CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech
the breach creates serious risk for affected individuals, direct communication to data subjects may also be required. The obligation concerns incidents affecting confidentiality, integrity or availability of personal data. Under the Cybersecurity Framework Law, state bod - ies, essential services and operators of vital impor - tance must report cybersecurity incidents and cyberat - tacks that may have significant effects. These include events affecting confidentiality, integrity, availability, resilience or authentication of networks, systems or information. The main authority is the National CSIRT within the National Cybersecurity Agency framework, and timelines are very short. Financial-sector entities must also report relevant operational and cybersecurity incidents to the CMF, including cyberattacks, technology failures, service interruptions, data leaks, loss of information and events affecting continuity, security or quality of reg - ulated services. Telecoms operators may also have duties to inform SUBTEL of events affecting service continuity, quality or regulated infrastructure. In practice, the authority notification obligation usually sits with the regulated entity, data controller, essential service provider or financial institution, not automati - cally with the IT supplier. Suppliers are usually con - tractually required to notify the customer immediately, provide technical information, preserve evidence, support forensic analysis, mitigate the incident and assist with regulatory or customer communications. 7.5 Supply Chain Requirements 7.5.1 Risk Assessments and Due Diligence on Suppliers and Extended Supply Chains Chile does not have a single cross-sector technology supply-chain due diligence law requiring all compa - nies to perform formal risk assessments on all suppli - ers. However, supplier due diligence is legally required or strongly expected in regulated contexts, especially where personal data, cybersecurity, financial services, cloud, outsourcing, essential services or public-sector technology are involved. Under the Data Protection Law, controllers must ensure that processors and subprocessors provide sufficient guarantees. This makes supplier due dili -
gence important where vendors process, host, access or support personal data. Customers should assess security, instructions, subprocessors, international transfers, breach notification, deletion/return and sup - port for data subject rights. The Cybersecurity Framework Law increases the importance of supply-chain risk management for essential services and operators of vital importance. This will often include third-party technology provid - ers, managed service providers, cloud providers, software vendors, critical subcontractors and other operational dependencies. The most developed requirements are in the financial sector. CMF-regulated entities must assess and man - age risks associated with outsourcing, cloud, external service providers, cybersecurity, continuity and inci - dents. They remain responsible for outsourced func - tions and must supervise providers, manage subcon - tracting, ensure continuity, protect customer data and allow audit or regulatory review. In the wider market, supplier due diligence is increas - ingly standard in IT contracts through security ques - tionnaires, ISO/SOC evidence, penetration test - ing summaries, business continuity plans, incident response procedures, subcontractor lists, data loca - tion information, cyber insurance, audit rights, exit plans and flow-down obligations. 7.5.2 Data Protection or Information/Cybersecurity Terms in Supply Agreements Chile does not impose a general obligation for every supply agreement to include data protection or cyber - security clauses. However, such clauses are legally required or strongly expected where the supplier pro - cesses personal data, provides outsourced or cloud services to regulated entities, supports essential ser - vices, or operates in a sector subject to cybersecurity, financial, telecoms or public-sector technology rules. Under the Data Protection Law, where a supplier pro - cesses personal data on behalf of a customer, the agreement should include data processing terms cov - ering instructions, purpose and duration, categories of data, security measures, confidentiality, data subject rights, breach notification, subprocessors, interna -
24 CHAMBERS.COM
Powered by FlippingBook