a Go.
· Sixto Valdés

Chile Law 21.719 guide for WordPress sites (2026)

What Chile's Law 21.719 on data protection requires from WordPress sites, what changed from the previous regime and how to automate most of the compliance work with the aGo Legal Pro plugin (USD 49.9 per year).

WordPressComplianceLaw 21.719ChileGDPR
§ Summary

What Chile’s Law 21.719 on data protection requires from WordPress sites, what changed from the previous regime, what your site must include and how to automate compliance.

Chile’s Law 21.719 on personal-data protection replaces the older Law 19.628 with a standard much closer to GDPR. If your website processes personal data of Chilean residents (a contact form, a newsletter, a WooCommerce store), the law applies to you. This guide covers what it requires, what your WordPress site must include and how to automate most of the compliance work.

What changes with Law 21.719

AspectBefore (Law 19.628)Now (Law 21.719)
ConsentVague, implicit acceptableExplicit, informed, verifiable, granular
Data-subject rightsLimited access and rectificationThe five of art. 14 ter letter f: access, rectification, deletion, objection and portability
Published processing policyNo minimum contents definedTwelve minimum contents, permanently available (art. 14 ter)
Breach notificationNot requiredMandatory, by the most expeditious means available and without undue delay (art. 14 sexies)
Data protection officerNot contemplatedDiscretionary: art. 50 says the controller may appoint one
PenaltiesLowSignificant tiered fines

The Personal Data Protection Agency (APDP) is the new regulator.

§ What the Chilean statute does not ask for

Three duties commonly attributed to Law 21.719 come from the European regulation and are absent from the Chilean text.

A record of processing activities. The phrase appears nowhere in the Chilean text. What the statute orders is publishing the categories of data, the universe of people, the recipients, the purposes and the legal basis (art. 14 ter, letter d), and having a retention period defined per category (art. 3, letter c). The internal inventory that makes writing all that possible is good practice.

Appointing a data protection officer. Art. 50 says the controller may appoint one. It is one of the elements of the infringement-prevention model of art. 49, and adopting that model is voluntary too.

An hours-based deadline to notify a breach. Art. 14 sexies asks to report to the Agency by the most expeditious means available and without undue delay, and sets no deadline.

What your WordPress site must include

Your site must let the visitor accept or reject cookie categories (analytics, marketing, functional). A blanket “accept all” banner is not enough.

2. Updated privacy policy

It must explicitly mention Law 21.719, the data-subject’s ARCO+ rights, response deadlines and who to contact to exercise them.

A list of cookies, category, duration and provider.

4. ARCO+ workflow

The data subject can request: to see their data, correct it, delete it, object to its processing and obtain it in a portable format. You need a process (a generic email is not enough).

Auditable record of what each visitor consented to and when. It must be demonstrable if the APDP asks.

6. Processing register

Inventory of what personal data you process, for what, on what legal basis and for how long.

Doing this manually takes weeks and requires a lawyer.

Sixto Valdés

How to automate most of it with WordPress

Doing this manually takes weeks and requires a lawyer. With serious plugins, much of it gets automated.

For WordPress our plugin aGo Legal Pro (USD 49.9 per year per site, with updates and direct support included) is built to help you address Law 21.719 without writing code. It delivers out of the box:

  • Cookie banner with granular categories.
  • Auto-generation of Privacy Policy, Cookie Policy, Terms and Conditions aligned to Law 21.719.
  • Full ARCO+ workflow with public form, tracking page and deadlines.
  • Consent log with SHA-256 hashing (anti-tampering).
  • Google Consent Mode v2 (you do not lose legitimate measurements).
  • Pre-consent script blocking (GA, Meta Pixel, Hotjar do not load until the visitor consents).
  • Multi-law: Law 21.719 + GDPR + LGPD + CCPA + PIPEDA in a single plugin.

See the aGo Legal Pro plugin

Conclusion

Law 21.719 is not optional and generic global plugins (CookieYes, OneTrust in their free tier) do not cover Chilean ARCO+. There are two paths: implement by hand (weeks plus a lawyer) or use a specialized plugin such as aGo Legal Pro (USD 49.9 per year).

For specific questions, let’s talk.


Official sources

§ Next step

Want to dig deeper? Get in touch at hola@ago.cl and we will review your case.

§ Technical notice

Technical notice, not legal advice

aGo lab is a technology studio. We describe how to implement software systems that can help comply with Chile's Personal Data Protection Law 21.719, not the official interpretation of the statute.

For legal decisions about compliance, consult a lawyer specialized in data protection. Law 21.719 enters full force on December 1, 2026. Verify the official text at bcn.cl and the doctrine of the Chilean Data Protection Agency.

§ FAQ

Frequently asked questions

What is Chile Law 21.719 and when does it apply?

[Chile Law 21.719](https://www.bcn.cl/leychile/navegar?idNorma=1209272) on Personal Data Protection was enacted December 2024 with full enforcement December 2026, after a 24-month adaptation period. It replaces old Law 19.628 and aligns Chile with standards similar to European GDPR and Brazilian LGPD. Applies to any controller processing personal data of people in Chile.

Does my SMB WordPress site have to comply with Law 21.719?

Yes if it processes personal data: contact forms, newsletter, comments with email, e-commerce, user login. Business size does NOT exempt you. The argument 'we're too small for fiscalization' is expensive because art. 35 grades fines by how serious the infringement is, up to 5,000 UTM for minor ones, 10,000 for serious and 20,000 for very serious, and the Data Protection Agency can act ex officio. During the first twelve months in force, the Agency may issue a written warning instead of a fine to smaller companies (sixth transitional article).

What does a WordPress site need to comply with Law 21.719 from December 2026?

Minimum: 1) A processing policy published and permanently available, carrying the twelve contents of art. 14 ter, among them the lawful basis per purpose. 2) Prior, specific and unambiguous consent for non-essential cookies, with the reject option as visible as accept (art. 12). 3) An ARCO+ request channel with requester identity verification and an answer within thirty calendar days, extendable once (art. 11). 4) A retention period defined per data category, with deletion or anonymization once it expires (art. 3, letter c). 5) Security measures you can evidence and a procedure to report breaches to the Agency (art. 14 quinquies and art. 14 sexies).

Is installing a cookies plugin enough?

No. Cookie banner plugins cover consent, but Law 21.719 also requires an ARCO+ request channel with verified identity answered within thirty calendar days (art. 11), a processing policy with the lawful basis declared per purpose (art. 14 ter), preserved proof of consent granted and revoked (art. 12, final paragraph) and security measures you can evidence (art. 14 quinquies). aGo Legal Pro (USD 49.90 per year) covers those four fronts in a single plugin, with consent log SHA-256 hashed per entry plus batch hash for auditable integrity verification.