Guides

Law 21.719: what changes for nutritionists in Chile on 1 December 2026

Chile’s new data protection law takes full effect on 1 December 2026 and creates a Data Protection Agency. What a nutrition practice needs ready before then.

11 min read

Chile is moving from one of the region’s oldest data laws to one of its most demanding. Law 21.719 was published in December 2024 and takes full effect on 1 December 2026: if you see clients in Chile, the time left to prepare is now measured in weeks.

Until 1 December 2026, Law 19.628 on the Protection of Private Life, from 1999, still governs. From that date Law 21.719 takes full effect, replacing it, creating a supervisory authority with enforcement powers, and bringing the Chilean standard closer to the European regulation.

What the new law brings

  • The Data Protection Agency, with inspection and sanctioning powers.
  • Full ARCO rights — access, rectification, cancellation, objection — plus portability.
  • A duty to notify security breaches, within a short deadline.
  • Express principles of purpose, proportionality, quality, and accountability.
  • A sanctions regime with fines scaling by severity and repeat offences.

For a nutrition practice, what matters most is that health data is treated as a special category, with heightened requirements both for the basis that permits processing and for the safeguards around it.

What to do before December

TaskWhy it mattersEffort
Inventory what data you processWithout knowing what you hold you cannot justify anything elseLow
Define and document the basis for each processingSeparates care from marketing and public contentMedium
Update the information you give clientsTexts written under Law 19.628 fall shortMedium
Review vendor contractsSoftware, payments, email, and cloud process data for youMedium
Define a breach procedureNotification has a deadline; improvising does not workLow
Review access and enable a second factorThe technical measure with the best cost-to-risk ratioLow
Preparation aimed at a solo practice or small centre. A centre with several professionals should also review roles and access profiles.

How it meets the clinical record

Law 20.584 and the Decree 41 regulation require keeping the clinical record for at least fifteen years from the last entry. Data protection law, by contrast, requires deleting what no longer has a purpose. There is no contradiction: a legal retention duty is a legitimate purpose. What does change is use: a client who stopped coming should no longer appear in your working lists or receive communications, even though their record stays stored.

Security breaches

The new law introduces a duty to notify security breaches affecting personal data. Decide in advance who detects, who decides whether to notify, and what information goes out. A one-page procedure, written before anything happens, is the difference between responding on time and not responding.

  1. Detect and contain: cut off the improper access before analysing anything.
  2. Record what happened, when, which data was affected, and how many people.
  3. Assess the risk to clients, not the inconvenience to you.
  4. Notify the authority if required, within the deadline.
  5. Inform affected people where the risk is high.
  6. Document corrective measures and review what failed.

Vendors and hosting

Every service processing your clients’ data on your behalf falls within the law: practice software, payment gateway, email, cloud, video calls. Ask each for their processing agreement, confirm where data is hosted, and keep that documentation. If a vendor cannot give you a written agreement, that is itself a relevant input to your decision.

Frequently asked questions

Is the law already in force?

It was published in December 2024, but it takes full effect on 1 December 2026. Until then Law 19.628 still governs.

Does it apply if I work alone with few clients?

Yes. The law reaches any natural or legal person processing personal data; size affects which measures are proportionate, not whether the law applies.

What if my software is hosted outside Chile?

That is an international transfer and needs to rest on the safeguards the law provides. Ask your vendor for their processing agreement and document where the data sits.

Do I need to appoint a data protection officer?

It is not a general requirement for a small practice, but it helps to have one identified person accountable for this, even part-time.

This guide is informational and is not legal advice. Check the regulations in force in your country and consult a professional if in doubt.

Next step

Take clinical nutrition to the next level with Almendra

Design plans, manage clients, and automate follow-ups in a single platform.

Get started for free
We use cookies
These cookies help us keep the page secure, give you a better experience, and show you more relevant advertising. We won't turn them on unless you agree.

Read more on our Privacy policy