CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
Currently, there is not a single supervisory authority for personal data protection. The Undersecretariat of Telecommunications, the Financial Market Commis - sion, and the Council for Transparency in the public sector have issued regulations or recommendations that, in some sense, also consider the adoption of cybersecurity measures. One of the most relevant of these authorities is the National Consumer Service (SERNAC), which, thanks to the Pro-Consumer Law, is – temporarily – the super - visory authority for personal data protection within consumer relations. This is until the new Personal Data Protection Law and the new Data Protection Agency come into effect in December 2026. SERNAC has issued interpretative circulars on the law, which, while not binding for providers, are binding for SERNAC officials in charge of oversight. This could lead to infringement complaints before the courts (SERNAC does not have direct sanctioning powers). Among the most important circulars are the following. Interpretative circular on good practices in electronic commerce – security in electronic contracting: SER - NAC believes that providers of services and products through electronic means must inform and adopt nec - essary technical measures to guarantee consumer security, integrity and confidentiality of transactions, payment methods and personal data. This includes indicating the levels of protection applied to each. Additionally, SERNAC considers that companies must take corresponding safeguards in cases of electronic contracting by minors, vulnerable consumers, or those who lack the capacity to understand the information provided on the website. Interpretative circular on criteria of equity in the stipu - lations contained in adhesion contracts referring to the collection and processing of personal data of con - sumers – abusive clauses that make the consumer responsible for the effects of possible deficiencies, omissions, or errors, such as limiting the liability of the supplier in case of unauthorised access, losses, alterations, or leaks of the consumer’s personal data: SERNAC maintains that the duty of professionalism falling on suppliers, considering the obligation of security in data processing, entails applying compre -
hensive security measures. This includes technical, organisational and human capital formation to safe - guard the confidentiality, integrity, and availability of consumers’ personal data to prevent alteration, loss,
transmission and unauthorised access. New Personal Data Protection Law
After extensive legislative discussion that took over seven years, Law No 21,719 was enacted, reforming Law No 19,628. This new law will come into force in December 2026, along with the creation of the National Personal Data Protection Agency. From that moment on, SERNAC will cease to be the controlling authority in this matter. The new law establishes a Security Principle, accord - ing to which the processing of personal data must guarantee adequate security standards, protecting it against unauthorised or illicit processing, loss, leak - age, accidental damage or destruction. In addition, security measures must be appropriate and consist - ent with the type of processing and the nature of the data. Furthermore, the new law recognises the principle of data protection by design and by default, according to which the data controller must implement technical and organisational measures from the design of the processing of personal data and during its execution, taking into account the state of the art, the costs of implementation, the nature of the data, the context and purposes of the processing, as well as the associ - ated risks. Likewise, by default, only the specific per - sonal data strictly necessary for the activity should be processed. The new law also includes various obligations related to information security and cybersecurity. Thus, the data controller must adopt the necessary measures to guarantee compliance with the security principle, ensuring the confidentiality, integrity, availability and resilience of data processing systems. They must also prevent the alteration, destruction, loss, processing or unauthorised access to data. Security measures may include: • pseudonymisation and encryption of personal data;
70 CHAMBERS.COM
Powered by FlippingBook