Data Protection and Privacy 2025

CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados

the new Law No 21.719 will bring about once it comes into force in December 2026. 1.2 Regulators At present, and in general, the main regulators of data protection are the civil courts under the Law. However, this will change in December 2026 when the Agency created by the New Law becomes functional. In the meantime, other entities currently have powers in matters of personal data protection, the main ones being the following. Consumer Rights Currently, the National Consumer Service ( Servi - cio Nacional del Consumidor , or SERNAC) is the supervisory body for the protection of personal data in the context of consumer relations, until the Agency is established in December 2026. Although it does not have sanctioning powers, SERNAC can exercise its powers to file individ - ual or class actions before the courts, supervise, inspect, investigate, and issue interpretative cir - culars that are mandatory for SERNAC officials when applying the regulation and the Law (eg, at the time of audit). Public Sector The Council for Transparency (the “Council”) is responsible for ensuring compliance with the Law by the organs of state administration. The Council has issued Recommendations on the Protection of Personal Data by the Organs of State Administration, the Guide on Protection of Personal Data for Public Institutions (2021) and Resolution No 489/2022, which approved the Procedure for Processing Requests for the Exercise of ARCO Rights made before the Coun - cil. ARCO rights are those of access, rectifica - tion, cancellation or elimination, opposition and

blocking of personal data held, in this case, by the Council. Financial Sector The Financial Market Commission ( Comisión para el Mercado Financiero , or CMF) is the con - trol body in the financial sector and has regula - tory and supervisory powers in matters of per - sonal data protection, information security and cybersecurity. Under Chapters 18-5, on information about debtors from financial institutions, and Chapters 20-6 and following of the Updated Compilation of Standards ( Recopilación Actualizada de Nor - mas de Bancos , or RAN) of the CMF on business continuity, information security and outsourcing of services, financial institutions must have an internal policy on security and management of debtor information ( Política Interna de Seguridad y Manejo de la Información sobre Deudores , or PISMID), which must follow international princi - ples and best practices on personal data pro - cessing. Law No 21.521, known as the “Fintech Law”, to “[promote] competition and financial inclusion through innovation and technology in the provi - sion of financial services”, mandates the CMF to dictate the cybersecurity and personal data protection standards that financial institutions participating in the future Open Finance System must comply with. Cybersecurity In the area of cybersecurity, Chile has the Cyber - security Framework Law No 21.663, which cre - ated the National Cybersecurity Agency that came into force on 1 January 2025. The Cyber - security Framework Law applies to two types of entities: providers of essential services (tel - ecommunications, digital services, digital infra -

57

CHAMBERS.COM

Powered by