Data Protection and Privacy 2025

CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados

For this reason, the plan proposes a series of measures that will be adopted by the country until 2030: • A digital tool will be created that will integrate information on energy availability, adequate land use, connectivity and socio-environmen - tal variables to identify strategic areas for the development of data centres. • A reference guide will be published, in Eng - lish and Spanish, detailing the permits and processes required for the construction and operation of data centres in Chile. • A guide will be developed with standardised technical criteria for the environmental evalu - ation of data centre projects in the Environ - mental Impact Assessment Service (SEIA). • The creation of Clean Production Agree - ments between the state and industry will be promoted to improve efficiency in the use of resources and reduce the environmental impact of data centres. • A multi-cloud state model will be promoted that allows the public sector to access and manage cloud services safely and efficiently. • A comprehensive public-private approach will be implemented to promote talent develop - ment and strengthen technical capabilities in industry and public institutions. • The implementation of regional technologi - cal campuses specialised in infrastructure for training AI systems, located in regions with high availability of renewable energy, will be promoted. • Agreements between the state and interna - tional companies will be promoted to guaran - tee access to AI computing infrastructure for Chilean research and development institu - tions. • A strategic committee will be created for the monitoring and evaluation of the plan, with

the participation of local governments, indus - try, experts and communities. 1.6 Interplay Between AI and Data Protection Regulations Public Sector The circular with the “Recommended Guidelines for the Use of AI by State Agencies” states that the processing of personal data, especially of a sensitive nature, when using AI tools should ensure compliance with Law No 19.628 on pri - vacy protection and its amendments (the “New Law”), in particular to ensure that data processed for the development, training or use of AI tools is used exclusively for the purposes authorised by the data subjects or by law. Likewise, the circular recommends that person - al information, especially of a sensitive nature, should not be entered in generative AI tools, when these have not been contracted or devel - oped by or for the state administration. In this regard, special care should also be taken with the confidential information of legal persons to which the administration has access. Bill Regulating AI Systems Since May 2024, the draft law filed by the gov - ernment regulating AI systems has been under discussion in the Chamber of Deputies. The bill is in some respects inspired by the EU AI Act, especially when classifying the risk levels of the uses of AI systems (unacceptable/prohibited risk; high risk; limited risk; no evident risk). In terms of personal data protection, the bill contemplates the principle of data governance, which would translate into specific obligations for operators of high-risk AI systems (eg, infor - mation management systems). In addition, the bill establishes that the Personal Data Protec - tion Agency would be the supervisory authority

61

CHAMBERS.COM

Powered by