Breaking down data rules from around the globe

Privacy laws

Chiles New Data Protection Law

Chile’s New Data Protection Law: A Website Tracking Readiness Guide

Chile’s personal data Protection Law 21.719 was published on December 13, 2024, and will enter into force on December 1, 2026, replacing the legacy Law No. 19,628.

Law No. 21.719 significantly reforms Chile's personal data protection framework: it strengthens individuals' rights, introduces new obligations for organizations, and creates a dedicated Personal Data Protection Agency.

The law will regulate websites, apps, advertising platforms, and digital services, setting requirements for how visitor data could be collected and used. It will affect analytics technologies, advertising pixels, cookies, device identifiers, geolocation technologies, profiling systems, and third-party integrations that may process personal data.

Businesses will be responsible for monitoring and adjusting their data management practices to comply with these new regulations and avoid possible penalties for non-compliance.

What Is Chile’s Personal Data Protection Law?

Chile’s Personal Data Protection Law 21.719 (PDPL) is a comprehensive data protection law that protects individuals' personal data in Chile and regulates how public and private entities collect, use, store, and process it.

The new law will enter into force on December 1, 2026.

PDPL replaces the outdated 1999 Law No. 19,628 and brings Chile closer to international privacy standards such as GDPR and LGPD.

The core principles of the law include:

  • Stronger regulation of personal data management by businesses;
  • Introduces broader individual rights.
  • Sets stronger accountability requirements for businesses;
  • Introduces privacy-by-design principle;
  • Introduces a specialized supervisory authority, the Agencia de Protección de Datos Personales (APDP).

 

Chile's Personal Data Protection Agency acts as an independent regulatory, investigative, and sanctioning authority responsible for supervising compliance with Chile’s privacy regulations.

Individuals have rights to access, rectify, delete, object to, and port their personal data, and to request temporary blocking.

That provision is particularly important for websites using behavioral analytics and advertising technologies.

For example, an e-commerce company may be located in Europe or the US, but could still fall within the law if its website targets Chilean customers and tracks their activity for advertising or profiling purposes.

The new framework requires organizations to follow these key principles, including:

  • Data collection lawfulness and fairness;
  • Purpose limitation;
  • Proportionality and data minimization;
  • Data quality;
  • Transparency;
  • Confidentiality and security; and
  • Accountability.

 

In practical terms, businesses should limit their data collection and be transparent with users. Businesses should be able to explain what personal data they collect, why they collect it, how they use it, who receives it, how long they retain it, and the legal basis for the processing.

Does Chile’s law 21.719 affect your business?

Chile’s privacy law applies to your business when it:

  • Is based in Chile, or
  • Offers goods or services to people in Chile, or
  • Processes data of Chilean residents, including tracking, profiling, analysis, and behavioral prediction.

 

The law has an extraterritorial scope: it applies to local entities as well as foreign businesses that offer goods or services to individuals in Chile, or monitor their behavior in Chile, including tracking, profiling, analysis, and behavioral prediction.

In practical terms, the law's extraterritorial scope means many international companies must comply with Chile's data privacy law.

Penalties for non-compliance

Penalties for non-compliance with Chile’s Law 21.719 depend on the severity of the violation.

Administrative fines by tier for small and medium-sized enterprises (SMEs):

  • Minor violations: Fines of up to 5,000 UTM (Monthly Tax Unit in Chile).
  • Serious violations: Fines of up to 10,000 UTM.
  • Very serious violations: Fines of up to 20,000 UTM.

 

In 2026, 20,000 UTM is equivalent to approximately USD 1.5M.

 

For large enterprises, repeat or severe offenses can result in fines of 2% to 4% of the entity's annual revenue from sales and services in Chile during the previous calendar year, whichever is higher.

Repeated offenses involving serious or very serious violations can also triple standard UTM fine amounts.

How Chile’s New Law Changes Cookie, Consent, and Tracking Requirements

Chile’s new Personal Data Protection Law (Law No. 21.719) aligns the digital tracking rules closely with the European Union's GDPR standard.

Key cookie and consent requirements include:

  • Explicit prior consent
    Websites must obtain active, opt-in consent before setting any non-essential cookies, such as analytics, marketing, tracking pixels, or personalization tags.
  • strictly necessary cookies do not need consent
    Cookies that enable security features and core website functions, such as shopping cart contents, user authentication, or session identifiers, do not require user consent when the user explicitly requested the service.
  • Banned practices
    PDPL bans implied consent, pre-ticked checkboxes, and dark patterns. Passive continued browsing and scrolling past a banner do not count as valid consent.
  • Equal banner prominence
    Websites must display cookie banners immediately upon entering the website, offer equal visual “Accept” and “Reject” buttons, and link directly to detailed privacy policies.
  • Granular cookie control
    Users must be able to select specific cookie categories.
  • Consent withdrawal
    Users must be able to withdraw their consent at any time as easily as they gave it.
  • Objection to marketing and profiling
    Users have stronger rights concerning marketing and profiling. Individuals may object to certain processing based on legitimate interests, where their data is processed exclusively for direct marketing and automated processing, including profiling.

 

Businesses using sophisticated personalization, behavioral scoring, audience segmentation, or automated decision systems will be affected. To reach cookie compliance in Chile, obtaining Cookie Consent will not be enough. Businesses should therefore evaluate the entire downstream use of the information those technologies collect.

Scan your website for free to see all your website cookies and other trackers in use.

Which Website Tracking Technologies and Data Practices Need Review

Modern websites often use dozens of third parties that process users’ personal data, sometimes without the website owner's knowledge. Chile’s Law No. 21.719 bans excessive data processing practices, setting requirements for transparency and granting individuals rights to object to marketing and profiling.

Compliance should therefore begin with a comprehensive audit of the website to identify and assess the tracking technologies used by the website and third parties.

Analytics tools

Website analytics platforms often collect IP-related information, device identifiers, browsing behavior, page interactions, referral information, approximate location, session information, and other data.

Businesses should identify what their analytics configuration collects rather than relying on the provider's general description of the service.

Businesses should therefore:

  • Evaluate whether the selected legal basis is appropriate;
  • Identify exactly what data analytics tools collect;
  • Identify whether all collected data is necessary;
  • Minimize IP or other identification tracking;
  • Reduce optional tracking;
  • Shorten retention periods, if possible;
  • Adequately inform users about their tracking.

Advertising pixels and conversion tracking

In Chile, advertising tracking technologies may create higher privacy risks because they can transmit information to external advertising platforms and use it for measurement, audience creation, retargeting, or profiling.

To avoid violating Chile’s new law for improper advertising practices, businesses should:

  • Review social-media advertising tools;
  • Review search advertising technologies;
  • Evaluate affiliate platforms, retargeting services, and programmatic advertising.

 

Pay particular attention to whether tags activate automatically when the page loads or only after users are informed and have given consent.

Third-Party Cookies and SDKs

Third-party code embedded in a website or application can disclose data to third parties without user consent.

Businesses should therefore evaluate:

  • Whether the third party receives information and the categories of information transferred;
  • Whether the provider really needs this information;
  • Where information is processed;
  • Whether the provider acts as a processor or for its own purposes;
  • Whether the contractual protections are in place.

Session replay, heatmaps, and behavioral analytics

Tools that record clicks, scrolling, mouse movements, form interaction, or user sessions can potentially collect much more information than businesses expect.

Businesses should therefore prevent analytics or replay systems from collecting sensitive fields, payment information, authentication credentials, health information, or other high-risk data.

Implement the the data minimization principle and configure the tools yourself rather than relying on the vendor's choices.

Geolocation tracking

Chile's revised law expressly addresses geolocation data.

Where geolocation data is processed, individuals must receive clear and timely information about the type of geolocation information processed, the purpose and duration of the processing, and whether the information will be shared with a third party for a value-added service.

Websites and applications using precise or approximate location information should include geolocation in their data inventories.

Fingerprinting and device identifiers

Chile’s Law 21.719 regulates not only cookies, but also all other identifiers that could reveal user’s privacy.

Browser fingerprinting, advertising IDs, hashed identifiers, and similar technologies can sometimes identify or distinguish individuals even when traditional cookies are not used.

Businesses should evaluate the data processing itself, including whether third parties use fingerprinting and device identifiers, rather than evaluating on whether the technology uses a cookie.

Compliance Requirements under Chile’s Personal Data Protection Law

To reach data privacy compliance in Chile, businesses must establish a valid legal basis, obtain explicit consent, provide transparent privacy information, apply privacy by design and by default, establish clear data policies, review international data transfers, strengthen security and breach processes, and respect data-subject rights.

Controlling website tracking is only one part of the broader compliance framework. Businesses should control the full lifecycle of personal data management and establish policies to comply with Chile’s PDPL.

  1. Establish a valid legal basis
    Every personal data processing activity should have appropriate legal justification. Businesses should therefore obtain valid consent and store it for proof of compliance or document the reasoning behind legitimate interest or another basis.
    Obtain explicit consent through a clear, affirmative action that is not bundled with other purposes or hidden behind ambiguous language. Consent must be freely given, informed, explicit, specific to the processing activity, and revocable. Do not use Pre-ticked boxes.
  2. Provide transparent privacy information
    Organizations should clearly explain their data practices to individuals. Privacy policies must contain information. such as the identity and contact details of the controller, purposes of processing, categories of data, applicable legal basis, recipients, international transfers, retention periods, individual rights, whether the data is used for automated decision-making, and how to withdraw consent or object to automated decision-making.
  3. Honor data-subject rights
    Organizations should establish procedures for receiving, authenticating, processing, and documenting requests related to individuals' privacy rights, and internal procedures for responding to those requests.
  4. Apply privacy by design and by default
    The Law 21.719 expressly requires implementing appropriate technical and organizational measures to respect data subject rights. By default, organizations should process only the personal data that is specifically and strictly necessary, set short data retention periods, and implement methods for responding to data subjects’ requests.
  5. Establish clear data policies
    Establish clear policies on data processing, storage, and sharing. These policies should outline how to obtain and manage consent, the lawful bases for processing personal data, and the purposes for data collection.
  6. Implement a Privacy Policy
    Create and regularly update a comprehensive Privacy Policy that includes mandatory elements, lists all tracking technologies, and provides a privacy notice with an active link to the Privacy Policy.
  7. Review international data transfers
    The new framework establishes requirements for data transfers outside Chile. Organizations should know which vendors receive users’ data, where that information is processed in Chile or travels internationally, which countries the information travels to, and whether those countries provide adequate levels of protection and other safeguards, such as contractual arrangements and approved mechanisms.
  8. Strengthen security and breach processes
    Organizations should implement appropriate safeguards based on the nature of the information and risks involved. Implement procedures for responding to security incidents.
  9. Perform DPIAs for high-risk processing activities
    Data Protection Impact Assessments (DPIAs) are mandatory when an activity is likely to pose high risks to rights and freedoms, such as managing sensitive data, using large-scale profiling, or implementing new technologies.
  10. Sign contracts with service providers
    Organizations using third-party processors remain responsible for meeting legal requirements. Thus, sign contracts with data processors and third-party service providers. Make sure they comply with the PDPL on your behalf.

Implement a Consent Management Platform (CMP) to deliver a cookie notice, obtain and store Cookie Consent, create a Privacy Policy, and respect user consent choices. CookieScript CMP was ranked by users as the best CMP on a peer-reviewed site, G2.

CookieScript CMP has the following features:

Frequently Asked Questions

How does Chile's Law No. 21.719 differ from GDPR?

Chile’s Law No. 21.719 is strongly influenced by GDPR. It emphasizes lawful and transparent processing, purpose limitation, data minimization, security, accountability, individual rights, controls over international data transfers, and introduces rights over personal data. However, it differs on children’s data, sanctions, and regulatory authority. Chile’s Law also includes specific rules concerning geolocation data, financial information, and enforcement procedures.

Who does Chile's new data protection law apply to?

Chile's Law No. 21.719 applies to your business when it is based in Chile, offers goods or services to people in Chile, or processes data of Chilean residents, including tracking, profiling, analysis, and behavioral prediction.

What are consent requirements under Chile's Law No. 21.719?

Websites or apps must obtain explicit prior consent before setting any non-essential cookies. strictly necessary cookies do not need consent. Users must be able to select specific cookie categories and withdraw their consent at any time as easily as they gave it. CookieScript CMP can manage Cookie Consent.

What are the penalties for non-compliance with Chile's new data protection law?

Penalties for non-compliance with Chile’s Law 21.719 depend on the severity of the violation. Fines for small and medium-sized enterprises can range from 5,000 UTM (monthly tax unit in Chile) for minor violations up to 20,000 UTM (approximately USD 1.5M) for very serious violations. For large enterprises, repeat or severe offenses can result in fines of up to 2% to 4% of the entity's annual revenue from sales and services in Chile during the previous calendar year, whichever is higher.

Is Chile's Law 21.719 already active?

Chile's Law 21.719 was published on December 13, 2024, and will become fully effective on December 1, 2026. It replaces the outdated 1999 framework (Law 19.628) and aligns data management practices closely with the European Union's GDPR.

New to CookieScript?

CookieScript helps to make the website ePrivacy and GDPR compliant.

We have all the necessary tools to comply with the latest privacy policy regulations: third-party script management, consent recording, monthly website scans, automatic cookie categorization, cookie declaration automatic update, translations to 34 languages, and much more.