CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
Role of Sectoral Regulators While the ANCI is the primary authority, other sectoral regulators play a crucial role in enforcing cybersecu - rity within their specific domains. The CMF is particu - larly active, requiring banks and financial institutions to implement robust risk management systems and report incidents within very short time frames. Simi - larly, the Subtel issues technical standards for the design and operation of secure telecommunications networks. 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation The primary regulatory framework for cybersecurity in Chile is established by the Cybersecurity Frame - work Law No 21.663, published on 8 April 2024. This legislation created the ANCI as the lead technical and specialised regulator responsible for supervising both public and private entities. The Law structures its scope of application around two main categories of regulated subjects: providers of “essential services” and OIV. Essential Services and Regulatory Uncertainties Article 4 of the Cybersecurity Framework Law lists the sectors considered essential to the maintenance of vital societal functions, health, safety and economic well-being. These include electricity (generation, transmission, or distribution), fuels, drinking water, telecommunications, banking and financial services, transport, social security, postal services, institu - tional health provision and pharmaceutical research. State administration bodies, including ministries and municipalities, are also classified as essential service providers by default. A significant uncertainty within this framework is that the Law does not provide exact definitions for sev - eral key categories, such as “digital services”, “digi - tal infrastructure” or “information technology services managed by third parties”. While Article 4 identifies these broad sectors as essential, the lack of specific statutory definitions leaves the exact scope to be determined by administrative resolutions.
Designation Criteria for OIV Not all providers of essential services are subject to the highest level of regulation; only those designated as OIV must meet the most stringent duties. Under Article 5 of the Law, ANCI qualifies an essential service provider as an OIV if the service depends significantly on computer networks and if its disruption would have a “significant impact” on public safety, the continuous provision of essential services or the functions of the state. Private institutions that do not provide essential services may also be qualified as OIVs if they hold a critical role in the supply of goods or have a high degree of risk exposure. The specific procedure and risk criteria for this des - ignation are detailed in Decree No 285, published in March 2025. Under Article 4 of this Decree, the Agen - cy determines a “significant impact” by applying five specific criteria: the number of potentially affected persons and territorial coverage; the redundancy of the service; the existence of monoprovision; the inter - dependency between services; and the strategic rel - evance of the institution. This process requires ANCI to request founded reports from sectoral authorities, such as the CMF, before making a final determination. Implementation Timeline and the Digital Sector Analysis The qualification process followed a staggered cal - endar established by Resolution No 24 in May 2025. The first stage, which concluded in December 2025, focused on priority sectors including banking, energy, telecommunications and the digital sector. The sec - ond stage, scheduled to begin in November 2025, covers water, fuels, transport, social security and pharmaceuticals. In Resolution No 87, published in December 2025, ANCI approved the final list of OIVs for the first stage and clarified how it analysed the digital sector. Given the lack of a sectoral regulator for digital services, ANCI identified potential OIVs using Internal Rev - enue Service (SII) activity codes related to software programming, data processing and IT consultancy. For the purpose of this qualification process, the Agency focused on entities with an annual turnover of CLF25,000 or higher (approximately USD1 million or above) or those acting as suppliers to the state.
62 CHAMBERS.COM
Powered by FlippingBook