion-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"1-2\">Public or private institutions engaged in private security must respect and protect fundamental human rights and freedoms, especially concerning vulnerable persons, children, adolescents, and persons with disabilities.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-reglamento-de-seguridad-privada-de-la-ley-n-21-659-y-la-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/chile/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement architecture is enacted but the Agency is not yet operational and the penalty framework may still be amended by a pending bill; current in-force redress is limited to civil litigation.",
   "claims": [
    {
     "statement": "<cite index=\"11-7\">The Agency has functions to issue instructions, interpret the regulation's provisions, oversee compliance with obligations, determine non-compliance, exercise sanctioning power, resolve data subjects' requests and complaints, conduct promotional and dissemination activities, propose measures to the President and Congress, provide technical assistance to autonomous bodies, enter cooperation agreements, participate with international organisations, and certify and supervise compliance models.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aspectos-del-recientemente-aprobado-proyecto-de-ley-que-crea-la-agencia-de-protecci-n-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"15-23,15-24\">Infringements by data controllers of the principles, rights and obligations established by the law are classified, according to gravity, as minor, serious and very serious, with minor infringements sanctioned by written warning or fines.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-nuevo-entorno-regulatorio-de-la-proteccion-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"43-13\">In cases of repeated very serious infringements within a 24-month period, the control authority may order suspension of the data controller's processing operations and activities for up to 30 days, extendable indefinitely until corrective measures are adopted.</cite>",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-nuevo-entorno-regulatorio-de-la-proteccion-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"35-9\">Ley 19.628 establishes only the duty to indemnify patrimonial and moral damage caused by improper data processing, without prejudice to eliminating, modifying or blocking data as required by the data subject or ordered by a court.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/el-nuevo-entorno-regulatorio-de-la-proteccion-de-datos-personales-en-chile",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"41-1,41-2\">Recently, in January 2026, via the public-sector adjustment bill, rules were approved establishing that the Agency's Consejo Directivo must be designated before 1 June 2026, and that if the Senate does not act before that date the presidential proposal of counsellors will be deemed accepted.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/d-a-de-la-pdp-en-chile-estamos-preparados-para-la-entrada-en-vigor-de-la-normativa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"2-8\">A parliamentary-motion bill (Boletín N.º 18.060-07) intended to perfect aspects of Ley N.º 21.719 is currently in first constitutional procedure.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/d-a-de-la-pdp-en-chile-estamos-preparados-para-la-entrada-en-vigor-de-la-normativa",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}