Chile - Prevention Models Regulation (662/2025)
Decree No. 662/2025 — Regulation that regulates the Models of Prevention of Offences
Decreto N° 662/2025 — Reglamento que regula los Modelos de Prevención de Infracciones
Chile
RAI-CL-NA-DN6RQXX-2025Decreto N° 662/2025 (Ministry of Finance) approves a draft regulation establishing requirements, modalities and procedures for implementation, certification, registration and supervision of voluntary Models of Prevention of Offences under Law 21.719 on personal data protection. The instrument is reported in public sources as submitted to the Contraloría General de la República (preventive legal review) and will operate in the context of the new data protection regime which becomes fully effective on 2026-12-01.
Summary
Read full text ↗Plain English
Overview
Decree No. 662 (dated 13 June 2025, as reported by legal commentators) approves the implementing regulation that sets out the procedural and substantive requirements for the adoption, certification, registration and supervision of voluntary Models of Prevention of Infringements (Modelos de Prevención de Infracciones — MPI) under the new data protection regime introduced by Law No. 21.719. The MPI is conceived as a structured compliance programme that controllers may adopt to organise governance, reduce risks and demonstrate due diligence in the processing of personal data. Several legal notices and specialist summaries explain that, at the time of reporting, the decree had been submitted to the Contraloría General de la República for the preventive legal review known as "toma de razón" and had not yet been published in the Diario Oficial; see analysis at IAPP and a firm alert at Ontier. The decree is framed to operate together with Law 21.719, whose general entry into force is specified for December 1, 2026 in the law text available at the Biblioteca del Congreso Nacional (BCN - Law No. 21.719).
Definitions
The regulation defines core terms for uniform interpretation across certified MPIs. Among definitions reported in secondary sources: "responsible" (controller) — the natural or legal person who determines the purposes and means of processing; "delegate" (Delegado de Protección de Datos) — the designated compliance officer for the MPI who may act as an internal or independent function; "Record of Processing Activities (RAT)" — the central inventory and characterization of processing operations; "model" or "MPI" — the set of documented protocols, policies, matrices, controls and reporting channels that constitute the compliance programme; "certification" — the process by which the Agency determines that an MPI complies with the legal and regulatory benchmarks for registration; and "revocation" — Agency's administrative power to withdraw a certification in cases of material breach. The decree's drafting aims to recreate operational definitions that align with Law 21.719 terminology and international best practices.
Governance and Institutional Framework
The decree assigns primary responsibilities for the MPI architecture to the data controller and to the Data Protection Delegate and establishes the supervisory role of the new Agency for the Protection of Personal Data. The controller must adopt an MPI voluntarily and is responsible for implementing, documenting and periodically reviewing the programme. The Delegate's functions include advising on compliance, participating in programme design, receiving internal reports and interacting with the Agency. The Agency (once constituted pursuant to Law 21.719) will be the certifying and supervisory authority: certification requests will be processed in accordance with Law N° 19.880 (administrative procedure) and subsequent implementing instructions; the Agency will also maintain or supervise the Registro Nacional de Sanciones y Cumplimiento and may require information, carry out audits and, where appropriate, revoke certification. The decree therefore frames a governance chain that connects private compliance programmes with public supervisory oversight; see commentaries at Diario Constitucional and firm notes at FerradaNehme.
Key Focus Areas
The regulation elaborates minimum core components required for an MPI. As synthesised by legal commentators, these elements include: (1) clear identification of the legal entity responsible for processing and its legal representatives; (2) a comprehensive Record of Processing Activities (RAT) covering all categories of processing, legal bases, recipients and retention periods; (3) risk identification and assessment tools (data protection risk matrix and process mapping) that link identified risks to concrete preventive and mitigation controls; (4) documented internal policies, technical and organizational measures, standard operating procedures, checklists and process flows that translate legal duties into day-to-day tasks; (5) designation and description of the powers and resources of the Data Protection Delegate (internal or external), specifying reporting lines and independence safeguards where applicable; (6) protocols for incident detection, internal escalation and external notification (including triggers for notifying the Agency and affected data subjects); (7) training and awareness programmes for staff and contractors; (8) internal reporting channels, whistleblowing and non-retaliation policies; (9) internal disciplinary regimes for MPI breaches and related procedures; (10) benchmarking and periodic internal/external audits; and (11) a mechanism for documenting corrective actions and continuous improvement. The decree also addresses the content of the certificate and the public entry in the National Registry, including identification of the certified entity, legal representative, date of certification and its term (commonly signalled as 3 years in secondary analyses). Together, these focus areas aim to operationalise principles such as accountability, privacy by design and by default, transparency and proportionality as required by Law 21.719 and international standards such as the GDPR.
Implementation Framework
Procedurally, the decree reportedly establishes that certification is initiated by the applicant and is subject to administrative processing under Law N° 19.880. The Agency will issue an instruction or guide that sets application formats, documentary evidence requirements, evaluation criteria and fees (if any). Review stages described in commentary include preliminary admissibility checks, technical evaluation (which may use independent auditors or experts), an opportunity for the applicant to cure formal deficiencies, final decision and registration. Certified MPIs will have a defined validity period (commonly three years) and must be renewed to remain registered. The regulation contemplates the possibility of early revocation for misrepresentations, systemic failures or repeated breaches. Where certification is revoked, the Agency may open sanctioning proceedings provided in Law 21.719. The decree also contemplates rules to determine whether an MPI may rely on external certifications or third-party attestations as part of the evidentiary package for the application.
Monitoring and Evaluation
Supervision under the decree is based on a risk-informed approach: the Agency may request periodic reports, require access to the RAT and to MPI documentation, and carry out on-site or remote inspections. The decree describes reporting obligations for certified controllers and specifies that unreasonable refusal to provide information, or the provision of false, incomplete or intentionally misleading information, will be treated as aggravating facts in subsequent administrative procedures. Monitoring includes review of incident reports, breach metrics and remedial action logs. The regulation also contemplates indicators for programme effectiveness, such as audit results, corrective action completion rates and frequency and impact of incidents, which the Agency may use to prioritise supervisory resources.
Penalties, Liability, and Appeals
While certification under the MPI regime is voluntary, the decree clarifies that certified entities remain subject to the full sanctioning regime set out in Law 21.719. The law established an updated catalogue of infringements classified as minor, serious and very serious, with fines that can reach significant amounts (expressed in UTM). The decree outlines that false statements in the certification process, obstruction of supervisory actions, material breaches of MPI obligations and repeated infringements may give rise to revocation and enforcement actions. A certified MPI may be considered a mitigating factor in sanctioning decisions when demonstrable evidence shows effective prevention and remediation; conversely, the lack of a functioning MPI where required by the nature of processing may constitute an aggravating circumstance. The decree also preserves the right to administrative appeals and judicial review as provided under Chilean administrative law.
Relationship to Other Instruments
The decree complements Law 21.719 and interacts with other legal instruments: (a) administrative procedure law (Ley N° 19.880) for certification proceedings; (b) existing sectoral or sector-specific rules that continue to apply (for example, health or financial regulations) and may impose additional obligations; (c) criminal and consumer protection statutes where parallel liability may arise; and (d) transnational data transfer rules and contractual requirements. The decree indicates that MPIs do not displace other sectoral compliance duties and are intended to be applied in a supplementary manner to reinforce internal governance systems. Legal commentators emphasise that the MPI establishes an interoperable compliance layer that organisations can align with internal audit, risk, compliance and cybersecurity programmes.
International Alignment
The regulation is drafted to align Chile's MPI architecture with international best practices and comparable compliance schemes such as those found in the EU (e.g., accountability and DPIA requirements under the GDPR) and other Latin American modernisations. The decree's emphasis on documented Records of Processing Activities, independent Delegates, risk matrices and certification mirrors global trends in accountability-based privacy regulation. Secondary sources note that this alignment is intended to facilitate cross-border data flows, increase legal certainty for multinational controllers and support international cooperation in enforcement and standards harmonisation; however, specific provisions for adequacy or binding transfer mechanisms remain governed by other instruments and by decisions of the Agency.
Implementation Timeline
| Event | Date |
|---|---|
| Law No. 21.719 published in Diario Oficial | 2024-12-13 |
| Decree No. 662 (draft) dated | 2025-06-13 |
| Decree submitted to Contraloría (reported) | 2025-08-28 |
| Law general entry into force (deferred) | 2026-12-01 |
| Expected publication of finalized decree (post Contraloría) | To be confirmed |
Compliance Checklist
| Requirement | Checklist Item |
|---|---|
| Governance | Identify controller, appoint Delegate, document reporting lines |
| Documentation | Maintain RAT, policies, SOPs and training records |
| Risk Management | Complete data protection risk matrix and DPIAs where necessary |
| Incident Response | Implement incident detection, internal reporting and external notification procedures |
| Certification | Prepare evidentiary package for Agency certification (audits, logs, attestations) |
Sources and References
Chile is preparing a new regulation that outlines how organizations can voluntarily implement structured compliance programs to prevent personal data breaches under the country's new data protection law. This regulation, known as Decree No. 662/2025, applies to any entity, or "data controller," that processes personal data in Chile and wishes to demonstrate due diligence and reduce risks.
The decree details the requirements for these voluntary "Models of Prevention of Infringements" (MPIs). To be certified, an MPI must include several key components: - A comprehensive record of all data processing activities. - Tools for identifying and assessing data protection risks. - Documented internal policies, procedures, and technical safeguards. - The appointment of a Data Protection Delegate to oversee compliance. - Protocols for detecting, escalating, and reporting data incidents. - Regular training for staff and internal audit mechanisms. The new Data Protection Agency, once established, will be responsible for certifying these MPIs, maintaining a public registry, and supervising their ongoing effectiveness.
While adopting an MPI is voluntary, it offers significant benefits. A certified MPI can serve as a mitigating factor if an organization faces penalties for data protection violations under the broader Law 21.719. Conversely, failing to have a robust MPI where the nature of processing warrants it could be seen as an aggravating factor. The Agency can revoke an MPI certification for serious breaches or misrepresentations, potentially leading to enforcement actions.
This regulation is currently under review by Chile's national audit office and is designed to operate alongside Law 21.719, which fully takes effect on December 1, 2026. A practical pitfall for organizations is underestimating the rigor required for certification and ongoing compliance; the process is formal and involves detailed documentation and audits. Organizations should prepare for a comprehensive review by the Agency, which will assess not just the existence of an MPI, but its actual implementation and effectiveness.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under Chile - Prevention Models Regulation (662/2025). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Upon MPI adoption
Applies to: Data controllers implementing an MPI.
“a comprehensive Record of Processing Activities (RAT) covering all categories of processing, legal bases, recipients and retention periods”
- #2Critical⏰ Upon MPI adoption
Applies to: Data controllers implementing an MPI.
“risk identification and assessment tools (data protection risk matrix and process mapping) that link identified risks to concrete preventive and mitigation controls”
- #3Critical⏰ Upon MPI adoption
Applies to: Data controllers implementing an MPI.
“protocols for incident detection, internal escalation and external notification (including triggers for notifying the Agency and affected data subjects)”
- #4Critical⏰ Upon request
Applies to: Data controllers seeking or with certified MPIs.
“unreasonable refusal to provide information, or the provision of false, incomplete or intentionally misleading information, will be treated as aggravating facts”
- #5Critical⏰ Ongoing
Applies to: Data controllers with certified MPIs.
“obstruction of supervisory actions... may give rise to revocation and enforcement actions.”
- #6Important⏰ Upon MPI adoption
Applies to: Data controllers adopting an MPI.
“The controller must adopt an MPI voluntarily and is responsible for implementing, documenting and periodically reviewing the programme.”
- #7Important⏰ Upon MPI adoption
Applies to: Data controllers implementing an MPI.
“designation and description of the powers and resources of the Data Protection Delegate (internal or external), specifying reporting lines and independence safeguards where applicable”
- #8Important⏰ Upon MPI adoption
Applies to: Data controllers implementing an MPI.
“documented internal policies, technical and organizational measures, standard operating procedures, checklists and process flows”
- #9Important⏰ Ongoing, after MPI adoption
Applies to: Data controllers implementing an MPI.
“training and awareness programmes for staff and contractors”
- #10Important⏰ Upon MPI adoption
Applies to: Data controllers implementing an MPI.
“internal reporting channels, whistleblowing and non-retaliation policies”
- #11Important⏰ Periodically
Applies to: Data controllers implementing an MPI.
“benchmarking and periodic internal/external audits”
- #12Important⏰ Before seeking benefits of certification
Applies to: Data controllers seeking MPI certification.
“certification is initiated by the applicant and is subject to administrative processing under Law N° 19.880.”
- #13Important⏰ Before certification expiration
Applies to: Data controllers with certified MPIs.
“Certified MPIs will have a defined validity period (commonly three years) and must be renewed to remain registered.”
Related Regulations
Law No. 21.719 — Regulates the protection and processing of personal data and creates the Personal Data Protection Agency
Chile92% similar
Directiva N° 45 (Dirección de Compras y Contratación Pública) — Recomendaciones sobre el tratamiento de datos personales en procedimientos de compras públicas
Chile89% similar
Ley N° 21.663 — Ley Marco de Ciberseguridad (Framework Law on Cybersecurity and Critical Information Infrastructure)
Chile88% similar
Decreto Supremo N° 285 (Reglamento) — Procedimiento de calificación de Operadores de Importancia Vital en el marco de la Ley Marco de Ciberseguridad (Law 21.663)
Chile87% similar
Proyecto de Ley que regula los Sistemas de Inteligencia Artificial (Government bill to regulate AI systems) (<a href="https://iapp.org/news/a/contin-a-la-tramitaci-n-del-proyecto-de-ley-sobre-ia-en-chile?utm_source=openai">iapp.org</a>)
Chile87% similar
© Regulations.AI — created on 13-Jun-2026