Diario Oficial de la República de Chile · 09 Sep 2026 · 2 vistas
Chile approves regulation for data breach prevention models
Por FactBox Admin

The Ministry of Finance approved the regulation governing the requirements, modalities, and procedures for the implementation, certification, registration, and supervision of the infringement prevention models referred to in Article 49, which Law No. 21,719 incorporates into Law No. 19,628 on the protection of private life. The regulation, issued via Decree No. 662 on June 13, 2025, was published in the Official Gazette of the Republic of Chile No. 44,546 on Wednesday, September 9, 2026, in the General Regulations section, page 1 of 9, with reference CVE 2865940.
The regulation develops the “infringement prevention model” system, a compliance program that any data controller—whether a natural or legal person, public or private—may voluntarily adopt to safeguard compliance with the law and the rights of personal data subjects. Law No. 21,719, published on December 13, 2024, comes into effect on December 1, 2026, and creates the Personal Data Protection Agency, which is responsible for certifying, registering, and supervising these models.
Content of the compliance program
The regulation establishes the minimum elements that every compliance program must contain, including:
- The identification of the data controller and their legal representative.
- The designation of a personal data protection officer, which is mandatory within the framework of the adoption and certification of the model.
- The characterization of the personal data processed, the databases managed, and the processing operations performed.
- The identification of processing activities with a higher risk of infringement, incorporated into a risk matrix.
- Specific protocols, rules, and procedures to prevent the commission of infringements.
- Internal reporting and complaint mechanisms to the officer, with the confidentiality of the whistleblower’s identity.
- Internal administrative sanctions applicable for the violation of data protection rules.
The data protection officer
The regulation details the role of the data protection officer, appointed by the highest management or administrative authority of the controller. The officer must have autonomy from the administration and report directly to the person who appointed them. In micro, small, and medium-sized enterprises, the owner or their highest authorities may personally assume these tasks, and entities within the same business group may appoint a single officer under common standards.
Among its functions, it stands out to advise the controller, supervise compliance with the law, train personnel, develop an annual work plan, and act as the point of contact with the Personal Data Protection Agency. The delegate is obliged to maintain strict secrecy and confidentiality regarding the data they become aware of in the exercise of their duties.
Certification, registration, and supervision
The Personal Data Protection Agency will certify models that meet the legal and regulatory requirements and will incorporate them into the National Register of Sanctions and Compliance, which is open to the public. The certificates will be valid for three years and may be renewed at the request of the interested party. Certification may be revoked ex officio or at the request of a party if the controller infringes the requirements or is sanctioned for committing violations, and may be requested again once the causes have been rectified.
The adoption of a certified model may act as a mitigating factor for the sanctions imposed by the Agency in the exercise of its oversight powers. The decree was signed by the President of the Republic, Gabriel Boric Font, the Minister of Finance, Mario Marcel Cullell, the Minister Secretary General of the Presidency, Macarena Lobos Palacios, and the Minister of Economy, Development, and Tourism, Nicolás Grau Veloso.
With the entry into force of Law No. 21,719 on December 1, 2026, this regulation provides companies and public bodies with the concrete tools to structure their compliance programs regarding personal data, within a context of high protection standards and a supervisory authority with new certification and sanctioning powers.
Source: Official Gazette of the Republic of Chile, No. 44,546, September 9, 2026, General Regulations section, page 1 of 9 (official reference: CVE 2865940).