Data Protection and Privacy 2025

CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados

• to the processing of data carried out by natural persons in relation to their personal activities. With regard to the territorial scope of application, it applies: • to a data controller or data processor estab - lished or incorporated in national territory; • to a data processor who processes personal data on behalf of a data controller established or incorporated in the national territory; • to a data controller or data processor not established or incorporated in national ter - ritory, but whose personal data processing operations are intended to offer goods or services to data subjects who are in Chile, or to monitor their behaviour, including analy - sis, tracking, profiling or prediction of their behaviour; or • to a data controller who, not being estab - lished in national territory, is subject to national legislation as a result of a contract or international law. In addition to the rights to which data subjects are entitled and which they may exercise vis- à-vis data controllers, the following have been added: • the right not to be subject to automated indi - vidual decisions (Article 8 bis); • the right to block (Article 8 ter); and • the right to data portability (Article 9). 3.2 Interaction of Data Regulation and Data Protection Currently, in Chile, the Law distinguishes between personal data and sensitive personal data. According to the Law, “sensitive data” means personal data that refer to the physical or moral characteristics of persons or to facts

or circumstances of their private or intimate life, such as personal habits, racial origin, political ideologies and opinions, religious beliefs or con - victions, physical or mental health conditions, and their sex life. Sensitive data may not be pro - cessed unless authorised by the data subject, or unless it is necessary for the determination or provision of health benefits, or authorised by law. On the other hand, there is no definition of finan - cial data in the law in force, although there are some rules in this respect. If financial data can be considered as personal data, no authorisation is required if the data originates, or is collected, from publicly accessible sources. Financial data may not be processed in the following cases: • five years or more after the respective obliga - tion became due; • in the case of debts incurred during a period of unemployment; • in the case of data relating to obligations that have been paid or extinguished by other legal means; and • in the case of debts relating to electricity, water, telephone, gas and roads. However, the New Law that will come into force in December 2026 brings with it more specific applicable rules for certain categories of per - sonal data, including sensitive personal data, such as biometric data, health data and human biological profile data, as well as special rules for the personal data of children and adolescents, historical or statistical data, and location data. 3.3 Rights and Obligations Under Applicable Data Regulation The Law in Force As there is currently no specialised data protec - tion supervisory authority, the obligations under the current law have little or no oversight. SER -

64

CHAMBERS.COM

Powered by