The advance of artificial intelligence created a new generation of platforms that integrate and analyze data at large scale, such as those of Palantir, now offered to governments, municipalities and companies. What conditions has comparative law set for them? What does Chile's legal order in transition require? And what must be settled in writing before signing?
In less than three years, artificial intelligence went from drafting text to operating on organizations’ systems. Its most ambitious form is the platforms that work directly with data: they integrate it, cross-reference it, detect patterns and propose or execute decisions. States have become the most coveted client of this new industry, and Chile already appears on its commercial map, as municipalities and public agencies devote growing budgets to cameras, crime analytics and mass information management, and companies bring these same platforms into their operations. The question now reaching municipal governments, agency heads and boards is concrete: can this be contracted, and under what conditions?
This analysis provides the answers that decision demands, with the sources in plain sight. What exactly do these platforms do, and why are they not just another database? What conditions have the courts and legislatures of comparable democracies imposed on them? Where does the Chilean legal order stand, with Law No. 21,719 (Ley N° 21.719) on the protection of personal data months away from full enforceability? And what must be settled in writing before signing? We state the conclusion up front: none of these technologies is banned in Chile, but the era when they could be adopted without a legal basis is over.
What are those who contract them really buying?
For decades, public data software served a filing function: storing records and returning them when someone looked them up. Criminal records in one database, vehicles in another, immigration movements in a third, and an official cross-referencing them by hand when an investigation required it. What is offered today to States and large corporations belongs to another category: platforms that connect repositories built in isolation from one another, reconstruct networks of links between people, assets and events, and, in their most recent layer, incorporate artificial intelligence models capable of suggesting decisions and executing them on those same data.
The mechanics, stripped of jargon, have three steps. First, the platform connects to the sources that already exist (databases, spreadsheets, cameras, complaint systems) without replacing them. Second, it unifies scattered identities: the same RUT, the same license plate or the same address appearing in separate records becomes a single object connected to all the others, a map of people, assets, places and events. Third, the analysis works on that map: an investigator looks up a license plate captured by a camera and obtains, in seconds, its owner, that owner’s court cases, their addresses and with whom they share them, a cross-reference that by hand would take weeks of official requests. The artificial intelligence layer operates on top: it answers questions posed in ordinary language about that map and suggests, or simply executes, the next step. The limit is just as mechanical: the map is worth exactly what the data feeding it are worth.
The reference player is Palantir Technologies, founded in 2003 with initial investment from In-Q-Tel, the CIA’s venture capital fund. Its catalog captures the industry’s full range: Gotham, for defense, intelligence and criminal prosecution; Foundry, the corporate variant, which applies the same mechanics to transactions, suppliers or sensors to detect fraud, monitor the supply chain or anticipate failures; and AIP, which since 2023 has orchestrated language models and AI agents over the client’s operational information. One nuance heads off a common misunderstanding: these companies do not trade in personal data; they license the software that integrates and exploits it. For the law the difference matters, because the problem is no longer the sale of the data and becomes instead its processing and the decisions taken on the basis of it.
Anyone following the markets or the technology industry will already have noticed the phenomenon: Palantir was the best-performing stock in the S&P 500 in 2024, closed that year with revenue of US$2,870 million, 29% more than the prior year, and in 2025 came to rank among the most valuable technology companies in the United States. Behind that stock-market performance there are contracts: in July 2025, the United States Army consolidated seventy-five scattered contracts into a single framework agreement with a ceiling of US$10,000 million over ten years (a purchasing cap, not committed spending); months earlier, Immigration and Customs Enforcement (ICE) had commissioned from it ImmigrationOS, the platform that manages the full deportation cycle; and NATO adopted its Maven AI system in a direct award closed in some six months, one of the fastest in its history.
That military and intelligence pedigree explains much of the power of these tools, and also the scrutiny that accompanies them. For legal analysis the underlying fact is enough: systems conceived for defense and espionage are offered today, with the same architecture, to police forces, municipalities and companies. That shift raises the question that orders everything to follow: what rules govern it?
Five conditions comparative law has already set
None of the jurisdictions that have already confronted these systems in court chose to ban them outright. They did something more demanding: turning their use into a matter of verifiable requirements. Five of those requirements recur with a regularity that no buyer or provider should ignore. The selection is not arbitrary: they are the conditions that explain, case by case, why a real system ended up annulled, prohibited or renegotiated. And each one responds to a precise feature of the mechanics described above.
Without a concrete danger there is no automated analysis. The first condition targets the map itself. The German Federal Constitutional Court, in a judgment of February 16, 2023 (cases 1 BvR 1547/19 and 1 BvR 2634/20), struck down the authorizations of Hesse and Hamburg for the automated analysis of police data. In Hesse the tool was already operating: the hessenDATA platform, built on the Gotham that state purchased in 2017; the Hamburg provision fell before it could be applied. The court reasoned that automated processing interferes with the informational self-determination of everyone whose data enter the system, and that such open-ended powers allow the police, in loose translation, to “create complete profiles of people, groups and environments”; for that reason it permits them only in the face of a concrete and identifiable danger to legal interests of particular weight. The record also left a warning on procurement: the framework contract that Bavaria signed in 2022, after a European tender whose criteria only Palantir met, allows the other federal states and the federation to join without a new procurement procedure.
Individual prediction by profiling is prohibited. The second targets the layer that suggests the next step. Regulation (EU) 2024/1689 on artificial intelligence prohibits, as of February 2, 2025 (article 5), systems that assess or predict the risk of a person committing an offense based solely on their profile or on personality traits; it allows AI only in support of a human assessment grounded in objective and verifiable facts directly connected to criminal activity. It also bans the untargeted mass scraping of facial images and sensitive biometric categorization. Systems for criminal prosecution, migration and the administration of justice are classified as high risk, subject to a prior conformity assessment, whose enforceability the Digital Omnibus simplification package deferred until December 2, 2027. Fines for engaging in a prohibited practice reach 35 million euros or 7% of worldwide turnover.
The state algorithm must be capable of being explained. The third attacks opacity: a criterion no one can reconstruct is a criterion no one can review. The District Court of The Hague, in a ruling of February 5, 2020 (ECLI:NL:RBDHA:2020:1878), set aside SyRI, the Dutch risk-scoring system for welfare-benefit fraud, for infringing article 8 of the European Convention on Human Rights: opacity, disproportion and deployment concentrated in lower-income neighborhoods. It was the first European ruling to strike down a state system for the algorithmic scoring of individuals, and the State chose not to appeal. The United Kingdom supplies the contractual version of the same lesson: the National Health Service (NHS) agreement with Palantir for its federated data platform, worth 330 million pounds over seven years, had to be published almost without redactions under pressure from transparency litigation, in the course of which the NHS admitted that sections of the contract on the protection of personal data were still being negotiated after signing. In 2026, the Health Committee of the British Parliament recommended abandoning the platform, and the Government is weighing the exit clause available from February 2027.
Operating from abroad does not exempt anyone from local law. The fourth follows the provider wherever it is incorporated. Clearview AI, which built a biometric database from billions of faces scraped from the internet, has accumulated fines of more than ninety million euros in the Netherlands, France, Italy and Greece. Its recurring defense, that it has no establishment in Europe, has been rejected by the data protection authorities, which apply the law of the place where the affected persons are. In Chile that rule is already written: the article 1 bis that Law No. 21,719 added to Law No. 19,628 (Ley N° 19.628) reaches controllers without an establishment in the country when their operations are aimed at offering goods or services to data subjects in Chile, “or at monitoring the behavior of data subjects located in the national territory, including its analysis, tracking, profiling or behavior prediction”. What remains pending is not the rule: it is enforcing it against a provider with no local presence.
The State’s data cannot fall under a foreign jurisdiction. The fifth asks where the data live and who holds the keys. In the Schrems II judgment (case C-311/18, of July 16, 2020), the Court of Justice of the European Union invalidated the framework that covered data transfers to the United States, because of the disproportionate access of its intelligence agencies. The underlying problem remains open: the United States law known as the CLOUD Act, of 2018, requires providers subject to its jurisdiction to hand over the data they control, wherever it is stored (18 U.S.C. § 2713), and no contractual clause overrides that legal obligation. Anyone who entrusts sensitive information to a foreign provider must accept that reach and mitigate it. None of this is distant theory: Chile knows each of these risks firsthand, although they are rarely named together.
A market with a track record in Chile
The discussion formally landed in our country in May of this year, when Peter Thiel, co-founder of Palantir, was received by President José Antonio Kast at La Moneda, a meeting the Government officially confirmed after a parliamentary request. The meeting matters less for what it was than for what it reveals: the global providers of this industry already regard Chile as a market.
Chile’s criminal-prosecution and intelligence bodies, moreover, have spent more than a decade contracting this class of system, with lower-profile providers and with episodes that foreshadow the problems to come. In 2014, the Investigations Police bought from the Italian firm Hacking Team the Galileo/RCS remote intrusion system, renamed in Chile as Phantom: a program capable of taking covert control of a device, acquired confidentially for US$2.85 million and with a local intermediary whose commission reached 30% of the total. The country only learned of it in 2015, through the mass leak the company itself suffered. The institution defended its use with judicial authorization in the prosecution of crimes; civil society organizations objected to the tool’s proportionality and the opacity of the purchase. It established the national precedent of surveillance technology acquired without prior democratic scrutiny: the same procurement-without-competition flank that the Bavarian contract exposed in Germany.
Forensic extraction followed a similar path. The equipment of the Israeli firm Cellebrite is used across the board by the Investigations Police, Carabineros and the Public Prosecutor’s Office, and its power came into view in the so-called Audios case: the phone of the lawyer Luis Hermosilla, seized in late 2023, was dumped in full with authorization from the guarantee court, and the resulting copy exceeded 777,000 pages. The episode made visible the two legal flanks of forensic extraction: the incidental discovery of offenses other than the one under investigation and the tension with professional privilege. Both are, at bottom, the proportionality problem with which the comparative standard opens: defining the limits of the measure before executing it.
Open-source analytics also has a record of its own, and an instructive one for any buyer. After the 2019 social unrest, a “Big Data Report” circulated to the Public Prosecutor’s Office and the National Intelligence Agency claiming to have processed millions of users and tens of millions of social media comments, prepared by the Spanish firm Alto Data Analytics and received by the ANI “as a sample, at no cost”, as the Comptroller General confirmed. The outcome holds the moral: the prosecutor in charge ended up dismissing it as “just hot air”. It is the mechanical limit anticipated at the outset: the map is worth what the data feeding it are worth. In parallel, Carabineros has operated, since April 2018, the Tactical Police Operation System (STOP), officially presented as a tool to “predict and prevent crime”. The predictive promise is, precisely, the one that comparative law now subjects to the highest standard.
The conclusion is uncomfortable, but it points the way: in Chile these technologies are not just arriving, they are already operating. What was never built around them is the framework of safeguards that comparative law treats as the minimum floor. And that framework is, right now, only half-built.
The regulatory board: what is in force and what is missing
The starting point is Article 19 No. 4 of the Constitution, which since the reform introduced by Law No. 21,096 (Ley N° 21.096), of 2018, guarantees the protection of personal data and makes informational self-determination enforceable through the constitutional protection action (recurso de protección).
On that basis rests the major piece. Law No. 21,719, published on December 13, 2024, creates the Personal Data Protection Agency, and its substantive regime will be fully enforceable on December 1, 2026, at the close of its twenty-four-month vacancy period. For an analytics platform, four of its rules are decisive. Biometric data become sensitive, with a heightened lawfulness standard. Processing capable of generating a high risk to the rights of data subjects requires a prior impact assessment (article 15 ter). International transfers proceed only to countries with an adequate level of protection or with equivalent safeguards. And automated individual decisions are subject to their own rules. Fines reach 20,000 monthly tax units, on the order of $1,400 million. Its Title IV (articles 20 et seq.) allows public bodies to process data without consent when they need it to carry out their legal functions, within their competence: that will be the path for police forces, municipalities and agencies.
There is, however, an anomaly we already examined in analyzing facial recognition: the Agency called to supervise and interpret the law has still not managed to constitute itself. That gap postpones nothing for those bound by the law. The duties arise from the law and not from the installation of the supervisor, and unlawful processing today is not cured because the authority arrives tomorrow.
Around that core orbit four bodies of law that an analytics contract cannot ignore. The first two guard the operation. Law No. 21,663 (Ley N° 21.663), the Cybersecurity Framework, with its essential duties in force since 2025, subjects Vital Importance Operators to risk management and incident notification: a platform that concentrates critical State data may trigger that classification. And Law No. 21,459 (Ley N° 21.459) sets the criminal boundary regarding computer crimes: the data feeding the system must be of lawful origin, and unauthorized access or interception is a crime.
The other two govern the purchase. Law No. 19,886 (Ley N° 19.886) on public procurement, reformed by Law No. 21,634 (Ley N° 21.634), imposes the tender as the rule; direct award invoking confidentiality or urgency, the same mechanism of the Phantom case and of the other states joining the Bavarian contract, is the probity flank that recent history requires examining under a magnifying glass. And Law No. 21,802 (Ley N° 21.802) on municipal security, of February 2026, opened the local entry door: its article 26 authorizes municipalities to arrange citizen-alert and data-analysis systems “implemented by them, by other State Administration bodies or by private parties”, requiring in the latter case that the service be put out to tender under Law No. 19,886 and that the reports the system generates be sent to the Ministry of Public Security and the police forces, while its article 5 contemplates sharing georeferenced information with the Public Prosecutor’s Office and even access to facial recognition systems.
The two missing pieces define the risk of the moment. The bill regulating artificial intelligence systems (bulletin 16.821-19, merged with 15.869-19), approved in detail by the Chamber of Deputies in October 2025 and in its second reading in the Senate, replicates the European risk-tier approach, but it is not yet law: today no Chilean rule expressly prohibits individual predictive policing by profiling, the red line Europe has already drawn. And Law No. 21,821 (Ley N° 21.821), passed by Congress in January 2026 and published on May 30, strengthened the State Intelligence System: it expanded the perimeter of bodies that supply information to the National Intelligence Agency and kept its activity outside the general transparency regime, with the authorization of intrusive measures vested in justices of the Supreme Court. During its passage, the National Human Rights Institute warned of the risk that expanded counterintelligence would lead to internal surveillance of lawful activities. The balance is asymmetric, because the State’s processing capacity grows while its controls do not grow at the same pace. As long as that gap persists, the lawfulness of each project will depend less on the general law and more on the design of each contract.
What must be settled before signing?
Translated into contractual mechanics, the file and the contract must contain, in writing and before signing, at least eight definitions. The number is not incidental: each one responds to a failure documented in the previous sections, from the German judgment to the NHS exit, by way of the Chilean procurement records. These are not statements of principle: they are clauses that are drafted and negotiated, including against a global provider with more lawyers than the client.
- A subject matter with a specified purpose and a ban on secondary use. A generic authorization of the “improve security” type does not withstand scrutiny. The subject matter must narrow the purpose, a processing annex must list categories of data, operations and sub-processors, and an express clause must prohibit the provider from using the client’s information to train its models or for any purpose of its own.
- The impact assessment as a condition of going live. Anticipating article 15 ter means agreeing to it: the provider is obliged to supply the system’s technical documentation (architecture, flows, analysis logic) to carry out the assessment, and entry into production is conditioned on its completion. That file is the proof that the risks were measured before deployment and not after the harm.
- Data residency and encryption keys held by the client. Data hosted in Chile or in a jurisdiction with an adequate level of protection, and encryption whose keys the client retains, so that the provider holds only encrypted material. This architecture does not override the CLOUD Act, but it renders a foreign request materially harmless: the only thing the provider can hand over is unreadable text.
- Transfers and requests from foreign authorities. Standard contractual clauses that withstand the regime of Law No. 21,719, a closed list of sub-processors with a veto right for the client, and the provider’s duty to notify any request from a foreign authority and to exhaust its challenge, unless legally prohibited.
- Audit, logs and explainability. An independent audit right over the system and its biases, tamper-proof access logs held by the client and documentation sufficient to give reasons for the decisions grounded in the platform: an administrative act supported by an unexplainable system is an act difficult to defend in court.
- Minimization by design. Query universes narrowed to the declared purpose, automatic deletion when retention periods expire and a ban on enriching the system with unagreed sources. The system examines the necessary data, not entire populations to find a few cases.
- A competitive route and integrity. The tender is the rule and direct award requires robust and public justification, with transparency of the contract and identification of intermediaries and their commissions: the lesson of the 30% in the Phantom case.
- Indemnity and exit. An indemnity (hold harmless) placing on the provider the fines of the future Agency and the claims of data subjects arising from breaches attributable to it, with liability caps that do not extend to data breaches; and a reversibility service level agreement (SLA), with export in open formats and maximum deadlines, transition assistance, deletion certification and a fixed-date exit clause. The exit door the British Government is now weighing exists because it was agreed before entering.
The bar, moreover, rises with each system’s intrusion capacity, because each one strains different rights. Remote intrusion amounts to a total and permanent interception of the device, and demands the highest proportionality standard with reinforced judicial control. Forensic extraction requires defining the scope of the authorization and protecting professional privilege against incidental discovery. Facial recognition processes sensitive data and does not permit deployment without a prior assessment. And predictive analytics requires ruling out individual prediction by profiling and auditing the system’s biases before operating it.
For private companies the board is twofold. The one that adopts these platforms in its operation, with the corporate variants of the Foundry or AIP type, is liable as the data controller: lawful basis, impact assessment, purpose and minimization, within a compliance program that leaves verifiable evidence. The one that provides or integrates these systems for a third party must agree in writing on the distribution of security measures, retention periods, audits and the consequences of an incident. And for both there is an incentive that the market is already pricing: arriving compliant by December 1, 2026, will be a credential required in tenders and in due diligence, not a voluntary gesture.
Contracting well today costs less than defending yourself tomorrow
Mass data analytics platforms offer States and companies a power that did not exist a decade ago, and they offer it in a country whose system of checks and balances is incomplete: the data law months away from full enforceability, its Agency not yet constituted, artificial intelligence regulation in progress and an intelligence reform whose scope already troubles the human rights bodies. Who, then, guarantees the lawfulness of these systems? In that interval it will not be the legislator: the contract provides it, or it does not. The institutions and companies that document today their lawful basis, their impact assessment and their sovereignty over the data will be able to keep using these tools when the scrutiny arrives; those that sign without that backing will be buying, along with the software, their next court case. The full argument fits in one line: new power, conditions already written, a country that already uses it and a contract that decides which side each project ends up on. Comparative law has already shown how those cases end.
This article is general and informational in nature and does not constitute legal advice for any specific case. If your institution or company is weighing whether to contract, provide or audit data analytics or artificial intelligence platforms, or must bring its processing into line with Law No. 21,719, contact us for a specific analysis.