Information Technology 2026

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

tional transfers, deletion or return, audits and alloca - tion of responsibilities. The Cybersecurity Framework Law also makes cyber - security clauses important for essential services and operators of vital importance. Contracts with critical technology suppliers should address security meas - ures, incident notification, co-operation, continuity, resilience, access controls, vulnerability management, evidence preservation, reporting and remediation. Financial-sector regulation is one of the clearest areas for detailed contractual requirements. CMF-regulat - ed entities entering outsourcing, cloud or technology supply arrangements must include provisions that allow them to manage operational, cybersecurity, continuity and third-party risks. This means service levels, audit rights, regulatory access, confidentiality, security, continuity, incident reporting, subcontracting controls, exit plans and termination assistance. Even outside regulated sectors, Chilean market prac - tice increasingly expects data protection and cyber - security provisions in IT, SaaS, cloud, outsourcing, software implementation and managed services con - tracts. 7.5.3 The Application of Laws Relevant to Supply Chains In Chile, laws relevant to technology supply chains do not apply solely to the customer in all cases. The answer depends on the applicable regime and the role each party plays. Often, the customer remains primar - ily accountable to the regulator, but the supplier may have direct legal obligations or contractual duties to support compliance. There is no general Chilean technology supply-chain due diligence law applying uniformly to all customers and suppliers. Obligations arise instead from data pro - tection, cybersecurity, financial regulation, telecoms regulation, public procurement and sector-specific rules. Under the Data Protection Law, both customer and supplier may have obligations, but not the same ones. The customer will often be the controller and the sup - plier the processor. The controller remains responsi -

ble for lawful processing and selecting processors with sufficient guarantees; the processor must follow instructions, implement security, maintain confiden - tiality, manage subprocessors, assist with rights and support breach management. Under the Cybersecurity Framework Law, direct obligations apply to entities that qualify as essential service providers or operators of vital importance. A customer may fall within that category, but so may a technology supplier if it provides critical digital infra - structure, managed IT, cloud, cybersecurity or other relevant services. In the financial sector, the regulated customer gen - erally remains accountable before the CMF for out - sourced services. Suppliers assume contractual obli - gations that allow the customer to comply, including audit rights, regulatory access, information security, confidentiality, incident notification, continuity, sub - contracting restrictions, exit assistance and access to relevant information. Chile is likely to move from policy guidance and gen - eral technology laws toward a more specific, risk- based AI regulatory framework. The pending AI bill is the clearest signal of this direction and follows a model broadly inspired by international risk-based regulation, with categories such as unacceptable risk, high risk, limited risk and systems with no evident risk. The future framework will probably combine three lay - ers. First, a general AI law setting baseline principles, risk classification, transparency, human oversight, technical robustness, data governance, cybersecu - rity, accountability, incident management, sanctions and civil liability, especially for high-risk uses affecting rights, consumers, public services, employment, edu - cation, health, financial services or essential benefits. Second, Chile is likely to develop sector-specific AI regulation. Financial services, health, education, labour, telecoms, consumer platforms, cybersecurity 8. Legislative and Regulatory Adaptation and Advancement 8.1 AI-Related Legal Adaptation

25 CHAMBERS.COM

Powered by