Cybersecurity 2026

CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados

Public-Private Co-Operation Framework Co-operation is a guiding principle of the Framework Law, acknowledging that cybersecurity depends on the interdependency of systems. The state has cre - ated the Multi-Sectoral Council on Cybersecurity as a consultative body where representatives from industry, academia and civil society advise the ANCI on threat mitigation. Additionally, the Inter-Ministeri - al Committee on Cybersecurity co-ordinates public policy implementation across different ministries to ensure a unified national strategy In the State Digital Transformation Law No 21,180 The “Technical Standard for Information Security and Cybersecurity” of the State Digital Transformation Law establishes guidelines and responsibilities for Chilean government bodies regarding information security and cybersecurity. Responsibilities are structured around key functions: • identification – bodies must identify and manage security risks associated with their processes, per - sonnel, and electronic platforms; • protection – implement security measures to ensure proper, timely and secure service delivery; • detection – develop processes for timely detection of security incidents; • response – implement technical and organisational measures in response to security incidents; and • recovery – maintain recovery plans and restore any capacity or service affected by a security incident. Additionally, each body must: • conduct an initial cybersecurity assessment; • develop an Information Security and Cybersecurity Policy; • appoint individuals responsible for information security and information assets; and • participate in the gradual implementation of this technical standard depending on the type of entity and the gradual implementation schedule, which will extend until 2028.

• Secondary reports – must include an assessment of severity and impact, evidence of potential crimi - nal activity and specific indicators of compromise. • Final report – must detail the root causes, the specific vulnerabilities exploited and the technical controls that failed or were absent. For OIVs, this report must also include a definitive estimate of the time taken to restore services. Multi-Agency and Parallel Reporting Obligations Chilean law acknowledges that many entities, such as those in the financial and telecommunications sectors, are subject to parallel reporting obligations. Article 9 of the Framework Law mandates that the ANCI coor - dinate with sectoral regulators to implement a “single window” ( ventanilla única ) system. Although the tran - sition to this unified platform is currently underway, its full implementation is still pending for most sectors. Until the single window is fully operational, entities must navigate sectoral rules, such as those from the CMF or the Subtel). Under Article 37, sectoral regu - lations prevail if they provide equivalent or stricter protections, such as the 30-minute reporting window required by the CMF for certain banking incidents. 2.4 State Responsibilities and Obligations In the Cybersecurity Framework Law The heads of service of the state administration agencies shall require information technology service providers to share information on vulnerabilities and incidents that may affect the computer networks and systems of state agencies, and provided that doing so is intended to prevent, detect, respond to, recover from or reduce incidents; or strengthen the level of cybersecurity, while ensuring that the potentially sen - sitive nature of the information shared is respected. In order to comply with the above, the contracts for the provision of services may not contain any clause that could restrict or hinder in any way the commu - nication of information about threats by the service provider, as long as this does not compromise the security and protection of data, including confidential - ity and protection of intellectual property.

65 CHAMBERS.COM

Powered by