← Back to blog

Employee data under Law 21.719: a practical guide for Human Resources

Human Resources is one of the areas that processes the most personal data in any company, and often without a clear lawful basis or retention criteria. This guide explains how to handle employee data under Law 21.719 correctly, from the applicant stage through to the end of the employment relationship.

GUIDE - LAW 21.719

The essentials in 30 seconds

  • Consent is not the usual basis in employment: the employment relationship and the employer's legal obligations tend to be stronger bases.
  • Health, union membership and socioeconomic status are sensitive data and demand special care and justification.
  • Workplace monitoring must be proportionate, disclosed and tied to a legitimate purpose; surveillance 'just in case' is not acceptable.
  • When a contract ends, you must keep only what is required by legal obligation and delete the rest.

Every time your company posts a job opening, reviews a resume, hires someone or records a medical leave, it is processing personal data. Human Resources probably holds the largest volume of sensitive data in the entire organization, and with Law 21.719 taking full effect in December 2026, that processing falls under a far more demanding framework, overseen by the new Personal Data Protection Agency. If you want the full picture, start with our guide to the data protection law in Chile.

Law 21.719 updates the Chilean framework that until now was governed by Law 19.628 and introduces clear principles: lawfulness and fairness, purpose limitation, proportionality, quality, accountability, security, transparency and information, and confidentiality. For HR, this means moving beyond the idea that it is enough for the employee to 'sign an authorization' upon joining. Consent is only one of several lawful bases, and in the employment context it is often neither the most appropriate nor the most solid.

In this guide we review the lawful bases that typically apply to employment, how to handle sensitive data such as health or socioeconomic status, how far monitoring can go, what to do with data when the relationship ends, and how to respond when an employee exercises their rights. The aim is practical: to help your people team handle data with order and support, not to pile on fear.

Why HR is a critical area for data protection

Human Resources processes data throughout the entire lifecycle of the relationship: receiving applications, selection processes, hiring, payroll administration, attendance tracking, managing medical leave, performance reviews, training and, finally, the end of the contract. At every stage there is personal information and, frequently, sensitive data.

What sets it apart from other areas is the power imbalance. An employee is rarely in a genuine position to refuse to hand over their data or to object to processing without fearing consequences for their job. That is why consent tends to lose strength as a basis in employment: it can hardly be considered freely given. The prudent approach is to rely on more appropriate bases and to apply the principles of purpose limitation and proportionality with particular rigor.

The accountability principle closes the loop: it is not enough to comply, you must be able to demonstrate it. In practice this means keeping records of processing activities, internal policies, confidentiality clauses, access controls over personnel files and appropriate contracts with providers such as payroll firms, workplace safety services or recruitment platforms.

Lawful bases beyond consent

The most common mistake in HR is to request a generic data authorization at the time of hiring and assume it covers everything. Law 21.719 recognizes consent as a basis, but not as the only one nor necessarily the main one in employment. Other bases often fit the realities of the workplace better.

In practice, much of the processing HR carries out can rely on performing the relationship to which the data subject is a party and on complying with the employer's legal obligations. Paying wages, remitting social security contributions, issuing contracts, keeping attendance records or reporting to pension bodies generally does not require asking for permission: these are part of the contract or legal mandates. Legitimate interest of the controller may also be invoked, but it requires an honest balancing against the employee's rights and cannot serve as a catch-all for any purpose.

The practical recommendation is to map each processing activity and assign it the correct basis, rather than forcing everything onto consent. It is best to reserve consent for genuinely optional uses, such as publishing an employee's photo on the company's social media or enrolling them in non-mandatory benefits, where refusing must carry no consequences whatsoever.

  • Performing the employment relationship: contract, wages, duties, attendance tracking.
  • Compliance with legal obligations: social security contributions, reporting to authorities, workplace safety, tax obligations.
  • Balanced legitimate interest: reasonable and expected uses, always weighed against the employee's rights.
  • Consent: reserved for optional purposes where the employee can refuse without reprisals.

Sensitive data in employment: health and socioeconomic status

In the workplace, data that Law 21.719 classifies as sensitive naturally appears: health data (medical leave, pre-employment exams, disability accommodations), union membership, biometric data (fingerprint or facial recognition for access or attendance control) and, distinctively in Chile, socioeconomic status. This data requires a higher standard of protection and a clear justification.

The minimization principle is key. HR should process strictly the health data needed for the legal purpose, not the full diagnosis. To manage a medical leave, the information required by the social security system is enough; it is not appropriate to demand or store clinical details that add nothing to the process. The same applies to union membership, which the company knows for reasons such as deducting dues, but which cannot be used to segment, evaluate or discriminate.

The use of biometrics warrants special attention. Installing facial recognition or fingerprint scanning to clock attendance means processing sensitive biometric data, and it is worth assessing whether a less intrusive alternative can serve the same purpose. When biometrics is chosen, it is appropriate to document the need, inform the employee and apply reinforced security measures.

  • Process only the sensitive data needed for the purpose, not the entire file.
  • Keep health data separate from the general file and restrict who can access it.
  • Assess less intrusive alternatives before deploying biometrics.
  • Never use union membership, health or socioeconomic status for performance or termination decisions.

Proportionate workplace monitoring and control

Cameras, review of corporate email, browsing controls, vehicle geolocation or productivity software are all forms of monitoring that process the employee's personal data. Law 21.719 does not prohibit them, but it subjects them to the principles of purpose limitation, proportionality and transparency. Monitoring must respond to a legitimate and specific purpose and use the least invasive means that achieves it.

Proportionality means that the intensity of the surveillance must relate to the objective. A camera in a warehouse for security is reasonable; a camera permanently aimed at one person's workstation to measure their pace is usually excessive. Reviewing corporate email may be justified in response to a specific incident, but not as mass, routine monitoring of all communications. The key is to ask whether there is a way to achieve the same result with less impact.

Transparency is non-negotiable: the employee must know that they are being monitored, for what purpose, by what means and how long the records are kept. Hidden or disproportionate monitoring can not only breach data protection rules, but often clashes with labor law and with respect for the employee's dignity.

  • Define the specific purpose before deploying any control (security, compliance, evidence in case of incidents).
  • Choose the least invasive means that fulfills that purpose.
  • Inform in writing and clearly: what is monitored, how and for how long.
  • Limit access to recordings or logs and set short retention periods.

Retention and deletion when the relationship ends

A frequent problem is that personnel files are kept indefinitely 'just in case.' Law 21.719 points in the opposite direction: data should be kept only for as long as it is necessary for the purpose that justified its processing. When the employment relationship ends, that need changes and you must review what is kept, why and for how long.

Some information must be retained due to the employer's legal obligations, for example payroll records, social security contributions or documents subject to tax and pension retention periods. In those cases, the basis for retention is compliance with a legal obligation, and the data should be kept for the period the applicable rules require, no longer. The rest of the data that no longer serves any purpose must be deleted or anonymized.

The recommended practice is to have a documented retention policy that sets periods by data type and a procedure for periodic cleanup. This not only aligns with the principles of quality and minimization, but also reduces the risk surface: less data stored means less data exposed in the event of a security breach.

  • Classify a former employee's data according to whether there is a legal obligation to retain it.
  • Set retention periods by document type and honor them.
  • Delete or anonymize anything that no longer has an associated purpose or obligation.
  • Document the retention policy: it is evidence of accountability before the Agency.

Employees as data subjects: their rights

An employee does not lose their status as a data subject just because they are under contract. Law 21.719 recognizes the rights of access, rectification, erasure, objection and portability, along with blocking. This means that an employee, or even a former employee, can ask what data of theirs you process, request that you correct inaccurate information or delete data that is no longer relevant.

HR must be prepared to receive and respond to these requests within reasonable timeframes and through a clear channel. It is advisable to define who handles them, how the requester's identity is verified and how the response is documented. When faced with an erasure request, you must distinguish what can be deleted from what must be retained by legal obligation, and explain it transparently to the employee.

When a breach of security measures affects employee data, for example a leak of the payroll database or of health data, the controller must notify the Agency of breaches that cause the destruction, leakage, loss or alteration of data, and inform those affected when the incident may affect their rights, with particular care if it involves sensitive data. The law requires acting without undue delay and by the fastest possible means, so HR must have an incident response procedure ready in advance.

  • Define a single, well-known channel for employees to exercise their rights.
  • Verify the requester's identity before releasing information.
  • Respond within reasonable timeframes and keep a documented record of each request.
  • Have a breach notification procedure ready before an incident occurs.

Bring order to data processing in your people team

At AlayIAtrust we help HR teams, DPOs and management map their processing activities, define the correct lawful bases and prepare retention and incident-response policies in line with Law 21.719. Book an assessment and see where your company stands today.

Schedule an assessment

Frequently asked questions

Do I need every employee to sign an authorization to process their data?

Not for everything. Much of HR's processing can rely on performing the employment relationship and on complying with the employer's legal obligations, which do not require consent. Reserve the signed authorization for optional uses, such as publishing an employee's photo or enrolling them in non-mandatory benefits, where refusing must carry no consequences.

Can I install facial recognition or fingerprint scanning for attendance control?

You can, but this involves sensitive biometric data and demands greater care. Before deploying it, assess whether there is a less intrusive alternative that serves the same purpose. If you still opt for biometrics, document the need, inform the employee and apply reinforced security measures.

What do I do with the personnel file when someone stops working with us?

Review what data must be kept due to legal obligations, for example payroll and social security records, and keep it only for the period the rules require. The rest of the information that no longer serves any purpose must be deleted or anonymized. Keeping everything indefinitely goes against the principle of storage limitation.

How much can I monitor my employees?

Monitoring must have a legitimate and specific purpose, use the least invasive means possible and be proportionate to the objective. In addition, the employee must be informed of what is monitored, how and for how long the records are kept. Hidden or mass surveillance without justification does not comply with the law.

How quickly must I notify a breach that affects employee data?

Chilean law does not set a deadline in hours like the European model. It requires notifying the Personal Data Protection Agency without undue delay and by the fastest possible means, and informing those affected when the incident may affect their rights, with particular attention if it involves sensitive data such as health.

From when must I comply with these obligations?

Law 21.719 was published in December 2024 and takes full effect after a transition period, in December 2026. It is wise to use that time to organize HR processing, define lawful bases, retention policies and response procedures, rather than leaving it to the last minute.

You may also be interested in

Sensitive data

Sensitive data under Law 21.719: what they are and how to protect them

Retention

Personal data retention and deletion

CCTV

Video surveillance and CCTV: complying with Law 21.719

Next step

Is your company ready
for December 2026?

A no-obligation 30-minute assessment.

Request an assessment