CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
structure, water, health; energy, utilities, etc.) and operators of vital importance ( operadores de importancia vital , or OIVs), the latter designated after a special procedure led by the National Cybersecurity Agency at least every three years. In the context of personal data protection, the Cybersecurity Framework Law establishes the obligation for both essential service provid - ers and OIVs to notify cybersecurity incidents with significant effects to the National Com - puter Security Incident Response Team ( Equipo Nacional de Respuesta a Incidentes de Seguri - dad Informática , or National CSIRT), including incidents affecting computer systems containing sensitive personal data. 1.3 Enforcement Proceedings and Fines There is currently no privacy regulator or data protection authority in Chile, although there is a legal action (habeas data) that data subjects may exercise in the event of a breach of data. Thus, data protection enforcement is addressed by general courts with general powers. A sum - mary court procedure is established by the Law if the person responsible for the personal data registry or bank fails to respond to a request for access, rectification, suppression or block - ing of personal data within two business days, or refuses a request on grounds other than the security of the nation or the national interest. Breaches of data protection caused by improper processing of data may eventually lead to fines determined by the Law (USD70 to USD700, and USD700 to USD3,490 approximately). Fines are determined in a summary court procedure. The Law establishes a general rule under which both non-monetary and monetary damages that result from wilful misconduct or negligence in the processing of personal data will be compensat - ed. In those cases, the amount of compensation
will be established reasonably by the civil judge, considering the circumstances of the case and the relevance of the facts. On the other hand, the New Law advances from judicial logic to administrative logic, where the body in charge of overseeing this new regulatory standard will be the Personal Data Protection Agency, an administrative body of a technical nature, with regulatory, interpretive, supervisory and sanctioning powers. With regard to the sanctioning regime, in the event of non-compliance with the New Law, the Agency may: • impose fines of up to 100 monthly tax units ( unidad tributaria mensual , or UTM) for minor infringements, up to 5,000 UTM for seri - ous infringements, and up to 10,000 UTM (USD725,000) for very serious infringements; • triple fines in cases of recidivism; • charge fines of up to 2% or 4% of the annual revenues of large companies in cases of recidivism of serious or very serious infringe - ments (with ceilings of 10,000 and 20,000 UTM – USD725,000 and USD1,450,000, respectively); • suspend the processing of data for up to 30 days, as an accessory sanction; and/or • register the sanctioned parties and the respective sanctions in the National Register of Sanctions and Enforcement (the records of which will be publicly accessible for five years). 1.4 Data Protection Fines in Practice Due to the fact that a protection system based on judicial logic is currently in force, there is no precedent of relevant administrative sanctioning procedure in this jurisdiction. This will eventually
58
CHAMBERS.COM
Powered by FlippingBook