CiberLATAMbywhalemate

Chile advances data rules, Senate reviews two bills

The Senate is moving two bills tied to Law 21,719 while debate continues over when it takes effect. The data agency is also being set up.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

August 21, 2026 update: Chile’s Senate is processing two bills linked to Law 21,719, one on digital identity and synthetic representation and another aimed at refining the personal data law and the Personal Data Protection Agency. At the same time, specialized sources say the law was published on December 13, 2024, and its entry into force remains set for December 1, 2026 unless another law changes that date.

Congress: new rules for data and platforms

The Science Committee of the Chamber of Deputies agreed to begin work on the bill that would require digital platforms to maintain a legal domicile in Chile, identified as Bill No. 18,362-19. The proposal originated as a motion from deputies and is now in its first constitutional stage.

In the same session, the committee kept under discussion the bill establishing a framework for algorithmic responsibility and digital protection for children and adolescents, Bill No. 18,318-19, also in its first constitutional stage. The fact that both initiatives are on the legislative agenda at the same time shows that the lower house is reviewing rules for digital intermediaries and specific safeguards for minors in parallel.

What bills tied to Law 21,719 entered the process?

The Senate is processing two bills linked to Law 21,719, one that amends the law on digital identity and synthetic representation, and another that seeks to improve the personal data protection and processing law and the creation of the Personal Data Protection Agency.

The first is Bill 18,118-07, and the Senate’s legislative system lists it as under consideration. The second is Bill 18,060-07, which also appears as under consideration in the upper house.

What does Bill 18,060-07 change?

Bill 18,060-07 aims to narrow the law’s extraterritorial application rule and refine several aspects of Law 21,719, according to the GDPRI international monitor.

That monitor also says the proposal remains in its first constitutional stage. In parallel, the same tracking places the general entry into force of Law 21,719 on December 1, 2026, with extraterritorial application to entities incorporated in Chile, processing operations located in the country, and entities offering goods or services in Chile.

When does Law 21,719 take effect?

Law 21,719 was published on December 13, 2024, and its entry into force is deferred until December 1, 2026, according to legal guides and specialized monitoring.

An independent legal blog says that date can only be changed by another law and that, until then, Law 19,628 remains in force. In the same vein, a local opinion and analysis outlet says the government is considering delaying the effective date, although there is still no official statement or specific bill to make that change.

How is the institutional rollout moving?

The Personal Data Protection Agency already has a deadline set for its political leadership, and the GDPRI monitor says a January 2026 public-sector adjustment law set June 1, 2026 as the date to appoint its Board of Directors.

That step fits the institutional setup needed before Law 21,719 fully enters into force. The agency will have the power to conduct ex officio inspections, investigate complaints, and directly sanction data controllers, according to the legal guide consulted.

Data governance in the Senate

Meanwhile, the Senate’s Committee on Future Challenges, Science, Technology and Innovation continues its general debate on the bill creating the National Data Management System and amending legal bodies, Bill No. 17,590-05. The initiative was introduced in a message from the President of the Republic and remains in its first constitutional stage.

The committee formally placed the discussion on its work calendar at the August 10, 2026 session, confirming that the bill remains active in the upper house.

Personal data law, still waiting for a decision

On the data protection front, the Minister of Economy and Mining, Daniel Mas, said the government is evaluating whether to delay the entry into force of Law No. 21,719, currently scheduled for December 1, 2026. That information was attributed to the source consulted, but there is still no official statement or published regulatory change.

The possible delay sits alongside public debate over the rollout timeline for the new law and the fact that the regulation remains a major institutional and technical issue in Chile.

Electrical cybersecurity under accelerated review

In the energy sector, the Undersecretariat of Energy instructed the National Energy Commission, or CNE, to finalize the draft Technical Standard for Cybersecurity and Information Security for the electricity sector, remove the chapter on the electric CSIRT, and submit the cleaned-up text for public consultation no later than August 31, 2026. The official goal is to publish the standard in 2026.

The order also set August 14, 2026 as the deadline for the CNE to send the revised text and the remediation matrix to the Undersecretariat of Energy and the National Cybersecurity Agency, or ANCI. The instruction also requires removing any provision, definition, or reference related to the designation, structure, or powers of a sectoral CSIRT or Electric CSIRT, so that design is left outside this standard and reserved for future ANCI regulation.

Sending the text to ANCI means the agency will act as a co-technical reviewer of the electricity sector standard before public consultation, with coordination between the energy regulator and the national cybersecurity authority.

Existing technical regulation

The CNE has also been framing the development of digital substations within the Technical Standard for Security and Service Quality and the Technical Annex of Minimum Design Requirements for Transmission Installations. According to its institutional communications, those instruments already include criteria for technological compatibility, redundancy, and secure design, and the future cybersecurity standard will complement that technical framework.

Sources

View all