CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
4. Cyber-Resilience 4.1 Cyber-Resilience Legislation
• Mandatory certification – operators of vital impor - tance must obtain cybersecurity certifications as determined by law and the regulations of the ANCI. • Authorised certification centres – valid certifica - tions can only be issued by bodies that are reg - istered and authorised by the ANCI. To be part of this register, entities must prove compliance with the requirements established in the regulations and, to remain so, comply with the aforemen - tioned requirements. The Regulation on accredited Certification Centres was published in the Official Gazette during the first quarter of 2025. • International certifications – the ANCI may approve international or foreign technical certifications on cybersecurity, by means of a reasoned resolution of its director. • Certification of operational continuity and cyber - security plans – operators of vital importance must prepare and implement operational continuity and cybersecurity plans. These plans must be certified and must be subject to periodic reviews by the obligated parties, with a minimum frequency of two years. The Agency also has the power to request certifications in shorter terms if there are serious supervening reasons. • Cybersecurity standards for the state – the ANCI will be in charge of certifying compliance with cybersecurity standards by the bodies of the State Administration. It is expected that there will be greater clarity on the specific certifications that operators of vital impor - tance must have during the 1st half of 2026, after the ANCI issues the respective secondary regulations. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection In matters of personal data protection, Law No 19,628 on the Protection of Private Life from 1999 is currently in force. This law does not specifically establish cyber - security obligations. At most, it contains a provision stating that the party responsible for records or data - bases where personal data is stored after collection must take due care, making them liable for any dam - ages.
The Cybersecurity Framework Law refers to the con - cept of resilience, defining it as the ability of networks and computer systems to maintain their availability and operation, as well as to recover quickly from cybersecurity incidents. For its part, the National Cybersecurity Policy 2023– 2028 establishes as one of its five fundamental objec - tives the development of a “resilient infrastructure” in the country. This implies that the country must have a robust information infrastructure prepared to withstand and recover from cybersecurity incidents and socio-environmental disasters. To advance this objective, the need to strengthen essential services and improve the response capacity to incidents, both in the public and private sectors, is established. However, neither the National Cybersecurity Policy nor the Cybersecurity Framework Law specifically establish detailed obligations related to cyber resil - ience. It is expected that in the future the National Cybersecurity Agency will issue general and specific instructions to promote cyber resilience in the country, especially taking into account the advancement of this type of regulation in the world and the fact that the Cybersecurity Framework Law is especially inspired by the Network and Information Security Directives 1 and 2 of the European Union. 4.2 Key Obligations Under Legislation For more information, see 4.1. Cyber-Resilience Leg- islation . 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation The Cybersecurity Framework Law establishes a cybersecurity standards certification scheme, mainly focused on operators of vital importance, although it also affects state bodies.
69 CHAMBERS.COM
Powered by FlippingBook