Logo AZ - 35 Años entregando soluciones legales

New Regulations on Model Rules for the Prevention of Violations in Personal Data Protection

Sep 10, 2026

The internal regulations resulting from the program must be expressly incorporated as an obligation in employment or service agreements.

On August 28, 2026, the Comptroller’s Office acknowledged Decree No. 662, which regulates the implementation, certification, registration, and supervision of “Infraction Prevention Models” (MPI), as provided for in Article 49 of Law No. 21,719, which amends Law No. 19,628 on personal data protection.

The Model, also known as a “compliance program,” may be voluntarily adopted by any data controller, whether a natural or legal person, public or private.

Its implementation does not replace the general duty to comply with the law, but it may serve as a mitigating factor against sanctions imposed by the new Personal Data Protection Agency, provided it is certified in accordance with the terms set forth in the regulations.

Among the elements the program must contain are:

  • The appointment of a personal data protection officer.
  • A description of the data and processing operations carried out by the entity.
  • A risk matrix identifying the processes most likely to result in violations of Articles 34 bis, 34 ter, and 34 quáter of Law No. 19,628.
  • Protocols to prevent violations, as well as internal reporting and complaint mechanisms.
  • The applicable administrative sanctions.

The internal regulations derived from the program must be expressly incorporated as an obligation into the employment or service contracts of all employees and service providers who process data—including top executives—and must be integrated into the internal regulations where applicable, in accordance with Articles 153 et seq. of the Labor Code.

The appointment of the officer will be mandatory for both the adoption and certification of the MPI. This position must be independent of management and may be held by an internal or external individual.

In the case of micro, small, and medium-sized enterprises, the owner may assume this role. Likewise, a single data protection officer may be appointed for an entire business group, provided that all entities operate under the same standards.

The data protection officer’s duties include:

  • Informing and advising the data controller.
  • Participating in the development of the program.
  • Training employees.
  • Advising on risk identification.
  • Serving as the point of contact with the Agency, while maintaining confidentiality regarding any information obtained in the course of their duties.

Furthermore, certification of the Model will be the responsibility of the Personal Data Protection Agency; it will be processed in accordance with Law No. 19,880 and will be valid for three years, renewable. Certificates will be entered into a publicly accessible National Registry of Sanctions and Compliance.

The Agency may monitor compliance with certified models and revoke certification on well-founded grounds if the data controller violates the regulations or is sanctioned for violations of Articles 34 bis, 34 ter, or 34 quáter of the law, in addition to other grounds such as the dissolution of the legal entity. Any entity whose certification is revoked may apply for a new one by demonstrating that it has remedied the violations.

One point to keep in mind is that the responsible party may only publicize that its program is certified by directly referencing the National Registry of Sanctions and Compliance; this shall not constitute advertising but solely serves to provide information to third parties.

In conclusion, and in anticipation of the entry into force of Law No. 21,719, these regulations—eagerly awaited by all stakeholders in the field—provide a concrete and operational framework for the design, implementation, and preparation for the certification of a compliance program regarding personal data protection.

For more information on these topics, please contact:

Rodrigo Albagli | Partner | ralbagli@az.cl

Yoab Bitran | Director, Compliance Group | ybitran@az.cl

Juan Pablo González | Director, New Technologies and AI | jgonzalez@az.cl

Loreto Osorio | Associate | losorio@az.cl

Sebastián Achondo | Associate | sachondo@az.cl


Be part of our multimedia platform and you can receive the latest legal news, events, podcazt and webinars.

Subscribe to our Newsletter here.

Te podría interesar