There is a comfortable idea about compliance worth dismantling before it costs you dearly: that complying with a law means having the document. The protocol signed and filed away in a folder, the privacy policy published on your site, the internal regulation with its latest version loaded. For years that was enough to sleep soundly. Two recent Chilean laws put an end to that calm. The paper is still necessary, but it stopped being sufficient, because what gets audited today is what you do after you sign it.
Both reach almost every company, not just the large ones or the financial sector. Ley Karin, Law 21.643, has been in force since August 2024 and requires every employer to prevent and investigate workplace harassment, sexual harassment and violence at work. Law 21.719, the new personal data protection law, was published in late 2024 and takes full effect on December 1, 2026, when a newly created agency will start auditing how you handle the data of your customers and employees. In substance they have nothing in common: one is about dignity at work and the other about privacy. What ties them together is how you comply with them.
Complying looks more like operating than filing
A process, unlike a piece of paper, puts two demands on you that don't forgive. One is the clock, because these laws run deadlines that expire whether or not anyone is watching. The other is proof, because acting correctly isn't enough if you later can't show, step by step and with dates, that you acted when you were supposed to. The day a request, a complaint or an auditor arrives, what backs you up isn't the document you signed a year ago: it's the record of everything you did since then. And for that record to count as proof, rather than a spreadsheet anyone could have edited the night before, it has to be able to show that things happened exactly as it says, on the dates it says.
Ley Karin: when a complaint comes in, a clock starts
Take Ley Karin, where it's plain to see. The moment a harassment complaint comes in, it doesn't open a quiet procedure: it sets several clocks running at once. The measures to protect the person who reports are immediate; the internal investigation has thirty business days; and notifying the Labor Directorate, referring the case, sending the report and applying the sanctions each carry their own deadline, all counted in business days that exclude weekends and Chilean public holidays. Doing that by hand on a spreadsheet, while you're also running a delicate investigation, is exactly where things fall apart. And if you miss a deadline, the Labor Directorate has a catalog of infractions with fines in monthly tax units that scale with the size of the company. A good share of those sanctions are triggered for being late to a deadline, not for the substance of the case.
That's why, when we built our whistleblowing channel for Ley Karin, the first thing we built wasn't a pretty form; it was a deadline engine. Each case carries its countdown in business days, with the holidays already loaded, and a traffic light that goes from green to amber to red before a due date catches up with you. The full case file, from the anonymous or identified report through to the closure and any referral to the Labor Directorate, is stored in a chain where each step is sealed with a cryptographic fingerprint that depends on the step before it. Changing a date or deleting an action later breaks that chain and leaves the trace in plain sight, so the record doesn't just tell what happened: it proves it happened when it says. That's what you actually show an auditor, and it's something no folder of documents can give you.
Law 21.719: the consent you have to be able to prove
Law 21.719 puts you in a different position, with the same underlying logic. It requires you to be able to prove the consent under which you process a person's data, not merely to have it stated in some text. That when someone exercises a right over their data, whether to request access, rectification or deletion, you respond within a legal window of thirty days. That if you suffer a security breach that carries risk, you report it to the Agency within hours. None of that is solved by a privacy policy published on your site. It's solved by holding, for each person, the record of what they accepted and when.
Our platform for this law keeps, for every consent, a copy of the exact text the person accepted at the moment they accepted it, not a generic version someone edited afterward. Each data subject request runs with its thirty-day deadline and its automatic acknowledgment of receipt. And each of those facts is sealed in the same kind of chain, where every link carries the fingerprint of the one before it, so the day the Agency asks for proof the answer is already built: a dated history that can be audited in full and that no one could rewrite after the fact. When enforcement begins in late 2026, the difference between complying and appearing to comply will be right there, in whether you can open that history or not.
What deliberately doesn't appear: artificial intelligence
You may have noticed something in both descriptions. Artificial intelligence shows up in neither, and that's on purpose. The core of both platforms is deterministic, code that always does the same thing and always leaves the same trail. When what's at stake is not missing a deadline and being able to prove every step, a model that improvises is the last thing you want at the center. What matters here is that the calculation of a deadline comes out identical today and a year from now, and that the proof is impossible to alter without it showing. Artificial intelligence comes in where it genuinely adds value, above all in speeding up the setup for a new company. What sustains compliance is the deterministic code underneath. Anyone selling you "AI to comply with the law" as if the model were the heart of the matter is selling you exactly the risk you should be avoiding.
Complying with these two laws, each in its own domain, stopped being a one-time act and became something you operate every day. That's the uncomfortable part. The good part is that a process you operate every day is exactly what software does well: keeping the clock without getting distracted and storing the proof without anyone having to remember. That's why two of our solutions are named after what they do, protecting data and managing complaints, and both start from the same place: the deadline you can't miss and the proof you have to be able to show.




