CiberLATAMbywhalemate

Chile's Cybersecurity Law 21.663 Takes Effect

Law 21.663 sets reporting duties, sanctions and obligations for essential entities. Chile is also advancing AI and data reforms.

Whalemate Labs · AI-assisted researchJul 19, 20262 min read

Chile’s Cybersecurity Framework Law, Law 21.663, now sets out an institutional structure and a duty regime for state bodies, essential institutions and vital operators. At the same time, Chile’s regulatory debate now includes a new Data Protection Law and progress on the artificial intelligence bill.

Law 21.663 sets concrete obligations

Law 21.663, Chile’s Cybersecurity Framework Law, establishes an institutional structure, principles and general rules to organize, regulate and coordinate cybersecurity actions across state agencies and their relationship with private parties. It also sets minimum requirements for prevention, containment, resolution and response to cybersecurity incidents.

The law applies to institutions that provide services classified as essential, as well as those designated as vital operators, both of which must comply with its provisions. Under this framework, public and private institutions considered essential, or deemed vital operators, must report cyberattacks and cybersecurity incidents that may have significant effects to the National CSIRT within the deadlines set by law.

Fines and oversight

The law’s penalty regime is tiered. It defines minor, serious and very serious violations, with fines of up to 5,000, 10,000 and 20,000 monthly tax units, respectively. For vital operators, those penalties are doubled.

The broader regulatory picture

Chile’s regulatory framework does not stop at cybersecurity. Among the available sources is an analysis of the country’s new Data Protection Law, which is also driving meaningful changes for companies and their compliance programs.

At the same time, Chile’s artificial intelligence bill is moving forward. The available reference to that file says the legislative process is still underway, as part of a broader debate that also includes regulation of data, advertising and copyright.

There are also references to proposals to update the regulation of computer crimes, completing a landscape in which cybersecurity, data protection and artificial intelligence are increasingly treated as pieces of the same regulatory puzzle.

Sources

View all