Information Technology 2026

Definitive global law guides offering comparative analysis from top-ranked lawyers

CHAMBERS GLOBAL PRACTICE GUIDES

Information Technology 2026

Definitive global law guides offering comparative analysis from top-ranked lawyers

Contributing Editor Kit Burden DLA Piper

Global Practice Guides

Information Technology Contributing Editor

Kit Burden DLA Piper

2026

Chambers Global Practice Guides For more than 20 years, Chambers Global Guides have ranked lawyers and law firms across the world. Chambers now offer clients a new series of Global Practice Guides, which contain practical guidance on doing legal business in key jurisdictions. We use our knowledge of the world’s best lawyers to select leading law firms in each jurisdiction to write the ‘Law & Practice’ sections. In addition, the ‘Trends & Developments’ sections analyse trends and developments in local legal markets. Disclaimer: The information in this guide is provided for general reference only, not as specific legal advice. Views expressed by the authors are not necessarily the views of the law firms in which they practise. For specific legal advice, a lawyer should be consulted. Content Management Director Claire Oxborrow Content Manager Jonathan Mendelowitz Senior Content Reviewers Sally McGonigal, Ethne Withers, Deborah Sinclair, Stephen Dinkeldein, Vivienne Button and Sean Marshall Content Reviewers Lawrence Garrett, Marianne Page, Heather Palomino, Alison Moore, Adrian Ciechacki and Michael Irvine Content Coordination Manager Nancy Tsang Senior Content Coordinators Carla Cagnina and Delicia Tasinda Content Coordinator Joanna Chivers Head of Production Jasper John Production Coordinator Genevieve Sibayan

Published by Chambers and Partners 165 Fleet Street London EC4A 2AE Tel +44 20 7606 8844 Fax +44 20 7831 5662 Web www.chambers.com

Copyright © 2026 Chambers and Partners

Contents

INTRODUCTION Contributed by Kit Burden, DLA Piper LLP p.4

CHILE Law and Practice p.7 Contributed by LawTech Trends and Developments p.28 Contributed by LawTech

CHINA Trends and Developments p.35 Contributed by Beijing Jincheng Tongda & Neal (Shanghai) Law Firm

EU Trends and Developments p.42 Contributed by Digital & Analogue Partners

PORTUGAL Law and Practice p.50 Contributed by Lektou Trends and Developments p.66 Contributed by Lektou SWITZERLAND Law and Practice p.74 Contributed by Wenger Plattner

3 CHAMBERS.COM

INTRODUCTION

Contributed by: Kit Burden, DLA Piper LLP

DLA Piper LLP is one of the world’s largest law firms, with offices in all of the major business jurisdictions around the globe. Specifically in the TMT space, it has for many years been recognised as an outstand -

ing law firm in the technology sector, advising both customers and providers of technology services, products and solutions in relation to their most busi - ness-critical projects.

Contributing Editor

Kit Burden is a partner in the technology and sourcing group at DLA Piper in their London office, having previously led their international technology sector for over nine years and also served on its

international board. He is widely recognised as one of the world’s foremost IT and outsourcing lawyers, acting for many of the leading suppliers of technology and outsourcing services as well as many household names.

DLA Piper 160 Aldersgate Street London EC1A 4HT UK

Tel: +44 020 7349 0296 Fax: +44 020 7796 6666 Email: kit.burden@dlapiper.com Web: dlapiper.com

4 CHAMBERS.COM

INTRODUCTION  Contributed by: Kit Burden, DLA Piper LLP

Overview of the Information Technology Sector and Relevant Legislation in 2026 There has probably never been a time which has been more turbulent for lawyers involved with the technol - ogy sector. The primary driver for this is – of course – the remorseless advance of artificial intelligence (AI) solutions. As both the capabilities and applications of AI continue to advance at breakneck pace, law - makers, regulators and contract negotiators inevitably struggle to keep up. From a regulatory perspective, the EU has of course sought to adopt the earlier high ground, much as they did with the previous “wave” in relation to personal data (by way of the introduction of the GDPR), in intro - ducing the EU Data Act, which for the time being at least remains the primary comprehensive legal frame - work for the development and deployment of AI solu - tions. However, the fact that the EU Data Act was so long in gestation (and went through so many changes prior to being finalised) shows the challenges that regulators and lawmakers face in trying to create a framework to address the perceived risks associated with AI, whilst simultaneously not stifling innovation. It remains to be seen whether the rest of the world will follow the line suggested by the EU, or will instead follow a different course (either in terms of adopting more sectorial approaches, or even by adopting more laissez-faire, industry-led regimes). After all, we do not yet even have a common global view as to whether AI- generated outputs are capable of protection by way of the creation of associated intellectual property rights. In the meantime, however, contract negotiators will need to chart their own paths in terms of the contract terms which they believe to be appropriate for the specific circumstances in which AI technologies are to be developed or deployed, and in that sense we can fairly say that market standards are very much in flux/ in the course of development (which in itself creates additional opportunities for lawyers to add genuine value to the commercial discussions of their clients and to help shape appropriate market outcomes). Will we, for example, see contracts mirror the principles of the EU AI Act, and require up-front commitments as to transparency/explainability and the lack of unintended bias or discrimination, or will this be left for case-by- case negotiation?

In the meantime, AI continues to cause wider convul - sions in the technology sector, with investment into companies associated with AI solutions and underpin - ning technologies reaching unprecedented levels, and creating chains of interlinked transactions between chip manufacturers, data centre operators and soft - ware licensors involving sums which are quite literally mind-boggling. It remains to be seen whether there is an element of a “bubble” in this regard that may burst at some point (with significant ramifications thereafter for the wider sector and indeed the global economy), but for the time being, at least, the engine continues to spin at ever increasing speeds. Traditional technology service providers also face particular challenges in this regard; with Agentic AI promising to remove carbon labour (ie, real people) from the service delivery model, the labour arbitrage- based model for offshoring of IT-related services comes under real pressure; we see, therefore, a rush from the tech service provider community to acquire smaller cloud and AI companies in the interests of developing end-to-end “solutions” for their custom - ers, but it remains to be seen whether the combination of AI and cloud technologies will augment their service offerings, or substantially replace them. The ripple effect of the AI revolution then extends into the drafting of technology contracts; what, for example, should be the right balance of risk to be undertaken by the parties in relation to the develop - ment and deployment of AI solutions, and especially those which are themselves dependent upon third- party large language models? What warranties would be appropriately expected from service providers? What kinds of limitations of liability should there be (ie, left to be dealt with as part of the “normal” liability cap or subsumed within a separate “super cap”)? If in the case of the latter, should that be in addition to any such cap for personal data claims, or as part of the same liability pot? It will be interesting to see whether a consistent global position will emerge from these discussions, or whether regional variations will develop. Beyond the world of AI, technology services continue to consolidate around the major SaaS providers and hyperscalers. As the scope of contract negotiation

5 CHAMBERS.COM

INTRODUCTION  Contributed by: Kit Burden, DLA Piper LLP

with such corporate behemoths becomes more lim - ited, the role of legal advisers alters accordingly, ie, away from a concentration upon the negotiation and drafting of specific contract provisions, and towards advice on regulatory compliance, operational resil - ience and risk mitigation. Regulators in the financial services sector have been especially active in this regard, such that lawyers advising on projects involv - ing the financial services world need to be regulatory specialists in addition to their day jobs, at least inso - far as such regulations mandate particular contractual approaches or forms of drafting. On a perhaps less positive note, the spectre of cyber assaults and incidents continues to loom large, exac - erbated now not just by lone wolves and criminal syn - dicates, but also state actors with access to far more computer resources than ever before. Increasingly for large and small organisations alike, it feels less like “whether” a cyber attack will eventually penetrate through the corporate defences, but “when” (and with what impact). In the UK, the multi-month downtime experienced by Jaguar Land Rover provided a sober reality check for the potential impact upon not just an individual company, but also the wider commer - cial ecosystem they participate in. Customers again need to consider how their contracts should be set up to address such incidents, whilst suppliers need to assess whether traditional forms of drafting are still applicable (for example, how realistic is it to provide hard and fast Recovery Time Objective figures when it is known that the customer will want to take more time to bring its operations back up?). In the online world, the past few months have seen increased scrutiny on social media and the control and/or regulation of content. Australia is providing an ongoing experiment in terms of the banning of social media access for adolescents, and it remains to be seen whether other countries will follow suit. In the meantime, there is a continued focus on what the key social media giants could or should be doing to regulate the content on their platforms, and newly emerging litigation risks associated with the perceived addictive effect of certain online offerings (said by some to be the beginning of a new wave of litigation to be akin to the “Big Tobacco” litigation of past years).

Amongst all of the above, there is the spectre of con - tinued geopolitical instability and apparent shifts away from globalisation. These shifts can and are impacting upon technology lawyers and the advice we provide in a myriad set of ways, whether in terms of trying to predict the potential impact of sanctions or tariffs, through to considering the impact of supply chain dis - ruptions and the potential invocation of force majeure or “material adverse change” style contract provi - sions. For all of the disruption caused by the conflict in the Gulf, for example, one shudders to think what the global impact of conflict around Taiwan would be, given their global share of semiconductor chip pro - duction. So... to use the old Chinese proverb, “we live in inter - esting times”, with change coming from multiple directions and market forces seeming to shift on a day-to-day basis, there has never been a time when it has been more important to keep up to date with the latest legal developments and thinking, and for law - yers to position themselves accordingly as the trusted advisers to their clients as they seek to chart their own course through these uncertain times. Whether your own view of the tech-driven future is utopian or dystopian (or somewhere in between), this multi- jurisdictional guide should help serve to point the way forward.

6 CHAMBERS.COM

CHILE

Bolivia Brazil Paraguay

Chile

Uruguay

Santiago

Law and Practice Contributed by: Carolina Cabrera LawTech

Argentina

Contents 1. Online Services and Products p.9 1.1 Online Harms or Digital Services Legislation p.9 1.2 E-Commerce p.10 2. Software Licensing and “As a Service” Provision p.11 2.1 “On Premise” Licence Models Rather Than SaaS Solutions p.11 2.2 Suspension Rights p.12 2.3 Audit Rights p.12 2.4 Escrow Provisions p.12 2.5 Commitments Regarding Ongoing Availability of Saas Solutions p.13 3. Artificial Intelligence p.13 3.1 AI Legislation and Regulation p.13 3.2 Contractual Requirements With Respect to AI p.14 3.3 Key Concerns of Providers p.15 4. IT Services p.16 4.1 Overlay of Requirements p.16 4.2 Liability Clauses p.16 4.3 Warranties p.16 4.4 Agile Methodology p.17 4.5 Payment Models p.17 5. Telecommunications and Networks p.18 5.1 Telecoms Laws and Regulations p.18 5.2 Telecoms Regulatory Bodies p.18 5.3 Telecoms-Related Regulated Activities p.18 5.4 Interconnection and Roaming Rules p.19 5.5 Consumer Protection Rules p.19

6. Intellectual Property Considerations p.20 6.1 Background and Foreground IP p.20 6.2 Types of IP p.20 6.3 Use of Generic Know-How p.21 6.4 Patent Claims p.21 6.5 IP and AI/Computer-Created Works p.22 7. Data Protection Considerations p.22 7.1 Relevant Laws and Regulations for Data Protection p.22 7.2 Data Transfer Restrictions p.23 7.3 Information Security and Cybersecurity Standards p.23 7.4 Information Notification Requirements p.23 7.5 Supply Chain Requirements p.24 8. Legislative and Regulatory Adaptation and Advancement p.25

8.1 AI-Related Legal Adaptation p.25 8.2 Standards in Contract Drafting p.26

8.3 Hyperscalers p.26 8.4 IP Evolution p.27

7 CHAMBERS.COM

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

LawTech was founded by Carolina Cabrera, whose career spans SAP, Hewlett Packard and Accenture. LawTech brings a unique market perspective to the design, negotiation and governance of complex tech - nology ecosystems, helping organisations success - fully execute high-value digital transformation, cloud, outsourcing and AI initiatives. The firm specialises in the commercial, operational and contractual ar - chitecture of complex technology projects, advising clients on the structuring of pricing models, service levels, warranties, liabilities, governance frameworks and risk allocation mechanisms. Drawing on exten -

sive experience structuring and negotiating strategic technology transactions for leading global technolo - gy providers and major organisations across multiple industries, LawTech understands both the provider and customer perspectives in business-critical ini - tiatives. This unique background enables the firm to align commercial, operational and technology objec - tives, navigate complex multi-vendor environments and develop contractual frameworks that support successful implementation, effective governance and long-term value realisation throughout the life cycle of large-scale technology investments. technology transactions for leading Chilean and multinational organisations across a range of industries, combining commercial, operational and technology perspectives. Having participated throughout the full life cycle of technology projects, from commercial structuring and pricing to implementation and governance, she brings a distinctive market perspective to the design, negotiation and governance of complex technology ecosystems.

Author

Carolina Cabrera is a technology and digital transformation adviser with senior experience at SAP, Hewlett Packard and Accenture, supporting complex technology transactions across Latin America. She has

advised on large-scale projects involving software licensing, cloud transformation, infrastructure, outsourcing, managed services, cyber security and AI. Carolina has structured and negotiated strategic

LawTech Luis Matte Larrain 9851 Las Condes Santiago Chile Tel: +56 954 241 575 Email: contacto@lawtech.cl Web: www.lawtech.cl

8 CHAMBERS.COM

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

1. Online Services and Products 1.1 Online Harms or Digital Services Legislation 1.1.1 Key Obligations for Online Services

outsourcing, additional CMF and Central Bank rules may apply. 1.1.2 Categories of Platforms Chile does not have a DSA-style classification of online platforms based on size, reach or systemic impact. There is no local equivalent to “very large online plat - forms” or “very large online search engines”. Chilean law classifies online actors mainly by function, service type and sector. In intellectual property matters, the law distinguishes between transmission, caching, hosting, search, link - ing and reference services for purposes of the ISP safe harbour regime. This is relevant to copyright liability, but not a general platform governance classification. In e-commerce, consumer rules distinguish between sellers, providers and platform operators. This affects information and transparency duties, including disclo - sure of seller identity, platform role, product or service features, price, delivery, availability, withdrawal rights and after-sales support. Telecoms law separately regulates internet access providers, focusing on connectivity, quality, continu - ity and net neutrality. Cybersecurity law introduces a risk-based classification based on criticality, applying enhanced duties to essential services and operators of vital importance. Financial regulation also creates functional categories, including fintech providers, open finance participants, payment initiation providers, card issuers, card opera - tors, sub-acquirers and payment processing provid - ers. Overall, Chile classifies digital actors by function, risk and regulatory role rather than platform scale. 1.1.3 Relevant Regulators and Enforcement Chile does not have a single regulator equivalent to an EU Digital Services Co-Ordinator. There is no authority with general jurisdiction over all online content, online safety and platform governance. Enforcement is dis - tributed among regulators, courts and public authori - ties depending on the issue. For online content, there is no administrative author - ity with general powers to supervise moderation poli -

Chile does not currently have a single horizontal stat - ute equivalent to the EU Digital Services Act regulating online harms, platform governance, systemic risks, notice-and-action mechanisms or general content moderation duties. Obligations arise from a layered framework, depending on the provider’s role, the ser - vice, the content or conduct involved, and whether the provider operates in a regulated sector. The closest regime to intermediary liability is found in the Intellectual Property Law, which provides condi - tional liability limitations for internet service providers in copyright and related rights matters. It distinguishes transmission, caching, hosting, search, linking and reference services, and generally links takedown obli - gations to statutory procedures and judicial orders. This regime is limited to IP matters and does not cre - ate a general online safety framework. Online marketplaces and e-commerce platforms are mainly regulated through consumer protection and e-commerce transparency rules. These require clear information on the seller, platform role, product or service, total price, terms, delivery, withdrawal rights and after-sales support. They are aimed at transpar - ency and consumer protection, not general content moderation. Other layers apply depending on the issue. The Com - puter Crimes Law is relevant for malicious activity, fraud, unlawful access and data interference. The Cybersecurity Framework Law applies to essential services and operators of vital importance. Data pro - tection rules apply where platforms collect, profile, personalise, monitor or otherwise process user data. Telecoms rules also matter where the provider acts as an internet access provider. Internet access is treated as a public telecommunications service, and net neu - trality rules restrict arbitrary blocking or interference with lawful content, applications and services. In regu - lated sectors, such as fintech, payments, banking and

9

CHAMBERS.COM

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

cies or order removal of all illegal or harmful content. Copyright takedown is linked to the ISP safe harbour regime and judicial procedures. Online criminal con - duct is enforced by the Public Prosecutor’s Office and criminal courts. For e-commerce and marketplaces, SERNAC is rel - evant for consumer protection, platform transparency, advertising, information duties, online contracting and consumer complaints. For cybersecurity, ANCI super - vises entities subject to the Cybersecurity Framework Law, including essential services and operators of vital importance. For personal data, the new Data Protection Agency will supervise how online services collect, use, profile, share, secure and otherwise process personal data once the new regime becomes fully effective. For internet access and telecoms, SUBTEL supervises telecoms networks, spectrum, quality, continuity and net neutrality. For digital financial services, fintech, open finance, payments and technology outsourcing in the financial sector, the CMF is the key regulator, with the Central Bank also issuing important payment rules. A platform may therefore interact with SERNAC, ANCI, the Data Protection Agency, SUBTEL, CMF, the Central Bank, prosecutors or courts depending on the service and risk. 1.2 E-Commerce 1.2.1 Principal E-Commerce Legislation Chile does not have a single e-commerce code. The main framework for e-commerce and online contract - ing combines contract law, consumer protection, electronic signatures, data protection and sector- specific rules where the online service involves pay - ments, financial services, telecoms or other regulated activities. For B2C e-commerce, the Consumer Protection Law and the E-Commerce Regulation are central. They regulate online contracting, advertising, pricing, unfair terms, warranties, withdrawal rights, consumer infor - mation, platform roles and SERNAC enforcement.

Online contracts are supported by the Electronic Sig - nature Law, which recognises electronic documents and signatures, functional equivalence with paper documents and the distinction between simple and advanced electronic signatures, subject to statutory exceptions. General civil and commercial contract rules continue to apply, including consent, offer and acceptance, capacity, object, cause, performance, breach and evi - dence, unless special consumer, electronic signature, payment or sector rules apply. Data protection is another key layer for customer registration, profiling, marketing, analytics and auto - mated processing. Where online contracting involves payments or regulated financial services, additional rules apply on unauthorised transactions, fintech ser - vices, open finance, card payments, payment systems and CMF/Central Bank supervision. 1.2.2 Key Obligations for Online Contracting Businesses contracting online in Chile must comply with consumer protection, e-commerce, contract, electronic signature, data protection and payment rules. The key obligation is practical: consumers must receive clear, complete and timely information before purchasing, the online acceptance process must be clear, and the consumer must receive confirmation once the contract is concluded. In B2C transactions, sellers and platform operators must provide accessible information on the seller, contact details, platform role, product or service, total price, charges, delivery costs, availability, delivery or performance conditions, payment methods, after- sales support and legal or contractual guarantees. A consumer’s mere visit to a platform does not cre - ate an obligation to contract. The consumer must unequivocally accept the terms and conditions, and businesses should ensure that online terms, advertis- ing, promotions and displayed offers are consistent. Misleading information may trigger consumer liability. Electronic contracting is generally valid, but busi - nesses should design flows that evidence consent, identity, date, accepted terms, contract version, notic -

10 CHAMBERS.COM

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

es and confirmation. Advanced electronic signatures may be needed or advisable where stronger evidence is required. Online businesses must also comply with data pro - tection obligations for account creation, purchases, delivery, support, marketing, profiling, analytics, fraud prevention and automated processing. Where pay - ments or regulated financial services are involved, fur - ther rules apply on payment channels, unauthorised transactions, security, authentication and regulatory supervision. 1.2.3 Formation of Contracts Online Online contracts are generally valid and enforceable in Chile. There is no special formality merely because a contract is entered into online. The starting point is ordinary contract law: capacity, consent, lawful object and lawful cause, plus commercial rules on offer and acceptance where relevant. The Electronic Signature Law recognises electronic documents and signatures and is based on techno - logical neutrality, functional equivalence and inter - national compatibility. Acts and contracts executed electronically generally produce the same effects as paper-based contracts, subject to statutory excep - tions. For most private online contracts, a simple electronic signature or electronic acceptance mechanism is suf - ficient if consent can be evidenced. This may include click-through acceptance, platform workflows, elec - tronic execution or other processes that identify the user and preserve the accepted terms. Advanced electronic signature is required where the electronic document has the status of a public instru - ment and is often used where stronger evidence of identity, integrity, date and non-repudiation is advis - able. Certain acts remain excluded, such as those requiring non-electronic solemnities, personal appear - ance or family law formalities. In B2C e-commerce, consumers must have clear prior access to terms and the ability to store or print them. Before payment, a transaction summary must be displayed, and after conclusion the seller must

send written confirmation. The main practical issue is therefore not validity alone, but evidence of consent, terms, notices and confirmation. 2. Software Licensing and “As a Service” Provision 2.1 “On Premise” Licence Models Rather Than SaaS Solutions Customers in Chile do not usually require on-premise licensing because SaaS is legally restricted. SaaS and cloud models are widely used. However, regu - lated, critical or legacy-heavy customers may prefer on-premise models because they offer greater control over infrastructure, data, security, continuity and cus - tomisation. A first driver is regulatory and operational con - trol. Banks, payment companies, utilities, telecoms operators, healthcare providers and other sensitive businesses may need to demonstrate control over technology environments, outsourced services, audit - ability, incident response and business continuity. Data control is also important. Customers may prefer on-premise deployment where they process sensitive, confidential, regulated or strategically important data, especially where they have concerns about data loca - tion, cross-border access, subcontracting, encryption or regulator and court requests. Continuity, legacy integration and customisation also matter. Some systems must remain available during connectivity failures, provider outages or cloud dis - ruptions, and many large companies still operate core systems that were not designed for cloud-native inte - gration. Vendor lock-in and pricing may also influence the decision. SaaS gives suppliers more control over hosting, upgrades, pricing, feature changes and end- of-life decisions. Some customers also prefer capital expenditure or perpetual licences over recurring sub - scriptions. Hybrid models remain common.

11 CHAMBERS.COM

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

2.2 Suspension Rights Suspension rights in Chilean software, SaaS and tech - nology services agreements are mainly contractual. There is no single statutory list of triggers. Providers typically seek suspension rights for non-payment, unauthorised use, security risks, legal or regulatory requirements, and conduct affecting the platform or other customers. The most common trigger is non-payment after notice and a cure period. Customers, especially regulated or operationally sensitive customers, usually negotiate prior notice, escalation, partial suspension, continued data access and exceptions for disputed invoices or critical services. Providers also seek suspension for unauthorised use, such as exceeding users, environments, API calls or volumes, sharing credentials, reverse engineering, scraping, misuse, breach of acceptable use policies, or interference with service performance. Security triggers are increasingly important. Provid - ers often request immediate suspension where the customer creates a real or suspected security risk, introduces malware, compromises credentials, affects platform integrity or threatens other customers. Legal, regulatory and data-related triggers are also common. Providers may suspend where continued service would breach law, a court order, regulatory instruction, sanctions, IP, privacy or cybersecurity requirements. Regulated customers normally seek proportionality, co-operation, emergency data access, transition assistance and clear reinstatement proce - dures. 2.3 Audit Rights Audit rights are increasingly important in Chilean soft - ware, SaaS, cloud and technology services agree - ments, especially where the customer is regulated or the service involves personal data, cybersecurity, payments, critical operations or outsourcing. Customers typically request audit rights covering security, availability, data protection, continuity, dis - aster recovery, subcontracting and regulatory compli - ance. This may include policies, certifications, pen -

etration testing summaries, incident records, access controls, encryption, backups, service levels, data processing terms and subcontractor controls. Regulated financial institutions and payment compa - nies are especially focused on auditability. For them, audit rights are part of regulatory risk management, and providers may need to support audits, regula - tory inspections, subcontractor disclosure, continuity reviews and exit planning. Cloud and multi-tenant SaaS providers usually resist broad on-site audits. Market practice often relies on SOC reports, ISO certifications, security question - naires, third-party audit reports, compliance portals, penetration testing summaries and customer-specific audit meetings. Providers also request audit rights to verify licence compliance, users, environments, installations, API usage, storage, transaction volumes and misuse. Modern clauses define scope, frequency, notice, per - mitted auditors, confidentiality, records, remediation, costs and regulatory access. 2.4 Escrow Provisions Escrow clauses are not standard in all Chilean soft - ware contracts. They are relatively uncommon in ordi - nary SaaS agreements, especially multi-tenant cloud services where the customer does not receive, install or operate the software. In those cases, customers usually negotiate data export, transition assistance, continuity commitments, termination support and backups instead of source code escrow. Escrow remains relevant for critical software, bespoke developments, on-premise deployments, private cloud, core systems and technology supplied by smaller or highly specialised vendors. Customers may request it where the software is difficult to replace, deeply integrated or essential for regulated or sensi - tive operations. Typical deposits include source code, build instruc - tions, technical documentation, configuration files, deployment scripts and materials needed to maintain or operate the software. More sophisticated arrange -

12 CHAMBERS.COM

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

ments require periodic updates and verification that the code can be compiled and used. Release triggers commonly include insolvency, cessa - tion of business, discontinuation of support, material breach of support obligations, critical service failure or termination where the customer needs continued access to operate the software. Escrow must be carefully drafted from an IP per - spective. Deposit does not transfer ownership. The contract should define the customer’s licence upon release, permitted users, confidentiality, trade secrets, third-party components, open source and restrictions on commercial exploitation. 2.5 Commitments Regarding Ongoing Availability of Saas Solutions SaaS availability commitments in Chile are mainly contractual, but increasingly influenced by cyberse - curity, data protection, business continuity and sector regulation. Customers typically expect uptime com - mitments, maintenance rules, support, incident man - agement, backups, recovery and remedies for missed service levels. The core commitment is usually an availability SLA measured monthly or annually. The clause should define how availability is calculated, exclusions from downtime, measurement tools, and whether the SLA applies to the platform, modules, APIs or critical func - tions. Scheduled maintenance, emergency mainte - nance, customer-caused downtime and third-party network failures are common exclusions. Maintenance and support commitments are also important. Customers often request prior notice, defined maintenance windows, limits on disruption, support channels, severity levels, response times, escalation, incident communications and remedia - tion obligations. For continuity, customers seek backup, restoration, redundancy, disaster recovery, recovery time and recovery point commitments. Regulated or critical customers may also require tested continuity plans, evidence of testing and support for their own regula - tory obligations.

Remedies are usually service credits, but customers often resist making credits the sole remedy for repeat - ed failures, prolonged outages, data loss, confiden - tiality breaches or failures affecting critical regulated services. Termination rights, audit, regulatory access, data export and transition assistance are increasingly negotiated.

3. Artificial Intelligence 3.1 AI Legislation and Regulation 3.1.1 General Legislative Regime for AI

Chile does not yet have a fully enacted general stat - ute regulating the use or development of AI solutions. AI systems are currently governed through general and sector-specific laws, including data protection, consumer protection, cybersecurity, IP, civil liability, employment, financial regulation and public sector rules, depending on the use case. Chile is actively moving toward a general AI regime. A bill regulating AI systems is under legislative discus - sion and follows a risk-based structure influenced by international AI governance trends, including the EU AI Act, OECD principles and UNESCO recommenda - tions. The bill would apply to providers placing AI systems on the Chilean market or putting them into service in Chile, implementers domiciled in Chile, and foreign providers or implementers where the output is used in Chile. It defines key actors across the AI value chain. The proposed framework classifies AI systems by foreseeable risk: unacceptable risk, high risk, limited risk and no evident risk. High-risk systems would be subject to risk management, data governance, tech - nical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity obligations. The bill also includes governance and enforcement mechanisms, serious incident reporting, sandboxes, confidentiality, administrative sanctions and civil liabil - ity. Until enacted, AI compliance in Chile remains a layered exercise based on data, cybersecurity, sector regulation, IP, contracts and risk management.

13 CHAMBERS.COM

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

3.1.2 AI-Related Lower-Level Regulation Chile does not yet have a complete set of AI-spe - cific lower-level regulations issued under a general AI statute. The current landscape combines soft-law instruments, public sector guidance and sector-driv - en rules that apply where AI involves personal data, cybersecurity, outsourcing, finance, payments, public procurement or public sector decision-making. The most AI-specific instrument currently in place is the public sector circular issued by SEGPRES and the Ministry of Science in December 2023. It provides recommended guidelines for public bodies on respon - sible, ethical, safe and transparent use of AI tools. The circular covers suitability of AI, avoidance of arbi - trary discrimination, citizen participation where rights may be affected, transparency and explainability, pri - vacy and data use, restrictions on entering personal or sensitive data into non-approved generative AI tools, training and cybersecurity. The National AI Policy Action Plan is also relevant, although not binding. It includes initiatives on data governance, the Data Protection Agency, cyberse - curity, algorithmic transparency, standards for critical AI applications, anonymisation, public sector AI, pro - curement criteria and sandboxes. In the private sector, AI-specific rules remain frag - mented. Financial, cybersecurity and data protection rules are highly relevant when AI is used in regulated services, outsourcing, payment infrastructure, profil - ing, scoring, fraud prevention, automated analysis or decision support. 3.1.3 AI-Related Self-Regulation AI self-regulation in Chile exists but remains uneven and developing. There is no general statutory obliga - tion requiring all companies to adopt an internal AI governance programme, but larger companies, regu - lated entities, multinational groups and technology- intensive businesses are increasingly doing so. This trend is driven by the pending AI bill, the new data protection framework, cybersecurity requirements, sector regulation, group-level compliance policies and international standards. Financial services, technol -

ogy, retail, healthcare, telecoms and utilities are more likely to treat AI governance as part of compliance, privacy, cybersecurity, outsourcing and operational risk. Common measures include AI acceptable-use poli - cies, approval processes for new tools, restrictions on public generative AI platforms, prohibitions on upload - ing personal, sensitive, confidential or client data into non-approved tools, and internal AI registers. Companies also use vendor due diligence, contrac - tual controls, cybersecurity review, data protection assessments, human oversight, staff training and escalation procedures. For AI used in scoring, HR, fraud detection, marketing, compliance or document automation, documentation, explainability, bias con - trols, data quality and auditability are increasingly important. International frameworks such as OECD, UNESCO, the EU AI Act, NIST AI RMF and ISO AI standards are used as references even when not binding. The market is moving from informal controls toward more formal AI governance, especially in regulated, multi - national and high-risk environments. 3.2 Contractual Requirements With Respect to AI 3.2.1 Key Requirements Sought by Customers Customers in Chile increasingly seek AI-specific con - tractual protections, especially for generative AI, deci - sion-support tools, personal data, regulated activities, cybersecurity risk and customer-facing uses. They no longer treat AI simply as ordinary software. A first requirement is a clear description of the AI use case and roles. Contracts should distinguish general- purpose AI, SaaS with embedded AI, bespoke devel - opment, fine-tuning, APIs, decision-support tools and managed services, because obligations on perfor - mance, explainability, data, outputs and liability vary. Data clauses are central. Customers seek commit - ments that customer data, prompts, files, outputs, personal data, confidential information and business data will not be used to train or improve models unless expressly authorised. They also regulate retention,

14 CHAMBERS.COM

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

access, location, subcontracting, transfers, deletion, anonymisation and security. Customers also request transparency, documentation and auditability, including capabilities and limitations, model versioning, testing, data sources at a high level, accuracy, bias controls, human oversight, logs and explainability. For higher-risk uses, impact assess - ments and risk management may be required. IP, security and output risk are heavily negotiated. Customers seek clarity on prompts, outputs, fine- tuned models, embeddings, datasets and bespoke developments; indemnities for third-party IP claims; safeguards against hallucinations, bias, harmful con - tent and prompt injection; and future-proofing clauses for regulatory change. 3.2.2 AI-Related Liabilities in Contracts AI-related liability in Chile is currently addressed main - ly by contract because there is not yet a fully enacted general AI liability regime. Parties allocate risk through warranties, disclaimers, indemnities, liability caps, carve-outs, compliance duties, human review, data protection, cybersecurity, IP and incident response clauses. A common approach is to distinguish liability for the AI tool from liability for the customer’s use of it. Sup - pliers state that outputs may be probabilistic or inac - curate and should be reviewed. Customers seek com - mitments that the system is tested, documented and configured for the agreed purpose. Generative AI contracts increasingly address halluci - nations, inaccurate outputs and customer decisions based on outputs. Customers try to narrow disclaim - ers where the supplier made specific performance claims, provided a bespoke or fine-tuned model, con - trolled the workflow or marketed the tool for a regu - lated or high-impact use. Data and IP liability are major negotiation points. Contracts allocate responsibility for lawful input data, prompts, training data and fine-tuning datasets. Cus - tomers seek protection against unauthorised training, disclosure, unlawful transfers, security incidents and third-party IP claims.

Liability caps are becoming more differentiated. Sup - pliers seek aggregate caps and exclusions, while customers request carve-outs or higher caps for con - fidentiality, data protection, IP, cybersecurity, fraud, wilful misconduct, gross negligence, regulatory fines caused by the supplier and failures affecting critical services. 3.3 Key Concerns of Providers AI providers in Chile are mainly concerned with avoid - ing an excessive transfer of risk, especially while the AI regime and market standards are still evolving. Their concerns usually relate to outputs, customer misuse, data rights, IP, confidentiality, cybersecurity, auditability and future regulatory change. A key concern is liability for outputs. Providers resist full responsibility for hallucinations, inaccurate or biased results, or decisions made by the customer where the customer controls the use case, inputs, prompts, configuration, workflow or final decision. They usually require human review and acceptable- use restrictions. Providers are also concerned about misuse, including unlawful, discriminatory, infringing, abusive or high- risk uses outside scope, scraping, reverse engineer - ing, model extraction, prompt injection, bypassing safety controls, or uses affecting third parties or other customers. Data and IP are heavily negotiated. Providers want customers to be responsible for the lawfulness and quality of inputs, prompts, training data and fine-tun - ing datasets. They also seek to preserve ownership of models, algorithms, pre-existing technology, docu - mentation, know-how, embeddings, generic improve - ments and platform developments. Transparency, audit and cybersecurity requests are another concern. Providers must balance customer and regulator demands against confidentiality, trade secrets, security and obligations to other customers. They also seek suspension, investigation, coopera - tion and change-control rights where customer use creates platform or compliance risk.

15 CHAMBERS.COM

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

4. IT Services 4.1 Overlay of Requirements

The starting point is usually an aggregate cap linked to fees paid or payable over a defined period. For ordinary failures, delays, implementation issues, sup - port failures or non-critical downtime, suppliers seek to limit liability to direct damages. SaaS and man - aged services often use service credits for availability failures. Contracts commonly exclude indirect, consequential, punitive or special damages, loss of profit, revenue, business opportunity, goodwill, anticipated savings and business interruption. Customers resist broad exclusions where the service is critical, regulated or supports customer-facing operations, payments or core systems. Specific indemnities usually cover third-party IP claims, confidentiality breaches, unauthorised use of customer data, data protection violations, supplier- caused cybersecurity incidents, employment or sub - contractor claims, and damage caused by supplier personnel or subcontractors. Carve-outs are heavily negotiated. Customers seek uncapped or higher-capped liability for fraud, wilful misconduct, gross negligence, confidentiality, person - al data, IP, security breaches, supplier-caused regula - tory fines, audit/compliance breaches, data loss and failures affecting critical regulated services. 4.3 Warranties Warranties in Chilean IT services contracts are mainly contractual and should be tailored to the service, sec - tor, customer profile and data or systems involved. A standard package covers professional performance, specifications, personnel, legal compliance, IP, securi - ty, confidentiality, data protection and, where relevant, service levels, interoperability and continuity. A basic warranty is that services will be performed professionally and diligently, in accordance with the contract, statement of work, specifications, documen - tation, project plan and industry standards. Implemen - tation, support and managed services contracts also include milestones, deliverables, acceptance criteria, response times and SLAs.

Chile does not have a single statute comprehensively regulating IT services. The framework is layered: con - tract law applies first, then cross-cutting and sector- specific rules depending on the service, customer, data, infrastructure and regulated sector. General civil and commercial rules govern consent, obligations, liability, termination and damages. Where the service involves software licensing, development, implementation, support, maintenance or assignment of rights, IP rules are relevant for software, source code, documentation, databases, licences, permit - ted use and infringement risk. Data protection is a key overlay because IT provid - ers often process, host, access or support systems containing personal data. Contracts must address lawful basis, controller/processor roles, confidenti - ality, security, rights, subcontractors, international transfers, breach management, retention, deletion and auditability. Cybersecurity is another important layer, especially where IT services support essential services, critical infrastructure, managed IT, telecoms, financial servic - es, payments, healthcare, energy, water or transport. Customers increasingly expect security-by-design, privacy-by-design, incident response, vulnerability management, logging, continuity and reporting. Regulated financial entities face a stronger overlay on outsourcing, security, continuity, incidents, pro - vider controls, audit, subcontracting, data location, exit plans and regulatory access. Public-sector IT is affected by public procurement and digital govern - ment rules, while B2C services must also consider consumer protection and e-commerce requirements. 4.2 Liability Clauses A typical IT services liability clause in Chile combines a general liability cap, exclusions for certain damag - es, specific indemnities and carve-outs for higher-risk breaches. It should be tailored to the service, cus - tomer sector, data, system criticality and regulatory requirements.

16 CHAMBERS.COM

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

Personnel warranties usually cover qualified staff, supervision, key personnel continuity, and supplier responsibility for employees, subcontractors and affili - ates. On-site or staff augmentation arrangements may also cover labour, health and safety, access, confiden - tiality and customer policies. IP warranties are important in software and technol - ogy services. Suppliers are expected to warrant that they have sufficient rights to provide software, tools, documentation, deliverables and services, and that authorised use will not infringe third-party IP rights, subject to common supplier exclusions. Security, data and confidentiality warranties are increasingly central. Customers expect reasonable technical and organisational measures, no intentional malware or backdoors, confidentiality controls, data processing only under instructions, breach assistance, subprocessor control, deletion or return of data, and continuity or support commitments for SaaS, cloud and managed services. 4.4 Agile Methodology Agile methodology is increasingly used in Chilean IT projects, particularly in software development, plat - form implementation, systems integration, cloud migration, data analytics and AI-related projects. It is most useful where the customer does not have a fully fixed specification at the outset and the project requires iterative design, testing, feedback and adjust - ment. In practice, many contracts are not purely agile. Sophisticated projects usually combine agile deliv - ery with more traditional contractual structures, such as master services agreements, statements of work, governance committees, project plans, budget limits, service levels, acceptance criteria, change control and milestone or sprint-based payments. This hybrid approach preserves flexibility while giving legal cer - tainty on scope, price, responsibility and deliverables. Key drafting points include the agile framework, party roles, backlog, sprint planning, sprint duration, demos, testing, acceptance and escalation. Cus - tomer responsibilities are also important: appointing a product owner, prioritising the backlog, providing

timely feedback, making users available and approv - ing deliverables. Pricing is usually time-and-materials, capacity-based or sprint-based, sometimes combined with caps, tar - get prices, milestones or hybrid models. Acceptance is also adapted: rather than one final acceptance, con - tracts may include acceptance by sprint, user story, release, module or minimum viable product. For regulated or public-sector customers, agile requires more discipline around documentation, audit - ability, security, continuity, change management and procurement rules. Overall, agile contracting is pre - sent in Chile, but usually in a controlled hybrid form. The main legal challenge is to allow iteration with - out losing certainty on governance, IP, data, security, change control and termination. 4.5 Payment Models Payment models for IT services in Chile vary according to the type of service, project maturity, scope uncer - tainty, procurement rules and whether the service is software, SaaS, cloud, outsourcing, implementation, support or consulting. Hybrid models are common. Fixed-price models are used where scope, delivera - bles, timeline and acceptance criteria are sufficiently clear, such as defined implementation phases, migra - tions, integrations or discrete software developments. Suppliers usually require assumptions, exclusions, change control and customer-dependency clauses. Time-and-materials models are common in consult - ing, agile projects, support, troubleshooting, cyberse - curity, data analytics and evolving projects. They usu - ally include hourly or daily rates, rate cards, estimated budgets, monthly invoicing, approval workflows and sometimes caps or not-to-exceed amounts. Milestone payments are frequent in implementation and development projects, with payment linked to modules, testing, acceptance, go-live, migration, sta - bilisation or handover. Subscription and recurring fees are typical for SaaS, cloud, software maintenance, support and managed services. Usage-based pric - ing is increasingly relevant for cloud, APIs, AI tools, analytics and infrastructure services.

17 CHAMBERS.COM

Page i Page 1 Page 2 Page 3 Page 4 Page 5 Page 6 Page 7 Page 8 Page 9 Page 10 Page 11 Page 12 Page 13 Page 14 Page 15 Page 16 Page 17 Page 18 Page 19 Page 20 Page 21 Page 22 Page 23 Page 24 Page 25 Page 26 Page 27 Page 28 Page 29 Page 30 Page 31 Page 32 Page 33 Page 34 Page 35 Page 36 Page 37 Page 38 Page 39 Page 40 Page 41 Page 42 Page 43 Page 44 Page 45 Page 46 Page 47 Page 48 Page 49 Page 50 Page 51 Page 52 Page 53 Page 54 Page 55 Page 56 Page 57 Page 58 Page 59 Page 60 Page 61 Page 62 Page 63 Page 64 Page 65 Page 66 Page 67 Page 68 Page 69 Page 70 Page 71 Page 72 Page 73 Page 74 Page 75 Page 76 Page 77 Page 78 Page 79 Page 80 Page 81 Page 82 Page 83 Page 84 Page 85 Page 86 Page 87

Powered by