Compliance Node Overview
Chile's Ley Marco de Datos Personales (Framework Law on Personal Data) - Law No. 21.719, published in the Diario Oficial de la República de Chile on 13 December 2024 and entering into force on 13 December 2026 (a two-year transition period) - is Chile's comprehensive modern data protection law, substantially replacing and modernising the prior Ley de Protección de la Vida Privada (Law No. 19.628 of 1999), which was one of Latin America's earliest data protection statutes. Law No. 21.719 represents a landmark reform of Chilean data protection, designed to bring Chile into alignment with international standards including the EU GDPR framework. Chile previously obtained EU GDPR adequacy status through European Commission Decision 2013/65/EU of 19 December 2012, which recognised Chile's 1999 framework as adequate - the new law is expected to strengthen and maintain this adequacy position. The enforcement authority under the new framework is the Consejo para la Transparencia (CPLT - Council for Transparency), which had been the transparency authority and will assume expanded data protection enforcement powers, and a newly established Agencia de Protección de Datos Personales (APDP - Personal Data Protection Agency) to be created under the new law. Key features of Law No. 21.719: (1) Controller (Responsable) and Processor (Mandatario) terminology; (2) Seven lawful bases for processing aligned with GDPR: consent, contract, legal obligation, vital interests, legitimate interests, public interest, and the controller's legitimate interests; (3) Sensitive personal data - broadly defined including: ideological, political, religious, or philosophical beliefs; trade union membership; physical or psychological health; ethnicity or race; life and sexual practices; genetic data; biometric data; criminal records; financial or economic data; (4) Data subject rights aligned with GDPR: right to information, access, rectification, erasure, portability, objection, and not to be subject to automated decision-making; (5) Data Protection Impact Assessment (DPIA) - required for high-risk processing; (6) Data Protection Officer (DPO) - required for large-scale or high-risk processing; (7) Mandatory breach notification to the APDP within 72 hours; (8) Cross-border data transfer restrictions aligned with GDPR adequacy framework; (9) Administrative fines up to 5% of annual income or UF 5,000 (approximately USD 200,000) whichever is greater. Note: as of April 2026, Law No. 21.719 is in its two-year transition period - full compliance obligations will take effect on 13 December 2026. Organisations should begin implementation planning immediately. The prior law (Law No. 19.628 of 1999) remains in force during the transition period. Chile is an OECD member and one of Latin America's most economically advanced nations, making data protection compliance particularly important for Chilean and multinational organisations.
Pillar: Cybersecurity · Authority: Consejo para la Transparencia (CPLT - Council for Transparency, Chile) · Version: 1.0.0 · Last updated:
Primary source: https://www.consejotransparencia.cl/
SHA-256 integrity: b5fde47f9ce80742cc9b948bdfd70cc7782a670aaab72a42dad3119a5246ee3d
Primary Citations — 6 traced to source
- Ley Marco de Datos Personales (Law No. 21.719, Chile) - published Diario Oficial 13 December 2024; full compliance 13 December 2026 (two-year transition); replaces Law No. 19.628 (1999); seven lawful bases: consent, contract, legal obligation, vital interests, legitimate interests, public interest, controller's legitimate interests; sensitive personal data: ideological/political/religious/philosophical beliefs, trade union membership, health, ethnicity/race, sexual practices, genetic data, biometric data, criminal records, financial data; 72-hour APDP breach notification; DPO for large-scale/high-risk processing; DPIA mandatory for high-risk processing; fines up to 5% of annual income or UF 5,000; rights: information, access, rectification, erasure, portability, objection, no automated decision-making
- Ley de Protección de la Vida Privada (Law No. 19.628, Chile, 1999) - predecessor legislation remaining in force during Law No. 21.719 transition period; primary obligations: consent or legal authorisation basis; sensitive data categories: race, health, personal habits, sexual life, political opinions, religious beliefs, trade union affiliation; data subject rights: access, rectification, erasure, blocking; 15-business-day response deadline; CPLT enforcement during transition; registration of certain databases with CPLT
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access