Logo AZ - 35 Años entregando soluciones legales

Is Your Company Ready? 10 Key Questions for Management About the New Data Law

Jul 9, 2026

Data protection is no longer just a legal issue; it has become a strategic priority for senior management.

The entry into force of Chile’s new Personal Data Protection Law on December 1 requires organizations to understand what data they collect, how they use it, what their responsibilities are, and what risks they face in the event of noncompliance.

Below, we present 10 key questions that every management team should ask itself to continue moving toward responsible management in compliance with the new regulation.

If my company is B2B, do I still have to comply with the law?

Yes. Even if your business is B2B, you still process personal data (for example, from employees, job candidates, business contacts, or suppliers). The law applies whenever data pertaining to individuals is involved.

What types of personal data does my company currently process?

You must identify whether you process identifying data (name, tax ID number, and email address), employment data, and contact information, as well as categories that require enhanced protection, such as sensitive data (e.g., health information or internal complaints), data on children and adolescents in the context of family responsibilities and benefits, and biometric data—for example, in time-tracking systems.

Do I always need consent to process data?

No. There are different legal bases for data processing. In the workplace, processing is often based on the employment contract or legal obligations. The key is not to hinder business operations, but to correctly identify the applicable legal basis in each case. Consent is particularly relevant for sensitive data or non-necessary processing, especially considering that it can be revoked at any time.

What happens if I use platforms or providers (SaaS)?

If a third party processes data on your behalf, you must sign a Data Processing Agreement (DPA) and ensure that it complies with, among other minimum requirements, confidentiality obligations, appropriate security measures, purpose limitation, incident notification, and regulations governing subprocessors.

Can I freely use data from public sources?

No. Under the new regulations, the fact that data comes from publicly accessible sources no longer constitutes, on its own, a valid legal basis for processing; therefore, you must still have a legal basis for processing it.

What risks do I face if I don't comply?

Primarily, administrative penalties of up to 20,000 UTM, along with measures such as the suspension of operations. Added to this are reputational damage and an increasingly stringent oversight standard under the new regulatory framework.

Do I need to have internal policies?

Yes. It is essential to have data processing policies (for employees, job candidates, and others), contractual clauses, and clear procedures. Furthermore, the regulations require that certain information be made available to the public through a valid communication channel, in accordance with the principle of transparency and disclosure, regardless of whether adopting a formal governance model is optional.

What happens to the data when an employee leaves?

You cannot retain it indefinitely. You must establish retention periods and delete or anonymize the information when it is no longer necessary, subject to legal obligations.

When do the new law and the agency take effect?

The law takes effect on December 1, 2026. As for the Personal Data Protection Agency, its implementation will be phased in, and its members must be appointed; therefore, its effective operation and enforcement capacity will be established in the coming months.

Where do I start if I want to comply?

The first step is to conduct a gap analysis to identify what data you process, for what purpose, and with which vendors, in order to establish a data protection governance framework. Next, move forward with implementing policies, contracts (DPAs), consent forms, and security measures.

Preparing for the new regulatory landscape not only helps reduce legal and reputational risks but also strengthens the trust of employees, customers, suppliers, and business partners.

Finally, it is essential to have an assessment and an action plan that will allow you to more confidently address the challenges posed by the law that will take effect in December of this year.

For more information on these topics, please contact:

Yoab Bitran | Compliance Group Director | ybitran@az.cl

Juan Pablo González | New Technologies and AI Director | jgonzalez@az.cl

Antonia Nudman | Senior Associate | anudman@az.cl

Loreto Osorio | Associate | losorio@az.cl

Sebastián Achondo | Associate | sachondo@az.cl


Be part of our multimedia platform and you can receive the latest legal news, events, podcazt and webinars.

Subscribe to our Newsletter here.

Te podría interesar