Our Compliance Group Director, Yoab Bitran, and New Technologies and AI Group Director, Juan Pablo González, spoke exclusively with LexLatin about the main challenges facing companies in Chile in light of the new Personal Data Protection Law and the advancement of artificial intelligence.
On December 1, 2026, the new Personal Data Protection Law (Law 21,719) will take effect in Chile, replacing Law 19,628 and significantly raising the requirements for organizations that collect, store, and use personal information. The law strengthens data subjects’ ARSOP rights (access, rectification, erasure, objection, and portability), incorporates traceability obligations, and establishes a Personal Data Protection Agency with oversight powers.
That is the legal framework. The question now is different: Are Chilean companies truly prepared for the new law to take effect?
According to Yoab Bitran, director of the Compliance Group at az, most Chilean companies are still working to identify and correct gaps in their internal processes. Regulated sectors, particularly the financial and healthcare sectors, are further along in meeting some of the obligations established by the new regulations. For the rest of the organizations, the spokesperson states, the work is still in the early stages.
“Although it is not a direct requirement under personal data regulations, mapping the personal data that organizations process is a valuable tool, as it allows them to identify the types of personal data being used and, based on that, take measures to address any risks associated with the use of this information. Many of these actions help organizations meet their legal obligations. Undoubtedly, safeguarding data subjects’ rights (ARSOP) is a tremendous challenge to address in a timely and proper manner,” he emphasizes.
Agency and Regional Leadership: Chile’s Two Challenges
The notion that the market should be prepared simply because the law was published two years ago does not reflect reality. For some organizations, adapting the processes for collecting, storing, and using personal data represents a cultural shift that is only just beginning.
Added to this is the establishment of the Personal Data Protection Agency, which will be responsible for overseeing the new regime. However, the formation of its Board of Directors is proceeding more slowly than originally scheduled, which could mean that the new authority will be fully operational almost at the same time that the obligations it is tasked with supervising come into effect.
Bitran notes that industry and the public sector expect the agency to play a guiding role and foster a culture of data protection in a country where, despite the existence of a law in force, the processing of personal information has not always received the attention that the reform demands.
“It is expected that, once it is established, it will be able to provide some guidelines and answers to questions that were not fully resolved in the approved regulations, before it begins an enforcement process, similar to international experience, for example, in Brazil,” he says.
In his view, once that initial stage is complete, the agency should move forward with oversight processes, particularly in sectors with aggressive business practices that may not comply with the new data protection regime.
In the regional context, Chile has a head start. Juan Pablo González, director of New Technologies and AI at az, believes that the regulatory update allows the country to rapidly advance toward the top ranks in Latin America.
“Notwithstanding this, much will depend on the ability to enforce the approved regulations. Chile does not have specific regulations on artificial intelligence, and although a bill on the subject is currently under consideration, there are several voices that believe it is necessary to address certain issues before establishing a mature regulatory framework for a technology such as AI. This analysis of preliminary issues mirrors what has happened in Europe, with the postponement of certain obligations under the European AI Regulation and proposed amendments to the regulations on personal data protection—particularly in support of small and medium-sized enterprises,” he explains.
Risks of Artificial Intelligence in Businesses
As companies prepare to comply with the new data protection regulations, artificial intelligence presents a challenge that is no longer solely the concern of the IT department. According to the latest report from global management consulting firm McKinsey, 78% of corporations actively use generative AI in their business processes, and this widespread adoption has turned algorithms into a source of operational, reputational, and regulatory risk all at once.
Global figures from IBM’s Cost of a Data Breach Report 2025 warn that the adoption of AI is outpacing security measures and corporate governance:
- 13% of companies have already reported security breaches linked to artificial intelligence applications.
- 97% of the compromised firms did not have access policies for their models.
- 8% were unsure whether their AI systems had been compromised.
- The average cost of an AI-related breach is US$670,000.
Added to this is the phenomenon known as “Shadow AI,” which involves the informal use of artificial intelligence tools by employees without the organization’s authorization or supervision, making data protection an integral part of technology governance.
In Chile, the situation is exacerbated by a local statistic: in 2025, the country faced nearly 8.8 trillion cyberattack attempts, and 16% of data breaches are already being perpetrated by cybercriminals who use AI to enhance their attacks.
In this context, Chile’s regulatory framework is structured around two laws that are beginning to interact with one another. On the one hand, the Cybersecurity Framework Law (Law 21.663) requires operators of critical importance to adhere to strict risk management standards and to report incidents within specific timeframes. On the other hand, Law 21.719 imposes stricter penalties for the improper handling of personal data—a critical consideration given that many artificial intelligence systems are trained using sensitive information that must be subject to additional protective measures before it can be used.
Compliance and Governance: A Roadmap for Companies
The challenge, however, does not end with the content of the regulations. To integrate this new landscape into their day-to-day operations, companies will need to review how they manage information and make decisions regarding the use of new technologies. This is a shift in approach that goes beyond simply updating internal policies.
Bitran argues that, although mapping personal data is not an explicit requirement of Law 21.719, it has become a key tool for any organization that wants to anticipate risks and comply with the new requirements. In this regard, he proposes steps for a technical assessment within the framework of corporate governance:
- understand in which processes the organization processes personal data;
- identify which artificial intelligence systems it uses and for what purposes;
- define access controls, as well as encryption in transit and at rest;
- update policies, procedures, and contractual clauses with suppliers;
- redefine roles and responsibilities within the organization to manage risk.
González recommends establishing multidisciplinary committees where decision-makers can discuss the risks associated with AI use at an early stage, and implementing metrics to measure the technology’s performance in specific use cases—a factor that, in his view, ultimately makes the difference between adopting AI in a controlled manner and adopting it blindly.
“This will undoubtedly enable an organization to successfully integrate this type of technology and achieve measurable results, especially in processes that may be critical, depending on the organization’s risk appetite,” he adds.
Artificial Intelligence Regulation
While the implementation of Law 21.719 is moving forward within an already defined regulatory framework, the regulation of artificial intelligence in Chile is still under discussion. The Executive Branch presented a draft AI Framework Law to the Senate, inspired by the European AI Regulation, which classifies systems according to their risk levels.
The director of New Technologies and AI at az has closely followed this discussion and argues that the European model does not necessarily address Chile’s specific needs.
“This framework addresses certain types of AI risks, which are not necessarily the same as those we need to regulate in Chile—particularly in terms of use cases. In that regard, the industry raised several points to be considered in the parliamentary debate, seeking to focus on incentives for advancing the AI development industry by regulating uses rather than the technology itself. The main objective is to avoid regulation that restricts technological development,” he states.
The European experience has become one of the main arguments put forward by those calling for a review of the scope and timeline of the Chilean proposal. The postponement of certain obligations under the European regulation has highlighted the difficulties of implementing a complex regulatory framework without giving companies and authorities sufficient time to adapt.
González notes that the fundamental debate centers on whether regulation should focus on the technology itself or on the ways it is used. This decision will determine which companies will be subject to stricter requirements and under what criteria. For this reason, the corporate legal sector is closely monitoring the progress of the bill, which will establish the rules for the development and use of artificial intelligence in Chile.
Impact on SMEs
The impact on smaller companies is one of the issues causing the greatest concern. If the proposed AI Framework Law maintains the classification of systems based on their risk level, companies could face new requirements, such as risk management systems, periodic assessments, technical documentation, human oversight, and standards for cybersecurity, accuracy, and technical robustness. The question is how SMEs will be able to meet these requirements.
“One of the concerns raised during the discussion is that while large companies may be able to handle these changes, for SMEs these obligations may entail costs that cannot be offset by early implementation within the organization, especially in an environment with diverse regulatory requirements. Ultimately, the bill does not establish any support system for this sector of the industry,” Bitran points out.
The bill, as currently being debated in the Senate, does not distinguish between multinational corporations and SMEs when it comes to fulfilling obligations related to risk management, technical documentation, and cybersecurity. In terms of personal data protection, however, Law 21,719 did establish a grace period for smaller companies, which during the first year of enforcement will only be subject to warnings and not fines. When it comes to artificial intelligence, for now, that distinction does not exist.
Despite the challenges, both az spokespeople agree that companies that act proactively will have an advantage. Bitran believes that incorporating artificial intelligence early on—by identifying its risks and analyzing them with the various departments within the organization—allows companies to make better use of the technology and reduce their exposure to incidents that could result in reputational damage, lost time, and penalties.
The challenge for Chile will be to maintain the progress made in personal data protection while, at the same time, developing artificial intelligence regulations that take into account the country’s specific circumstances. In this discussion, small and medium-sized enterprises (SMEs) emerge as one of the main outstanding issues.




