On September 1, 2026, the Chilean Senate opened tramitación on Boletín 18623-07, a bill that amends Ley 21.719, the personal data protection statute published in the Diario Oficial on December 13, 2024 that creates the Agencia de Protección de Datos Personales (APDP) and is set for full vigencia on December 1, 2026. The bill is at the earliest legislative stage: ingresado, status En tramitación. For every controller and processor preparing for the December go-live, a legislative amendment to the statute itself, this close to the cutover, is a development that shifts the planning baseline.

The Senate's tramitación register lists the bill under its official title: "Modifica la ley N° 21.719, que regula la protección y el tratamiento de los datos personales y crea la Agencia de Protección de Datos Personales, en el sentido que indica." The phrase "en el sentido que indica" signals that the register records the filing, but the specific modifications sit in the bill's text, which advances through committee and floor votes. In other words, the development is real and official, but the operative detail of what changes, and by when, lives in the mensaje and the text the Senate will debate, not in the register row.

Why does a bill amending Ley 21.719 matter three months before go-live?

Ley 21.719 is the overhaul that replaces Chile's fragmented legacy regime, Ley 19.628 (Protección de la Vida Privada), with a GDPR-grade framework and a dedicated regulator, the APDP. Under the law as promulgated, the APDP will be an autonomous body under the Ministry of Economy, empowered to issue binding instructions, sanction controllers up to 20,000 UTM, and maintain a Registro Nacional de Sanciones. Until December 1, 2026, enforcement remains split across civil courts and sectoral supervisors.

An amendment landing now can touch any of the load-bearing parts of that design: the vigencia date, the APDP's governance and staffing, the sanction ladder, or the scope of controller obligations. A bill at this stage is not law, and it can still be modified, rejected, or withdrawn in committee. But the existence of a government-backed amendment this close to vigencia is itself the signal: the December 1, 2026 calendar and the APDP's shape are not yet frozen, and compliance programmes built around them need a contingency.

What does the legislative process mean for the timeline?

Under Chile's bicameral process, a bill moves through primer trámite in the chamber of origin (general and particular votes), segundo trámite in the revising chamber, and tercer trámite back in the origin on any amendments, with a mixed commission if disagreement persists. The President has 30 days to sancionar or veto, then promulga, and the law is publicada in the Diario Oficial within days. Boletín 18623-07 has only just been ingresado, so it sits at the very start of that ladder.

The practical consequence: the December 1, 2026 vigencia set by Ley 21.719 as promulgated remains the operative date until and unless this bill, or any other, changes it. Controllers should plan to that date, while tracking whether the amendment alters it.

Who is exposed, and what should compliance teams do now?

The exposed perimeter is broad. Privacy leads, DPOs and compliance teams at Chilean banks, retailers, telcos, insurers, public bodies and municipalities all process personal data in scope, as do the extraterritorial platforms selling into Chile. For those, the underlying obligations, lawful basis, data-subject rights, breach notification and cross-border transfer rules, do not change in substance because a bill is filed; what can move is the date and the supervisory design around them.

The bill is also distinct from two parallel digital-governance tracks: Ley 21.663 (the Marco de Ciberseguridad, which creates the ANCI for critical infrastructure) is a cybersecurity regime with a separate regulator, and the still-pending Chilean AI bill is a separate instrument. Conflating them in compliance planning is an error: ANCI is not the APDP, and neither is the AI bill.

Continuous, per-jurisdiction monitoring from Obsidian surfaces this kind of filing the moment it enters tramitación, before the detail reaches the trade press.

Subscribe to the free newsletter

Chile: data protection, ANCI OIV wave 2 and open finance resetLive
Monitor Chile's regulatory milestones.
Email report 1 news
You will receive an email report each time something new happens on this topic. Free, no account required.
Subscribe to the newsletter

For next steps: track the bill's text and its committee assignment in the Senate; keep hardening consent flows, data-subject request pipelines, breach notification and vendor contracts against the December 1, 2026 date rather than pausing them; brief privacy, procurement and vendor-management teams on the contingency that the vigencia or the APDP's design could shift; and distinguish this bill from the cybersecurity and AI tracks so resourcing stays correct.