CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
For its part, according to the New Law, it is not necessary to request authorisation from the Personal Data Protection Agency to carry out an international transfer of data, except when some of the specific requirements under which it is legal to carry out this type of activity have not been met. 5.3 Data Localisation Requirements Currently, the Law does not establish data locali - sation requirements, nor does the New Law pro - vide for such limitations. However, under Chapter 20-7 of the Updated Compilation of Standards (“RAN”) on the out - sourcing of services by financial institutions (especially banks), the data, technological plat - forms, and applications to be used in the out - sourcing of services must be located at specific processing sites, and in the case of processing abroad, in a defined and known jurisdiction. In addition to jurisdiction, the city where the data centres operate is also required. For the purpose of contracting any type of ser - vice through the modality called cloud comput - ing, the board of directors of a financial insti - tution must pronounce annually about the risk tolerance that the financial institution is will - ing to assume in this type of outsourcing. This pronouncement must consider an analysis of the data to be stored or processed under this modality and its location. Without prejudice to the due fulfilment of the dif - ferent requirements contained in Chapter 20-7, financial institutions may outsource their non- critical services to the public or private cloud. If the financial institution evaluates the contracting of a cloud service for an activity considered stra - tegic or critical, this may also be carried out in public or private cloud mode. However, in these
cases, the financial institution must carry out an enhanced due diligence of the provider and the service. 5.4 Blocking Statutes There are no blocking statutes in Chile. 5.5 Recent Developments The New Law, which will come into force in December 2026, regulates international trans - fers of personal data in a specific manner, unlike the current Law in force. Thus, international data transfers will be legal in the following cases: • when the recipient of the data is in a country with adequate levels of data protection; • when the transfer is covered by contractual clauses or other legal instruments; and • when the data controller and the recipient adopt a compliance model or certification mechanism. In the absence of an adequacy decision or ade - quate guarantees, a specific and unusual trans - fer may be made in the following cases: • with the express consent of the data subject; • for bank, financial or stock market transfers; • to comply with international obligations; • for international judicial co-operation; • for the conclusion or execution of a contract; and • for urgent measures in medical or health mat - ters. The Personal Data Protection Agency will be responsible for determining which countries have adequate levels of data protection. A country’s legal system will be deemed to have adequate levels of data protection when it meets standards similar to or higher than those of Chile, taking into account at least whether the
69
CHAMBERS.COM
Powered by FlippingBook