RESOURCES · LAW 21,663 / ANCI
Two regimes, one operation
Data protection and critical-infrastructure cybersecurity arrived in Chile through different laws, with different regulators and different clocks. In practice they meet on the same systems — and one of the two is already enforcing.
What each law asks for
| Dimension | Law 21,719 — personal data | Law 21,663 — cybersecurity |
|---|---|---|
| What it protects | People's personal data | The continuity and security of essential services |
| Who enforces | Personal Data Protection Agency (still without a governing board) | National Cybersecurity Agency — ANCI, operating since January 2025 |
| Who it applies to | Every company processing personal data in Chile | Essential services and Operators of Vital Importance (OIV) designated by resolution |
| In force since | 1 December 2026 (current calendar; under review) | Enforceable today |
| Incident notification | Without undue delay, to the Agency and to affected data subjects where applicable | Early warning ≤ 3 h · update ≤ 24 h (OIV) or ≤ 72 h · final report at 15 days |
| Maximum fine | 20,000 UTM, or 2%–4% of annual revenue for repeat offences | 20,000 UTM, and up to 40,000 UTM if the offender is an OIV |
| Mandatory role | Data protection officer, where applicable | Cybersecurity officer |
LAW 21,719 DOES NOT SET A 72-HOUR BREACH DEADLINE — THAT CLOCK BELONGS TO THE GDPR AND TO THE LAW 21,663 REGIME
The regulator already operating
Law 21,663, the Cybersecurity Framework Law, is published.
ANCI begins operating.
General Instructions No. 2, 3 and 4: registration, cybersecurity officer and incident management.
Resolution 187 in the Official Gazette: final second-stage list. With it, 1,154 institutions are designated OIV and the first qualification process closes.
While the Data Protection Agency still has no governing board, ANCI has closed its first full designation cycle. For a critical-infrastructure company, today's real order of urgency is the reverse of what the 1 December countdown suggests.
And on top of that, a third standard: NERC-CIP in the SEN
Companies in Chile's National Electrical System did not wait for either law: since 2020 they have had their own sector standard, built on NERC-CIP, with an annual compliance report to the Coordinator.
Cybersecurity Standard for the SEN
The SEC instructed the National Electrical Coordinator to draft it (official letters from 2018 and 2019); the Coordinator adopted NERC-CIP with technical support from CAISO. Pilot phase from October 2020, text updated October 2022.
Scope
The Coordinator and coordinated companies, according to each facility’s High / Medium / Low impact rating. Thirteen CIP standards, CIP-002 through CIP-014.
Annual report
Each Responsible Entity reports its compliance level per requirement to the Coordinator within the first quarter of each year, signed by the CIP Officer.
Evidence
Evidence and control records are retained for at least 3 years. The Coordinator may order audits by specialised third parties.
One system, three demands
PHYSICAL ACCESS CONTROL
To the SEN standard, your physical access control system protects the perimeter of your critical systems — and the system itself is an asset that must be monitored, tested and maintained.
PERSONAL DATA
To Law 21,719, that same system is a personal database: names, national IDs, licence plates, fingerprints and faces, with records of where each person was and when. If it uses biometrics, it processes sensitive data.
INCIDENTS
A single event — an unauthorised entry, a leak of the access log — can start three clocks at once: ANCI, the Data Protection Agency and the Coordinator. The evidence, however, is produced only once.
HOW WE WORK ON THIS
Octo has run physical access control at critical facilities since 2022, and data protection as a service. We do not do network monitoring, SOC or penetration testing: we do access — physical and digital — and the compliance that hangs off it.
Where each figure comes from
- Law 21,719, published 13.12.2024; Law 21,663, published 08.04.2024.
- ANCI — close of the first OIV qualification process and Resolution 187, published in the Official Gazette on 24.07.2026.
- National Electrical Coordinator — Cybersecurity Standard for the Power Sector, October 2022 (sections 3, 4 and 7).
- Status of the Law 21,719 calendar: see our article with the timeline and press sources.
INFORMATIONAL CONTENT · NOT LEGAL ADVICE