{
  "node_id": "cl-dp-law-2022",
  "title": "Chile Data Protection Law 21.719 - Ley Marco de Datos Personales and CPLT Enforcement",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "Chile's Ley Marco de Datos Personales (Framework Law on Personal Data) - Law No. 21.719, published in the Diario Oficial de la República de Chile on 13 December 2024 and entering into force on 13 December 2026 (a two-year transition period) - is Chile's comprehensive modern data protection law, substantially replacing and modernising the prior Ley de Protección de la Vida Privada (Law No. 19.628 of 1999), which was one of Latin America's earliest data protection statutes. Law No. 21.719 represents a landmark reform of Chilean data protection, designed to bring Chile into alignment with international standards including the EU GDPR framework. Chile previously obtained EU GDPR adequacy status through European Commission Decision 2013/65/EU of 19 December 2012, which recognised Chile's 1999 framework as adequate - the new law is expected to strengthen and maintain this adequacy position. The enforcement authority under the new framework is the Consejo para la Transparencia (CPLT - Council for Transparency), which had been the transparency authority and will assume expanded data protection enforcement powers, and a newly established Agencia de Protección de Datos Personales (APDP - Personal Data Protection Agency) to be created under the new law. Key features of Law No. 21.719: (1) Controller (Responsable) and Processor (Mandatario) terminology; (2) Seven lawful bases for processing aligned with GDPR: consent, contract, legal obligation, vital interests, legitimate interests, public interest, and the controller's legitimate interests; (3) Sensitive personal data - broadly defined including: ideological, political, religious, or philosophical beliefs; trade union membership; physical or psychological health; ethnicity or race; life and sexual practices; genetic data; biometric data; criminal records; financial or economic data; (4) Data subject rights aligned with GDPR: right to information, access, rectification, erasure, portability, objection, and not to be subject to automated decision-making; (5) Data Protection Impact Assessment (DPIA) - required for high-risk processing; (6) Data Protection Officer (DPO) - required for large-scale or high-risk processing; (7) Mandatory breach notification to the APDP within 72 hours; (8) Cross-border data transfer restrictions aligned with GDPR adequacy framework; (9) Administrative fines up to 5% of annual income or UF 5,000 (approximately USD 200,000) whichever is greater. Note: as of April 2026, Law No. 21.719 is in its two-year transition period - full compliance obligations will take effect on 13 December 2026. Organisations should begin implementation planning immediately. The prior law (Law No. 19.628 of 1999) remains in force during the transition period. Chile is an OECD member and one of Latin America's most economically advanced nations, making data protection compliance particularly important for Chilean and multinational organisations.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-27001-2022",
    "iso-27701-privacy-information-management"
  ],
  "primary_citations_count": 6
}