Chile Law 21.719 Personal Data Protection Cookie Consent Compliance Guide: 2026 Modernisation Playbook for Publishers

Chile spent more than two decades operating under Law 19.628 — the 1999 statute that gave the country its first personal-data-protection regime but stopped well short of the global standard the GDPR set in 2018. The catch-up came in August 2024 when Law 21.719 was promulgated, replacing the bulk of Law 19.628's operative provisions with a modernised framework that adopts the contemporary architecture: lawful bases for processing, data-subject rights, controller-processor accountability, breach notification, cross-border-transfer controls, an independent regulator with administrative-penalty authority, and a sanctions regime with fines that can reach UTM 5,000 — the inflation-indexed Chilean tax unit — for the most serious categories. Law 21.719 entered into force after a two-year grace period that brought its substantive provisions into binding effect in 2026. The implication for publishers reaching Chilean readers is direct: a cookie-consent posture that worked under Law 19.628 is no longer sufficient, and a posture that satisfies the GDPR will satisfy Law 21.719 only when the integration accounts for the specific points where the regimes diverge.

What Law 21.719 actually requires

The Law applies to the processing of personal data of individuals located in Chile regardless of where the controller or processor is established, and to controllers and processors located in Chile regardless of where the data subjects are located. The territorial scope is therefore broad and catches most publishers serving Chilean readers, with the most common edge case — a non-Chilean publisher with no Chilean infrastructure but with Chilean visitors — resolved by reference to whether the controller has actively directed services into Chile. Personal data is defined broadly as any information relating to an identified or identifiable natural person, with sensitive personal data — including data relating to racial origin, political opinion, religious belief, trade-union affiliation, health, sexual life, sexual orientation, and biometric data — subject to a higher consent threshold and additional procedural protections.

The Law establishes lawful bases for processing modelled on the GDPR's Article 6 catalogue but with Chile-specific additions for public-interest and judicial processing, the standard slate of data-subject rights — access, rectification, erasure, opposition, portability, and a Chile-specific right to block automated decision-making — a controller-processor accountability framework with mandatory data-protection-officer appointment for higher-risk categories, breach-notification obligations to the new Personal Data Protection Agency within 72 hours of awareness, cross-border-transfer controls turning on the Agency's adequacy determinations or approved contractual safeguards, and an administrative-penalty regime with fines categorised by infraction gravity and reaching UTM 5,000 for the most serious breaches.

How Law 21.719 treats cookie consent

Law 21.719 does not contain a separate ePrivacy-style provision on cookies; cookies and analogous storage-and-access technologies fall within the general consent framework. The standard is explicit, voluntary, specific, informed, and unequivocal agreement evidenced by an affirmative act — the family of requirements that the GDPR set as the global baseline and that Chile has imported with its own procedural overlay. The Personal Data Protection Agency, the new independent regulator the Law establishes, has issued initial guidance during the grace-period rollout confirming that pre-ticked boxes, implicit consent inferred from continued browsing, and bundled consent banners do not satisfy the Law's threshold. That brings Chile firmly into line with the global trajectory and means the posture publishers already maintain for the EEA is the right starting point for Chilean traffic.

The practical effect is that cookies and analogous technologies which are not strictly necessary to deliver the service the visitor has actively requested must not be set before the visitor has consented. Strictly-necessary cookies — session identifiers, cart contents, security tokens, load-balancing cookies — can be set on the basis that the visitor has actively requested the service. Everything else — analytics, advertising, personalisation, A/B testing, session replay, and any third-party tag — requires prior consent.

How Law 21.719 diverges from the GDPR in practice

Three differences matter when wiring a CMP for Chilean traffic. First, the Law explicitly recognises a right to block automated decision-making — including profiling — that is broader than the GDPR's Article 22 equivalent and applies whenever the processing produces significant effects on the data subject, with the threshold for significant effects interpreted more generously than under European practice. For publishers running personalisation engines that segment visitors into commercial categories, the right means an opt-out path from automated profiling must be available even after analytics consent has been granted. Second, the Law's cross-border-transfer regime requires the Agency to designate destination jurisdictions; transfers to undesignated jurisdictions require either explicit data-subject consent, contractual safeguards approved by the Agency, or one of the narrow derogations. Third, the Law applies a tighter standard to the processing of biometric data and to genetic data than the GDPR baseline, requiring a separate authorisation track for those categories that publishers running biometric-authentication or similar processing must factor into their architecture.

What a compliant cookie banner looks like under Law 21.719

The technical requirements converge with what every modern CMP already produces, but the labelling, the documentation, and the consent log must reflect Chilean specifics. The first-layer banner must present the visitor with a real choice — accept, reject, manage — where the reject option is at least as prominent as the accept option. Bundled consent is prohibited, so the second layer must allow per-category opt-in covering at minimum analytics, advertising, automated-decision-making, and any cross-border-transfer-dependent processing. Categories must default to off; the banner must not load tags until the visitor has affirmatively flipped them on.

The privacy notice surfaced from the banner must identify the controller, the controller's registration with the Agency where applicable, the categories of personal data collected, the lawful basis for each processing purpose, the data-retention period, the categories of recipients including any sub-processors located outside Chile, the data subject's rights under the Law including the automated-decision-making opt-out, the DPO's contact details where the DPO appointment is mandatory, and the Agency's contact details for complaints. A notice that meets the GDPR's Article 13 standard substantially overlaps but the automated-decision-making opt-out and Agency-contact lines must be added explicitly.

The integration pattern that passes an Agency review

The reference implementation has four moving parts. The first is a CMP that supports per-category, default-off opt-in including a separate automated-decision-making toggle and exposes the visitor's choice via a structured consent string the publisher can persist. The second is a tag-loading layer — a server-side tag manager or a CMP-native gate — that strictly enforces consent state before any non-essential cookie is set. The third is a consent log, stored server-side, that records for every consent event the visitor's choice per category, the timestamp, the banner version, the language version the visitor saw, and a truncated or hashed IP identifier such that the controller can produce the record on Agency request. The fourth is a withdrawal path at least as easy as the original grant — a persistent banner re-open link in the footer plus a Spanish-language privacy-rights page that surfaces the automated-decision-making opt-out as a separate affordance.

Validation, registration, and audit posture for 2026

A defensible Chilean deployment in 2026 must pass four technical checks. First, a clean browser session served from a Chilean IP address must produce zero non-essential cookies before the banner has been actioned. Second, the reject-all path must result in the same posture as a no-action session — no analytics tags, no advertising tags, no session-replay scripts, no automated profiling. Third, an accept-all flow must produce only the tags the visitor has consented to, and the consent log must contain a matching record. Fourth, a withdrawal flow must immediately stop further tag fires, expire the cookies set during the consented session, deactivate any automated decision-making affecting the visitor, and trigger any downstream deletion or opt-out signals the recipient partners require.

Beyond the technical checks, the registration and audit posture is what makes a deployment defensible. Controllers processing the personal data of Chilean residents above the Agency-defined thresholds must complete the relevant registrations and notifications, and the registration record — together with the consent log, the privacy notice, the data-protection-impact-assessment results for higher-risk processing including profiling, the DPO appointment paperwork, and the cross-border-transfer authorisations — forms the documentation the Agency may request during a compliance review. A correctly configured CMP with a server-side log, a tag-loading layer that enforces consent state, a privacy notice that names each cross-border-transfer destination, an automated-decision-making opt-out affordance, and the registration paperwork on file is what turns Law 21.719 from a regulatory unknown into a defensible part of a publisher's Latin American consent posture.

← Blog Read All →