BusinessSeptember 17, 2026

Ley 21.719: what to do before December (and why the postponement won't save you)

The government submitted a bill to postpone the law by a year, but it hasn't been voted on. Until it is, the date in force is still December 1, 2026. Here's what changes and what to do now.

By id3a Team
Ley 21.719: what to do before December (and why the postponement won't save you)

Search "Ley 21.719" today and you'll find two contradictory headlines: some say it takes effect on December 1, 2026, others that it was postponed to 2027. Both are citing real things, and the difference matters.

Where the law actually stands

Ley 21.719 was published in the Diario Oficial on December 13, 2024, with a 24-month entry into force: December 1, 2026.

On September 1, 2026, the government submitted a bill to the Senate that proposes pushing that date to December 1, 2027. The stated reason is the complexity of standing up the Agencia de Protección de Datos Personales and getting it ready to actually exercise its powers.

That bill is sitting in the Constitución and Hacienda committees. It has not been voted on.

The date in force hasn't changed

A bill doesn't change anything until Congress passes it and it's published in the Diario Oficial. Until that happens, Ley 21.719 takes effect on December 1, 2026 — a little over two months from now.

That's the short answer to the practical question: planning as if the postponement already existed means betting that Congress will vote in time on something that's been sitting unvoted for two weeks.

What else the bill brings, if it passes

It isn't just a date change. Two points worth knowing:

The Agency's Council would go from three to five members, with six-year terms, no re-election, and partial renewal every two years. That's an institutional design change, not an administrative detail: it aims to have the Agency arrive better equipped.

The transitional regime would be extended to everyone. Today, the initial period during which the Agency can only issue a written warning applies specifically to smaller companies. The bill would remove that reference, so that during the first twelve months in force, the warning-only period would apply to everyone bound by the law, not just SMEs.

That second point is the one worth reading carefully, because it changes the risk calculation for a mid-size or large company.

What changes relative to the current law

Ley 19.628 has been in force since 1999, and its problem was never the text — it was that there was no one to enforce it. Ley 21.719 creates that authority and gives it teeth.

AspectLey 19.628 (today)Ley 21.719
Enforcement authorityNoneAgencia de Protección de Datos Personales
SanctionsThrough the courts, in practice nonexistentAdministrative fines, on the Agency's own initiative
Maximum fine5,000 / 10,000 / 20,000 UTM depending on severity
Repeat offensesUp to 2% or 4% of annual sales revenue in Chile
Public registryNoNational Sanctions Registry, for up to 5 years
Breach notificationNot requiredMandatory, to the Agency and to those affected

The real jump isn't in the maximum fine — it's that there's now a body that can open an investigation without anyone filing a complaint, and the sanction gets published.

The four things that take time, and why to do them now

Some obligations get resolved in an afternoon. These aren't those.

1. Knowing what data you have and where it lives

The record of processing activities isn't paperwork — it's an inventory. What personal data you have, what system it lives in — CRM, ERP, spreadsheets, mailboxes, that Excel file someone's been maintaining since 2019 — for what purpose you process it, on what legal basis, and for how long you keep it.

In our experience this is the part that takes the longest, and not because of the documentation: it takes long because processing activities show up that nobody remembered. A contact list exported three years ago. A backup sitting in a personal account. Forms that are still collecting data nobody uses anymore.

2. Deciding who's accountable

The law requires organizations that carry out high-risk processing or handle large volumes to appoint a data protection officer. If you don't fall into those categories, you can operate with a trained internal person in charge — but someone needs to have that role assigned in writing, because once a data subject's request comes in, there will be a clock running.

3. Being able to respond to a rights request

Access, rectification, erasure, objection, portability and blocking. When someone writes asking for a copy of their data, you'll need to be able to pull it together from every system it lives in, verify that the requester is who they say they are, and respond within the legal deadline.

If point 1 isn't done, point 3 is impossible to meet on time.

4. Publishing the policy, with a version and a date

The duty to inform requires keeping the processing policy permanently available on the site, identifying who's responsible, and stating its version and its date. That's not a stylistic detail — the law specifically requires those to appear.

What this looks like in practice

Our own privacy policy is written against Ley 21.719's duties rather than Ley 19.628's, precisely so we don't have to rewrite it in December. It shows a version and a date, names every processor that receives data, and states the two things the site stores in your browser and why.

What the postponement would actually change

If the bill passes, the extra year is real and useful. But it changes the deadline, not the work: the data inventory still has to get done either way, and doing it with time to spare is cheaper than doing it against a deadline.

The practical difference is elsewhere. Today, with the law in force in December, a mid-size company has to prioritize whatever reduces the risk of a sanction. With an extra year, it can do things in the right order: first understand what it processes, then decide what to stop processing. The fastest way to comply is almost always to delete data you should never have been keeping in the first place.

What we'd do in the next two weeks

Without waiting for the vote:

  • Build the processing inventory, even if it's just a spreadsheet. It's the input for everything else.
  • Review which providers receive personal data and from which country they process it. If they're outside Chile, that has to be declared.
  • Name the accountable person in writing, even if it isn't a formal position.
  • Publish or update the privacy policy, with a version and a date.
  • Put a review on the calendar for whenever the Senate votes, because that's where the date actually gets decided, not before.

This article describes the state of the bill as of September 17, 2026, and isn't legal advice. Ley 21.719 has areas — sensitive data processing, automated decisions, international transfers — where a specialist lawyer is worth having. What we can do is the technical part: finding where your data lives, who receives it, and what can stop being kept.

Let's talk about your situation

Enjoyed this article?

Find out how we can help you bring these solutions into your business.