12 August 2026

Chile’s Law 21.719: what your company needs ready before December 1

Chile’s new personal data law takes effect on December 1, 2026. It is not paperwork: it changes how your systems have to be built.

On December 1, 2026, Chile's Law 21.719 comes into force, replacing Law 19.628 and bringing the country in line with the European standard. It was published in December 2024, so there were two years to prepare. As of this article, there are fewer than four months left.

Almost everything written about this is written by lawyers. This is written from the other side: what your system has to be able to do for compliance to be possible at all.

What changes, briefly

  • A Data Protection Agency is created, with real enforcement and sanctioning powers. Until now there was no body with teeth.
  • People gain full data subject rights: access, rectification, erasure and objection, plus portability.
  • Security breaches must be reported within 72 hours of becoming aware of them.
  • Fines reach 20,000 UTM, and up to 4% of revenue for repeat offenders.
  • It applies to any organization processing personal data in Chile, regardless of size.

There is some breathing room: during the first year, between December 2026 and December 2027, small and medium businesses face warnings rather than fines. That is time to get organized, not time to ignore the law.

Where this stops being a legal matter

Three of those obligations cannot be solved with a document. They are solved with software.

1. Answering a data subject request on time

If someone asks for all their data, your system has to be able to gather it. If they ask you to delete it, it has to be able to do so without breaking your accounting or the records other laws require you to keep. That is a feature, and if the system does not have it, it has to be built.

The concrete question for your software vendor is: can I export and delete all of one person's data without opening the database by hand? If the answer is that the tech team does it case by case, you will not hold the deadline.

2. Detecting a breach in time to report within 72 hours

The clock starts when you become aware. Without an access log there is no way to know what leaked or whom to notify. A system with no audit trail turns a small breach into one you cannot scope.

3. Keeping the record of processing activities

You have to document what data you process, why, on what legal basis, how long you keep it and who you share it with. You do it once and then maintain it. What you cannot do is invent it the day the regulator arrives.

If you handle health data, the bar is higher

Health data is sensitive data and carries a stricter regime. Any occupational medical center, insurer or company storing exam results falls into the most demanding category of the law.

We write this separately because we know the case well: GesLaboral runs occupational medical centers in Chile, where every report, every exam panel and every health survey is sensitive data with a name and a national ID next to it.

Where to start this week

  1. Take inventory. Which systems hold personal data. Include the spreadsheets and the WhatsApp groups: they count too.
  2. Review who has access to what. If everyone in the company sees everything, that is the first fix.
  3. Ask every software vendor how they handle export, deletion and access logging. In writing.
  4. Decide who is accountable. The law requires a Data Protection Officer in organizations processing data significantly; even if that is not you, someone has to own it.

If step 3 makes it clear your system will not get there, there is still room to adapt it. In December there will not be.


At egobytes we build custom software for companies in Chile and Costa Rica. If you want to check whether your systems will make it to December, get in touch.

Sources: Law 21.719 — Chilean National Congress Library · Ministry of Science, Technology, Knowledge and Innovation

If you can imagine it, we can build it.

Tell us what you need. We'll get back with a clear proposal, no jargon.