NEWS

// ARTICULOS

Delay or pause? 10 practical considerations regarding the potential postponement of Chile’s Personal Data Protection Law

By Mariano Wood y Gabriel Vargas

The Executive has submitted a bill to the Chilean Senate proposing to postpone, from December 1, 2026 to December 1, 2027, the entry into force of the amendments introduced by Law No. 21,719. The stated reasons are primarily implementation-related: allowing additional time to establish the Personal Data Protection Agency, develop implementing regulations and standards, and enable both the public and private sectors to adapt their systems and processes. The purpose of this column is not to debate whether the postponement is advisable, but to clarify what it would mean in practice for companies and how that period should be used. Delaying the new regime does not reduce the importance of personal data protection, nor should the additional year be treated as idle time.

Delay or pause? 10 practical considerations regarding the potential postponement of Chile’s Personal Data Protection Law

1. The postponement is still only a proposal.

Until the bill is approved, enacted and published, December 1, 2026 remains the legally applicable reference date. Fully suspending a compliance-readiness process would therefore mean taking an unnecessary legislative risk.

2. The new regime would be postponed—not personal data protection itself.

If the proposal is approved in its current form, the new lawful bases for processing, expanded data subject rights, enhanced transparency and security duties, reporting of certain data breaches, rules governing processors and international data transfers, supervision by the Agency and the new sanctions regime would, among other matters, be deferred. In the meantime, Law No. 19,628 remains in force, together with the constitutional protection of personal data.

3. Virtually every company processes personal data and should review its position.

Data protection is not a matter limited to banks, healthcare providers or technology companies. Any company with employees already processes personal data: employment and payroll information, contact details, leave records, attendance records, performance reviews and other employment-related information. In most businesses, this is supplemented by data relating to job applicants, customers, suppliers and users.

4. The first step is to map the data and correctly allocate roles.

Before drafting policies, a company needs to identify what data it collects, for what purposes, on what legal basis, where it is stored, who can access it, how long it is retained and with which third parties it is shared. That inventory also makes it possible to determine when the company acts as a data controller and when it processes information on behalf of a third party as a data processor.

5. Outsourcing processing does not outsource responsibility.

The new law makes the relationship among controllers, processors and subprocessors particularly important. Liability and compliance exposure can run across the chain: a controller retains obligations even when using a SaaS or cloud provider; a processor must comply with the controller’s instructions and may incur direct responsibility if it uses the data for its own or different purposes; and subprocessors require appropriate contractual and operational controls. Data processing agreements therefore become a core part of third-party risk management.

6. Software and artificial intelligence make data governance more urgent.

CRM systems, HR platforms, analytics tools, cloud services and AI solutions multiply the points at which information is collected, hosted, shared and analysed. Companies are also increasingly using data to train, fine-tune or otherwise feed AI systems. Where personal data is involved, purpose limitation, lawfulness, minimisation, security and traceability must be assessed, particularly in cases involving profiling or automated decision-making. Correcting a data flow before it becomes embedded in the business is usually far easier than redesigning it afterwards.

7. Security risks and incidents do not wait for the law.

Data leaks, unauthorised access, configuration errors and cyberattacks can occur today. Companies should therefore move forward now with access controls, retention rules, backups, vendor management and incident-response protocols. The new regime will make these obligations more demanding and more demonstrable, but the operational and reputational risks already exist.

8. Data protection readiness also affects tenders and international contracting.

Contracts with multinational companies, due diligence processes, tenders, and dealings with foreign States, public authorities or international organisations increasingly include privacy, security, audit and data-transfer requirements. Law No. 21,719 expressly regulates international data transfers. Reaching comparable standards in advance can facilitate contracting, reduce last-minute negotiations and help avoid lost business opportunities.

9. Written warnings do not amount to immunity—and they also leave a record.

The bill proposes that, during the first twelve months of the new regime, the Agency’s power to issue a written warning may apply to all controllers, rather than only smaller companies. This is a discretionary enforcement tool, not a right to avoid a fine. In addition, such warnings are subject to registration. Law No. 21,719 creates a public and free National Register of Sanctions and Compliance, whose entries may remain accessible for up to five years. Compliance will therefore carry a reputational and due diligence dimension as well as a strictly legal one.

10. An additional year is not a long time when compliance is done properly.

A serious compliance project is not limited to publishing a new privacy policy. It requires an initial assessment, data mapping, review of lawful bases, vendor and processing agreements, procedures for exercising data subject rights, retention rules, security measures, incident response, training and evidence of compliance. It may also require technology changes and coordination among Legal, IT, Cybersecurity, HR, Marketing, Sales and Procurement. These advisory and implementation processes take months. An additional year may provide useful breathing room; it is hardly excessive.

If the postponement is approved, the better way to view it is not as a one-year pause, but as an opportunity to be better prepared. Companies that use that period to understand their data, organise their vendor relationships, update contracts and test their processes will enter the new regime in a materially stronger position when the Agency begins enforcement. In that context, demonstrable diligence and compliance will matter.