CiberLATAMbywhalemate

Chile keeps Law 21,719 delay under review

Chile’s Senate is still debating a delay to Law 21,719, with enforcement still set for Dec. 1, 2026 unless approved

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

The delay to Law 21,719 remains under review in the Senate, and until it is approved and published, enforcement is still set for Dec. 1, 2026. The debate has added proposals to shorten the postponement to six months or phase in the law, but the legal timetable has not changed.

Update Oct. 6, 2026: as of Oct. 1, the postponement bill had still not begun its legislative process, and it was expected to start in mid-October. At the same time, the opposition pushed to cut the delay to six months, and proposals also emerged for a gradual rollout of some provisions.

The delay to Chile’s Personal Data Law 21,719 is still moving through the Senate, and until it is approved and published, the effective date remains Dec. 1, 2026. The political debate has also introduced alternatives, including trimming the government’s proposed one-year delay or applying the law in phases, but none of those options has changed the legal calendar so far.

What changes with the bill in the Senate?

CSiTI says the change is not in force yet because the bill is still making its way through Congress. Until it is approved and published, it should not be treated as settled. In that context, the firm’s analysis stresses that the key point for companies and public agencies is not to rework compliance plans based on an announcement that has not been enacted.

As of Oct. 1, 2026, the postponement bill had not yet begun its legislative process. La Tercera reported that debate was expected to start in mid-October, while Pedro Araya had said the review could begin in the second week of the month.

What date does the postponement propose?

According to a BioBioChile column, the bill would not only move the effective date to Dec. 1, 2027, but also expand the Personal Data Protection Agency council from three members to five and advance the appointment of its first board member. That information, however, should be checked against the official text of the message.

The debate also includes a narrower option from the opposition. Pauta reported that opposition sectors proposed reducing the government’s one-year delay to six months. CONADECUS said the discussion could also include a gradual rollout of different provisions, in addition to the one-year or six-month delay options.

What compliance obligations remain in force?

CSiTI links Supreme Decree 662 to a diligence standard that could be demonstrated through an infraction-prevention model. In its analysis, the firm also explains that the new regulation on the implementation and certification of those models is intended to organize how compliance is proven, even if the delay is later approved.

For small and midsize companies, the bill would not change the substantive obligations of Law 21,719, only the point at which penalties for noncompliance would begin. Another private analysis adds that, during the initial period, the agency could issue a written warning instead of a fine to any company, although that would be up to the authority and not an automatic guarantee.

What happens with international data transfers?

A specialized legal analysis says the postponement bill would not change the regime for international data transfers. Under that reading, the matter would continue to depend on a temporary instrument until the Personal Data Protection Agency regulates it.

The interpretation appears in a Diario Financiero column and does not reflect a legal change already in force, but rather an assessment of the bill’s scope while it is still under review. The same analysis places the postponement’s main focus on the board of the Personal Data Protection Agency.

What signals is the private sector sending?

Emol reported that 72% of companies in Chile say they are not ready for the new Personal Data Protection Law, although the methodology for that measurement was not available in the result reviewed. Portal Innova, citing GlobalLogic, said the delay is meant to allow more time to set up the new institutional framework and help public and private organizations adapt.

G5 Noticias, in a column by a regional Sophos representative, raised risks tied to delaying the law, a cybersecurity-sector response that reflects concern in the market. The Clinic also published comments from Diego Morandé, who said the law applies to anyone handling data, from a building concierge to a multinational.

Another report says the bill would increase the future Personal Data Protection Agency board from three to five members, set a quorum of three, and move up the appointment of the first board no later than 12 months before the law takes effect. That same reading says the bill would also change the transitional sanction regime, with a written warning for all regulated entities during the first year instead of limiting it to smaller companies.

DSN Group also said the Senate rejected the government’s nominations for the agency board in May 2026, leaving the regulator unformed and without guidance, model clauses or adequacy decisions. That claim still needs further official confirmation.

Sources

View all