CiberLATAMbywhalemate

Chile tightens cyber reporting

Law 21.663 sets 24-, 72-hour and 15-day reporting deadlines, while raising penalties for vital operators.

Whalemate Labs · AI-assisted researchJul 14, 20262 min read

Chile has set fixed deadlines for reporting cyber incidents and a sanctions regime that raises maximum fines to 20,000 UTM, doubled for vital operators.

Reporting deadlines and incident closure

Chile's cyber framework now sets specific timelines for reporting incidents. Updates must be filed within 72 hours, or within 24 hours if the affected party is an operator of vital importance and essential services are affected, according to the National Congress Library of Chile's guide to Law 21.663. In addition, a final report is required within 15 calendar days, along with another one if the incident is still ongoing.

The framework is designed to push early notification and also require follow-up documentation after the incident. In practice, notifying authorities is not enough, the rules call for formal closure, with a second submission if the event has not been resolved within the initial period.

Fines and regulatory scope

Law 21.663 also includes a sanctions regime with maximum fines of 5,000, 10,000 and 20,000 UTM for minor, major and very serious violations, respectively. For operators of vital importance, those caps are doubled.

Chambers places this law within a broader Chilean information security framework that also includes the data protection law, the cybercrime law, CMF sector rules and telecommunications regulations. In that reading, the new law strengthens expectations around governance, incident reporting and operational resilience.

For financial institutions and other actors operating in Chile, the impact is not limited to compliance with a single statute. The framework sits alongside data handling obligations, cybercrime treatment and sector-specific regulation, in an environment where incidents must be reported and documented within fixed deadlines.

Required compliance controls

Prey Project's compliance guide adds that, together with Law 21.663 and Law 21.719, organizations in Chile must implement security controls, manage risk, protect personal data, maintain incident response plans and be able to show those measures to authorities.

That sets a compliance standard that goes beyond internal policies. It also requires evidence that those controls exist and work, a point that carries added weight in more heavily regulated sectors such as finance.

Sources

View all