🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CL · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

Chile

CL schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 47 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
47Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Statute enacted and constitutionally validated, but the regulator is not yet operational and the implementing regulation is not yet finalized; current in-force law (Ley 19.628) is materially weaker than the incoming regime.

Primary frameworkLey N.º 21.719 (modifying Ley N.º 19.628 sobre Protección de la Vida Privada), in force 1 December 2026
Supervisory authorityAgencia de Protección de Datos Personales (APDP)
Traffic-light rationale — AmberStatute enacted and constitutionally validated, but the regulator is not yet operational and the implementing regulation is not yet finalized; current in-force law (Ley 19.628) is materially weaker than the incoming regime.

Sub-modules (5)

Regulator And AuthorityAmber

The APDP is an autonomous, decentralized public-law corporation with its own legal personality and patrimony, relating to government via the Ministry of Economy, governed by a 3-member Consejo Directivo; the Council must be appointed before 1 June 2026 per a January 2026 public-sector adjustment law.

Claims: CLM-CL-a10f2b3c, CLM-CL-b21e4c5d

Act And InstrumentsAmber

Ley 19.628 (1999) remains operative today; Ley 21.719 (enacted, not yet effective) and its implementing Decreto Supremo N.º 662 (Reglamento on Compliance Models, pending Contraloría review) both commence 1 December 2026.

Claims: CLM-CL-c32d5e6f, CLM-CL-d43c6f70, CLM-CL-e54b7081

Material ScopeAmber

Ley 21.719 introduces differentiated regimes for biometric data, children/adolescent data, historical/statistical/scientific data, and geolocation data.

Claims: CLM-CL-f65a8192

Territorial ScopeAmber

The law applies extraterritorially to entities constituted in Chile, to processing operations located in Chile, and to entities offering goods or services in Chile; a pending parliamentary bill (Boletín N.º 18.060-07) proposes narrowing this extraterritorial rule.

Claims: CLM-CL-072913a3, CLM-CL-183a24b4

Regulator Registration And FilingAmber

There is no mandatory general controller-registration duty; instead, adoption of a voluntary Modelo de Prevención de Infracciones is certified and recorded by the APDP in a National Registry of Sanctions and Compliance.

Claims: CLM-CL-294b35c5

Category narrative95 words

Chile is mid-transition from the 1999 Ley N.º 19.628 sobre Protección de la Vida Privada (a minimal, civil-court-enforced regime with no dedicated regulator) to a GDPR-influenced omnibus regime under Ley N.º 21.719, which creates the Agencia de Protección de Datos Personales (APDP) and enters into force on 1 December 2026. As of the research date the APDP does not yet exist operationally: its 3-member Consejo Directivo must be appointed before 1 June 2026, and its implementing Reglamento (Decreto Supremo N.º 662) remains under constitutionality/legality review (toma de razón) at the Contraloría General de la República.

Sources and claims (9)
  1. ConfirmedIAPP<cite index="42-1,42-2">The Agencia de Protección de Datos Personales is an autonomous, technical, decentralized public-law corporation with its own legal personality and patrimony, relating to government through the Ministry of Economy, and is governed by a directive council made up of three counsellors.</cite>
  2. ConfirmedIAPP<cite index="41-1">Under a January 2026 public-sector adjustment law, the Agency's Consejo Directivo must be designated before 1 June 2026, requiring the presidential nomination to occur between March and April.</cite>
  3. ConfirmedIAPP<cite index="6-1">Ley N.º 21.719, which regulates the protection and treatment of personal data and creates the Agencia de Protección de Datos Personales, enters into force on 1 December 2026.</cite>
  4. ConfirmedIAPPLey N.º 19.628 sobre protección a la vida privada (1999) remains the current operative statute governing personal data processing in Chile until Ley 21.719 takes effect, as confirmed by multiple 2025-2026 legal commentaries referencing its continued applicability pending the reform's entry into force.
  5. ConfirmedIAPP<cite index="34-1">On 13 June 2025 the Ministry of Finance issued Decreto Supremo N.º 662, approving the Regulation governing requirements, modalities and procedures for the implementation, certification, registration and supervision of Infraction Prevention Models, which remains in the process of legality review before the Contraloría General de la República.</cite>
  6. ConfirmedIAPP<cite index="53-2">Ley 21.719 establishes special regimes for biometric data; data relating to children and adolescents; data used for historical, statistical, scientific or research purposes; and geolocation data.</cite>
  7. ConfirmedIAPP<cite index="23-3">The regulation applies to subjects constituted in Chilean territory, to those carrying out data-processing operations established in national territory, and to those offering goods or services in Chile, whether through their activities or by application of a contract or international law.</cite>
  8. ProbableIAPP<cite index="2-8,2-9">A parliamentary-motion bill (Boletín N.º 18.060-07), currently in first constitutional procedure, proposes to perfect aspects of Ley N.º 21.719, including limiting the law's scope of application with respect to the extraterritorial rule.</cite>
  9. ConfirmedIAPP<cite index="11-9,11-10">The law establishes leve, grave and gravísima infringement tiers with a certification-based Infraction Prevention Model recognized by the Agency as a mitigating factor, and certified models are entered into a national registry administered by the Agency.</cite>

#

Expanded lawful bases and sensitive-data regime are enacted but not yet effective (1 Dec 2026); current regime is narrower.

Primary frameworkLey N.º 21.719 (amending Ley N.º 19.628)
Supervisory authorityAgencia de Protección de Datos Personales (APDP)
Traffic-light rationale — AmberExpanded lawful bases and sensitive-data regime are enacted but not yet effective (1 Dec 2026); current regime is narrower.

Sub-modules (4)

Lawful BasesAmber

Ley 19.628 historically recognized only legal authorization and express written consent; Ley 21.719 adds legitimate interest, contractual necessity, vital interest, legal obligation, judicial cooperation, specific banking/financial/stock-market transactions, international agreements, and urgent medical necessity.

Claims: CLM-CL-3a5f61d6, CLM-CL-4b6072e7

Special CategoriesAmber

Exceptions to the express-consent default for sensitive data include manifestly public data, legitimate interest, vital interest, exercise/defense of a right, and legal-duty compliance; differentiated regimes exist for biometric, children's, research/statistical, and geolocation data.

Claims: CLM-CL-6d829409

Pseudonymisation And AnonymisationAmber

Retention-limitation principle requires deletion or anonymisation of data once the processing purpose is fulfilled, absent legal authorization or consent for extended retention.

Claims: CLM-CL-7e93051a

Category narrative40 words

The current Ley 19.628 recognizes only two lawful bases (legal authorization and express written consent). Ley 21.719 substantially broadens the lawful-basis catalogue and introduces a differentiated regime for sensitive/special-category data with an expanded set of exceptions to the express-consent default.

Sources and claims (5)
  1. ConfirmedIAPP<cite index="28-15">Ley 19.628 only recognizes as sources of lawful processing legal authorization and the express and written consent of the data subject.</cite>
  2. ConfirmedIAPP<cite index="23-1">The new law recognizes international/domestic transfer scenarios and lawful processing hypotheses including legitimate interest, vital interest, formulation/exercise/defense of a right, legal duty compliance, banking/financial/stock-market transactions, international obligations or cooperation agreements, express legal authorization, international judicial cooperation, contract necessity or precontractual measures, and urgent medical or health measures.</cite>
  3. ConfirmedIAPP<cite index="53-1">Regarding sensitive personal data, as a general rule its processing must be carried out with the express consent of the data subject, without prejudice to exceptions.</cite>
  4. ConfirmedIAPP<cite index="53-1">Sensitive data may be processed without express consent when it has been made manifestly public and its use relates to the published purposes, when a legitimate interest is involved, when a vital interest is involved, for the formulation, exercise or defense of a right, and in compliance with a legal duty.</cite>
  5. ProbableIAPP<cite index="28-2,28-3">Data must be retained only for the period necessary to fulfil the purposes of processing, after which it must be deleted or anonymised, and processing for a longer period requires legal authorization or the data subject's consent.</cite>

#

Rights expansion enacted but not yet effective; current ARCO regime under Ley 19.628 is narrower and lacks portability/blocking/ADM-opposition rights.

Primary frameworkLey N.º 21.719 (amending Ley N.º 19.628)
Supervisory authorityAgencia de Protección de Datos Personales (APDP)
Traffic-light rationale — AmberRights expansion enacted but not yet effective; current ARCO regime under Ley 19.628 is narrower and lacks portability/blocking/ADM-opposition rights.

Sub-modules (5)

Access RightAmber

Access right retained from Ley 19.628 and continued under Ley 21.719, allowing data subjects to obtain confirmation and details of processing.

Claims: CLM-CL-8fa41625

Rectification And ErasureAmber

The 'cancelación' right is renamed 'supresión' (erasure) under the new law, alongside rectification.

Claims: CLM-CL-90b52736

Restriction And ObjectionAmber

New rights of blocking (bloqueo) and opposition to automated decision-making are introduced.

Claims: CLM-CL-a1c63847

Data PortabilityAmber

Portability is a newly introduced data subject right under Ley 21.719.

Claims: CLM-CL-b2d74958

Deadlines And Response WindowsAmber

Controllers have 30 calendar days (extendable once) to respond to a rights request; denial, partial denial, or silence entitles the data subject to file a claim with the Agency.

Claims: CLM-CL-c3e85a69

Category narrative43 words

Ley 21.719 expands the classic ARCO (access, rectification, cancellation, opposition) rights into an ARCOP+ scheme: access, rectification, suppression (renamed from cancellation), opposition, blocking, portability, and opposition to automated decision-making/profiling. A 30-calendar-day response window applies, with escalation to the Agency on denial or silence.

Sources and claims (5)
  1. ConfirmedIAPP<cite index="31-1">Data subjects must be permitted the full exercise of their rights of access, rectification, suppression or opposition, and portability, unless a legal limitation exists.</cite>
  2. ConfirmedIAPP<cite index="23-5">Regarding data subject rights, in addition to those currently recognized in Ley N.º 19.628 — access, rectification, and cancellation (now termed suppression) and opposition — the new law adds blocking, portability, and opposition to automated decisions.</cite>
  3. ConfirmedIAPP<cite index="23-5">The rights catalogue is extended to include blocking and opposition to automated decisions.</cite>
  4. ConfirmedIAPP<cite index="23-5">Portability is added as a new data subject right not previously recognized under Ley 19.628.</cite>
  5. ConfirmedIAPP<cite index="11-13">An administrative procedure is established under which, if within 30 calendar days following the filing date (extendable once) the request is denied in whole or in part or no response is given, the data subject may file a claim with the Agencia de Protección de Datos Personales.</cite>

#

Core accountability and breach/security duties are enacted but not yet effective; DPO is only conditionally mandatory and no formal RoPA is required, both material divergences from GDPR.

Primary frameworkLey N.º 21.719 (amending Ley N.º 19.628); Decreto Supremo N.º 662 (Reglamento on Compliance Models)
Supervisory authorityAgencia de Protección de Datos Personales (APDP)
Traffic-light rationale — AmberCore accountability and breach/security duties are enacted but not yet effective; DPO is only conditionally mandatory and no formal RoPA is required, both material divergences from GDPR.

Sub-modules (7)

Accountability And DpiaAmber

Accountability principle requires controllers/processors to answer for infringements; DPIA-like impact assessments are required for high-risk activities such as systematic monitoring of publicly accessible areas.

Claims: CLM-CL-d4f96b7a, CLM-CL-e50a7c8b

Dpo RequirementsAmber

The DPO role is voluntary in general, becoming effectively mandatory once an entity adopts and certifies a compliance/prevention model; the DPO must report directly to the entity's highest governing authority.

Claims: CLM-CL-f61b8d9c, CLM-CL-072c9ead

Ropa RequirementsAmber

Unlike GDPR Art.30, no formal Records of Processing Activities register is mandated; instead, controllers must publish categories of data, purposes, legal bases, recipients, retention periods, data sources, and international transfers.

Claims: CLM-CL-183dafbe

Joint Controller ArrangementsRed

No specific joint-controller regime distinct from general controller/processor obligations was identified in the sources reviewed for this run.

Absence provenance: not recorded. Searched: L, e, y, , 2, 1, ., 7, 1, 9, , j, o, i, n, t, , c, o, n, t, r, o, l, l, e, r, , /, , r, e, s, p, o, n, s, a, b, l, e, s, , c, o, n, j, u, n, t, o, s, , C, h, i, l, e.

Security MeasuresAmber

Controllers/processors must adopt risk- and data-nature-proportionate technical and organisational security measures, bearing the burden of demonstrating their adequacy (accountability model).

Claims: CLM-CL-294ebfcf

Breach NotificationAmber

Breach must be reported to the Agency via the most expeditious means without undue delay when there is risk to rights/freedoms; no fixed 72-hour-style deadline exists; data subjects must additionally be notified for sensitive data, under-14 children's data, or economic/financial/banking/commercial data breaches.

Claims: CLM-CL-3a5fc0d0, CLM-CL-4b60d1e1

Retention And DisposalAmber

Data must be retained only as long as necessary for the processing purpose, then deleted or anonymised absent extended legal authorization or consent.

Claims: CLM-CL-5c71e2f2

Category narrative66 words

Ley 21.719 introduces an accountability principle, DPIA-equivalent impact assessments for high-risk processing, a voluntary-but-conditionally-mandatory DPO (delegado de protección de datos), transparency-publication duties in lieu of a formal Art.30-style RoPA, risk-proportionate security obligations with a demonstrated-accountability burden of proof, and a breach-notification duty without a fixed statutory clock (unlike GDPR's 72 hours), but with mandatory data-subject notice for sensitive data, under-14 children's data, or financial/economic data breaches.

Sources and claims (9)
  1. ConfirmedIAPP<cite index="10-10">The future law recognizes the principle of accountability, indicating that those who process personal data must, in the event of non-compliance with principles, obligations or other provisions, take responsibility for possible infringements of the regulation.</cite>
  2. ConfirmedIAPP<cite index="22-9,22-10">Where processing involves systematic observation or monitoring of a publicly accessible area, an impact assessment must be carried out, considering the description of the processing operations, the purpose, and the evaluation of necessity and proportionality, and thus the risks and mitigation measures.</cite>
  3. ConfirmedIAPP<cite index="4-3,4-4">A major novelty of Ley N.º 21.719 is the introduction of the data protection delegate figure, a role that is in principle voluntary, applying only to entities that adopt an infraction prevention model.</cite>
  4. ConfirmedIAPP<cite index="4-1">Decree N.º 662's Article 8 establishes that the DPO must report directly to the authority that designated them, and that authority must be the entity's highest directive or administrative authority.</cite>
  5. ConfirmedIAPP<cite index="12-8">Unlike the GDPR, the future law does not require controllers to maintain a formal record of processing activities (Article 30 GDPR equivalent), though a transparency duty requires publishing categories of data processed, the general description of the data subjects, recipients, purposes, legal basis, and, for legitimate-interest processing, what those interests are.</cite>
  6. ConfirmedIAPP<cite index="35-12,35-14">The controller must guarantee adequate security standards, protecting data against unauthorized or unlawful processing and against loss, leakage, accidental damage or destruction; upon a security incident, it falls to the controller or processor to demonstrate the existence and functioning of security measures adopted based on risk levels and available technology.</cite>
  7. ConfirmedIAPP<cite index="38-1">Regarding the security duty and specifically the obligation to report security breaches, no fixed deadline is indicated, as in the case of the GDPR (72 hours); instead the law states it must be done by the most expeditious means possible and without undue delay.</cite>
  8. ConfirmedIAPP<cite index="35-2">Data subjects must additionally be notified when the breach affects sensitive personal data, data of children under 14 years of age, or data relating to economic, financial, banking or commercial obligations.</cite>
  9. ConfirmedIAPP<cite index="28-2">Data must be retained only for the period necessary to fulfil the purposes of the processing, after which it must be cancelled or anonymised.</cite>

#

Transfer-mechanism framework is enacted but not yet effective and awaits Agency ratification of model clauses; adequacy in/out and localisation dimensions are unaddressed in available sources.

Primary frameworkLey N.º 21.719 (amending Ley N.º 19.628), Article 27
Supervisory authorityAgencia de Protección de Datos Personales (APDP)
Traffic-light rationale — AmberTransfer-mechanism framework is enacted but not yet effective and awaits Agency ratification of model clauses; adequacy in/out and localisation dimensions are unaddressed in available sources.

Sub-modules (6)

Transfer MechanismsAmber

Article 27 permits transfers via adequate-protection-level assessment of the destination country, contractual clauses/BCRs or similar instruments, certification/compliance models, explicit consent, specific banking/financial/stock-market transfers, treaty/cooperation obligations, express legal authorization, international judicial cooperation, contract necessity, and urgent medical measures.

Claims: CLM-CL-6d82f3f3

Adequacy ReceivedRed

No evidence was found of any foreign regulator or bloc (e.g., the EU) having issued an adequacy decision in favour of Chile.

Absence provenance: not recorded. Searched: C, h, i, l, e, , a, d, e, q, u, a, c, y, , d, e, c, i, s, i, o, n, , E, U, , G, D, P, R, , r, e, c, e, i, v, e, d.

Adequacy GrantedRed

No evidence was found of Chile (via the not-yet-operational Agency) having granted adequacy status to any other jurisdiction; this determination is expected to be a future Agency function.

Absence provenance: not recorded. Searched: C, h, i, l, e, , A, g, e, n, c, i, a, , a, d, e, c, u, a, c, i, ó, n, , p, a, í, s, e, s, , t, e, r, c, e, r, o, s, , d, a, t, o, s, , p, e, r, s, o, n, a, l, e, s.

Sccs And BcrsAmber

Model contractual clauses for international transfers, based on the Red Iberoamericana de Protección de Datos template, were administratively pre-approved in December 2025 and await ratification once the Agency is installed.

Claims: CLM-CL-7e930404

Transfer Impact AssessmentRed

No distinct, formally named Transfer Impact Assessment obligation (as distinguished from the general destination-country adequacy assessment under Article 27) was identified in sources reviewed.

Absence provenance: not recorded. Searched: L, e, y, , 2, 1, ., 7, 1, 9, , e, v, a, l, u, a, c, i, ó, n, , d, e, , i, m, p, a, c, t, o, , d, e, , t, r, a, n, s, f, e, r, e, n, c, i, a, , i, n, t, e, r, n, a, c, i, o, n, a, l, , C, h, i, l, e.

Data LocalisationRed

No general data-localisation mandate was identified; sector-specific data-retention/event-log requirements exist for open-finance API providers (5-year retention) but this is a security/retention rule, not a localisation mandate.

Absence provenance: not recorded. Searched: C, h, i, l, e, , d, a, t, a, , l, o, c, a, l, i, z, a, t, i, o, n, , r, e, q, u, i, r, e, m, e, n, t, , p, e, r, s, o, n, a, l, , d, a, t, a, , 2, 0, 2, 6.

Category narrative81 words

Ley 21.719 introduces, for the first time, a structured international-transfer regime with multiple transfer mechanisms (adequacy-style destination assessment, contractual clauses/BCRs, certification, consent, sector-specific carve-outs, treaty-based cooperation, contractual necessity, urgent medical need), plus an intra-group derogation added by a later amendment. Model contractual clauses have been pre-approved administratively pending Agency ratification. No evidence was found of Chile having received or granted formal adequacy decisions, of an explicit Transfer Impact Assessment requirement distinct from the general destination-country assessment, or of a data-localisation mandate.

Sources and claims (2)
  1. ConfirmedIAPP<cite index="23-1">International data transfer is possible when there are adequate levels of data protection in the recipient country; when contractual clauses, binding corporate rules or another similar legal instrument are complied with; when a compliance model or certification mechanism exists; when there is express consent of the data subject; when carried out in the context of specific banking, financial or stock-market transfers; when international obligations acquired or cooperation agreements are complied with; when there is express legal authorization; when it occurs in the context of international judicial cooperation; when necessary for the conclusion or execution of a contract or precontractual measures; and when necessary to adopt urgent medical or health measures.</cite>
  2. ConfirmedIAPP<cite index="21-15">In December 2025, via an exempt resolution of the Undersecretariat of Economy and Small Business, model contractual clauses for international transfers were approved, based on the model approved by the Ibero-American Data Protection Network, to be ratified once the Agencia de Protección de Datos Personales is installed.</cite>

#

Financial-sector overlay is well documented and currently in force; other sectoral overlays (telecoms, education, insurance) show no dedicated findings.

Primary frameworkLey N.º 21.521 (Ley Fintech); CMF Norma de Carácter General N.º 514; Ley N.º 21.719 (general overlay)
Supervisory authorityComisión para el Mercado Financiero (CMF)
Traffic-light rationale — AmberFinancial-sector overlay is well documented and currently in force; other sectoral overlays (telecoms, education, insurance) show no dedicated findings.

Sub-modules (7)

Financial Sector OverlayAmber

The Fintech Law establishes an Open Finance system requiring express client consent, security, and interoperability standards for data-sharing among regulated financial participants; the CMF's NCG 514 mandates API security monitoring, safeguards, 5-year event-log retention, and secure data deletion.

Claims: CLM-CL-8fa41a1a, CLM-CL-90b52b2b

Health Sector OverlayRed

No dedicated health-sector DP overlay (comparable to HIPAA) was identified in sources reviewed for this run; general special-category rules under Ley 21.719 would apply to health data as sensitive data.

Absence provenance: not recorded. Searched: C, h, i, l, e, , h, e, a, l, t, h, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, e, c, t, o, r, , l, a, w, , f, i, c, h, a, , c, l, í, n, i, c, a, , i, n, t, e, r, o, p, e, r, a, b, i, l, i, d, a, d.

Telecoms And EprivacyRed

No dedicated telecoms/ePrivacy-style overlay (comparable to the EU ePrivacy Directive) was identified in sources reviewed.

Absence provenance: not recorded. Searched: C, h, i, l, e, , e, P, r, i, v, a, c, y, , t, e, l, e, c, o, m, u, n, i, c, a, c, i, o, n, e, s, , c, o, o, k, i, e, s, , l, e, y.

Employment DataAmber

Compliance-model obligations under the Reglamento must be incorporated into employment contracts, service-provider agreements, and internal workplace regulations (Reglamento Interno de Orden, Higiene y Seguridad).

Claims: CLM-CL-a1c63c3c

Credit And ScoringAmber

Historic rules permitting reporting of non-compliance with economic, financial, banking or commercial obligations (e.g., mortgages, loans) are preserved under the new regime.

Claims: CLM-CL-b2d74d4d

EducationRed

No education-sector-specific DP overlay was identified in sources reviewed for this run.

Absence provenance: not recorded. Searched: C, h, i, l, e, , p, r, o, t, e, c, c, i, ó, n, , d, a, t, o, s, , p, e, r, s, o, n, a, l, e, s, , e, d, u, c, a, c, i, ó, n, , e, s, t, u, d, i, a, n, t, e, s, , l, e, y.

InsuranceRed

No insurance-sector-specific DP overlay was identified in sources reviewed for this run.

Absence provenance: not recorded. Searched: C, h, i, l, e, , d, a, t, o, s, , p, e, r, s, o, n, a, l, e, s, , s, e, g, u, r, o, s, , l, e, y, , p, r, o, t, e, c, c, i, ó, n.

Category narrative66 words

Financial-sector data flows are governed by the Ley Fintech (Open Finance system) and CMF technical standards (NCG N.º 514), which pre-date and currently sit alongside the incoming general DP law; the compliance-model regime under Ley 21.719 requires embedding DP obligations into employment contracts and internal workplace regulations; historic economic/financial/commercial-obligation reporting rules are preserved. No comprehensive telecoms/ePrivacy, education-sector, or insurance-sector DP overlay was identified in sources reviewed.

Sources and claims (4)
  1. ConfirmedIAPP<cite index="40-2">Ley N.º 21.521 (the Fintech Law) establishes a special regulation of the Open Finance System, setting rules and principles for an exchange system among financial service providers based on clients' express consent, remote automated access, and high security standards.</cite>
  2. ConfirmedIAPP<cite index="40-1">The Comisión para el Mercado Financiero issued Norma de Carácter General N.º 514 in 2024, applicable to IPI, IPC, PSBI and PSIP entities, requiring API security processes including monitoring, safeguards, maintenance of an updated event registry for five years, and secure deletion of information once legal retention periods expire.</cite>
  3. ConfirmedIAPP<cite index="16-4">The compliance program must include incorporating these obligations into the employment contracts of workers, employees and service providers, or as a specific obligation in the entity's internal regulation on order, hygiene and safety.</cite>
  4. ProbableIAPPThe current regulation on personal data concerning economic, financial, banking or commercial obligations is maintained, permitting reporting of default on obligations such as mortgages and loans subject to specific rules retained under the new regime.

#

No dedicated adtech-specific regime found; general DP-law rights (opposition/profiling) provide only indirect coverage.

Primary frameworkLey N.º 21.719 (general overlay only; no dedicated adtech statute identified)
Supervisory authorityAgencia de Protección de Datos Personales (APDP)
Traffic-light rationale — RedNo dedicated adtech-specific regime found; general DP-law rights (opposition/profiling) provide only indirect coverage.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent statute was identified.

Absence provenance: not recorded. Searched: C, h, i, l, e, , l, e, y, , c, o, o, k, i, e, s, , c, o, n, s, e, n, t, i, m, i, e, n, t, o, , r, a, s, t, r, e, a, d, o, r, e, s.

Dark PatternsRed

No dark-pattern-specific prohibition was identified.

Absence provenance: not recorded. Searched: C, h, i, l, e, , d, a, r, k, , p, a, t, t, e, r, n, s, , l, e, y, , p, r, o, t, e, c, c, i, ó, n, , d, a, t, o, s.

Opt Out SignalsRed

No recognized technical opt-out signal (comparable to GPC or DAA) was identified.

Absence provenance: not recorded. Searched: C, h, i, l, e, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , o, p, t, -, o, u, t, , s, e, ñ, a, l.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific rule was identified.

Absence provenance: not recorded. Searched: C, h, i, l, e, , c, l, e, a, n, , r, o, o, m, , d, a, t, o, s, , c, o, l, a, b, o, r, a, c, i, ó, n, , r, e, g, u, l, a, c, i, ó, n.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context advertising concept was identified in the Chilean framework.

Absence provenance: not recorded. Searched: C, h, i, l, e, , p, u, b, l, i, c, i, d, a, d, , c, r, o, s, s, -, c, o, n, t, e, x, t, , v, e, n, t, a, , d, a, t, o, s, , p, e, r, s, o, n, a, l, e, s.

Direct MarketingAmber

The new opposition right to automated decisions/profiling under Ley 21.719 is the closest applicable mechanism to direct-marketing opt-out, though no marketing-specific suppression regime was separately identified.

Claims: CLM-CL-c3e85e5e

Category narrative42 words

No dedicated cookie/adtech-consent statute, dark-pattern prohibition, recognized opt-out signal (e.g., GPC/DAA equivalent), or clean-room/data-collaboration rule was identified for Chile in sources reviewed. Ley 21.719's new opposition right to automated decision-making/profiling is the closest applicable mechanism relevant to targeted advertising and direct marketing.

Sources and claims (1)
  1. ProbableIAPP<cite index="23-5">The new law adds a right of opposition to automated decisions to the ARCO rights catalogue, relevant to profiling-based marketing activities.</cite>

#

Core ADM-opposition and biometric provisions are enacted but not yet effective; AI-labelling bill remains a proposal; genetic-data and surveillance-carveout coverage is unconfirmed.

Primary frameworkLey N.º 21.719 (amending Ley N.º 19.628)
Supervisory authorityAgencia de Protección de Datos Personales (APDP)
Traffic-light rationale — AmberCore ADM-opposition and biometric provisions are enacted but not yet effective; AI-labelling bill remains a proposal; genetic-data and surveillance-carveout coverage is unconfirmed.

Sub-modules (6)

Profiling RestrictionsAmber

New right to oppose profiling/automated decision-making introduced.

Claims: CLM-CL-d4f9dfdf

Automated Decision Making TransparencyAmber

Compliance-model documentation must specify the existence of automated decisions or profiling, including their logic and expected effects on data subjects.

Claims: CLM-CL-e50a0e0e

Ai Risk AssessmentsAmber

A separate bill would mandate clear, traceable labelling of AI-generated synthetic content involving personal likeness; it remains in legislative process, not yet in force.

Claims: CLM-CL-f61b1f1f

Biometric RegimeAmber

A special regime is established for biometric data processing under Ley 21.719.

Claims: CLM-CL-072c2c2c

Genetic DataRed

No distinct genetic-data-specific regime beyond general special-category treatment was identified in sources reviewed.

Absence provenance: not recorded. Searched: L, e, y, , 2, 1, ., 7, 1, 9, , d, a, t, o, s, , g, e, n, é, t, i, c, o, s, , r, é, g, i, m, e, n, , e, s, p, e, c, i, a, l, , C, h, i, l, e.

State Surveillance CarveoutsRed

No specific national-security/state-surveillance carve-out provision was identified in sources reviewed for this run.

Absence provenance: not recorded. Searched: C, h, i, l, e, , L, e, y, , 2, 1, ., 7, 1, 9, , e, x, c, e, p, c, i, ó, n, , s, e, g, u, r, i, d, a, d, , n, a, c, i, o, n, a, l, , v, i, g, i, l, a, n, c, i, a, , e, s, t, a, t, a, l.

Category narrative55 words

Ley 21.719 introduces a right to oppose automated decision-making/profiling and a distinct biometric-data regime, and requires impact assessments for systematic monitoring of publicly accessible areas. A separate draft bill on mandatory traceable AI-content labelling is in legislative process but not yet law. No dedicated genetic-data regime or state-surveillance carve-out provision was identified in sources reviewed.

Sources and claims (4)
  1. ConfirmedIAPP<cite index="23-5">The rights of data subjects are expanded to include opposition to automated decisions, alongside blocking and portability.</cite>
  2. ConfirmedIAPP<cite index="3-12">The compliance program must also specify retention periods and the existence of automated decisions or profiling, indicating their logic and expected effects for data subjects.</cite>
  3. ProbableIAPP<cite index="18-5">A draft bill defines synthetic content as any image, video, audio or graphic representation that, using personal data or distinctive elements of a natural person's identity, has been created or substantially modified using AI systems such that it could be mistaken for an authentic representation, and would impose labelling obligations on those who develop, operate or make such AI systems available.</cite>
  4. ConfirmedIAPP<cite index="53-2">Special regimes are established for biometric data, among other differentiated categories.</cite>

#

A children's-data regime and an under-14 breach-notification threshold are enacted but not yet effective; no dedicated age-verification/parental-consent/profiling-ban mechanism was confirmed.

Primary frameworkLey N.º 21.719 (amending Ley N.º 19.628); Ley N.º 21.659 (Reglamento de Seguridad Privada, ancillary)
Supervisory authorityAgencia de Protección de Datos Personales (APDP)
Traffic-light rationale — AmberA children's-data regime and an under-14 breach-notification threshold are enacted but not yet effective; no dedicated age-verification/parental-consent/profiling-ban mechanism was confirmed.

Sub-modules (5)

Age VerificationAmber

No dedicated age-verification mechanism was identified; the law does use an under-14 threshold for heightened breach-notification duties, implying an operative age marker without a verification procedure being specified.

Claims: CLM-CL-183d3d3d

Minor Profiling BansRed

No minor-specific profiling ban was identified in sources reviewed.

Absence provenance: not recorded. Searched: C, h, i, l, e, , p, r, o, h, i, b, i, c, i, ó, n, , p, e, r, f, i, l, a, m, i, e, n, t, o, , m, e, n, o, r, e, s, , l, e, y, , d, a, t, o, s, , p, e, r, s, o, n, a, l, e, s.

Education SettingsRed

No education-setting-specific DP rule was identified in sources reviewed.

Absence provenance: not recorded. Searched: C, h, i, l, e, , p, r, o, t, e, c, c, i, ó, n, , d, a, t, o, s, , p, e, r, s, o, n, a, l, e, s, , e, s, t, a, b, l, e, c, i, m, i, e, n, t, o, s, , e, d, u, c, a, c, i, o, n, a, l, e, s, , m, e, n, o, r, e, s.

Dependent AdultsAmber

The Private Security Regulation under Ley 21.659 imposes a duty on public/private security entities to respect and protect the fundamental rights of vulnerable persons, including persons with disabilities, in data-processing activities tied to security operations.

Claims: CLM-CL-294e4e4e

Category narrative62 words

Ley 21.719 creates a differentiated regime for children's/adolescents' data and imposes a heightened breach-notification duty when a breach affects data of children under 14. A separate private-security regulation (Ley 21.659) imposes fundamental-rights-protection duties toward vulnerable groups, including children and persons with disabilities, in security-related personal-data processing. No explicit age-verification mechanism, parental-consent procedure, minor-profiling ban, or education-setting-specific rule was identified in sources reviewed.

Sources and claims (2)
  1. ConfirmedIAPP<cite index="35-2">Data subjects must be notified when breaches affect data of children under 14 years of age, establishing an operative age threshold within the breach-notification regime.</cite>
  2. ProbableIAPP<cite index="1-2">Public or private institutions engaged in private security must respect and protect fundamental human rights and freedoms, especially concerning vulnerable persons, children, adolescents, and persons with disabilities.</cite>

#

Enforcement architecture is enacted but the Agency is not yet operational and the penalty framework may still be amended by a pending bill; current in-force redress is limited to civil litigation.

Primary frameworkLey N.º 21.719 (amending Ley N.º 19.628)
Supervisory authorityAgencia de Protección de Datos Personales (APDP)
Traffic-light rationale — AmberEnforcement architecture is enacted but the Agency is not yet operational and the penalty framework may still be amended by a pending bill; current in-force redress is limited to civil litigation.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Agency will hold instruction, interpretation, supervision, infringement-determination, sanctioning, complaint-resolution, certification, and international-cooperation powers; infringements are tiered leve/grave/gravísima, denominated in UTM, with suspension powers for repeat very-serious violations.

Claims: CLM-CL-3a5f4f4f, CLM-CL-4b604f5f, CLM-CL-5c714f6f

Enforcement Activity IndexRed

No enforcement activity index could be constructed: the Agency does not yet exist and Ley 19.628's civil-court mechanism generates no centrally tracked enforcement statistics identified in sources reviewed.

Absence provenance: not recorded. Searched: C, h, i, l, e, , A, g, e, n, c, i, a, , P, r, o, t, e, c, c, i, ó, n, , D, a, t, o, s, , m, u, l, t, a, s, , s, a, n, c, i, o, n, e, s, , 2, 0, 2, 6.

Regulator Funding And CapacityRed

Agency capacity/funding cannot yet be assessed since its governing Consejo Directivo had not been appointed as of the research date (deadline 1 June 2026).

Absence provenance: not recorded. Searched: A, g, e, n, c, i, a, , P, r, o, t, e, c, c, i, ó, n, , d, e, , D, a, t, o, s, , P, e, r, s, o, n, a, l, e, s, , C, h, i, l, e, , p, r, e, s, u, p, u, e, s, t, o, , d, o, t, a, c, i, ó, n, , p, e, r, s, o, n, a, l.

Claims: CLM-CL-b21e5e5e

Collective Redress And Class ActionsRed

No data-protection-specific collective-redress or class-action mechanism was identified in sources reviewed for this run.

Absence provenance: not recorded. Searched: C, h, i, l, e, , a, c, c, i, ó, n, , d, e, , c, l, a, s, e, , p, r, o, t, e, c, c, i, ó, n, , d, a, t, o, s, , p, e, r, s, o, n, a, l, e, s, , L, e, y, , 2, 1, ., 7, 1, 9.

Private Right Of ActionAmber

Under current Ley 19.628, data subjects may pursue civil damages for patrimonial and moral harm caused by improper data processing via the courts.

Claims: CLM-CL-6d824f7f

Recent Developments 180DAmber

Within the last 180 days: a January 2026 public-sector adjustment law set the 1 June 2026 deadline for appointing the Agency's Consejo Directivo, and a parliamentary-motion bill (Boletín N.º 18.060-07) to amend aspects of Ley 21.719 remains in first constitutional procedure.

Claims: CLM-CL-b21e5e5e, CLM-CL-7e934f8f

Category narrative65 words

Under current Ley 19.628, redress is court-based (civil damages actions for patrimonial and moral harm). Ley 21.719 (not yet effective) creates the APDP with instruction, interpretation, supervision, sanctioning, and complaint-resolution powers, a tiered leve/grave/gravísima penalty structure denominated in UTM, and suspension powers for repeated very-serious infringements. A pending parliamentary bill would revise the penalty ranges. No dedicated collective-redress/class-action mechanism specific to data protection was identified.

Sources and claims (6)
  1. ConfirmedIAPP<cite index="11-7">The Agency has functions to issue instructions, interpret the regulation's provisions, oversee compliance with obligations, determine non-compliance, exercise sanctioning power, resolve data subjects' requests and complaints, conduct promotional and dissemination activities, propose measures to the President and Congress, provide technical assistance to autonomous bodies, enter cooperation agreements, participate with international organisations, and certify and supervise compliance models.</cite>
  2. ConfirmedIAPP<cite index="15-23,15-24">Infringements by data controllers of the principles, rights and obligations established by the law are classified, according to gravity, as minor, serious and very serious, with minor infringements sanctioned by written warning or fines.</cite>
  3. ConfirmedIAPP<cite index="43-13">In cases of repeated very serious infringements within a 24-month period, the control authority may order suspension of the data controller's processing operations and activities for up to 30 days, extendable indefinitely until corrective measures are adopted.</cite>
  4. ConfirmedIAPP<cite index="35-9">Ley 19.628 establishes only the duty to indemnify patrimonial and moral damage caused by improper data processing, without prejudice to eliminating, modifying or blocking data as required by the data subject or ordered by a court.</cite>
  5. ConfirmedIAPP<cite index="41-1,41-2">Recently, in January 2026, via the public-sector adjustment bill, rules were approved establishing that the Agency's Consejo Directivo must be designated before 1 June 2026, and that if the Senate does not act before that date the presidential proposal of counsellors will be deemed accepted.</cite>
  6. ProbableIAPP<cite index="2-8">A parliamentary-motion bill (Boletín N.º 18.060-07) intended to perfect aspects of Ley N.º 21.719 is currently in first constitutional procedure.</cite>
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Chile
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 47 claim(s), 13 source(s) in the cumulative register.