Data protection: new regulations on the implementation and credentials of infringement prevention frameworks

This month, Decree No. 662 was published in the Official Gazette, approving the regulations regarding the infringement prevention models introduced by Law No. 21,719 into Law No. 19,628 on the Protection of Personal Data (moving forward, the “Law”). Specifically, the regulation establishes the practical framework for implementing these prevention models by defining their minimum requirements, the certification process, their inclusion in the corresponding registry, and the supervisory powers of the Personal Data Protection Agency (the “Agency”).

What are infringement prevention models?

Infringement prevention models are voluntary compliance programs that data controllers may adopt to implement organizational and operational measures aimed at ensuring compliance with the Law and protecting the rights of personal data subjects. These models are intended to promote a regulatory compliance culture by establishing internal procedures, controls, and governance mechanisms designed to prevent violations of personal data protection rules and strengthen accountability within organizations.

Why certify an infringement prevention model?

Although the adoption of an infringement prevention model is voluntary, obtaining certification from the Agency constitutes a mitigating factor in the event of a violation of the Law. Certification serves as evidence that the organization has thoroughly fulfilled its management and performance review regarding the protection of personal data subject to processing. Nevertheless, the implementation of a certified model does not exclude data controllers from their general obligation to take measures aimed at preventing infringements and ensuring compliance with the terms of the Law.

What requirements must compliance programs meet?

The regulation establishes a minimum set of requirements that compliance programs must include. Among other measures, organizations must appoint a data protection officer, identify and characterize their data processing activities, analyze processes that present a higher risk of infringement, and incorporate them into a risk matrix. The program must also establish prevention protocols, internal reporting and whistleblowing mechanisms, and disciplinary measures for non-compliance. In addition, the program’s internal rules and procedures must be incorporated as mandatory obligations in employment and service agreements and, where applicable, reflected in the organization’s internal regulations. This framework seeks to promote a structured and risk-based approach to data protection compliance, ensuring that organizations apply effective governance measures to prevent breaches and strengthen accountability across their operations.

The role of the data protection officer

The regulation further develops the role of the data protection officer, whose appointment will be mandatory for organizations that adopt an infringement prevention model and seek to obtain its certification. This role may be performed either by an employee of the organization or by an external service provider. It must be appointed by the highest executive or administrative authority of the data controller and report directly to that authority. In the case of micro, small, and medium-sized enterprises, the role may be carried out by the owners of the business or its highest-ranking executives.

The regulation requires that the individual serving as the data protection officer possess specialized and up-to-date knowledge of personal data protection, act independently, and has the necessary access to perform their duties effectively. Organizations must also ensure that the role is carried out in a manner that avoids actual or potential conflicts of interest.

Among the data protection officer key responsibilities is advising the organization on compliance with data protection regulations, monitoring adherence to the legal framework, participating in the design and review of the compliance program, responding to inquiries from data subjects, and acting as the primary point of contact with the Agency. By strengthening the role of the data protection officer, the regulation seeks to ensure that organizations maintain effective internal oversight mechanisms and a clear management structure for the protection of personal data.

Certification, registration, and oversight

Certification must be requested from the Agency, and once granted, it will remain valid for three years. Certification may be renewed at the request of the interested party.

Once certification has been granted, the prevention framework will be incorporated into the Chilean National Registry of Sanctions and Compliance, a public registry. Data controllers may only promote or reference their certification through direct reference to this official registry.

The Agency will have the authority to oversee compliance with certified prevention frameworks and may request any information or supporting documentation necessary to verify their effective implementation and operation. Failure to comply with such requests, or the submission of false, incomplete, or clearly inaccurate information, can lead to sanctions under the Law.

Certification may also be revoked if the data controller no longer meets the requirements established by the regulatory system or is sanctioned for certain violations set forth in the Law. In such cases, the organization may apply for certification again, provided it can demonstrate that it has remedied the circumstances that led to the revocation and implemented measures aimed at preventing similar situations from occurring in the future.

The certification regime therefore not only provides an incentive for organizations to adopt robust compliance programs but also establishes an ongoing monitoring mechanism to ensure that certified frameworks continue to operate effectively and in accordance with fitting data protection standards.

For further information or assistance regarding this matter, please contact our Corporate legal team. You may also find the following related publications of interest:

Recieve our legal alerts