Chile Personal Data Protection Law (LPPD) Compliance
Pandectes GDPR Compliance helps Shopify stores meet LPPD requirements by blocking non-essential cookies until visitors consent, scanning and classifying cookies, and keeping consent records.
Start Free
The #1 cookie consent app for Shopify, trusted by 185k stores
What is LPPD?
LPPD is a common name for Chile’s new personal data protection law, Law No. 21.719, which regulates the protection and processing of personal data and creates the Personal Data Protection Agency. It was published in the Official Gazette on 13 December 2024. Rather than replacing Chile’s 1999 privacy law, Law No. 19.628, it rewrites most of it, bringing Chilean rules much closer to the EU’s GDPR.
Its key rules include:
- Personal data may be processed with the consent of the data subject or on another legal basis set out in the law, such as performing a contract, meeting a legal obligation, or a legitimate interest.
- Consent must be free, specific, unequivocal, and informed, given through a statement or a clear affirmative action.
- Individuals have rights of access, rectification, erasure, objection, portability, and blocking of processing, as well as rights regarding automated decisions, including profiling.
- Businesses must tell people how their data is processed, keep it secure, and report security breaches.
- International transfers of personal data are allowed only under the conditions in the law, such as transfers to countries with adequate protection or with appropriate safeguards.
- A new independent regulator, the Personal Data Protection Agency (Agencia de Protección de Datos Personales), supervises the law and can impose sanctions.

Who does the LPPD apply to?
The LPPD applies to public bodies and private organizations of every size that process personal data in Chile. It also applies to businesses outside Chile when their processing is aimed at offering goods or services to people in Chile, or at monitoring their behavior, including tracking and profiling, so a foreign online store selling to Chilean customers can fall within its scope.

What happens if I don’t comply with the LPPD?
The LPPD classifies infringements as minor, serious, or very serious, with fines set in UTM (unidad tributaria mensual), a Chilean inflation-indexed monetary unit:
- Minor infringements: A written warning or a fine of up to 5,000 UTM.
- Serious infringements: Fines of up to 10,000 UTM.
- Very serious infringements: Fines of up to 20,000 UTM.
- Repeat infringements: For companies that are not small businesses and repeat a serious or very serious infringement, fines can reach 2% or 4% of annual revenue, respectively.
- Uncorrected violations: If the measures ordered by the Agency are not taken within 60 days, the fine increases by 50%.
- Public record: Sanctions are recorded in a public National Register of Sanctions and Compliance kept by the Agency.
During the first year the law is in force, the Agency may issue a written warning instead of a fine to smaller businesses.
When will the LPPD go into effect?
Law No. 21.719 is scheduled to come into force on 1 December 2026, 24 months after its publication. In September 2026, the government sent Congress a bill to postpone that date to 1 December 2027. Until such a change is approved and published, 1 December 2026 remains the legal date.
Complying with the LPPD
If your online store sells to customers in Chile, the LPPD can apply to the personal data you collect from them, including data collected through cookies and tracking tools that monitor how visitors behave on your storefront.
For cookies and tracking, the main points are:
- Consent: For analytics, advertising, and other non-essential cookies, ask for consent before they are set. Consent must come from a clear affirmative action, so pre-ticked boxes or simply continuing to browse are not enough, and visitors should be able to withdraw it at any time.
- Notice: Tell visitors what data you collect, for what purposes, who receives it, and how they can exercise their rights, including details of the third-party tools that place cookies on your store.
- Cross-border transfers: Many analytics and marketing tools process data outside Chile. Check that each provider offers a basis for the transfer that the law recognizes.
- Data subject requests: Be ready to respond to requests for access, rectification, erasure, objection, and portability.
To prepare, consider using a Consent Management Platform (CMP) like Pandectes GDPR Compliance. It shows a cookie banner that blocks non-essential cookies until the visitor consents, scans your store to detect and classify cookies automatically, and generates a cookie declaration for your policy page. It keeps consent logs as proof of each visitor’s choice, helps you handle data subject requests, and uses geolocation to show region-specific banner settings to visitors from different countries. Pandectes GDPR Compliance is designed specifically for Shopify stores.
The Agency’s guidance and the law’s start date may still change, so review your setup with legal counsel where appropriate.














