CiberLATAMbywhalemate

Chile Revises Cybersecurity and Data Compliance Rules Under

Chile's Law 21.663 and the rollout of Law 21.719 are reshaping compliance requirements for organizations operating in the country. The most visible

Whalemate Labs · AI-assisted researchPublished:2 min read

Chile's Law 21.663 sets out a regulatory framework aimed at stronger risk management, security, and digital continuity practices across organizations, although the strictest obligations are concentrated in critical sectors. At the same time, disclosure materials in Chile say the rule requires an Information Security Management System, the appointment of a cybersecurity officer, and procedures for reporting incidents.

New regulatory obligations

Chile's Law 21.663 creates a regulatory framework that pushes better risk management, security, and digital continuity practices across organizations, although the strictest obligations are aimed at critical sectors. At the same time, disclosure materials in Chile say the rule requires organizations to implement an Information Security Management System, appoint a cybersecurity officer, and establish incident reporting procedures, framing it as a broad change for organizations operating in the country.

Personal data and penalties

On data protection, training materials in Chile indicate that [Law 21.719](/en/news/chile-data-protection-law-takes) significantly increases fines and sanctions for public and private organizations that process personal data without complying with the rules. That framing places the law as a structural shift in the sanction regime, with a direct effect on internal compliance processes and the handling and protection of personal information.

Timelines and implementation uncertainty

The regulatory transition still has gray areas. A LinkedIn post by Valentina Palma, a lawyer specializing in data protection in Chile, says there are implementation obligations under the new Law 21.719 with a milestone on Dec. 1, but argues that by that date there were still no basic certainties about how the authority would operate or about the regulations needed to support it. That view points to uncertainty in the adjustment process.

The debate comes as local disclosure pieces have been outlining the practical reach of Law 21.663, from the role of the ANCI in regulating and overseeing it to the need to prepare for a more formal incident, security, and privacy management model. In that framework, the issue is no longer just about adopting technical controls, but about maintaining evidence of compliance under two legal regimes that are beginning to impose tighter order on digital operations in Chile.

Sources

View all