Chile sets rules for data protection certification
Chile issued a decree setting rules for implementation, certification, registration, and supervision of data protection prevention models.
Chile issued the decree that sets the rules for implementing, certifying, registering, and supervising models for preventing violations in personal data protection. Decree No. 662 from the Ministry of Finance also sets the minimum elements for those models and the rules for supervising them.
Update October 9, 2026: Chile published Decree No. 662 in the Official Gazette, approving the regulation on the implementation, certification, registration, and supervision of models for preventing violations in personal data protection. The official text also clarified the minimum components of those models, which were already contemplated by Law No. 21,719 as a voluntary compliance program.
Chile published a regulation that sets the rules for implementing, certifying, registering, and supervising models for preventing violations in personal data protection. Decree No. 662, from the Ministry of Finance, was published in the Official Gazette on September 9, 2026, according to Garrigues, and lays out the process for anyone seeking to have that framework approved by the competent authority.
What changes with this regulation?
The new framework defines how models for preventing violations in personal data protection are implemented, certified, registered, and supervised. Law No. 21,719 amended Law No. 19,628 by adding Articles 49 through 53, which create this model as a voluntary compliance program for any data controller, whether an individual or legal entity, public or private, according to Garrigues.
The decree also adds the operational detail that had been missing from the framework. According to the official text of Decree No. 662, the model includes, among other elements, identification of the data controller, the appointment of a data protection officer, characterization of the data and processing activities, a risk matrix, prevention protocols and procedures, internal and external reporting mechanisms, internal administrative sanctions, and internal complaint mechanisms.
Who does the pending compliance apply to?
The compliance obligation applies to any data controller that decides to adopt a model for preventing violations, regardless of whether it is an individual or legal entity, public or private. Law No. 21,719 made that adoption voluntary and placed it within Law No. 19,628, so the scope is not limited to any specific sector or type of organization, according to Garrigues.
At the same time, public discussion of the new law continued to show that the change requires a review of internal processes. Emol reported that 72% of companies in Chile say they are not ready for the new Personal Data Law, while The Clinic cited a broad reading of the law’s scope, from a building concierge to a multinational company.
What happens if the requirements are not met?
The regulation provides for consequences if the requirements are not met or if false, incomplete, or clearly inaccurate information is submitted. In those cases, the conduct may be sanctioned under the law, which makes the information submitted to obtain certification highly sensitive.
FYCOM also noted that certification is valid for three years and can be supervised, two elements that require compliance to be maintained over time, not just at the moment the application is filed. With the entry into force of Law No. 21,719 drawing closer, the adjustment for Chilean organizations is no longer just about documenting policies, but about sustaining them under a formal framework of control and verification.
Sources
- Protección de datos: Nuevo reglamento sobre implementación y certificación de modelos de prevención de infraccionesfycom.cl· FYCOM
- El 72% de las empresas en Chile reconoce no estar preparada para la nueva Ley de Datos Personalesemol.com· Emol
- Diego Morandé ante la nueva ley de Datos Personales: “Aplica a todo aquel que trate datos desde el conserje del edificio hasta una transnacional”theclinic.cl· The Clinic
- Government Publishes Regulation Governing Personal Data Infringement Prevention Modelslegal500.com· Legal 500
- Decreto N° 662/2025 — Reglamento que ...regulations.ai· Regulations.ai
- New Regulations on Model Rules for the Prevention of Violations in Personal Data Protectionaz.cl· Alessandri Abogados
- Modelos de prevención de infracciones de datos personalescuatrecasas.com· Cuatrecasas
- Ley de Protección de Datos: Hacienda publicó reglamento para modelos de prevención de infraccionesesghoy.cl· ESG Hoy
- Lawyers Explain the Implications of the First Regulation Under the Personal Data Protection Actaz.cl· AZ
- Reglamento del MPI: qué exige el Decreto 662codevsys.cl· Codevsys
- Chile fortalece la protección de datos con un marco de certificación de modelos de prevención de infraccionesgarrigues.com· Garrigues
- Ley Chile - Decreto 662 (09-sep-2026) M. de Haciendabcn.cl· Biblioteca del Congreso Nacional de Chile



