There's a document almost no one in the private sector has read that is among the best things published on Law 21.719. It was produced by the Secretariat for Digital Government, and it's called the Practical Guide for implementing the new data protection law. It was written for State Administration bodies, but it can be useful to you even if you don't know where to start with the data protection law.
The asterisk is right there in the first line: the guide speaks to public services, not to a small business or a large company. It mentions service heads, civil servants and the public-sector office for information, complaints and suggestions (OIRS). But the skeleton it proposes, the order in which it makes sense to do things, has nothing public about it and works just as well for any organization that handles people's data. That's why we walk through it here, pointing out along the way where the hard work is and where the guide leaves you on your own.
The guide gets the order right
The first thing it does well is not to start with technology. Before any system, it asks for three almost boring things: appoint someone responsible for the implementation, set up the project with its deadlines, and tell the whole organization that this is serious. Only then comes the heart of the diagnosis, which is building a matrix of every piece of personal data the institution handles today. What data, about whom, for what purpose, on what legal basis, in which system it lives, who it's shared with, whether it leaves the country, whether there are automated decisions involved.
With that matrix filled in you write a findings report that compares what you do today against what the law requires and lays the gaps bare. A committee reviews that report, and only then do you start drafting the instruments: a catalog of the data you process, a processing policy and the technical protocols for the riskiest parts. The guide even comes with a timeline, and it's tight. All its dates fall in 2026: the data mapping between January and April, the catalog for May or June, the policy in July, and the protocols from August to November (right up against the law taking effect on December 1). Today, in mid-June, if you've been keeping that pace you should be closing your catalog about now. If you still haven't built the matrix, you're behind, and that's the first favor the guide does you: it tells you what month you should be in.
There's one detail that says a lot. The matrix asks you to register the artificial intelligence tools and automated decisions you use, along with an explanation of the logic they apply. Not even the State itself treats AI as a compliance solution. It treats it as something you have to inventory and be able to explain.
But every company is its own world
The document comes with template formats for almost everything: the project charter, the matrix, the catalog, the policy. They're an excellent starting point, and the guide itself says so when it asks you to adapt each template to the reality of each institution. The template doesn't supply the content, you do.
No template format knows what data your company handles. It doesn't know that your customer base lives in three systems that don't talk to each other, that the sales team keeps spreadsheets full of RUT numbers in a shared Drive, that you send emails to a marketing vendor in the United States, or that the form on your site has spent years asking for more data than it needs. That doesn't come out of a template. It comes from sitting down to map, area by area, what actually happens, and from someone who can read the law well enough to tell which of those processing activities rest on a solid legal basis and which are a breach waiting for a complaint.
That's the work of the consulting phase, and it's the most bespoke of all. It's the data mapping done properly, the findings report that prioritizes your risks and not those of a generic manual, and the drafting of your catalog and your policy with your own processing activities inside. At Alicanto we support that setup with consulting, and we use artificial intelligence to speed it up, so that putting a company's compliance together takes days and not months. The guide tells you what you have to produce. The hard part is producing it with your business inside, before December.
What a document can't do for you
This is where the part the guide can't resolve, by its very nature, begins, and it's the part that never ends. The catalog, the policy and the protocols end up being documents. Necessary, well-made documents, but documents. What the law is going to enforce after December 1 isn't the file you signed and filed away in a folder: it's what you do with it every day.
Take consent as the example. Your policy can state that you ask for informed, specific consent. But that's only the paper. The proof is something else: the day someone files a complaint, you have to be able to show the exact text that person accepted, when, through which channel, and that the record hasn't been altered. A box ticked in a table anyone could edit proves nothing. The same thing repeats with every obligation the guide leaves drafted. Every access or deletion request starts a thirty-day clock that expires even if no one is watching, every breach runs against a clock measured in hours, and every new vendor forces a contract review.
That's the part no template sustains, because it isn't a document but an operation. It's what we built into Alicanto's data protection platform. Every consent is stored with the exact text the person accepted and a fingerprint that reveals any later change. Every data subject right enters with its clock already running and a traffic light that warns before the deadline. Every security breach is logged with its notification deadline to the Agency already ticking. And all of it stays sealed in a chain of evidence that can be exported in full the day they ask for it. The platform doesn't decide for you: your team keeps control of each case, but it won't let you miss a deadline or show up without the proof.
Up to the starting line
The Secretariat for Digital Government's guide takes you up to the starting line, and it does it well. It puts you in order, it gives you dates and it hands you the formats. What comes after has two halves no template covers: adapting all of it to your company, and then operating it without a single deadline falling through. Those two halves are exactly what we do at Alicanto, with consulting that walks the roadmap with your business inside and a platform that sustains the operation once the guide has done its part. The map is published and it's free. What's left is adapting it to your reality, and there we can walk alongside you.




