Cybersecurity 2026

CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados

cal authority, but it must request reports from sectoral regulators before issuing rules that affect their spe - cific jurisdictions. This process ensures that secto - ral expertise is respected while maintaining a unified national strategy. A crucial rule of prevalence exists: if a sectoral author - ity issues cybersecurity instructions with effects at least equivalent to those of the ANCI, the sectoral rules shall prevail. This prevents duplication of obli - gations and allows industries with high technical requirements, such as energy or banking, to follow specialised standards. However, the ANCI and the sectoral body must jointly issue a rule to evaluate this equivalence. 1.3 Cybersecurity Regulators ANCI The principal authority responsible for enforcing cyber - security regulations in Chile is the ANCI. Established by the Cybersecurity Framework Law No 21,663, the ANCI is a functionally decentralised public ser - vice with its own legal personality and assets. Its pri - mary mandate involves advising the President of the Republic on cybersecurity matters, protecting national interests in cyberspace, and co-ordinating both public and private institutions to ensure computer security. The Agency officially commenced its activities on 1 January 2025, marking a significant milestone in the country’s digital governance. The ANCI possesses broad regulatory and adminis - trative powers to structure the national cybersecurity landscape. It is authorised to issue mandatory proto - cols, technical standards, and instructions that apply to state agencies and private entities providing essen - tial services. Furthermore, the Agency has the power to qualify specific service providers as OIV, subject - ing them to the most rigorous compliance require - ments. Through its National Director, the ANCI can also homologate international technical certifications to align local practices with global standards. Supervisory and Enforcement Powers The Agency has the authority to oversee compliance with the law through regular inspections, security analyses, and the instruction of audits conducted either by its own staff or by authorised third parties. If

a cybersecurity incident occurs, the ANCI may require the affected entity to provide truthful and timely infor - mation to potential victims. These powers ensure that institutions maintain the necessary standards of pre - vention, containment and response to digital threats. The ANCI wields significant sanctioning power to penalise non-compliance with its regulations or gen - eral instructions. Infringements are classified as minor, serious or very serious, with fines varying based on the status of the offender and the nature of the breach. For instance, very serious infractions by an Operator of Vital Importance can result in fines of up to 40,000 Monthly Tax Units (UTM) or approximately USD3 million. This robust penalty structure is intended to incentivise a high level of institutional maturity and accountability across all regulated sectors. Investigative Tools and System Access The legislature has provided the ANCI with several investigative tools to perform its supervisory duties effectively. The Agency can require state and private institutions to provide access to any information strict - ly necessary to prevent or manage incidents, including activity logs of networks and computer systems. Addi - tionally, the ANCI has the authority to summon part - ners, directors and employees of regulated entities to testify regarding facts relevant to its investigations. In cases of incidents with significant impact where access to systems is deemed indispensable, the ANCI may require direct access to the affected infrastruc - ture. If an institution denies this access, the Agency is empowered to seek a prior judicial authorisation from the Court of Appeal of Santiago. National and Sectoral Incident Response Teams Incident response is structured through a network of specialised teams co-ordinated by the ANCI. The CSIRT Nacional operates within the Agency as the central node for responding to significant cyberat - tacks. Its functions include supervising incidents at a national scale, performing dynamic risk analyses, and providing technical advice to other state CSIRTs. The CSIRT Nacional also serves as the international point of contact for exchanging information with for - eign counterparts.

61 CHAMBERS.COM

Powered by