CiberLATAMbywhalemate

Chile keeps Law 21.719 set for 2026

Chile’s delay bill for Law 21.719 is still moving through the Senate, so the current effective date remains Dec. 1, 2026.

Whalemate Labs · AI-assisted researchPublished:Updated 3 min read

Brazil is back at the center of regional data protection debate after its data authority fined TikTok 153.7 million reais under LGPD enforcement. In Chile, that case is now a reference point as officials and analysts discuss Law 21.719, the new personal data protection agency, and tighter oversight of companies and platforms.

Update October 8, 2026: In Chile, the bill to delay Law 21.719 is Bill No. 18.623-07 and was still in its first constitutional stage in the Senate Constitution Committee. Unless an amendment is approved and published, the legal effective date remains December 1, 2026.

Brazil is back at the center of the regional data protection debate after the National Data Protection Authority fined TikTok 153.7 million reais, part of enforcement under the LGPD. In Chile, that case is being used as a reference point for Law 21.719, the creation of the Personal Data Protection Agency, and a more active oversight environment for companies and platforms.

Why is Brazil being used as a reference for Chile?

Brazil is being cited because the LGPD has been in force since 2020 and the ANPD has already begun issuing sanctions, including a first significant fine against TikTok in July 2023, according to the research material. Chilean media and consulting firms have treated that experience as an example of the shift from having a law on the books to real enforcement.

The comparison appears in several analyses published in Chile. Poder y Liderazgo mentions it while explaining new Law No. 21.719, Forbes Chile uses it to anticipate the future oversight environment, and Grupo Cygnus cites it as one of the models behind Chile’s updated framework. SONDA also includes it in describing a full data processing chain that will be monitored by the future local authority.

What are they taking from the Brazilian experience?

They are taking both the sanctions regime and the compliance guidance and supervision model of the ANPD. Portal Innova said 72% of companies in Chile report they are not ready to comply with the data protection law, and it compared Chile’s planned penalties with the fines imposed in Brazil.

Revista Emprende also said the Brazilian framework became a regulatory benchmark for Chilean firms, which use the amounts of fines and risk criteria published in Brazil to map risks and prioritize investment in data governance and incident response. Estamos en Línea added that, even if there is another delay, consulting firms and compliance teams are still moving ahead using the LGPD as a regional case study to estimate the financial impact of possible noncompliance.

What does Law 21.719 change in Chile?

Law 21.719 creates the Personal Data Protection Agency and pushes companies to implement security measures, incident protocols, and obligations for registration and response to data subjects, several of them inspired by Europe’s GDPR and Brazil’s LGPD. AHD makes that explicit when describing the new compliance requirements.

Anguita Osorio added that the Infringement Prevention Model, linked to DS 662, allows companies to prevent violations, reduce fines, and demonstrate data governance before the future Chilean agency. The consulting firm presents it as a voluntary program based on international compliance best practices, with experience from the LGPD and ANPD enforcement serving as a practical reference for showing diligence in the face of potential sanctions.

What is the Chilean market saying about readiness?

The market is under pressure because of how unprepared companies appear to be. Portal Innova reported that 72% say they are not ready to comply with the law, while Forbes Chile and Poder y Liderazgo note that the debate over postponement does not remove the need to keep advancing internal controls, data governance, and process adaptation.

Publimetro Chile said the official reason for delaying the effective date is that the Personal Data Protection Agency is not yet in place. In that context, experts quoted by that outlet called for using the extra year to study the ANPD’s guidance and enforcement actions under the LGPD in detail, since Brazil is already at a more mature stage of enforcement and offers signals on regulatory priorities, exposed sectors, and types of conduct that are sanctioned.

At the same time, ASENTIC said the delay bill corresponds to Bill No. 18.623-07 and was still in its first constitutional stage in the Senate Constitution Committee. Until that change is approved and published, the current legal date remains December 1, 2026.

Sources

View all