Chile · Ley 21.719
Chile's Ley 21.719: be ready by 1 December 2026
Chile's new data protection law, Ley 21.719, enters full force on 1 December 2026, replacing a 1999 law that had almost no enforcement power. The new Data Protection Agency (APDP) is already operating, breach notification will be due within 72 hours, and fines reach 20,000 UTM, about USD 1.55 million, with repeat serious offenses scaling to 4% of annual revenue. The law applies to companies of every size; smaller companies get written warnings instead of fines for the first 12 months, but warnings go on the record. MapleNorthIT runs remote readiness audits for businesses with 5 to 100 employees, sharing most of Santiago's business day from Vancouver.
Last updated: July 2026 · MapleNorthIT
Ley 21.719 full force: 1 December 2026
Published in December 2024 with a 24-month transition, the clock runs out on 1 December 2026. The APDP can investigate on its own initiative, suspend data processing for up to 30 days, and publish sanctions in a national registry for five years. The law is closely aligned with the GDPR, so companies with European clients get double value from preparing once.
What Chile businesses need to know
- Fines reach 20,000 UTM, roughly USD 1.55 million, and repeat serious offenses scale to 4% of annual revenue or triple the fine, whichever is greater.
- Breaches must be reported to the APDP within 72 hours, with affected people notified when the risk to them is high.
- Small companies receive written warnings instead of fines from December 2026 to December 2027, but each warning is recorded and counts later.
- The APDP is already operating and inspects operational evidence: logs, inventories, and dated records, not just written policies.
Two ways to get compliant
Compliance Readiness Audit
A one-hour remote call plus a review of your setup. Written report within 48 hours, with every gap ranked Critical, Important, or Recommended and a rough cost to fix each one.
Book an auditFixed-scope security projects
One problem, one price, one deliverable: email authentication, account hardening, backup testing, offboarding cleanup, and more, from $399 CAD, fully remote.
View the projectsPay in CAD by card via Stripe. A $400 CAD audit is roughly CLP 280,000.
Common questions
When does Ley 21.719 take effect?
1 December 2026, full stop. The law was published on 13 December 2024 with a 24-month transition period, and the Data Protection Agency has been building capacity since. From that date the APDP can investigate, fine, and suspend data processing.
Does the law apply to small companies?
Yes, to every organisation that processes personal data in Chile, public or private, of any size. Companies that qualify as smaller enterprises under Ley 20.416 receive written warnings instead of fines during the first 12 months, until December 2027. The warning window is a chance to fix things, not a pass: warnings are recorded and weigh against you in later inspections.
What should we have ready before December 2026?
An inventory of the personal data you hold and where it lives, access controls with MFA, contracts with every vendor that touches your data, and a breach response process that can actually hit the 72-hour notification clock. The APDP has signalled it will ask for dated operational evidence, not just policies, so logs and records matter as much as documents.
We already comply with GDPR. Are we covered?
Mostly, and that is good news. Ley 21.719 was modeled closely on the GDPR, so existing GDPR policies, processing records, and vendor contracts can be reused with adjustments for Chilean specifics like UTM-based fines and the APDP's procedures. A readiness audit maps the remaining gap, which is usually smaller and cheaper than starting over.