CiberLATAMbywhalemate

Chile sets 3-hour cyber alerts, fines up to 40,000 UTM

Chile now requires 3-hour alerts, 72-hour updates and penalties of up to 40,000 UTM under its new cyber laws.

Whalemate Labs · AI-assisted researchJul 17, 20262 min read

Chile is moving on two regulatory fronts at once: Law 21,663 sets reporting deadlines and oversight powers tied to operational continuity, while the new data protection law raises internal requirements for companies and public agencies, with fines that can reach 40,000 UTM.

Tight reporting windows and more oversight of continuity

Law 21,663 sets a very specific response window for incidents with significant impact: an early alert within 3 hours, an update within 72 hours, and a final report within 15 days. It also gives the ANCI authority to demand proof that continuity and cybersecurity plans actually work, according to an analysis by Quarancle.

That shifts the regulatory debate. Having internal documents or plans written for audits is no longer enough. The expectation now also includes operational evidence that the measures were implemented and can hold up during an incident.

Higher fines and new internal requirements

At the same time, Tivit said the sanctions regime linked to Chile’s new cybersecurity and data protection laws can reach 40,000 UTM, equivalent to more than $2.8 billion in the most severe cases.

Quarancle’s analysis added that the new data protection law introduces concrete operational requirements such as security and privacy by design, continuous assessment, and the ability to show that measures were implemented, not just documented. Together, those obligations increase pressure on companies and public agencies to adjust internal processes, controls, and the traceability of their compliance measures.

Two regulatory fronts at once

Chile’s regulatory shift leaves organizations facing two parallel obligations. On one side, Law 21,663 defines how incidents must be reported and what must be provable before the authority. On the other, the data protection law raises the standard for how organizations design and verify the measures they adopt.

For both private companies and the public sector, the key issue is no longer just reacting to incidents or formalizing policies. They will also have to show that operational continuity and data protection work in practice, under a stricter oversight and penalty framework.

Sources

View all