Chile — data protection and AI governance
Ley que regula la protección y el tratamiento de los datos personales (Ley 21.719), in force since 2026-12-01. Supervisory authority: Agencia de Protección de Datos Personales.
Data protection
- Instrument
- Ley que regula la protección y el tratamiento de los datos personales (Ley 21.719)
- In force since
- 2026-12-01
- Authority
- Agencia de Protección de Datos Personales
- Penalties
- Jusqu'à 20 000 UTM (~1,4M USD)
- Key obligations
- Remplace la Ley 19.628
- Basé RGPD (bases légales, droits ARCO+)
- Entrée en vigueur déc. 2026
What the engine decides here
These three attributes are what an agent decision depends on in this jurisdiction. They are modelled, sourced and dated.
- Transfer regime
- Conditional
Moving data out is possible under conditions — a contractual mechanism, a prior assessment or equivalent safeguards depending on the case.
- Localisation mandate
- Not modelled
- Automated decision rights
- Not modelled
- Verified on
- 2026-08-14
Three decisions, computed just now
Same actions, this jurisdiction's context. These answers come out of the engine as the page renders — the same function the API calls.
- ALLOW
Read an internal contract
Low-risk operation
- ALLOW
Send a customer record to US_FED
Low-risk operation
- DENY
Decide on a job application
Decision reserved for a human
Conditional regime: the engine does not require a prior mechanism here. The law may still impose safeguards — contractual accountability, comparable protection at the recipient. The engine does not substitute for them.
Advisory decisions. StructureClerk decides; your infrastructure enforces.
Do your agents operate in Chile?
The authority API makes these attributes executable: an ALLOW, APPROVE, DENY or ESCALATE decision before the agent acts, with signed evidence any third party can verify.