Information Technology 2026

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

7.2 Data Transfer Restrictions Chile does not have a general data localisation rule or a blanket restriction on transferring all categories of data abroad. The main restrictions apply to personal data, with additional controls in regulated sectors such as financial services, telecoms, health, public- sector technology, cybersecurity-sensitive services and outsourced IT operations. Under the Data Protection Law, international transfers of personal data are subject to specific requirements. The new regime moves Chile closer to internation - al standards by requiring organisations to consider whether the destination offers adequate protection or whether the transfer is supported by an appropriate legal mechanism. Transfers may be legitimised through adequacy deci - sions or recognised adequate jurisdictions, contrac - tual safeguards, binding corporate rules, data subject consent, contract necessity, legal claims, public inter - est grounds or other statutory derogations. In practice, companies use data processing agreements, transfer clauses, vendor due diligence, transfer risk assess - ments, security measures and subprocessor controls. For non-personal data, Chile does not generally impose the same transfer restrictions. However, con - tractual, confidentiality, cybersecurity, procurement, sector-specific or regulatory obligations may restrict storage, access, processing or transfer abroad, espe - cially for trade secrets, source code, financial informa - tion, health information, telecoms data, government records or security-sensitive operational data. For cloud and outsourcing, the practical approach is to map jurisdictions, processors and subprocessors; assess transfer risks; implement contractual safe - guards; define security and encryption requirements; regulate incident notification; ensure audit and regu - latory access; and agree on return, deletion and exit assistance. 7.3 Information Security and Cybersecurity Standards Chile does not impose one single mandatory secu - rity standard, such as ISO 27001, NIS2 or CSA CCM, across all industries. The approach is generally risk-

based and sector-specific. Security obligations arise mainly from the Data Protection Law, the Cybersecuri - ty Framework Law, CMF financial regulation, telecoms regulation, public-sector digital government rules and market practice. The Data Protection Law requires controllers and processors to implement appropriate technical and organisational measures to protect personal data. It does not mandate one certification, but measures should be proportionate to the data, processing risks, state of the art and potential impact on data subjects. The Cybersecurity Framework Law focuses on gov - ernance, risk management, prevention, detection, response, incident reporting, continuity and compli - ance with technical rules and instructions issued by cybersecurity authorities, particularly for State bodies, essential services and operators of vital importance. Financial-sector regulation is more prescriptive. CMF- regulated entities must maintain robust frameworks for information security, cybersecurity, outsourcing, continuity, operational risk and incident management. ISO 27001, SOC 2, NIST, PCI DSS or cloud secu - rity frameworks may be used as evidence of good practice, but the key is effective governance, controls, monitoring, auditability, resilience and vendor over - sight. NIS2 does not directly apply in Chile, but may influ - ence multinational groups, suppliers to EU-regulated customers or global cybersecurity policies. CSA CCM, SOC reports, penetration testing and cloud security documentation are commonly requested in cloud, SaaS and outsourcing due diligence, mostly as market requirements rather than universal legal obligations. 7.4 Information Notification Requirements Chile has legal and regulatory requirements to notify certain security incidents, but the applicable regime depends on the type of incident, sector and role of the affected entity. Under the Data Protection Law, once the new regime is fully in force, personal data breaches must be assessed and, where they may affect data subjects’ rights, notified to the Data Protection Agency. Where

23 CHAMBERS.COM

Powered by