CiberLATAMbywhalemate

Chile sets rules for data protection certification

Chile issued a decree setting rules for implementation, certification, registration, and supervision of data protection prevention models.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Chile issued the decree that sets the rules for implementing, certifying, registering, and supervising models for preventing violations in personal data protection. Decree No. 662 from the Ministry of Finance also sets the minimum elements for those models and the rules for supervising them.

Update October 9, 2026: Chile published Decree No. 662 in the Official Gazette, approving the regulation on the implementation, certification, registration, and supervision of models for preventing violations in personal data protection. The official text also clarified the minimum components of those models, which were already contemplated by Law No. 21,719 as a voluntary compliance program.

Chile published a regulation that sets the rules for implementing, certifying, registering, and supervising models for preventing violations in personal data protection. Decree No. 662, from the Ministry of Finance, was published in the Official Gazette on September 9, 2026, according to Garrigues, and lays out the process for anyone seeking to have that framework approved by the competent authority.

What changes with this regulation?

The new framework defines how models for preventing violations in personal data protection are implemented, certified, registered, and supervised. Law No. 21,719 amended Law No. 19,628 by adding Articles 49 through 53, which create this model as a voluntary compliance program for any data controller, whether an individual or legal entity, public or private, according to Garrigues.

The decree also adds the operational detail that had been missing from the framework. According to the official text of Decree No. 662, the model includes, among other elements, identification of the data controller, the appointment of a data protection officer, characterization of the data and processing activities, a risk matrix, prevention protocols and procedures, internal and external reporting mechanisms, internal administrative sanctions, and internal complaint mechanisms.

Who does the pending compliance apply to?

The compliance obligation applies to any data controller that decides to adopt a model for preventing violations, regardless of whether it is an individual or legal entity, public or private. Law No. 21,719 made that adoption voluntary and placed it within Law No. 19,628, so the scope is not limited to any specific sector or type of organization, according to Garrigues.

At the same time, public discussion of the new law continued to show that the change requires a review of internal processes. Emol reported that 72% of companies in Chile say they are not ready for the new Personal Data Law, while The Clinic cited a broad reading of the law’s scope, from a building concierge to a multinational company.

What happens if the requirements are not met?

The regulation provides for consequences if the requirements are not met or if false, incomplete, or clearly inaccurate information is submitted. In those cases, the conduct may be sanctioned under the law, which makes the information submitted to obtain certification highly sensitive.

FYCOM also noted that certification is valid for three years and can be supervised, two elements that require compliance to be maintained over time, not just at the moment the application is filed. With the entry into force of Law No. 21,719 drawing closer, the adjustment for Chilean organizations is no longer just about documenting policies, but about sustaining them under a formal framework of control and verification.

Sources

View all