/ Legal Alert: Bill Postpones Effective Date of the Personal Data Protection Law
September 2, 2026Two regulatory developments marked the beginning of September in the area of personal data protection: the introduction of a bill seeking to postpone the effective date of the new legislation and the formal acknowledgment of the regulations on models for preventing violations.
Carla Illanes
Partner at Alessandri
1. Bill to Postpone the Effective Date of the Personal Data Protection Act
On September 1, 2026, the Executive Branch announced the submission to the Senate of a bill proposing to postpone the effective date of Law No. 21,719 by one year, moving it from December 1, 2026, to December 1, 2027.
The initiative also provides for:
- Increasing the number of members on the Board of Directors of the future Personal Data Protection Agency from 3 to 5.
- Bringing forward the appointment of its first Board of Directors.
- Adjusting the transitional regime applicable during the first year of the law’s effectiveness.
Important: This is a bill currently under consideration; therefore, the effective date of Law No. 21,719 remains December 1, 2026, until the reform is approved.
Organizations should continue their compliance efforts, given that the regulations will introduce new compliance obligations, strengthen the rights of data subjects, and establish the Personal Data Protection Agency as the supervisory authority.
2.Supreme Decree No. 662 of 2025, Regulations Governing Models for the Prevention of Violations in This Area
Also on September 1, Supreme Decree No. 662 of 2025, which approves the Regulations governing the requirements, modalities, and procedures for the implementation, certification, registration, and supervision of Infraction Prevention Models in the area of personal data protection, was acknowledged by the Comptroller General of the Republic.
The Regulations are structured into a Title on General Provisions and a Title on Compliance Programs. The latter is, in turn, divided into three sections: (i) a first section on the elements and public disclosure of Compliance Programs; (ii) a second section dedicated to the Data Protection Officer, which outlines their functions and powers; and (iii) a third section that regulates the approval, certification, registration, implementation, and supervision of such programs.



