{"id":12023,"date":"2026-06-29T08:06:25","date_gmt":"2026-06-29T07:06:25","guid":{"rendered":"https:\/\/lawwwing.com\/?p=12023"},"modified":"2026-06-29T09:05:36","modified_gmt":"2026-06-29T08:05:36","slug":"the-new-era-of-data-protection-in-chile-what-changes-with-law-21-719","status":"publish","type":"post","link":"https:\/\/lawwwing.com\/en\/the-new-era-of-data-protection-in-chile-what-changes-with-law-21-719\/","title":{"rendered":"The New Era Of Data Protection In Chile: What Changes With Law 21.719?"},"content":{"rendered":"\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>On December 1, 2026, Chile's new personal data protection legislation will enter into force. The main objective of this law is to regulate the conditions under which personal data is processed, ensuring that all processing activities respect individuals' rights and freedoms.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Who Is Subject to This Regulation?<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Compliance with the new law is required of any natural or legal person that processes personal data, as well as public bodies acting within the scope of their functions.<\/p>\n\n\n\n<p>Furthermore, Chilean law not only applies when the data controller or processor is established or incorporated in Chilean territory, but also in the following situations:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>When the representative, regardless of its place of establishment or incorporation, carries out personal data processing operations on behalf of a controller established or incorporated in Chile.<\/li>\n\n\n\n<li>When the responsible or processor is not established in Chile, but its personal data processing activities are intended to offer goods or services to data subjects located in Chile or to monitor the behavior of data subjects within Chilean territory.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">What Are the Main Obligations for Businesses and E-commerce Companies?<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Obtain Free, Informed, and Explicit Consent<\/strong><br>Consent becomes one of the primary legal bases for the processing of personal data. The new law establishes that consent must be freely given, informed, specific, and unambiguous, and must be expressed through a statement or a clear affirmative action by the data subject.<br><br>Implicit consent, pre-ticked boxes, or any mechanism that does not allow the demonstration of the user's genuine intention are not valid.<br><br>In practice, this means that websites must review their contact forms, user registration processes, purchasing procedures, and newsletter subscription forms to ensure that they clearly inform users about:<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">What personal data is being collected.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">The purposes for which the data will be used.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">How long the data will be retained.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">Whether the data will be disclosed or shared with third parties.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">How users can withdraw their consent.<br><br>In addition, the law recognizes individuals' right to withdraw their consent at any time and without having to justify their decision. Businesses must provide simple, free, and accessible mechanisms that allow consent to be withdrawn as easily as it was originally given.<br><\/li>\n<\/ul>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>Guarantee Data Subjects' Rights<\/strong><br>One of the most significant advances introduced by Law 21.719 is the strengthening of individuals' control over their personal data rights.<br><br>Accordingly, the law recognizes the rights of access, rectification, erasure, objection, portability, and blocking.<br><\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\"><strong>Right of Access<\/strong><br>Users may request information about whether a company is processing their personal data and obtain details regarding:<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--60);margin-left:var(--wp--preset--spacing--60)\">The personal data being held.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--60);margin-left:var(--wp--preset--spacing--60)\">The source of the data.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--60);margin-left:var(--wp--preset--spacing--60)\">The purposes for which it is being used.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--60);margin-left:var(--wp--preset--spacing--60)\">The retention period.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--60);margin-left:var(--wp--preset--spacing--60)\">Any third parties with whom the data has been shared.<br><br>This requires e-commerce businesses to implement internal procedures that allow them to locate and provide this information efficiently.<br><br><\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\"><strong>Right to Rectification<\/strong><br>Data subjects may request the correction of inaccurate, outdated, or incomplete data.<br><br>For example, a customer may require an e-commerce business to update an incorrect delivery address or amend outdated contact details.<br><br><\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\"><strong>Right to Erasure<\/strong><br>Individuals may request the deletion of their personal data when:<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--60);margin-left:var(--wp--preset--spacing--60)\">The data is no longer necessary for the purposes for which it was originally collected.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--60);margin-left:var(--wp--preset--spacing--60)\">Consent has been withdrawn.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--60);margin-left:var(--wp--preset--spacing--60)\">The data has been processed unlawfully.<br><br><\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\"><strong>Right to Object<\/strong><br>Individuals may object to certain processing activities, particularly where their data is used for direct marketing, personalized advertising, or commercial profiling purposes.<br><br><\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\"><strong>Right to Data Portability<\/strong><br>The law allows individuals to request a copy of their personal data in a structured electronic format, facilitating its transfer to another service provider whenever technically feasible.<br><br><\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\"><strong>Right to Block<\/strong><br>This right allows data subjects to request the temporary suspension of certain processing activities involving their personal data while a request for rectification, erasure, or objection is being resolved.<br><br>This right is particularly relevant in situations where there is a dispute regarding the accuracy of the data or the lawfulness of its processing, as it prevents the controller from continuing to use the information until the data subject's request has been resolved.<br><br>To facilitate the exercise of these rights, businesses must provide clear communication channels and respond to requests within <strong>30 calendar days<\/strong>, which may be extended by an additional 30 days. The period begins on the date the request is received.<br><br>However, there is a particular rule when a request for rectification, erasure, or objection is accompanied by a request for the temporary blocking of data or processing activities.<br><br>In such cases, the company has only <strong>two business days<\/strong> to decide on the temporary blocking request. Until a decision has been issued, the affected data may not continue to be processed.<br><br>If the controller fully or partially rejects the request, the data subject may file a complaint with the Personal Data Protection Agency.<br><\/li>\n<\/ul>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li><strong>Transparency and Information Obligations<\/strong><br>The principle of transparency requires the data controller to provide data subjects with all the information necessary for the exercise of their rights, ensuring that its data processing policies and practices remain permanently accessible in a precise, clear, and free-of-charge manner.<br><br>The data controller must make the following minimum information available to users on its website:<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">The personal data processing policy that it has adopted.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">The identification of the data controller and its data representative.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">Its address, email address, contact form, or identification of an equivalent technological means that is commonly used and easily accessible through which requests may be submitted.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">The categories, classes, or types of data processed, the recipients of the data, and the purposes of the processing activities.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">The security policy and measures adopted to protect personal data databases.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">Information regarding the right to exercise ARSOP rights (Access, Rectification, Erasure, Objection, and Portability).<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">The right to file a complaint with the Agency.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">Any transfer of personal data to a third country or international organization.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">The data retention period.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">The source from which the data originates.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">The existence of the right to withdraw consent at any time.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\">The existence of automated decision-making processes, including profiling.<br><br><\/li>\n<\/ul>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li><strong>Security Obligations<\/strong><br>The principle of security requires the data controller to ensure appropriate standards of protection against unauthorized processing, loss, disclosure, or accidental destruction of personal data.<br><br>This may be achieved through:<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\"><strong>Technical and organizational measures<\/strong>, such as data pseudonymization or encryption.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\"><strong>Ongoing assessments<\/strong>, through a process of regular verification and evaluation of the effectiveness of the security measures adopted.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--50);margin-left:var(--wp--preset--spacing--50)\"><strong>Data protection by design and by default<\/strong>, meaning that security measures must be implemented before processing begins and must ensure that, by default, only the personal data strictly necessary for the specific purpose is processed.<br><br>Where a security incident poses a risk to the rights of data subjects, the data controller must notify the Personal Data Protection Agency.<br><br>According to Law 21.719, no specific deadline is established for reporting security breaches. The law simply states that the controller must inform the Agency \u201cthrough the most expeditious means possible and without undue delay.\u201d<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">The Personal Data Protection Agency (APDP) and Its Powers<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Another major development introduced by Law 21.719 is the creation of the Personal Data Protection Agency (APDP). The APDP is an autonomous public law corporation that operates independently and whose mission is to ensure the effective protection of individuals' rights and personal data.<\/p>\n\n\n\n<p>Among its various powers, the following are particularly noteworthy:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Regulatory and Interpretative Powers<\/strong><\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">It has the authority to issue general and binding regulations governing personal data processing activities, following a public consultation process on its website.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">It may interpret legal provisions, regulations, and the instructions that it issues concerning data protection matters.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">It may propose new laws or regulations to the President of the Republic or the National Congress with the aim of improving the regulatory framework.<\/li>\n<\/ul>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>Monitoring and Supervisory Powers<\/strong><\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">It may require any data controller to provide documents, records, or other information necessary for its supervisory activities.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">It may determine whether infringements have occurred and summon any person with relevant knowledge of the facts to provide testimony.<br>It is responsible for certifying and supervising infringement prevention models and compliance programs that companies voluntarily adopt.<\/li>\n<\/ul>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li><strong>Enforcement and Redress Powers<\/strong><\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">It may impose fines on natural or legal persons that violate the provisions of the law.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">It resolves requests and complaints submitted by data subjects when their rights have been infringed.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">In cases involving very serious infringements, it may order the total or partial suspension of data processing activities for up to 30 days.<\/li>\n<\/ul>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li><strong>Registry Management and Transparency<\/strong><\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">It administers the National Register of Sanctions and Compliance, which records imposed sanctions and identifies organizations that have certified prevention models in place.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">It determines which countries provide an adequate level of data protection, thereby allowing international data transfers to those jurisdictions.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">What Must My Website Have to Comply with Law 21.719?<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>To ensure that your website complies with the requirements of Law 21.719, it is necessary to implement structural changes both in the user interface and in internal data management processes.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Consent Through an Affirmative Action<\/strong><br>Any form of implied consent must be eliminated. This means:<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">No pre-ticked boxes.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">Consent must be obtained through a clear affirmative action.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">Users must be provided with a simple, free, and permanently available mechanism to withdraw their consent with the same ease with which it was originally granted.<br><br><\/li>\n<\/ul>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>Privacy Policy Permanently Accessible, Clear, and Free of Charge<\/strong><br>Your website must provide a privacy policy that is permanently accessible, easy to understand, and available free of charge. It should include information regarding:<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">The identity of the data controller.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">Available communication channels.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">Data processing practices.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">Any automated decision-making activities.<br><br><\/li>\n<\/ul>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li><strong>Channels for Exercising ARSOPB Rights<\/strong><br>The website must provide users with clear and effective channels through which they can exercise their rights of Access, Rectification, Erasure, Objection, Portability, and Blocking (ARSOPB).<br><br><\/li>\n<\/ol>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li><strong>Data Protection by Design and by Default<\/strong><br>Business must:<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">Collect only the data that is strictly necessary for the specific purpose.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">Implement security measures such as pseudonymization or encryption of personal information.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">Ensure that privacy and security requirements are incorporated into systems and processes from the outset.<br><br><\/li>\n<\/ul>\n\n\n\n<ol start=\"5\" class=\"wp-block-list\">\n<li><strong>Cookie Banner Compliant with SERNAC Recommendations<\/strong><br>The website must implement a cookie banner that complies with the recommendations issued by SERNAC, based on an <strong>opt-in model<\/strong> and <strong>privacy by default<\/strong> principles.<br>We explain this in more detail below.<\/li>\n<\/ol>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Cookie Management<\/h3>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Law 21.719 requires consent to be freely given, informed, specific, and unambiguous. For this reason, the operator of your e-commerce website must clearly inform users about the purpose of each cookie, the retention period of the information collected, and whether the data will be shared with third parties. In addition, the law imposes an obligation to ensure that, by default, only the data strictly necessary for the specific activity is processed.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">What Should a Cookie Banner in Chile Look Like to Comply with Law 21.719?<\/h4>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>SERNAC conducted an experiment demonstrating that the design of cookie banners significantly affects users' privacy decisions. Based on the results, it issued the following recommendations:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Privacy by Default \u2013 Opt-In<\/strong><br>Non-essential cookies must require an active expression of consent. By default, all additional cookies should be disabled.<br><br><\/li>\n\n\n\n<li><strong>Clear Patterns (No Dark Patterns)<\/strong><br>The banner should make it easy for users to reject non-essential cookies and avoid manipulative design practices.<br><br><\/li>\n\n\n\n<li><strong>Simple and Clear Language<\/strong><br>Information regarding the use and purpose of cookies should be presented in language that any consumer can understand without technical knowledge.<br><br><\/li>\n\n\n\n<li><strong>Information About Cookie Types and Purposes<\/strong><br>Based on these recommendations, SERNAC suggests two cookie banner designs that have proven most effective in protecting users' privacy.<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">In the first interaction, users are presented with two buttons: \"<strong>Configure<\/strong>\" and \"<strong>Reject<\/strong>.\" If the user selects \"Configure,\" an opt-in configuration panel should open, displaying cookie categories with all non-essential cookies unchecked by default. If the user selects \"Reject,\" this option should be displayed as a prominent and highlighted button.<\/li>\n\n\n\n<li style=\"margin-right:var(--wp--preset--spacing--40);margin-left:var(--wp--preset--spacing--40)\">The cookie categories are displayed directly within a single interface, allowing users to select which cookies they wish to activate. All non-essential cookies must be disabled by default.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">What Are the Penalties for Non-Compliance with Law 21.719?<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>The law classifies infringements into three categories according to the nature of the violation and the level of risk posed to data subjects.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Minor Infringements<\/strong>. These include: partial non-compliance with transparency obligations, failure to respond to data subject requests within the applicable deadlines and failure to submit mandatory communications to the Agency.\n<ul class=\"wp-block-list\">\n<li>Penalty: Written warning or a fine of up to <strong>5,000 UTM<\/strong>.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Serious Infringements<\/strong>. These include: Processing personal data without consent or another valid legal basis, breaching the duty of confidentiality, implementing insufficient security measures, obstructing the exercise of data subject rights and unlawfully processing personal data belonging to minors.\n<ul class=\"wp-block-list\">\n<li>Penalty: A fine of up to <strong>10,000 UTM<\/strong>.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Very Serious Infringements. <\/strong>These include: fraudulent processing of personal data, deliberately providing false information, malicious failure to report security breaches, processing sensitive data in violation of the law and repeated non-compliance with Agency decisions.\n<ul class=\"wp-block-list\">\n<li>Penalty: A fine of up to <strong>20,000 UTM<\/strong>.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>The law also recognizes several <strong>mitigating factors<\/strong>, including: self-reporting of the infringement, cooperation during investigations, voluntar<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On December 1, 2026, Chile's new personal data protection legislation will enter into force. The main objective of this law is to regulate the conditions under which personal data is processed, ensuring that all processing activities respect individuals' rights and freedoms. Who Is Subject to This Regulation? Compliance with the new law is required of [&hellip;]<\/p>\n","protected":false},"author":22,"featured_media":12081,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[203,216,617,213,215,214,344,210,345,481,618,326,446,688,348,243,228,224,201,211,619,338,474,246,328,502,206,508],"tags":[768,769,771,770],"class_list":["post-12023","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance-en","category-consent","category-consumers","category-cookies-en","category-cookies-banner","category-cookies-policy-en","category-cookies-web-en","category-data-protection","category-datos-personales-en","category-ecommerce-2","category-law","category-legislacion-web-en","category-legislation","category-ley-en","category-leyes-en","category-online-privacy-en","category-politica-de-privacidad-pagina-web-en","category-poner-cookies-en-mi-web-en","category-privacy-en","category-privacy-policy-en","category-regulations","category-sancion-en","category-security","category-seguridad-en","category-terms-and-conditions-en","category-web","category-web-legal-texts","category-website","tag-apdp-en","tag-arsopb-en","tag-chile-en","tag-ley-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12023","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/comments?post=12023"}],"version-history":[{"count":3,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12023\/revisions"}],"predecessor-version":[{"id":12071,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12023\/revisions\/12071"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media\/12081"}],"wp:attachment":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media?parent=12023"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/categories?post=12023"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/tags?post=12023"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}