Chilean Court Rules on Data Breach and Banking Secrecy, Highlighting New Data Protection Law
A recent ruling by the Iquique Labor Court initially deemed a bank's dismissal of a long-serving executive as undue. The executive was fired not for embezzlement, but for accessing a client's account without authorization and sharing information with a third party, despite no financial loss or personal gain. The court found the dismissal disproportionate, considering the employee's decade of service and the lack of proven harm to the bank, suggesting a lesser disciplinary action would have been appropriate. However, the Iquique Court of Appeals overturned this decision, validating the disciplinary dismissal and denying the employee severance pay. The appellate court reasoned that the employment contract included explicit confidentiality duties, accessing client data outside functional purposes violated probity and loyalty, and that banking secrecy violations carry criminal penalties, thus warranting severe disciplinary action. Furthermore, the court emphasized that the employee's extensive tenure, rather than mitigating the offense, aggravated it, as she should have known better. This case, currently awaiting a Supreme Court decision on an appeal, signals a judicial stance that unauthorized access and disclosure of confidential information are serious breaches, especially with the upcoming Personal Data Protection Law. The bank only learned of the breach because the client complained, not through internal controls. The new law, effective December 2026, will impose strict data handling requirements, including data processing activity logging, privacy by design, security measures, and incident reporting to a new Data Protection Agency with significant enforcement powers. This agency can impose fines up to 20,000 UTM (approximately US$1.5 million) for severe violations, with penalties tripling for repeat offenses. The appellate court's decision indicates a judicial readiness to treat such breaches as grave offenses, irrespective of direct financial damage.
This case underscores a critical tension between traditional employment law interpretations and the escalating data privacy landscape. While the initial labor court focused on demonstrable financial harm and employee tenure, the appellate court's reasoning aligns with the evolving legal and societal understanding of data as a valuable asset. The impending Personal Data Protection Law in Chile, with its stringent penalties and enforcement mechanisms, signals a systemic shift. Companies must proactively invest in robust internal controls and automated monitoring to detect data breaches, rather than relying on client complaints. The judiciary's increasing willingness to classify data misuse as a severe offense, even without direct financial loss, highlights the growing importance of data governance and security as core business imperatives, not merely compliance checkboxes. This trend suggests a future where data integrity is paramount, and organizational accountability for data protection will be rigorously enforced.
AI-generated to prompt reflection — not editorial opinion, not advice, not a statement of fact. How this works.