Cybersecurity 2026

CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados

tial services span various sectors such as electricity, telecommunications, banking, healthcare, digital ser - vices and digital infrastructure. The law applies even to private institutions that do not provide essential ser - vices but have acquired a critical role in the supply of goods or have a high degree of risk exposure. Within these sectors, the ANCI has the authority to qualify specific providers as Operators of Vital Impor - tance (OIV). This qualification is based on the depend - ence of the service on computer systems and the significant impact that any disruption would have on public order or safety. OIVs are subject to the strictest obligations, including the implementation of continu - ous information security management systems. They must also appoint a cybersecurity delegate to act as a formal counterpart to the ANCI. Complementary Cybersecurity Legislation Furthermore, the Computer Crimes Law No 21,459 seeks to adapt Chilean legislation to international standards like the Budapest Convention. It typifies specific offences such as attacks on the integrity of systems, unlawful interception and computer fraud. The law includes exemptions for responsible ethical hackers who register with the ANCI and report vulner - abilities promptly. The penalties for these crimes are increased if they result in the interruption of public utility services. In the field of privacy, Law No 21,719 was recently enacted to reform the outdated data protection regime and will come into full effect in December 2026. It introduces a security principle requiring data control - lers to guarantee adequate standards against unau - thorised processing or loss. This legislation also cre - ates the National Personal Data Protection Agency, which will act as the specialised supervisory body. The new framework establishes clear duties for reporting security breaches that put the rights of data subjects at risk. Sector-Specific Regulations Specific sectoral regulations also play a crucial role, such as the Ministry of Health’s instructions for the digital transformation of clinical processes. Financial entities must comply with the Fintech Law No 21,521 and the detailed general norms issued by the Finan -

cial Market Commission (CMF). These rules mandate robust risk management and incident reporting to ensure the operational resilience of the financial sys - tem. Similarly, the electricity sector follows specific standards like NERC-CIP to protect critical opera - tional assets. 1.2 Cybersecurity Laws The Cybersecurity Framework Law No 21,663 The Cybersecurity Framework Law No 21,663, which entered into force in 2024, serves as the primary stat - ute governing digital security in Chile. It established the ANCI as a specialised, decentralised technical body responsible for advising the President and co- ordinating cybersecurity actions across the State and private sectors. The law also created the CSIRT Nacional to handle significant incidents. The subject-matter scope of this law includes the establishment of minimum-security requirements for the prevention, containment and response to inci - dents. It applies to all state administration bodies, including ministries, regional governments, munici - palities and the armed forces. In the private sector, it targets providers of “essential services” and those qualified as OIV. Regarding territorial reach, the law focuses on enti - ties operating within Chile or providing services that impact national security and public order. It does not contain express rules for extraterritorial applica - tion beyond the domestic jurisdiction. Guidance and codes issued by the ANCI, such as mandatory proto - cols and technical standards, play a binding role for all regulated entities. Personal Data Protection Law The Personal Data Protection Law No 21,719, enacted in late 2024, significantly reformed the existing 1999 regime and is scheduled to enter into full force in December 2026. This statute introduces the “Secu - rity Principle”, which mandates that data controllers must guarantee adequate standards to protect data against unauthorised processing, loss or destruction. It also recognises the principles of data protection by design and by default.

59 CHAMBERS.COM

Powered by