Fine turquoise lines of light flowing over a dark petrol background, like threads of data in motion
Back to the blog

Compliance

The Data Protection Law: what changes for your company

June 16, 20267 min read172 views

Law 21.719, the new personal data protection law, takes full effect on December 1, 2026. It was published in late 2024 with a two-year transition period for companies to prepare, and of those two years less than half is left today. The second thing to know is who it reaches: almost any company that handles people's data, not just banks or large firms. If you have a customer base, a payroll or a contact form on your site, you are processing personal data and the law applies to you just as it does to a company on the IPSA, Chile's main stock index.

What changes with it isn't that you suddenly have to look after data. That was always the case. What changes is that this care stops being a good intention and becomes a list of concrete obligations, with deadlines that run and a new body that enforces them. The Personal Data Protection Agency is created, an autonomous entity with the power to investigate on its own initiative, order you to suspend a processing activity and impose fines. Before this law, that body simply did not exist.

What it actually requires you to do

The law is easier to grasp if you bring it down to the things you'll need to be able to show the day someone asks.

The first is consent. It is no longer enough to have a box ticked at some point: you have to be able to prove the exact text each person accepted and when they did it. The second is the rights of the data subject, what is known as ARSOP: access, rectification, erasure, objection, portability and blocking. Anyone can ask to see their data, correct it, have you delete it or have it handed over in a portable format, and you have a legal deadline of thirty days to respond. The third is the RAT, the record of processing activities, which is the inventory of what data you process, for what purpose, on what legal basis and for how long you keep it. It is the tool with which you demonstrate that you know what you are doing with the information.

To that, two obligations are added that appear when things get serious. If you suffer a security breach that puts people at risk, you have to report it to the Agency within hours, not when it suits you. And before launching a high-risk processing activity, the law asks you for an EIPD, an impact assessment that analyzes what could go wrong with that data before you touch it.

The law also brings fines. Infringements are graded as minor, serious and very serious, with ceilings of 5,000, 10,000 and 20,000 UTM (monthly tax units) respectively. For large repeat-offender companies, the calculation can rise to a percentage of annual revenue. That said, it is worth stressing that those numbers are the legal ceiling, not the bill you are going to receive. The actual amount of the fine will depend on the size of your company, the seriousness of the case and whether it is the first time, and during the first year in force the Agency starts by issuing written warnings to smaller companies rather than fining them. More than the headline figure, what shifts the board is that there is now someone with the authority to review how you handle data and to sanction you if you do it wrong.

Seen this way, what you have ahead of you is really two distinct problems, and they are solved in different ways.

The first challenge is reaching December with everything in place

The first problem is one of implementation. Between now and December you have to build much of this from scratch: rework your consent forms so they are versioned and store the text each person accepted, assemble the RAT by mapping all the processing that today happens spread across different areas, review the contracts with every vendor that processes data on your behalf, define how you will receive and answer data subjects' requests within the deadline, and have the mechanics ready to report a breach in time. It is setup work, intense and bounded, that mixes interpreting what the rule requires of you with building the technical solution that meets it. Most companies today have neither the time nor the internal knowledge to do it well before the deadline, and it is precisely the moment when you most need someone who has already walked the path.

The second challenge starts the day the law takes effect

The second problem is the one almost no one is looking at, and it is the one that never ends. Once the law comes into force, complying stops being a project with an end date and becomes an everyday operation. Every new customer generates a consent that has to be stored properly. Every access or deletion request starts a thirty-day clock that expires even when no one is watching. Every new vendor forces a contract review. Every change in how you use data should update the RAT. And if one day there is a breach, the clock in hours runs from that moment, not from when you noticed.

That burden does not disappear after December: that is when it begins. It is permanent work, with deadlines that don't forgive and with the obligation to always have ready the proof that each step was taken when it should have been. A company can be perfectly prepared by December 1 and still break the law in March, simply because it let a request slip or because no one was left in charge of keeping count.

Someone has to own this

The two challenges point to the same thing. This needs an owner, someone who takes charge of compliance day to day, not a document signed and filed away in a folder. The law even contemplates the figure of the data protection officer, a formal person responsible for looking after these matters within the organization. But the role, on its own, solves nothing if it has nothing to operate with: a person cannot manage hundreds of deadlines, consent versions and records by hand without something slipping through.

At Alicanto we built a platform to tackle both challenges. For the first, we support the setup with consulting that interprets the rule and adapts the solution to your business, so you reach December with everything in place and not with a list of pending items. For the second, there is the data protection platform: it stores each consent with the exact text the person accepted, tracks each data subject's request with its thirty-day deadline and automatic acknowledgement, keeps the RAT up to date and leaves every step sealed in a chain of evidence that can later be audited in full. The platform is what makes the role workable, what turns a permanent obligation into something the software carries without getting distracted and without anyone having to remember.

When enforcement begins, the difference between complying and appearing to comply won't lie in who has the prettiest privacy policy published on their site. It will lie in who can open the full history and prove, request by request and date by date, that they did what the law asks, every day, from the first one.

Sources

More articles

View all