Law No. 21,719 turns facial features into sensitive personal data, while municipalities and institutions expand video surveillance with artificial intelligence and the new Personal Data Protection Agency is not yet established. An analysis of the Chilean framework, comparative experience and the obligations facing institutions, companies and individuals.
On December 1, 2026, the substantive regime of Law No. 21,719 (Ley N° 21.719) takes effect, and with it a rule that redefines the conditions of any camera installed in a Chilean public space: facial features become sensitive personal data. The change comes at a singular moment. Municipalities of different sizes are adding video analytics and artificial intelligence to their video-monitoring systems, a recently published law (Law No. 21,802, Ley N° 21.802) mentions facial recognition for the first time among the tools municipalities may make available to criminal prosecution, and a bill on artificial intelligence, still in progress, proposes to prohibit real-time remote biometric identification, though with an exception for public security. To that convergence is added a circumstance that complicates the picture: the authority called to supervise the new regime is not yet constituted.
This analysis offers an overview of the legal framework applicable to facial recognition in public spaces, contrasts the most recent comparative experience and specifies the obligations the new legislation imposes on institutions, companies and individuals. The discussion admits no easy answers. The technology is not prohibited, but neither is it permitted unconditionally: the law imposes a set of requirements of lawfulness, proportionality and transparency whose breach gives rise to liability. Understanding that balance, and not the mere availability of the device, is what makes it possible to decide in an informed way.
The problem: security, proportionality and informational self-determination
Facial recognition in public spaces poses a conflict between legitimate interests. On one side, public security and criminal prosecution, whose effectiveness can be aided by the automated identification of wanted persons. On the other, fundamental rights such as data protection, private life and, less obviously, the freedoms of assembly and expression, which tend to be chilled when people know they are permanently identifiable as they move through the street. The American sociologist Shoshana Zuboff has observed that, in a space under permanent surveillance, it makes no sense to speak of informed consent or voluntary opt-out, since no one can wholly withdraw from the public spaces they move through every day. The idea has a direct legal translation: if there is no real option to avoid capture, consent ceases to be free, and the processing of sensitive data must rest on another lawful basis and pass a strict proportionality test.
Chilean constitutional law recognizes informational self-determination as a manifestation of the protection of personal data incorporated into Article 19 No. 4 of the Constitution. Any measure that restricts it must pass a test of suitability, necessity and proportionality in the strict sense: that it serves a legitimate aim, that there is no equally effective less intrusive means, and that the sacrifice of the right is not excessive against the benefit pursued. A relevant fact for that test is that facial identification is not infallible, and that its margin of error is not distributed uniformly.
The available technical evidence shows that the accuracy of these systems varies by demographic group. The United States National Institute of Standards and Technology (NIST), in its benchmark 2019 study on demographic effects (report NISTIR 8280), evaluated 189 algorithms from 99 developers and found higher false-positive rates in women, in people of African and Asian descent, and markedly so in women of African descent. Earlier academic research (the Gender Shades study, of 2018), in tasks classifying gender from the face, had found error differences of more than 30 percentage points between dark-skinned women and light-skinned men. Although those measurements are not exactly equivalent to the one-to-one identification a security system performs, they illustrate a risk the Chilean State itself has already confirmed: in tests carried out in the country in 2018, the Investigations Police (PDI) reported high percentages of false positives. A system that errs unevenly across groups poses not only a data problem but also one of equality before the law.
The Chilean framework: from the Constitution to Law No. 21,719
The foundation is constitutional. Law No. 21,096 (Ley N° 21.096), published on June 16, 2018, incorporated into Article 19 No. 4 of the Constitution the protection of personal data, providing that its processing will be carried out “in the manner and under the conditions established by law”. The standard applicable to public thoroughfares is that provision, concerning private life and personal data, and not Article 19 No. 5, which protects the inviolability of the home and of private communications and does not extend to public space.
The law that gives effect to that mandate is today Law No. 21,719, published on December 13, 2024, which amends Law No. 19,628 (Ley N° 19.628) and creates the Personal Data Protection Agency. Its substantive regime takes effect on December 1, 2026, after a 24-month adaptation period. Three definitions are decisive for facial recognition. First, biometric data are sensitive personal data: the law includes them among the categories of sensitive data in article 2 of Law No. 19,628 and defines them in its article 16 ter as those referring to the physical, physiological or behavioral characteristics that allow the unique identification of a person, with express mention of facial features. Second, the processing of sensitive data requires, as a general rule, the express consent of the data subject, together with specific duties to provide information about the system, its purpose and how to exercise rights, and it proceeds without consent only in the cases specified by the law (article 16). Third, processing by public bodies, including municipalities, is governed by a special title (Title IV, articles 20 et seq.) that allows them to process data without consent when it is necessary for the performance of their legal functions, within the scope of their competence and subject to the principles of the law.
The reform also incorporates the impact assessment in data protection (article 15 ter) as a prior requirement for processing that may generate a high risk to the rights of data subjects, a category that may include the systematic surveillance of publicly accessible areas through sensitive data. The sanctions regime classifies breaches as minor, serious and very serious, with fines of up to 5,000, 10,000 and 20,000 monthly tax units (UTM), respectively, the last on the order of $1,400 million depending on the value of the unit, in addition to aggravated penalties in the event of recidivism. The processing of sensitive data without a valid lawful basis ranks among the most severe breaches.
A law in force without a fully operational authority
In mid-2026 a circumstance that should not be overlooked is added to that architecture. Law No. 21,719 entrusts supervision and the sanctioning power to the Personal Data Protection Agency, whose Governing Council was to be constituted before the entry into force. In May 2026, however, the Senate rejected the slate of councilors put forward by the Executive, as the two-thirds quorum its appointment requires was not reached (the proposal obtained 19 votes in favor and 12 against), and the legal deadline to constitute the body passed without any designation.
The result is an unusual situation. From December 1, 2026, the obligations of the law will be fully enforceable, but the body called to interpret them, to issue its technical rules and to exercise the sanctioning power might not be operational. For institutions and companies, that uncertainty does not suspend the duty to comply. Rather, it advises adapting in advance, because the obligations arise from the law and not from the Agency going live, and the subsequent regularization of the body will not cure the processing that was unlawful in the meantime.
Municipal security and artificial intelligence: two rules in opposite directions
Two recent legislative developments pull in opposite directions. Law No. 21,802, published on February 11, 2026, strengthened the municipal institutional framework for public security and, in its article 5(c), contemplates the collaboration of municipalities with the Public Prosecutor’s Office through, among other forms, “online access to information held in IT or video-monitoring systems that may aid criminal prosecution, such as facial recognition systems, vehicle license-plate readers or data-analysis platforms”. It is the first time a Chilean law expressly names facial recognition as a tool whose access municipalities may make available to criminal prosecution.
In the opposite direction advances the bill regulating artificial intelligence systems, merged into bulletins 16.821-19 and 15.869-19, approved in detail by the Chamber of Deputies on October 13, 2025, and currently in its second constitutional reading in the Senate. That bill, following the European model of classification by risk tiers, proposes to place real-time remote biometric identification in publicly accessible spaces among the uses of unacceptable risk, that is, prohibited, though with an exception for public security and criminal prosecution. The amendments that sought to narrow that exception, requiring prior judicial authorization, were rejected in committee.
The coexistence of these rules is not contradictory if they are construed systematically. One rule already in force enables municipalities to share facial recognition access with the prosecution service; another, Law No. 21,719, requires a lawful basis, proportionality and an impact assessment to process the face as sensitive data; and a bill in progress seeks to prohibit that same real-time identification, except for public security. The authorization to collaborate with criminal prosecution does not exempt anyone from complying with the data protection regime or from the proportionality test. It requires, from whoever deploys the technology, careful legal justification. That same standard reaches the mass data analytics platforms now offered to municipalities and companies, which we analyze separately.
The comparative experience
The Chilean discussion does not take place in a vacuum. In recent years, courts and authorities in various countries have set standards worth keeping in view, which in general do not question the technology itself, but its use without a precise legal framework, without an impact assessment and without control of biases.
In the United Kingdom, the case R (Bridges) v Chief Constable of South Wales Police ([2020] EWCA Civ 1058), decided by the Court of Appeal of England and Wales, declared police use of live facial recognition unlawful for three reasons: a legal framework that left excessive discretion over where to deploy it and whom to include on the watchlists, a deficient impact assessment and the failure to verify possible race and sex biases in the software. The ruling did not prohibit the technology; it required a more precise framework. The subsequent institutional response is illustrative: in late 2025 the Home Office (the UK interior ministry) opened a public consultation to create a specific legal framework on police facial recognition and biometrics, while the Metropolitan Police (London) installed its first permanent fixed cameras of this kind. The official figures accompanying that deployment are part of the debate: the police itself reported more than 900 arrests attributed to the technology between September 2024 and September 2025 and, in a recent pilot, a single erroneous alert among more than 470,000 people checked. Those data, coming from the police authority, coexist with the objections of human rights bodies about their proportionality.
In the European Union, the Artificial Intelligence Regulation (Regulation (EU) 2024/1689, known as the AI Act), whose prohibitions have applied since February 2, 2025, establishes as a rule the prohibition of real-time remote biometric identification in publicly accessible spaces for law enforcement purposes (article 5), with specified exceptions (searching for victims, an imminent terrorist threat or locating suspects of serious crimes) subject to prior judicial or administrative authorization and to a fundamental rights impact assessment. For the other operators, remote biometric identification systems are considered high risk and are subject to strict requirements. The application of these rules is gradual and, in 2026, a simplification package known as the Digital Omnibus, agreed by the Parliament and the Council, postponed the enforceability of the obligations for high-risk systems until December 2, 2027.
In Spain, the Spanish Data Protection Agency (AEPD) in 2021 fined the supermarket chain Mercadona 3.15 million euros (proceeding PS/00120/2021), later reduced to 2.52 million for voluntary payment and acknowledgment of liability, for a facial recognition system installed in 48 stores to detect people subject to restraining orders. The authority concluded that the processing was prohibited by article 9.1 of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), as it lacked a sufficient enabling basis to process special categories of data, and reproached the company for having confused the system’s usefulness with its necessity, subjecting all of its customers to biometric identification to locate a few. The underlying principle, proportionality and data minimization, is the same one the Chilean law adopts.
In the United States, in the absence of a federal law, the state of Illinois has had, since 2008, the Biometric Information Privacy Act (BIPA; 740 ILCS 14), which requires prior written consent and sets statutory damages of between US$1,000 and US$5,000 for each violation. That statute has generated high-value litigation, including a Facebook (now Meta) settlement of US$650 million, and its case-law interpretation, which at one point allowed each capture to be counted as a separate violation, led in 2024 to a legislative reform that limited the accumulation of damages. Several cities, such as San Francisco, have also prohibited the use of facial recognition by their public bodies. The contrast with the European and Chilean approach is instructive: where the European law regulates mainly the use, the Illinois model deters through civil liability.
In Latin America the trend is convergent. In Argentina, the Fugitive Facial Recognition System (SRFP) of the City of Buenos Aires was declared unconstitutional in its implementation in 2022, a decision confirmed in 2023, after it was established that it had been used to query the data of millions of people unconnected to the wanted lists and that the required controls and impact assessment were missing. In Brazil, where the Lei Geral de Proteção de Dados (General Data Protection Law, LGPD; Lei N° 13.709, of 2018) also classifies biometric data as sensitive, the 6ª Vara de Fazenda Pública de São Paulo suspended in 2022 the facial recognition system of the São Paulo Metro for failing to substantiate its purpose or to meet the requirements of that law. Added to this is the coordinated action of the European authorities against the company Clearview AI, which has accumulated multimillion penalties in several countries (among them, 30.5 million euros imposed by the Dutch authority in 2024) for having built a database of more than 30 billion facial images without a legal basis.
At the international level, the Office of the United Nations High Commissioner for Human Rights (OHCHR) called for the utmost safeguards against these technologies and, in its report A/HRC/48/31 of 2021, recommended a moratorium on the use of systems that do not meet human rights standards, a position reiterated in later reports.
What is already happening in Chile
The debate is not hypothetical in Chile either, where different forms of facial recognition already coexist without a uniform framework. Two cases illustrate the point. In Temuco, the artificial intelligence video surveillance project announced in mid-2026, with funding from the Inter-American Development Bank (IDB), has for now been framed without facial recognition, limited to behavior analysis, which is an example of a more narrowly tailored design. Coexisting with it, however, are other initiatives, such as the installation in a public high school in the city, during 2025, of an access gate with a facial recognition camera, a measure the Superintendence of Education questioned and inspected for not conforming to the sector’s rules. In Las Condes, the system promoted years earlier gave rise to a warning from the Council for Transparency (CPLT) about the high percentages of false positives detected in the tests, close to 90% in a trial carried out in a shopping mall in the municipality, a fact the body itself took into account in deeming the measure disproportionate. Both cases show the two faces of the same void: that of a use that gets ahead of the rule and that of a technology whose reliability has been called into question.
What it means for institutions, companies and individuals
For the institutions and public bodies that operate or plan video surveillance systems, adaptation cannot wait. The legal authorization to collaborate with criminal prosecution does not replace the need for a valid lawful basis, a purpose that is specified and confined to security, or an impact assessment when the processing is high risk. To this are added duties that comparative practice has made unavoidable:
- Inform the public about the existence and purpose of the system.
- Limit the retention periods for the images.
- Adopt security measures that prevent third-party access.
- Guarantee individuals’ rights of access and deletion.
- Document the proportionality test that justifies the measure.
Earlier guidance, such as the recommendations the Council for Transparency issued in 2017 for municipal video surveillance, anticipated many of these requirements, which the new law raises to a legal duty.
For companies, the critical point is twofold. As data controllers, they must have a lawful basis, carry out the impact assessment and observe the principles of purpose and minimization, avoiding the mistake that comparative experience has penalized: subjecting a broad universe of people to biometric identification to reach a few. As providers of technology to a third party, the distribution of security responsibilities, deadlines, audits and the consequences of an incident must be defined in writing. A leak of biometric data is not a minor reputational problem: it may constitute a reportable incident under the Cybersecurity Framework Law (Law No. 21,663, Ley N° 21.663), whose risk-management and notification obligations have been in force since 2025, and trigger liability under Law No. 21,459 (Ley N° 21.459) on computer crimes. Early adaptation, within a data protection compliance program, is the way to transform legal exposure into a competitive advantage.
For individuals, the new legislation strengthens a set of powers worth knowing. Any citizen has the right to know which video surveillance systems their municipality operates, for what purpose and under what safeguards, information they can request through the transparency route. The data law also recognizes rights of access, rectification, deletion and objection over personal information, and against processing deemed unlawful or arbitrary the legal order provides the constitutional protection action (recurso de protección), without prejudice to a complaint before the future Agency once constituted. Chilean case law on the matter is still scarce and has not decided a case of facial recognition in public space, but the framework to bring a claim exists and is strengthened by the reform.
A decision that demands justification, not just technology
Facial recognition in public space is not, under Chilean law, a prohibited technology or a freely available tool. It is a processing of sensitive data subject to conditions: a lawful basis, a serious test of necessity and proportionality, an impact assessment, and duties of transparency and security. Comparative experience teaches that the deployments that were annulled or penalized were not so because of the technology itself, but for having dispensed with that framework. The question to ask, then, is not whether the technology exists or whether security justifies it in the abstract, but whether its concrete use satisfies the conditions the law imposes. That is a legal decision before a technical one, and its soundness will depend on the quality of the justification that supports it.
This article is general and informational in nature and does not constitute legal advice for any specific case. If your institution, company or organization needs to bring a video surveillance or biometric data processing system into line with Law No. 21,719, or if you believe your rights have been affected, contact us for a specific analysis.