chiledata protectioncomplianceprivacydecree 662/2025mpi

Chile's Decree 662/2025: Your Guide to Data Protection Compliance

Regulations.ai (AI-assisted)

Chile is gearing up for a significant shift in its data protection landscape, and a key piece of this puzzle is Decree No. 662/2025. This regulation, currently under review, provides the much-anticipated framework for organizations to voluntarily implement robust compliance programs, known as Models of Prevention of Infringements (MPIs), designed to prevent personal data breaches under the country's new data protection law.

What's changing — substance

At its core, Decree No. 662/2025 establishes a detailed blueprint for what constitutes an effective MPI. While adopting an MPI is not mandatory, it offers substantial advantages, acting as a critical mitigating factor should an organization face penalties for data protection violations under Law 21.719. Conversely, a lack of a robust MPI, especially where the nature of data processing warrants it, could be viewed as an aggravating factor by the authorities.

The decree outlines several key components that an MPI must include to be certified by Chile's new Data Protection Agency (once established). These are not mere suggestions but foundational requirements for demonstrating genuine commitment to data protection:

  • Comprehensive Record of Processing Activities (RAT): Organizations must maintain a detailed and up-to-date record of every data processing activity. This includes information on the types of personal data processed, the purposes of processing, categories of data subjects, recipients of data, data retention periods, and the security measures in place. This record serves as the bedrock for understanding and managing data protection risks.
  • Risk Identification and Assessment Tools: An MPI must incorporate systematic tools and methodologies for identifying, assessing, and prioritizing data protection risks. This involves not only understanding potential threats and vulnerabilities but also evaluating their likelihood and impact. Techniques like risk matrices and process mapping are crucial here, allowing organizations to proactively address weaknesses before they lead to incidents.
  • Documented Internal Policies and Procedures: Clear, written policies and procedures are essential. These must cover all aspects of data processing, from collection and storage to access, transfer, and deletion. They should also detail technical and organizational safeguards designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
  • Appointment of a Data Protection Delegate (DPD): The regulation mandates the appointment of a Data Protection Delegate. This individual or team is responsible for overseeing the organization's compliance with data protection laws and regulations, advising on data protection matters, and acting as a contact point for the Data Protection Agency and data subjects.
  • Incident Protocols: Organizations must establish clear protocols for detecting, escalating, and reporting data incidents. This includes internal reporting mechanisms, as well as procedures for notifying the Data Protection Agency and affected data subjects within specified timelines, minimizing potential harm and ensuring transparency.
  • Regular Training and Internal Audits: An effective MPI requires ongoing effort. This means providing regular training for all staff involved in data processing to ensure they understand their responsibilities and the organization's policies. Furthermore, internal audit mechanisms must be in place to regularly review the MPI's effectiveness, identify areas for improvement, and ensure continuous compliance.

The Data Protection Agency will play a pivotal role, not only certifying these MPIs and maintaining a public registry but also supervising their ongoing effectiveness. The Agency has the power to revoke an MPI certification in cases of serious breaches or misrepresentations, which could lead to significant enforcement actions.

Who is affected — jurisdictions, sectors, sizes

Decree No. 662/2025 applies to any entity, or "data controller," that processes personal data within Chile. This broad scope means that businesses of all sizes, across all sectors—from technology startups to traditional industries, financial institutions, healthcare providers, and public bodies—are potentially affected. If an organization handles personal data in Chile, this regulation is relevant.

While the adoption of an MPI is voluntary, the strategic benefits it offers make it a highly advisable undertaking. It provides a structured way to demonstrate due diligence, reduce legal and reputational risks, and potentially mitigate penalties in the event of a data breach. Given that Law 21.719, which this decree supports, takes full effect on December 1, 2026, organizations have a clear timeline to prepare.

The practical pitfall for many will be underestimating the rigor required. The certification process is formal, demanding detailed documentation, evidence of implementation, and a comprehensive review by the Data Protection Agency. It's not enough to simply have policies on paper; their actual effectiveness and consistent application will be scrutinized.

Three things to do this week

To prepare for the full implementation of Chile's new data protection regime and the opportunities presented by Decree No. 662/2025, organizations should consider these concrete actions:

  1. Start or update your Record of Processing Activities (RAT): This is the foundational step. Begin documenting every instance where your organization collects, stores, uses, or shares personal data. For each activity, identify the categories of data subjects, the types of data, the purpose of processing, legal basis, data recipients, international transfers, retention periods, and the security measures in place. A comprehensive RAT is indispensable for identifying risks and building an effective MPI.
  2. Implement data protection risk identification and assessment tools: Don't wait for an incident. Establish a systematic process to identify potential data protection risks. This involves mapping your data flows, identifying vulnerabilities in your systems and processes, and assessing the likelihood and impact of potential breaches. Develop a risk matrix to prioritize these risks and plan for their mitigation. This proactive approach is a core requirement of the MPI.
  3. Establish clear protocols for incident detection, internal escalation, and external notification: Data breaches are a matter of when, not if. Develop and document clear procedures for how your organization will detect a data incident, who needs to be informed internally, and the steps for escalating the issue. Crucially, define the process for notifying the Data Protection Agency and affected data subjects, including timelines and communication strategies. Regular testing of these protocols is also highly recommended.

Related context

Decree No. 662/2025 does not operate in a vacuum but is part of a broader regulatory ecosystem in Chile aimed at strengthening data protection and digital governance. It is intrinsically linked to:

  • Law No. 21.719: This overarching law regulates the protection and processing of personal data and establishes the Personal Data Protection Agency. The MPIs outlined in Decree No. 662/2025 are the practical mechanisms for compliance with this fundamental law. (See: /regulations/RAI-CL-NA-N2RPPXX-2024)
  • Directiva N° 45 (Dirección de Compras y Contratación Pública): This directive provides recommendations on the treatment of personal data in public procurement procedures, highlighting the importance of data protection even in government contracting. (See: /regulations/RAI-CL-NA-DN4DDXX-2025)
  • Proyecto de Ley que regula los Sistemas de Inteligencia Artificial: As AI systems become more prevalent, this government bill aims to regulate their use, particularly concerning personal data processing and ethical considerations, further shaping the digital regulatory landscape in Chile. (See: /regulations/RAI-CL-NA-PDLQRXX-2024)

Understanding Decree No. 662/2025 in conjunction with these related regulations provides a holistic view of Chile's evolving approach to data protection and digital responsibility.

Note: this article was drafted by AI - Google Gemini