Cybersecurity 2026

CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados

Magliona Abogados Santiago de Chile Avda Andrés Bello 2687 Piso 24 Las Condes Santiago de Chile Santiago Chile Tel: +56 2 3210 0030 Fax: +56 2 377 9451 Email: contacto@magliona.cl Web: www.magliona.cl

1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy National Cybersecurity Strategy and Regulatory Landscape Chile has established two primary sources of regula - tion and public policy that steer the current national cybersecurity strategy. The first is the National Cyber - security Policy 2023–2028, which aims to develop a robust and resilient information infrastructure capable of resisting and recovering from incidents. This policy promotes the protection of individual rights online and fosters a culture where education and best practices are central to digital engagement. It also emphasises national and international co-ordination and the pro - motion of the local cybersecurity industry and scien - tific research. The strategy incorporates several transversal dimen - sions to ensure that its objectives are reached with a focus on protecting families and individuals. These include gender equality, the protection of children and adolescents, safeguards for the elderly, and the pro - tection of the environment. By publishing a separate action plan, the government can periodically review progress and adjust measures based on the evolving threat landscape. This approach allows the authorities to emend actions that have been implemented defi - ciently while maintaining long-term strategic goals.

The Cybersecurity Framework Law (Law No 21,663) The second pillar is the Cybersecurity Framework Law No 21,663, which entered into force in January 2025, along with the creation of the National Cybersecurity Agency (ANCI). This statute established a new institu - tional framework and general regulations to structure and co-ordinate cybersecurity actions among state agencies and between them and private entities. It mandates minimum requirements for the preven - tion, containment and resolution of incidents, signifi - cantly modernising the national approach. The law also creates the National Computer Security Incident Response Team ( CSIRT Nacional ) within the ANCI. The legislature frames the purpose of these regula - tions as a fundamental duty of the state to safeguard security in cyberspace. Priorities are set using a risk management perspective, where measures must be necessary and proportional to the level of exposure and potential social impact. This framing ensures that computer systems and technologies are managed with security and privacy by design as core princi - ples. It also grants special protection to those groups that are often the target of malicious cyber activities. Legislative Scope and Sectoral Application The scope of the Cybersecurity Framework Law extends to state agencies, including ministries, regional governments and the armed forces. It also covers public enterprises and private institutions that provide services qualified as essential. These essen -

58 CHAMBERS.COM

Powered by