On September 9, Supreme Decree No. 662 of the Ministry of Finance was published in the Official Gazette, approving the Regulation on Personal Data Protection Compliance Models (Modelos de Prevención de Infracciones) (the “Regulation”).
The Regulation establishes the requirements and procedures for the implementation, certification, registration, and supervision of these models, as contemplated under Law No. 19,628 following the amendments introduced by Law No. 21,719.
- What are Personal Data Protection Compliance Models?
These are voluntary compliance programs aimed at preventing violations of personal data protection regulations.
To obtain certification, they must include, among other elements:
- A mapping of processing activities, including the data processed, data subjects, purposes, legal bases, recipients, international transfers, and data retention periods.
- The identification of higher-risk activities and their incorporation into a risk matrix.
- Specific protocols and procedures to prevent violations, tailored to the characteristics and risks of each organization.
- Internal mechanisms for reporting and whistleblowing in connection with non-compliance.
- The appointment of a Data Protection Officer and dissemination of the program within the organization.
- What are the main developments introduced by the Regulation?
The Regulation sets out the requirements that these models must meet in order to obtain certification and establishes a specific standard for their design and implementation.
In particular, it develops the content required for the mapping of processing activities and the risk matrix; requires protocols and controls to address the actual processing activities and risks of each organization; and regulates the requirements and functions of the Data Protection Officer, who must have sufficient autonomy and direct access to the organization’s highest authority and may be appointed internally or externally.
Accordingly, the Regulation confirms that a Personal Data Protection Compliance Model is not limited to the adoption of policies or documents, but requires a risk management and prevention system tailored to the specific circumstances of each organization.
- What role will the Personal Data Protection Agency play?
The Personal Data Protection Agency will be responsible for certifying, registering, and supervising Personal Data Protection Compliance Models.
The certification process will be initiated at the request of the interested party and, for the review and assessment of applications, the Agency may engage third-party service providers. It may also request information to supervise certified models and may revoke certification on duly justified grounds when the requirements established by law or the Regulation are no longer met.
Certification will be valid for three years and may be renewed. Certified entities will be included in the National Register of Sanctions and Compliance.
- Why is having a certified model relevant?
Although adoption of these models is voluntary, having a certified model is particularly relevant because it may constitute a mitigating circumstance in determining liability for violations of personal data protection regulations.
The Regulation therefore provides organizations with concrete parameters to advance the implementation of their compliance systems ahead of the entry into force of Law No. 21,719 on December 1, 2026.
Should you require further information on this matter, please contact Macarena Naranjo (mnaranjo@jdf.cl) or Consuelo Santana (csantana@jdf.cl).





