
Law No. 21,459 on Computer Crimes and Law No. 21,719 on Personal Data Protection
In response to the increase in cybercrime and the risks associated with processing personal data, Chile has moved to modernize its legal framework with two key regulations:
- Law No. 21,459 (2023): Strengthening of computer crimes, updating the Penal Code to punish new forms of cyberattacks, digital fraud, and identity theft.
- Law No. 21,719 (2024): New Personal Data Protection Law, which raises privacy and security standards, aligning with international regulations such as the European GDPR.
These laws aim to:
- Protect individuals and businesses: against threats such as hacking, phishing, or data breaches.
- Establish clear obligations: for organizations that process personal information.
- Strengthen sanctions for non-compliance: with fines and prison sentences in serious cases.
Law No. 21,459, in force since June 2023, amends the Penal Code and Law 19,223 to modernize and toughen sanctions for computer crimes. These are its key points:
1.New Criminalized Offenses
-
Digital identity theft (Art. 466 quater CP):
-Creating fake profiles or using another person's data to harm them (e.g., phishing, bank fraud).
-Penalty: 61 days to 5 years in prison + fine. -
Non-consensual dissemination of intimate images or data ("revenge porn", Art. 466 quinquies CP):
-Sharing intimate material without authorization.
-Penalty: 541 days to 3 years in prison. -
Attacks on critical systems (public infrastructure, health, energy):
-Aggravated penalty: Up to 10 years in prison if national risk is caused.
2.Modifications to Existing Offenses
-
Illicit access to systems ("hacking", Art. 3 Law 19,223):
-Increased penalties: up to 5 years if there is damage or economic benefit. -
Illegal data interception (e.g., espionage with malware):
-Penalty: 541 days to 5 years. -
Computer fraud (Art. 468 CP):
-Use of technology to defraud (e.g., card cloning).
-Penalty: 541 days to 5 years + fine.
3. Specific Aggravating Factors
Higher penalties if the crime affects:
- Minors.
- Essential public services (hospitals, transportation).
- Large volumes of data (e.g., massive leaks).
4. Corporate Responsibility
Legal entities may be fined if they do not prevent crimes committed by employees or due to failures in their systems.
5. International Cooperation
Chile can collaborate with other countries to investigate cybercrimes (aligning with the Budapest Convention).Why is it important?
- It updates an obsolete law (Law 19,223 from 1993) that did not cover modern crimes.
- It protects victims of cyberbullying, fraud, and attacks on critical infrastructure.
- It strengthens security in digital transactions and privacy.
Law No. 21,719, published in 2024, modernizes Chilean personal data protection regulations (previously governed by Law 19,628 of 1999), aligning with international standards such as the GDPR (General Data Protection Regulation of the EU). These are its key points:
1. NEW RIGHTS FOR DATA SUBJECTS
- Access and portability: Request a copy of their data in digital format.
- Rectification and update: Correct inaccurate information.
- Erasure ("right to be forgotten"): Request the deletion of data when it is no longer necessary.
- Objection to processing: Refuse to have their data used for specific purposes (e.g., marketing).
2. OBLIGATIONS FOR COMPANIES AND INSTITUTIONS
- "Privacy by design" principle: Implement security measures from the outset when creating systems that process data.
- Impact assessments: Risk analysis when sensitive data is processed (e.g., health, sexual orientation).
- Breach notification: Inform affected parties and the authority (Data Protection Agency) in case of leaks.
- Explicit and informed consent: Must be free, specific, and revocable (pre-ticked boxes are not valid).
3. CREATION OF THE DATA PROTECTION AGENCY (APDP)
- Autonomous body that will oversee compliance with the law.
- May impose fines of up to 20,000 UTM depending on the severity of the infringement.
4. SPECIAL CATEGORIES OF DATA
- Sensitive data: Health, biometrics, religious beliefs, sexual orientation, etc. Requires greater protection.
- Data of minors: Prohibited from collecting without parental/guardian consent.
5. INTERNATIONAL DATA TRANSFERS
- Data can only be sent to countries with an adequate level of protection (similar to Chile). If not, contractual clauses or explicit consent are required.
6. SANCTIONS
- Administrative fines: Up to 10,000 UTM for companies.
- Criminal liability: In serious cases (e.g., illegal data sale), there may be prison sentences for direct perpetrators.
Why is it important?
- Chile had an obsolete law from 1999 for the digital age.
- Companies must adapt their processes (e.g., contracts, privacy policies).
- Citizens gain control over their personal information.
Every Geocom employee can find our General Information Policy hosted on our personnel platform, in the section Documents => Information Policies.
Although Law No. 21,719 is in force (published on December 13, 2024), its full application depends on two pending milestones from the State: the regulation that will detail how the law will be applied and that the Personal Data Protection Agency (APDP) is operational. For this, there are key deadlines to consider:
1. PUBLICATION OF THE REGULATION (ART. 4° TRANSITORY):
- The government has until June 14, 2025, to publish the regulation detailing how to apply the law.
2. ENTRY INTO FORCE OF THE APDP (DATA PROTECTION AGENCY):
- The APDP must be operational no later than 2 years from the publication of the law (i.e., by December 2026).
- It will be responsible for oversight and imposing fines.
3. COMPLIANCE DEADLINE FOR COMPANIES:
- The estimated deadline is December 01, 2026.
What is in force is indicated in Article 4 of the Law, which states that the data subject has the right to access, rectify, or delete data, in accordance with the Law, but companies have a margin to adapt. In addition, companies must process data with transparency and security (based on Law 19,628 while the new regulations are implemented).
What is still pending operation and would come into effect by the end of 2026 is the following:
- Fines and sanctions: Until the APDP becomes operational, sanctions under this law will not be applied.
- Specific obligations: Such as impact assessments or 72-hour breach notification, which will be defined in the regulation.
Today, our IT Department, in collaboration with our Cybersecurity advisors, is actively working on the implementation of the key requirements of Law 21,719 on Data Protection. Among the priority actions we are developing are:
1. DATA INVENTORY
- Identification and classification of all personal information we collect and process, ensuring detailed data flow mapping.
2. CONSENT UPDATES
- Review and adaptation of consent mechanisms, ensuring they are explicit, informed, and duly documented according to new legal standards.
3. PRIVACY POLICIES
- Updating our internal and external policies to align with the new rights of data subjects (access, rectification, erasure, and data portability).
4. STRENGTHENING SECURITY MEASURES
- Implementation of data encryption, restricted access controls, and security breach response protocols, in line with privacy by design principles.
We are committed to a proactive approach to ensure regulatory compliance, even before the Data Protection Agency (APDP) becomes fully operational.
NEXT STEPS
- Await the publication of the Regulation (2025) to adjust operational details.
- Ongoing training for teams on the law's obligations.
- Evaluation of suppliers and third parties to ensure compliance throughout the data chain.

Compartir:
KARIN LAW
CRIME PREVENTION MODEL