Data Protection and Privacy 2025

CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados

NAC has now taken action against WorldCoin, but at the national level this is practically an anecdotal case. See 2. Privacy Litigation . Among the obligations for data controllers, the following stand out: to adopt security measures; to respond to requests from data subjects; and to use personal data only for the purposes for which it was collected. However, there are no specific rules that regulate in detail the duties and obligations of data controllers, except at the sectoral level depending on the instructions or powers of the supervisory authorities, for exam - ple, in banking and finance or in the public sec - tor. The New Law From December 2026 when Law No 21.719 comes into force, data controllers will have the following obligations: • to inform and make available to the data subject the background information that proves the lawfulness of the data processing it carries out; • to ensure that personal data is collected from lawfully accessible sources for specific, explicit and lawful purposes, and that the processing is limited to the fulfilment of these purposes; • to communicate or transfer, in accordance with the provisions of the law, accurate, com - plete and current information; • to suppress or anonymise the personal data of the holder when this was obtained for the execution of pre-contractual measures; and • to comply with the other duties, principles and obligations of the law. A data controller who is not domiciled in Chile, and who processes the data of persons residing in Chile, must keep an email address or other

suitable means of contact updated and opera - tional in order to receive communications from the data subjects and the Agency. In addition, the following duties applicable to both data controllers and data processors are regulated (with some exceptions): • the duty of secrecy or confidentiality; • the duty of information and transparency; • the duty of protection by design and by default; • the duty to adopt security measures; and • the duty to report breaches of security meas - ures. In the event of data processing through a data processor, the considerations contained in Arti - cle 15 bis of the New Law must be complied with and addressed. Thus, such processing must be governed by the contract entered into between the data controller and the data processor and must contain the special elements set out in that provision. Furthermore, where it is likely that a type of pro - cessing, by its nature, scope, context, technol - ogy used or purposes, is likely to put the rights of data subjects at high risk, the controller must, prior to starting processing operations, carry out a personal data protection impact assessment. Finally, unlike the GDPR, the Chilean regulation will provide for a voluntary infraction prevention model, consisting of a compliance programme that will have to be certified by the Agency. The certification of this model will help to reduce the amount of the fine in case of infraction, as it was contemplated as an attenuating circumstance of liability.

65

CHAMBERS.COM

Powered by