CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
As for the appointment of the data processing officer (DPO), while the GDPR establishes a man - datory nature for this appointment, based on the type of entity and the processing activities, the Chilean regulation links it to the voluntary adop - tion of a prevention model. In other words, in Chile, the appointment of a DPO is only manda - tory if a prevention model is voluntarily adopted. 3.4 Regulators and Enforcement For more details on the control authorities cur - rently in force regarding personal data protection in Chile, see 1.2 Regulators . On the other hand, the Personal Data Protec - tion Agency, created by Law No 21.719, which will come into operation in December 2026, will be an autonomous, technical and decentralised entity that will have the objective of protecting the personal data of people in Chile. Powers of the Personal Data Protection Agency • Regulation: It will issue instructions and general rules to regulate the processing of personal data, ensuring compliance with the law. • Supervision: It will supervise entities to ensure they comply with the law and its regulations in the processing of data. To do so, it may require those who process personal data to provide any document, book or record and other information that is necessary for the fulfilment of its supervisory function. • Sanctioning: It may sanction those who violate the law or its regulations. For more information, see 1.3 Enforcement Proceed- ings and Fines . • Conflict resolution: It will address requests and claims from data subjects against those who violate the law.
• Education: It will promote citizen awareness on the protection of personal data. • Consulting: It will provide technical assistance to other state agencies in the implementation of data protection policies. • Co-operation: It will collaborate with national and international entities in data protection. • Certification: It will certify infringement pre - vention models and compliance programmes regarding personal data. Under both the current law and the New Law that will come into force in December 2026, if cookies collect personal data, they can be con - sidered as data processing, so companies that place cookies will require the consent of the data subject (with some exceptions, or using other bases of lawfulness of data processing) and must comply with the general rules for the processing of personal data. See 3. Data Regu- lation on IoT Providers, Data Holders and Data Processing Services . 4.2 Personalised Advertising and Other Online Marketing Practices Law No 19.496 on the Protection of Consumer Rights contains a provision regarding marketing through email. Every promotional or advertising communication sent by email must indicate its subject, the identification of the sender, and a valid email address to which the recipient can address their request for the suspension of the advertising communication, which will remain banned from then on. Providers that direct promotional or marketing communications to consumers via mail, fax, telephone calls or messaging services must 4. Sectoral Issues 4.1 Use of Cookies
66
CHAMBERS.COM
Powered by FlippingBook