Skip to content
Octo Inc. — Data Protection Unit
Octoberus DATA

RESOURCES · LAW 21,663 / ANCI

Two regimes, one operation

Data protection and critical-infrastructure cybersecurity arrived in Chile through different laws, with different regulators and different clocks. In practice they meet on the same systems — and one of the two is already enforcing.

Side by side

What each law asks for

Dimension Law 21,719 — personal data Law 21,663 — cybersecurity
What it protects People's personal data The continuity and security of essential services
Who enforces Personal Data Protection Agency (still without a governing board) National Cybersecurity Agency — ANCI, operating since January 2025
Who it applies to Every company processing personal data in Chile Essential services and Operators of Vital Importance (OIV) designated by resolution
In force since 1 December 2026 (current calendar; under review) Enforceable today
Incident notification Without undue delay, to the Agency and to affected data subjects where applicable Early warning ≤ 3 h · update ≤ 24 h (OIV) or ≤ 72 h · final report at 15 days
Maximum fine 20,000 UTM, or 2%–4% of annual revenue for repeat offences 20,000 UTM, and up to 40,000 UTM if the offender is an OIV
Mandatory role Data protection officer, where applicable Cybersecurity officer

LAW 21,719 DOES NOT SET A 72-HOUR BREACH DEADLINE — THAT CLOCK BELONGS TO THE GDPR AND TO THE LAW 21,663 REGIME

ANCI

The regulator already operating

08.04.2024

Law 21,663, the Cybersecurity Framework Law, is published.

02.01.2025

ANCI begins operating.

2025–2026

General Instructions No. 2, 3 and 4: registration, cybersecurity officer and incident management.

24.07.2026

Resolution 187 in the Official Gazette: final second-stage list. With it, 1,154 institutions are designated OIV and the first qualification process closes.

While the Data Protection Agency still has no governing board, ANCI has closed its first full designation cycle. For a critical-infrastructure company, today's real order of urgency is the reverse of what the 1 December countdown suggests.

Power sector

And on top of that, a third standard: NERC-CIP in the SEN

Companies in Chile's National Electrical System did not wait for either law: since 2020 they have had their own sector standard, built on NERC-CIP, with an annual compliance report to the Coordinator.

Cybersecurity Standard for the SEN

The SEC instructed the National Electrical Coordinator to draft it (official letters from 2018 and 2019); the Coordinator adopted NERC-CIP with technical support from CAISO. Pilot phase from October 2020, text updated October 2022.

Scope

The Coordinator and coordinated companies, according to each facility’s High / Medium / Low impact rating. Thirteen CIP standards, CIP-002 through CIP-014.

Annual report

Each Responsible Entity reports its compliance level per requirement to the Coordinator within the first quarter of each year, signed by the CIP Officer.

Evidence

Evidence and control records are retained for at least 3 years. The Coordinator may order audits by specialised third parties.

The overlap

One system, three demands

PHYSICAL ACCESS CONTROL

To the SEN standard, your physical access control system protects the perimeter of your critical systems — and the system itself is an asset that must be monitored, tested and maintained.

PERSONAL DATA

To Law 21,719, that same system is a personal database: names, national IDs, licence plates, fingerprints and faces, with records of where each person was and when. If it uses biometrics, it processes sensitive data.

INCIDENTS

A single event — an unauthorised entry, a leak of the access log — can start three clocks at once: ANCI, the Data Protection Agency and the Coordinator. The evidence, however, is produced only once.

HOW WE WORK ON THIS

Octo has run physical access control at critical facilities since 2022, and data protection as a service. We do not do network monitoring, SOC or penetration testing: we do access — physical and digital — and the compliance that hangs off it.

Sources

Where each figure comes from

INFORMATIONAL CONTENT · NOT LEGAL ADVICE