Law / Chile

Chile

7 of 10 named instruments researched to a stage, across three of the six areas of law we track: 2 in force, 2 enacted but not yet in force and 3 proposed. As of 6 September 2026.

  1. AI law 3
  2. Privacy law 3
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 3 proposed

Research summary (144 words)

Chile has no binding AI-specific law in force as of this date. The advanced measure is Boletín N° 16.821-19, an omnibus bill regulating AI systems on a risk-based model closely following the EU AI Act, which absorbed an earlier bill (Boletín 15.869-19).

It passed the Chamber of Deputies in October 2025 and is in second constitutional procedure before the Senate's Comisión de Futuro, Ciencia, Tecnología, Conocimiento e Innovación. A separate cross-party Senate bill, Boletín 17.618-19, presented July 2025, would require visible labelling of AI-generated content; no primary-source or official-analysis page for it was located, so no instrument is recorded for it here.

The government has also approved Decreto N° 12 of 2024 (published 28 January 2025), updating Chile's National Artificial Intelligence Policy; it is a non-binding strategic policy statement rather than a source of legal duties, so no instrument is recorded for it either.

AI prohibited practices

Boletín 16.821-19, clasificación de riesgo y prohibición de sistemas de IA de riesgo inaceptable

Boletín N° 16.821-19, arts. 5 y 6 (proyecto de ley que regula los sistemas de inteligencia artificial)Biblioteca del Congreso Nacional (BCN)

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Article 5 of this bill classifies AI systems into four risk categories (riesgo inaceptable, alto riesgo, riesgo limitado, sin riesgo evidente). Article 6 bans the market introduction or entry into service of any AI system in the riesgo inaceptable category, defined as incompatible with respect for and guarantee of people's fundamental rights, subject to exceptions for therapeutic and public-safety use.

The bill has passed the Chamber of Deputies and remains under second constitutional review in the Senate; it does not currently bind anyone.

What it requires

AI risk obligations

Boletín 16.821-19, obligaciones para sistemas de IA de alto riesgo

Boletín N° 16.821-19, art. 9 (proyecto de ley que regula los sistemas de inteligencia artificial)Biblioteca del Congreso Nacional (BCN)

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Article 9 of this bill would require an operator of a high-risk AI system to establish a risk-management system, data governance and use of recognized standards, clear technical documentation, a system of usage logs, transparency and human-oversight mechanisms, and accuracy, robustness, and cybersecurity standards, plus contingency measures to disable, withdraw, or recall the system and post-market monitoring.

The bill has passed the Chamber of Deputies and remains under second constitutional review in the Senate; it does not currently bind anyone.

What it requires

AI transparency

Boletín 16.821-19, obligaciones de transparencia para sistemas de IA de riesgo limitado

Boletín N° 16.821-19, arts. 11 y 12 (proyecto de ley que regula los sistemas de inteligencia artificial)Biblioteca del Congreso Nacional (BCN)

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Articles 11 and 12 of this bill would place a transparency duty on limited-risk AI systems (defined as those presenting non-significant risks of manipulation, deception, or error through interaction with natural persons), requiring that a person interacting with such a system be made aware it is an AI system and not a human, with an exception for systems authorized by law for criminal detection, prevention, investigation, or prosecution unless made available to the public.

The bill has passed the Chamber of Deputies and remains under second constitutional review in the Senate; it does not currently bind anyone.

What it requires

Privacy law3 instruments, 1 in force, 2 enacted but not yet in force

Research summary (116 words)

Chile's private-sector personal-data regime is currently Ley 19.628, sobre Protección de la Vida Privada (1999, as amended), a comprehensive statute covering both public and private processing and arming a data subject with a civil damages action against a controller for improper treatment.

Ley 21.719 was enacted in December 2024 to replace it with a General Data Protection Regulation (GDPR)-style regime and create a dedicated supervisory authority, the Agencia de Protección de Datos Personales (APDP), but its substantive obligations do not take effect until 1 December 2026; Ley 19.628 remains the law in force today. Ley 21.719 has itself already been amended once before taking effect, by Ley 21.806 (5 February 2026), a sign of active continuing reform ahead of commencement.

Comprehensive regime

Ley 19.628, sobre Protección de la Vida Privada

Ley 19.628, sobre Protección de la Vida Privada (Ley sobre Protección de Datos de Carácter Personal)Biblioteca del Congreso Nacional (BCN), Ley Chile, consolidated text

In force since 28 August 1999. Binds public and private bodies.

What this law does

Ley 19.628 governs the processing of personal data in registries or data banks by both public bodies and private parties, with an exception for processing carried out in the exercise of freedom of opinion and information.

Its Título V arms a data subject with a direct civil action: the controller, whether a private person or a public body, must compensate the patrimonial and moral damage caused by improper treatment of the data, and that damages claim may be brought together with the claim establishing the infraction itself, under summary civil procedure.

The statute remains the law in force in Chile as of this date; its substantive provisions are due to be superseded by Ley 21.719 on 1 December 2026, and several of its articles already carry pending-amendment banners on the primary source pointing to that commencement date.

What it requires

Ley 21.719, Regula la Protección y el Tratamiento de los Datos Personales

Ley 21.719 Regula la Protección y el Tratamiento de los Datos Personales y Crea la Agencia de Protección de Datos Personales (Boletines 11.092-07 y 11.144-07, refundidos)BCN, Ley Chile, consolidated text

In force in 76 days, effective 1 December 2026. Binds public and private bodies.

What this law does

Ley 21.719 replaces Ley 19.628 with a General Data Protection Regulation (GDPR)-influenced comprehensive regime covering both public and private-sector processing and amends Ley 20.285 (public information access) and Ley 19.496 (consumer protection) in the same act.

It was promulgated 25 November 2024 and published in the Diario Oficial 13 December 2024, but its own transitory provisions delay commencement of the substantive amendments to the twenty-fourth month after publication, which the primary source's own version banner confirms as 1 December 2026; the law is therefore enacted but not yet in force. It has already been amended once before taking effect, by Ley 21.806 (5 February 2026).

What it requires

Enforcement supervision

Ley 21.719, Agencia de Protección de Datos Personales, Sanciones

Ley 21.719, art. 35 (sanciones) y arts. 42-45 (procedimiento administrativo y judicial)BCN, Ley Chile, consolidated text

In force in 76 days, effective 1 December 2026. Binds public and private bodies.

What this law does

Ley 21.719 establishes the Agencia de Protección de Datos Personales (APDP) as data-protection regulator, with an administrative-sanction procedure for infractions classified as leve, grave, or gravísima, escalating fines by tier, and a further judicial review of Agency decisions before the Corte de Apelaciones. Persons affected by a decision of a public body handling their data under this law may also bring a claim before the Corte de Apelaciones under the same procedure. As with the rest of Ley 21.719, this enforcement structure is enacted but not yet in force.

What it requires

Scraping law1 instrument, 1 in force

Research summary (151 words)

Chile's computer-misuse exposure for scraping runs through Ley 21.459 (delitos informáticos), whose unauthorized-access offence requires both the absence of authorization and the defeat of a technical security barrier, so ordinary crawling of a public, unauthenticated page is not itself a criminal access offence under this statute.

Chile's copyright statute, Ley 17.336, holds a general Título III of limitations and exceptions (Arts. 71 A to 71 S), but the specific text of those articles on quotation or text-and-data-mining is not available from the located BCN page, which returns the statute's table of contents rather than the article bodies, so no copyright_tdm instrument is recorded here.

Personal-data reach over scraped public data is governed by Ley 19.628 (in force) and Ley 21.719 (in force from 1 December 2026), both already researched under the privacy topic rather than restated here. Database rights, unfair competition doctrine specific to scraping, and robots.txt legal weight remain unresearched.

Computer misuse

Ley 21.459, art. 2, acceso ilícito a un sistema informático

Ley 21.459, art. 2 (acceso ilícito)Biblioteca del Congreso Nacional (BCN), Ley Chile, consolidated text

In force since 20 June 2022. Binds private bodies.

What this law does

Article 2 criminalizes accessing a computer system without authorization, or exceeding held authorization, only where the actor also defeats a technical barrier or technological security measure protecting that system.

Both elements are conjunctive on the statute's own text, so crawling a page that carries no such barrier, a public, unauthenticated page, does not by itself satisfy this offence; accessing a system behind a login, a paywall, or another technical access control without authorization does.

The offence carries presidio menor en su grado mínimo (a short custodial term) or a fine of eleven to twenty unidades tributarias mensuales, rising where the access is committed with intent to appropriate or use the system's information (art. 2, second paragraph, not quoted here). This statute repealed and replaced Ley 19.223 to align Chile with the Budapest Convention on Cybercrime.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.