CiberLATAMbywhalemate

Chile extends data protection law timeline

Chile is seeking more time to roll out Law 21,719 as Law 21,663 already has active penalties and 1,154 critical operators.

Whalemate Labs · AI-assisted researchPublished:3 min read

Chile’s government has proposed extending the implementation deadline for Personal Data Protection Law No. 21,719, while regulatory attention also remains on the Cybersecurity Framework Law No. 21,663, which has had an active sanctions regime since March 2025 and 1,154 Vital Importance Operators classified by ANCI as of 2026.

Chile’s government has proposed extending the implementation deadline for Personal Data Protection Law No. 21,719 and its related institutions, while regulatory debate is also centered on Cybersecurity Framework Law No. 21,663. At the same time, a sector analysis said the law has had an active sanctions regime since March 2025 and that ANCI had classified 1,154 Vital Importance Operators as of 2026.

What is the government proposing on the data law?

The official proposal aims to extend the implementation deadline for Law No. 21,719 and the institutions tied to it, according to Chile’s Ministry of Economy, Development and Tourism on September 1, 2026. The announcement comes amid a broader regulatory discussion that affects regulated organizations across sectors.

The ministry material provided does not specify the new deadline, but it does confirm that compliance with the data law is now at the center of the agenda. That debate is unfolding alongside the practical enforcement of other rules already in force in Chile’s ecosystem.

What is the status of Cybersecurity Framework Law 21.663?

Cybersecurity Framework Law No. 21.663 has had an active sanctions regime since March 2025, according to a sector analysis published in Chile by NBITEK. The same review says ANCI had classified 1,154 Vital Importance Operators as of 2026.

That figure shows the law has already moved into an operational phase. It affects regulated organizations and sits at the center of the discussion alongside the data protection law.

What does Chile’s public and business agenda show?

The agenda reflects an overlap between regulatory compliance, operational resilience, and the continuity of critical infrastructure, themes that also appear in the call for the Industrial Cyber Summit Chile 2026. InvestChile presented the event as a forum to discuss the practical implementation of Law 21.663, industrial resilience, and critical infrastructure protection.

The meeting will take place on September 3, 2026, at the Hilaria Convention Center in Santiago, bringing together the public sector, industry, and experts. According to InvestChile, the program will also address operational resilience and other regulatory and technology issues linked to critical infrastructure.

What role does the Central Bank play in this scenario?

Chile’s Central Bank also came under the regulatory spotlight by expanding access to the LBTR system to new non-bank financial entities, with associated cybersecurity requirements. That move adds another front for players seeking to join the financial system under new technical and control conditions.

Sources

View all