CBCTHubCBCTHub
PricingBlogHelp
 
 
Back to blog
data-protectioncompliancechileley-19628ley-21719healthcare-dental

Patient data protection in Chile: Law 19.628 and the new Law 21.719 for dental imaging centers

CBCTHub·June 28, 2026
Patient data protection in Chile: Law 19.628 and the new Law 21.719 for dental imaging centers

Chile is going through the most important regulatory shift in personal data protection in more than two decades. Law 19.628 on the Protection of Private Life, in force since 1999, was for years one of the more permissive regimes in the region. That changes with Law 21.719, published in December 2024 and fully in force from December 2026, which modernizes the regime by aligning it with the EU GDPR and creates the new Personal Data Protection Agency.

For a dental imaging center in Chile, this means a two-year transition period during which you must adapt processes, vendor contracts, and technical safeguards. This article explains what each law says, what changes with 21.719, and how CBCTHub already meets both sets of obligations.

Regulatory framework for a Chilean dental clinic

  • Law 19.628 (1999) on Private Life Protection. Currently in force.
  • Law 21.719 (2024) amending 19.628. Creates the Personal Data Protection Agency and meaningful fines. Effective December 2026.
  • Law 20.584 (2012) on Patient Rights and Duties. Regulates confidentiality of the clinical record.
  • Chilean Sanitary Code articles on professional secrecy.
  • 2018 Constitutional Reform: article 19 number 4 recognizes personal data protection as a fundamental right.

Law 19.628: what is in force today

Sensitive data and consent

Article 2(g) of Law 19.628 defines sensitive data as anything referring to physical or moral characteristics, explicitly including health-related data. Article 10 requires specific written consent to process this data, unless the law expressly authorizes it.

Data subject rights

Access, modification, erasure, and blocking. They are exercised by registered letter or equivalent. The controller has two business days to respond.

Clinical record

Law 20.584 establishes that the clinical record is the property of the provider, but the data belongs to the patient. It must be kept for at least fifteen years. The patient may request a copy and it must be delivered within a reasonable timeframe.

Penalties under 19.628

The current regime is weak: fines from 1 to 50 UTM per infraction (roughly USD 70 to USD 3,500). Without a dedicated supervisory authority, fines are imposed via civil lawsuit.

Law 21.719: what changes from December 2026

New Personal Data Protection Agency

For the first time Chile will have a regulator with audit and sanctioning power, similar to the Spanish AEPD or Mexican INAI.

Significantly higher fines

  • Minor infractions: up to 5,000 UTM (about CLP 326 million).
  • Serious infractions: up to 10,000 UTM (CLP 650 million).
  • Very serious infractions: up to 20,000 UTM (CLP 1.3 billion, about USD 1.4 million).

New obligations

  • Mandatory Data Protection Officer for large-scale processing of sensitive data (this includes imaging centers).
  • Documented record of processing activities.
  • Breach notification to the Agency within 72 hours.
  • Data Protection Impact Assessment (DPIA) for high-risk processing.
  • Right to data portability.
  • Privacy by design and privacy by default.
  • Strict rules for international transfers.

Concrete risks for a Chilean dental imaging center

Many Chilean clinics still use WhatsApp to send scans, unencrypted Google Drive for backups, or unprotected USB drives. Those habits, tolerated under Law 19.628, become serious infractions from December 2026. A single reported incident can result in fines of several hundred million pesos.

How CBCTHub helps you comply with Law 19.628 today and Law 21.719 tomorrow

Informed consent in Law 20.584 format

CBCTHub generates informed-consent templates adapted to Chilean legislation, with clear language about purpose, legal basis, retention period, and patient rights. The patient signs electronically and the signature is publicly verifiable.

End-to-end encryption

TLS 1.3 on all connections and AES-256 at rest in Cloudflare R2. Meets the technical safeguards required by Law 21.719 security articles.

Exportable audit log

Every exam access is recorded. When the Agency or a patient asks who viewed their scan, you export the log in CSV from the dashboard.

PIN and unique links with expiration

Each exam has a unique URL with opaque identifier and optional PIN. The clinic''s public page requires a mandatory PIN. Links expire automatically per the policy you configure.

Right to erasure (Law 19.628 art. 12 and future right to be forgotten)

The endpoint DELETE /api/v1/exams/{id} removes the exam and all DICOMs in R2. Fulfills an erasure request in seconds.

Portability ahead of schedule

Although Law 19.628 does not require portability, Law 21.719 does. The endpoint /api/account/export-data already returns data in structured JSON, so you are ready when it comes into force.

Processing agreement

CBCTHub signs a data processing agreement with every Chilean center, aligned with what Law 21.719 will introduce for processors.

Multi-tenant RLS on Supabase

Strict isolation between clinics via Row Level Security. Your center can never see another clinic''s data, not even by a developer mistake.

Location and breach notification

We have an incident response procedure that meets the 72-hour clock introduced by Law 21.719. If we detect a breach, we notify you so you can report to the Agency.

Compliance checklist for your Chilean imaging center

  • Designate a data protection officer (get ready for the 21.719 mandatory DPO).
  • Document all processing activities.
  • Sign processing agreements with CBCTHub and other vendors.
  • Informed-consent template per Law 20.584.
  • 15-year retention policy for the clinical record.
  • Procedure for handling access, modification, and erasure requests.
  • Incident response plan with 72-hour clock (get ready for 21.719).
  • Annual staff training.
  • Audit cloud vendors and require encryption.

FAQ

Can I keep using WhatsApp to send scans?

Today it is a gray area under Law 19.628. From December 2026 with Law 21.719, it will clearly be an infraction because it fails to meet the security and traceability requirements. Use a secure CBCTHub link instead.

How long must I retain the CBCT?

Law 20.584 sets a minimum of fifteen years for the clinical record, which includes the associated exams.

What happens if I lose a backup with patient data?

Today the penalty is low. From December 2026, failure to notify the breach to the new Agency may be a very serious infraction with fines of up to 20,000 UTM.

Do I need a DPO?

Not today. Under Law 21.719, if your center processes sensitive data at scale (any active imaging center does), you will. Designate one now so you do not improvise in 2026.

Official resources

  • Law 19.628 at BCN
  • Law 21.719 at BCN
  • Law 20.584 on Patient Rights and Duties
  • Chilean Ministry of Health

Download the CBCTHub processing agreement | Our solution for imaging centers in Chile | Plans and pricing

This article is informational and does not constitute legal advice. Consult with a Chilean data protection lawyer for your specific case.

Try free viewerSee solutions

Try CBCTHub for free

Upload, view, and share DICOM scans in the cloud. Nothing to install.

Create free account

Related articles

Patient data protection in Spain: LOPDGDD 3/2018 and GDPR compliance for dental imaging centers

Patient data protection in Spain: LOPDGDD 3/2018 and GDPR compliance for dental imaging centers

How a dental imaging center complies with Spain's LOPDGDD 3/2018, EU GDPR, and Law 41/2002 on clinical records. Obligations, penalties up to EUR 20M, and how CBCTHub helps.

Patient data protection in Mexico: LFPDPPP, INAI, and NOM-024 compliance guide for dental imaging centers

Patient data protection in Mexico: LFPDPPP, INAI, and NOM-024 compliance guide for dental imaging centers

How to comply with Mexico's LFPDPPP, its regulation, NOM-024-SSA3-2012, and NOM-004 at a dental imaging clinic. INAI, Privacy Notice, UMA-based fines. How CBCTHub helps.

Patient data protection in the USA: HIPAA and HITECH compliance guide for dental imaging centers

Patient data protection in the USA: HIPAA and HITECH compliance guide for dental imaging centers

How to comply with HIPAA (Public Law 104-191), Privacy Rule, Security Rule, and HITECH Act in a dental imaging clinic. PHI, BAA, OCR fines up to USD 1.5M per year.

CBCTHubCBCTHub

Digital CBCT delivery. 100% local processing. No CDs, ever.

Download on theApp Store
Get it onGoogle Play

Solutions

Imaging centersDental radiologistsOnline CBCT viewer

Product

FeaturesPricingBlogAlternativesLearnEducationNewDevelopersAPIDemo

Support

Help centerFAQContactsoporte@cbcthub.comStatus+56 9 7632 9096

Company

AboutSecurityTerms of servicePrivacy policy

By country

United StatesUnited KingdomCanadaAustralia
HIPAA-readyGDPRLGPDLey 21.719

© 2026 CBCTHub. All rights reserved.

AppLab Software LLC · 1021 E Lincolnway, Cheyenne, WY 82001