Chile’s comprehensive personal data protection reform under Law No. 21.719 is scheduled to take effect on 1 December 2026. A subsequent amendment through Law No. 21.806 adjusted certain transitional rules, including a requirement that the new Personal Data Protection Agency be established six months before the law’s entry into force. Under the revised mechanism, if the Senate does not act on the list of candidates proposed by the President, the nominations are deemed accepted and the agency’s Directing Council can be formed without further formalities.
As of early August 2026, that appointment process remains incomplete. Two earlier candidate lists failed to advance, and no new shortlist has been publicly presented. The delay has generated noticeable concern across both the domestic public and private sectors, as well as among international companies evaluating entry into the Chilean market and closely tracking the evolving regulatory landscape.
What Is Certain: The Law Will Apply from 1 December
Despite the outstanding institutional question, one fact is fixed: on 1 December 2026 the reformed rules will apply to virtually all personal data processing activities in Chile, whether carried out by public or private entities (subject only to the limited exceptions contained in the statute itself). Organizations will be expected to comply regardless of whether the new Agency has been fully staffed and operational by that date.
This creates particular pressure for industries that lack a dedicated sectoral regulator and therefore have fewer existing guidelines to draw upon. Small and medium-sized enterprises face additional challenges, given the volume of other regulatory obligations they already manage and the operational adjustments a modern data-protection regime typically requires.
Organizations Are Already Moving Toward Compliance
In the absence of detailed implementing guidance from a fully constituted Agency, many organizations have begun adapting their internal processes. Formal written policies and procedures alone will not be sufficient. The law demands substantive, operational measures that address how personal data is actually used—covering not only customers and third parties, but also employees and other internal stakeholders.
A practical starting point is an internal diagnostic or gap assessment that maps current data-processing activities against the obligations that apply to controllers and processors under the new framework. Organizations that already employ a risk-based approach can leverage that methodology to identify higher-priority areas—those involving large volumes of data or particularly sensitive categories—and to design preventive controls accordingly.
Self-Regulation and Program Design as Interim Tools
While waiting for the Agency’s leadership to be appointed and for clearer official guidance to emerge, self-regulatory tools remain useful. Privacy programs or formal models aimed at preventing infractions can help organizations structure their efforts. Articles 49 and 50 of the reformed law set out minimum content that can serve as a reference when identifying routine or occasional activities that may create compliance risk. For processing that poses a high risk to the rights and freedoms of data subjects, a full impact assessment will be required.
These steps allow an organization to demonstrate tangible progress, to develop a concrete work plan that operationalizes its privacy program, and to keep senior leadership informed of the status of implementation. Such documentation will be valuable both for internal governance and for any future interactions with the Agency once it is fully established.
Looking Ahead
The most immediate outstanding issue remains the appointment and installation of the Personal Data Protection Agency’s Directing Council. Until that occurs, organizations lack a dedicated supervisory body to issue interpretive guidance, answer practical questions, or provide official expectations on implementation timelines and priorities.
Nevertheless, the effective date of 1 December 2026 is not contingent on the Agency’s readiness. Controllers and processors that process personal data in Chile—or that plan to do so—should continue advancing their internal readiness work. Mapping data flows, aligning practices with the new obligations, embedding risk-based controls, and documenting progress will position organizations to meet the law’s requirements on day one and to engage constructively with the Agency once it begins operations.