CiberLATAMbywhalemate

Chile Tightens Data Breach Reporting

Law 21.719 adds 5-day breach notices, higher penalties and new internal compliance demands for banks and fintechs in Chile.

Whalemate Labs · AI-assisted researchJul 15, 20262 min read

Chile's Personal Data Protection Law 21.719 adds new obligations for companies, including financial firms, with tighter notification deadlines, data governance requirements and a tougher sanctions regime. The change builds on existing duties to the CMF and the National CSIRT.

Chile's Personal Data Protection Law 21.719 adds another layer of requirements for companies, including those in the financial sector. According to analysis released by the Santiago Chamber of Commerce and BigBuda, the law requires firms to map data processing activities, determine legal bases, review breaches and carry out corrective measures, in addition to notifying any breach that poses a risk to rights and freedoms within a maximum of 5 business days from the moment it becomes known.

New reporting flow

That notice must be sent both to the future Data Protection Agency and to affected data subjects. In practice, the scheme adds a dedicated reporting channel on top of the obligations already imposed on banks and fintechs before the CMF and the National CSIRT. The result is a stricter notification framework for incidents involving personal data and information security.

Penalties and financial exposure

The law also sets out a sanctions regime that can reach up to 5,000 UTM for minor violations, 10,000 UTM for serious violations, and 20,000 UTM or 4% of annual global sales for the most serious violations, whichever is higher. According to BigBuda's summary of Garrigues' analysis, this significantly raises the financial risk tied to security breaches and poor data management in banks and fintechs compared with the previous regime.

More internal compliance functions

The Santiago Chamber of Commerce also published a guide for SMEs on personal data protection with a 10-step methodology. Those steps include appointing an internal data protection officer, mapping processing activities and analyzing breaches. That framework suggests that even smaller financial services firms, such as fintechs and merchants that process payments, will need a formal internal function dedicated to data and security compliance.

Existing security framework

The move lands in a regulatory environment that had already been raising technical requirements. Sources available for this report include CMF rules on information security and cybersecurity management, Chile's Fintech Law, Cybersecurity Law 21.663 and the Congressional Library's guide on cybersecurity for state agencies and critical information infrastructure. Together, that framework points to stronger obligations around risk management, critical asset inventories, registration and periodic reporting for regulated players in Chile's financial system.

Sources

View all