REGULATORY STATUS ·
Will Chile postpone Law 21,719? What we know, and what to do meanwhile
The question has changed. Until July, clients asked how long until 1 December; now they ask whether that date will exist at all. The honest answer, as of 18 August 2026: 1 December 2026 is still the legal calendar, and there are concrete reasons to think it may move.
The timeline, without adjectives
- 13 December 2024. Law 21,719 is published in the Official Gazette, with deferred entry into force on 1 December 2026.
- May 2026. The Senate rejects the slate of nominees for the governing board of the Personal Data Protection Agency.
- June 2026. The legal deadline to appoint the board members lapses — six months before entry into force.
- August 2026. The executive acknowledges it is evaluating a postponement. One material question is still open: whether a delay would cover the whole law or only the Agency’s start-up. No decision has been taken and no bill has been filed.
Chile’s association of data protection professionals (AGPD) has publicly asked that any postponement be capped at six months, with the governing board appointed no later than 1 December 2026.
Why this is not an extension of your plan
1. The other regulator is already enforcing. Law 21,663 created the National Cybersecurity Agency (ANCI), operating since January 2025. It has issued general instructions on registration, the cybersecurity officer and incident management, and in July 2026 it closed the first qualification process for Operators of Vital Importance: 1,154 institutions. If your company is on that list, you have obligations enforceable today, with fines up to 40,000 UTM. See Law 21,719 and Law 21,663: two regimes, one operation.
2. Your customers are not waiting for the Agency. Data protection clauses are already appearing in contracts and tender documents. A processor that cannot produce its record of processing activities loses the contract long before any regulator shows up.
3. None of the work is wasted. The record of processing activities, the review of lawful bases, processor agreements, the breach procedure and the lifecycle of sensitive data are internal work that does not depend on the Agency existing. If the date moves, the work still stands; if it does not, you arrived on time.
The one decision worth revisiting
If you had a large spend timed precisely to 30 November — an external certification, a full-time DPO hire, a tooling rollout — sequence it: first what pays off either way (discovery, RoPA, contracts, breach process), then what only makes sense with a functioning Agency (formal interaction and notification procedures before it).
What we will do on this site
We are keeping the countdown and the 1 December 2026 date because that is the law in force, and we publish the real status of the calendar next to it, with a review date. If a bill is filed, we update this page the same day.
Sources. Actualidad Jurídica / DOE, 4 Aug 2026 · Diario Financiero · trendTIC, 18 Aug 2026 · AGPD, via ESG Hoy · ANCI, close of the first OIV qualification process
NEXT STEP
Want to know how this applies to your company? The free self-assessment gives you your gap map in 10 minutes.
Free self-assessment →